Friedrich & ClementBETA

Managed Detection and Response (MDR)

Denmark · Ballerup · how to bid here →

Your path to submission

  1. Deadline: 30 November at 13:00 — 58 days left.
  2. The submission point is stated in the notice (link on the right).
  3. Offer and evidence in: DAN.
  4. Collect your evidence — use the eligibility analysis above: it lists the requirements and, for known certificates, how to get them.
Compiled automatically from notice and documents — no guarantee; the procedure's wording is binding.
Clement
References and certificates from your home country count fully across the EU — that is what European procurement law is for.

Foreign bidders

In Denmark · Business services, 41 contracts went to foreign companies over the last 3 years (of 492 recorded awards) — mostly from Germany, Italy, Ireland.

Typical field: median 5 (from 451 awards).

Measured from linked award data; foreign winners bidding through a local subsidiary count as domestic — the true share is higher.

What the buyer is looking for

In order to protect the State's IT (Order) against current and future cyber threats, the Order uses a number of security technologies, including an Extended Detection and Response (XDR) platform. The XDR platform supports the collection, correlation and analysis of security-related incidents across the Customer's IT environment in order to protect systems, services and data as well as ensure the confidentiality, integrity and availability of data. In view of this, the Contracting Party offers a contract whose purpose is to support and strengthen the Contracting Party's own operational IT security through the provision of a Managed Detection and Response (MDR) service from a Security Operations Center (SOC). The MDR service shall use and complement the Client's XDR platform with 24/7 monitoring, analysis, detection, validation, escalation and management of security incidents. The service…

Show full description

… shall be provided 24 hours a day, 365 days a year, and shall contribute to the rapid identification, assessment and management of cyber threats and security incidents. The services constitute an essential element of the contracting entity’s continued cybersecurity maturation and development process, focusing on technology, processes, competencies and collaboration across internal and external stakeholders. With the tender, the Contracting Authority wishes to have access to a professional MDR service that can meet the Contracting Authority's high requirements for quality, robustness and efficiency, as well as a supplier that can continuously engage in dialogue with the Contracting Authority on developments in cybersecurity, including the threat landscape, technological opportunities, automation, competence development and continuous improvement of the security level. The supplier must implement a technical, organisational and procedural Transition Ind that ensures that the ongoing MDR services can be provided from the transition to the operational phase. The Contracting Authority points out that the Contracting Authority has entered into a contract with two (2) suppliers for the performance of the Contracting Authority's existing XDR platform, with which the supplier must cooperate in connection with Transition Ind. As part of this, the Supplier shall establish and configure the necessary integrations between the Contracting Entity’s XDR platform and other relevant security sources, as well as the Supplier’s tools and platforms used for the performance of the Contract. The Supplier shall provide Continuous MDR Services; including continuous monitoring, analysis, correlation, validation and detection of alarms and security incidents. The supplier shall triage and qualify alarms to identify real security incidents, as well as ensure timely escalation and alerting in accordance with agreed processes and service levels. These ongoing MDR services include: • Continuous SOC monitoring of security-related incidents and alarms. • Analysis, correlation and qualification of events across relevant data sources. • Identification, detection and validation of security incidents. • Preparation, implementation and continuous optimization of detection rules, use cases and analysis models. • Use of relevant Threat Intelligence to support detection and analysis work. • Continuous assessment of the threat landscape and its relevance to the contracting entity’s environment. • Proactive identification of potential security incidents and security risks, including through Threat Hunting activities. • Escalation, notification and reporting of security incidents according to agreed processes and service levels. • Maintenance of existing integrations and establishment of new integrations as needed. • Optimization and further development of the Client’s XDR platform and other security solutions. • Advice on the development and maturation of the Contracting Authority’s security organisation, security processes and governance. • Conducting targeted Threat Hunting courses and analysis of suspicious activities. • Incident Response assistance for security incidents upon requisition from the Client, including analysis, scoping, handling, disposing of

Machine translation (EU eTranslation) — official wording via the PDF link.

