The Supply of Software Composition Analysis Tool (including Binary Repository Manager) for Security Vulnerability Checking, License Compliance and Architectural Governance

Department of Social Protection

In summary, the Services comprise:
1) Supply of a tool to perform software composition analysis and a binary repository manager tool for the purpose of
(a) security vulnerability checking of 3 party open source libraries;
(b) license compliance checking of those libraries; and
(c) architectural governance to manage the use of such 3 party libraries;
2) Support/maintenance contract of the tool for the duration of the license.
The proposal may supply an alternate binary repository manager tool to replace the Departmentโ€™s use of Sonatype Nexus Repository Pro. If so, then it must have equivalent capabilities to Sonatype Nexus. (This RFT outlines the features used in its current integration to Nexus).

Deadline

The time limit for receipt of tenders was 2021-04-26. The procurement was published on 2021-03-16.

Suppliers

The following suppliers are mentioned in award decisions or other procurement documents:

Who? What? Where?
Procurement history
Date Document
2021-03-16 Contract notice
2021-10-27 Contract award notice
Contract notice (2021-03-16)
Object
Scope of the procurement
Title: Software support services
Short description:
In summary, the Services comprise: 1) Supply of a tool to perform software composition analysis and a binary repository manager tool for the purpose of (a) security vulnerability checking of 3 (b) license compliance checking of those libraries; and (c) architectural governance to manage the use of such 3 2) Support/maintenance contract of the tool for the duration of the license. The proposal may supply an alternate binary repository manager tool to replace the Departmentโ€™s use of Sonatype Nexus Repository Pro. If so, then it must have equivalent capabilities to Sonatype Nexus. (This RFT outlines the features used in its current integration to Nexus).
Show more
Notice metadata
Original language: English ๐Ÿ—ฃ๏ธ
Document type: Contract notice
Nature of contract: Services
Regulation: European Union
Common procurement vocabulary (CPV)
Code: Software support services ๐Ÿ“ฆ
Additional CPV: License management software package ๐Ÿ“ฆ
Place of performance
NUTS region: ร‰ire/Ireland ๐Ÿ™๏ธ

Procedure
Procedure type: Open procedure
Type of bid: Submission for all lots
Award criteria
The most economic tender

Contracting authority
Identity
Country: Ireland ๐Ÿ‡ฎ๐Ÿ‡ช
Awarding authority type: Ministry or any other national or federal authority
Awarding authority name: Department of Social Protection
Postal address: College Road
Postal town: Sligo
Contact
Internet address: https://www.gov.ie/en/organisation/department-of-employment-affairs-and-social-protection/ ๐ŸŒ
E-mail: garret.mullaney@welfare.ie ๐Ÿ“ง
Phone: +353 719148555 ๐Ÿ“ž
URL for documents: http://irl.eu-supply.com/app/rfq/rwlentrance_s.asp?PID=184942&B=ETENDERS_SIMPLE ๐ŸŒ
URL for participation: http://irl.eu-supply.com/app/rfq/rwlentrance_s.asp?PID=184942&B=ETENDERS_SIMPLE ๐ŸŒ

Reference
Dates
Date dispatched: 2021-03-16 ๐Ÿ“…
Submission deadline: 2021-04-26 ๐Ÿ“…
Publication date: 2021-03-19 ๐Ÿ“…
Identifiers
Notice number: 2021/S 055-138213
OJ-S issue: 55

Object
Scope of the procurement
Short description:
In summary, the Services comprise:
1) Supply of a tool to perform software composition analysis and a binary repository manager tool for the purpose of
(a) security vulnerability checking of 3
(b) license compliance checking of those libraries; and
(c) architectural governance to manage the use of such 3
2) Support/maintenance contract of the tool for the duration of the license.
The proposal may supply an alternate binary repository manager tool to replace the Departmentโ€™s use of Sonatype Nexus Repository Pro. If so, then it must have equivalent capabilities to Sonatype Nexus. (This RFT outlines the features used in its current integration to Nexus).
Show more
Estimated total value: 270 000 EUR ๐Ÿ’ฐ
Short description: In summary, the services comprise:
Estimated value excluding VAT: 270 000 EUR ๐Ÿ’ฐ
Duration: 36 months
Description of renewals:
The contracting authority reserves the right to extend the term for a period one (1) year with a maximum of two (2) such extension on the same terms and conditions, subject to the contracting authorityโ€™s obligations at law.

