Sector Guide

Cybersecurity Procurement in Europe — How Governments Buy Security

European governments are spending more on cybersecurity than at any point in history. The combination of rising threat levels, mandatory regulation through the NIS2 Directive, and accelerating digital transformation has turned cybersecurity into one of the fastest-growing procurement categories on the continent.

The European cybersecurity market exceeds 50 billion EUR annually. Public sector spending on cybersecurity is growing at 15-20% per year. And the NIS2 Directive, effective since October 2024, has expanded mandatory cybersecurity obligations to over 150,000 entities across the EU — each of which must now procure security tools, services, or expertise to comply.

For cybersecurity companies, this creates a large and growing market. But government cybersecurity procurement follows rules and patterns that differ from commercial sales. This guide covers how European governments buy security services, where to find tenders, what qualifications you need, and how to position your company to win.

What governments buy: cybersecurity procurement categories

Government cybersecurity procurement spans four broad categories, each with distinct procurement patterns, buyer expectations, and competitive dynamics.

Security consulting and advisory

Governments buy cybersecurity strategy, risk assessments, compliance audits, and policy development. NIS2 compliance assessments are a major growth area. These contracts typically use open procedures or framework agreement call-offs, with evaluation weighted heavily toward consultant expertise and methodology.

Common scope items:

  • Cybersecurity maturity assessments
  • NIS2 gap analysis and compliance roadmaps
  • Risk management framework design (based on ISO 27005, NIST CSF, BSI IT-Grundschutz)
  • Security architecture reviews
  • GDPR and cybersecurity policy alignment

Managed security services

Managed detection and response (MDR), security operations center (SOC) services, and managed firewall and endpoint protection represent the largest recurring revenue segment. These are almost always procured through framework agreements or dynamic purchasing systems, given their multi-year nature and the need for rapid call-off capability.

Typical contract structures:

  • 2-4 year base term with optional extensions
  • Service level agreements with defined response times (15 minutes to 4 hours depending on severity)
  • 24/7 monitoring and incident response requirements
  • Monthly or quarterly reporting obligations
  • Security clearance requirements for staff accessing government networks

Security products and tools

Governments procure SIEM platforms, endpoint detection and response (EDR), identity and access management (IAM), vulnerability scanners, encryption solutions, and network security appliances. Product procurement often uses lowest price evaluation for commodity items, but MEAT (most economically advantageous tender) for complex platforms.

Training and awareness

Security awareness training for government employees is a rapidly growing category. NIS2 explicitly requires management-level cybersecurity training. Contracts range from e-learning platform licenses to bespoke tabletop exercises and incident simulation programs.

NIS2 Directive: the procurement catalyst

The NIS2 Directive is the single largest driver of cybersecurity procurement growth in Europe. Understanding its procurement implications is essential for any supplier targeting this market.

What NIS2 requires

NIS2 replaced the original NIS Directive (2016) with dramatically expanded scope. Key provisions that drive procurement:

  • Entity coverage expanded 15x — From roughly 10,000 to over 150,000 organizations across the EU, including energy, transport, banking, healthcare, water, digital infrastructure, public administration, space, postal services, waste management, food, manufacturing, and chemicals.
  • Mandatory risk management measures — All covered entities must implement "appropriate and proportionate" cybersecurity measures. Article 21 specifies incident handling, business continuity, supply chain security, network security, access control, encryption, and multi-factor authentication.
  • Supply chain security — Entities must assess and manage cybersecurity risks in their supply chains. This creates secondary procurement demand as regulated entities require their suppliers to demonstrate security capabilities.
  • Incident reporting — Significant incidents must be reported within 24 hours (early warning) and 72 hours (full notification). This drives procurement of incident detection, monitoring, and response capabilities.
  • Management liability — Senior management can be held personally liable for cybersecurity failures. This accelerates procurement timelines and budget approvals.

