Published

    Managed Security Services und Aufbau eines Security Operation Centers

    Notice number: ocds-mnwr74-e6a6653d-4919-4ed3-9226-a509de9ee095

    🇩🇪 GermanyUniversität HamburgServices

    KEY INFORMATION

    Submission deadline
    Sep 21, 2026
    Location
    🇩🇪 Germany
    Contracting authority
    Universität Hamburg
    Accepted Languages
    DEU
    Tender type
    Services
    Contract Value
    Published date
    Aug 21, 2026

    TENDER DESCRIPTION

    This tender seeks a Managed Security Service Provider (MSSP) to establish and operate a Security Operations Center (SOC) for multiple Hamburg universities, delivering comprehensive IT security services including 24/7 Managed Detection and Response (MDR), Computer Emergency Response Team (CERT) functions, Incident Response (IR), and Security Information and Event Management (SIEM) system operation. The scope encompasses continuous vulnerability management, threat intelligence, provision of network sensors, and proactive threat hunting, with the SIEM platform capable of processing 4-6 TB of daily data. Service providers must adhere to stringent technical requirements, including ISO 27001 (for data center, SOC, and SIEM), SOC 2 Type 2, and C5-Katalog certifications, operating from at least two geographically distributed data center locations within the European Economic Area (EEA) using a sovereign, auditable technology stack. Required methodologies include DFN-CERT integration, ITIL standards for ITSM, and incident management based on frameworks like MITRE ATT&CK, ensuring SOC core team and Incident Response Team reactivity within 24 hours. Bidders must demonstrate robust economic…

    TENDER BRIEF

    The contract is expected to start directly after the contract award, likely in the 1st quarter of 2027. The initial duration of the contract is 12 months. The client has the option to extend the contract multiple times, each time for an additional 12 months, or until the specified maximum budget is exhausted.

    Key milestones and phases of the procurement process include:

    • Teilnahmewettbewerb (Participation Competition): Week 34 to Week 38.
    • Selection of bidders and invitation to submit a first offer: Presumably until Week 39.
    • Period for bidders to prepare a first offer: Presumably Week 40 to Week 43.
    • Evaluation of first offers: Presumably until Week 44.
    • Negotiation round: Presumably Week 45 to Week 46.
    • Invitation and period for submitting a (final) offer: Presumably Week 47 to Week 50.
    • Evaluation of final offers: Presumably until Week 53.
    • Contract award and availability of the service provider: Presumably January 2027.

    Sources

    • 1Unterlagen\Vergabeunterlagen.pdf — “der Freien und Hansestadt Hamburg vorliegende Leistungsbeschreibung und Vertragsbedingungen Bestimmungen der dem Vergabeverfahren zu Grunde liegenden Vergabeunterlagen inkl. etwaiger Bieterkommunikation Zusätzliche Bedin…

    The core scope of work for this tender involves the provision of IT services to support Hamburg universities with Managed Security Services, including the establishment and operation of a Security Operation Center (SOC). The services aim to centrally collect, monitor, analyze, and evaluate security-relevant events within the IT environments of the participating universities.

    The Statement of Work summary includes the following core deliverables and services:

    • Managed Security Services and Security Operation Center (SOC) Establishment and Operation: This is the overarching goal, providing a comprehensive security framework for the universities.
    • Computer Emergency Response Team (CERT) Services: Provision of CERT services, including DFN-CERT integration.
    • Threat Intelligence: Delivering threat intelligence as an enrichment for specific cases.
    • 24/7 Managed Detection and Response (MDR) Services: Operating a 24/7 SOC with active security monitoring and alert triage.
    • Automation of Reactions to Security Incidents and Incident Response (IR): Developing and implementing automated responses and handling security incidents.
    • Security Information and Event Management (SIEM) System Operation: Providing and operating a multi-client university SIEM platform and a portal with capabilities for daily data processing (4-6 TB), integration of identity providers, role-based access, and defined storage/deletion concepts.
    • Vulnerability Scans and Vulnerability Management: Conducting continuous vulnerability scans, prioritizing results, and performing annual scans of managed endpoints using a Thor-Scanner.
    • Provision of Network Sensors: Supplying network sensors with active monitoring based on a sovereign, auditable technology stack (primarily open source).
    • Integration and Onboarding: Integrating existing IT systems into monitoring, implementing interfaces for asset representation, and facilitating standardized project onboarding for universities, including defining information networks, risks, use cases, data sources, and interfaces.
    • Threat Hunting: Proactive searching for threats within the network.
    • Case Management: Classic case processing, including communication and follow-up based on frameworks like MITRE ATT&CK.
    • Use-Case-Library Maintenance and Engineering: Managing and expanding a library of security use cases in collaboration with universities.
    • Continuous Improvement: Implementing continuous improvement processes based on PDCA (Plan-Do-Check-Act).
    • Service Level Agreements (SLAs): Defining criticality-dependent SLAs with each university.
    • Central Services: Operating a Central Services component within university data centers to provide sensor information for research, including an R&D platform and data protection concepts for research integration.
    • IT Service Management (ITSM): Integration of ITIL standards into ITSM processes.
    • Platform, Hardware, and Licenses: All necessary platforms, hardware, and licenses must be provided as part of the offering.

    Sources

    • 1Unterlagen\Vergabeunterlagen.pdf — “und Aufbau eines Security Operation Centers Gegenstand der Ausschreibung ist die Vergabe von IT-Dienstleistungen zur Unterstützung der Hamburger Hochschulen durch Managed Security Services inkl. eines Security Operation…

    Login to view all answers and insights

    Unlock tender brief for free

    TENDER DOCUMENTS

    DIRECTORY • 2 FILES

    • Unterlagen\Vergabeunterlagen.pdf
    • Bekanntmachung\Auftragsbekanntmachung.pdf

    Login to view and download all tender documents

    Unlock documents for free

    ASK AI ABOUT THIS TENDER

    You

    Can a foreign company apply?

    Riko

    Yes, foreign companies can apply as long as they meet all the requirements set out in the procurement documents.

    Login to ask more questions.

    Unlock AI tender chat for free

    Unlock your tender workflow

    Run your first search, evaluate the results, save a daily monitor and start building a pipeline of tenders worth pursuing.

    First monitor on Day 1All features included in trialNo credit card required

    You may also be interested in

    Similar tenders