European governments are spending more on cybersecurity than at any point in history. The combination of rising threat levels, mandatory regulation through the NIS2 Directive, and accelerating digital transformation has turned cybersecurity into one of the fastest-growing procurement categories on the continent.
The European cybersecurity market exceeds 50 billion EUR annually. Public sector spending on cybersecurity is growing at 15-20% per year. And the NIS2 Directive, effective since October 2024, has expanded mandatory cybersecurity obligations to over 150,000 entities across the EU — each of which must now procure security tools, services, or expertise to comply.
For cybersecurity companies, this creates a large and growing market. But government cybersecurity procurement follows rules and patterns that differ from commercial sales. This guide covers how European governments buy security services, where to find tenders, what qualifications you need, and how to position your company to win.
What governments buy: cybersecurity procurement categories
Government cybersecurity procurement spans four broad categories, each with distinct procurement patterns, buyer expectations, and competitive dynamics.
Security consulting and advisory
Governments buy cybersecurity strategy, risk assessments, compliance audits, and policy development. NIS2 compliance assessments are a major growth area. These contracts typically use open procedures or framework agreement call-offs, with evaluation weighted heavily toward consultant expertise and methodology.
Common scope items:
- Cybersecurity maturity assessments
- NIS2 gap analysis and compliance roadmaps
- Risk management framework design (based on ISO 27005, NIST CSF, BSI IT-Grundschutz)
- Security architecture reviews
- GDPR and cybersecurity policy alignment
Managed security services
Managed detection and response (MDR), security operations center (SOC) services, and managed firewall and endpoint protection represent the largest recurring revenue segment. These are almost always procured through framework agreements or dynamic purchasing systems, given their multi-year nature and the need for rapid call-off capability.
Typical contract structures:
- 2-4 year base term with optional extensions
- Service level agreements with defined response times (15 minutes to 4 hours depending on severity)
- 24/7 monitoring and incident response requirements
- Monthly or quarterly reporting obligations
- Security clearance requirements for staff accessing government networks
Security products and tools
Governments procure SIEM platforms, endpoint detection and response (EDR), identity and access management (IAM), vulnerability scanners, encryption solutions, and network security appliances. Product procurement often uses lowest price evaluation for commodity items, but MEAT (most economically advantageous tender) for complex platforms.
Training and awareness
Security awareness training for government employees is a rapidly growing category. NIS2 explicitly requires management-level cybersecurity training. Contracts range from e-learning platform licenses to bespoke tabletop exercises and incident simulation programs.
NIS2 Directive: the procurement catalyst
The NIS2 Directive is the single largest driver of cybersecurity procurement growth in Europe. Understanding its procurement implications is essential for any supplier targeting this market.
What NIS2 requires
NIS2 replaced the original NIS Directive (2016) with dramatically expanded scope. Key provisions that drive procurement:
- Entity coverage expanded 15x — From roughly 10,000 to over 150,000 organizations across the EU, including energy, transport, banking, healthcare, water, digital infrastructure, public administration, space, postal services, waste management, food, manufacturing, and chemicals.
- Mandatory risk management measures — All covered entities must implement "appropriate and proportionate" cybersecurity measures. Article 21 specifies incident handling, business continuity, supply chain security, network security, access control, encryption, and multi-factor authentication.
- Supply chain security — Entities must assess and manage cybersecurity risks in their supply chains. This creates secondary procurement demand as regulated entities require their suppliers to demonstrate security capabilities.
- Incident reporting — Significant incidents must be reported within 24 hours (early warning) and 72 hours (full notification). This drives procurement of incident detection, monitoring, and response capabilities.
- Management liability — Senior management can be held personally liable for cybersecurity failures. This accelerates procurement timelines and budget approvals.
Procurement impact by sector
| Sector | NIS2 impact | Procurement priorities |
|---|---|---|
| Energy | Critical, 100% covered | OT/ICS security, SCADA monitoring, incident response |
| Healthcare | Expanded coverage | Medical device security, patient data protection, SOC |
| Transport | All modes covered | Network segmentation, access control, monitoring |
| Public administration | Central + regional | Compliance assessments, managed services, training |
| Digital infrastructure | Cloud, DNS, data centers | Penetration testing, certification, security audits |
| Water and waste | Newly covered | Basic cyber hygiene, network security, awareness |
NIS2 transposition timeline
Member states had until October 2024 to transpose NIS2 into national law. Several countries met this deadline. Others are still finalizing transposition. This staggered timeline means procurement activity is ramping up across different markets at different speeds — creating opportunities for suppliers who can track which countries are entering their active procurement phase.