Procurement impact by sector

Sector NIS2 impact Procurement priorities
Energy Critical, 100% covered OT/ICS security, SCADA monitoring, incident response
Healthcare Expanded coverage Medical device security, patient data protection, SOC
Transport All modes covered Network segmentation, access control, monitoring
Public administration Central + regional Compliance assessments, managed services, training
Digital infrastructure Cloud, DNS, data centers Penetration testing, certification, security audits
Water and waste Newly covered Basic cyber hygiene, network security, awareness

NIS2 transposition timeline

Member states had until October 2024 to transpose NIS2 into national law. Several countries met this deadline. Others are still finalizing transposition. This staggered timeline means procurement activity is ramping up across different markets at different speeds — creating opportunities for suppliers who can track which countries are entering their active procurement phase.

Where to find cybersecurity tenders

Cybersecurity tenders are distributed across EU-wide and national platforms. Effective monitoring requires coverage of multiple sources, because buyers classify cybersecurity contracts inconsistently.

EU-level sources

  • TED (Tenders Electronic Daily) — All above-threshold cybersecurity contracts from EU member states appear here. The eForms standard provides structured CPV code data for filtering.
  • CERT-EU and EU institution tenders — The European Commission, EU agencies, and CERT-EU publish dedicated cybersecurity tenders for their own infrastructure.
  • ENISA (EU Agency for Cybersecurity) — Publishes its own procurement and provides intelligence on member state cybersecurity procurement patterns.

National platforms

Each country maintains procurement portals where cybersecurity tenders appear:

  • Germany: bund.de (federal), plus 14 state-level platforms. BSI publishes security-specific tenders.
  • France: BOAMP, PLACE, and ANSSI-related tenders across 18 regional platforms.
  • Netherlands: TenderNed. The NCSC (National Cyber Security Centre) drives significant procurement.
  • UK: Contracts Finder, Digital Marketplace, and the dedicated Cyber Security Services framework through Crown Commercial Service.
  • Nordic countries: Doffin (Norway), Hilma (Finland). The Nordics are early adopters of advanced cybersecurity capabilities.

CPV codes for cybersecurity

Cybersecurity does not have a dedicated CPV division. Tenders are scattered across several codes:

CPV code Description Cybersecurity relevance
72000000 IT and related services Broadest cybersecurity category
72200000 Software programming and consulting Security software development, consulting
72212000 Programming of application software Security tool development
72310000 Data processing services SOC services, log management, SIEM
72500000 Computer-related services General IT security services
79710000 Security services Physical and information security overlap
79713000 Guard services Increasingly includes cyber guard services
32420000 Network equipment Firewalls, IDS/IPS appliances
80510000 Specialist training Cybersecurity training

Because CPV classification is inconsistent, keyword-based monitoring is essential. Key terms: cybersecurity, information security, penetration testing, vulnerability assessment, SOC, SIEM, incident response, managed detection, threat intelligence, security operations, NIS2, ISO 27001 audit.

Procurement intelligence

Given the fragmentation of cybersecurity tenders across hundreds of sources and inconsistent classification, most serious cybersecurity suppliers use procurement intelligence platforms like Duke to aggregate, filter, and monitor opportunities across all European markets. Duke tracks cybersecurity-related tenders across 30 countries using CPV code matching and keyword analysis, ensuring suppliers see relevant opportunities regardless of how the buyer classified them.

Security clearance requirements by country

Many cybersecurity contracts — particularly those involving government classified networks, critical infrastructure, or defense systems — require security clearances. Requirements vary significantly by country.

