Published
Managed Security Operations Center (SOC) und Cisco Security Enterprise Agreement
Notice number: 00583172-2026
KEY INFORMATION
- Submission deadline
- • Sep 22, 2026
- Location
- 🇩🇪 Germany
- Contracting authority
- Universität zu Lübeck - Zentraler Einkauf
- Accepted Languages
- German
- Tender type
- Goods
- Contract Value
- Published date
- Aug 24, 2026
TENDER DESCRIPTION
This tender seeks a comprehensive Managed Security Operations Center (SOC) as a service, encompassing the provision, extension, and maintenance of essential software licenses for continuous 24/7 security operations with defined response and resolution times. The core scope includes service design and transition, proactive license management for SOC products, and robust service operations featuring automated security incident detection via the Cisco XDR platform, incident response, threat hunting, and threat intelligence, alongside detailed monthly and executive reporting. Key technical requirements mandate expertise and operation across a range of technologies, including Cisco XDR, Secure Endpoint, Umbrella, DUO, Secure Access, Secure Email, Splunk Enterprise Security, and Tenable platforms (ASM, Tenable One), alongside adherence to the MITRE ATT&CK Framework and relevant professional certifications. The contract is set to commence on November 1, 2026, for a duration of 60 months, concluding on October 31, 2031, with half-yearly service recap and innovation workshops, while requiring all data processing and data center locations to be within the EU. Financial standing…
TENDER BRIEF
The contract start date is November 1, 2026. The total duration of the contract is 60 months. Based on a start date of November 1, 2026, and a duration of 60 months, the contract end date would be October 31, 2031.
Key milestones or phases include a "Termin- und Leistungsplan" (Timeline and Performance Plan) that is expected to be detailed in a table or an appendix. Additionally, there are half-yearly "Service-Recap und Innovationsworkshop" (Service Recap and Innovation Workshop) conducted twice per calendar year, specifically at the end of each calendar half-year.
Sources
- 1Preisblatt_20260653.xlsx — “Preisblatt,,,,,, Vergabe - 20260653,,,,,, ,,,,,, Bitte füllen Sie nur die grün hinterlegten Felder aus!,,,,,, ,,,,,, Firma:,,,,,, Name Ansprechpartner:,,,,,, Telefon-Nr.:,,,,,, E-Mail:,,,,,, ,,,,,, Hinweis:," - die Zahlu…”
- 2EVB_IT_Systemlieferungsvertrag.docx — “zur Vergütung nach Aufwand Besondere Bestimmungen zur Vergütung nach Aufwand sind in Anlage Nr. _____ vereinbart. Preisanpassung für Systemserviceleistungen, die nicht im Pauschalfestpreis enthalten sind Gemäß Ziffer 8.6…”
- 3EVB_IT_Systemlieferungsvertrag_Muster.pdf — “gesondert vergütet. Reisezeiten werden zu 50% als Arbeitszeiten vergütet. Reisezeiten werden vergütet gemäß Anlage Nr. Besondere Bestimmungen zur Vergütung nach Aund Besondere Bestimmungen zur Vergütung nach Aufyd sind i…”
- 4LV_Cisco SOC und Security EA.pdf — “kooperativer, vertrauensvoller Prozess zwischen Auftraggeber und Auf- tragnehmer gestalten. 5.2 Zusammenarbeit Die Zusammenarbeit zwischen den Vertragspartnern erfolgt auf Basis der klar definierten RACI-Matrix (Responsi…”
The core scope of work for this tender involves the provision of a Managed Security Operations Center (SOC) as a service, including the necessary software licenses (provision, renewal, and maintenance).
The Statement of Work summary and core deliverables include:
- Service Design & Transition: Building a quality-assured operating model and optimizing the existing architecture for productive operation. This involves analyzing Cisco licenses and configurations, developing an optimization concept, and improving the operational state to ensure a fully operational and documented SOC stack with clear responsibilities and full utilization of licenses.
- License Management - SOC Products: Continuous monitoring of license status and End-of-Life (EOL) situations for all inventoried SOC platform components. The contractor is responsible for monitoring license durations and EOL/EOS announcements, communicating renewals at least 90 days prior to expiration, and initiating them in coordination with the client to prevent unused or expired licenses and ensure planning security.
- Service Operation: This encompasses several key functions:
- Automated detection of security incidents using the Cisco XDR platform, including false-positive filtering and prioritization.
- Incident Response with automated workflows.
- Threat Hunting & Threat Intelligence.
- Monitoring, Reporting, and Control.
- Reporting: Generation of monthly service reports and executive reports, detailing Key Performance Indicators (KPIs), SLA fulfillment, security status, and recommendations to provide transparency and a basis for future investments.
- Continual Service Improvement (CSI): Ongoing improvement of the SOC platform configuration and service quality through formal review processes and measurable optimization efforts. This includes service reviews and innovation workshops based on KPIs, and prioritizing identified optimization measures like new Cisco XDR correlation rules or policy adjustments within the existing platform.
- Half-yearly Service Recap and Innovation Workshop: Conducted twice a year to review past performance based on metrics and service reports, and to discuss further development topics for the Managed SOC and related infrastructure.
- Operation & Integration as Managed Service (Tenable): Providing managed services for the operation, configuration, and onboarding of the Tenable platform, including its integration into the existing SOC toolchain with Cisco XDR and Splunk Enterprise Security.
- Dashboards & Reporting (Tenable One): Ensuring the availability of customizable dashboards and automated reports within the Tenable platform for management and compliance purposes.
- Asset Inventory & Vulnerability Management (Tenable ASM): Enabling the client to identify and evaluate domains, IP addresses, certificates, and cloud resources using Tenable Attack Surface Management (ASM).
- Escalation Processes in the SOC: Establishing and adhering to defined escalation processes for security incidents based on their priority.
The service delivery is primarily remote or at the contractor's premises, with physical access to the client's site provided as needed. All data processing and data center locations must be within the EU.
Sources
- 1LV_Cisco SOC und Security EA.pdf — “.9 | Reaktions- und Lösungszeiten. 4.3 | | 9 | 4.4 Sprache und Serviceort. | | 9 | 4.5 Servicebereiche 4.5.1 Service Design & Transition | | 10 10 | 4.5.2 Lizenzmanagement - SOC-Produkte. | | 11 | Service Operation. 4.6…”
- 2Anlage_A_Kriterienkatalog.xlsx — “Auftraggebers mittels der beim Auftraggeber eingesetzten Lösung Tenable Attack Surface Management (ASM) ermöglicht wird. Dies umfasst insbesondere die Identifikation und Bewertung von Domains, IP-Adressen, Zertifikaten s…”
Login to view all answers and insights
Unlock tender brief for freeTENDER DOCUMENTS
DIRECTORY • 10 FILES
- 2025_v1_Bewerbungsbedingungen_VgV.pdf583 KBPDF
- LV_Cisco SOC und Security EA.pdf289 KBPDF
- Eigenerklärung Lieferkettensorgfaltspflichtengesetz.pdf151 KBPDF
and 3 other documents
Login to view and download all tender documents
Unlock documents for freeASK AI ABOUT THIS TENDER
Can a foreign company apply?
Yes, foreign companies can apply as long as they meet all the requirements set out in the procurement documents.
Login to ask more questions.
Unlock AI tender chat for freeUnlock your tender workflow
Run your first search, evaluate the results, save a daily monitor and start building a pipeline of tenders worth pursuing.