← Back to search results

plannedFind a Tender · planning

OT and IT Cybersecurity Services framework

Buyer: SCOTTISH HYDRO ELECTRIC TRANSMISSION PLC →

Participate on sse.app.jaggaer.com ↗External submission platform

BuyerSCOTTISH HYDRO ELECTRIC TRANSMISSION PLC
Statusplanned
DeadlineNot published
Value£150,000,000
Published8 Jul 2024

What is being bought

Scottish Hydro Electric Transmission Plc. (SHET) seeks a skilled provider of Operational Technology (OT) cybersecurity assurance services and IT cybersecurity services. The supplier will act as an independent assurance authority, ensuring that OT systems are designed, delivered and managed in a secure manner and in line with SHET and national standards. Among key responsibilities the prospective supplier would provide design assurance, assurance of onsite installation, security testing, threat-intelligence, and operational assurance. Additionally they may be required to provide ad-hoc projects and support with incident management and response, digital forensics, security, network and infrastructure consulting. The supplier should be able to provide CREST certified penetration testing services There may be a future requirement for IT managed services, IT cybersecurity services and project delivery services to be provided by the supplier, so it is desirable that the supplier have the capability to provide IT managed services (for example but not limited to networking, infrastructure, cybersecurity specialisms), cybersecurity services and professional services. This may include implementing new security tools or architectures. The PIN estimate reflects a combination of day to day capacity, flex contingency, potential ad-hoc projects and support services, and is not a promise or guarantee that the estimate will be reached during the initial or renewal terms.

Delivery location

UK

Categories

Computer support and consultancy services 72600000

Lot details

Lot 1

Detailed description Among key responsibilities the prospective supplier would provide design assurance, assurance of onsite installation, security testing, threat-intelligence, and operational assurance. Additionally they may be required to provide ad-hoc projects and support with incident management and response, digital forensics, security, network and infrastructure consulting. SHET seeks suppliers with experience in all of the following;  Audit Review & Compliance  Cyber Security Training & Awareness  Design and Build of Turnkey Cyber Security Services  Digital Forensics  Incident Management & Response  Risk Assessment and Management Services  Security Architecture Services  Security Consultancy  Security Testing  Technical Cyber Assurance  Vulnerability Management  Desirable; o Infrastructure Managed Service Support o Network Service Managed Service Support o IT managed services delivery (including but not limited to networking, infrastructure, cybersecurity) o Vendor Cyber Assurance Managed Services. There may be a future requirement for IT managed services, IT cybersecurity services and project delivery services to be provided by the supplier, so it is desirable that the supplier have the capability to provide IT managed services (for example but not limited to networking, infrastructure, cybersecurity specialisms) and professional services. This may include implementing new security tools or architectures. The PIN estimate reflects a combination of day to day capacity, flex contingency, potential ad-hoc projects and support services, and is not a promise or guarantee that the estimate will be reached during the initial or renewal terms.

Statusplanned
Value£150,000,000

What is included

ItemCategoryQuantity
1Not publishedNot published

Comparable-procurement analytics

Benchmarked against retained Find a Tender procedures with CPV division 72. The category anchor is Computer support and consultancy services (72600000); this is a deliberately broad market comparator. The comparison is shown at several levels rather than pretending one company or region is always the best benchmark.

Comparison setProceduresReported bids per procedureNamed award suppliersPrice evidence
Market: CPV division 7210,5392 median · 15.4 average (4,163 of 10,539 with a bid count)2 average (5,055 of 10,539 with named award suppliers)Not published
Same buyer8Not publishedNot publishedNot published
Delivery region: UK3,3252 median · 33.8 average (1,172 of 3,325 with a bid count)2.8 average (1,502 of 3,325 with named award suppliers)Not published
Similar published value (0.5×–2×)181264 median · 264 average (1 of 181 with a bid count)39 average (1 of 181 with named award suppliers)Not published

“Reported bids” is an official aggregate, sometimes reported per lot; it is the closest available competition measure. “Named award suppliers” are winners, not all applicants.

Price-outcome signal

Not enough comparable procedures currently publish both a GBP tender value and a usable lowest-valid-bid value to calculate a responsible price-reduction benchmark. Tenderline deliberately does not infer a saving from named award suppliers or from missing award values.

Procurement strategy & market signals

Framework agreementYes
Dynamic purchasing systemNot published
Competitive procurementNot published
Recurring requirementNot published
Procurement method rationaleNot published
Rationale classificationsNot published
Special regimeNot published
Covered byNot published
Submission policyNot published
Selection criteriasuitability, economic, technical
Risk detailsNot published

Planning & early market engagement

BudgetNot published
No-engagement rationaleNot published
Planning documents0
Planning milestones0

No planning milestones published.

