Published

    Managed Security Services und Aufbau eines Security Operation Centers

    Notice number: 00580618-2026

    🇩🇪 GermanyUniversität HamburgServices

    KEY INFORMATION

    Submission deadline
    Sep 21, 2026
    Location
    🇩🇪 Germany
    Contracting authority
    Universität Hamburg
    Accepted Languages
    German
    Tender type
    Services
    Contract Value
    Published date
    Aug 21, 2026

    TENDER DESCRIPTION

    This tender seeks a Managed Security Service Provider (MSSP) to establish and operate a Security Operations Center (SOC) for multiple Hamburg universities, ensuring comprehensive information security through 24/7 Managed Detection and Response (MDR), SIEM operations, Incident Response, and continuous vulnerability management. Key technical requirements include the provision and operation of a multi-client university SIEM platform capable of processing 4-6 TB of daily data, utilizing a sovereign and auditable technology stack (e.g., Open Source), and ensuring data processing within the EWR/EU, all supported by redundant infrastructure and two geographically distributed data centers. The contract is projected to commence in Q1 2027 for an initial 12-month period, with options for extension, and bidders must demonstrate a minimum turnover of >500,000 EUR in relevant managed security services for public scientific clients over the last three years. Adherence to standards such as OCSF, ITIL, and the MITRE ATT&CK framework, along with support for both German and English communication, is essential.

    TENDER BRIEF

    Question: What is the contract timeline?

    Context: Contract start date, end date, total duration, and any key milestones or phases mentioned. Return null if not stated.

    The contract is expected to start directly after the award, likely in the 1st quarter of 2027. The initial duration of the contract is 12 months. The client has the option to extend the contract multiple times, each for an additional 12 months, or until the maximum budget specified in section 11 is utilized. Further funding from the BWFG may also lead to the continuation of the contract.

    Key milestones and phases of the procedure are:

    • Participation Competition: Calendar Week (KW) 34 to KW 38.
    • Selection of bidders and invitation to submit a first offer: Approximately until KW 39.
    • Period for bidders to prepare a first offer: Approximately KW 40 to KW 43.
    • Evaluation of first offers: Approximately until KW 44.
    • Negotiation round: Approximately KW 45 to KW 46.
    • Invitation and period for submitting a (final) offer: Approximately KW 47 to KW 50.
    • Evaluation of final offers: Approximately until KW 53.
    • Award of contract and availability of the service provider: Approximately January 2027.

    Sources

    • 1Unterlagen\Vergabeunterlagen.pdf — “Bestimmungen der Freien und Hansestadt Hamburg vorliegende Leistungsbeschreibung und Vertragsbedingungen Bestimmungen der dem Vergabeverfahren zu Grunde liegenden Vergabeunterlagen inkl. etwaiger Bieterkommunikation Zusä…

    The core scope of work for this tender involves the provision of IT services to support Hamburg universities through Managed Security Services, including the establishment and operation of a Security Operation Center (SOC).

    Key services and deliverables include:

    • Centralized Security Event Management: Collection, monitoring, analysis, and evaluation of security-relevant events within the IT environments of the participating universities.
    • CERT Services: Operation of CERT services, including Threat Intelligence.
    • Security Operation Center (SOC) Operations:
    • 24/7 Managed Detection and Response (MDR) services.
    • 24/7 active security monitoring and alert triage.
    • Provision of network sensors and active monitoring based on a sovereign technology stack (primarily open source and auditable source code).
    • Integration of existing IT systems into monitoring (especially SIEM and network).
    • Implementation of an interface from network sensors to existing systems for asset representation, including filtering options for defined subnets.
    • Threat Hunting.
    • Provision of Indicators of Compromise.
    • Case management (e.g., based on MITRE ATT&CK framework).
    • Additional Threat Intelligence for specific cases.
    • Maintenance of a Use Case Library, with a standard library to be adapted and expanded with universities.
    • Detection and Use Case Engineering tailored to university needs.
    • Continuous improvement based on PDCA (e.g., false positives).
    • SIEM Operations: Operation of a Security Information and Event Management (SIEM) system.
    • Incident Response: Automation of reactions to detected security incidents and incident response.
    • Vulnerability Management:
    • Conducting continuous vulnerability scans, including evaluation and reporting.
    • Prioritization of scan results in consultation with universities.
    • Annual scans of managed endpoints using Thor-Scanner (Nextron).
    • Platform, Hardware, and Licenses: All necessary platforms, hardware, and licenses must be presented as part of the offer.
    • Standardized Project Onboarding:
    • Kick-off meeting with all stakeholders for project planning.
    • Development of communication and escalation concepts.
    • Definition of the information network, including protection needs analysis and identification of critical systems and processes.
    • Definition of relevant risks and use cases.
    • Definition of data sources and interfaces.
    • Connection of existing systems (XDR, SIEM, MDR, Logging systems, etc.).
    • Data-Onboarding, normalization, and integration engineering.
    • DFN-CERT Integration: Participation in DFN-CERT integration, including technical and process integration, coordination of collaboration, and quality management.
    • Provision and Operation of a Multi-Client University SIEM Platform and Portal:
    • Redundant data platform operated in UHH data centers or UHH partners, with integration of other universities.
    • Portal operation at universities or by the contractor, preferably at universities.
    • Maintenance (updates, patches) if a university operates the portal.
    • Requirements include multi-client capability, processing of 4-6 TB data daily, integration of SSO providers (Shibboleth, Keycloak), logical-technical client separation, user portal with role-based access and interaction with SOC, role and authorization concepts, storage and deletion concepts, auditable logging, high availability strategies, redundant infrastructure, regular backups, recovery concept, continuous monitoring, and update/upgrade concept.
    • Integration of ITIL standards and ITSM processes.
    • Central Services: Provision and development of central services (e.g., quality assurance, responsibilities), research and development platform (R&D platform), data protection concept for research integration, access controls, security measures, logging of relevant data and actions, definition and export of anonymized and released data, tool-independent data pipeline for reporting, and training and documentation.
    • Sensor Technology and Telemetry: Deployment of the contractor's own network sensor technology for data collection, monitoring, and analysis from various systems and sources.
    • Collaboration and Reporting: Collaboration with university departments, information security officers, the Regional Computing Center (RRZ), subcontractors, and other external service providers. This includes joint sprint/takt planning, transparent capacity planning, and regular reporting on status, risks, throughput times, and key performance indicators.
    • Cost Scaling: Modular cost structure for service delivery to reflect the staggered integration of individual universities.The core scope of work and statement of work summary for this tender centers on providing Managed Security Services, including the establishment and operation of a Security Operation Center (SOC), to support Hamburg universities. The services aim for centralized collection, monitoring, analysis, and evaluation of security-relevant events within the universities' IT environments.

