Managed Security Operations Center (SOC) - 24/7

Open/public
Start date: 06-11-2025 - 10:30
End date: 05-12-2025 - 12:00

Establishment of a 24/7 Security Operations Center (SOC)

Issued by: EVIDA

Introduction

EVIDA is exploring the establishment of a 24/7 Security Operations Center (SOC) to enhance its cybersecurity posture and ensure continuous monitoring, detection, and response to security incidents across its infrastructure. This can be for IT, for OT and for both IT and OT. This RFI is intended to gather information from qualified vendors to inform a potential future procurement process.

Purpose of the RFI

The purpose of this RFI is to:

• Understand the capabilities of the market in delivering SOC services.

• Identify best practices and innovative approaches to 24/7 security monitoring.

• Assess the feasibility, scalability, and cost implications of various SOC models (in-house, outsourced, hybrid).

• Include is the Request for Proposal (RFP).

Scope of Services

Vendors are requested to provide information on their ability to deliver the following services:

• 24/7/365 monitoring of IT and OT environments.

• Threat detection, analysis, and incident response.

• Integration with SIEM, SOAR, and threat intelligence platforms.

• Vulnerability management and threat hunting.

• Compliance monitoring (e.g., NIS2, ISO 27001).

• Reporting and dashboards for KPIs and SLAs

Attached documents
10. November 2025 - Søren Nielsson, GLOBALCONNECT A/S
Questions
Response form and format?

Do you have a preferred response form and format for the suppliers to respond to your RFI? 

  • Replying in a separate document (Excel?)?
  • Adding a Response column to the right of your questions column in your Excel RFI sheet?  
  • Other? 

10. November 2025 - Søren Nielsson, GLOBALCONNECT A/S
Questions
2.3 Compliance

In item #2,3 Compliance you write: "Does your employees/specialists adhere to the OT security specialists guidance reference from the Danish Energy Ministry (attached)"


We have not been able to find such an attachment. Please advise.

10. November 2025 - Søren Nielsson, GLOBALCONNECT A/S
Questions
3.1 Architecture & Platform

In 3.1 you write: "The service must be operated fully out of the European Union"


Could this be expanded to the EEA (the 27 EU member states plus three non-EU countries: Iceland, Liechtenstein, and Norway)?


13. November 2025 - Mikkel Larssen, BDO Statsautoriseret Revisionspartnerselskab
Questions
Additional information needed

1. There are several questions about our capability to integrate with EVIDA’s system such as OT SIEM. Is there a chance you can share more details about your environment? In addition, to answer many of your questions about Detection and Response, we’ll need to know which security systems you already have.


2. In 6.2 you write that the service must be delivered by personnel with security clearance. Can you please let us know what will be accaptable for Israelian citizens that will be part of the solution offered by BDO?

13. November 2025 - Morten Stenfeldt Bølle, Mnemonic Cybersecurity Danmark, filial af Mnemonic AS, Norge
Questions
Form and format of the RFI answer

Hi!
We would like some additional clarification regarding the level of detail in the first RFI - round of this tender. 
 
Do you want us to make a complete offer and answer all the requirements in the RFP excel-sheet in this RFI-round?

Or would you like us to present our servies more broadly based on your requirements, while the document is included to prepare us for a next round if we qualify?


14. November 2025 - Anonymous
Questions
Vulnerability scans

What vulnerability scanning tool is currently in place and are your management requirements configuration only or full scanner infrastructure management?

14. November 2025 - Valentin CAYROU, SCHNEIDER ELECTRIC DANMARK A/S
Questions
Current monitoring information

  • If monitoring is already in place, what is the current log volume per day for OT and IT and is transition from an incumbent provider required as part of this exercise?
  • In the RFI, it is requested to integrate with the current OT SIEM, could you tell us what is the current OT SIEM solution?
  • What level of logging will be shared with the MSS provider (firewall, IDS, EDR/EPP, authentication logs)?

14. November 2025 - Valentin CAYROU, SCHNEIDER ELECTRIC DANMARK A/S
Questions
EVIDA’s NDA and NPA

To answer questions 8.4 and 8.5 in the RFI, could you please share EVIDA’s NDA and NPA documents? We haven't been able to find those attached to this RFI. 

14. November 2025 - Valentin CAYROU, SCHNEIDER ELECTRIC DANMARK A/S
Questions
Data and Operation Residency

Can we utilise specialist resources from other regions thank Europe, if we ensure Data is kept within EU ?

18. November 2025 - Søren Nielsson, GLOBALCONNECT A/S
Questions
Timeline

Can you say anything about when you expect / want the outlined new solution to be Ready for Service?

19. November 2025 - Søren Nielsson, GLOBALCONNECT A/S
Questions
OT section - 1.1 Commercial

You write: "Please provide a net price example for 900 PLC'er, 4000 IP'er og 100 servers for: 3 year contract term (in DKK)"


Can you elaborate or describe in more details what you mean by "IP'er" here? 

19. November 2025 - Søren Nielsson, GLOBALCONNECT A/S
Questions
OT section - 3.2 Architecture & Platform

You write: "The service must be offered based on the EVIDA’s Trellix for Endpoint clients"


Please 

1. elaborate what you mean by "based on" 

and 

2. could you state the number of clients?

19. November 2025 - Marc Brændstrup, SIEMENS AKTIESELSKAB
Questions
2,3 - Guidance from the Danish Energy Ministry

How do we get access to this guidance from the Danish Energy Ministry ?

19. November 2025 - Anonymous
Questions
RFP dialogue

Don't see anywhere in the Comdia portal to submit the filled sheet RFP answer, how should this be done?

19. November 2025 - Anonymous
Questions
NDA / DPA Templates

The RFP sheet refers EVIDA NDA and DPA standard templates.

Could You please share those for review and possible comments? 

20. November 2025 - Henrik Andersen, CSIS SECURITY GROUP A/S
Questions
Clarification to RFI questions

Hi Evida

We have following questions to the RFI:

OT 3.5 Which network devices do you have in mind?

OT 5.1 Which SIEM do you have in mind?

OT 5.13 Which Log System do you have in mind?

IT 5.13 Which Log System do you have in mind?

Additionally:

• If monitoring is already in place, what is the current log volume per day for OT and IT and is transition from an incumbent provider required as part of this exercise?

• In the RFI, it is requested to integrate with the current OT SIEM, could you tell us what is the current OT SIEM solution?

• What level of logging will be shared with the MSS provider (firewall, IDS, EDR/EPP, authentication logs)?

• There are several questions about our capability to integrate with EVIDA’s system such as OT SIEM. Is there a chance you can share more details about your environment? In addition, to answer many of your questions about Detection and Response, we’ll need to know which security systems you already have.


24. November 2025 - Anonymous
Questions
OT sites

How many Sites do you have where OT assets exist ?

How many OT switches do you want to take a copy of their traffic in each site and in total

24. November 2025 - Anonymous
Questions
Protection priorities

What are your protection priorities (availability, integrity or confidentiality) for the OT assets?

27. November 2025 - Simon Søndergaard Bitsch, Evida
Idea
Clarification

If any potential suppliers need to send us something that they do not wish to share with others, please contact meran@evida.dk. 

Furthermore, we apologize for the long response time and have therefore extended the market dialogue until 05.12.2025.