What you must prove — eligibility criteria

›
References: services
Ansøger skal i Bilag A indarbejde en liste over de fire (4) betydeligste sammenlignelige leverancer, jf. punkt 2.1.4 i udbudsbekendtgørelsen, som ansøger har udført i løbet af de sidste fem (5) år inden ansøgningsfristen. Hver reference må ikke indeholde mere … ▸▾
Ansøger skal i Bilag A indarbejde en liste over de fire (4) betydeligste sammenlignelige leverancer, jf. punkt 2.1.4 i udbudsbekendtgørelsen, som ansøger har udført i løbet af de sidste fem (5) år inden ansøgningsfristen. Hver reference må ikke indeholde mere end 7 200 anslag (antal tegn med mellemrum). Hvis en reference indeholder mere end 7 200 anslag, vil alene de første 7 200 anslag blive taget i betragtning. Ved sammenlignelige referencer forstås leverancer af lignende type ydelser og af lignende kompleksitet, som de ydelser, der fremgår af udbudsbekendtgørelsen pkt. 2.1.4. Kun referencer, der vedrører leverancer, som er udført på ansøgningstidspunktet, vil blive tillagt betydning ved vurdering af, hvilke ansøgere der har dokumenteret de mest relevante leverancer. Hvis der er tale om en igangværende opgave, er det således alene den del af leverancen, der allerede er udført på ansøgningstidspunktet, der vil indgå i vurderingen af referencen. Beskrivelsen af hver reference skal indeholde en klar beskrivelse af, hvilke af de under punkt 2.1.4, anførte hovedydelser, leverancen vedrørte, samt ansøgers rolle(r) i udførelsen af leverancen. Endvidere bør referencen indeholde den økonomiske værdi af leverancen (beløb), dato for leverancens udførelse samt navn og mailadresse på kunden (modtager). Ved angivelse af dato for leverancen bedes ansøger angive datoen for leverancens påbegyndelse og afslutning. Der kan maksimalt angives fire (4) referencer, uanset om ansøger er en enkelt virksomhed, om ansøger baserer sig på andre enheders tekniske formåen, eller om der er tale om en sammenslutning af virksomheder (f.eks. et konsortium). Såfremt der angives mere end fire (4) referencer, vil der alene blive lagt vægt på de fire (4) nyeste referencer. Referencer herudover vil der blive set bort fra. I forbindelse med evalueringen af hvilke ansøgere, der har leveret de mest relevante referencer, vil hver reference blive vurderet ud fra en skala fra 1-7 point (med præference for højeste antal point). Vurderingen af relevansen sker ud fra, i hvor høj grad referencerne er sammenlignelige med Kontraktens hovedydelser, hvor tildelte point for hovedydelsen ”Transition Ind” vægtes med 25% og point tildelt for hovedydelsen ”Løbende MDR-Ydelser” vægtes med 75%. På den baggrund tildeles referencerne en samlet karakter, der beregnes som summen af det vægtede tildelte antal point for hovedydelserne. Ordregiver anser de fremlagte referencer i pkt. 2, som endelig dokumentation for ansøgers tekniske og faglige formåen. Ordregiver forbeholder sig dog retten til at anmode ansøger om at supplere eller uddybe dokumentationen, jf. FSD artikel 4 og 45. Herunder kan ordregiver efter behov kontakte de angivne kontaktpersoner i referencerne fed henblik på at få attesteret oplysningerne om referencen, herunder de for referencen angivne datoer for leverancens udførelse.
›
Other economic requirement
Ansøgeren skal have en positiv egenkapital for hvert af de seneste to (2) generalforsamlingsgodkendte / revisionsattesterede årsregnskaber.
›
Independent quality certificate (e.g. ISO 9001)
Ansøger skal være certificeret i henhold til ISO/IEC 27001:2022 (Informationssikkerhed) med tilhørende Statement of Applicability (SoA). Der vil ved udvælgelsen af ansøgerne blive krævet dokumentation for, at ansøgeren har de nævnte certificeringer eller tilsvarende, samt en dertilhørende SoA.
Requirement texts are quoted in the notice's original language — the official wording is binding.

Contract

BuyerStatens It
TypeServices
Estimated value24.000.000 DKK
Published17 September 2026
CategoryBusiness services · CPV 79417000

Who has won here before

CompanyAwardsPeriod
BT Global Services Belgium12026
Bravida Danmark A/S12025
From 18.0M documented awards · regular winners know this buyer's requirements — that is your competition.
·
days until the deadline — Monday 30 November at 13:00

How to bid

Read the full notice — Original + documents
Goes directly to this tender on TED — Tenders Electronic Daily. The full specification and all annexes are there.

Tender documents — direct download

Specifications and annexes hosted by the buyer — usually accessible without registration.
Friedrich finds tenders like this for you — every morning at 7:30, each one checked by Claude (Anthropic) for fit, and he learns from your feedback what your company really does.
Register now →