Overview
Restricted EU procurement for ENSOC Hosting Site ES ICT Infrastructure (procedure ECCC/BUH/2026/RP/0020) to supply, deploy and operate resilient hosting, connectivity, cybersecurity, backup, training and communications services at an existing Tier 4 data centre in Madrid with an estimated value of €4,000,000 and a maximum duration of 36 months. The two-step restricted procedure requires electronic requests to participate on the EU Funding & Tenders Portal by 14 September 2026 14:00 (Europe/Bucharest), with up to five candidates shortlisted and invited to tender under NDA. Award is by best price-quality ratio (quality 60%, price 40%) and bidders must meet strict exclusion, financial, technical and ownership/control checks, ISO/IEC 27001 and Facility/Personnel Security Clearance requirements (RESTREINT UE / EU RESTRICTED). All submissions and templates are available on the Funding & Tenders Portal and costs of security compliance are borne by the contractor.
Highlights
Quick summary
What is procured
Restricted procurement for the design, supply, deployment and 36-month operation of the ENSOC Spain hosting site (computing, storage, networking, cybersecurity), to be hosted in an existing Tier 4 data centre in Madrid. Scope includes infrastructure hardware, backups, secure connectivity, security services, identity management, SLAs, maintenance and training.
Estimated value:€4 000 000 (total estimated contract value for the procedure).
- 1Contract type: restricted procedure, two‑stage (requests to participate then invitation to tender).
- 2Lead contracting authority: European Cybersecurity Industrial, Technology and Research Competence Centre (ECCC) with Centro Nacional de Inteligencia as coordinator.
- 3Location of performance: Madrid hosting site (Tier 4 data centre), Spain; work may include contractor premises for services.
- 4Duration: up to 36 months.
- 5Award method: best price-quality ratio (price 40% / quality 60%).
Who may apply
Eligible applicants are legal or natural persons established in EU Member States or EEA/associated countries meeting the Digital Europe Programme security and ownership/control restrictions. All participants (including subcontractors and entities relied upon) must register in the Participant Register (PIC), complete the Ownership Control Declaration and may be subject to ownership/control validation and security clearance requirements.
Key compliance and selection highlights:Applicants must satisfy exclusion and selection criteria (financial turnover, ISO/IEC 27001, facility security clearance or equivalent, technical experience with at least three similar projects >= €1 400 000 each, and personnel security clearances). See procurement documents for full requirements 1.
- 1Register in the Participant Register and obtain a PIC before submission.
- 2Submit Declaration on Honour and required annexes with request to participate.
- 3Up to 5 candidates will be invited to tender following evaluation and ranking of selection criteria.
- 4Tenders submitted electronically via eSubmission (EU Login required).
| Procurement ID / Reference | ECCC/BUH/2026/RP/0020 (TED ref 152/2026 — 552127-2026) |
|---|---|
| Estimate | €4 000 000 |
| Submission method | Electronic via eSubmission (EU Login) — Participant Register PIC required |
| Request to participate deadline | 14/09/2026 14:00:59 (Europe/Bucharest) |
| TED publication / documents | Published 10/08/2026; tender specifications, invitation to tender, annexes and draft contract available on the F&T Portal Funding & Tenders Portal |
Important:this is a restricted two‑stage procurement. Only candidates who pass the exclusion and selection checks in step 1 will be invited to submit full tenders in step 2. Security vetting, ownership/control checks and PSC/FSC requirements are strict and may prevent participation if not met. Full technical minimum requirements and award criteria are in the tender specifications 1.
Footnotes
- 1Procurement documentation, annexes and submission instructions are available on the Funding & Tenders Portal: ENSOC Hosting Site ES ICT Infrastructure (tender details) F&T Portal tender page.
Find a Consultant to Support You
Breakdown
Opportunity summary and essential facts
Procurement organiser:European Cybersecurity Industrial, Technology and Research Competence Centre (ECCC) in joint procurement with Centro Nacional de Inteligencia - Centro Criptológico Nacional (Spain) representing the ENSOC hosting consortium (member states: Spain, Italy, Portugal, Luxembourg, Portugal, Romania, Austria, Netherlands). Procedure type: restricted procedure organised in two steps (requests to participate, then invited tenders). Place of performance and hosting site: premises of an existing Tier 4 Data Centre in Madrid, Spain. Main objective: procure resilient hosting-site ICT infrastructure, internet connectivity, cybersecurity, backup, secure communications, training and communications services to host the majority of ENSOC cross-border platform (ENSOC CBP) solutions in Spain for a 36-month contract period. Estimated total procedure value: €4 000 000 (estimated overall contract amount). Award method: best price-quality ratio. Submission method: exclusive electronic submission via the EU Funding & Tenders Portal (eSubmission). Deadlines: requests to participate by 14 September 2026 14:00 (Europe/Bucharest time). TED publication date: 10/08/2026. TED reference numbers: 152/2026, 552127-2026. Main CPV codes: 51611100 (hardware installation services), additional CPVs 30234500 (memory storage media), 44316400 (hardware).
