Published

    Managed Security Operations Center (SOC) und Cisco Security Enterprise Agreement

    Notice number: ocds-mnwr74-785c47f0-4a2b-4547-9751-14570b80812b

    🇩🇪 GermanyUniversität zu Lübeck - Zentraler EinkaufGoods

    KEY INFORMATION

    Submission deadline
    Sep 22, 2026
    Location
    🇩🇪 Germany
    Contracting authority
    Universität zu Lübeck - Zentraler Einkauf
    Accepted Languages
    DEU
    Tender type
    Goods
    Contract Value
    Published date
    Aug 23, 2026

    TENDER DESCRIPTION

    This tender seeks the provision of a comprehensive Managed Security Operations Center (SOC) as a service, encompassing the supply, renewal, and maintenance of required software licenses. The core scope includes robust service design and transition, continuous license management, and full-spectrum service operation covering incident detection, automated response workflows, threat hunting, monitoring, reporting, and escalation processes, all underpinned by continuous service improvement. Key technical requirements mandate the utilization and administration of a specific security architecture centered on Cisco XDR, Cisco Secure Endpoint, Cisco Umbrella, Cisco DUO, Tenable Attack Surface Management (ASM), and Splunk Enterprise Security, ensuring seamless integration and no replacement of existing components. All data processing and data center locations must be within the EU, with the contract spanning 60 months from November 1, 2026, to October 31, 2031. Bidders must confirm sound financial standing and adherence to exclusion criteria as per German public procurement law.

    TENDER BRIEF

    The contract timeline is as follows:

    • Contract start date: 01.11.2026
    • Total duration: 60 months
    • Contract end date: Calculated to be 31.10.2031 (60 months after 01.11.2026).

    Sources

    • 1Preisblatt_20260653.xlsx — “Preisblatt,,,,,, Vergabe - 20260653,,,,,, ,,,,,, Bitte füllen Sie nur die grün hinterlegten Felder aus!,,,,,, ,,,,,, Firma:,,,,,, Name Ansprechpartner:,,,,,, Telefon-Nr.:,,,,,, E-Mail:,,,,,, ,,,,,, Hinweis:," - die Zahlu…
    • 2LV_Cisco SOC und Security EA.pdf — “Ausschreibung eines Managed Security Operations Center (SOC) an der Universität zu Lübeck Feld | Angabe Dokumententyp | Leistungsbeschreibung / Leistungsverzeichnis Auftraggeber | Universität zu Lübeck (nachfolgend „Auft…

    The core scope of work for this tender is the provision of a Managed Security Operations Center (SOC) as a service. This includes the supply, renewal, and maintenance of necessary software licenses.

    The Statement of Work (SOW) summarizes several key service areas and deliverables:

    • Service Design & Transition: This involves establishing a quality-assured operating model and optimizing the existing architecture for productive use. The contractor will analyze the current Cisco license and configuration, develop an optimization concept, and improve the operational state. The goal is to deliver a fully operational, documented SOC-Stack with clear responsibilities and ensure full utilization of existing licenses.
    • License Management - SOC Products: This service ensures continuous monitoring of license status and End-of-Life situations for all inventoried SOC platform components. License renewals will be communicated at least 90 days prior to expiration and initiated in coordination with the client, ensuring no unused or expired licenses, early planning security, and uninterrupted operations.
    • Service Operation: This encompasses several critical functions:
    • Incident Detection (Cisco XDR): Automated detection of security incidents via the Cisco XDR platform, including false-positive filtering and prioritization, continuously operated and optimized by the contractor.
    • Incident Response - Automated Workflows.
    • Threat Hunting & Threat Intelligence.
    • Monitoring, Reporting, and Control: This includes providing a dashboard for service performance monitoring (e.g., SLA compliance, incident status, license utilization) and generating monthly service reports. This aims to provide full transparency of the SOC platform's security status, measurable SLA fulfillment, and informed decision-making for future investments.
    • Escalation Processes: Ensuring security incidents are managed and escalated according to agreed-upon procedures and priority.
    • Continual Service Improvement (CSI): This involves the continuous enhancement of the SOC platform configuration and service quality through formal reviews and measurable optimization. Service reviews will be based on KPIs (MTTA, MTTR, False-Positive-Rate, SLA-Compliance-Rate), with identified optimization measures recorded and prioritized. This aims for sustainable quality improvement, regulatory compliance, and proactive adaptation to new threats.
    • Semi-annual Service Recap and Innovation Workshop: The contractor will conduct a service recap twice per calendar year to review performance based on key metrics and reports. Immediately following, an innovation workshop will be held to discuss further development of the Managed SOC and related infrastructure topics.
    • Data Processing and Location: All processing and data center locations must be within the EU due to the sensitive nature of processed personal data (identity, login, network, and communication metadata of students and employees).
    • Tenable Platform Integration: The contractor is responsible for enabling vulnerability scanning, prioritization, and attack surface management using Tenable Attack Surface Management (ASM). This includes providing customizable dashboards and automated reports within the Tenable platform for management and compliance. The operation, configuration, and onboarding of the Tenable platform are provided as a Managed Service, including integration with Cisco XDR and Splunk Enterprise Security.
    • Service Location: The service will primarily be delivered remotely or from the contractor's premises, with physical access to the client's site provided as needed or explicitly requested.

    Sources

    • 1LV_Cisco SOC und Security EA.pdf — “.9 | Reaktions- und Lösungszeiten. 4.3 | | 9 | 4.4 Sprache und Serviceort. | | 9 | 4.5 Servicebereiche 4.5.1 Service Design & Transition | | 10 10 | 4.5.2 Lizenzmanagement - SOC-Produkte. | | 11 | Service Operation. 4.6…
    • 2Anlage_A_Kriterienkatalog.xlsx — “Auftraggebers mittels der beim Auftraggeber eingesetzten Lösung Tenable Attack Surface Management (ASM) ermöglicht wird. Dies umfasst insbesondere die Identifikation und Bewertung von Domains, IP-Adressen, Zertifikaten s…

    Login to view all answers and insights

    Unlock tender brief for free

    TENDER DOCUMENTS

    DIRECTORY • 10 FILES

    • 2026_v1_Bieter_und_Eigenerklaerung.pdf
    • 2025_v1_Bewerbungsbedingungen_VgV.pdf
    • Anlage_A_Kriterienkatalog.xlsx

    and 3 other documents

    Login to view and download all tender documents

    Unlock documents for free

    ASK AI ABOUT THIS TENDER

    You

    Can a foreign company apply?

    Riko

    Yes, foreign companies can apply as long as they meet all the requirements set out in the procurement documents.

    Login to ask more questions.

    Unlock AI tender chat for free

    Unlock your tender workflow

    Run your first search, evaluate the results, save a daily monitor and start building a pipeline of tenders worth pursuing.

    First monitor on Day 1All features included in trialNo credit card required

    You may also be interested in

    Similar tenders