Unmodified official OCDS data retained by Tenderline for this procurement process.
Complete current OCDS release JSON
{
"id": "020845-2024",
"tag": [
"planning"
],
"date": "2024-07-08T20:20:51+01:00",
"ocid": "ocds-h6vhtk-047bc5",
"buyer": {
"id": "GB-COH-SC213461",
"name": "SCOTTISH HYDRO ELECTRIC TRANSMISSION PLC"
},
"tender": {
"id": "7648",
"lots": [
{
"id": "1",
"value": {
"amount": 150000000,
"currency": "GBP"
},
"status": "planned",
"renewal": {
"description": "Duration estimate reflects initial term with extension options up to a maximum term of 10 years"
},
"hasRenewal": true,
"description": "Detailed description\nAmong key responsibilities the prospective supplier would provide design assurance, assurance of onsite installation, security testing, threat-intelligence, and operational assurance. Additionally they may be required to provide ad-hoc projects and support with incident management and response, digital forensics, security, network and infrastructure consulting.\nSHET seeks suppliers with experience in all of the following;\n\tAudit Review & Compliance\n\tCyber Security Training & Awareness\n\tDesign and Build of Turnkey Cyber Security Services\n\tDigital Forensics\n\tIncident Management & Response\n\tRisk Assessment and Management Services\n\tSecurity Architecture Services\n\tSecurity Consultancy\n\tSecurity Testing\n\tTechnical Cyber Assurance\n\tVulnerability Management\n\tDesirable;\no\tInfrastructure Managed Service Support\no\tNetwork Service Managed Service Support\no\tIT managed services delivery (including but not limited to networking, infrastructure, cybersecurity)\no\tVendor Cyber Assurance Managed Services.\nThere may be a future requirement for IT managed services, IT cybersecurity services and project delivery services to be provided by the supplier, so it is desirable that the supplier have the capability to provide IT managed services (for example but not limited to networking, infrastructure, cybersecurity specialisms) and professional services. This may include implementing new security tools or architectures.\nThe PIN estimate reflects a combination of day to day capacity, flex contingency, potential ad-hoc projects and support services, and is not a promise or guarantee that the estimate will be reached during the initial or renewal terms.",
"contractPeriod": {
"durationInDays": 3600
}
}
],
"items": [
{
"id": "1",
"relatedLot": "1",
"deliveryLocation": {
"description": "Onsite delivery services to take place in the UK"
},
"deliveryAddresses": [
{
"region": "UK"
}
]
}
],
"title": "OT and IT Cybersecurity Services framework",
"value": {
"amount": 150000000,
"currency": "GBP"
},
"status": "planned",
"legalBasis": {
"id": "32014L0025",
"scheme": "CELEX"
},
"techniques": {
"frameworkAgreement": {
"periodRationale": "The cost, resource effort, complexity and business disruption to change a major support partner is substantial; 10 years reflects and reasonable period through which it is desirable to retain the services of a single supplier. It is desirable to retain a cybersecurity providers services for an extended time so they are deeply familiar with the recent history and practices of the organisation",
"maximumParticipants": 1
},
"hasFrameworkAgreement": true
},
"description": "Scottish Hydro Electric Transmission Plc. (SHET) seeks a skilled provider of Operational Technology (OT) cybersecurity assurance services and IT cybersecurity services. The supplier will act as an independent assurance authority, ensuring that OT systems are designed, delivered and managed in a secure manner and in line with SHET and national standards.\nAmong key responsibilities the prospective supplier would provide design assurance, assurance of onsite installation, security testing, threat-intelligence, and operational assurance. Additionally they may be required to provide ad-hoc projects and support with incident management and response, digital forensics, security, network and infrastructure consulting.\nThe supplier should be able to provide CREST certified penetration testing services\nThere may be a future requirement for IT managed services, IT cybersecurity services and project delivery services to be provided by the supplier, so it is desirable that the supplier have the capability to provide IT managed services (for example but not limited to networking, infrastructure, cybersecurity specialisms), cybersecurity services and professional services. This may include implementing new security tools or architectures. \nThe PIN estimate reflects a combination of day to day capacity, flex contingency, potential ad-hoc projects and support services, and is not a promise or guarantee that the estimate will be reached during the initial or renewal terms.",
