Tender detail

Security Testing Tender

Summary

The Estonian Information Technology Centre of the Ministry of the Environment is seeking framework-agreement partners to test the security of its e-services, information systems and network infrastructure and provide related support. The services include penetration testing of applications, APIs and infrastructure; cloud-security and source-code assessments; attack simulations, including phishing and Red Teaming; test-environment development; and expert support.

Reference number
312907-0000
Buyer
Keskkonnaministeeriumi Infotehnoloogiakeskus
Country
Estonia (EST)
Procedure
Open procedure
CPV
72254100 Systems testing services
Deadline
2026-12-04
Status
Open
Contract subject
Services
Estimated value
1 000 000,00 EUR
Source
RHR

Participation requirements

Tender requirements are available in the official tender documents.

Compliance requirements

A bidder must be excluded if the bidder or a person with management or representative authority has been convicted of participation in a criminal organisation, corruption, fraud, terrorism-related offences, money laundering or terrorist financing, illegal use of child labour or human trafficking; has outstanding taxes, contributions or environmental charges; or if awarding the contract would breach sanctions. Exclusion is also mandatory where the bidder or a responsible person has been penalised for enabling an unlawfully present foreign national to work or for a tax offence. Certain conviction grounds apply until the criminal-record information is deleted, but for no more than five years from the final judgment. The contracting authority may also exclude a bidder for local tax debt; breaches of environmental, social or labour obligations; bankruptcy or insolvency; serious professional misconduct; agreements distorting competition; an unavoidable conflict of interest; an unjustified advantage arising from involvement in preparing the procurement; significant or repeated breach of a previous contract; false statements or failure to provide required information or documents; or attempts to influence the authority or obtain confidential information. In general, these discretionary grounds apply where the procurement began within three years of the act or the ground arising. If a tax debt is identified, the authority must allow at least three working days to pay or reschedule it; the bidder will not be excluded if the debt is paid or rescheduled by the deadline. A tax-debt certificate is not issued where the debt is below EUR 100 or payment has been rescheduled. The authority checks exclusion grounds for each joint bidder and each entity relied upon to meet qualification requirements and may require replacement of an affected entity. An ESPD must be submitted for the bidder, each joint bidder and each relied-upon entity. Before signing the framework agreement, successful bidders may be required to provide documents supporting their ESPD declarations, with at least five working days allowed for submission. Where permitted, a bidder may provide evidence of measures taken to restore its reliability.

Qualification criteria and exclusion grounds

The bidder’s aggregate net turnover for the three financial years completed by the start of the last three procurement procedures must be at least EUR 1,000,000. For a bidder established or commencing business more recently, turnover is assessed for its period of activity. Turnover information must be provided in the ESPD; the contracting authority may request extracts from annual accounts if they are not freely available. A bidder may rely on another entity’s resources but must submit an ESPD for that entity and evidence that the resources will be available and that the entity will be jointly and severally liable for the relevant part of the contract. The bidder must hold a valid ISO/IEC 27001 information-security management system certificate or provide an independent audit result demonstrating compliance with E-ITS requirements, with a scope covering the services being procured. Equivalent evidence is accepted. The ESPD must identify the certificate or audit issuer, number, validity period and scope. For the framework agreement, the bidder must continuously provide at least one project manager and at least three security testers or experts. Each role must be performed by a different person. The project manager must have at least 2 years of IT project-management experience and a valid CISSP, CISM or CISA certificate, or a certificate accepted by the contracting authority as equivalent. Each security tester must have at least 3 years of proven practical penetration-testing experience and at least one of the following certificates, or an equivalent: OSCP, OSWE, OSCE, OSEE, CPTS, GWAPT, CWAPT, CEPT, CMWAPT, CRTO, CRTE or OSEP. Submit CVs using the tender-document template, signed by each individual, together with certificate copies or links for verifying validity. The bid must remain valid for at least 90 days and confirm that the bidder holds the intellectual property rights necessary to perform the framework agreement and orders. It must state hourly prices in euros excluding VAT for security and penetration-testing services, test-environment construction and consultancy, and include the table and information required by the tender documents for award criterion 3. Conditional bids are not permitted. Any proposed equivalent must be explained in the bid and supported with evidence. If the bid is signed by someone other than the bidder’s statutory representative, a power of attorney must be provided. Joint bidders must submit a power of attorney appointing their representative and specify the size and nature of each member’s share of the contract; they are jointly and severally liable for performance. The bidder, subcontractors and suppliers involved in performance, and entities whose capacity is relied upon must not be among the persons covered by the Russian sanctions specified in the tender documents. Such subcontractors and suppliers may not account for more than 10% of the contract value; the confirmation must also cover performance of the framework agreement and resulting contracts. Participation is limited to bidders established in Estonia, another EU or EEA country, or a country party to the WTO Agreement on Government Procurement.