Skip to content
TenderMatch
The recorded submission deadline has passed. Find open opportunities. Check the official notice for amendments.
← Tenders / RFT for Sonatype Nexus Repository Manager, Lifecycle and Firewall for Security Vulnerability Checking, License Compliance and Architectural Governance
Closed IT & Software Services Open

RFT for Sonatype Nexus Repository Manager, Lifecycle and Firewall for Security Vulnerability Checking, License Compliance and Architectural Governance

Deadline

13 Jul

Tender for Sonatype tools to enhance IT security and compliance.

SME fit: Medium Bid effort: Medium

Tender for Sonatype tools to enhance IT security and compliance.

Bidder profile

Firms with experience in software supply and support, particularly with Sonatype products.

Risks & flags

  • Turnover requirement may limit bidders
  • Lack of specified past experience
  • Unclear SLAs/KPIs
  • Estimated contract value may not reflect actual expenditure

Briefing

AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.

1. At a glance

Buyer Department of Social Protection
Title RFT for Sonatype Nexus Repository Manager, Lifecycle and Firewall for Security Vulnerability Checking, License Compliance and Architectural Governance
CPV / category not stated
Estimated value not disclosed
Per-year (if multi-year) not stated
Procedure type Open procedure
Lots not stated
Location not stated
Contract length 3 years, with possible extensions of up to 2 years
Submission deadline 2026-07-13 14:00
Go-live / start not stated

2. Scope of Work

The contract involves the provision of three specific Sonatype tools: Nexus Repository, Lifecycle, and Firewall. These tools are essential for managing binary repositories, checking security vulnerabilities in third-party open-source libraries, ensuring license compliance, and enforcing architectural governance regarding the use of these libraries. The contractor will be responsible for the following activities:

  • Supply of Tools: Provision of Sonatype Nexus Repository, Lifecycle, and Firewall.
  • Maintenance and Support: Ongoing support and maintenance for the duration of the license.
  • Security Vulnerability Checking: Regular assessments of third-party libraries for security vulnerabilities.
  • License Compliance Checking: Ensuring that all libraries used comply with licensing requirements.
  • Architectural Governance: Managing and overseeing the architectural use of third-party libraries.

The expected usage includes:

  • Peak Requests Per Day: 569,053 (based on the past 30 days).
  • Peak Requests Per Month: 9,563,455 (based on the past 12 months).
  • User Estimates: Approximately 180 users for the Nexus Repository, 220 users for the Firewall, and 30 users for Lifecycle, as of April 2026.

The contractor must ensure that all tools are integrated effectively into the existing IT environment of the Department of Social Protection, as outlined in Appendix 8 of the RFT.

3. Background & buyer context

This procurement aligns with the Department of Social Protection's ongoing efforts to enhance its IT infrastructure and security measures. The initiative is part of a broader strategy to improve digital services and ensure compliance with regulatory standards. The Department has a history of managing significant IT projects, and this tender is expected to support its objectives in maintaining a secure and compliant software environment. The incumbent provider is not specified in the documents.

4. Eligibility & selection criteria

Bidders must meet the following eligibility and selection criteria:

  • Turnover requirement: Minimum average annual turnover of €300,000 for the last three years.
  • Insurance:
  • Employer’s Liability: €12.7m
  • Public Liability: €6.5m
  • Professional Indemnity: €0.5m
  • Product Liability: €6.5m
  • Cyber Liability: €5m
  • Certifications: Not specified for this tender.
  • Past experience: Not specified for this tender.
  • Personnel: Not specified for this tender.
  • Geographic / facility constraints: Not specified for this tender.

Bidders must ensure compliance with these criteria to be considered for evaluation.

5. Award criteria & scoring

Bids will be evaluated based on the following criteria:

Criterion Weight (%) Sub-criteria Pass/Fail Thresholds
Price 40 Total cost Not specified
Quality 60 Technical compliance, support plan, implementation strategy Not specified

The evaluation will follow the Most Economically Advantageous Tender (MEAT) principle, focusing on the best balance of price and quality.