Country Authority Clearance levels Typical processing time
Germany BMWi / BSI VS-NfD, VS-Vertraulich, Geheim, Streng Geheim 6-12 months
France SGDSN / ANSSI Confidentiel Defense, Secret Defense, Tres Secret Defense 6-18 months
UK UKSV BPSS, SC, CTC, DV 6-18 months
Netherlands AIVD Vertrouwelijk, Geheim, Staatsgeheim 8-16 months
Belgium ANS/NVO Confidentiel, Secret, Tres Secret 6-12 months
Italy DIS Riservato, Riservatissimo, Segreto, Segretissimo 6-18 months

Key principles:

  • Facility Security Clearance (FSC) — Your company premises must meet classified information handling standards before any personnel clearances can be issued.
  • Personnel Security Clearance (PSC) — Individual clearances for staff who will access classified systems or data.
  • Foreign ownership restrictions — Some countries restrict or scrutinize clearances for companies with non-national ownership structures.
  • NATO clearance — For contracts involving NATO systems, separate NATO security clearances may be required.

Non-classified cybersecurity work (which represents the majority of the market) does not require clearances. Most NIS2 compliance consulting, security awareness training, managed detection for non-classified networks, and commercial product procurement is unclassified.

Framework agreements and dynamic purchasing systems

Framework agreements are the dominant procurement mechanism for cybersecurity services in Europe. Understanding how they work is essential for building a sustainable public sector cybersecurity business.

Why frameworks dominate cyber procurement

Cybersecurity threats evolve continuously. Governments need the ability to procure security services quickly, without running full procurement procedures for each engagement. Frameworks provide:

  • Speed — Call-offs under existing frameworks can be placed in days or weeks, versus 3-6 months for a new procurement.
  • Pre-qualification — Only framework members can bid, reducing competition and increasing win rates on individual call-offs.
  • Multi-year revenue — Frameworks typically run 2-4 years with extensions, providing predictable revenue.
  • Relationship building — Repeat call-offs create ongoing client relationships and deeper understanding of buyer needs.

Major cybersecurity frameworks in Europe

  • UK Cyber Security Services 3 (CSS3) — Crown Commercial Service framework covering penetration testing, security operations, cyber consultancy, and incident response. Values in the hundreds of millions GBP.
  • Germany Kaufhaus des Bundes IT Security — Federal purchasing frameworks for IT security consulting, products, and managed services.
  • France UGAP Cybersecurity — Centralized frameworks covering security products and services for all French public entities.
  • Netherlands SLM Rijk Security — IT security frameworks serving the Dutch central government.
  • EU Institutions CERT-EU frameworks — Dedicated cybersecurity frameworks for European Commission and EU agency infrastructure.

Dynamic purchasing systems (DPS)

Some contracting authorities use dynamic purchasing systems for cybersecurity procurement. Unlike frameworks, DPS allows new suppliers to join at any time during the system's life. This lowers the barrier to entry for smaller or newer cybersecurity firms.

DPS is particularly common for:

  • Penetration testing services
  • Security training
  • Cyber incident response retainers
  • Vulnerability assessment services

Qualification requirements and certifications

Government cybersecurity buyers require demonstrable competence. Certifications serve as the primary qualification filter. Building the right certification portfolio before pursuing tenders is the most effective investment a cybersecurity supplier can make.

Essential certifications

Certification Issuer Relevance Geography
ISO 27001 ISO Information security management system Universal across EU
SOC 2 Type II AICPA Service organization controls Growing EU adoption
ISO 22301 ISO Business continuity management Incident response contracts
ISO 9001 ISO Quality management Baseline for all tenders

Country-specific requirements

Certification Country Relevance
BSI C5 Germany Mandatory for cloud security services to federal government
SecNumCloud France Required for sensitive government cloud workloads
CREST UK Accreditation for penetration testing firms
CHECK UK Required for penetration testing on government networks
Cyber Essentials Plus UK Baseline for all government cyber contracts
PASSI France ANSSI qualification for security audit providers
IT-Grundschutz Germany BSI framework alignment, often requested

Professional qualifications

Beyond company certifications, tenders frequently require named individuals with specific professional certifications:

  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • CEH (Certified Ethical Hacker)
  • OSCP (Offensive Security Certified Professional)
  • GIAC certifications (SANS Institute)
  • CompTIA Security+

Buyers evaluate the team proposed for the contract. Having certified professionals on staff — and being able to name them in your bid — is often a mandatory pass/fail criterion.

