Overview
This is a restricted two-stage EU procurement (request to participate deadline 8 September 2026 at 14:00 Europe/Bucharest) for the ATHENA Cross Border Cyber Hub Platform Infrastructure with an estimated total value of €9,405,000. The contract covers acquisition, integration, installation and SLA-backed support of hardware and datacentre infrastructure including servers, clustered virtualization, FIPS 140 storage, networking, firewalls, HSMs, backup and cabling to host a cross-border threat intelligence and SOC interconnection platform. Eligible applicants are economic operators established in EU Member States or EEA countries who meet Digital Europe ownership/control and security requirements, and selection requires demonstration of at least three similar projects of minimum €500,000 each and specified key personnel. Award will be by best price-quality ratio, maximum contract duration 36 months, with electronic submission via the EU Funding & Tenders Portal.
Highlights
What it funds
Procurement of hardware, datacentre and network infrastructure, security appliances, storage (FIPS140), backup, HSM and associated configuration, warranty and SLA-based support to host the ATHENA cross-border cyber hub platform.
Who can apply
Economic operators established in EU Member States or EEA (NO/IS/LI) meeting Digital Europe Programme security restrictions (entities must be controlled by Member States or nationals of Member States/EEA); subcontractors and entities on whose capacities candidates rely are subject to the same checks.
Key eligibility and selection highlights
Minimum technical capacity:At least three similar projects (scope/complexity comparable) completed within the last 3 years, minimum value €500,000 each (excl. VAT). Additional scoring for projects > €750,000. Facility security clearance of at least EU RESTRICTED and specified expert roles required (project manager, 2 system administrators, network engineer, 2 cybersecurity engineers). 1
- 1Procedure: Restricted two-stage procurement (requests to participate then invited tenders)
- 2Award method: Best price-quality ratio (price 40%, quality 60%)
- 3Estimated total value: €9,405,000 (procedure budget)
- 4Maximum contract duration: 36 months
- 5Number of candidates to be invited to stage 2: up to 5
| Deadline (requests to participate) | 2026-09-08 14:00:59 (Europe/Bucharest) |
|---|---|
| TED publication / call date | 2026-08-07 |
| Submission method | Electronic via EU Funding & Tenders Portal (EU Login) |
Place of performance and beneficiaries:joint procurement by the ECCC (lead) and Digital Security Authority of Cyprus acting for partners from Cyprus, Greece, Malta, Bulgaria and Belgium; hardware to support cross-border platform and local SOC interconnection.
How to apply:Submit a request to participate electronically via the EU Funding & Tenders Portal (EU Login). Selected candidates will be invited to sign an NDA and submit full tenders. See procurement documents and Annexes for templates and mandatory evidence (Annex 8 Similar Projects; Annex 9 Professional Capacity; Annex 6a Ownership Control Declaration). 1
- 1Prepare PIC registration and upload required ownership/control documents in the Participant Register
- 2Include Declaration on Honour and requested financial, legal and technical evidence with the request to participate
- 3If invited, sign NDA to receive Technical Specifications Part 2 and submit technical and financial tender via eSubmission
Award and contracting details:framework service contract for delivery, maintenance and support; contracting authority is the European Cybersecurity Industrial, Technology and Research Competence Centre (ECCC); award based on best price-quality ratio. Electronic correspondence and invoicing procedures are defined in the tender documents. 1
Footnotes
- 1Procurement documents, deadlines and submission links are published on the EU Funding & Tenders Portal: ATHENA Cross Border Cyber Hub Platform - Infrastructure (ECCC/BUH/2026/RP/0019) F&T Portal - ATHENA Tender.