Related procurements

No linked framework, prior procurement or reprocurement published.

Documents & submission route

No documents are published in the current source record.

Source data inventory

Diagnostic view. “Not published” means this current release does not provide a value.

OCIDocds-h6vhtk-047bc5
Latest release ID020845-2024
Latest release timestampMon Jul 08 2024 19:20:51 GMT+0000 (Coordinated Universal Time)
Sourcefind-a-tender
Official notice URLNot published
Tender statusplanned
Procurement methodNot published
Procurement method detailsNot published
Main procurement categoryservices
Above thresholdNot published
Legal basis32014L0025
Tender period: startNot published
Tender period: endNot published
Expression of interest deadlineNot published
Enquiry deadlineNot published
Award period: startNot published
Award period: endNot published
Submission method detailshttps://sse.app.jaggaer.com/esop/guest/go/opportunity/detail?opportunityId=387
Submission languagesen
Electronic catalogue policyNot published
Total tender value£150,000,000
Tender lots in source1
Tender items in source1
Tender documents in source0
Awards in latest release0
Contracts in latest release0
Parties in latest release2

Notice history

DateEventReference
8 Jul 2024planning020845-2024

All source data

Unmodified official OCDS data retained by Tenderline for this procurement process.

Complete current OCDS release JSON
{
  "id": "020845-2024",
  "tag": [
    "planning"
  ],
  "date": "2024-07-08T20:20:51+01:00",
  "ocid": "ocds-h6vhtk-047bc5",
  "buyer": {
    "id": "GB-COH-SC213461",
    "name": "SCOTTISH HYDRO ELECTRIC TRANSMISSION PLC"
  },
  "tender": {
    "id": "7648",
    "lots": [
      {
        "id": "1",
        "value": {
          "amount": 150000000,
          "currency": "GBP"
        },
        "status": "planned",
        "renewal": {
          "description": "Duration estimate reflects initial term with extension options up to a maximum term of 10 years"
        },
        "hasRenewal": true,
        "description": "Detailed description\nAmong key responsibilities the prospective supplier would provide design assurance, assurance of onsite installation, security testing, threat-intelligence, and operational assurance.  Additionally they may be required to provide ad-hoc projects and support with incident management and response, digital forensics, security, network and infrastructure consulting.\nSHET seeks suppliers with experience in all of the following;\n\tAudit Review & Compliance\n\tCyber Security Training & Awareness\n\tDesign and Build of Turnkey Cyber Security Services\n\tDigital Forensics\n\tIncident Management & Response\n\tRisk Assessment and Management Services\n\tSecurity Architecture Services\n\tSecurity Consultancy\n\tSecurity Testing\n\tTechnical Cyber Assurance\n\tVulnerability Management\n\tDesirable;\no\tInfrastructure Managed Service Support\no\tNetwork Service Managed Service Support\no\tIT managed services delivery (including but not limited to networking, infrastructure, cybersecurity)\no\tVendor Cyber Assurance Managed Services.\nThere may be a future requirement for IT managed services, IT cybersecurity services and project delivery services to be provided by the supplier, so it is desirable that the supplier have the capability to provide IT managed services (for example but not limited to networking, infrastructure, cybersecurity specialisms) and professional services.  This may include implementing new security tools or architectures.\nThe PIN estimate reflects a combination of day to day capacity, flex contingency, potential ad-hoc projects and support services, and is not a promise or guarantee that the estimate will be reached during the initial or renewal terms.",
        "contractPeriod": {
          "durationInDays": 3600
        }
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "deliveryLocation": {
          "description": "Onsite delivery services to take place in the UK"
        },
        "deliveryAddresses": [
          {
            "region": "UK"
          }
        ]
      }
    ],
    "title": "OT and IT Cybersecurity Services framework",
    "value": {
      "amount": 150000000,
      "currency": "GBP"
    },
    "status": "planned",
    "legalBasis": {
      "id": "32014L0025",
      "scheme": "CELEX"
    },
    "techniques": {
      "frameworkAgreement": {
        "periodRationale": "The cost, resource effort, complexity and business disruption to change a major support partner is substantial; 10 years reflects and reasonable period through which it is desirable to retain the services of a single supplier.  It is desirable to retain a cybersecurity providers services for an extended time so they are deeply familiar with the recent history and practices of the organisation",
        "maximumParticipants": 1
      },
      "hasFrameworkAgreement": true
    },