Procurement scope and technical context
Scope:supply, deployment, configuration, operation and maintenance of segregated secure hosting infrastructure for ENSOC CBP Spain, including computing resources (physical or virtual), RAM, OS and operational storage, appliances or virtual appliances, backups, identity governance and centralized user/identity management, network and internet connectivity with redundancy, security services (IDS/IPS, firewalling, segmentation, encryption, monitoring, vulnerability scanning, sensitive information protection), service level commitments (hardware delivery, deployment times, incident response and resolution), documentation and asset management (CMDB entries), delivery of software/licences and updates for 36 months. Hosting will comply with Spanish National Security Scheme (ENS) high level, EU Classified Information requirements up to RESTREINT UE / EU RESTRICTED, and will be implemented in a Tier 4 Data Centre in Madrid with physical and biometric controls and CCTV. Data protection and data protection-by-design obligations (Regulation (EU) 2018/1725 and Regulation (EU) 2016/679) apply and the contractor must be able to support drafting and maintaining DPIAs, records of processing, pseudonymisation/anonymisation and encryption measures.
Who is buying:European Cybersecurity Industrial, Technology and Research Competence Centre (ECCC) as lead contracting authority in joint procurement with Centro Nacional de Inteligencia - Centro Criptológico Nacional (Spain) and participating partners forming the ENSOC hosting consortium (Agenzia per la Cybersicurezza Nazionale - IT, Luxembourg House of Cybersecurity - LU, Gabinete Nacional de Segurança - PT, National Cyber Security Directorate - RO, Bundesministerium für Inneres - AT, Ministry of Justice and Security - NL).
Contract duration and value:Maximum contract duration: 36 months. Estimated overall contract amount: €4 000 000. The contracting authority may procure additional similar services up to 50% of initial contract value within three years under a negotiated procedure.
Detailed eligibility, evaluation and application requirements
This is a restricted two-step tender. Step 1:submit a request to participate via eSubmission (EU Login and Participant Register PIC required). All required administrative, exclusion and selection evidence must be filed as specified in Annex 1A. Up to five candidates will be selected and invited to step 2. Step 2: invited candidates sign an NDA and receive the full Technical Specifications (Tender Specifications Part 2) and Draft Contract; they submit technical and financial tenders in eSubmission. Award criterion: best price-quality ratio with price weighting 40% and quality weighting 60% (quality subdivided into technical implementation and project management, quality and suitability of the technical solution, and organisation of the work).
Security, classified information and personnel clearance:Contract and hosting site must support handling EU classified information up to RESTREINT UE / EU RESTRICTED. Selection requirements include Facility Security Clearance (FSC) of at least RESTREINT UE/EU RESTRICTED or an accepted Security Declaration of Responsibility by a national security authority; Personnel Security Clearance (PSC) for key experts: Project Manager (T6), Senior Expert (T7) and Junior Analysts/Technicians (T8) must hold PSC RESTREINT UE/EU RESTRICTED. Contractor must follow ECCC security rules and may be asked to provide security-vetted personnel. Security compliance costs are at contractor expense.
- 1Eligible Applicant Types — detailed description: Eligible applicants are legal persons (commercial firms, SMEs, large enterprises), large system integrators, data centre operators and managed service providers, IT infrastructure vendors, cybersecurity service providers, engineering and consulting firms, as well as public bodies and research organisations that are validated as public bodies in the Participant Register. Subcontractors and entities on whose capacities a candidate relies are allowed but must meet the same access-to-procurement and ownership/control requirements. Natural persons may participate only where national rules permit and subject to the tender rules. Participation is restricted by ownership/control rules (see below).
- 2Funding Type and Contract Nature: This is a public procurement contract (service contract) implemented under the Digital Europe Programme funding. Primary financial mechanism: procurement / service contract; not a grant, loan or equity instrument.