Procedure
Legal basis: 32014L0024
Time of receipt of tenders: 18:00
Languages in which tenders or requests to participate may be submitted: English ๐Ÿ—ฃ๏ธ
Tender validity period: 6 months
Tender opening date: 2021-04-26 ๐Ÿ“…
Tender opening time: 18:00
Place: Online Tender Box.

Contracting authority
Identity
National registration number: N/a
Contact
Contact point: Garret Mullaney
Address of the buyer profile: https://irl.eu-supply.com/ctm/Company/CompanyInformation/Index/349 ๐ŸŒ
Documents URL: http://irl.eu-supply.com/app/rfq/rwlentrance_s.asp?PID=184942&B=ETENDERS_SIMPLE ๐ŸŒ

Complementary information
Review body
Name: High Court
Postal address: Four Courts, Inns Quay
Postal town: Dublin
Country: Ireland ๐Ÿ‡ฎ๐Ÿ‡ช
Source: OJS 2021/S 055-138213 (2021-03-16)
Contract award notice (2021-10-27)
Object
Scope of the procurement
Reference number: 1028
Short description:
In summary, the Services comprise: (1) supply of a tool to perform software composition analysis and a binary repository manager tool for the purpose of (a) security vulnerability checking of 3rd party open source libraries, (b) license compliance checking of those libraries, and (c) architectural governance to manage the use of such 3rd party libraries; (2) support/maintenance contract of the tool for the duration of the license. The proposal may supply an alternate binary repository manager tool to replace the Departmentโ€™s use of Sonatype Nexus Repository Pro. If so, then it must have equivalent capabilities to Sonatype Nexus. (This RFT outlines the features used in its current integration to Nexus).
Show more
Total value of the procurement: 321 269 EUR ๐Ÿ’ฐ
Notice metadata
Document type: Contract award notice

Procedure
Type of bid: Not applicable

Contracting authority
Identity
Postal code: Ie
Contact
E-mail: alan.mcgettigan@welfare.ie ๐Ÿ“ง

Reference
Dates
Date dispatched: 2021-10-27 ๐Ÿ“…
Publication date: 2021-10-29 ๐Ÿ“…
Identifiers
Notice number: 2021/S 211-555629
Refers to notice: 2021/S 055-138213
OJ-S issue: 211
Additional information
Estimated value is best estimate at time of tender and may be subject to change.

Object
Scope of the procurement
Short description:
In summary, the Services comprise: (1) supply of a tool to perform software composition analysis and a binary repository manager tool for the purpose of (a) security vulnerability checking of 3rd party open source libraries, (b) license compliance checking of those libraries, and (c) architectural governance to manage the use of such 3rd party libraries; (2) support/maintenance contract of the tool for the duration of the license.
Show more
The proposal may supply an alternate binary repository manager tool to replace the Departmentโ€™s use of Sonatype Nexus Repository Pro. If so, then it must have equivalent capabilities to Sonatype Nexus. (This RFT outlines the features used in its current integration to Nexus).
Show more
Additional information: Estimated value is best estimate at time of tender and may be subject to change.

Procedure
Award criteria
Quality criterion (name): Technical Requirements
Quality criterion (weighting): 45%
Quality criterion (name): Support/Maintenance
Quality criterion (weighting): 10%
Quality criterion (name): Additional Features/Roadmap
Quality criterion (weighting): 5%
Price (weighting): 40%

Award of contract
Date of contract conclusion: 2021-08-09 ๐Ÿ“…
Name: FTL Group Technologies Limited
National registration number: IE1111284WH
Postal address: 6-9 Trinity Street
Postal town: Dublin
Postal code: Dublin 2
Country: Ireland ๐Ÿ‡ฎ๐Ÿ‡ช
Phone: +353 19011380 ๐Ÿ“ž
E-mail: torourke@ftlgroup.ie ๐Ÿ“ง
Internet address: http://www.ftlgroup.ie ๐ŸŒ
Total value of the procurement: 321 269 EUR ๐Ÿ’ฐ
Information about tenders
Number of tenders received: 2

Contracting authority
Contact
Contact point: Alan McGettigan
Source: OJS 2021/S 211-555629 (2021-10-27)