Publications Office of the EU
Joint Procurement: Infrastructure penetration tests / Supply of IT Security Assessment Services: Penetration Testing / IT Security Assessment Services according to the TIBER-EU framework - EU tenders
DisplayCustomHeader
Procurement Detail Actions Portlet
OP Portal - Procurement - Details

This page contains content generated automatically to improve findability and accessibility

- indicates text translated automatically in your browsing language

Joint Procurement: Infrastructure penetration tests / Supply of IT Security Assessment Services: Penetration Testing / IT Security Assessment Services according to the TIBER-EU framework Text automatically translated in your browsing language Automatically translated

  • Awarded
    30/04/2025
  • Today
    08/11/2025
Status
Awarded
Type of contract
Services
Subject for Renewal
No
Buyer
Banca Nationala a Romaniei
Place of performance
NUTS code: Multiple place of performance
Location of buyer
NUTS code: RO321 Bucureşti
Business sector (Main CPV)
72820000 Computer testing services
Total estimated contract value (excluding VAT)
Not available
Total final contract value (excluding VAT)
Not available
Number of lots
3
Tender reference number
361684_2021_M10
Description

The contract remains a joint procurement. The contracting authority is purchasing also on behalf of other contracting authorities. The numerous institutions are: Banca d'Italia, Via Nazionale 91, Rome, IT 00184, Italy Banco de España, Calle Alcalá, 48, 28014, Spain Banque centrale du Luxembourg, 2, boulevard Royal, L-2983 Luxembourg Central Bank of Cyprus, 80 Kennedy Avenue, Nicosia, CY-1076, CYPRUS Central Bank of Ireland, New Wapping Street, North Wall Quay, Dublin 1, Ireland Central Bank of Malta, Castille Place, Valletta, VLT1060, Malta European Central Bank, Sonnemannstrasse 20, Frankfurt am Main,60314, Germany Oesterreichische Nationalbank, Otto-Wagner-Platz 3, Wien, 1090, Austria Malta Financial Services Authority, Triq l-Imdina, Zone 1, Central Business District, Birkirkara, Malta Other institutions, having the right to participate in EPCO’s activities (according to Decision ECB/2008/17 as amended), which did not express an interest in this procedure before the publication of the contract notice in the OJEU will also have the possibility to join the Framework Agreements - if they wish so - before its expiry. The identity of EPCO members may be consulted on EPCO's website: https://epco.lu/. The objective of the current joint tender procedure is to contract the services for identifying the cybersecurity risks and for guidance to take appropriate technical and organisational measures to minimize those risks within current and future EPCO members of the ESCB. To cover a wider scope, according to the testing methodology, the National Bank of Romania identified three lots for the joint tender procedure: • Lot no. 1 - IT Security Assessment Services in line with the latest Regular Penetration Testing Execution Standards; IT Security Assessment Services according to the TIBER-EU framework: • Lot no. 2 - Targeted Threat Intelligence Services; • Lot no. 3 - Red team IT Security Services. Each lot will result in a framework agreement with the following characteristics: multi-supplier framework agreement (max 5), with reopening the competition. For all Participating Institutions, except NBR, this Framework Agreement shall be non-exclusive, meaning that these Participating Institutions will not have obligation to award assignments to the Contractor according to this Framework Agreement for the purchase of IT Security Assessment Services with the Contractor. For NBR this Framework Agreement shall be exclusive, meaning that during the term of this Framework Agreement NBR will have the obligation to fulfill its needs for IT Security Assessment Services through this Framework Agreement by concluding Further Agreements with the Contractors. All current and future EPCO member central banks are together potential among the Framework Agreements, which the Participating Institutions will implement via reopening of the competition (mini-competition) among the Contractors. Each Participating Institution shall be entitled to describe its specific needs regarding the IT Security Assessment Services (the IT infrastructure that needs to be tested), apply its own offers evaluation methodology, and quality/price weighting within the terms of the Framework Agreement to assign the Further Agreements. Deadline for deciding clarifications to the award documentation: 16 days before the deadline for submission of offers Date of response to all requests for clarification: 11 days before the deadline for submission of offers Text automatically translated in your browsing language Automatically translated

Submission Method
Not available
Tenders may be submitted
Not available
Information about a public contract, a framework agreement or a dynamic purchasing system (DPS)
The procurement involves the establishment of a framework agreement
Conditions for opening tenders (date)
Not available
Place of performance
Prior information
Contract
Award
Footnote - legal notice

This content published on this page is meant purely as an additional service and has no legal effect. The Union's institutions do not assume any liability for its contents. The official versions of the relevant tendering notices are those published in the Supplement of Official Journal of the European Union and available in TED. Those official texts are directly accessible through the links embedded in this page. For more information please see Public Procurement Explainability and Liability notice.