France – Services de technologies de l'information – Accord cadre relatif à la mise en place de services et solutions de détection, supervision, et protection du SI - (SOC, EDR/EPP, SIEM, WAF, Antispam)

DeadlineAugust 28, 2026 at 03:00 PM8 days left

AI summary

This tender concerns the establishment of a framework agreement for security operations centre (SOC) services and cybersecurity solutions, including endpoint detection and response (EDR/EPP), security information and event management (SIEM), and web application firewalls (WAF). The contractor will implement and operate detection, supervision, and protection tools for healthcare facility information systems, manage security alerts, support incident response coordination, and provide continuous security improvement reporting.

#cybersecurity#soc services#healthcare it#france#incident response#security operations
Fit for

Specialized IT security service providers with established SOC capabilities, cybersecurity expertise, and experience in healthcare sector information system protection should bid. Consortiums of complementary service providers are acceptable.

Key requirements

Suppliers must demonstrate expertise in SOC operations, EDR/EPP, SIEM, and WAF technologies. Experience managing healthcare sector IT security, incident response coordination with national CERT authorities, and proven capability to reduce detection and response times (MTTD/MTTR) are required.

Frequently asked questions

  • What is this tender about?

    This tender concerns the establishment of a framework agreement for security operations centre (SOC) services and cybersecurity solutions, including endpoint detection and response (EDR/EPP), security information and event management (SIEM), and web application firewalls (WAF). The contractor will implement and operate detection, supervision, and protection tools for healthcare facility information systems, manage security alerts, support incident response coordination, and provide continuous security improvement reporting.

  • What are the requirements for suppliers?

    Suppliers must demonstrate expertise in SOC operations, EDR/EPP, SIEM, and WAF technologies. Experience managing healthcare sector IT security, incident response coordination with national CERT authorities, and proven capability to reduce detection and response times (MTTD/MTTR) are required.

  • What type of company should bid?

    Specialized IT security service providers with established SOC capabilities, cybersecurity expertise, and experience in healthcare sector information system protection should bid. Consortiums of complementary service providers are acceptable.

  • Who is the buyer?

    The buyer is GCS SARA.

  • When does this tender close?

    Submissions close on August 28, 2026.

Le présent marché a pour objectif de confier à un ou plusieurs prestataires spécialisés la mise en place et l'exploitation de solutions de détection, supervision, protection du système d'information permettant : - La mise en oeuvre et l'exploitation des outils de détection et de réponse, notamment les solutions de type EDR / EPP, SIEM et SOAR ; - La supervision de sécurité du système d'information des établissements de santé ; - La détection des événements et incidents de cybersécurité, y compris les comportements anormaux et les menaces avancées ; - La qualification, l'analyse et la priorisation des alertes ; - L'assistance à la réponse à incident, en coordination avec les équipes internes et avec le CERT Santé et éventuellement avec le CERT-FR ; - La réduction des délais de détection (MTTD) et de réaction (MTTR) ; - La production de reporting, d'indicateurs et de recommandations contribuant à l'amélioration continue du niveau de sécurité.

Buyer
GCS SARA
Buyer ID: 84467690800016
63170, Aubière
Body responsible for review procedures
Tribunal administratif de Clermont-Ferrand
Buyer ID: 176 300 051 00024
63033, CLERMONT FERRAND
Other organization
DEMATIS
Buyer ID: 45072478600030
75015, Paris

Computing match…

AI document analysis

We read the tender PDFs and DOCX files and surface key requirements, deadlines, budget and red flags.

Loading…