"communication": {
"futureNoticeDate": "2024-08-19T00:00:00+01:00"
},
"contractTerms": {
"hasElectronicPayment": true,
"hasElectronicOrdering": true,
"electronicInvoicingPolicy": "allowed"
},
"classification": {
"id": "72600000",
"scheme": "CPV",
"description": "Computer support and consultancy services"
},
"submissionTerms": {
"languages": [
"en"
]
},
"submissionMethod": [
"electronicSubmission"
],
"otherRequirements": {
"requiresStaffNamesAndQualifications": true
},
"selectionCriteria": {
"criteria": [
{
"type": "suitability",
"appliesTo": [
"supplier"
],
"description": "Prospective suppliers should be able to commit that they have reasonable procedures in place for the prevention of modern slavery, human trafficking, financial crime and bribery\nProspective suppliers should be able to commit to revealing the identity of any third party subcontractors or solutions upon which their delivery of services would be dependent. SHET may require the right to undertake business probity, financial, cybersecurity and other compliance reviews of subcontractors.\nProspective suppliers may be required to sign a Non-Disclosure-Agreement before security sensitive content is shared with them\nOther or additional conditions of participation may be set out in the final tender documents."
},
{
"type": "economic",
"appliesTo": [
"supplier"
],
"description": "Prospective suppliers should have a minimum annual turnover of £50m p.a.\nThe financial standing of a prospective supplier must give SHET reasonable confidence that they can successfully fund the services for the duration and accept reasonable liability in line with the level of risk their project presents to SHET. \nOther/additional requirements may be set out in the final tender documents."
},
{
"type": "technical",
"minimum": "Prospective suppliers will be required to be accredited to SOC2 or ISO27001 level (or recognized equivalent)\nProspective suppliers should be able to provide personnel based in the UK (during delivery) who have been through enhanced background vetting or carry current security clearance (SC or above). The same vetting expectation may be required for subcontractors of the supplier who work on the delivery\nProspective suppliers should be knowledgeable in NIST standard SP800-53\nPenetration test personnel provided should be CREST accredited.\nAdditional requirements may be set out in the final tender documents",
"appliesTo": [
"supplier"
],
"description": "Prospective suppliers should be able to evidence strong knowledge and experience in the delivery of similar services, at scale; ideally in a critical national infrastructure context.\nProspective suppliers should be familiar with major brands of OT and IT equipment\nAdditional requirements may be set out in the final tender documents."
}
]
},
"mainProcurementCategory": "services",
"submissionMethodDetails": "https://sse.app.jaggaer.com/esop/guest/go/opportunity/detail?opportunityId=387"
},
"parties": [
{
"id": "GB-COH-SC213461",
"name": "SCOTTISH HYDRO ELECTRIC TRANSMISSION PLC",
"roles": [
"buyer"
],
"address": {
"region": "UKM77",
"locality": "PERTH",
"postalCode": "PH13AQ",
"countryName": "United Kingdom",
"streetAddress": "Inveralmond House,200 Dunkeld Road"
},
"details": {
"url": "https://www.ssen-transmission.co.uk/",
"classifications": [
{
"scheme": "TED_CE_ACTIVITY",
"description": "IT Services"
}
]
},
"identifier": {
"id": "SC213461",
"scheme": "GB-COH",
"legalName": "SCOTTISH HYDRO ELECTRIC TRANSMISSION PLC"
},
"contactPoint": {
"name": "James Pike",
"email": "james.pike@sse.com"
}
},
{
"id": "GB-FTS-117914",
"name": "SSE Plc.",
"roles": [
"reviewBody"
],
"address": {
"locality": "Perth, Scotland",
"countryName": "United Kingdom"
},
"identifier": {
"legalName": "SSE Plc."