    "description": "Scottish Hydro Electric Transmission Plc. (SHET) seeks a skilled provider of Operational Technology (OT) cybersecurity assurance services and IT cybersecurity services.  The supplier will act as an independent assurance authority, ensuring that OT systems are designed, delivered and managed in a secure manner and in line with SHET and national standards.\nAmong key responsibilities the prospective supplier would provide design assurance, assurance of onsite installation, security testing, threat-intelligence, and operational assurance.  Additionally they may be required to provide ad-hoc projects and support with incident management and response, digital forensics, security, network and infrastructure consulting.\nThe supplier should be able to provide CREST certified penetration testing services\nThere may be a future requirement for IT managed services, IT cybersecurity services and project delivery services to be provided by the supplier, so it is desirable that the supplier have the capability to provide IT managed services (for example but not limited to networking, infrastructure, cybersecurity specialisms), cybersecurity services and professional services.  This may include implementing new security tools or architectures. \nThe PIN estimate reflects a combination of day to day capacity, flex contingency, potential ad-hoc projects and support services, and is not a promise or guarantee that the estimate will be reached during the initial or renewal terms.",
    "communication": {
      "futureNoticeDate": "2024-08-19T00:00:00+01:00"
    },
    "contractTerms": {
      "hasElectronicPayment": true,
      "hasElectronicOrdering": true,
      "electronicInvoicingPolicy": "allowed"
    },
    "classification": {
      "id": "72600000",
      "scheme": "CPV",
      "description": "Computer support and consultancy services"
    },
    "submissionTerms": {
      "languages": [
        "en"
      ]
    },
    "submissionMethod": [
      "electronicSubmission"
    ],
    "otherRequirements": {
      "requiresStaffNamesAndQualifications": true
    },
    "selectionCriteria": {
      "criteria": [
        {
          "type": "suitability",
          "appliesTo": [
            "supplier"
          ],
          "description": "Prospective suppliers should be able to commit that they have reasonable procedures in place for the prevention of modern slavery, human trafficking, financial crime and bribery\nProspective suppliers should be able to commit to revealing the identity of any third party subcontractors or solutions upon which their delivery of services would be dependent.  SHET may require the right to undertake business probity, financial, cybersecurity and other compliance reviews of subcontractors.\nProspective suppliers may be required to sign a Non-Disclosure-Agreement before security sensitive content is shared with them\nOther or additional conditions of participation may be set out in the final tender documents."
        },
        {
          "type": "economic",
          "appliesTo": [
            "supplier"
          ],
          "description": "Prospective suppliers should have a minimum annual turnover of £50m p.a.\nThe financial standing of a prospective supplier must give SHET reasonable confidence that they can successfully fund the services for the duration and accept reasonable liability in line with the level of risk their project presents to SHET. \nOther/additional requirements may be set out in the final tender documents."
        },
        {
          "type": "technical",
          "minimum": "Prospective suppliers will be required to be accredited to SOC2 or ISO27001 level (or recognized equivalent)\nProspective suppliers should be able to provide personnel based in the UK (during delivery) who have been through enhanced background vetting or carry current security clearance (SC or above).  The same vetting expectation may be required for subcontractors of the supplier who work on the delivery\nProspective suppliers should be knowledgeable in NIST standard SP800-53\nPenetration test personnel provided should be CREST accredited.\nAdditional requirements may be set out in the final tender documents",
          "appliesTo": [
            "supplier"
          ],
          "description": "Prospective suppliers should be able to evidence strong knowledge and experience in the delivery of similar services, at scale; ideally in a critical national infrastructure context.\nProspective suppliers should be familiar with major brands of OT and IT equipment\nAdditional requirements may be set out in the final tender documents."
        }
      ]
    },
    "mainProcurementCategory": "services",
    "submissionMethodDetails": "https://sse.app.jaggaer.com/esop/guest/go/opportunity/detail?opportunityId=387"
  },
  "parties": [
    {
      "id": "GB-COH-SC213461",
      "name": "SCOTTISH HYDRO ELECTRIC TRANSMISSION PLC",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UKM77",
        "locality": "PERTH",
        "postalCode": "PH13AQ",
        "countryName": "United Kingdom",
        "streetAddress": "Inveralmond House,200 Dunkeld Road"
      },
      "details": {
        "url": "https://www.ssen-transmission.co.uk/",
        "classifications": [
          {
            "scheme": "TED_CE_ACTIVITY",
