Closed tender

Supplier Cyber Protection Service

Details

Value
GBP 2,050,000
Published
7 December 2022
Submission
21 December 2022

Tender description

Summary of the work The Cyber Resilience Programme requires a transactional digital service for use by the Ministry of Defence (MOD) and its suppliers that will support the Defence Cyber Protection Partnership (DCPP) governed Cyber Security Model (CSM) and enable continuous cyber risk profiling of Defence’s supply chain. Expected Contract Length The expected contract length is 18 months. Latest start date Monday 3 April 2023 Budget Range Pricing proposals are to cover the delivery of the service for an 18-month contract period. Proposal costs are not to exceed £2,050,000 ex VAT. Why the Work is Being Done The Supplier Cyber Protection Service (SCPS) is a required transactional digital service for use by the Ministry of Defence (MOD) and its suppliers. The SCPS will support the Defence Cyber Protection Partnership (DCPP) governed Cyber Security Model (CSM), enabling continuous cyber risk profiling of Defence’s supply chain. Further detail on the CSM can be found here: https://www.gov.uk/guidance/defence-cyber-protection-partnership The previous SCPS digital solution was retired in 2021. Since then, a manual interim process has been operated by the MOD’s Cyber Supply Chain Security (CSCS) team within MOD Defence Digital. A replacement digital SCPS solution was brought into limited operation during 2022 . This development ceased at the private beta phase. The Authority seeks a new supplier to refresh the findings from previous discovery activity, define an enduring service and deliver that service. Problem to Be Solved An SCPS solution (‘SCePTre’) was partially developed and brought into private beta during 2022. While the user interface and business logic implementation was accepted, the architecture and support wrap could not achieve the desired level of MOD and Government Service Standard compliance. Development therefore ceased. After the supplier is contracted, the Authority will endeavour to provide SCePTre Intellectual Property (IP), with the intention to accelerate understanding of the problem. The supplier is encouraged to use SCePTre IP to de-risk delivery. However, if using such IP, it will need to conduct its own due diligence and take responsibility for delivery of the service. Who Are the Users The users are personnel within the MOD and the Defence Supply Chain (DSC). The DSC will access the service via the public internet at the following URL: https://www.supplier-cyber-protection.service.gov.uk/ Key user roles are: Buyers: MOD staff or industry staff applying flow down to sub-contracts. Buyers need to use the digital service to quantify the level of cyber risk to a contract by completing a Risk Assessment (RA), which results in a Cyber Risk Profile and Risk Assessment Reference (RAR) to provide to their bidders (and suppliers for extant contracts) to respond to. Buyers will also review and accept (or otherwise) supplier responses and conduct RA renewals. Suppliers: Organisations supplying (or bidding to supply) a contract that will handle MOD Identifiable information (MODII). They complete a Supplier Assurance Questionnaire (SAQ) to provide assurance to their Buyer that their cyber security controls and processes will adequately protect MODII in line with the Cyber Risk Profile that has been shared with them. Suppliers need to be able to apply the Risk Assessment and Supplier Assurance process down through their own supply chain for organisations involved in delivering the contract. Early Market Engagement Not applicable. Work Already Done An SCPS solution (‘SCePTre’) was partially developed and brought into private beta during 2022. While the user interface and business logic implementation was accepted, the architecture and support wrap could not achieve the desired level of MOD and Government Service Standard compliance. Development therefore ceased. On contract start, the Authority will endeavour to provide SCePTre Intellectual Property (IP), with the intention to accelerate understanding of the problem. The supplier is encouraged to use SCePTre IP to de-risk delivery. However, if using such IP, it will need to conduct its own due diligence and take responsibility for delivery of the service. Existing Team The supplier will work alongside the Secure in Depth project team and key user teams (consisting of internal MOD personnel and other suppliers) to ensure alignment between the business and technical architecture layers of the capability that the project will deliver. Current Phase Not started Skills & Experience • Evidence and experience of agile delivery for MOD or a similar organisation. • Evidence and experience of delivering cloud services for MOD or a similar organisation. • Evidence and experience of delivering cloud hosted applications for MOD or a similar organisation. • Knowledge and experience of delivering technical solutions in compliance with MOD policies, including JSP440 and JSP604, or similar industry standards. • Evidence and experience of working to the Government Service Standard. • Evidence and experience of applying secure architecture design throughout delivery. • Evidence and experience of gaining security accreditation of ICT in MOD or a similar organisation. • Evidence and experience of conducting user research in previous deliveries. Nice to Haves • Recent experience deploying applications into MODCloud or similar organisation environments. • Evidence and experience of applying a DevSecOps approach throughout delivery. • Evidence and experience of agile coaching in MOD or a similar organisation. Work Location No specific