}
}
],
"language": "en",
"initiationType": "tender"
}Complete JSON history (1 releases)
8 Jul 2024 · 020845-2024 · planning
{
"id": "020845-2024",
"tag": [
"planning"
],
"date": "2024-07-08T20:20:51+01:00",
"ocid": "ocds-h6vhtk-047bc5",
"buyer": {
"id": "GB-COH-SC213461",
"name": "SCOTTISH HYDRO ELECTRIC TRANSMISSION PLC"
},
"tender": {
"id": "7648",
"lots": [
{
"id": "1",
"value": {
"amount": 150000000,
"currency": "GBP"
},
"status": "planned",
"renewal": {
"description": "Duration estimate reflects initial term with extension options up to a maximum term of 10 years"
},
"hasRenewal": true,
"description": "Detailed description\nAmong key responsibilities the prospective supplier would provide design assurance, assurance of onsite installation, security testing, threat-intelligence, and operational assurance. Additionally they may be required to provide ad-hoc projects and support with incident management and response, digital forensics, security, network and infrastructure consulting.\nSHET seeks suppliers with experience in all of the following;\n\tAudit Review & Compliance\n\tCyber Security Training & Awareness\n\tDesign and Build of Turnkey Cyber Security Services\n\tDigital Forensics\n\tIncident Management & Response\n\tRisk Assessment and Management Services\n\tSecurity Architecture Services\n\tSecurity Consultancy\n\tSecurity Testing\n\tTechnical Cyber Assurance\n\tVulnerability Management\n\tDesirable;\no\tInfrastructure Managed Service Support\no\tNetwork Service Managed Service Support\no\tIT managed services delivery (including but not limited to networking, infrastructure, cybersecurity)\no\tVendor Cyber Assurance Managed Services.\nThere may be a future requirement for IT managed services, IT cybersecurity services and project delivery services to be provided by the supplier, so it is desirable that the supplier have the capability to provide IT managed services (for example but not limited to networking, infrastructure, cybersecurity specialisms) and professional services. This may include implementing new security tools or architectures.\nThe PIN estimate reflects a combination of day to day capacity, flex contingency, potential ad-hoc projects and support services, and is not a promise or guarantee that the estimate will be reached during the initial or renewal terms.",
"contractPeriod": {
"durationInDays": 3600
}
}
],
"items": [
{
"id": "1",
"relatedLot": "1",
"deliveryLocation": {
"description": "Onsite delivery services to take place in the UK"
},
"deliveryAddresses": [
{
"region": "UK"
}
]
}
],
"title": "OT and IT Cybersecurity Services framework",
"value": {
"amount": 150000000,
"currency": "GBP"
},
"status": "planned",
"legalBasis": {
"id": "32014L0025",
"scheme": "CELEX"
},
"techniques": {
"frameworkAgreement": {
"periodRationale": "The cost, resource effort, complexity and business disruption to change a major support partner is substantial; 10 years reflects and reasonable period through which it is desirable to retain the services of a single supplier. It is desirable to retain a cybersecurity providers services for an extended time so they are deeply familiar with the recent history and practices of the organisation",
"maximumParticipants": 1
},
"hasFrameworkAgreement": true
},
"description": "Scottish Hydro Electric Transmission Plc. (SHET) seeks a skilled provider of Operational Technology (OT) cybersecurity assurance services and IT cybersecurity services. The supplier will act as an independent assurance authority, ensuring that OT systems are designed, delivered and managed in a secure manner and in line with SHET and national standards.\nAmong key responsibilities the prospective supplier would provide design assurance, assurance of onsite installation, security testing, threat-intelligence, and operational assurance. Additionally they may be required to provide ad-hoc projects and support with incident management and response, digital forensics, security, network and infrastructure consulting.\nThe supplier should be able to provide CREST certified penetration testing services\nThere may be a future requirement for IT managed services, IT cybersecurity services and project delivery services to be provided by the supplier, so it is desirable that the supplier have the capability to provide IT managed services (for example but not limited to networking, infrastructure, cybersecurity specialisms), cybersecurity services and professional services. This may include implementing new security tools or architectures. \nThe PIN estimate reflects a combination of day to day capacity, flex contingency, potential ad-hoc projects and support services, and is not a promise or guarantee that the estimate will be reached during the initial or renewal terms.",