Find a Consultant to Support You
Breakdown
Opportunity snapshot
Title:ATHENA Cross Border Cyber Hub Platform - Infrastructure. Lead contracting authority: European Cybersecurity Industrial, Technology and Research Competence Centre (ECCC). Procedure: Restricted procedure, two-step (step 1: request to participate; step 2: invited tenders). Main procurement classification: CPV 51611100 Hardware installation services (additional CPVs: 30234500 Memory storage media, 44316400 Hardware). Nature of contract: services. Estimated total procedure value: €9,405,000. Maximum contract duration: 36 months. Submission method: electronic via the EU Funding & Tenders Portal (eSubmission). Deadline (step 1 requests to participate): 2026-09-08 14:00:59 Europe/Bucharest. Documents and procurement dossier available via the Funding & Tenders Portal Funding & Tenders Portal - ATHENA. 1
What is being procured
Purpose:Acquisition, configuration, delivery and lifecycle support of the hardware infrastructure required to build and operate the ATHENA cross border Cyber Hub platform and to interconnect local Security Operation Centers (SOCs) of participating national authorities. Scope highlights: clustered virtualization servers (redundancy and scalability), FIPS 140 compliant NAS storage, networking switches with high port density and resiliency, firewalls, backup solutions, Hardware Security Module (HSM), datacentre equipment, interconnection cabling and associated installation and integration services. The procurement requires system configuration, secure integration, SLA-based support, warranty and maintenance for a fixed period, and built-in operating systems that accompany procured hardware. Security, data protection by design and compliance with EU data protection requirements are explicit contractual expectations.
ATHENA programme context and objectives
ATHENA is a cross-border threat intelligence, response and preparedness platform designed to enable cross-border, cross-organisational and cross-functional cooperation between Member State cybersecurity authorities. The ATHENA hosting consortium (led by ECCC with the Coordinator Digital Security Authority of Cyprus and participating partners from Bulgaria, Greece, Malta and Belgium) will use the acquired hardware to implement a common cross-border platform providing: AI-enhanced situational awareness (CTI discovery, UEBA, attack prediction), coordinated SOAR-driven incident response and cross-border alerting, joint preparedness and cyber range access, and timely secure information exchange interoperable with EU frameworks such as CyCLONe. The procurement supports the implementation, operational sustainability, resilience and future expandability of the platform.
Key administrative and procedural facts
- 1Procedure type: Restricted procedure (two-stage). Step 1 = request to participate; Step 2 = invited tenderers (up to 5 candidates to be invited).
- 2Submission method: Electronic via eSubmission (EU Login required).
- 3Tender documents published in English; additional annexes (Annex 2 DoH, Annex 6a Ownership Control Declaration, Annex 8 Similar Projects, Annex 9 Professional Capacity, Tender Specifications Part 1) available on the Funding & Tenders Portal.
- 4Selection/award: Award method best price-quality ratio. Award weighting: Price 40%, Quality 60% (detailed sub-criteria defined in Tender Specifications).
- 5Estimated total value: €9,405,000 (procurement documents and draft contract).
- 6Maximum contract duration: 36 months.
- 7Security and data protection obligations apply; Facility Security Clearance at least EU RESTRICTED or equivalent security arrangements may be required for involved entities or personnel.
Structured extraction: program classification and eligibility
Eligible Applicant Types
Eligible applicants:legal and natural persons established and validated in the Participant Register (PIC). The call explicitly targets economic operators, including sole applicants and groups of economic operators (consortia). Roles allowed: sole tenderer, consortium/group members (joint request to participate), subcontractors, and entities on whose capacity the candidate relies (not subcontractors). Typical eligible organisation types: SMEs, large enterprises (hardware vendors, system integrators), integrators and professional services firms, research organisations or technical centres where their legal status and access to procurement rules permit, and non-profit entities where applicable. Public bodies validated in the Participant Register are treated as public bodies (control assessment rules differ).
Funding Type
This is a procurement (tender) awarding a services contract. Financial mechanism:public procurement contract to purchase services and hardware with payments to the winning contractor(s). Not a grant, loan or equity instrument.
Consortium Requirement
Procedure:Restricted two-stage procedure. The tender allows either a single tenderer or a joint tender (consortium). Joint tenders must appoint a group leader and provide a signed Agreement/Power of Attorney (Annex 3). The selection step will select up to five candidates (based on exclusion and selection criteria) who will be invited to step 2 to submit full tenders. Subcontracting is permitted; identified subcontractors above 20 % or those relied upon for selection criteria must be declared and provide commitment letters (Annex 4 and 5.1). Entities on whose capacities the candidate relies must provide commitment letters (Annex 5.2).
Beneficiary Scope (Geographic Eligibility)
Beneficiaries must be established in EU Member States or EEA countries (Norway, Iceland, Liechtenstein). Participation is restricted for security reasons to entities established in these jurisdictions and controlled by Member States or nationals of Member States or EEA countries (see Annex 6a Ownership Control Declaration and Annex €6Bguidance). Public bodies validated in the Participant Register are considered controlled by their country. The procurement is executed by an EU agency and funded under the Digital Europe Programme (2021-2027).
