Published

    Serveis per a la gestió i suport als sistemes d'Informació, Infraestructures, Eines de Seguretat i Suport al Lloc de Treball de l'Agència de Ciberseguretat de Catalunya

    Notice number: CO.04.2025

    🇪🇸 SpainAgència de Ciberseguretat de CatalunyaServices

    KEY INFORMATION

    Submission deadline
    Sep 24, 2026
    Location
    🇪🇸 Spain
    Contracting authority
    Agència de Ciberseguretat de Catalunya
    Accepted Languages
    CA
    Tender type
    Services
    Contract Value
    Published date
    Aug 12, 2026

    TENDER DESCRIPTION

    This tender seeks comprehensive services for the management and support of Information Systems, Infrastructures, Security Tools, and Workplace Support for the Cybersecurity Agency of Catalonia. The scope encompasses critical areas such as ITSM, identity and access management, secure cloud and SaaS environments (Azure, Microsoft 365), backup and recovery, digital workplace solutions, transversal governance, knowledge management, and the implementation and governance of AI models, including Microsoft 365 Copilot, Copilot Studio, and Security Copilot. Expertise is required across a wide array of technologies, including Microsoft Intune, Palo Alto, CrowdStrike, Microsoft Defender, Cisco, Cohesity, VMware, Nutanix, and various IT service management platforms, alongside a focus on post-quantum transition and crypto-agility. The contract has an initial duration of twelve months, extendable by two successive twelve-month periods for a maximum of 36 months, with a mandatory three-week service commencement phase for knowledge transfer. Bidders must demonstrate an annual turnover of at least €400,000.00 within the contract's scope, based on the best financial year out of the last three…

    TENDER BRIEF

    The contract has an initial duration of twelve (12) months, starting from the date of formalization or the date established in the service commencement act. There is a possibility of two (2) successive extensions, each lasting twelve (12) months, as long as the service characteristics remain unchanged. Therefore, the maximum duration of the contract is 12 months with the possibility of two extensions. The contract can be terminated early if the maximum allocated amount is exhausted.

    A key milestone mentioned is the "Start of service" (Inici de la prestació) phase, which has a maximum duration of three weeks from the formalization of the award. During this phase, the contractor is expected to acquire the necessary knowledge for service provision, including knowledge transfer, document review, technological environment analysis, and operational procedure review, to ensure service continuity, security, quality, and operational efficiency.

    Sources

    • 13.- PCAP-ok_s.pdf — “la Llei 9/2017, de Contractes del Sector Públic, el contracte podrà ser objecte de dues (2) pròrrogues successives de dotze (12) mesos cadascuna, sempre que les característiques de la prestació romanguin inalterables dur…
    • 21.-Memòria Jutificativa CO.04.2025 vfinal (1).pdf — “servei, incrementaria els riscos de coordinació i responsabilitat, i podria comprometre la continuïtat operativa, la seguretat i la qualitat global de la prestació. DURADA DEL CONTRACTE La durada inicial del contracte se…
    • 3PPT CO.04.2025_vfinal_signat.pdf — “obligatoris, revisió del model de servei, substitució de recursos, reforç de governança, compensacions, penalitzacions acumulades o resolució contractual, d’acord amb el marc jurídic aplicable. 65/68 PPT Acord Marc Consu…

    The core scope of work for this tender revolves around providing support services for the Agency's Information Systems, Infrastructures, Security Tools, and Workplace Support. The Statement of Work outlines several key areas, each with specific purposes and minimum deliverables:

    1. ITSM Services Support: This involves the categorization, prioritization, and validated closure of incidents and requests. Core deliverables include monthly reports, ITSM dashboards, ticket logs, review minutes, and action plans for recurrence.

    2. Identity, Access, and Device Management Solution: The objective is to establish an integrated capacity for governing identities, accesses, devices, profiles, permissions, and compliance policies for the TIC Service. Minimum deliverables include inventories of managed identities, devices, and profiles; evidence of policy application; device compliance reports; records of additions, deletions, and modifications; evidence of privileged access reviews; and deviation and risk reports.

    3. Cloud and SaaS Environment: The purpose is to provide a secure, scalable, governed, and efficient cloud and SaaS environment integrated with Azure, Microsoft 365, and other corporate platforms. Key deliverables are usage, capacity, and consumption reports; secure configuration evidence; licensing and assignment reports; cloud dashboards; and proposals for technical and economic optimization.

    4. Backup, Recovery, and Continuity Solution: This aims to ensure a documented and verifiable capacity for backup, recovery, and continuity, aligned with the TIC Service.

    5. TIC Assets and Services Map: This involves maintaining an authoritative, structured, updated, and exploitable source of information on TIC assets, configuration items, relationships, and the service map. Minimum deliverables include an updated inventory of assets and CIs; a service and dependency map; data quality reports; and obsolescence and risk reports.

    6. Digital Workplace and Secure Remote Access: The goal is to establish a secure, homogeneous, governed, and efficient digital work environment for the Agency's internal users and collaborators.

    7. Transversal Governance Model of the TIC Service: This model is designed for the governance, monitoring, control, and improvement of the TIC Service, based on indicators, risks, service level agreements (SLAs), quality, and capacity. Minimum deliverables include a monthly service report; an executive monitoring report; a transversal dashboard; a risk register; an improvement register; and SLA monitoring.

    8. Document Repository and Knowledge Base: The aim is to create a structured, updated, accessible, and reusable repository of technical and operational knowledge for the TIC Service. Minimum deliverables include an updated document repository; operational procedures; technical manuals; support guides; a knowledge base; and a knowledge transfer plan.

    9. Artificial Intelligence Model, Copilot, and Governed Use Cases: This product focuses on the adoption, governance, exploitation, and continuous improvement of AI capabilities for the TIC Service, specifically Microsoft 365 Copilot, Copilot Studio, and Security Copilot. Minimum deliverables include a map of AI and Copilot use cases; prioritization and valuation criteria; use case fiches; a secure Copilot usage guide; and adoption and usage reports.

    Sources

    • 1PPT CO.04.2025_vfinal_signat.pdf — “Plec de prescripcions tècniques particulars que regeix la contractació relativa als Serveis de suport als Sistemes d’Informació, Infraestructures, Eines de Seguretat i Suport al Lloc de Treball de l’Agència Exp. CO.04.20…

    Login to view all answers and insights

    Unlock tender brief for free

    TENDER DOCUMENTS

    DIRECTORY • 5 FILES

    • 4.- Certificat existència de crèdit serveis TIC.pdf
    • 6.-Aprovacio_expedient_signed (1).pdf
    • 1.-Memòria Jutificativa CO.04.2025 vfinal (1).pdf

    Login to view and download all tender documents

    Unlock documents for free

    ASK AI ABOUT THIS TENDER

    You

    Can a foreign company apply?

    Riko

    Yes, foreign companies can apply as long as they meet all the requirements set out in the procurement documents.

    Login to ask more questions.

    Unlock AI tender chat for free

    Unlock your tender workflow

    Run your first search, evaluate the results, save a daily monitor and start building a pipeline of tenders worth pursuing.

    First monitor on Day 1All features included in trialNo credit card required

    You may also be interested in

    Similar tenders