Published
SIEM, SOC, SOAR-dienstverlening
Notice number: 433831
KEY INFORMATION
- Submission deadline
- • Sep 25, 2026
- Location
- 🇳🇱 Netherlands
- Contracting authority
- Veiligheidsregio Noord- en Oost- Gelderland
- Accepted Languages
- Dutch
- Tender type
- Services
- Contract Value
- Published date
- Jul 19, 2026
TENDER DESCRIPTION
This tender invites proposals for a framework agreement with a single contractor for the delivery, implementation, setup, management, and continuous development of integrated SIEM, SOC, and SOAR services. The primary objective is to monitor, detect, analyze, and respond to cybersecurity threats and incidents to strengthen VNOG's digital resilience and professionalize information security across its complex hybrid IT and OT environment. The scope includes 24/7 SIEM, SOC, and SOAR operations, leveraging AI/ML models, Microsoft security products (e.g., Sentinel, Defender XDR), and adherence to frameworks such as MITRE ATT&CK, NIST, ISO 27001, BIO, and NIS2, alongside a requirement for SOC 2 Type II certification or equivalent. Optional services encompass additional cybersecurity consultancy and potential CERT services. The agreement, with a maximum budget ceiling of €1,400,000 excluding VAT for an eight-year duration, commences on April 26, 2027, and requires adequate professional liability insurance with a minimum coverage of €1,250,000 per claim.
TENDER BRIEF
The contract is scheduled to commence on April 26, 2027. The initial term of the agreement extends until April 25, 2031. However, there is an option for VNOG to unilaterally extend the framework agreement twice, each for a period of two years, bringing the maximum end date to April 25, 2035. This results in a total maximum duration of eight years (4 + 2 + 2).
Key milestones and phases include:
- Publication of Information Memorandum: Friday, September 11, 2026.
- Closing date for submission of Request for Participation: Friday, September 25, 2026, 12:00 PM.
- Notification of intended selection decision: Friday, October 9, 2026.
- Standstill period (selection): Saturday, October 10 to Thursday, October 29, 2026.
- Final selection decision: Friday, October 30, 2026.
- Sending of Award Guidelines to selected parties: Monday, November 2, 2026.
- Closing date for submitting questions about the Award Guidelines: Friday, November 20, 2026, 12:00 PM.
- Publication of 1st Information Memorandum: Friday, November 27, 2026.
- Closing date for submitting questions about the Award Guidelines: Friday, December 4, 2026, 12:00 PM.
- Publication of 2nd Information Memorandum: Friday, December 11, 2026.
- Closing date for submitting Bids: Friday, January 8, 2027, 12:00 PM.
- Notification of provisional award decision: Friday, February 5, 2027.
- Standstill period (award): Saturday, February 6 to Thursday, February 25, 2027.
- Final award: Friday, February 26, 2027.
- Implementation period: Friday, February 26 to Friday, April 23, 2027.
- Start date of agreement: Monday, April 26, 2027.
Sources
- 1Selectieleidraad Europese niet openbare aanbestedingsprocedure SIEM, SOC, SOAR-dienstverlening.pdf — “Selectieleidraad | Publicatie Nota van Inlichtingen | Vrijdag 11 september 2026 Sluitingsdatum voor het indienen van Verzoek tot | Vrijdag 25 september 2026, 12:00 uur Deelneming | Kennisgeving voorgenomen selectiebeslis…”
- 2TN600148 - EF18 Aankondiging van een opdracht - defensierichtlijn, standaardregeling 20260717115713.pdf — “uitvoering Land: Nederland Overal in het desbetreffende land Aanvullende informatie: 5.1.3 Geraamde duur Begindatum: 26/04/2027 Einddatum van de duur: 25/04/2035 5.1.4 Verlenging Maximumaantal verlengingen: 2 Overige inf…”
- SIEM-dienstverlening
- SOC-dienstverlening
- SOAR-dienstverlening
- SOC 2 Type II-verklaring (of gelijkwaardig)
- Inzet van AI-modellen
- Inzet van ML-modellen
- Microsoft Intelligent Security Association (MISA) lidmaatschap
- Gebruik van Microsoft beveiligingsproducten (algemeen)
- Microsoft Sentinel
- Microsoft Defender XDR
- Defender for Cloud Apps
- Defender for O365
- Defender for Identity
- 24/7 SIEM-, SOC- en SOAR-dienstverlening
- Ondersteuning van open standaarden
- MITRE ATT&CK (als uitgangspunt voor detectieontwikkeling en risicogestuurd werken)
- NIST (als framework voor risicogestuurd werken)
- ISO 27001 (als framework voor risicogestuurd werken)
- BIO (Baseline Informatiebeveiliging Overheid) (als framework voor risicogestuurd werken en conformiteit)
- NIS2 (als framework voor risicogestuurd werken)
- Gedragsanalyse
- Threat intelligence
- Threat hunting
- Geautomatiseerde respons (gecontroleerd en gefaseerd toegepast)
- Modulaire architectuur (geadviseerd ter voorkoming van vendor lock-in)
- XDR-functionaliteiten (als onderdeel van geïntegreerde securityplatformen)
- OT-monitoring (met gefaseerde benadering)
Sources
- 1Selectieleidraad Europese niet openbare aanbestedingsprocedure SIEM, SOC, SOAR-dienstverlening.pdf — “beschreven, een beschrij- ving van de organisatorische continuïteitsmaatregelen of een verklaring waaruit blijkt dat het SOC binnen de EER is gevestigd. Certificeringen & Compliance: uitvoering van de dienstverlening ond…”
- 2Bijlage 7 - Marktconsultatieverslag SIEM, SOC, SOAR-dienstverlening.pdf — “correlatie. MITRE ATT&CK wordt hierbij veelvuldig genoemd als uitgangspunt voor detectieontwikkeling. Meerdere partijen benadrukken dat de focus niet uitsluitend ligt op het genereren van meldingen, maar op het leveren v…”
Login to view all answers and insights
Unlock tender brief for freeTENDER DOCUMENTS
DIRECTORY • 9 FILES
- Bijlage 7 - Marktconsultatieverslag SIEM, SOC, SOAR-dienstverlening.pdf136 KBPDF
- Bijlage 3 - Verklaring Geen Russische Betrokkenheid.docx110 KBDOCX
- Bijlage 2 - Referentieformulier.docx111 KBDOCX
and 2 other documents
Login to view and download all tender documents
Unlock documents for freeASK AI ABOUT THIS TENDER
Can a foreign company apply?
Yes, foreign companies can apply as long as they meet all the requirements set out in the procurement documents.
Login to ask more questions.
Unlock AI tender chat for freeUnlock your tender workflow
Run your first search, evaluate the results, save a daily monitor and start building a pipeline of tenders worth pursuing.