Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, October 14 at 2:00 PM EDT

Register Free →

Cytundeb Fframwaith CymruSOC 2.0 CymruSOC 2.0 Framework Agreement

Active
CS/MTCBC/SOC/002International

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

CymruSOC 2.0 is a national managed Security Operations Centre framework established through a collaborative procurement by Merthyr Tydfil County Borough Council in partnership with the Welsh Government. The framework aims to appoint a single supplier to provide a Core managed SOC service and optional Plus Services, ensuring continuity from the CymruSOC 1.0 outcomes while supporting technical improvements and wider participation across diverse technical environments. A critical requirement is that the service remains SIEM-agnostic, supporting various participant-owned or approved security tooling to achieve necessary monitoring, interoperability, and assurance outcomes. The estimated total value of the contract is 90 million GBP excluding VAT. The agreement is structured as a single-lot framework with an estimated seven-year term from April 1, 2027, to March 31, 2034, a duration justified under Section 47(3) of the Procurement Act 2023 due to the complexities of data migration and the onboarding and offboarding of providers. The procurement follows a three-stage competitive flexible procedure consisting of a capability assessment, a conditions of participation review, and a final invitation to submit tenders for a maximum of six shortlisted suppliers. Award decisions are based on a weighted score of quality and price, with the top three candidates invited to a moderation presentation. Additionally, the incumbent contractor has indicated that TUPE regulations will apply to this procurement.

General Info

A £90 million framework for a SIEM-agnostic national managed SOC service in Wales.

Documents

3

CymruSOC 2.0 Framework Agreement

PDF, High priority: read this firstrfp
High

All Wales Clause for UK4 Notice

DOCX, Low priority1 page · special-notice
Low

Justification for 7-Year SOC Framework (PA23 Compliant)

DOCX, Low priority1 page · justification-and-authorization
Low

AI Contract Breakdown

Uniform Contract Format

Sign up to view the full breakdown with detailed analysis of each section.

Timeline

PhaseSolicitation
Posted

Solicitation

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyMerthyr Tydfil County Borough Council
Contacts1 person available
OfficeN/A
Office AddressN/A

Full Description

Show more
Bydd CymruSOC 2.0 yn darparu fframwaith SOC a reolir cenedlaethol sy'n cynnwys gwasanaeth SOC craidd a reolir a Gwasanaethau Ychwanegol a archebir ar wahân. Rhaid i'r gwasanaeth gynnal parhad canlyniadau gofynnol CymruSOC 1.0, gan gefnogi gwelliant rheoledig, cyfranogiad ehangach ac amgylcheddau technegol amrywiol y Cyfranogwyr. Rhaid i'r gwasanaeth barhau i fod yn annibynnol ar unrhyw SIEM penodol a rhaid iddo gefnogi trefniadau SIEM ac offer diogelwch eraill sydd naill ai'n eiddo i Gyfranogwyr neu'n drefniadau amgen a gymeradwywyd, lle gellir cyflawni'r canlyniadau gofynnol o ran diogelwch, monitro, rhannu gwybodaeth, rhyngweithrededd a sicrwydd. Mae rhagor o wybodaeth fanwl ar gael yn y Datganiad o'r Gofynion, a ddarperir fel atodiad yng Ngham 1 ar eDendroCymru. Mae hwn yn gaffaeliad cydweithredol sy'n cael ei gynnal gan Gyngor Bwrdeistref Sirol Merthyr Tudful (yr Awdurdod Contractio) mewn partneriaeth â Llywodraeth Cymru, a bydd yn ceisio sefydlu Cytundeb Fframwaith un lot gydag un cyflenwr er mwyn galluogi awdurdodau sy'n cymryd rhan i alw i lawr a chreu contractau ar gyfer y gwasanaethau sydd eu hangen arnynt. Bydd yn ofynnol i'r tendrwr llwyddiannus ymrwymo i Gytundeb Fframwaith gyda'r Awdurdod Contractio ac, wedi hynny, ymrwymo i gontractau unigol gan ddefnyddio templed contract galw i lawr gydag awdurdodau sy'n cymryd rhan drwy'r weithdrefn galw i lawr. Er budd tryloywder ac er mwyn rhoi gwybod i ddarpar dendrwyr cyn gynted â phosibl, mae'r contractwr presennol wedi nodi y bydd TUPE yn berthnasol i'r caffaeliad hwn. Yn unol â'r rheoliadau, rhaid i'r contractwr presennol a'r contractwr newydd a ddyfernir i'r Fframwaith o ganlyniad i'r caffaeliad hwn gydymffurfio â rheoliadau TUPE lle maent yn berthnasol. Bydd gwybodaeth TUPE yn cael ei darparu i dendrwyr ar y rhestr fer yng Ngham 3. CymruSOC 2.0 will provide a national managed SOC framework comprising a Core managed SOC service and separately ordered Plus Services. The service must preserve continuity of the required CymruSOC 1.0 outcomes while supporting controlled improvement, wider participation and different Participant technical environments. The service must remain SIEM-agnostic and must support approved Participant-owned and alternative SIEM and security tooling arrangements where the required security, monitoring, information-sharing, interoperability and assurance outcomes can be achieved. Further detailed information can be located in the Statement of Requirements which is provided as an attachment within Stage 1 on eTenderWales. This is a collaborative procurement being conducted by Merthyr Tydfil County Borough Council (the Contracting Authority) in partnership with Welsh Government and will seek to put in place a single-Lot single supplier Framework Agreement for participating authorities to be able to call off and create contracts for the services they require. The successful tenderer will be required to enter into a Framework Agreement with the Contracting Authority and subsequently enter into individual contracts, using a call off contract template, with participating authorities via the call off procedure. In the interests of transparency and to make potential tenderers aware at the earliest stage, the incumbent contractor has indicated TUPE will apply to this procurement. As per the regulations, the incumbent contractor and new contractor awarded to the Framework as a result of this procurement must adhere to the TUPE regulations where they may apply. TUPE information will be provided to shortlisted tenderers in Stage 3.