            "description": "IT Services"
          }
        ]
      },
      "identifier": {
        "id": "SC213461",
        "scheme": "GB-COH",
        "legalName": "SCOTTISH HYDRO ELECTRIC TRANSMISSION PLC"
      },
      "contactPoint": {
        "name": "James Pike",
        "email": "james.pike@sse.com"
      }
    },
    {
      "id": "GB-FTS-117914",
      "name": "SSE Plc.",
      "roles": [
        "reviewBody"
      ],
      "address": {
        "locality": "Perth, Scotland",
        "countryName": "United Kingdom"
      },
      "identifier": {
        "legalName": "SSE Plc."
      }
    }
  ],
  "language": "en",
  "initiationType": "tender"
}
Complete JSON history (1 releases)
8 Jul 2024 · 020845-2024 · planning
{
  "id": "020845-2024",
  "tag": [
    "planning"
  ],
  "date": "2024-07-08T20:20:51+01:00",
  "ocid": "ocds-h6vhtk-047bc5",
  "buyer": {
    "id": "GB-COH-SC213461",
    "name": "SCOTTISH HYDRO ELECTRIC TRANSMISSION PLC"
  },
  "tender": {
    "id": "7648",
    "lots": [
      {
        "id": "1",
        "value": {
          "amount": 150000000,
          "currency": "GBP"
        },
        "status": "planned",
        "renewal": {
          "description": "Duration estimate reflects initial term with extension options up to a maximum term of 10 years"
        },
        "hasRenewal": true,
        "description": "Detailed description\nAmong key responsibilities the prospective supplier would provide design assurance, assurance of onsite installation, security testing, threat-intelligence, and operational assurance.  Additionally they may be required to provide ad-hoc projects and support with incident management and response, digital forensics, security, network and infrastructure consulting.\nSHET seeks suppliers with experience in all of the following;\n\tAudit Review & Compliance\n\tCyber Security Training & Awareness\n\tDesign and Build of Turnkey Cyber Security Services\n\tDigital Forensics\n\tIncident Management & Response\n\tRisk Assessment and Management Services\n\tSecurity Architecture Services\n\tSecurity Consultancy\n\tSecurity Testing\n\tTechnical Cyber Assurance\n\tVulnerability Management\n\tDesirable;\no\tInfrastructure Managed Service Support\no\tNetwork Service Managed Service Support\no\tIT managed services delivery (including but not limited to networking, infrastructure, cybersecurity)\no\tVendor Cyber Assurance Managed Services.\nThere may be a future requirement for IT managed services, IT cybersecurity services and project delivery services to be provided by the supplier, so it is desirable that the supplier have the capability to provide IT managed services (for example but not limited to networking, infrastructure, cybersecurity specialisms) and professional services.  This may include implementing new security tools or architectures.\nThe PIN estimate reflects a combination of day to day capacity, flex contingency, potential ad-hoc projects and support services, and is not a promise or guarantee that the estimate will be reached during the initial or renewal terms.",
        "contractPeriod": {
          "durationInDays": 3600
        }
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "deliveryLocation": {
          "description": "Onsite delivery services to take place in the UK"
        },
        "deliveryAddresses": [
          {
            "region": "UK"
          }
        ]
      }
    ],
    "title": "OT and IT Cybersecurity Services framework",
    "value": {
      "amount": 150000000,
      "currency": "GBP"
    },
    "status": "planned",
    "legalBasis": {
      "id": "32014L0025",
      "scheme": "CELEX"
    },
    "techniques": {
      "frameworkAgreement": {
        "periodRationale": "The cost, resource effort, complexity and business disruption to change a major support partner is substantial; 10 years reflects and reasonable period through which it is desirable to retain the services of a single supplier.  It is desirable to retain a cybersecurity providers services for an extended time so they are deeply familiar with the recent history and practices of the organisation",
        "maximumParticipants": 1
      },
      "hasFrameworkAgreement": true
    },
    "description": "Scottish Hydro Electric Transmission Plc. (SHET) seeks a skilled provider of Operational Technology (OT) cybersecurity assurance services and IT cybersecurity services.  The supplier will act as an independent assurance authority, ensuring that OT systems are designed, delivered and managed in a secure manner and in line with SHET and national standards.\nAmong key responsibilities the prospective supplier would provide design assurance, assurance of onsite installation, security testing, threat-intelligence, and operational assurance.  Additionally they may be required to provide ad-hoc projects and support with incident management and response, digital forensics, security, network and infrastructure consulting.\nThe supplier should be able to provide CREST certified penetration testing services\nThere may be a future requirement for IT managed services, IT cybersecurity services and project delivery services to be provided by the supplier, so it is desirable that the supplier have the capability to provide IT managed services (for example but not limited to networking, infrastructure, cybersecurity specialisms), cybersecurity services and professional services.  This may include implementing new security tools or architectures. \nThe PIN estimate reflects a combination of day to day capacity, flex contingency, potential ad-hoc projects and support services, and is not a promise or guarantee that the estimate will be reached during the initial or renewal terms.",
