β—† TenderMetric Intelligence Team Β· Last Reviewed: May 2026 Β· Sources: TED Europa Β· EU Publications Office
β—† EU Procurement Intelligence β€” Key Facts
  • βœ“ The EU public procurement market is worth €2 trillion+ annually β€” approximately 14% of EU GDP
  • βœ“ TED Europa publishes 700,000+ contract notices per year across all 27 EU member states
  • βœ“ EU procurement thresholds in 2026: €143,000 (supplies/services, central) Β· €5.538M (works)
  • βœ“ Open procedures account for ~67% of all above-threshold EU contracts β€” the most accessible route for new bidders
  • βœ“ All above-threshold contracts must be published in the Official Journal of the EU (OJEU) under Directive 2014/24/EU
← Back to Insights
Reference Last Reviewed: April 2026 TM-INS-081 // MARCH 2026

Cybersecurity CPV Codes: Complete Reference for EU Procurement 2026

Summary

Common Procurement Vocabulary (CPV) codes are the EU's standardised classification system for public procurement, used across all 27 member states and by EU institutions on TED (Tenders Electronic Daily). For cybersecurity vendors, understanding the full CPV landscape is essential for monitoring opportunities systematically β€” a single missed code family can mean overlooking hundreds of relevant contracts per year. This reference guide provides a complete catalogue of CPV codes relevant to cybersecurity procurement, explains how the CPV system works, covers how to configure TED alerts, and identifies the highest-volume codes and emerging codes to watch in 2026.

How CPV Codes Work β€” and Why They Fall Short for Cybersecurity

CPV codes are 8-digit numerical codes with a check digit, organised into a hierarchical taxonomy. The structure is: Division (first 2 digits) β†’ Group (first 3 digits) β†’ Class (first 4 digits) β†’ Category (first 5 digits) β†’ Sub-category (all 8 digits). For example, the code 72212730 breaks down as: 72 (IT services division) β†’ 722 (software programming group) β†’ 7221 (application software programming class) β†’ 72212 (programming services category) β†’ 72212730 (security software development).

The CPV system was designed in 2003 and last significantly revised in 2008. Both dates predate the modern cybersecurity category as a distinct discipline β€” concepts like SIEM, EDR, zero trust, and cloud security have no dedicated CPV divisions. The word "cybersecurity" does not appear anywhere in the CPV taxonomy's top-level divisions, which is why cybersecurity contracts scatter across IT services (Division 72), security equipment (Division 35), audit services (Division 79), and training (Division 80) depending entirely on how the contracting authority chose to frame their requirement.

This fragmentation creates a systematic monitoring problem. A contracting authority procuring a next-generation firewall might use 48730000-4 (security software package), 32420000-3 (network equipment), or 51000000-9 (installation services) β€” depending on whether the emphasis is the software licence, the physical appliance, or the deployment work. All three are legitimate classifications for essentially the same purchase. Unless you monitor all three code families, you will miss a portion of the market. The practical answer is to combine CPV code alerts with keyword alerts ("NIS2", "ISO 27001", "penetration test", "SIEM", "SOC") because contracting authorities are deeply inconsistent in their coding choices.

Country variation makes this worse. German contracting authorities tend to use CPV codes with greater precision β€” BAAINBw and similar agencies have standardised internal coding guidance. Italian authorities frequently apply broad parent codes and leave specificity to the contract title. French contracting authorities on the PLACE platform allow CPV filtering but keyword searching in French is often necessary to catch notices where the CPV is a generic IT code. Monitoring a single national market requires understanding that country's coding culture.