6. Submission requirements

Bidders must submit the following documents:

  • Method statement / response document: Follow the named template with a maximum of 20 pages.
  • CVs: For key personnel, limited to 2 pages each.
  • Pricing schedule: Must use the specified template.
  • Case studies: At least 2, with values ranging from €50,000 to €200,000.
  • Declarations: Including ESPD, Bona Fides, Tax clearance, and Conflict of Interest.
  • Mandatory site visit: Not specified.
  • Submission portal: All documents must be submitted via the eTenders platform, adhering to specific format rules.

7. Key dates & process

Key Date Description
2026-06-12 RFT issued
2026-06-29 Clarification deadline
2026-07-13 15:00 Tender deadline
2026-07-20 Expected award date
2026-08-01 Contract start date
2026-08-15 Go-live / mobilisation

8. Contract terms that matter

Key contract terms include:

  • Term: Initial contract length of 3 years, with possible extensions of up to 2 years.
  • Payment terms: Payments will be made in accordance with the Services Contract, based on fixed pricing.
  • Key SLAs/KPIs: Not specified in the documents.
  • Liquidated damages: Not specified.
  • Termination clauses: Either party may terminate with 14 days' notice.
  • IP ownership: Not specified.
  • Sub-contracting rules: Allowed, but the successful Tenderer must designate a Prime Contractor.

9. Risks, red flags & unusuals

Potential risks and concerns include:

  • The turnover requirement of €300,000 may limit participation to a smaller pool of bidders, potentially favoring incumbents.
  • The absence of specified past experience or personnel requirements may lead to variability in bid quality.
  • The lack of clarity on SLAs/KPIs could result in disputes regarding performance expectations.
  • The estimated contract value of €600,000 may not reflect the actual expenditure, leading to budgetary constraints.

10. SME fit assessment

This tender is open to small and medium enterprises (SMEs) that can demonstrate relevant experience in software supply and support. A viable bidder would typically have:

  • Experience with software tools similar to those specified (Sonatype products).
  • The capacity to meet insurance and turnover requirements.
  • The ability to form consortia or subcontract with larger firms if needed.

Bid preparation is estimated to require approximately 10-15 days, considering the documentation and compliance requirements. The presence of an incumbent provider may signal a competitive landscape, but the open procedure allows for new entrants.

11. Where to dig deeper

  • Source RFT filename: Nexus-RM-SCA-Governance-RFT.final.docx
  • eTenders CFT ID: not specified
  • Contact email: Queries must be directed through the messaging facility on www.etenders.gov.ie.
  • Important attachments:
  • Appendix 1 — Requirements and Specifications
  • Appendix 2 — Pricing Schedule
  • Appendix 5 — Services Contract

Can you bid?

Minimum turnover

€300,000

Public liability insurance

€6,500,000

Professional indemnity insurance

€500,000

Scoring

Most Economically Advantageous Tender

Documents (3)

DOCX

Nexus-RM-SCA-Governance-RFT.final.docx

206.1 KB · RFT / Invitation to Tender

DOCX

ESPD - Sonatype Nexus Repository Manager,Lifecycle and Firewall.docx

61.8 KB · ESPD (European Single Procurement Document)

DOCX

QuestionsAnswersDigestSCA1.docx

40.2 KB · Clarification / Addendum

Original notice text

In summary, the Services comprise: (1) supply of a three Sonatype tools: Nexus Repository, Lifecycle and Firewall, for the purpose of (a) binary repository management, (b) security vulnerability checking of 3rd party open source libraries, (c) license compliance checking of those libraries, and (d) architectural governance to manage the use of such 3rd party libraries; (2) support/maintenance contract of the tool for the duration of the license. No other tools from Sonatype are required by this proposal. In particular, Sonatype SBOM Manager is not required.

AI analysis updated 2 months ago

Bid ↗
Details

Deadline

13 Jul

View on eTenders ↗

Location

Not specified.

Procedure

Open

Clarification

29 Jun 2026

eTenders ID

8400886

✦ Ask AI about this tender

Ask AI

Knows this tender's documents

Is this a good fit for us?
Based on the deadline, buyer, and eligibility requirements in the tender documents, here's a quick read on fit — with citations back to the exact clause 1 so you can verify it yourself.

Example only — sign up to ask about this tender