Target Sector
Primary sectors:cybersecurity, ICT, infrastructure and data centre hardware and integration. Secondary links: AI-enabled analytics (CTI, UEBA), network security, storage and backup solutions, cyber range infrastructure and training support, and cross-border SOC operations.
Mentioned Countries
Explicitly mentioned countries in the opportunity:Cyprus, Greece, Malta, Bulgaria, Belgium. Lead contracting authority location and portal administration references identify Romania (Bucharest) as the lead contracting authority office location. Eligible geographic scope for participants: EU and EEA countries (see Beneficiary Scope).
Project Stage
Expected maturity and stage:deployment and operationalisation of infrastructure (implementation, integration, testing, validation, transition to operations). The procurement covers hardware acquisition, installation and operational support — i.e. deployment, commissioning, integration and operational sustainment rather than R&D or early-stage research.
Funding Amount
Estimated total procurement value:€9,405,000. This is the estimated overall contract amount indicated in the procedure notice and procurement documents. The procurement documents state that the contracting authority may procure repetition of similar services up to 50 % of the initial value within three years using negotiated procedure (option for follow-on buys).
Application Type
Submission method and call type:Restricted two-stage call. Step 1 = open submission of a request to participate (electronic, via eSubmission). Step 2 = only selected candidates (up to five) are invited to submit full tenders. The call is not rolling and has fixed deadlines. The procedure is invitation-only for step 2 following step 1 evaluation.
Nature of Support
Contracting authority will procure services and hardware. The selected contractor(s) will receive monetary payments under a services contract (public procurement). The procurement also requires delivery of tangible hardware and non-monetary services (installation, configuration, maintenance, warranties, training, documentation).
Application Stages
Number of procedural stages:2. Stage 1: submission of a request to participate, administrative, exclusion and selection assessment (includes ownership/control checks and professional/technical capacity checks). Stage 2: invited tenderers submit full technical and financial offers; evaluation against award criteria (price-quality ratio) followed by award and contracting.
Success Rates
Success rate indicators:Up to five (5) candidates will be invited to Step 2. The published procurement value is a single award (or a single contract). Exact success rates depend on the number of requests to participate received and the number of tenders ultimately submitted. Historically, restricted calls with an invitation cap (5) typically yield low single-digit to low double-digit percentage chances of being invited, and ultimate contract award success is 1 divided by number of invited tenderers for the contract award stage (for example 1/5 = 20 % conditional on being invited). No guaranteed published success rate is provided in the call documents.
Co-funding Requirement
Co-funding is not specified in the procurement documents as a requirement. The procurement is a fee-for-service public contract; the contracting authority pays the contractor pursuant to the contract. No own financial co-funding from applicants is requested by the contracting authority, however tenderers must propose compliant prices and may need to carry initial costs until payment milestones are reached. There is no matching grant requirement in the procurement documents.
Eligibility, selection and technical requirements (key items and templates)
This section reproduces and highlights the essential requirements and templates that applicants must complete and submit. Tenderers must follow the tender specifications (Part 1 Administrative and Part 2 Technical) and provide the required annexes. All documents listed below are mandatory where indicated and must be provided at the step and in the manner requested.
- 1Participant Register (PIC). All organisations intending to submit a request to participate or a tender must have a valid PIC and be registered in the Portal Participant Register.
- 2Declaration on Honour (Annex 2). Mandatory evidence for exclusion checks. Signed by authorised representative(s).
- 3Ownership Control Declaration (Annex 6a). Mandatory for all entities (tenderer, all group members in a joint request, subcontractors and entities on whose capacity the tenderer relies) to support eligibility under Digital Europe restricted participation rules. Supporting documents required in the PIC account and validated by the Central Validation Service.
- 4Tender Specifications Part 1 (Administrative) — lists formal requirements, exclusion and selection criteria, annex templates, and administrative forms.
- 5Tender Specifications Part 2 (Technical) — detailed technical specifications and deliverables. Part 2 is provided only to selected candidates invited to Step 2 and requires an NDA signature prior to release.
