This public procurement record has 2 releases in its history.

Tender

02 Oct 2026 at 16:08

Planning

11 Aug 2026 at 10:28

Summary of the contracting process

Merthyr Tydfil County Borough Council, working with the Welsh Government, is procuring a national managed security operations centre (SOC) framework for public bodies and other organisations across Wales whose services are essential to the country’s functioning and resilience. It covers a core managed SOC service and separately ordered additional services. The provider must maintain the security outcomes of the existing CymruSOC 1.0 service while enabling controlled improvement and supporting participants with different technical environments. The service must be independent of any single security information and event management (SIEM) system, and work with approved participant-owned or alternative SIEM and security tools. The framework is intended for participating authorities to place individual service contracts. Delivery is across Wales.

The buyer invited offers through a three-stage competitive flexible procedure. Suppliers first complete a capability assessment, then qualifying suppliers submit participation responses; up to six eligible suppliers can be shortlisted for the tender stage. This is a single-lot, single-supplier framework, with call-off contracts awarded without reopening competition. The framework is intended to run from 1 April 2027 to 31 March 2034. Its estimated value is £90 million excluding VAT (£108 million including VAT). The deadline for enquiries was 14 October 2026 at 12:00, and the deadline for expressions of interest was 16 October 2026 at 12:00. At the final stage, technical and commercial responses are scored: quality carries 80% and price 20%. The top three tenderers before presentations are invited to present; presentations may adjust scores but do not earn additional points.

This opportunity suits managed security providers able to operate a national SOC service and support a range of public-sector technical environments. Suppliers need to demonstrate that their service can sustain security monitoring, incident response, information sharing, interoperability and assurance while working across different SIEM and security-tooling arrangements. The requirement also favours providers capable of onboarding a new service, transferring security data and working with the incumbent to maintain continuity; TUPE may apply, and the incoming provider must comply with the regulations where relevant. Small and medium-sized enterprises are identified as suitable to bid. The framework can be used by public-sector bodies throughout Wales and organisations supporting essential Welsh services, offering the selected supplier a route to individual call-off contracts. The framework contractor must pay a levy to the contracting authority; details are to be provided at the tender stage.

How relevant is this notice?

Notice Information

Notice Title

Cytundeb Fframwaith CymruSOC 2.0 CymruSOC 2.0 Framework Agreement

Notice Description

Bydd CymruSOC 2.0 yn darparu fframwaith SOC a reolir cenedlaethol sy'n cynnwys gwasanaeth SOC craidd a reolir a Gwasanaethau Ychwanegol a archebir ar wahan. Rhaid i'r gwasanaeth gynnal parhad canlyniadau gofynnol CymruSOC 1.0, gan gefnogi gwelliant rheoledig, cyfranogiad ehangach ac amgylcheddau technegol amrywiol y Cyfranogwyr. Rhaid i'r gwasanaeth barhau i fod yn annibynnol ar unrhyw SIEM penodol a rhaid iddo gefnogi trefniadau SIEM ac offer diogelwch eraill sydd naill ai'n eiddo i Gyfranogwyr neu'n drefniadau amgen a gymeradwywyd, lle gellir cyflawni'r canlyniadau gofynnol o ran diogelwch, monitro, rhannu gwybodaeth, rhyngweithrededd a sicrwydd. Mae rhagor o wybodaeth fanwl ar gael yn y Datganiad o'r Gofynion, a ddarperir fel atodiad yng Ngham 1 ar eDendroCymru. Mae hwn yn gaffaeliad cydweithredol sy'n cael ei gynnal gan Gyngor Bwrdeistref Sirol Merthyr Tudful (yr Awdurdod Contractio) mewn partneriaeth a Llywodraeth Cymru, a bydd yn ceisio sefydlu Cytundeb Fframwaith un lot gydag un cyflenwr er mwyn galluogi awdurdodau sy'n cymryd rhan i alw i lawr a chreu contractau ar gyfer y gwasanaethau sydd eu hangen arnynt. Bydd yn ofynnol i'r tendrwr llwyddiannus ymrwymo i Gytundeb Fframwaith gyda'r Awdurdod Contractio ac, wedi hynny, ymrwymo i gontractau unigol gan ddefnyddio templed contract galw i lawr gydag awdurdodau sy'n cymryd rhan drwy'r weithdrefn galw i lawr. Er budd tryloywder ac er mwyn rhoi gwybod i ddarpar dendrwyr cyn gynted a phosibl, mae'r contractwr presennol wedi nodi y bydd TUPE yn berthnasol i'r caffaeliad hwn. Yn unol a'r rheoliadau, rhaid i'r contractwr presennol a'r contractwr newydd a ddyfernir i'r Fframwaith o ganlyniad i'r caffaeliad hwn gydymffurfio a rheoliadau TUPE lle maent yn berthnasol. Bydd gwybodaeth TUPE yn cael ei darparu i dendrwyr ar y rhestr fer yng Ngham 3. CymruSOC 2.0 will provide a national managed SOC framework comprising a Core managed SOC service and separately ordered Plus Services. The service must preserve continuity of the required CymruSOC 1.0 outcomes while supporting controlled improvement, wider participation and different Participant technical environments. The service must remain SIEM-agnostic and must support approved Participant-owned and alternative SIEM and security tooling arrangements where the required security, monitoring, information-sharing, interoperability and assurance outcomes can be achieved. Further detailed information can be located in the Statement of Requirements which is provided as an attachment within Stage 1 on eTenderWales. This is a collaborative procurement being conducted by Merthyr Tydfil County Borough Council (the Contracting Authority) in partnership with Welsh Government and will seek to put in place a single-Lot single supplier Framework Agreement for participating authorities to be able to call off and create contracts for the services they require. The successful tenderer will be required to enter into a Framework Agreement with the Contracting Authority and subsequently enter into individual contracts, using a call off contract template, with participating authorities via the call off procedure. In the interests of transparency and to make potential tenderers aware at the earliest stage, the incumbent contractor has indicated TUPE will apply to this procurement. As per the regulations, the incumbent contractor and new contractor awarded to the Framework as a result of this procurement must adhere to the TUPE regulations where they may apply. TUPE information will be provided to shortlisted tenderers in Stage 3.

