Tender detail
Information Security Assessments (RVICTO-PT) 2026
Summary
The procurement seeks a framework agreement for information security assessments and penetration testing of applications, infrastructure, cloud environments, IoT/OT and other digital objects. Testing must combine automated and manual methods and identify, validate and report digital vulnerabilities so that they can be remediated or mitigated. The agreement will support multiple Dutch ministries, national organisations and public bodies for up to four years, with an estimated total value of EUR 20 million excluding VAT and a maximum value of EUR 35 million excluding VAT. Around 800 penetration tests are expected over four years, although actual call-off volumes are not guaranteed. Bidders must submit a complete European Single Procurement Document, relevant penetration-testing references, three quality responses, a price form and a Russia-sanctions declaration. Key requirements include experience across at least three of four target types, experience with complex interdependent IT environments and multi-cloud or multi-tenant environments, an organisation-wide quality management system, ISO/IEC 27001 certification or equivalent controls, and registration in a relevant professional or commercial register. The tender must be submitted electronically by 30 November 2026 at 14:00. Quality accounts for 90 points and price for 10 points; a minimum quality score of 48 points applies, and a score of zero on any quality topic leads to exclusion.
More tender information after sign-in
The public view shows key tender details. Sign in to open official links, documents and AI tender support.