- 6Annex 8 Similar Projects Description — template for listing at least three similar projects (minimum for each project: €500,000 value; completed within last 3 years or portion completed in the reference period). Corrigendum updated the per-project minimum from €750,000 to €500,000. For scoring additional points, projects with value exceeding €750,000 are counted as scoring elements; evidence (reference letters, certificates, invoices) required.
- 7Annex 9 Professional capacity T4 description — CVs (Europass recommended) and evidence for proposed key personnel (Project Manager, System Administrators, Network Engineer, Cybersecurity Engineers) including minimum education, years of experience and CEFR English levels (Project Manager minimum C1; administrators, network and cybersecurity engineers minimum B2).
- 8Annex 4 List of identified subcontractors and Annex 5.1 commitment letters — mandatory where subcontractors are identified or are relied upon for selection criteria. Subcontractors with intended share above 20% or relied upon for selection must be identified and provide commitment letters.
- 9Agreement/Power of Attorney (Annex 3) — joint tender agreement signed by all group members appointing a group leader and establishing joint and several liability.
- 10Administrative identification form (Annex 7) and financial statements required for economic and financial selection criteria (average turnover test F1: combined candidate turnover above €3,000,000 over last two financial years where applicable).
Minimum technical selection highlights (extracted):
- Criterion T3: Minimum of three similar projects completed in the last three years, each project value at least €500,000 (ex VAT). The tender documents and Annex 8 provide the project template and require supporting evidence (references, invoices).
- Criterion T4: Minimum human resources: one Project Manager (university degree, ≥3 years total experience, ≥2 years in relevant cybersecurity hosting/infrastructure and English C1), two System Administrators (university degree, ≥5 years relevant experience, English B2), one Network Engineer (university degree, ≥5 years relevant experience, English B2), two Cybersecurity Engineers (university degree, ≥3 years relevant experience, English B2). Europass CVs and evidence required.
Clarification on Annex 8 per-project values:The procurement dossier was updated by corrigendum: Annex 8 originally referenced a per-project minimum of €750,000 but was corrected (Corrigendum dated 19/08/2026 and version V2 published 24/08/2026) so that the minimum level of capacity for each of the three required similar projects is €500,000 (ex VAT). Projects with a value greater than €750,000 (ex VAT) are used in the selection scoring logic to award additional points where applicable. The contracting authority has confirmed in Q&A that (1) the minimum level per project is €500,000 and (2) the €500,000 and €750,000 thresholds are excluding VAT.
Evaluation and award: scoring structure
Award is by best price-quality ratio with weighting Price 40 % and Quality 60 %. Quality is evaluated across three main technical award sub-criteria: A1 Performance (technical performance and benchmarks), A2 Operational sustainability, resilience and future expandability (SLA, maintenance, redundancy, BDR, RTO/RPO and lifecycle), and A3 Implementation methodology and project management (workplan, risk mitigation, quality assurance). The tender evaluation includes compliance checks with the minimum requirements (non-compliant tenders will be rejected).
Submission practicalities and portal templates
All submissions must be electronic via the Funding & Tenders Portal eSubmission tool. Applicants must create/register an organisation in the Participant Register and obtain a PIC. System constraints and technical guidance (accepted file formats, attachment size limits, browser requirements) are documented on the Portal and in the eSubmission Quick Guide. The portal manages subscriptions for updates and publishes corrigenda, Q&As and document versions (Annex 8 V2, Annex 6a, Annex 9, Draft Contract, Tender Specifications Part 1). The Tender Specifications include Annex templates and precise instructions for labelling and uploading attachments and specify which documents must be submitted at Step 1 and Step 2 (Annex 1A and €1B).
Selection and contracting timeline (published dates)
TED/Portal publication date:07/08/2026. Deadline for requests to participate (Step 1): 08/09/2026 14:00 (Europe/Bucharest). Annex 8 Corrigendum published 24/08/2026. Draft contract and Tender Specifications Part 1 published with the call. Tender Specifications Part 2 (technical) will be issued to candidates invited to Step 2 following NDA signature. Note: TED record shows two published deadlines (early metadata included) and clarifications; always rely on the official timestamp in the Funding & Tenders Portal eSubmission interface for final submission time.
Templates and required forms (summary)
- 1Annex 2 Declaration on Honour on exclusion and selection criteria (mandatory with Step 1).
- 2Annex 3 Agreement/Power of Attorney for joint submissions (group leader appointment and joint & several liability).
- 3Annex 4 List of identified subcontractors and the proportion of subcontracting (declaration).
