8 days leftIT consultingFramework agreementPolski

Framework agreement Support for IT security

Investitionsbank Schleswig-HolsteinKiel, GermanyNotice 665122-2026

At a glance

Investitionsbank Schleswig-Holstein (Kiel, Germany) is tendering: Framework agreement Support for IT security. Offers are due 12 Oct 2026, 10:00 CEST. 2 lots. Bidders must show, among other things: references, key people, minimum turnover, insurance.

12 Oct 2026, 10:00 CEST
Deadline
Negotiated with call
Procedure
IT services: consulting, software development, Internet and support (72000000)
Main CPV
28 Sept 2026
Published

Translated from the official notice. The original text is the legally binding one.

What the buyer wants

A framework agreement is to be concluded between IB.SH and three service providers. The framework agreement governs task assignments that are issued on the one hand by IB.SH and encompass the following services: ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Description of activities: • Support for the client in technical and technical-organizational matters of IT security / cyber security based on the strategies, policies, roles, and responsibilities specified by the client; the list of services is not exhaustive. • Development, concretization, updating, and monitoring of technical IT security standards, technical specifications, operational processes, runbooks, and implementation guidelines within the scope of existing internal specifications. • Risk-based assessment, classification, and implementation support for technical IT security requirements arising from operations, change management, projects, architecture, service provider management, regulatory requirements, and internal guidelines. • Support in technical IT security, digital operational resilience, restart and recovery capabilities, as well as the continuity of critical IT services, including technical contributions to scenario analyses, emergency drills, alternative procedures, fallback/exit scenarios, and action tracking. • Initiation, evaluation, implementation, and tracking of operational security measures for IT infrastructures, applications, platforms, end devices, and operating environments, including on-premises, private cloud, public cloud, hybrid cloud, multi-cloud, as well as SaaS/PaaS/IaaS environments. • Coordination, evaluation, and further development of technical security architectures, including network and zone concepts, segmentation, firewalling, encryption, PKI, DNSSEC, proxy/gateway services, IAM/PAM, endpoint security, server/client hardening, cloud, container/Kubernetes, and API security, as well as secure administration models. • Initiation, accompaniment, evaluation, and follow-up of vulnerability analyses, penetration tests, technical security reviews, configuration and hardening checks, readiness checks, as well as red/purple team or comparable technical security exercises. • Monitoring and evaluation of external reports on vulnerabilities, threats, attack patterns, and security-relevant industry developments, as well as derivation, accompaniment, and documentation of technical measures. • Support with security monitoring, logging, detection, and response, particularly regarding SIEM/SOC requirements, log source onboarding, use case design, alert tuning, detection engineering, SOC provider steering, triage processes, playbooks, escalation paths, and security-related reporting. • Technical support in the handling, containment, analysis, documentation, and post-incident review of IT security incidents, including interfaces with incident, problem, change, emergency, and service provider management. • Technical-functional review, evaluation, and follow-up of service provider reports, security verifications, action plans, audit findings, and internal audit points. • Maintenance, updating, and quality assurance of technical IT security documentation, runbooks, control descriptions, verification documentation, and technical security concepts. • Technical-functional input for audits, internal audits, and regulatory evidence; this does not include the execution of original auditing, internal audit, or control functions. • Support for the Data Protection Officer on technical matters as well as coordination and cooperation with the Information Security Officer / Information Security Management. • Implementation of awareness-raising measures for employees on the subject of IT security. • Proactive identification, assessment, and target-audience-oriented preparation of technical IT security topics with…

Die Investitionsbank Schleswig-Holstein (IB.SH) das zentrale Förderinstitut des Landes mit derzeit knapp 900 Mitarbeitern und Mitarbeiterinnen sucht drei Rahmenvertragspartner als IT-Dienstleister für die Erbringung von IT-Unterstützungsleistungen im Bereich der IT-Security. --------------------------------------------------------------------------------------------------------------------------------------------------------------- Es ist der Abschluss, der in den Unterlagen als Anlage 1 beigefügten Rahmenvereinbarung, der Vereinbarung zur Auftragsverarbeitung mit den drei Bietern, die die Mindestkriterien erfüllen und Plätze 1-3 belegen, beabsichtigt. --------------------------------------------------------------------------------------------------------------------------------------------------------------- Die von der IB.SH konkret benötigten Unterstützungsleistungen werden unter Berücksichtigung der Arbeits- und Projektsituation, Qualifikation, Verfügbarkeit im Rahmen von Mini- Wettbewerben abgerufen. Die Gestaltung dieser Einzelabrufe ist in der Anlage 3 Rahmenvereinbarung geregelt (s. § 2 der Rahmenvereinbarung). ---------------------------------------------------------------------------------------------------------------------------------------------------------------

