Network as a Service (NaaS)
Tender ID: 618374
Tender Details
Tender Description
Scope:
WCQ is seeking the design, supply, deployment, operation, and ongoing lifecycle management of its internal Head Office network capability, delivered as a fully managed Network-as-a-Service (NaaS). The NaaS provider will be accountable for transitioning WCQ from its current internally managed network environment to a vendor-delivered managed service, and for operating that service throughout the contract term.
WCQ does not wish to own or operate the day-to-day network function. The NaaS provider will be responsible for all aspects of service delivery for the in-scope environment, including infrastructure, performance, security controls, monitoring, incident response, and lifecycle management.
The in-scope environment is located at WCQ Head Office, 280 Adelaide Street, Brisbane. The scope is limited to the internal building network capability. External connectivity, cloud networking, and enterprise security platforms are explicitly out of scope and governed under separate WCQ arrangements.
Network Infrastructure
The provider is responsible for the design, supply, installation, configuration, operation, and full lifecycle management of the following active network infrastructure at WCQ Head Office:
• Core switching infrastructure within the building
• Access switching across all floors
• Switching fabric required for internal connectivity
• Wireless access points providing building-wide wireless coverage
• UTM/Next-Generation Firewall positioned between the out-of-scope internet edge router and the internal network core, providing perimeter security enforcement across all internal network traffic
Physical racks, cabinets, and cabling infrastructure are owned by WCQ. The provider is responsible for managing, supporting, and maintaining cabling and physical connectivity between all in-scope devices as part of service delivery.
The provider is responsible for the full lifecycle of all in-scope infrastructure throughout the contract term, including end-of-life tracking, firmware and software currency, hardware refresh planning, and delivery of refresh activities within the managed service model.
Network Capability and Controls
The provider is responsible for implementing and operating the following network capabilities within the Head Office environment:
• Network access control (NAC) across wired LAN and wireless environments, ensuring only authorised and compliant devices and users can connect
• Network segmentation and internal security policy enforcement between defined security zones
• Management of internal routing and switching behaviour within the building
• UTM/NGFW security functions including perimeter threat prevention, intrusion prevention, application control, URL filtering, and SSL inspection
• Cloud-based network management platform (SaaS) providing centralised visibility, configuration management, and operational control
Implementation and Transition
The provider is responsible for transitioning WCQ from the current network environment to the new managed service. This includes:
• Discovery and assessment of the current WCQ network environment
• Detailed solution design developed in collaboration with WCQ and validated against agreed requirements
• Implementation planning and deployment sequencing to minimise disruption to WCQ operations
• Physical installation, configuration, and commissioning of all in-scope infrastructure
• Structured transition from the current environment including cutover planning, risk management, and parallel running where required
• Testing and validation of all infrastructure, security controls, and integrations prior to go-live
• Formal service acceptance and handover into ongoing operations
Managed Service Operations
Following service acceptance, the provider is responsible for ongoing operational delivery of the network service throughout the contract term, including:
• Continuous monitoring of network infrastructure health, performance, and security posture
• Incident detection, response, and restoration within defined SLAs
• Structured change management for all network changes including advance notification to WCQ
• Service request management including physical moves, additions, and changes such as desk relocations, port patching, and floor reconfigurations
• Proactive capacity management and performance optimisation
• Vulnerability management and controlled patching of all in-scope components
• Real-time dashboards and structured reporting providing WCQ visibility of network health, performance, security posture, and usage
• Comprehensive audit logging of all administrative access and configuration changes
• Full operational documentation maintained and kept current throughout the contract term
• Alignment with WCQ's applicable security, regulatory, and governance obligations throughout the contract term
All operational, configuration, monitoring, and performance data generated by the network service remains the property of WCQ and must be exportable in non-proprietary formats at any time.
Integration with WCQ Enterprise Platforms
The provider is responsible for integrating the network service with the following WCQ enterprise platforms as part of both implementation and ongoing operations:
• Microsoft Sentinel - network security events and telemetry must be available to WCQ's existing security detection and response processes
• Microsoft Entra ID - administrative access must federate with WCQ's identity platform, supporting MFA and Conditional Access policies
• ServiceNow - incidents, changes, and network asset data must integrate with WCQ's ITSM platform and CMDB
Professional Services
The provider must have the capability to deliver discrete project-based and advisory work requested by WCQ during the contract term that falls outside BAU managed service operations. This includes activities such as network design for new requirements, scoping and delivery of network change projects, and advisory support for WCQ programs with a network dependency. The provider must describe how such work is scoped, priced, and delivered alongside ongoing managed service obligations
Out of Scope
The following are outside the scope of the NaaS engagement. Anything not listed as in scope above should be assumed out of scope. Where out-of-scope domains create dependencies with the in-scope environment, the provider is expected to collaborate with WCQ and other appointed suppliers to ensure effective integration and interoperability at the boundary
Edge and Perimeter Network Domain
• Edge routers and upstream routing infrastructure sitting above the in-scope UTM Firewall
• SD-WAN infrastructure and routing domains used to connect WCQ to external networks
• Perimeter routing architecture, ISP circuit design, and ISP connectivity management
Cloud Networking and Cloud Platform Connectivity
• AWS networking configuration and VPC design
• Azure networking configuration and VNet design
• Cloud hub or transit gateway architecture
• SaaS connectivity architecture including Microsoft Global Secure Access (GSA)
Enterprise Security and Identity Platforms
• SASE/SSE platform migration activities
• Identity or authentication platform ownership and operation - Microsoft Entra ID integration is in scope, Entra ID platform management is not
• Microsoft Sentinel platform ownership and operation - log and telemetry integration is in scope, Sentinel platform management is not
Dual ISP Services
• Procure and establish dual ISP connectivity as a prerequisite for cloud-managed network architecture.
General Exclusions
• End user device management or configuration
• Application-layer support above the network
• Any initiative, platform, or capability not explicitly listed as in scope above
Location
Similar Tenders
Active opportunities matching this tender's categories and regions.