Security Software CPV Codes

  • 48730000-4 β€” Security software package (top-level code; one of the highest-volume cybersecurity codes on TED)
  • 48731000-7 β€” Security management software package
  • 48732000-0 β€” Data security software package
  • 48761000-0 β€” Anti-virus software package
  • 48900000-7 β€” Miscellaneous software packages and computer systems
  • 72212730-5 β€” Security software development services (rising sharply with NIS2-driven custom development mandates)
  • 72212900-8 β€” Cybersecurity software development (explicitly named; use alongside 72212730)
  • 72212517-6 β€” IT software development services (security applications)

Security Services CPV Codes β€” and How They Are Actually Used

The services codes require the most attention because they carry the highest misclassification rate. The most-searched cybersecurity service codes on TED by volume are 72220000-3, 48730000-4, 79212000-3, and 72212900-8 β€” but the specific use cases within each vary widely:

  • 72220000-3 β€” Systems and technical consultancy services. The single most-used code for security architecture, NIS2 compliance consulting, and penetration testing β€” contracting authorities treat this as a catch-all for "expert cybersecurity advice". High volume, highly competitive.
  • 72222300-0 β€” Information technology services (broad security services; frequently used when the authority cannot identify a more specific code)
  • 72700000-7 β€” Computer network services (network security monitoring, SOC-as-a-service, managed detection and response)
  • 72315000-6 β€” Data network management and support services (network security management, firewall administration)
  • 72250000-2 β€” System and support services (managed security services, MSSP contracts)
  • 72300000-8 β€” Data services (data security, data classification, DLP)
  • 72600000-6 β€” Computer support and consultancy services (security helpdesk, incident response retainers)

Audit and Compliance CPV Codes

Security audits and compliance assessments are one of the fastest-growing segments following NIS2 transposition. The key code is 79212000-3 β€” auditing services β€” which covers ISO 27001 gap assessments, NIS2 compliance audits, and penetration testing reports commissioned as audit deliverables. It is one of the top-five most-searched cybersecurity codes on TED because it is consistently used by public administrations buying external audit services regardless of whether the subject is financial, IT, or specifically cybersecurity.

  • 79212000-3 β€” Auditing services (security audits, ISO 27001 assessments, NIS2 compliance audits; high volume on TED)
  • 79212100-4 β€” Internal audit services
  • 79212300-6 β€” Statutory audit services
  • 79131000-1 β€” Documentation services (data mapping, Records of Processing Activities, policy documentation)
  • 79100000-5 β€” Legal services (data protection legal advice, DPO-as-a-service)
  • 73000000-2 β€” Research and development services. A "watch code": ENISA and national cybersecurity agencies use this for research and threat intelligence study procurement. Not a primary security code but increasingly active.

Hardware and Infrastructure CPV Codes β€” and Their Misclassification Patterns

Hardware codes are where misclassification is most costly for vendors to miss. A next-generation firewall procurement may appear under 32420000-3 (the hardware), 48730000-4 (the software licence), or 51000000-9 (the installation services) β€” or all three as separate line items in a single contract. Security monitoring hardware presents the same problem: 35120000-1 (surveillance systems) is a "watch code" because authorities frequently use it for physical-digital hybrid security deployments β€” access control systems, security operations centre hardware, and perimeter monitoring equipment that also generates logs ingested by a SIEM.

  • 35120000-1 β€” Surveillance and security systems and devices. Watch code: used for security monitoring hardware, perimeter systems, and access control appliances with cyber components.
  • 32420000-3 β€” Network equipment (firewalls as hardware appliances; one of three possible codes for firewall procurement)
  • 32422000-7 β€” Network components
  • 35125300-2 β€” Security cameras (CCTV β€” physical security sometimes paired with cyber monitoring)
  • 30200000-1 β€” Computer equipment and supplies (secure computing hardware, HSMs)
  • 51000000-9 β€” Installation services. Often overlooked by cybersecurity vendors, but firewall and network security appliance deployments frequently appear here β€” always include it in hardware-focused monitoring.

Training and Education CPV Codes

80533100-0 is the primary watch code for the training segment and is growing significantly. NIS2 Article 20's explicit mandate for management-body training has pushed this code into much higher volume than it carried before 2023. Training contracts for awareness campaigns, phishing simulation platforms, and board-level programmes all flow through this code. Also note 80570000-0 (personal development training) β€” used specifically for CISO and executive-level security leadership programmes, which carry higher per-delegate values.

  • 80533100-0 β€” Computer training services (cybersecurity awareness, technical security training; rising strongly since NIS2 transposition)
  • 80000000-4 β€” Education and training services (broad parent code; some authorities use this instead of subcodes)
  • 80510000-2 β€” Specialist training services (advanced security qualifications β€” CISSP, CISM, CEH programmes)
  • 80531000-8 β€” Technical and vocational training services (hands-on technical skills: ethical hacking, incident response)
  • 80570000-0 β€” Personal development training services. Watch code: used for CISO and executive security leadership development β€” higher value per contract than awareness training.

