Published
Servicio de Ciberseguridad
Notice number: DOUE-2026-125
KEY INFORMATION
- Submission deadline
- • Sep 21, 2026
- Location
- 🇪🇸 Spain
- Contracting authority
- Bilbao Exhibition Centre, S.A.-Director General
- Accepted Languages
- Spanish
- Tender type
- Contract Value
- Published date
- Jul 24, 2026
TENDER DESCRIPTION
This tender seeks to procure an integral, turnkey cybersecurity solution delivered as a managed service, encompassing a unified, cloud-native SaaS platform for EPP/EDR/XDR and Next-Gen SIEM capabilities from a single manufacturer. The scope includes a 24x7x365 Managed Security Operations Service (SOC) and Advanced Response and Proactivity Capabilities (MDR) with threat hunting and delegated incident response. Key technical requirements include integration with Active Directory, Microsoft 365, FortiGate, Apache Proxy, and Windows environments, alongside mandatory functionalities like software inventory, USB device control, and application control, all while ensuring a minimum of 12 months log retention and compliance with RGPD and ENS. The contract has a total duration of 5 years (3 initial years plus 2 optional annual extensions), with EPP/EDR implementation due by January 8, 2027, and SIEM sources by January 31, 2027. Bidders must demonstrate a minimum annual turnover of €75,000.
TENDER BRIEF
The contract has a total duration of 5 years. The initial duration is 3 years, starting from the day following the contract signing. The contract can be extended for 2 successive annual periods, which is mandatory for the contractor if notified at least two months before the end of the current period.
Key milestones and phases include:
- Phase 1: Deployment of the SaaS platform.
- Phase 2: Implementation of SIEM + SOC.
- Phase 3: Endpoints.
- The deadline for the implementation of EPP/EDR is January 8, 2027.
- The deadline for the implementation of SIEM sources is January 31, 2027.
Sources
- 1Carátula.pdf — “inclusión en este sobre de cualquier dato que se refiera a los criterios de aplicación mediante fórmula. | SOBRE 3. "OFERTA RELATIVA A LOS CRITERIOS DE ADJUDICACIÓN VALORABLES | DE FORMA AUTOMÁTICA POR APLICACIÓN DE FÓRM…”
- 2PPT.pdf — “el licitador deberá ser clara, estructurada y suficiente para acreditar el cumplimiento de los requisitos establecidos en el presente pliego. Tendrá una extensión máxima de 60 páginas, excluyéndose del cómputo: • Portada…”
The core scope of work and statement of work summary for this tender is the contracting of an integral cybersecurity solution. This solution must be based on an endpoint protection and event management platform, encompassing EPP/EDR/XDR and SIEM capabilities.
Key requirements include:
- A native and unified platform where EPP/EDR/XDR and Next-Gen SIEM components are from the same manufacturer and operated from a single centralized web interface.
- A 100% Cloud-Native architecture using a SaaS model.
- Deployment of advanced protection technology, including the supply and configuration of EPP/EDR/XDR licenses for corporate assets.
- Intelligent event management, involving the collection, correlation, enrichment, storage, exploitation, and automated analysis of security logs and events via the SIEM.
- A Managed Security Operations Service (SOC) operating 24x7x365.
The awarded contractor will provide a "turnkey integral solution" as a managed service, which includes three main operational blocks:
1. Unified Technology Platform (SaaS): This covers the supply, deployment, and cloud configuration of necessary licenses to protect the entire infrastructure, integrating Advanced Endpoint Protection (EPP/EDR/XDR) and SIEM Security Event Management under a single management console from the same manufacturer.
2. Managed SOC Operational Service (24x7x365): This entails continuous human operation of the platform by specialized security analysts, covering continuous monitoring, alert classification and prioritization, protocolized incident escalation, and technical support for National Security Scheme (ENS) audits.
3. Advanced Response and Proactivity Capabilities (MDR): This includes proactive threat hunting, enrichment using corporate threat intelligence, and the delegated execution of immediate response actions to critical incidents, such as remote isolation of affected assets and remediation.
Mandatory functionalities of the solution include software inventory (automatic discovery, centralized inventory, unauthorized software identification, compliance reports), USB device control (default blocking, whitelists, centralized exception management, usage audit), and application control (application control, whitelists/blacklists, restriction of unauthorized application execution). The SIEM component must integrate with Active Directory, Microsoft 365, FortiGate Firewall, Apache Proxy, and Windows endpoints and servers.
Core deliverables implicitly include the provision and operation of the unified cybersecurity platform, the 24x7x365 SOC service, MDR actions, support for ENS audits, generation of audit evidence, and adherence to specified Service Level Agreements (SLAs) for response times. The solution must also ensure a minimum log retention of 12 months with historical query capabilities.
Sources
- 1PPT.pdf — “P á g i n a 1 | 12 Pliego de prescripciones técnicas DOUE-2026-125 Plataforma de Ciberseguridad: SIEM + SOC + EDR/XDR 1 Objeto del contrato El objeto del presente pliego es la contratación de una solución integral de cib…”
Login to view all answers and insights
Unlock tender brief for freeTENDER DOCUMENTS
DIRECTORY • 6 FILES
- PPT.pdf362 KBPDF
- DEUC.pdf81 KBPDF
- PPA .pdf590 KBPDF
Login to view and download all tender documents
Unlock documents for freeASK AI ABOUT THIS TENDER
Can a foreign company apply?
Yes, foreign companies can apply as long as they meet all the requirements set out in the procurement documents.
Login to ask more questions.
Unlock AI tender chat for freeUnlock your tender workflow
Run your first search, evaluate the results, save a daily monitor and start building a pipeline of tenders worth pursuing.