    "communication": {
      "futureNoticeDate": "2024-08-19T00:00:00+01:00"
    },
    "contractTerms": {
      "hasElectronicPayment": true,
      "hasElectronicOrdering": true,
      "electronicInvoicingPolicy": "allowed"
    },
    "classification": {
      "id": "72600000",
      "scheme": "CPV",
      "description": "Computer support and consultancy services"
    },
    "submissionTerms": {
      "languages": [
        "en"
      ]
    },
    "submissionMethod": [
      "electronicSubmission"
    ],
    "otherRequirements": {
      "requiresStaffNamesAndQualifications": true
    },
    "selectionCriteria": {
      "criteria": [
        {
          "type": "suitability",
          "appliesTo": [
            "supplier"
          ],
          "description": "Prospective suppliers should be able to commit that they have reasonable procedures in place for the prevention of modern slavery, human trafficking, financial crime and bribery\nProspective suppliers should be able to commit to revealing the identity of any third party subcontractors or solutions upon which their delivery of services would be dependent.  SHET may require the right to undertake business probity, financial, cybersecurity and other compliance reviews of subcontractors.\nProspective suppliers may be required to sign a Non-Disclosure-Agreement before security sensitive content is shared with them\nOther or additional conditions of participation may be set out in the final tender documents."
        },
        {
          "type": "economic",
          "appliesTo": [
            "supplier"
          ],
          "description": "Prospective suppliers should have a minimum annual turnover of £50m p.a.\nThe financial standing of a prospective supplier must give SHET reasonable confidence that they can successfully fund the services for the duration and accept reasonable liability in line with the level of risk their project presents to SHET. \nOther/additional requirements may be set out in the final tender documents."
        },
        {
          "type": "technical",
          "minimum": "Prospective suppliers will be required to be accredited to SOC2 or ISO27001 level (or recognized equivalent)\nProspective suppliers should be able to provide personnel based in the UK (during delivery) who have been through enhanced background vetting or carry current security clearance (SC or above).  The same vetting expectation may be required for subcontractors of the supplier who work on the delivery\nProspective suppliers should be knowledgeable in NIST standard SP800-53\nPenetration test personnel provided should be CREST accredited.\nAdditional requirements may be set out in the final tender documents",
          "appliesTo": [
            "supplier"
          ],
          "description": "Prospective suppliers should be able to evidence strong knowledge and experience in the delivery of similar services, at scale; ideally in a critical national infrastructure context.\nProspective suppliers should be familiar with major brands of OT and IT equipment\nAdditional requirements may be set out in the final tender documents."
        }
      ]
    },
    "mainProcurementCategory": "services",
    "submissionMethodDetails": "https://sse.app.jaggaer.com/esop/guest/go/opportunity/detail?opportunityId=387"
  },
  "parties": [
    {
      "id": "GB-COH-SC213461",
      "name": "SCOTTISH HYDRO ELECTRIC TRANSMISSION PLC",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UKM77",
        "locality": "PERTH",
        "postalCode": "PH13AQ",
        "countryName": "United Kingdom",
        "streetAddress": "Inveralmond House,200 Dunkeld Road"
      },
      "details": {
        "url": "https://www.ssen-transmission.co.uk/",
        "classifications": [
          {
            "scheme": "TED_CE_ACTIVITY",
            "description": "IT Services"
          }
        ]
      },
      "identifier": {
        "id": "SC213461",
        "scheme": "GB-COH",
        "legalName": "SCOTTISH HYDRO ELECTRIC TRANSMISSION PLC"
      },
      "contactPoint": {
        "name": "James Pike",
        "email": "james.pike@sse.com"
      }
    },
    {
      "id": "GB-FTS-117914",
      "name": "SSE Plc.",
      "roles": [
        "reviewBody"
      ],
      "address": {
        "locality": "Perth, Scotland",
        "countryName": "United Kingdom"
      },
      "identifier": {
        "legalName": "SSE Plc."
      }
    }
  ],
  "language": "en",
  "initiationType": "tender"
}