- 3Consortium Requirement: The procedure allows single tenderers or joint requests to participate (groups of economic operators). If a joint tender is submitted, the group must appoint a group leader who signs the Agreement/Power of attorney (Annex 3). Joint tenders create joint and several liability. Subcontracting is permitted; identified subcontractors (>=20% share or relied-on for selection criteria) must be declared and submit commitment letters (Annex 4 and Annex 5.1). Entities on whose capacities the candidate relies (not subcontractors) must supply commitment letters (Annex 5.2).
- 4Beneficiary Scope (Geographic Eligibility): Applicants must be established in EU Member States or EEA countries. Participation is subject to ownership/control restrictions under the Digital Europe Programme: entities must be established in Member States or EEA and be controlled by Member States or nationals of Member States/EEA; public bodies validated in Participant Register are considered controlled by their country. Ownership/control assessment is mandatory (Annex 6a).
- 5Target Sector(s): ICT infrastructure, cybersecurity, data hosting, cloud and storage, networks and connectivity, backup and disaster recovery, identity and access management, secure communications, training and operations support. Thematically: cyber security, ICT, data infrastructure, services for public sector cybersecurity operations.
- 6Mentioned Countries: Spain (hosting site Madrid), Romania (ECCC location Bucharest lead authority), Italy, Portugal, Luxembourg, Austria, Netherlands (participating partners). Location of performance: Spain (Madrid Data Centre) and contractor premises as indicated in the procurement documents.
- 7Project Stage (expected maturity): Integration, deployment, operation and maintenance of production hosting site (development, validation, demonstration and operational deployment). This is not research funding: it is procurement for production-grade infrastructure.
- 8Funding Amount: Estimated overall contract value €4 000 000.
- 9Application Type and Submission: Open restricted call with two-stage restricted procedure. Step 1: open call for requests to participate (electronic submission via eSubmission on the EU Funding & Tenders Portal). Step 2: invitation-only submission of full tenders for selected candidates. Deadlines are fixed; late submissions are rejected. EU Login account and PIC required.
- 10Nature of Support: Contracted services and supply of equipment and licences (monetary payments under public contract). The contractor will receive monetary payments according to contractual schedule; beneficiaries receive procurement payment, not grants. Non-monetary obligations include delivering documentation, licences, training, maintenance and security safeguards.
- 11Application Stages: Two stages — Step 1: Request to participate (exclusion and selection criteria verified). Step 2: Invitation to submit tenders (award evaluation).
- 12Success Rates: Not provided numerically. Up to 5 candidates will be shortlisted and invited to submit tenders. Selection to step 2 is competitive and limited to top-ranked candidates meeting exclusion and selection criteria. The probability of selection depends on market interest and compliance.
- 13Co-funding Requirement: No explicit co-funding required. Tenderers must price the full service in their financial offer and cover costs of security clearances and compliance themselves. Where applicable, contracting authority may offset debts owed to the Union against payments.
- 14Templates and mandatory forms: Annexes included in procurement documents (available on the portal) and required at Step 1 where indicated: Annex 1A (list of documents to submit with request to participate), Annex 2 (Declaration on Honour on exclusion and selection criteria), Annex 3 (Agreement/Power of attorney for joint tenders), Annex 4 (List of identified subcontractors), Annex 5.1 (commitment letter by identified subcontractors), Annex 5.2 (commitment by entities on whose capacity tenderer relies), Annex 6a (Ownership Control Declaration), Annex €6B (Guidance for DEP restricted calls), Annex 8 (Similar Projects Description template — at least 3 projects >= €1 400 000 each in last 3 years), Annex 9 (Professional capacity T6-T8 description template — CVs and PSC evidence). The Draft Contract is provided (Annex: Draft Contract).
Selection, technical and personnel requirements (key points)
- Exclusion and integrity: Complete Declaration on Honour (Annex 2). Be ready to supply judicial records, tax and social security certificates or national equivalents upon request. EDES registration may apply on detection of exclusion conditions.
- Ownership and control: Complete Annex 6a Ownership Control Declaration and upload supporting corporate documents to the Participant Register PIC account. Public bodies validated in the Portal are treated as controlled by their country. The Central Validation Service will assess control and may request additional evidence. Entities controlled by ineligible third countries will be ineligible.