Planning Information

Bydd y weminar yn cael ei chynnal ar 18 Awst am 14:00. Defnyddiwch y ddolen ganlynol i ymuno â’r weminar: https://teams.microsoft.com/meet/37963638632896?p=OoDn5RZJZdNDBKPT4W Meeting ID: 379 636 386 328 96 Passcode: zQ2wy7aJ The webinar will be held on 18th August at 14:00hrs. Please use this link to joint the webinar - Join: https://teams.microsoft.com/meet/37963638632896?p=OoDn5RZJZdNDBKPT4W Meeting ID: 379 636 386 328 96 Passcode: zQ2wy7aJ

Notice Details

Publication & Lifecycle

Open Contracting ID
ocds-h6vhtk-06e0f5
Publication Source
Find A Tender Service
Latest Notice
https://www.find-tender.service.gov.uk/Notice/093506-2026
Current Stage
Tender
All Stages
Planning, Tender

Procurement Classification

Notice Type
UK4 - Tender Notice
Procurement Type
Framework
Procurement Category
Services
Procurement Method
Selective
Procurement Method Details
Competitive flexible procedure
Tender Suitability
SME
Awardee Scale
Not specified

Common Procurement Vocabulary (CPV)

CPV Divisions

72 - IT services: consulting, software development, Internet and support


CPV Codes

72000000 - IT services: consulting, software development, Internet and support

Notice Value(s)

Tender Value
£90,000,000 £10M-£100M
Lots Value
£90,000,000 £10M-£100M
Awards Value
Not specified
Contracts Value
Not specified

Notice Dates

Publication Date
2 Oct 20264 days ago
Submission Deadline
Not specified
Future Notice Date
21 Sep 2026Expired
Award Date
Not specified
Contract Period
1 Apr 2027 - 31 Mar 2034 Over 5 years
Recurrence
Not specified

Notice Status

Tender Status
Active
Lots Status
Active
Awards Status
Not Specified
Contracts Status
Not Specified

Buyer & Supplier

Contracting Authority (Buyer)

Main Buyer
Merthyr Tydfil County Borough Council
Contact Name
Available with D3 Tenders Premium →
Contact Email
Available with D3 Tenders Premium →
Contact Phone
Available with D3 Tenders Premium →

Buyer Location

Locality
MERTHYR TYDFIL
Postcode
CF47 8AN
Postcode Area
Cardiff
Country
Wales

Major Region (ITL 1)
TLL Wales
Basic Region (ITL 2)
TLL5 South East Wales
Small Region (ITL 3)
TLL51 Central Valleys and Bridgend
Delivery Location
TLL Wales

Local Authority
Merthyr Tydfil
Electoral Ward
Town
Westminster Constituency
Merthyr Tydfil and Aberdare

Further Information

Notice Documents

Open Contracting Data Standard (OCDS)

View full OCDS Record for this contracting process

JSON Markdown

The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.

Loading OCDS record...