Where to find cybersecurity tenders
Cybersecurity tenders are distributed across EU-wide and national platforms. Effective monitoring requires coverage of multiple sources, because buyers classify cybersecurity contracts inconsistently.
EU-level sources
- TED (Tenders Electronic Daily) — All above-threshold cybersecurity contracts from EU member states appear here. The eForms standard provides structured CPV code data for filtering.
- CERT-EU and EU institution tenders — The European Commission, EU agencies, and CERT-EU publish dedicated cybersecurity tenders for their own infrastructure.
- ENISA (EU Agency for Cybersecurity) — Publishes its own procurement and provides intelligence on member state cybersecurity procurement patterns.
National platforms
Each country maintains procurement portals where cybersecurity tenders appear:
- Germany: bund.de (federal), plus 14 state-level platforms. BSI publishes security-specific tenders.
- France: BOAMP, PLACE, and ANSSI-related tenders across 18 regional platforms.
- Netherlands: TenderNed. The NCSC (National Cyber Security Centre) drives significant procurement.
- UK: Contracts Finder, Digital Marketplace, and the dedicated Cyber Security Services framework through Crown Commercial Service.
- Nordic countries: Doffin (Norway), Hilma (Finland). The Nordics are early adopters of advanced cybersecurity capabilities.
CPV codes for cybersecurity
Cybersecurity does not have a dedicated CPV division. Tenders are scattered across several codes:
| CPV code | Description | Cybersecurity relevance |
|---|---|---|
| 72000000 | IT and related services | Broadest cybersecurity category |
| 72200000 | Software programming and consulting | Security software development, consulting |
| 72212000 | Programming of application software | Security tool development |
| 72310000 | Data processing services | SOC services, log management, SIEM |
| 72500000 | Computer-related services | General IT security services |
| 79710000 | Security services | Physical and information security overlap |
| 79713000 | Guard services | Increasingly includes cyber guard services |
| 32420000 | Network equipment | Firewalls, IDS/IPS appliances |
| 80510000 | Specialist training | Cybersecurity training |
Because CPV classification is inconsistent, keyword-based monitoring is essential. Key terms: cybersecurity, information security, penetration testing, vulnerability assessment, SOC, SIEM, incident response, managed detection, threat intelligence, security operations, NIS2, ISO 27001 audit.
Procurement intelligence
Given the fragmentation of cybersecurity tenders across hundreds of sources and inconsistent classification, most serious cybersecurity suppliers use procurement intelligence platforms like Duke to aggregate, filter, and monitor opportunities across all European markets. Duke tracks cybersecurity-related tenders across 30 countries using CPV code matching and keyword analysis, ensuring suppliers see relevant opportunities regardless of how the buyer classified them.
Security clearance requirements by country
Many cybersecurity contracts — particularly those involving government classified networks, critical infrastructure, or defense systems — require security clearances. Requirements vary significantly by country.
| Country | Authority | Clearance levels | Typical processing time |
|---|---|---|---|
| Germany | BMWi / BSI | VS-NfD, VS-Vertraulich, Geheim, Streng Geheim | 6-12 months |
| France | SGDSN / ANSSI | Confidentiel Defense, Secret Defense, Tres Secret Defense | 6-18 months |
| UK | UKSV | BPSS, SC, CTC, DV | 6-18 months |
| Netherlands | AIVD | Vertrouwelijk, Geheim, Staatsgeheim | 8-16 months |
| Belgium | ANS/NVO | Confidentiel, Secret, Tres Secret | 6-12 months |
| Italy | DIS | Riservato, Riservatissimo, Segreto, Segretissimo | 6-18 months |
Key principles:
- Facility Security Clearance (FSC) — Your company premises must meet classified information handling standards before any personnel clearances can be issued.
- Personnel Security Clearance (PSC) — Individual clearances for staff who will access classified systems or data.
- Foreign ownership restrictions — Some countries restrict or scrutinize clearances for companies with non-national ownership structures.