- 4Annex 5.1 Commitment letter template for identified subcontractors (must be provided with Step 1 if subcontractor is relied upon).
- 5Annex 5.2 Commitment letter template for entities on whose capacities the candidate relies (not subcontractors).
- 6Annex 6 Financial Tender Model (to be used in Step 2 invited tender submission).
- 7Annex 6a Ownership Control Declaration (mandatory for participants and relevant entities; upload to PIC account).
- 8Annex €6BGuidance for DEP restricted calls (ownership control guidance).
- 9Annex 7 Administrative identification form (to be uploaded Step 1).
- 10Annex 8 Similar Projects Description (template to list required similar projects; corrigendum updated minimum per-project value to €500,000).
- 11Annex 9 Professional capacity T4 description (CV and evidence template for key personnel).
- 12Tender Specifications Part 1 (Administrative) and Part 2 (Technical).
- 13Draft Contract (published as part of Step 1 documentation).
| Document / Template | Purpose and submission timing |
|---|---|
| Annex 2 Declaration on Honour | Exclusion & selection declaration. Submit with Step 1 request to participate. |
| Annex 6a Ownership Control Declaration | Used to assess eligibility under Digital Europe restricted participation; upload to PIC for each involved entity. Submit at Step 1 (supporting documents may be requested and validated). |
| Annex 8 Similar Projects Description | List and describe at least 3 similar projects (each ≥ €500,000). Submit with Step 1 request to participate. Corrigendum V2 updates threshold. |
| Annex 9 Professional capacity T4 | CV templates and evidence for key personnel. Submit with Step 1; additional verification possible at Step 2. |
| Annex 6 Financial Tender Model | Mandatory financial model to be used when invited to Step 2. Submit with Step 2 tender. |
Selection tips and bidder preparation checklist
- Register your organisation in the Participant Register and obtain a PIC early. Ensure the PIC record contains up-to-date SME status and uploaded ownership/control documents.
- Prepare Annex 2 Declaration on Honour and supporting exclusion evidence in advance (judicial extracts, tax and social security certificates where applicable).
- Prepare Annex 8 entries: complete descriptions, client references, value breakdowns, and supporting evidence (invoices, reference letters) for at least three similar projects each ≥ €500,000 (ex VAT).
- Prepare Annex 9 CVs (Europass recommended) and certifications for all required experts and scan diplomas and certificates that may be requested.
- If relying on subcontractors or external entities for selection criteria, secure signed commitment letters (Annex 5.1/.5.2) and identify subcontractors in Annex 4; ensure that any subcontractor above 20 % of contract value is declared and evidenced.
- Prepare financial statements and turnover evidence to meet the economic criterion (average turnover of last two financial years above stated threshold as per F1).
- Plan for onboarding of security-cleared personnel and verify Facility Security Clearance requirements where relevant (Criterion T2).
- Monitor the Funding & Tenders Portal for corrigenda and Q&A updates (e.g. Annex 8 Corrigendum).
Key procurement risks and attention points:1) Ownership/control and DEP restrictions: be prepared for detailed ownership/control evidence (Annex 6a) and Central Validation Service checks. 2) Security clearance: some roles or access to contracting-authority premises may require Facility Security Clearance at least EU RESTRICTED or a Security Declaration accepted by a national security authority. 3) Annex 8 thresholds and corrigenda: always use the latest document version from the Portal and rely on the corrigendum (Annex 8 V2). 4) eSubmission technical constraints: multiple attachments, file naming conventions, maximum 200 files and individual attachment size limits; prepare compressed and properly named attachments well ahead of the deadline. 5) Two-step timing: step 1 completeness is crucial because only invited candidates can access technical specifications (Part 2) and submit tenders in step 2.
What this opportunity is about and final summary
This procurement is a restricted two-stage tender to acquire a resilient, secure and scalable hardware infrastructure, installation, integration and SLA-backed support services to host and interconnect the ATHENA cross border Cyber Hub platform and participating national SOCs. The ATHENA platform is a Digital Europe Programme initiative to enable cross-border threat intelligence sharing, coordinated incident response (SOAR), AI-assisted situational awareness (CTI, UEBA, attack prediction), cyber-range based preparedness and timely information exchange among Member State cybersecurity authorities. The ECCC leads the procurement in cooperation with a consortium of national authorities (Coordinator: Digital Security Authority of Cyprus; participating partners: Bulgaria, Greece, Malta, Belgium).