- Financial capacity: Minimum consolidated average turnover for the last two financial years > €1,500,000 (consolidated assessment allowed across involved entities). Provide P&L accounts for the last two closed years.
- Technical capacity: Mandatory ISO/IEC 27001 certificate (information security management). Facility Security Clearance (FSC) of at least RESTREINT UE / EU RESTRICTED or equivalent accepted by a national security authority (consolidated assessment). Evidence of compliance with ENS (Spanish National Security Scheme) High level and ISO standards: ISO 22301 (BCM), ISO 20000 (Service Management) and ISO 9001 (Quality), plus code of ethics / compliance system.
- Proven experience: At least three similar projects in scope and complexity completed within the last three years, each of minimum total project value €1,400,000 (Annex 8 template). Projects demonstrating secure cybersecurity infrastructure services (hardware, computing, storage, networking, cybersecurity) are required.
- Key personnel and security clearance: Provide CVs and Annex 9 professional capacity details for the proposed experts: T6 Project Manager (university degree; >=10 years international PM experience incl. >=5 years in secure hosting/integration; English and Spanish CEFR C1; PSC RESTREINT UE/EU RESTRICTED), T7 Senior Expert (>=5 years international experience delivering training and operational support; >=3 years in design/deploy/operate secure technology infrastructure; English & Spanish C1; PSC), T8 Junior Analysts/Technicians (4 persons, each >=3 years experience as analysts/technicians incl. >=2 years in secure hosting/integration; English B2, Spanish C1; PSC). Provide Europass CVs and documentary evidence of qualifications, language levels and PSCs.
- Technical offer: Must demonstrate compliance with the Technical Specifications (Part 2), include detailed architecture, hardware and software BOM or appliance specifications, backup and disaster recovery design, identity governance approach, monitoring and logging, secure communications and redundant internet connectivity plan, SLA improvements offered, warranty and update frequency, interoperability and secure configuration details, CMDB and documentation package and EoL/EoS dates for hardware and software.
- SLA and operational constraints: Propose SLA metrics (uptime, response times, resolution times, delivery and deployment times), incident response and escalation procedures, security incident handling and reporting, patch and vulnerability scanning frequency, and maintenance windows.
- Data protection and DPIA: Demonstrate Data Protection Engineering and data protection by design and by default capability, provide proposed approach for DPIA, data flow documentation and pseudonymisation/anonymisation where applicable.
- Interoperability: Demonstrate secure data sharing and communications between ENSOC solutions and related infrastructures using standard CTI formats and protocols (e.g., STIX/TAXII, MISP integration) as required by ENSOC conceptual model.
| Procurement identifier | ECCC/BUH/2026/RP/0020 (TED ref 152/2026; 552127-2026) |
|---|---|
| Estimated value | €4 000 000 |
| Contract duration | 36 months |
| Procedure | Restricted, two-step (Step 1: requests to participate; Step 2: invited tenders) |
| Submission method | Electronic via EU Funding & Tenders Portal (eSubmission) — EU Login and PIC required 1 |
| Shortlisting | Up to 5 candidates will be invited to submit tenders; tie-handling: all candidates with equal score at cut-off score invited |
| Award formula | Best price-quality ratio: Price 40% / Quality 60% |
| Main CPV codes | 51611100 (hardware installation services); additional: 30234500 (memory storage media), 44316400 (hardware) |
Application templates and form structure (what you must prepare)
At Step 1 (request to participate) candidates must prepare and upload the following at minimum (see Annex 1A and the Tender Specifications Part 1 for exact file names and sections):
- 1Declaration on Honour (Annex 2) signed by authorised representative (exclusion and selection criteria).
- 2Evidence of legal and regulatory capacity (proof of registration in trade/professional register) for each involved entity.
- 3Financial accounts / P&L for the last two years for each involved entity (to support turnover F1).
- 4Ownership Control Declaration (Annex 6a) plus supporting ownership and corporate governance documents uploaded to the Participant Register PIC account (full ownership chain up to ultimate owners, shareholders with >=5%, shareholders agreements, commercial/financial links).
- 5List of identified subcontractors (Annex 4) and commitment letters by identified subcontractors (Annex 5.1) where applicable (subcontractors >20% or relied on for selection).
- 6Commitment letters by entities on whose capacities the candidate relies (Annex 5.2) where applicable.