Lots (2)

  1. Lot 1Framework agreement Support for IT security

    A framework agreement is to be concluded between IB.SH and three service providers. The framework agreement governs task assignments that are issued on the one hand by IB.SH and encompass the following services: ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Description of activities: • Support for the client in technical and technical-organizational matters of IT security / cyber security based on the strategies, policies, roles, and responsibilities specified by the client; the list of services is not exhaustive. • Development, concretization, updating, and monitoring of technical IT security standards, technical specifications, operational processes, runbooks, and implementation guidelines within the scope of existing internal specifications. • Risk-based assessment, classification, and implementation support for technical IT security requirements arising from operations, change management, projects, architecture, service provider management, regulatory requirements, and internal guidelines. • Support in technical IT security, digital operational resilience, restart and recovery capabilities, as well as the continuity of critical IT services, including technical contributions to scenario analyses, emergency drills, alternative procedures, fallback/exit scenarios, and action tracking. • Initiation, evaluation, implementation, and tracking of operational security measures for IT infrastructures, applications, platforms, end devices, and operating environments, including on-premises, private cloud, public cloud, hybrid cloud, multi-cloud, as well as SaaS/PaaS/IaaS environments. • Coordination, evaluation, and further development of technical security architectures, including network and zone concepts, segmentation, firewalling, encryption, PKI, DNSSEC, proxy/gateway services, IAM/PAM, endpoint security, server/client hardening, cloud, container/Kubernetes, and API security, as well as secure administration models. • Initiation, accompaniment, evaluation, and follow-up of vulnerability analyses, penetration tests, technical security reviews, configuration and hardening checks, readiness checks, as well as red/purple team or comparable technical security exercises. • Monitoring and evaluation of external reports on vulnerabilities, threats, attack patterns, and security-relevant industry developments, as well as derivation, accompaniment, and documentation of technical measures. • Support with security monitoring, logging, detection, and response, particularly regarding SIEM/SOC requirements, log source onboarding, use case design, alert tuning, detection engineering, SOC provider steering, triage processes, playbooks, escalation paths, and security-related reporting. • Technical support in the handling, containment, analysis, documentation, and post-incident review of IT security incidents, including interfaces with incident, problem, change, emergency, and service provider management. • Technical-functional review, evaluation, and follow-up of service provider reports, security verifications, action plans, audit findings, and internal audit points. • Maintenance, updating, and quality assurance of technical IT security documentation, runbooks, control descriptions, verification documentation, and technical security concepts. • Technical-functional input for audits, internal audits, and regulatory evidence; this does not include the execution of original auditing, internal audit, or control functions. • Support for the Data Protection Officer on technical matters as well as coordination and cooperation with the Information Security Officer / Information Security Management. • Implementation of awareness-raising measures for employees on the subject of IT security. • Proactive identification, assessment, and target-audience-oriented preparation of technical IT security topics with…

  2. Lot 2

What a bidder needs

Can you bid? Your readiness check

These are the conditions this notice asks bidders to prove. In SalesDots each one is checked against your company profile: certificates with their validity dates, delivered references and your people.

Example company profile
  • References

    Similar contracts delivered before

    In your profile
  • Key people

    Named roles, CVs or minimum team

    Not in your profile yet
  • Minimum turnover

    Minimum annual turnover or financial standing

    In your profile
  • Insurance

    Professional or liability insurance

    Expires before the deadline

Detected automatically in the published notice. Always confirm against the tender documents.

Check it against my company
Show the notice text (13)

1. self-declaration that there is an entry in the professional or commercial register or another comparable proof of the permitted professional practice. Note: GMSH will, if necessary, request the corresponding proof before awarding the contract.

2. On the basis of the (group) annual financial statements of the company’s last completed financial year (2025) and, if applicable, the (group) annual financial statements of the parent company’s last financial year (if the bidding part of the company is a subsidiary), a rating of the providers acc. the official DSGV or RSU corporate rating procedure by the credit division of IB.SH. The ratings are subsequently categorised. Providers with a DSGV / RSU corporate rating of 12 or worse are not further considered in the procedure = exclusion of proceedings.

3. Self-declaration on proof of a correspondingly existing company liability insurance or that this is concluded accordingly in the case of conclusion of a contract (according to § 45 para 1 no. 3 VgV). The insurance liability for personal, property and property damages should be at least € 4 million.

4. Professional qualification of the applicant (know-how and customer references): description of the range of services, know-how and experience of the company in providing the requested IT security assistance; a description of the business lines in which it operates; A list of min. 3 suitable references on previously executed service contracts in the area of banks, among others already in the development banking environment, in the form of a list of the main comparable services provided in the last three years (2023 - 2025) with keyword-like description (e.g. on the subject of the investigation, range of services) and indication of the service period, the client (municipality) including contact person for reference check with contact details (address, telephone) or reference letter and the scope of the order.

