Published

    Część 1

    Notice number: 08df0759-80bd-fde3-ab56-940001856e5c

    🇵🇱 PolandMiejski zakład komunalny spółka z ograniczoną odpowiedzialnościąGoods

    KEY INFORMATION

    Submission deadline
    Sep 11, 2026
    Location
    🇵🇱 Poland
    Contracting authority
    Miejski zakład komunalny spółka z ograniczoną odpowiedzialnością
    Accepted Languages
    Polish
    Tender type
    Goods
    Contract Value
    Published date
    Aug 31, 2026

    TENDER DESCRIPTION

    This tender, titled "Part 1," seeks the delivery, installation, configuration, integration, and implementation of advanced cybersecurity solutions to enhance the IT infrastructure at Miejski Zakład Komunalny Sp. z o.o. in Stalowa Wola. The scope encompasses server-storage infrastructure, specifically two servers (including one for backup with deduplication) and a disk array with LTO, alongside a robust Web Application and API Protection (WAF/WAAP) system. Additionally, the project requires comprehensive protection for Microsoft 365 email against ransomware and other threats, including configuration, policy implementation, administrator training, and provision of all necessary licenses and support. Key technical requirements include support for various operating systems (e.g., Windows Server 2022/2025, RHEL 9.4/10.0) and virtualization platforms (e.g., VMware ESXi 8.0U3/9.0), Deep Packet Inspection (DPI), multi-factor authentication, and integration with Microsoft 365, all while adhering to strict cybersecurity standards. The entire execution, including delivery, installation, configuration, integration, and final acceptance, must be completed within 60 days from the contract's…

    TENDER BRIEF

    The contract timeline is as follows:

    • Contract Start Date: The agreement comes into effect on the date it is signed by both parties. The execution period for the subject of the agreement begins from its conclusion date.
    • End Date and Total Duration:
    • Execution of the Subject of the Agreement: This phase is to be completed within 60 days from the date the agreement is concluded, for both Part 1 and Part 2. The date of execution of the subject of the agreement is considered the date of signing the Final Acceptance Protocol.
    • Confidentiality Agreement: This agreement is concluded for a definite period of 5 years from its date of conclusion. The obligation of confidentiality applies during the offer preparation, procurement process, contract implementation, and for 5 years from the last disclosure of Confidential Information. For certain sensitive information (trade secrets, authentication data, active vulnerabilities, security architecture/configuration, or information whose disclosure could affect the disclosing party's security), the confidentiality obligation lasts as long as the information retains its confidential nature or significance for security.
    • Warranty, Service, Updates, and Subscriptions: These are realized for periods specified in Annex 3 to the SWZ. For solutions covered by the support period criterion, this period cannot be shorter than 12 months from final acceptance, or from the date of production launch if the OPZ links the start of the subscription to it.
    • Key Milestones or Phases:
    • Completion of the Subject of the Agreement: This must occur within 60 days from the contract's conclusion and includes delivery, installation, configuration, integration, tests, documentation handover, and final acceptance.
    • Final Acceptance Protocol: Signing this protocol marks the date of execution of the subject of the agreement.
    • Post-execution support: Warranty, service, updates, and subscriptions, which run for specified periods, generally at least 12 months after final acceptance or production launch.
    • Possibility of Extension: The contracting authority allows for an appropriate change to the contract performance deadline if the Grantor (specifically CPPC) permits an extension of the project implementation period or eligibility of expenses. This extension can include shifting deadlines for delivery, installation, configuration, integration, tests, documentation handover, final acceptance, and related organizational deadlines.