Setting Up TED Alerts: CPV Codes Are Not Enough

TED's alert system (ted.europa.eu) allows you to save searches and receive email notifications when matching notices are published. For cybersecurity specifically, CPV-only alerts will underperform β€” the taxonomy fragmentation described above means that keyword alerts are equally important. The effective strategy combines both layers:

  • Create an account on TED and access the "My TED" section. Use Expert Search to combine multiple CPV codes with OR operators.
  • Set up a parallel keyword alert for terms that appear in contract titles and descriptions regardless of CPV code: "NIS2", "ISO 27001", "penetration test", "penetration testing", "SIEM", "SOC", "security operations", "cyber awareness", "zero trust". These catch notices where the authority used a generic IT code.
  • Filter by country if focused on specific member states, and supplement TED with national portals β€” BOAMP in France, Vergabe.de in Germany, TenderNed in Netherlands β€” which carry pre-threshold contracts (below €140,000 for services) that never appear on TED.
  • Set notification frequency to daily; cybersecurity tenders have short response windows, often 3–4 weeks from publication to deadline.

A recommended starting CPV alert set for cybersecurity β€” covering software, services, audit, training, and hardware across all major code families: 48730000, 48761000, 72220000, 72222300, 72700000, 79212000, 80533100, 80570000, 35120000, 32420000, 73000000. Run this alongside keyword alerts for the terms above and you will capture the substantial portion of the market that CPV codes alone miss.

Most Active Codes by Volume and Codes to Watch in 2026

Highest volume cybersecurity codes in 2025 (by number of TED notices)

The top-five most-searched cybersecurity codes on TED by notice volume are: 72220000-3 (IT systems consultancy β€” the dominant code for security architecture and NIS2 consulting), 48730000-4 (security software), 79212000-3 (audit services β€” used heavily for security audits), 72212900-8 (cybersecurity software development), and 72222300-0 (broad IT services). These five codes collectively account for the majority of identifiable security contract activity on TED.

Codes to watch in 2026

72212730-5 and 72212900-8 are both rising as NIS2 pushes public bodies to commission custom security tooling rather than buying off-the-shelf. 80533100-0 is growing fast β€” NIS2 Article 20's management-body training mandate is generating a wave of awareness training contracts that did not exist at scale before 2023. 73000000-2 (R&D services) is worth tracking specifically for ENISA-funded research and national CERT procurement of threat intelligence capability. The hardware codes 35120000-1 and 32420000-3 are trending upward as government network security refresh cycles accelerate β€” particularly in Central and Eastern European member states increasing defence and resilience spending under NATO commitments.

TenderMetric's alert service monitors all relevant CPV codes and keywords simultaneously across TED and national portals, so a firewall tender misclassified under 51000000-9 (installation services) receives the same alert as one correctly filed under 48730000-4.

End of Briefing // TenderMetric Intelligence Systems β€” TM-INS-081

β—† Primary Sources & Further Reading

β—† Live EU Tenders β€” From TED Europa

View all β†’
Business ServicesCHE

Switzerland – Security services – Mandat de Prestations SΓ»retΓ© et Accueil

Deadline: 06/08/2026

Business ServicesSweden

Sweden – Business services: law, marketing, consulting, recruitment, printing and security…

Deadline: 05/25/2026

Business ServicesNOR

Norway – Business services: law, marketing, consulting, recruitment, printing and security…

Deadline: 05/26/2026

Business ServicesSweden

Sweden – Business services: law, marketing, consulting, recruitment, printing and security…

Deadline: 05/25/2026

€6,000,000

TM
TenderMetric Editorial Verified Publisher
EU Procurement Research & Intelligence Β· Est. 2025

This article was researched and written by the TenderMetric editorial team using primary sources: TED (Tenders Electronic Daily) XML feeds, official EU procurement directives (2014/24/EU, 2014/25/EU), OJEU contract notices, national procurement authority guidelines, and EU Publications Office data. Contract values and award data are sourced from official contract award notices β€” not estimated.