- NATO clearance — For contracts involving NATO systems, separate NATO security clearances may be required.
Non-classified cybersecurity work (which represents the majority of the market) does not require clearances. Most NIS2 compliance consulting, security awareness training, managed detection for non-classified networks, and commercial product procurement is unclassified.
Framework agreements and dynamic purchasing systems
Framework agreements are the dominant procurement mechanism for cybersecurity services in Europe. Understanding how they work is essential for building a sustainable public sector cybersecurity business.
Why frameworks dominate cyber procurement
Cybersecurity threats evolve continuously. Governments need the ability to procure security services quickly, without running full procurement procedures for each engagement. Frameworks provide:
- Speed — Call-offs under existing frameworks can be placed in days or weeks, versus 3-6 months for a new procurement.
- Pre-qualification — Only framework members can bid, reducing competition and increasing win rates on individual call-offs.
- Multi-year revenue — Frameworks typically run 2-4 years with extensions, providing predictable revenue.
- Relationship building — Repeat call-offs create ongoing client relationships and deeper understanding of buyer needs.
Major cybersecurity frameworks in Europe
- UK Cyber Security Services 3 (CSS3) — Crown Commercial Service framework covering penetration testing, security operations, cyber consultancy, and incident response. Values in the hundreds of millions GBP.
- Germany Kaufhaus des Bundes IT Security — Federal purchasing frameworks for IT security consulting, products, and managed services.
- France UGAP Cybersecurity — Centralized frameworks covering security products and services for all French public entities.
- Netherlands SLM Rijk Security — IT security frameworks serving the Dutch central government.
- EU Institutions CERT-EU frameworks — Dedicated cybersecurity frameworks for European Commission and EU agency infrastructure.
Dynamic purchasing systems (DPS)
Some contracting authorities use dynamic purchasing systems for cybersecurity procurement. Unlike frameworks, DPS allows new suppliers to join at any time during the system's life. This lowers the barrier to entry for smaller or newer cybersecurity firms.
DPS is particularly common for:
- Penetration testing services
- Security training
- Cyber incident response retainers
- Vulnerability assessment services
Qualification requirements and certifications
Government cybersecurity buyers require demonstrable competence. Certifications serve as the primary qualification filter. Building the right certification portfolio before pursuing tenders is the most effective investment a cybersecurity supplier can make.
Essential certifications
| Certification | Issuer | Relevance | Geography |
|---|---|---|---|
| ISO 27001 | ISO | Information security management system | Universal across EU |
| SOC 2 Type II | AICPA | Service organization controls | Growing EU adoption |
| ISO 22301 | ISO | Business continuity management | Incident response contracts |
| ISO 9001 | ISO | Quality management | Baseline for all tenders |
Country-specific requirements
| Certification | Country | Relevance |
|---|---|---|
| BSI C5 | Germany | Mandatory for cloud security services to federal government |
| SecNumCloud | France | Required for sensitive government cloud workloads |
| CREST | UK | Accreditation for penetration testing firms |
| CHECK | UK | Required for penetration testing on government networks |
| Cyber Essentials Plus | UK | Baseline for all government cyber contracts |
| PASSI | France | ANSSI qualification for security audit providers |
| IT-Grundschutz | Germany | BSI framework alignment, often requested |
Professional qualifications
Beyond company certifications, tenders frequently require named individuals with specific professional certifications:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CEH (Certified Ethical Hacker)
- OSCP (Offensive Security Certified Professional)
- GIAC certifications (SANS Institute)
- CompTIA Security+
Buyers evaluate the team proposed for the contract. Having certified professionals on staff — and being able to name them in your bid — is often a mandatory pass/fail criterion.
Winning strategies for cybersecurity procurement
Get onto frameworks first
The highest-return action for any cybersecurity supplier entering the public sector market is qualifying for relevant frameworks. Once on a framework, you gain access to call-off opportunities with reduced competition. Monitor framework re-procurement cycles and prepare applications well in advance of deadlines.
Build your reference portfolio
Government buyers are risk-averse. They want evidence you have delivered similar cybersecurity services to similar organizations. Build references by:
- Starting with smaller, lower-clearance contracts
- Pursuing subcontracting roles on larger programs
- Delivering NIS2 compliance assessments (high volume, lower barrier to entry)
- Working with local government before pursuing national-level contracts
Invest in certifications proactively
Do not wait for a specific tender to require a certification before pursuing it. The most successful cybersecurity suppliers in the public sector build certification portfolios ahead of demand. ISO 27001 and one country-specific certification (BSI C5, SecNumCloud, CREST) for your primary target market should be the minimum.
