Merthyr Tydfil County Borough Council and the CymruSOC team are engaging suppliers ahead of CymruSOC 2.0, the planned replacement for the current CymruSOC provision. The proposed framework is intended to provide Security Operations Centre (SOC) and Security Information and Event Management (SIEM) services to a wide range of public-sector organisations in Wales.
The notice estimates a value of £108 million including VAT and a seven-year operating period. This is preliminary market engagement rather than a live tender, so suppliers should use the current stage to understand the planned route and make sure their cyber-security evidence is ready. Contact Thornton & Lowe if you want to review your fit before the tender is issued.
What CymruSOC 2.0 covers
The core requirement is clear: CymruSOC 2.0 is being developed as a dedicated framework for SOC and SIEM services. The resulting arrangement is expected to be available to a broad range of public-sector organisations in Wales.
That makes the opportunity most relevant to managed security service providers and cyber-security suppliers able to deliver continuous monitoring, threat detection, incident management and SIEM capability at public-sector scale. General IT providers should only treat it as a priority if SOC/SIEM delivery is a genuine part of their service offer and can be evidenced.
Thornton & Lowe's guidance on IT, digital and technology tenders covers the evidence themes that often matter in complex technology procurements, including service management, resilience, security, implementation and performance reporting.
Dates suppliers need to know
- Estimated value: £90 million excluding VAT / £108 million including VAT
- Proposed term: 2 April 2027 to 1 April 2034
- Supplier engagement event: 18 August 2026 at 2:00pm
- Engagement deadline: 18 August 2026
- Estimated tender publication: 21 September 2026
- Current stage: Preliminary market engagement
The current CymruSOC 2.0 Find a Tender notice includes the webinar joining details and confirms the proposed framework structure.
What a credible future bid is likely to need
Suppliers should start assembling evidence around 24/7 service resilience, security operations processes, incident escalation, SIEM implementation and integration, threat intelligence, governance, reporting and continuous improvement. Public-sector examples that demonstrate safe migration or transition between security platforms will be particularly useful if the final procurement includes a significant mobilisation requirement.
Because this is a Wales-wide framework, bidders should also think about how they will support participating organisations of different sizes and maturity levels. A delivery model should be scalable without becoming generic, with clear service levels, onboarding processes, account management and routes for urgent incident response.
Use engagement to test the model
The engagement event is an opportunity to understand how the authority intends to structure the framework and to raise practical questions about service scope, onboarding, data, integration, support and call-off arrangements. Suppliers should avoid waiting for the tender before challenging assumptions that could affect their ability to bid.
Support with CymruSOC 2.0
Thornton & Lowe can support cyber-security suppliers with bid strategy, evidence planning, response development and independent review. Discuss CymruSOC 2.0 with our bid team.