The procurement is not a research grant:it is a public procurement for tangible hardware, associated services and support. Applicants must satisfy formal exclusion, financial and technical selection criteria (including a minimum of three similar projects of minimum €500,000 each and defined personnel profiles) and pass the Digital Europe Programme ownership/control eligibility checks. Up to five candidates will be invited to submit full tenders. Award is by best price-quality ratio (Price 40% / Quality 60%), and contract(s) will be signed under ECCC rules and the published draft contract. The estimated value of the procedure is €9.405 million and the contract duration is up to 36 months. Tenderers must use the Funding & Tenders Portal eSubmission system and follow the mandatory annex templates (Annexes 2, 3, 4, 5, 6a, 8, 9 and the Financial Model at step 2).
Footnotes
- 1Tender documents, announcements, corrigenda and Q&A are published on the Funding & Tenders Portal (F&T Portal). Use the official call page for downloads and for eSubmission: EU Funding & Tenders Portal - ATHENA Cross Border Cyber Hub Platform - Infrastructure Funding & Tenders Portal.
Short Summary
Impact Provide a resilient, secure and scalable cross-border cyber hub that enables shared situational awareness, AI-enhanced threat intelligence, coordinated incident response and joint preparedness across participating Member States. | Impact | Provide a resilient, secure and scalable cross-border cyber hub that enables shared situational awareness, AI-enhanced threat intelligence, coordinated incident response and joint preparedness across participating Member States. |
Applicant Ability to deliver and integrate datacentre-grade hardware and secure network infrastructure (servers, clustered virtualization, FIPS‑compliant storage, HSMs, firewalls, switches), implement secure system configuration and SLAs, and support operational cybersecurity tooling including SOAR/CTI/UEBA and data protection compliance. | Applicant | Ability to deliver and integrate datacentre-grade hardware and secure network infrastructure (servers, clustered virtualization, FIPS‑compliant storage, HSMs, firewalls, switches), implement secure system configuration and SLAs, and support operational cybersecurity tooling including SOAR/CTI/UEBA and data protection compliance. |
Developments Deployment, integration and lifecycle support of hardware and operational infrastructure to host a cross‑border Security Operations Centre platform supporting AI-driven situational awareness, coordinated incident response and cyber‑range preparedness. | Developments | Deployment, integration and lifecycle support of hardware and operational infrastructure to host a cross‑border Security Operations Centre platform supporting AI-driven situational awareness, coordinated incident response and cyber‑range preparedness. |
Applicant Type Profit SMEs/startups, large corporations, government organizations, and research/technical centres with proven secure infrastructure delivery experience. | Applicant Type | Profit SMEs/startups, large corporations, government organizations, and research/technical centres with proven secure infrastructure delivery experience. |
Consortium Single tenderers or joint tendering groups are allowed (joint bids must appoint a lead and sign a power of attorney); the procedure is a restricted two‑stage procurement with up to five candidates invited to step 2. | Consortium | Single tenderers or joint tendering groups are allowed (joint bids must appoint a lead and sign a power of attorney); the procedure is a restricted two‑stage procurement with up to five candidates invited to step 2. |
Funding Amount Estimated total procedure value €9,405,000 (contract duration up to 36 months). | Funding Amount | Estimated total procedure value €9,405,000 (contract duration up to 36 months). |
Countries Explicitly involves Cyprus, Greece, Malta, Bulgaria and Belgium for platform use; applicants must be established and controlled in EU Member States or EEA countries (Norway, Iceland, Liechtenstein). | Countries | Explicitly involves Cyprus, Greece, Malta, Bulgaria and Belgium for platform use; applicants must be established and controlled in EU Member States or EEA countries (Norway, Iceland, Liechtenstein). |
Industry Digital Europe Programme (ECCC) targeting cybersecurity infrastructure and cross‑border Cyber Hubs. | Industry | Digital Europe Programme (ECCC) targeting cybersecurity infrastructure and cross‑border Cyber Hubs. |
Additional Web Data
This is a restricted two step EU procurement for the ATHENA Cross Border Cyber Hub Platform Infrastructure. The request to participate deadline is 8 September 2026 at 14:00 Europe/Bucharest, and the estimated total value is €9,405,000.[2]
Core objective:ATHENA is a cross border threat intelligence, response and preparedness platform intended to connect Cyprus, Greece, Malta, Bulgaria and Belgium for shared situational awareness, coordinated incident response, joint preparedness and secure information exchange.[11][2]
