Published
Ausschreibung SIEM-MSOC
Notice number: ocds-mnwr74-95611c28-c715-4dde-b2ca-09ca80d62678
KEY INFORMATION
- Submission deadline
- • Sep 25, 2026
- Location
- 🇩🇪 Germany
- Contracting authority
- Hamburger Energiewerke GmbH
- Accepted Languages
- DEU
- Tender type
- Services
- Contract Value
- Published date
- Aug 23, 2026
TENDER DESCRIPTION
This tender seeks a comprehensive, fully managed Security Information and Event Management (SIEM) and Managed Security Operations Center (MSOC) solution for the Office IT environment of Hamburger Energiewerke GmbH, excluding power plant and OT systems. The scope encompasses the introduction, provision, operation, and continuous development of a system for attack detection, including SIEM/Log Management, Managed SOC services for continuous monitoring and escalation, and Incident Response capabilities, supporting approximately 1,500 users and 2,000 endpoints. Key technical requirements mandate an ISMS compliant with ISO/IEC 27001:2022 or equivalent, with all data storage, processing, and Managed SOC services exclusively within the European Union or Switzerland, and critical communications and documentation in German. Financially, bidders must demonstrate an average annual net turnover of at least €1 million in MDR/SOC services over the last three years and hold business liability insurance with a minimum coverage of €3 million for property damage and €0.5 million for personal injury. The contract features a basic term of 36 months from the service start, extendable twice by 12…
TENDER BRIEF
The contract timeline is as follows:
Contract Start Date: The project and implementation are planned to start within 14 calendar days after the contract conclusion.
Contract End Date: Not explicitly stated as a fixed date, as it depends on the start date and potential extensions.
Total Duration: The contract has a basic term of 36 months from the contractually agreed start of services. The client has the option to extend the contract twice, each time by 12 months, making the maximum contract term 60 months.
Key Milestones/Phases (Preliminary Schedule):
- Submission/Publication of the procurement procedure: August 21, 2026
- Deadline for applicant questions in the participation competition: September 14, 2026, 12:00 PM
- Deadline for participation applications: September 25, 2026, 12:00 PM
- Review of participation applications and selection of applicants: Approximately October 2026
- Invitation to submit a first offer: Approximately October 19, 2026
- Deadline for bidder questions in the offer phase: November 2, 2026, 12:00 PM
- Deadline for first offers: November 16, 2026, 10:00 AM
- Review, evaluation, and, if necessary, negotiation of first offers: Approximately November/December 2026
- Invitation to submit final offers, if required: Approximately December 2026
- Deadline for submission of final offers, if required: Approximately December 2026
- Information of unsuccessful bidders according to § 134 GWB: Approximately January 2027
- Award and contract placement: Earliest after the legal waiting period according to § 134 GWB, approximately December 2026
- Binding period for offers: Until February 8, 2027, inclusive
- Planned start of services: Within 14 calendar days after contract conclusion.
- Transition to regular operation: Occurs after completion of the agreed implementation, testing, and acceptance activities.
Sources
- 112 Leistungsverzeichnis SIEM_MSOC_HEnW.pdf — “| 14.09.2026, 12:00 Uhr Ablauf der Teilnahmefrist / Endtermin für Teilnahmeanträge | 25.09.2026, 12:00 Uhr Prüfung der Teilnahmeanträge und Auswahl der Bewerber | voraussichtlich Oktober 2026 Aufforderung zur Abgabe eine…”
The core scope of work for this tender is the introduction, provision, operation, and continuous development of a system for attack detection specifically for the Office IT environment of Hamburger Energiewerke GmbH. This excludes power plant, production, and OT systems.
The statement of work summarizes a comprehensive, integrated model that includes:
- The provision and operation of a SIEM (Security Information and Event Management)/Log Management solution.
- A Managed SOC (Security Operations Center) service, responsible for continuous monitoring, analysis, evaluation, and escalation of security-relevant events.
- Incident Response (IR) services, providing support for the analysis, coordination, containment, and handling of security incidents.
All these services are to be delivered as a Fully Managed Service, where the contractor assumes full technical, professional, and operational responsibility for the solution's provision, implementation, and operation. This includes the dimensioning, delivery, installation, configuration, scalability, performance, operational readiness, maintainability, security (including backups), and maintenance of all necessary hardware, software, and platform components.
Key deliverables and phases explicitly stated include:
- Developing an implementation concept detailing project phases, dependencies, and client contributions.
- Project kick-off.
- Detailed conceptual design and coordination of operational processes.
- Onboarding of prioritized log and data sources.
- Configuration of agreed use cases, reporting channels, escalation paths, and dashboards.
- A test phase, including defined attack scenarios and communication pathways.
- Documentation and operational handover, which involves training client personnel on the solution's functions, processes, usage, and interpretation of dashboards, reports, KPIs, and incidents.
- Transition into regular operation.
The solution should support approximately 1,500 networked users, 2,000 endpoints, and an initial log volume of around 100 GB per day within a hybrid IT environment that includes local infrastructure, Microsoft 365, and Azure services.
Sources
- 112 Leistungsverzeichnis SIEM_MSOC_HEnW.pdf — “Beschreibung Auftragsgegenstand Gegenstand des Vergabeverfahrens ist die Einführung, Bereitstellung, der Betrieb und die kon- tinuierliche Weiterentwicklung eines Systems zur Angriffserkennung für die Office-IT der Ham-…”
Login to view all answers and insights
Unlock tender brief for freeTENDER DOCUMENTS
DIRECTORY • 16 FILES
- Vertraulichkeitsvereinbarung.docx59 KBDOCX
- 14 Anlage_Formblatt Kunden-Referenzen.xlsx27 KBXLSX
- 15 Anlage_Formblatt Mitarbeiter-Referenzen.xlsx19 KBXLSX
and 9 other documents
Login to view and download all tender documents
Unlock documents for freeASK AI ABOUT THIS TENDER
Can a foreign company apply?
Yes, foreign companies can apply as long as they meet all the requirements set out in the procurement documents.
Login to ask more questions.
Unlock AI tender chat for freeUnlock your tender workflow
Run your first search, evaluate the results, save a daily monitor and start building a pipeline of tenders worth pursuing.