- 7Evidence of ISO/IEC 27001 and other management system certificates, FSC or Security Declaration of Responsibility, and compliance evidence with ENS high level, ISO 22301, ISO 20000, ISO 9001 as required.
- 8Annex 8 Similar Projects Description — at least three eligible projects with minimum value €1 400 000 each in the last 3 years, with supporting evidence (reference letters, certificates, invoices) where available.
- 9Annex 9 Professional Capacity T6-T8: CVs (Europass) and evidence of PSC clearances and language capability for proposed experts (or declaration of ability to recruit).
If any of the requested supporting documents are already registered with the contracting authority and still valid (issued within the last 12 months), you may indicate the reference to the previous submission where allowed. The contracting authority or Central Validation Service may request additional documents or clarifications at short notice during the evaluation.
Practical submission, timelines and compliance checklist
- 1Create EU Login account and verify organisation in the Participant Register (obtain PIC). Ensure LEAR is appointed and Ownership Control Declaration and supporting evidence are uploaded in the PIC account (Annex 6a).
- 2Subscribe to the Funding & Tenders Portal call page to receive notifications and download all documents (Invitation to tender, Tender Specifications Part 1 Administrative specifications, Annexes 2, 6a, €6B, 8, 9, Draft Contract).
- 3Prepare and upload the full request to participate through eSubmission before the deadline: 14 September 2026 14:00 (Europe/Bucharest). The eSubmission timestamp is the proof of timely submission.
- 4If shortlisted, expect to sign an NDA to access full Technical Specifications (Tender Specifications Part 2) and the Draft Contract. Prepare detailed technical and financial tender for Step 2 in line with award criteria and technical specs. Use the Financial Tender Model (Annex 6) provided at Step 2.
- 5Provide all requested evidence of exclusion/selection criteria if requested during evaluation. Maintain availability of key personnel and PSC evidence for verification.
Important operational notes and risks:ownership and control screening is strict under DEP restricted calls — any indication of control by ineligible third countries or entities may render the tender ineligible. PSCs and FSCs are mandatory at selection for certain roles and for facility-level clearance. The contracting authority may require replacement of personnel who do not meet security or competency expectations. Costs of security clearances, compliance and required certificates are at tenderer expense. Tenderers should ensure hardware and software EoL/EoS dates and warranty/maintenance coverage for 36 months are included. Variants are not permitted.
How would you explain this opportunity — general summary
This is a restricted public procurement launched by the European Cybersecurity Competence Centre in partnership with national partners to procure a resilient, secure, production-grade hosting site in Madrid to host the majority of the ENSOC cross-border cybersecurity platform solutions for the consortium. The contract covers hardware, storage, compute, networking, cybersecurity services, secure Internet connectivity with redundancy, backup, identity governance, monitoring and operations, maintenance, training and documentation for a 36-month operational lifecycle and a €4 millioneuro estimated value. The tender is a two-step restricted process: eligible bidders must first submit a request to participate with mandatory exclusion and selection evidence including ownership/control declarations (Digital Europe restricted rules), financial capacity, technical experience (three similar projects >= €1.4M each), ISO and security certifications and security clearances for personnel. Up to five candidates will be invited to submit full tenders (technical and financial) and the award will be based on best price-quality ratio (40% price, 60% quality). All submissions are electronic via the EU Funding & Tenders Portal and all procurement documents and templates (Annexes 1A/€1B, 2, 3, 4, 5.1, 5.2, 6a, €6B, 8, 9 and the Draft Contract) are published on the Portal. This is a procurement for a production hosting site delivering operational cybersecurity and infrastructure services under EU security and data protection rules and strict ownership/control limitations, requiring experienced integrators with demonstrated high-security hosting track record and personnel security clearance capability.