location, although the supplier may be required to attend meetings at MOD sites, in particular MOD Corsham and London. T&S will be available for potential site visits, in line with MoD policy. Working Arrangments The supplier is expected to work collaboratively with the Secure in Depth project team and other stakeholders, attending face to face meetings as required. It is expected that the supplier will be able to work under own initiative once tasked and attend relevant MOD locations as required to deliver service outcomes. Security Clearance The minimum level of national security vetting required to work on the contract is SC clearance. Clearances must be in place prior to the contract start date, and must be valid for the duration of the contract. Evidence of validity is required. Additional T&Cs All expenses must be pre-agreed between the parties and must comply with the MOD Travel and Subsistence (T&S) Policy. Suppliers must use the Authority’s Purchase to Payment Tool CP&F or be prepared to sign up to the tool. In accordance with DEFCON 658 a Cyber risk assessment has been undertaken. Risk Assessment Ref: RAR-713513776 Cyber risk profile: High Potential bidders are required to complete a Supplier Assurance Questionnaire (SAQ) against the security controls appropriate to the risk level. Tenderers should complete their SAQ using the form in the following link: https://forms.office.com/Pages/ResponsePage.aspx?id=7WB3vlNZS0iuldChbfoJ5Tv4OR9pb0BHial1Ag-WKXVUOFk3Sk9SS0JDQ0FRWjhYNDhTVldHUDJaNy4u No. of Suppliers to Evaluate 5 Proposal Criteria • Explain your understanding of the Cyber Security Model - 5% • Describe your experience delivering secure ICT systems or services and what key steps and activities you undertook to achieve authority to operate - 10% • Describe your approach to delivery and methodologies to be used, how you will plan, estimate, monitor and manage work quality, and how you will control the delivery - 10% • Describe the approach you will take to gathering and verifying user and business requirements - 5% • Describe your experience delivering in accordance with the Government Service Standard, what the key roles within your team were and what steps you went through - 10% • Describe your approach to support and continuous improvement of services delivered - 5% • Describe how you will document the technical and management aspects of the delivery. Please include details of key documents - 5% • Describe your experience of implementing services using cloud infrastructure and the key technologies involved - 5% • Provide details of your proposed team who will execute the work, what their responsibilities are, their organisation, and how they will work together and with others - 5% Cultural Fit Criteria • Able to communicate effectively with staff, technical SMEs and senior management to identify pragmatic solutions to problems -2.5% • Suppliers must demonstrate an ability and willingness to work collaboratively within a multi-stakeholder environment to achieve outcomes - 2.5% • Recent proven experience of an open, transparent, and collaborative working relationship at all levels with excellent communication skills - 5% • Take responsibility for their work and outcomes-2.5% • Social Value - Demonstrate the company's approach to Support educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications -2.5% • Social Value - Demonstrate the company's approach to delivering additional environmental benefits in the performance of the contract, including working towards net zero greenhouse gas emissions -2.5% • Social Value - Demonstrate action to identify and tackle inequality in employment, skills and pay in the contract workforce-2.5% Payment Approach Fixed price Assessment Method • Case study • Presentation Evaluation Weighting Technical competence 60% Cultural fit 20% Price 20% Questions from Suppliers 1. Is there an Incumbent ? There is a current incumbent which is in the process of ceasing work. For the purposes of this ITT, the supplier should assume this work has ceased. 2. In relation to the following – ‘Evidence and experience of delivering cloud services for MOD or a similar organisation’ – Does this question refer to the end to end delivery of Cloud Services or can it include supporting activities to deliver Cloud Services. Any relevant evidence and experience of delivery of such services will be considered. Stronger responses will include examples that closely match the context of the requirement. 3. In relation to the following – ‘Evidence and experience of delivering cloud hosted applications for MOD or a similar organisation’ – Does this question refer to the end to end delivery of Cloud Hosted Applications or can it include supporting activities to deliver Cloud Hosted Applications. Any relevant evidence and experience of delivery of such services will be considered. Stronger responses will include examples that closely match the context of the requirement. 4. Please can you advise at what stage potential bidders are required to complete a Supplier Assurance Questionnaire (SAQ) for this opportunity? Now, when responding to the essential and desirable skills and experience, or if downselected to the Proposal stage? Completes SAQ's will be required from downselected suppliers, as part of their tender submission.

Timeline

  1. Completed: Tender published7 December 2022
    Current notice
  2. Completed: Submission date21 December 2022

About the buyer

Ministry of Defence is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Related topics

Topics related to Supplier Cyber Protection Service, ranked by notice volume.

View all topics

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.