    Sources

    • 1Załącznik nr 6 do Umowy podstawowej - umowa o zachowaniu poufności NDA.docx — “oraz osób wyznaczonych do kontaktu każda ze Stron działa jako odrębny administrator danych. § 12. Okres obowiązywania Umowa wchodzi w życie z dniem jej podpisania przez obie Strony. Obowiązek zachowania poufności obowiąz…
    • 2Załącznik nr 5A do SWZ - Projektowane postanowienia umowy (PPU) Część 1.docx — “jej interfejs API, jeżeli występuje, wraz z testami, dokumentacją, instruktażem i wsparciem, dostawa, uruchomienie i konfiguracja rozwiązania cloud-to-cloud chroniącego pocztę elektroniczną Microsoft 365 Zamawiającego pr…
    • 3SWZ ZP.271.Pzp.8.2026.docx — “w równoważnym stopniu spełniają wymagania określone w opisie przedmiotu zamówienia. W przypadku kiedy Wykonawca zaoferuje produkt równoważny lub produkt spełniający normy równoważne wskazane przez Zamawiającego i nie zło…
    • 4Załącznik nr 6 do SWZ -Wniosek o udostępnienie danych i umowa poufności NDA.docx — “Umowy. Wykonawca ponosi odpowiedzialność za naruszenie postanowień Umowy przez jej pracowników lub współpracowników. §5 [Naruszenie Umowy] Wykonawca zgadza się, że ujawnienie Informacji Poufnych osobom trzecim lub wykorz…
    • 5Załącznik nr 5B do SWZ - Projektowane postanowienia umowy (PPU) Część 2.docx — “po zawarciu Umowy Grantodawca, w szczególności CPPC, dopuści możliwość przedłużenia terminu realizacji projektu albo kwalifikowalności wydatków dla Zamawiającego, w jakiejkolwiek prawnie lub organizacyjnie skutecznej for…

    • PTES (Penetration Testing Execution Standard) or equivalent methodology
    • CVSS (Common Vulnerability Scoring System) or equivalent scale for vulnerability classification
    • OSCP/OSCP+ certification
    • OSWE certification
    • OSEP certification
    • PNPT certification
    • eWPTX certification
    • CPTS certification
    • CRTO certification
    • NTP (Network Time Protocol) for time synchronization
    • MFA (Multi-Factor Authentication)
    • Constant Internet access with guaranteed bandwidth not less than 512 kb/s
    • PC or MAC class computer
    • Web browser supporting TLS 1.2
    • Java Script support enabled
    • Acrobat Reader or other program supporting .pdf files
    • Supported file formats: txt, rtf, pdf, xps, odt, ods, odp, doc, xls, ppt, docx, xlsx, pptx, csv, jpg, jpeg, tif, tiff, geotiff, png, svg, wav, mp3, avi, mpg, mpeg, mp4, m4a, mpeg4, ogg, ogv, zip, tar, gz, gzip, 7z, html, xhtml, css, xml, xsd, gml, rng, xsl, xslt, tsl, xmlsig, xades, pades, cades, asic, asics, sig, xmlenc, dxf, ath, prd
    • Single file size limit up to 2 GB
    • Modbus protocol analysis
    • S7+ protocol analysis
    • S7 protocol analysis
    • Profinet protocol analysis
    • HL7 protocol analysis
    • EtherNet/IP protocol analysis
    • GOOSE protocol analysis
    • MAsterBus300 protocol analysis
    • DLMS/COSEM protocol analysis
    • IEC 101/102/103/104 protocol analysis
    • SLMP protocol analysis
    • IXL protocol analysis
    • BACNET protocol analysis
    • Threat Intelligence database for OT environments
    • Machine Learning (ML) for behavioral analysis
    • Integration with FortiGate firewalls
    • Integration with Palo Alto firewalls
    • Integration with Cisco ASA firewalls
    • Integration with Cisco ISE firewalls
    • Integration with Stormshield SNS firewalls
    • Integration with Barracuda firewalls
    • Integration with TXOne OT Defense Console firewalls
    • Integration with Tanium SIEM systems
    • Integration with ServiceNow SIEM systems
    • Integration with IBM QRadar SIEM systems
    • Integration with Splunk SIEM systems
    • Integration with NetWitness SIEM systems
    • Integration with Kafka SIEM systems
    • Active Directory integration
    • SSL support
    • IPv4 support
    • IPv6 support
    • SNMP v3 support
    • RESTful API
    • Integrated Remote Console for Windows clients
    • DNS/DHCP for network auto-configuration
    • HTML5 for graphical interface
    • PowerShell for REST API
    • Virtual appliance format for management software
    • VMware vSphere ESXi 8.x (supported hypervisor for management software)
    • Microsoft Hyper-V Server 2022 (supported hypervisor for management software)
    • VMware (supported hypervisor for virtual environment platforms)
    • Hyper-V (supported hypervisor for virtual environment platforms)
    • KVM (supported hypervisor for virtual environment platforms)
    • XEN (supported hypervisor for virtual environment platforms)
    • Minimum 1 Gbps throughput
    • Minimum 1000 protected IP/MAC address points
    • Minimum 20000 protected network elements
    • Minimum 4000 protected IoT devices
    • SFTP for backup
    • Two-factor authentication
    • Microsoft Windows Server 2022 (supported operating system)
    • Microsoft Windows Server 2025 (supported operating system)
    • Red Hat Enterprise Linux (RHEL) 9.4 (supported operating system)
    • Red Hat Enterprise Linux (RHEL) 10.0 (supported operating system)
    • SUSE Linux Enterprise Server (SLES) 15 SP6 (supported operating system)
    • SUSE Linux Enterprise Server (SLES) 16 (supported operating system)
    • VMware ESXi 8.0U3 (supported virtualization system)
    • VMware ESXi 9.0 (supported virtualization system)
    • Server operating system with ability to utilize 320 logical processors and at least 4 TB RAM in physical environment
    • Server operating system with ability to utilize 64 virtual processors, 1TB RAM, and disk up to 64TB
    • Deep Packet Inspection (DPI)
    • WAF/WAAP (Web Application Firewall/Web Application and API Protection)