Opportunity at a glance
| Field | Details |
|---|---|
| Procedure | Restricted procedure, electronic submission.[2] |
| Contract nature | Services procurement for hardware infrastructure and related support, maintenance and guarantee services.[2] |
| Estimated value | €9,405,000.[2] |
| Maximum duration | 36 months.[2] |
| Award method | Best price quality ratio.[2] |
| Lead contracting authority | European Cybersecurity Industrial, Technology and Research Competence Centre.[2] |
| Publication date | 7 August 2026.[2] |
| CPV codes | 51611100 main, with additional classifications 30234500 and 44316400.[2] |
What the procurement is about
The contract covers the acquisition and integration of a robust cyber infrastructure to support the ATHENA platform, including multiple servers, clustered virtualization, switches, firewalls, storage, backup capability, hardware security modules, cabling, built in operating systems and related support under an SLA. The broader technical aim is to enable secure processing, storage and transmission of cybersecurity information, while supporting AI driven situational awareness, incident response, preparedness and information sharing.[2][11]
Who can apply
- 1Economic operators established in EU Member States or in EEA countries may participate, and EEA EFTA countries are treated as equivalent to Member States for this call.[2]
- 2All participating entities must be controlled by Member States or by nationals of Member States, or by nationals of EEA countries where applicable.[2]
- 3Subcontractors and entities whose capacity is relied on for technical and professional selection criteria must also have access to procurement under the applicable rules.[2]
- 4No involved entity may be subject to EU restrictive measures, and the participation rules exclude countries covered by the WTO Government Procurement Agreement for this procedure.[2]
- 5A Participant Identification Code is required for submission, and all entities in a joint bid must be registered in the Participant Register.[2]
Selection requirements applicants should prepare for
| Criterion | Requirement |
|---|---|
| Technical and professional capacity T3 | At least three similar projects completed within the last three years, or a completed part within the reference period, each with a minimum value of €500,000 after corrigendum, demonstrating experience in highly secure cybersecurity infrastructure services. |
| Professional capacity T4 team | At least one project manager, two system administrators, one network engineer and two cybersecurity engineers, each meeting the stated degree, experience and language requirements. |
| Documentary evidence | Similar projects must be described in Annex 8 and supported by reference letters, certificates, invoices or equivalent evidence. Europass CVs and supporting documents are required for experts. |
| Ownership and control | All tenderers, consortium members, subcontractors and relied on entities must submit the ownership and control declaration and supporting evidence in the Participant Register. |
- 1Project manager: related university degree, at least 3 years professional experience, at least 2 years in cybersecurity hosting site or similar infrastructure projects, English at least C1, Europass CV required.
- 2System administrator 1 and system administrator 2: related university degree, at least 5 years professional experience in cybersecurity hosting site or cybersecurity infrastructure projects, English at least B2, Europass CV required.
- 3Network engineer: related university degree, at least 5 years professional experience in secure network infrastructures, English at least B2, Europass CV required.
- 4Cybersecurity engineer 1 and cybersecurity engineer 2: related university degree, at least 3 years professional experience in secure network infrastructures or cybersecurity infrastructures, English at least B2, Europass CV required.
Contract conditions and practical points
- The technical specifications are made available only to candidates invited to step 2 after signing a non disclosure agreement.
- Variants are not allowed and the contracting authority will disregard alternative solutions.
- The contractor must comply with security rules for sensitive non classified and EU classified information, and any security vetting or clearance costs are for the contractor's account.
- Data protection compliance is a substantive contract obligation, including data protection by design and by default and supporting documentation such as DPIAs, records and privacy statements where needed.
- The contractor must support fraud prevention and can be required to pass related obligations to subcontractors and personnel.
- Within three years after signature, the contracting authority may use a negotiated procedure for repeat services up to 50 percent of the initial contract value on the same conditions.
- If the successful tenderer has overdue EU debts, the amount may be offset against payments under the contract.
- The working language for implementation is English.