For application, follow the Annex 1A checklist exactly, upload the Declaration on Honour, Ownership Control Declaration and all required certificates and financial evidence to the Participant Register PIC account and submit the request to participate before 14 September 2026 14:00 (Europe/Bucharest). Shortlisted candidates will be invited to Step 2 and will receive the Technical Specifications Part 2 and Draft Contract under NDA. 1
Footnotes
- 1Full procurement documents, templates, invitation to tender, tender specifications and Annexes are published on the EU Funding & Tenders Portal at the tender page. Access and eSubmission require EU Login and a PIC. See the call page: Funding & Tenders Portal ENSOC Tender Details
Short Summary
Impact Deliver a resilient, secure production hosting site in Madrid to enable cross‑border cyber intelligence sharing, incident coordination and operational continuity for the ENSOC platform. | Impact | Deliver a resilient, secure production hosting site in Madrid to enable cross‑border cyber intelligence sharing, incident coordination and operational continuity for the ENSOC platform. |
Applicant Experienced ICT integrators able to supply, deploy and operate high‑security hosting infrastructure with proven secure‑hosting, networking, backup, identity governance and data‑protection capabilities and personnel security clearances. | Applicant | Experienced ICT integrators able to supply, deploy and operate high‑security hosting infrastructure with proven secure‑hosting, networking, backup, identity governance and data‑protection capabilities and personnel security clearances. |
Developments Provision, configuration, operation and 36‑month maintenance of secure computing, storage, networking and cybersecurity services in a Tier‑4 data centre to host ENSOC cross‑border cyber hub solutions. | Developments | Provision, configuration, operation and 36‑month maintenance of secure computing, storage, networking and cybersecurity services in a Tier‑4 data centre to host ENSOC cross‑border cyber hub solutions. |
Applicant Type Large corporations and government organisations with capabilities in secure data‑centre hosting, system integration and managed cybersecurity services. | Applicant Type | Large corporations and government organisations with capabilities in secure data‑centre hosting, system integration and managed cybersecurity services. |
Consortium Single applicants or joint submissions are permitted (joint liability applies); subcontracting and reliance on other entities is allowed but those entities must meet ownership/control and security requirements. | Consortium | Single applicants or joint submissions are permitted (joint liability applies); subcontracting and reliance on other entities is allowed but those entities must meet ownership/control and security requirements. |
Funding Amount Estimated total contract value €4,000,000 for the procedure (36‑month contract); no co‑funding rate because this is a procurement contract. | Funding Amount | Estimated total contract value €4,000,000 for the procedure (36‑month contract); no co‑funding rate because this is a procurement contract. |
Countries Primary location Spain (Madrid hosting site); contracting lead ECCC (Romania) with participating partners from Spain, Italy, Portugal, Luxembourg, Romania, Austria and the Netherlands influencing eligibility and requirements. | Countries | Primary location Spain (Madrid hosting site); contracting lead ECCC (Romania) with participating partners from Spain, Italy, Portugal, Luxembourg, Romania, Austria and the Netherlands influencing eligibility and requirements. |
Industry Cybersecurity (Digital Europe Programme) targeting secure ICT infrastructure and cross‑border cyber‑defence capabilities. | Industry | Cybersecurity (Digital Europe Programme) targeting secure ICT infrastructure and cross‑border cyber‑defence capabilities. |
Additional Web Data
This is an EU restricted procurement, not a grant call, for a services contract that will provide hosting site infrastructure, internet connectivity, cybersecurity, training, and communications support for the ENSOC solutions hosted in Madrid. The official portal summary shows an estimated value of €4,000,000, a restricted procedure, and a request to participate deadline of 14 September 2026 at 14:00 Europe/Bucharest.[1]
| Key item | Details |
|---|---|
| Opportunity title | ENSOC Hosting Site ES ICT Infrastructure (Computing, Storage, Networking, Cybersecurity) |
| Procedure identifier | ECCC/BUH/2026/RP/0020 |
| Opportunity type | Tender, restricted procedure |
| Estimated total value | €4,000,000[1] |
| Contract nature | Services |
| Maximum contract duration | 36 months |
| Award method | Best price-quality ratio |
| Price and quality weighting | Quality 60 percent, price 40 percent |
| Lots | No lots |
| Submission method | Electronic only |
| Deadline for requests to participate | 14 September 2026, 14:00 Europe/Bucharest[1] |
| Primary performance location | Existing Tier 4 data centre in Madrid, Spain |
| Main CPV | 51611100 Hardware installation services |
| Additional CPV codes | 44316400, 30234500 |
| SME suitability | Not SME suitable |
| Framework agreement | No |
| Lead contracting authority | European Cybersecurity Industrial, Technology and Research Competence Centre |
What the procurement is about
The contract aims to secure the hosting site capabilities for the majority of ENSOC solutions in Spain, with state of the art resilient infrastructure, secure data sharing, communications, and related services. The contractor must provide hardware, storage, networking, cybersecurity, backup, secure connectivity, monitoring, maintenance, and support services for the ENSOC CBP environment, hosted at an existing Tier 4 data centre in Madrid.