Similar Contracts

Same NAICS industry code

NAICS: 541512
New
International
“Your Education Technology” An Open Framework (PA 2023) for the provision of ICT products, services, and solutions.
Solicitation # 868543
Nexus Multi Academy Trust is establishing an Open Framework, titled Your Education Technology, to provide a compliant route to market for ICT products, services, and solutions for publicly funded schools and colleges. Operating under the Procurement Act 2023, the framework is divided into three lots: Lot 1 for ICT Support and Managed Services, Lot 2 for Professional Services, and Lot 3 for Hardware. The framework has a maximum duration of eight years with an estimated total value of 1,000,000,000 GBP excluding VAT. There is no limit on the number of suppliers appointed to each lot, and the framework will be reopened periodically to allow new applicants. The award process utilizes an open procedure with evaluation criteria weighted at 60 percent for quality, 30 percent for qualitative pricing, and 10 percent for social value. While call-off contracts are generally awarded through competitive selection, exceptions are made for requirements below procurement thresholds, specialized technical or intellectual property needs, or cases where changing suppliers would cause disproportionate technical difficulties. Most individual awards are for an initial 12-month period with a possible 12-month extension, though Scheme 8 is limited to 12 months without an extension option. Tenders must be submitted in English via the designated supplier portal by October 30, 2026.
Nexus Multi-Academy Trust

POSTED

about 11 hours ago

DEADLINE

in 27 days
View Details
NAICS: 541512
New
SLED
Managed Services – College and Career Advising
Solicitation # 781-6-CB-20
The Texas Higher Education Coordinating Board (THECB) is seeking one or more long-term technology partners under solicitation 781-6-CB-20 to provide comprehensive Managed Services for its College and Career Advising technology portfolio. This engagement focuses on the operation, maintenance, enhancement, and modernization of a diverse ecosystem including ApplyTexas, My Texas Future, ADVi, Direct Admissions, Salesforce-based applications, Azure-hosted applications, and various enterprise integrations and databases. The selected vendor will be responsible for application operations, engineering execution, and proactive modernization to reduce technical debt and improve cybersecurity. Services must be delivered using Agile methodologies and DevSecOps principles, with a strong emphasis on accessibility compliance and a secure-by-design approach. The contract follows a fixed-fee pricing model based on dedicated delivery capacity through recurring Sprint Cycles, divided between a Design, Development, and Implementation team and a Support and Maintenance Services team. The initial term runs from execution through August 31, 2027, with options for four one-year renewals and a possible twelve-month extension for service continuity. Key requirements include TX-RAMP compliance for cloud services, mandatory criminal background checks for all personnel, and adherence to VetHUB subcontracting plans. Proposals are evaluated based on the respondent's technical approach, experience with public sector organizations, personnel certifications, and overall pricing value. All submissions must be filed electronically via the THECB Vendor Client Gateway by October 22, 2026.
Texas Higher Education Coordinating Board

POSTED

about 12 hours ago

DEADLINE

in 20 days
View Details
NAICS: 541512
New
SLED
Cybersecurity Risk Assessment — Water and Wastewater Systems
Solicitation # 2026-SECURE-01
The City of Ogdensburg is soliciting proposals for a comprehensive cybersecurity risk assessment of its municipally owned drinking water and wastewater systems. This project, identified as RFP No. 2026-SECURE-01, is funded by the New York State Environmental Facilities Corporation SECURE Program Assessment Grant. The selected consultant will be required to evaluate the systems using the NIST CSF 2.0 framework and CIA Triad principles to ensure compliance with New York State Department of Health and Department of Environmental Conservation regulations effective March 1, 2026. Key deliverables include draft and final risk assessment reports, regulatory gap analyses, prioritized remediation roadmaps, and non-sensitive executive summaries for grant submission. The contract has a strict not-to-exceed budget of 45,000 dollars, and any proposal exceeding this amount will be deemed non-responsive. Performance is expected to begin with contract execution in February 2027, with a draft report due within 120 calendar days of the notice to proceed. Award decisions will be based on a weighted evaluation of technical approach, firm qualifications, cost, personnel expertise, and the proposed schedule. Qualified firms must demonstrate experience with at least three similar engagements within the last five years and provide personnel with relevant certifications such as CISSP, CISM, GICSP, or CEH. Proposals must be submitted in a sealed package by November 20, 2026, including a signed cover letter, firm qualifications, a technical work plan, and required non-collusion and eligibility certifications.
City of Ogdensburg

POSTED

about 23 hours ago

DEADLINE

in about 2 months
View Details

Ready to Pursue This Opportunity?

Get AI-powered intelligence on this solicitation and the ones like it

Every page of the solicitation package shredded into a compliance breakdown

AI-powered matching based on your capabilities and past performance

Competitor and incumbent history on the requirement

Automated alerts on amendments, Q&A deadlines, and award

Miguel
Hillary
Keith Deutsch
Christine

Join 750+ contractors already using CLEATUS