Track NIS2 transposition by country
NIS2 transposition timelines vary by member state. Countries that have completed transposition are generating active procurement. Countries still finalizing national legislation will generate procurement waves in the coming 12-18 months. Position your business in markets that match your language, certification, and clearance capabilities.
Specialize, then expand
The cybersecurity procurement market rewards specialization. Buyers prefer suppliers with deep expertise in a specific area — penetration testing, SOC services, OT/ICS security, identity management — over generalists claiming broad capabilities. Establish a strong position in one category, build references, and then expand to adjacent services.
Trends and outlook
NIS2 compliance wave
The full procurement impact of NIS2 is still unfolding. As enforcement mechanisms mature and penalties for non-compliance begin to be applied, the urgency of procurement will increase. The 150,000+ newly regulated entities represent years of procurement activity as they work through compliance requirements.
AI-powered security
Governments are increasingly procuring AI-enhanced cybersecurity tools for threat detection, automated incident response, and security analytics. The EU AI Act creates a regulatory framework that intersects with cybersecurity procurement, requiring suppliers to address both security and AI compliance requirements.
OT/ICS security growth
Critical infrastructure protection under NIS2 is driving rapid growth in operational technology (OT) and industrial control system (ICS) security procurement. Energy, water, and transport operators must now secure legacy industrial systems that were never designed with cybersecurity in mind. This niche requires specialized expertise that few suppliers currently offer.
Sovereign security solutions
The EU's push for digital sovereignty extends to cybersecurity. Governments increasingly prefer European-developed security tools, particularly for sensitive applications. The European Cybersecurity Certification Framework under the EU Cybersecurity Act is creating EU-specific certification schemes that may advantage European suppliers.
Cyber resilience and supply chain security
NIS2's supply chain security requirements are creating cascading procurement demand. Regulated entities must assess the cybersecurity of their suppliers, driving procurement of supply chain risk management tools, third-party security assessments, and continuous monitoring services.
How Duke helps cybersecurity suppliers
Duke provides procurement intelligence specifically designed for cybersecurity companies competing across European markets:
- Unified monitoring across 30+ countries and hundreds of procurement platforms, filtered by cybersecurity-relevant CPV codes and keyword matching
- AI-powered matching that surfaces relevant cyber tenders based on your specific capabilities, certifications, and target markets
- Framework tracking with alerts when major cybersecurity frameworks are opening for new applications or re-procurement
- NIS2 opportunity mapping showing which countries and sectors are generating the highest volumes of cybersecurity procurement
- Real-time alerts ensuring you never miss a deadline on a high-value cybersecurity opportunity
Conclusion
Cybersecurity procurement in Europe is entering a period of sustained, regulation-driven growth. NIS2 has expanded mandatory cybersecurity requirements to 150,000+ entities. Public sector cybersecurity spending is growing at 15-20% annually. Framework agreements, security clearances, and professional certifications define the competitive landscape.
Success in this market requires preparation. Build your certification portfolio. Get onto the right frameworks. Start with accessible contract types and build references. Track NIS2 transposition timelines to identify emerging procurement waves. And use procurement intelligence to ensure you see every relevant opportunity across Europe's fragmented procurement landscape.
The companies that treat government cybersecurity as a strategic market — investing in certifications, clearances, and public sector expertise — are the ones that will capture the largest share of this growing spend.
Related Resources
- IT Procurement in Europe -- Cybersecurity sits within the broader IT procurement ecosystem
- EU Defense Procurement Guide -- Defense cyber overlaps with classified cybersecurity procurement
- What Are CPV Codes -- Master CPV filtering for cybersecurity opportunity search
- How to Set Up Tender Alerts -- Configure alerts for cybersecurity-specific keywords and CPV codes
- Framework Agreements -- How multi-year cybersecurity frameworks work
Find cybersecurity procurement opportunities across all European markets in one feed. Duke monitors 300+ sources, matches by CPV codes and cybersecurity keywords, and alerts you to framework openings. Start your free trial today.