"communication": {
"futureNoticeDate": "2024-08-19T00:00:00+01:00"
},
"contractTerms": {
"hasElectronicPayment": true,
"hasElectronicOrdering": true,
"electronicInvoicingPolicy": "allowed"
},
"classification": {
"id": "72600000",
"scheme": "CPV",
"description": "Computer support and consultancy services"
},
"submissionTerms": {
"languages": [
"en"
]
},
"submissionMethod": [
"electronicSubmission"
],
"otherRequirements": {
"requiresStaffNamesAndQualifications": true
},
"selectionCriteria": {
"criteria": [
{
"type": "suitability",
"appliesTo": [
"supplier"
],
"description": "Prospective suppliers should be able to commit that they have reasonable procedures in place for the prevention of modern slavery, human trafficking, financial crime and bribery\nProspective suppliers should be able to commit to revealing the identity of any third party subcontractors or solutions upon which their delivery of services would be dependent. SHET may require the right to undertake business probity, financial, cybersecurity and other compliance reviews of subcontractors.\nProspective suppliers may be required to sign a Non-Disclosure-Agreement before security sensitive content is shared with them\nOther or additional conditions of participation may be set out in the final tender documents."
},
{
"type": "economic",
"appliesTo": [
"supplier"
],
"description": "Prospective suppliers should have a minimum annual turnover of £50m p.a.\nThe financial standing of a prospective supplier must give SHET reasonable confidence that they can successfully fund the services for the duration and accept reasonable liability in line with the level of risk their project presents to SHET. \nOther/additional requirements may be set out in the final tender documents."
},
{
"type": "technical",
"minimum": "Prospective suppliers will be required to be accredited to SOC2 or ISO27001 level (or recognized equivalent)\nProspective suppliers should be able to provide personnel based in the UK (during delivery) who have been through enhanced background vetting or carry current security clearance (SC or above). The same vetting expectation may be required for subcontractors of the supplier who work on the delivery\nProspective suppliers should be knowledgeable in NIST standard SP800-53\nPenetration test personnel provided should be CREST accredited.\nAdditional requirements may be set out in the final tender documents",
"appliesTo": [
"supplier"
],
"description": "Prospective suppliers should be able to evidence strong knowledge and experience in the delivery of similar services, at scale; ideally in a critical national infrastructure context.\nProspective suppliers should be familiar with major brands of OT and IT equipment\nAdditional requirements may be set out in the final tender documents."
}
]
},
"mainProcurementCategory": "services",
"submissionMethodDetails": "https://sse.app.jaggaer.com/esop/guest/go/opportunity/detail?opportunityId=387"
},
"parties": [
{
"id": "GB-COH-SC213461",
"name": "SCOTTISH HYDRO ELECTRIC TRANSMISSION PLC",
"roles": [
"buyer"
],
"address": {
"region": "UKM77",
"locality": "PERTH",
"postalCode": "PH13AQ",
"countryName": "United Kingdom",
"streetAddress": "Inveralmond House,200 Dunkeld Road"
},
"details": {
"url": "https://www.ssen-transmission.co.uk/",
"classifications": [
{
"scheme": "TED_CE_ACTIVITY",
"description": "IT Services"
}
]
},
"identifier": {
"id": "SC213461",
"scheme": "GB-COH",
"legalName": "SCOTTISH HYDRO ELECTRIC TRANSMISSION PLC"
},
"contactPoint": {
"name": "James Pike",
"email": "james.pike@sse.com"
}
},
{
"id": "GB-FTS-117914",
"name": "SSE Plc.",
"roles": [
"reviewBody"
],
"address": {
"locality": "Perth, Scotland",
"countryName": "United Kingdom"
},
"identifier": {
"legalName": "SSE Plc."
}
}
],
"language": "en",
"initiationType": "tender"
}