Gå til hovedindhold
UdbudsScanner
Alle udbud
TED603665-2026

Tender for a framework agreement on the delivery of Cybersecurity advisory and assessment services

Oplyst værdi / estimat
9.200.000 DKK
Frist
Publiceret
2.9.2026
Leveringssted (NUTS)
DK011, DNK

Dataposten opdateret . Datakilder, dækning og beregningsmetode.

Beskrivelse
Danmarks Nationalbank (the Customer) seeks to establish a framework agreement with one Supplier for the provision of specialized cybersecurity advisory and assessment services. As the operator and overseer of critical financial infrastructure in Denmark, Danmarks Nationalbank supports essential processes and systems that require a high level of security, resilience, and trust. The Customer continuously introduces new technologies, vendors, services and architectural changes that may impact its security posture. To ensure informed decision-making and maintain an appropriate level of cyber resilience, the Customer seeks access to independent technical experts capable of evaluating cybersecurity risks from an adversarial perspective. The purpose of the agreement is to provide the Customer with on-demand access to highly skilled technical cybersecurity experts with offensive security backgrounds, capable of delivering rapid, pragmatic and risk-based assessments of new technologies, systems, solutions, architectures and security-related questions. The service shall complement the Customer's internal cybersecurity capabilities by providing independent expert judgement, specialized technical expertise and threat-informed analysis to support secure decision-making, risk management and operational resilience. The Supplier shall provide access to cybersecurity specialists with relevant expertise across infrastructure, cloud, applications, identity and access management, emerging technologies, adversarial techniques and offensive security methodologies.

Procedure og udbudsmateriale

Oplysninger fra bekendtgørelsen kan dække flere delkontrakter. Listerne nedenfor er separate uddrag; rækkefølgen kobler ikke et kriterium til en beskrivelse eller delkontrakt. Kontrollér krav, vægtning, frister, optioner og eventuelle rettelser i originalmaterialet.

Proceduretype (kildens kode)

  • restricted

Tildelingskriterier

  • Price
  • Competences
  • Collaboration model
  • Risk management and information security

Beskrivelser af tildelingskriterier

  • Cfr. Appendix A to the tender specificaitons.
  • Cfr. Appendix A to the tender specifications

Beskrivelser af krav til deltagelse

  • The candidate must submit the ESPD with the following information: A list of the 5 most significant comparable services that the candidate has carried out in the latest 3 years before the expiry of the deadline for application. Only references relating to services carried out at the time of the deadline for application will be given importance in the evaluation of whether the requirements regarding technical and professional capacity have been complied with, see below. Hence, in the case of an ongoing task, only the part of the services already performed at the time of the deadline for application will be included in the evaluation of the reference. Each reference is requested to include a brief description of the deliveries made. The description of the delivery should include a clear description of the services to which the delivery relates and the candidate’s role(s) in the performance of the delivery. The reference is furthermore requested to include the financial value of the delivery (amount), the date of delivery and the name of the customer (recipient). When indicating the date of the delivery, the candidate is requested to indicate the date of commencement and finalisation of the delivery. If this is not possible, for example if the tasks were performed on a continuous basis under a framework agreement, the candidate is asked to indicate how the date is specified. No more than 5 references may be stated, irrespective of whether the candidate is a single operator, whether the candidate relies on the technical capacity of other entities, or is a group of operators (e.g. a consortium). Where more than 5 references are stated, only the most recent 5 references will be taken into account. Any additional references will be disregarded. If it is not possible to decide which references are the most recent 5 references, the references will be selected by drawing lots. In this procedure, the candidate may rely on the technical capacity of other operators to fulfil the suitability requirements. The operator(s) making its/their technical capacity available to the candidate must sign a letter of commitment, see further in the tender specifications. The form is enclosed as an attachment to the tender specifications. If the candidate relies on the professional experience of other entities for the performance of specific parts of the services comprised by the contract, such specific parts of the services under the contract must be performed by the entity on which the candidate relies. The ESPD serves as provisional documentation that the candidate fulfils the requirements in respect of technical and professional capacity. Before the award decision is made, the candidate to whom the contracting entity intends to award the contract must submit documentation that the information stated in the ESPD is accurate. No additional documentation of technical and professional capacity will be required from the candidate. However, the contracting entity reserves the right to contact the tenderer or the customer stated in the reference for verification of the information stated in the reference, including the dates of the reference indicated. Minimum requirement: as a minimum requirement for participation, the candidate must provide documentation of at least one (1) reference for the provision of specialized cybersecurity advisory and assessment services.
  • Criteria for selection among the suitable candidates. The shortlisting of candidates invited to tender will be based on an evaluation of which candidates have documented the most relevant specialized cybersecurity advisory and assessment services in relation to the main services put up for tender. The relevance assessment will be made on the basis of the extent to which the references, combined, document experience in the provision of services that are comparable to the main services put up for tender. In the evaluation of which candidates have documented the most relevant services, the contracting entity will award points to the candidates on a scale from 1-5 for each main service, based on the extent to which the references, combined, document relevant experience in providing the main services. On this basis, the candidate will be awarded a total score calculated as the average number of points awarded for the main services. In the selection, the contracting entity will place particular emphasis on the following main services: • Demonstrated experience with delivery of similar services into central banking, financial sector or similar regulated environments • Demonstrated experience with providing a multidisciplinary team across relevant areas such as technical assessment, advisory, AI assurance, operational resilience and incident readiness • Demonstrated experience in technical assurance/technical validation activities in live, business-critical or production environments • Demonstrated experience in delivering similar services including communication with both technical and non-technical customer resources • Demonstrated experience with delivering similar services in various it-environments, ex. Cloud, outsourced, on-prem and in-house devel-oped systems

Udbudsmateriale

Aflevering af tilbud

Andre bekendtgørelser i samme CPV-kategori

Nyeste bekendtgørelser med samme firecifrede CPV-kategori. Listen kan omfatte både åbne udbud og historik.