    Sources

    • 1Załącznik nr 1B do SWZ - Formularz Techniczny dla Części 2.docx — “i wydajność | Minimum 1 000 punktów adresowych IP/MAC, 20 000 elementów sieci, 4 000 urządzeń IoT oraz przepustowość minimum 1 Gbps. | Uzupełnij | Uzupełnij | Kontrola dostępu i audyt | Role administracyjne, MFA, rejestr…
    • 2SWZ ZP.271.Pzp.8.2026.pdf — “dopuszcza się podpisanie dokumentów w formacie innym niż pdf", wtedy będzie wymagany oddzielny plik z podpisem. W związku z tym Wykonawca będzie zobowiązany załączyć, prócz podpisanego dokumentu, oddzielny plik z podpise…
    • 3Załącznik nr 3 OPZ IT i OT aktualizacja 01.09.2026.docx — “analizy protokołów: Modbus, S7+, S7, Profinet, HL7, EtherNet/IP, GOOSE, MAsterBus300, DLMS/COSEM, IEC 101/102/103/104, SLMP, IXL, BACNET. System musi mieć wbudowaną i aktualizowaną bazę zagrożeń Threat Intelligence dedyk…
    • 4Załącznik nr 3 do SWZ - OPZ IT i OT.docx — “wzorcowego schematu. System musi mieć możliwość integracji z systemami typu firewall takimi jak: FortiGate, Palo Alto, Cisco ASA, Cisco ISE, Stormshield SNS, Barracuda, TXOne OT Defense Console, integracja powinna umożli…
    • 5Załącznik nr 1A do SWZ Formularz Techniczny dla Części 1 aktualizacja 01.09.2026.docx — “lub SFTP. Musi istnieć możliwość utworzenia harmonogramu automatycznego tworzenia kopii zapasowych. Oprogramowanie zarządzające musi mieć możliwość obsługi co najmniej 700 serwerów w swoim interfejsie. | Uzupełnij | Uzup…

    Login to view all answers and insights

    Unlock tender brief for free

    TENDER DOCUMENTS

    DIRECTORY • 21 FILES

    • zmiana treści SWZ i załączników do SWZ.pdf
    • Załącznik nr 1A do SWZ - Formularz Techniczny dla Części 1.docx
    • Załącznik nr 3 OPZ IT i OT aktualizacja 01.09.2026.docx

    and 14 other documents

    Login to view and download all tender documents

    Unlock documents for free

    ASK AI ABOUT THIS TENDER

    You

    Can a foreign company apply?

    Riko

    Yes, foreign companies can apply as long as they meet all the requirements set out in the procurement documents.

    Login to ask more questions.

    Unlock AI tender chat for free

    Unlock your tender workflow

    Run your first search, evaluate the results, save a daily monitor and start building a pipeline of tenders worth pursuing.

    First monitor on Day 1All features included in trialNo credit card required

    You may also be interested in

    Similar tenders