The wider programme context is the ENSOC Cross border Cyber Hub Platform, a joint European cybersecurity effort focused on cyber intelligence sharing, incident coordination, automation, and situational awareness across participating member states. The hosting site in Spain is one of the three hosting infrastructures of the broader ENSOC ecosystem, alongside Portugal and Italy.
Who can apply
The procedure is open to economic operators that can participate in a restricted EU procurement and that are not excluded by the standard EU exclusion grounds or by restrictive measures restrictions. Interested operators must submit a request to participate electronically, and only selected candidates will be invited to submit a full tender.
Applicants may participate as a single candidate or as a joint submission, and they may also rely on subcontractors or on the capacities of other entities where permitted by the tender documents. A Participant Identification Code is required, and all relevant entities must complete the required declarations, including the ownership and control declaration.
- Candidates must be able to prove legal and regulatory capacity, economic and financial capacity, and technical and professional capacity.
- Candidates, consortium members, subcontractors, and relied-on entities must not be subject to EU restrictive measures.
- Candidates must not have established debts to the Union, the Euratom Community, or an executive agency when relevant.
- Candidates must submit the request to participate only through the electronic submission system.
- Only one request to participate per candidate will be considered; if more are submitted, only the latest remains valid unless earlier ones were withdrawn.
Eligibility and selection requirements
| Area | Requirement | Applicant implication |
|---|---|---|
| Similar project experience | At least three similar projects in scope and complexity, each with a value of at least €1,400,000, completed within the last three years, with experience in highly secure cybersecurity infrastructure services. | Evidence of relevant large scale references is essential. |
| Project manager T6 | At least one project manager with a university degree, at least 10 years of international professional experience, at least 5 years in design, deployment or operation of secure technology infrastructure and complex integrations, C1 English, C1 Spanish, and PSC at RESTREINT UE or EU RESTRICTED level. | A named senior delivery lead is required. |
| Senior expert T7 | At least one senior expert with a university degree, at least 5 years of international professional experience delivering training and operational support in hosting and secure integration, at least 3 years in secure infrastructure and complex integrations, C1 English, C1 Spanish, and PSC at RESTREINT UE or EU RESTRICTED level. | Training and operational support capability is mandatory. |
| Junior analyst or technician T8 | At least four junior analysts or technicians with a university degree, at least 3 years of professional experience in hosting and secure integration projects, at least 2 years in secure infrastructure and complex integrations, B2 English, C1 Spanish, and PSC at RESTREINT UE or EU RESTRICTED level. | The delivery team must be staffed at the stated minimum level. |
| Security and control | Ownership and control declaration required for all relevant entities, including evidence of ownership structure, governance, and possible control links with ineligible countries. | This is a sensitive security restricted procurement and the contracting authority may request further evidence. |
| Data protection capability | Staff must be able to support data protection compliance, including data protection by design and by default, DPIAs, records, privacy statements, and breach handling where relevant. | Data protection competence is a substantive delivery requirement. |
Technical and contractual points applicants should note
- The full technical specifications are not disclosed at step 1 and are only made available to invited candidates after signing a non disclosure agreement.
- Variants are not allowed, so tenders must match the model solution requested by the contracting authority.
- The contract will be a direct contract, not a framework agreement, and no lotting applies.
- The contractor must comply with ECCC security rules, EU classified information requirements, and the contracting authority may require security briefings or security cleared personnel at the contractor's expense.
- The contractor must support secure communications, cybersecurity controls, monitoring, backups, identity governance, interoperability, and service level commitments covering the full 36 month lifecycle.
- The work must support compliance with both Regulation 2018/1725 and Regulation 2016/679 where personal data is processed.
Submission process and practical requirements
Requests to participate must be submitted electronically through the Funding and Tenders Portal eSubmission system. EU Login is required, and the portal documents indicate that the candidate must ensure the submission is complete, timely, and properly signed where required.
- Deadline for requests to participate: 14 September 2026 at 14:00 Europe/Bucharest.
- The invitation warns that late submissions will be rejected.
- The invitation to tender states that any legal or natural person not invited to tender in the second step will have a subsequent tender rejected.
- The procurement documents and updates are published in English, and candidates are responsible for monitoring changes during the submission period.
- The portal provides public guidance on required documents, including the declaration on honour, ownership control declaration, similar projects form, professional capacity form, and draft contract.