    Key deliverables and services explicitly stated include:

    • SOC Operations: This involves 24/7 Managed Detection and Response (MDR) services, active security monitoring, alert triage, threat hunting, and the provision of Indicators of Compromise. It also encompasses case management (e.g., using the MITRE ATT&CK framework), additional threat intelligence, and maintaining a Use Case Library tailored to university needs.
    • SIEM Management: The operation of a Security Information and Event Management (SIEM) system is a core component.
    • Incident Response and Automation: The tender requires the automation of responses to detected security incidents and comprehensive incident response services.
    • Vulnerability Management: This includes continuous vulnerability scans with evaluation and reporting, prioritization of results, and annual scans of managed endpoints using specific tools like Thor-Scanner (Nextron).
    • Platform and Infrastructure: The contractor must provide all necessary platforms, hardware, and licenses as part of their offering.
    • Standardized Project Onboarding: A structured onboarding process is required, including kick-off meetings, developing communication and escalation concepts, defining the information network (including protection needs analysis and critical system identification), defining risks, use cases, data sources, and interfaces. It also covers connecting existing systems (XDR, SIEM, MDR, logging systems) and data onboarding, normalization, and integration engineering.
    • DFN-CERT Integration: The contractor is expected to participate in DFN-CERT integration, covering technical and process integration, coordination of collaboration, and quality management.
    • Multi-Client SIEM Platform and Portal: Provision and operation of a redundant, multi-client university SIEM platform and a user portal, preferably hosted at the universities. This platform must handle 4-6 TB of daily data, integrate Single Sign-On (SSO) providers, ensure logical-technical client separation, offer role-based access, and adhere to defined role, authorization, storage, and deletion concepts. High availability, regular backups, recovery concepts, continuous monitoring, and update/upgrade strategies are also crucial, alongside the integration of ITIL standards and ITSM processes.
    • Central Services: The solution must include a Central Services component, operated in university data centers, to provide sensor information for researchers. This involves basic operation and development, a research and development platform, a data protection concept for research integration, access controls, security measures, comprehensive logging, and definitions/export of anonymized data.
    • Sensor Technology and Telemetry: The contractor is responsible for deploying their own network sensor technology for data collection, monitoring, and analysis.
    • Collaboration and Reporting: The scope includes close cooperation with university departments, information security officers, the Regional Computing Center (RRZ), subcontractors, and other external service providers. This requires joint sprint/takt planning, transparent capacity planning, and regular reporting on project status, risks, throughput times, and agreed-upon metrics.
    • Cost Structure: A modular cost structure is required to reflect the staggered integration of individual universities over time.

    Sources

    • 1Unterlagen\Vergabeunterlagen.pdf — “Services und Aufbau eines Security Operation Centers Gegenstand der Ausschreibung ist die Vergabe von IT-Dienstleistungen zur Unterstützung der Hamburger Hochschulen durch Managed Security Services inkl. eines Security O…

    Login to view all answers and insights

    Unlock tender brief for free

    TENDER DOCUMENTS

    DIRECTORY • 2 FILES

    • Unterlagen\Vergabeunterlagen.pdf
    • Bekanntmachung\Auftragsbekanntmachung.pdf

    Login to view and download all tender documents

    Unlock documents for free

    ASK AI ABOUT THIS TENDER

    You

    Can a foreign company apply?

    Riko

    Yes, foreign companies can apply as long as they meet all the requirements set out in the procurement documents.

    Login to ask more questions.

    Unlock AI tender chat for free

    Unlock your tender workflow

    Run your first search, evaluate the results, save a daily monitor and start building a pipeline of tenders worth pursuing.

    First monitor on Day 1All features included in trialNo credit card required

    You may also be interested in

    Similar tenders