Network as a Service (NaaS)
Tender Overview
About this tender
Scope: WCQ is seeking the design, supply, deployment, operation, and ongoing lifecycle management of its internal Head Office network capability, delivered as a fully managed Network-as-a-Service (NaaS). The NaaS provider will be accountable for transitioning WCQ from its current internally managed network environment to a vendor-delivered managed service, and for operating that service throughout the contract term. WCQ does not wish to own or operate the day-to-day network function. The NaaS provider will be responsible for all aspects of service delivery for the in-scope environment, including infrastructure, performance, security controls, monitoring, incident response, and lifecycle management. The in-scope environment is located at WCQ Head Office, 280 Adelaide Street, Brisbane. The scope is limited to the internal building network capability. External connectivity, cloud networking, and enterprise security platforms are explicitly out of scope and governed under separate WCQ arrangements. Network Infrastructure The provider is responsible for the design, supply, installation, configuration, operation, and full lifecycle management of the following active network infrastructure at WCQ Head Office: • Core switching infrastructure within the building • Access switching across all floors • Switching fabric required for internal connectivity • Wireless access points providing building-wide wireless coverage • UTM/Next-Generation Firewall positioned between the out-of-scope internet edge router and the internal network core, providing perimeter security enforcement across all internal network traffic Physical racks, cabinets, and cabling infrastructure are owned by WCQ. The provider is responsible for managing, supporting, and maintaining cabling and physical connectivity between all in-scope devices as part of service delivery. The provider is responsible for the full lifecycle of all in-scope infrastructure throughout the contract term, including end-of-life tracking, firmware and software currency, hardware refresh planning, and delivery of refresh activities within the managed service model. Network Capability and Controls The provider is responsible for implementing and operating the following network capabilities within the Head Office environment: • Network access control (NAC) across wired LAN and wireless environments, ensuring only authorised and compliant devices and users can connect • Network segmentation and internal security policy enforcement between defined security zones • Management of internal routing and switching behaviour within the building • UTM/NGFW security functions including perimeter threat prevention, intrusion prevention, application control, URL filtering, and SSL inspection • Cloud-based network management platform (SaaS) providing centralised visibility, configuration management, and operational control Implementation and Transition The provider is responsible for transitioning WCQ from the current network environment to the new managed service. This includes: • Discovery and assessment of the current WCQ network environment • Detailed solution design developed in collaboration with WCQ and validated against agreed requirements • Implementation planning and deployment sequencing to minimise disruption to WCQ operations • Physical installation, configuration, and commissioning of all in-scope infrastructure • Structured transition from the current environment including cutover planning, risk management, and parallel running where required • Testing and validation of all infrastructure, security controls, and integrations prior to go-live • Formal service acceptance and handover into ongoing operations Managed Service Operations Following service acceptance, the provider is responsible for ongoing operational delivery of the network service throughout the contract term, including: • Continuous monitoring of network infrastructure health, performance, and security posture • Incident detection, response, and restoration within defined SLAs • Structured change management for all network changes including advance notification to WCQ • Service request management including physical moves, additions, and changes such as desk relocations, port patching, and floor reconfigurations • Proactive capacity management and performance optimisation • Vulnerability management and controlled patching of all in-scope components • Real-time dashboards and structured reporting providing WCQ visibility of network health, performance, security posture, and usage • Comprehensive audit logging of all administrative access and configuration changes • Full operational documentation maintained and kept current throughout the contract term • Alignment with WCQ's applicable security, regulatory, and governance obligations throughout the contract term All operational, configuration, monitoring, and performance data generated by the network service remains the property of WCQ and must be exportable in non-proprietary formats at any time. Integration with WCQ Enterprise Platforms The provider is responsible for integrating the network service with the following WCQ enterprise platforms as part of both implementation and ongoing operations: • Microsoft Sentinel - network security events and telemetry must be available to WCQ's existing security detection and response processes • Microsoft Entra ID - administrative access must federate with WCQ's identity platform, supporting MFA and Conditional Access policies • ServiceNow - incidents, changes, and network asset data must integrate with WCQ's ITSM platform and CMDB Professional Services The provider must have the capability to deliver discrete project-based and advisory work requested by WCQ during the contract term that falls outside BAU managed service operations. This includes activities such as network design for new requirements, scoping and delivery of network change projects, and advisory support for WCQ programs with a network dependency. The provider must describe how such work is scoped, priced, and delivered alongside ongoing managed service obligations Out of Scope The following are outside the scope of the NaaS engagement. Anything not listed as in scope above should be assumed out of scope. Where out-of-scope domains create dependencies with the in-scope environment, the provider is expected to collaborate with WCQ and other appointed suppliers to ensure effective integration and interoperability at the boundary Edge and Perimeter Network Domain • Edge routers and upstream routing infrastructure sitting above the in-scope UTM Firewall • SD-WAN infrastructure and routing domains used to connect WCQ to external networks • Perimeter routing architecture, ISP circuit design, and ISP connectivity management Cloud Networking and Cloud Platform Connectivity • AWS networking configuration and VPC design • Azure networking configuration and VNet design • Cloud hub or transit gateway architecture • SaaS connectivity architecture including Microsoft Global Secure Access (GSA) Enterprise Security and Identity Platforms • SASE/SSE platform migration activities • Identity or authentication platform ownership and operation - Microsoft Entra ID integration is in scope, Entra ID platform management is not • Microsoft Sentinel platform ownership and operation - log and telemetry integration is in scope, Sentinel platform management is not Dual ISP Services • Procure and establish dual ISP connectivity as a prerequisite for cloud-managed network architecture. General Exclusions • End user device management or configuration • Application-layer support above the network • Any initiative, platform, or capability not explicitly listed as in scope above
How to respond to this tender
A strong tender response is clear, compliant, and backed by evidence. These steps apply to most Australian and New Zealand public tenders.
Read the requirements in full
Open the official listing and download the full tender pack. Note the response schedules, evaluation criteria, mandatory conditions, and the exact closing time and lodgement method.
Confirm you are eligible and it is worth bidding
Check licences, insurances, certifications, and any conformance requirements before you commit. A quick bid or no-bid decision saves days of wasted effort on a tender you cannot win.
Answer every criterion with evidence
Respond to each evaluation criterion directly and back your claims with concrete examples, referees, and past performance. Address the buyer’s stated need, not a generic capability statement.
Lodge early through the official portal
Submit through the source portal well before the deadline. Late or incorrectly lodged bids are almost always rejected, so leave time for uploads, portal errors, and last-minute questions.