5. Self-declaration on resource availability in relation to the desired term of the contract.

6. A meaningful description of the measures for quality assurance and quality management (max. 10 DIN A4 pages).

7. Self-declaration (form) on contracts and concessions above the EU thresholds implementing Article 5k of Regulation (EU) No 833/2014 concerning restrictive measures in view of Russia's actions destabilising the situation in Ukraine, inserted by Council Regulation (EU) 2022/576 of 8 March 2022. April 2022. The form shall form part of the procurement documents.

8. Self-declaration that the minimum requirements specified in the attached specifications are met.

9. self-declaration that the register of competitions does not contain negative entries. Note: GMSH will obtain a competition register extract before awarding the contract.

10. Self-declaration that the contractor acknowledges the tender conditions and has not entered into any cartel agreements, fixed prices or similar agreements, and excludes the validity of company's own General Terms and Conditions (GTC) and, if these are used on the back of business letters or are attached in any other form to the request for participation, do not become effective. Self-declaration that there is no compelling reason for exclusion according to § 123 and § 126 GWB, unless self-cleaning according to § 125 GWB has taken place. If there is an optional exclusion reason according to § 124 and § 126 GWB and no self-cleaning has taken place according to § 125 GWB, the participation depends on a discretionary decision of the client. If an optional reason for exclusion also affects the commercial reliability within the meaning of § 158 No. 4 BauGB, an exclusion takes place.

12. Presentation of sustainability in the company (work paths of employees, measures relating to training, flexible working models, mobility in the company, energy measures).

13. Self-declaration of the applicant that the obligations under the Minimum Wage Act (MiLoG) are complied with and that any subcontractors commissioned by the applicant in the context of the implementation of a possible contract and their subcontractors also comply with the requirements of MiLoG.

14. Design of the participation documents and meaningful company presentation incl. Service portfolio (name, address, legal form, ownership structure, organisational structure, company size in the relevant segment, personnel, locations, date of incorporation, history, telephone and e-mail address, VAT identification number, bank details, description of the company branch that will provide the advertised service, date of incorporation for this company branch, customers in Germany, other meaningful documents that enable the client to obtain an overall picture of the company).

How offers are scored

  • With the offer, the fully completed price sheet must be entered..30%
  • Presentation of the organisation, qualification and experience of the ..50%
  • Quality of the concept (composition and organization of the team,..10%
  • Presentation of the offer during the negotiation10%

What this buyer bought before

Recent IT contracts awarded by the same buyer, from published award notices.

  • Unterstützungsleistungen im Rahmen der Implementierung einer zentralen Datenplattform

    Winner: Bietergemeinschaft CAS Concepts and Solutions AG & ARREBA Consulting GmbH

    €1

    9 Mar 2026

  • Rahmenvereinbarung zur Erbringung von Unterstützungsleistungen in der Anwendungsbetreuung Data Warehouse

    Winner: InfoFabrik GmbH

    €1

    15 Dec 2025

  • Bereitstellung und Betrieb einer Software für das Personalmanagement in der IB.SH

    Winner: GuideCom AG

    €1

    15 Sept 2025

  • Erbringung von Unterstützungsleistungen im IT Implementierungsmanagement sowie IT-Anwendungsbetreuung und SAP-Anwendungsbetreuung bzw. Anwendungsentwicklung

    Winner: KPMG AG WPG + syracom AG + PricewaterhouseCoopers GmbH WPG + d-fine GmbH + Finbridge GmbH & Co. KG + Be Shaping The Fut…

    €1

    14 Jul 2025

  • Bereitstellung und Betrieb SaaS-Lösung zum PeP- und Sanktionsabgleich für die IB.SH

    Winner: ACTICO GmbH

    €1

    16 Dec 2024

  • Germany-Kiel: Software development services

    Winner: msgGillardon AG

    €478,400

Win it with SalesDots

Read the documents for you

SalesDots fetches the tender documents (or takes your upload when a platform does not allow it) and answers the two questions that matter first: what the buyer wants built, and what you must prove to take part, each with the exact quote and page.

Analyse documents

Match it with your profile

Every certificate, reference and role is checked against your company: green when you have it, amber when it expires before the deadline, grey when it needs a look.

Check my fit

Prepare your response

Turn the conditions into a bid checklist with owners and due dates, draft the questions to the buyer and keep the team on one plan.

Start a response

Never miss a change

Track the deadline, amendments and answers to clarification questions, and get similar tenders and re-tenders before they are published.

Track this tender

Source: Tenders Electronic Daily (TED), Official Journal of the EU. SalesDots is not the contracting authority; offers are submitted only through the buyer's platform.