Overall opportunity assessment
This is a high value, security sensitive EU ICT infrastructure procurement for experienced suppliers with demonstrable delivery in secure hosting, cybersecurity, networking, and multi site integration. The most important success factors are a strong track record in comparable secure infrastructure projects, a qualified team with the required project management and operational expertise, strong Spanish and English language capability, and the ability to meet stringent ownership, security, and data protection requirements.[1]
Because the contract is a procurement and not a grant, there is no funding rate or co financing percentage. The relevant commercial variables are the contract value, technical compliance, award score, service levels, and the ability to pass the restricted selection stage.[1]
Update Log
No updates recorded yet.
Discover with AI
Let our intelligent agent help you find the perfect funding opportunities tailored to your needs.
EU Grant Database
Explore European funding opportunities in our comprehensive, up-to-date collection.
Stay Informed
Get notified when grants change, deadlines approach, or new opportunities match your interests.
Track Your Favorites
Follow grants you're interested in and keep them organized in one place. Get updates on changes and deadlines.
ATHENA Cross Border Cyber Hub Platform - Infrastructure
This is a restricted two-stage EU procurement (request to participate deadline 8 September 2026 at 14:00 Europe/Bucharest) for the ATHENA Cross Border Cyber Hub Platform Infrastructure with an estimated total value of EUR 9,405,000. The...
Administrative support services to EUSPA (EUSPA/OP/19/26)
The European Union Agency for the Space Programme (EUSPA) is procuring framework contracts in cascade for administrative support services divided into two lots: Lot 1 for unclassified services delivered from contractor premises (estimate...
Supply and Installation of the Personal Microwave Security Scanners
The European Union Agency for the Space Programme (EUSPA) is procuring the supply and installation of personal microwave security scanners for its sites near Paris, France and near Madrid, Spain under a supplies framework agreement. The...
ICTSS IV - ICT Support Services IV
CEDEFOP has launched an open procurement (ref CEDEFOP/2026/OP/0010) to award a single-provider framework contract for ICT support services, with submission by 15 September 2026. The contract covers operational ICT support for Microsoft t...
Maintenance of Technical Installations and Engineering Services Delegation of the European Union to Japan
The Delegation of the European Union to Japan has published a call for tenders (EEAS/DELJPNT/2026/RP/0066) for a framework contract to provide maintenance of technical installations and engineering services at Europa House in Tokyo, with...
CFT-1747 - IT Security Hardware and Software
CFT-1747 is a European Investment Bank open tender to award a multiple-operator framework agreement (minimum 2, maximum 5 providers) for the supply and renewal of IT security hardware and software and associated services, with an estimat...
Guarding services for the Houses of Europe in Copenhagen, Stockholm and Helsinki
Public procurement tender for guarding and reception services at the European Commission Representations (Houses of Europe) in Copenhagen, Stockholm and Helsinki, to be awarded as a framework agreement split into three lots. Procedure is...
DTS/260921-IT Consultancy Services
The European Centre for Disease Prevention and Control (ECDC) has published an open tender ECDC/2026/OP/0009 for IT consultancy services with an estimated total value of EUR 12,000,000. The procurement will establish a mixed multiple fra...
ACQUISITION, DELIVERY, INSTALLATION AND HARDWARE AND SOFTWARE MAINTENANCE OF INNOVATE INDUSTRIAL GRADE SUPERCOMPUTER – FOR THE EUROPEAN HIGH PERFORMANCE COMPUTING JOINT UNDERTAKING (EUROHPC JU)
The EuroHPC Joint Undertaking has published a public procurement to select a single vendor or consortium to supply, deliver, install and provide hardware and software maintenance for the INNOVATE industrial-grade supercomputer to be host...
Provision of Interim Workers to EUSPA (EUSPA/OP/18/26)
This procurement seeks to conclude up to two framework contracts in cascade for the provision of interim workers to perform clerical, secretarial and office management tasks at EUSPA headquarters in Prague under Czech law. The estimated...
European Health Data Space IT systems development, operations and support
This is a competitive EU public procurement (service contract) to provide development, operations, maintenance, cybersecurity, user support and handover for core European Health Data Space IT systems including HealthData@EU platforms, th...
Efficient, experience-driven, proactive and resilient solutions and support services
Call EC-DIGIT/2025/OP/0071 is a European Commission (DG DIGIT) open tender to award a single-lot framework contract for end-to-end Digital Workplace services including service desk and support, device lifecycle management, endpoint manag...