Winning strategies for cybersecurity procurement

Get onto frameworks first

The highest-return action for any cybersecurity supplier entering the public sector market is qualifying for relevant frameworks. Once on a framework, you gain access to call-off opportunities with reduced competition. Monitor framework re-procurement cycles and prepare applications well in advance of deadlines.

Build your reference portfolio

Government buyers are risk-averse. They want evidence you have delivered similar cybersecurity services to similar organizations. Build references by:

  • Starting with smaller, lower-clearance contracts
  • Pursuing subcontracting roles on larger programs
  • Delivering NIS2 compliance assessments (high volume, lower barrier to entry)
  • Working with local government before pursuing national-level contracts

Invest in certifications proactively

Do not wait for a specific tender to require a certification before pursuing it. The most successful cybersecurity suppliers in the public sector build certification portfolios ahead of demand. ISO 27001 and one country-specific certification (BSI C5, SecNumCloud, CREST) for your primary target market should be the minimum.

Track NIS2 transposition by country

NIS2 transposition timelines vary by member state. Countries that have completed transposition are generating active procurement. Countries still finalizing national legislation will generate procurement waves in the coming 12-18 months. Position your business in markets that match your language, certification, and clearance capabilities.

Specialize, then expand

The cybersecurity procurement market rewards specialization. Buyers prefer suppliers with deep expertise in a specific area — penetration testing, SOC services, OT/ICS security, identity management — over generalists claiming broad capabilities. Establish a strong position in one category, build references, and then expand to adjacent services.

NIS2 compliance wave

The full procurement impact of NIS2 is still unfolding. As enforcement mechanisms mature and penalties for non-compliance begin to be applied, the urgency of procurement will increase. The 150,000+ newly regulated entities represent years of procurement activity as they work through compliance requirements.

AI-powered security

Governments are increasingly procuring AI-enhanced cybersecurity tools for threat detection, automated incident response, and security analytics. The EU AI Act creates a regulatory framework that intersects with cybersecurity procurement, requiring suppliers to address both security and AI compliance requirements.

OT/ICS security growth

Critical infrastructure protection under NIS2 is driving rapid growth in operational technology (OT) and industrial control system (ICS) security procurement. Energy, water, and transport operators must now secure legacy industrial systems that were never designed with cybersecurity in mind. This niche requires specialized expertise that few suppliers currently offer.

Sovereign security solutions

The EU's push for digital sovereignty extends to cybersecurity. Governments increasingly prefer European-developed security tools, particularly for sensitive applications. The European Cybersecurity Certification Framework under the EU Cybersecurity Act is creating EU-specific certification schemes that may advantage European suppliers.

Cyber resilience and supply chain security

NIS2's supply chain security requirements are creating cascading procurement demand. Regulated entities must assess the cybersecurity of their suppliers, driving procurement of supply chain risk management tools, third-party security assessments, and continuous monitoring services.

How Duke helps cybersecurity suppliers

Duke provides procurement intelligence specifically designed for cybersecurity companies competing across European markets:

  • Unified monitoring across 30+ countries and hundreds of procurement platforms, filtered by cybersecurity-relevant CPV codes and keyword matching
  • AI-powered matching that surfaces relevant cyber tenders based on your specific capabilities, certifications, and target markets
  • Framework tracking with alerts when major cybersecurity frameworks are opening for new applications or re-procurement
  • NIS2 opportunity mapping showing which countries and sectors are generating the highest volumes of cybersecurity procurement
  • Real-time alerts ensuring you never miss a deadline on a high-value cybersecurity opportunity

Conclusion

Cybersecurity procurement in Europe is entering a period of sustained, regulation-driven growth. NIS2 has expanded mandatory cybersecurity requirements to 150,000+ entities. Public sector cybersecurity spending is growing at 15-20% annually. Framework agreements, security clearances, and professional certifications define the competitive landscape.

