Tender detail
Penetration testing
Summary
The Royal Library of the Netherlands is seeking one contractor for penetration testing of its applications and IT environments. The procurement concerns a single-lot framework agreement with an initial term from 11 January 2027 to 10 January 2029 and two possible one-year extensions, potentially lasting until 10 January 2031. The estimated average annual value is EUR 70,000 excluding VAT, while the maximum framework value is EUR 500,000; there is no volume or revenue guarantee. The contractor must carry out the full testing lifecycle, including scoping, preparation, testing, analysis, risk assessment, advice, reporting and discussion of the results. Reports must cover the tested scope, methods, findings, evidence, impact, remediation advice, tools, limitations, incidents and final assessment. Serious vulnerabilities from CVSS High upwards must be reported immediately. Data must be stored securely in the Netherlands, deleted by default within six months with a destruction certificate, and cloud-based AI tools may not be used during testing. The tender is awarded on the best price-quality ratio: quality carries 60% and price 40%. Quality is assessed through open questions on test execution, reporting and sustainability. The tender submission deadline is 13 November 2026 at 10:00. The bid must be submitted electronically and include the required qualification evidence, reference declarations, signed forms, quality responses, a sample report and the price sheet in both spreadsheet and signed PDF format.
More tender information after sign-in
The public view shows key tender details. Sign in to open official links, documents and AI tender support.