Submission and timing
Submissions are electronic only and must be made through the Funding and Tenders Portal using EU Login. One request to participate per candidate is allowed, and if multiple submissions are sent without withdrawal, only the latest one is considered.[2]
The portal documents show a corrigendum to Annex 8 published on 24 August 2026, so applicants should use the latest version of the similar projects template before submitting.
Professional assessment
This opportunity is most suitable for established cyber infrastructure integrators, hardware and security vendors, systems engineering firms and consortia with proven delivery in highly secure environments. The combination of access restrictions, staffing thresholds and reference project requirements makes the market entry bar high, but the contract value and strategic nature of ATHENA make it attractive for experienced operators with strong public sector cyber credentials.
Update Log
No updates recorded yet.
Discover with AI
Let our intelligent agent help you find the perfect funding opportunities tailored to your needs.
EU Grant Database
Explore European funding opportunities in our comprehensive, up-to-date collection.
Stay Informed
Get notified when grants change, deadlines approach, or new opportunities match your interests.
Track Your Favorites
Follow grants you're interested in and keep them organized in one place. Get updates on changes and deadlines.
ENSOC Hosting Site ES ICT Infrastructure (Computing, Storage, Networking, Cybersecurity)
Restricted EU procurement for ENSOC Hosting Site ES ICT Infrastructure (procedure ECCC/BUH/2026/RP/0020) to supply, deploy and operate resilient hosting, connectivity, cybersecurity, backup, training and communications services at an exi...
MANAGED IT SERVICES 2026
Managed IT Services 2026 is an open EU procurement published by the Clean Hydrogen Joint Undertaking (CLEANH2/2026/OP/0014) to award a single-supplier framework contract for comprehensive managed IT and IT professional services with a st...
Services for the Design, Development and Analysis of Cybersecurity Indexes
ENISA has published an open service tender ENISA/2026/OP/0013 to design, develop and analyse cybersecurity indexes covering EU Member States and other partners to produce evidence based insights on cybersecurity posture and maturity. The...
ICTSS IV - ICT Support Services IV
CEDEFOP has launched an open procurement (ref CEDEFOP/2026/OP/0010) to award a single-provider framework contract for ICT support services, with submission by 15 September 2026. The contract covers operational ICT support for Microsoft t...
Pilot Project on Multi-layered Airborne Capabilities for Situational Awareness - HAPS Services for Border Surveillance
Open Frontex tender to procure a pilot High Altitude Platform Systems (HAPS) service package to demonstrate persistent wide-area surveillance, on-board data fusion, radio-frequency interference monitoring and wireless connectivity. The c...
CFT-1747 - IT Security Hardware and Software
CFT-1747 is a European Investment Bank open tender to award a multiple-operator framework agreement (minimum 2, maximum 5 providers) for the supply and renewal of IT security hardware and software and associated services, with an estimat...
European Health Data Space IT systems development, operations and support
This is a competitive EU public procurement (service contract) to provide development, operations, maintenance, cybersecurity, user support and handover for core European Health Data Space IT systems including HealthData@EU platforms, th...
Open procedure for the conclusion of a single framework contract on the supply of security equipment to the benefit of CFSP Entities
The European Commission Service for Foreign Policy Instruments (FPI.6) is launching an open procedure to award a single 48-month framework contract for the supply of security equipment to CFSP entities and operations. The estimated overa...
Guarding services for the Houses of Europe in Copenhagen, Stockholm and Helsinki
Public procurement tender for guarding and reception services at the European Commission Representations (Houses of Europe) in Copenhagen, Stockholm and Helsinki, to be awarded as a framework agreement split into three lots. Procedure is...
Administrative support services to EUSPA (EUSPA/OP/19/26)
The European Union Agency for the Space Programme (EUSPA) is procuring framework contracts in cascade for administrative support services divided into two lots: Lot 1 for unclassified services delivered from contractor premises (estimate...
Promoting the use and fostering integration of EU space services into Civil Protection authorities early warning and monitoring systems
This tender seeks a service provider to deliver capacity building and tailored training to EU Member States and UCPM Participating States on integrating Copernicus Emergency Management Services and the Galileo Early Warning Satellite Ser...
Study of the Cyber Solidarity Act
The European Commission (DG CNECT) has published a services tender (EC-CNECT/2026/OP/0112) to commission a study evaluating the Cyber Solidarity Act, including assessment of effectiveness, efficiency, relevance, coherence and EU added va...