Success in this market requires preparation. Build your certification portfolio. Get onto the right frameworks. Start with accessible contract types and build references. Track NIS2 transposition timelines to identify emerging procurement waves. And use procurement intelligence to ensure you see every relevant opportunity across Europe's fragmented procurement landscape.

The companies that treat government cybersecurity as a strategic market — investing in certifications, clearances, and public sector expertise — are the ones that will capture the largest share of this growing spend.


Find cybersecurity procurement opportunities across all European markets in one feed. Duke monitors 300+ sources, matches by CPV codes and cybersecurity keywords, and alerts you to framework openings. Start your free trial today.

Frequently Asked Questions

What CPV codes should I use to find cybersecurity tenders in Europe?

Cybersecurity tenders appear under several CPV codes. The primary ones are 72000000 (IT and related services), 72212000 (programming services for application software), 72310000 (data processing services), 72500000 (computer-related services), and 79710000 (security services). For hardware-adjacent contracts like firewalls and network security appliances, check CPV 32420000 (network equipment) and 30210000 (data-processing machines). Because buyers classify cybersecurity inconsistently, keyword searches for terms like 'cybersecurity', 'SOC', 'penetration testing', 'SIEM', and 'incident response' are essential supplements to CPV filtering.

Do I need a security clearance to bid on government cybersecurity contracts?

It depends on the contract's classification level. Many cybersecurity tenders — vulnerability assessments, security training, managed detection and response, compliance consulting — do not require clearances. However, contracts involving classified government networks, national critical infrastructure, or defense cyber operations typically require both facility and personnel security clearances. Processing times range from 6 to 18 months depending on the country. If you plan to pursue classified cyber work, start the clearance application process well before specific tenders appear.

How has the NIS2 Directive changed cybersecurity procurement?

NIS2, effective since October 2024, expanded the scope of mandatory cybersecurity obligations from roughly 10,000 to over 150,000 entities across the EU. These entities — spanning energy, transport, healthcare, digital infrastructure, and public administration — must now implement risk management measures, report incidents, and secure their supply chains. This has generated a wave of procurement for cybersecurity audits, managed security services, incident response planning, security awareness training, and compliance tooling. The directive also makes corporate management personally liable for cybersecurity failures, which accelerates procurement decision-making.

What certifications do I need to win cybersecurity procurement contracts?

ISO 27001 (information security management) is near-universal for cybersecurity procurement across Europe. Beyond that, requirements vary by country and contract type. Germany requires BSI C5 attestation for cloud-related security services. France mandates SecNumCloud for sensitive workloads. The UK expects CREST accreditation for penetration testing and CHECK certification for work on government networks. SOC 2 Type II is increasingly requested for managed services. Cyber Essentials Plus (UK) and ENISA certification scheme alignment are also growing requirements. Building certifications proactively, before specific tenders demand them, is the most effective strategy.

Are framework agreements common for cybersecurity procurement?

Framework agreements are the dominant procurement mechanism for cybersecurity in Europe. Governments establish multi-year frameworks (typically 2-4 years, sometimes with extensions) with pre-qualified cybersecurity suppliers. Individual contracts are then placed as call-offs without full re-procurement. Major examples include the UK's Cyber Security Services 3 framework, Germany's Kaufhaus des Bundes IT security panels, France's UGAP cybersecurity frameworks, and EU institutions' own cyber frameworks managed by CERT-EU. Getting onto these frameworks is often the single highest-value action a cybersecurity supplier can take.

Newsletter

Enjoyed this article?

Get data-driven procurement insights like this delivered weekly.

  • Market intelligence & trend analysis
  • New opportunity alerts across Europe
  • Practical bidding strategies that work

Free. No spam. Unsubscribe anytime.

A

Antoine Simon

Founder & CEO at Duke

Building infrastructure for public contracts. Based in Brussels.

LinkedIn

Never miss a winnable contract

Duke monitors public procurement across 16 countries so you don't have to.

Request a demo