Tender detail

Security Operations Center as a Service (SoCaaS)

Summary

The tender concerns the provision of a Security Operations Center as a Service (SoCaaS) to provide centralized log management, monitoring and control of the contracting authority’s IT infrastructure, as well as timely detection and handling of security incidents. The bidder must demonstrate at least two completed SOC service contracts in the previous 36 months with a combined value of at least EUR 100,000 excluding VAT. The service team must include experts with the specified SOC, CISSP, vulnerability-management and Microsoft security certifications, and the bidder must have ISO 27001 and ISO 9001-compliant management systems or equivalent. The bid must follow the required pricing structure, be unconditional and include the required authorizations and equivalence evidence where applicable.

Reference number
311793-0000
Buyer
AS HOOLEKANDETEENUSED
Country
Estonia (EST)
Procedure
Open procedure
CPV
72220000 Systems and technical consultancy services
Deadline
2026-09-11
Status
Evaluation
Contract subject
Services
Estimated value
180 000,00 EUR
Source
RHR

Participation requirements

Tender requirements are available in the official tender documents.

Compliance requirements

The bidder must confirm that neither it nor its management, administrative or supervisory body members or other authorised representatives have been finally convicted within the last five years of participation in a criminal organisation, corruption, fraud, terrorist offences, money laundering or terrorist financing, or offences involving child labour or human trafficking. Exclusion may also apply in cases of unpaid taxes or social security contributions, breaches of environmental, social or labour-law obligations, bankruptcy or other insolvency, liquidation, an agreement with creditors, assets administered by a liquidator or court, suspended business activities, serious professional misconduct, anti-competitive agreements, a conflict of interest, involvement in preparing the procurement, material breaches of previous contracts, or false statements and failure to provide required documents. The authority also checks breaches related to enabling an unlawfully staying foreign national to work, the applicability of international or Estonian sanctions, and convictions for tax offences. The threshold stated for unpaid tax and social security contributions is EUR 0; as an exception, an Estonian tax authority does not issue a tax-debt certificate where the debt is below EUR 100 or payment has been deferred. Where an exclusion ground exists, the contracting authority may assess remedial measures taken to restore the bidder’s reliability where permitted.

Qualification criteria and exclusion grounds

Within the 36 months preceding publication of the tender, the bidder must have properly completed at least 2 Security Operations Center service contracts with a combined value of at least EUR 100,000 excluding VAT. For each contract, the bid must provide the contract signature and completion dates, value, and the name and contact details of the other contracting party, including email and telephone number. The procurement reference number must also be stated where applicable. The contracting authority may request confirmation from the client that the contract was properly performed. Throughout the contract period, the bidder must provide a suitably competent team comprising at least 2 experts holding a Certified SOC Analyst or equivalent certificate, at least 1 expert holding an ISC2 CISSP or equivalent certificate, at least 3 experts holding certificate(s) demonstrating competence in the proposed vulnerability detection and management technology, and at least 1 expert holding Microsoft Certified: Cybersecurity Architect Expert and/or Microsoft Certified: Azure Security Engineer Associate (AZ-500), or an equivalent certificate. The bid must include the experts’ names, roles, qualifications and experience, and certificate details or other supporting evidence. For the organisation of the SOC service, the bidder must have its own implemented information security management system meeting at least ISO 27001 or an equivalent standard, and its own implemented quality management system meeting at least ISO 9001 or an equivalent standard. Reliance on another entity’s resources to meet these requirements is not permitted. Copies of the certificates or other documents proving compliance must be submitted. The bid must comply with all tender document requirements, be unconditional and follow the required pricing structure. Where applicable, equivalence must be explained and supporting evidence attached. In a joint bid, a power of attorney for the joint bidders must be included; if the bid is submitted by a person who is not a management board member with the relevant representation rights in the commercial register, a separate power of attorney must also be provided. The bidder must identify and justify any trade secrets, but may not classify the bid price or prohibited numerical indicators related to evaluation as trade secrets.