πŸ“… Last reviewed: 2026-03-28 πŸ”„ Tender data updated daily from TED Europa
β—† Editorial Review Panel
EU Procurement Research Analyst
TED Europa Β· OJEU notices Β· CPV classification
Public Law Editor
EU Directives 2014/24 & 2014/25 Β· national transposition
Procurement Compliance Reviewer
Threshold verification Β· award data Β· deadline accuracy
Publisher
TenderMetric
Independent EU Procurement Intelligence
Aggregates 700,000+ EU public procurement notices per year. Coverage spans all 27 EU member states, all procurement procedures, and all CPV divisions β€” sourced directly from TED and the EU Publications Office.
Research Methodology
Articles are researched from official EU procurement sources: TED XML feeds, EU procurement directives, OJEU contract notices, and national procurement authority guidelines. Award data is sourced from official contract award notices β€” not estimated.
Primary Data Sources
Accuracy & Updates
Tender deadlines, contract values, and buyer details change frequently. TenderMetric syncs with TED daily. Editorial articles are reviewed quarterly or when EU procurement legislation changes. Always verify tender status directly on TED Europa before submitting a bid.
β—† Live EU Tender Intelligence
Browse Live EU Public Tenders
Updated daily from TED Europa Β· All 27 EU member states Β· All CPV sectors
Search Live Tenders β†’
About TenderMetric β†’ Research Methodology β†’ Legal Disclaimer β†’ LinkedIn β†’

Editorial Notice: This article was reviewed by the TenderMetric editorial team. EU procurement law and thresholds are revised periodically. For legally binding procurement information, always refer to the official notice on ted.europa.eu. To report an inaccuracy, contact dev@tendermetric.com.

Related Insights

Beginner Guide
CPV Codes Explained 2026: What They Are, Complete List and How to Find Yours
Read β†’
Reference
CPV Codes List 2026: All 45 EU Procurement Divisions with Descriptions and Examples
Read β†’
Sector Guide
Cybersecurity Audit Tenders EU: Government Security Assessment Contracts
Read β†’
Sector Guide
EU Cybersecurity Tenders 2026: How to Win Government Security Contracts
Read β†’
β—†
TenderMetric Intelligence Team
EU Procurement Research & Analysis Β· Last updated May 2026
Analysis compiled from TED Europa (Official Journal of the EU), European Commission procurement data, and CPV code classifications. TenderMetric tracks 10,000+ active EU procurement notices across all 27 member states, updated daily from the TED open data feed.
Get Weekly EU Tender Alerts
New tenders from TED Europa across all 27 EU member states β€” every Monday. Free forever.
β—† EU Procurement Intelligence at a Glance
10K+
Active tenders tracked
27
EU member states
€2T+
Annual market value
Daily
Data refresh from TED
β—† EU Contract Value Distribution (above-threshold)
Works contracts (construction, infrastructure) ~52%
Services contracts (IT, consulting, healthcare) ~35%
Supplies contracts (equipment, goods) ~13%
SME award rate (% of contracts to SMEs) ~45%
Source: European Commission Public Procurement Statistics β€” approximate figures based on TED Europa data.
β—† EU Procurement Lifecycle (Open Procedure)
Day 1
Contract Notice Published (TED)
Day 1–35
Tender Preparation & Submission
Day 35–70
Evaluation & Clarifications
Day 70–85
Standstill Period (10 days)
Day 85
Contract Award Decision
Day 90+
Contract Signature & Start
Timeline is indicative. Open procedure minimum: 35 days from publication to submission deadline (Directive 2014/24/EU).
β—†
About the Author
TenderMetric Research Team
EU Procurement Intelligence Specialists Β· tendermetric.com
Our analysts monitor 10,000+ EU procurement notices daily across construction, IT, healthcare, defense, and energy sectors. All data sourced from TED Europa and the EU Publications Office.
πŸ“‹ 10K+ tenders tracked πŸ‡ͺπŸ‡Ί 27 member states πŸ”„ Updated: May 2026
β—† Common Questions About EU Procurement
What is TED Europa and where do EU tenders come from? +
TED (Tenders Electronic Daily) is the online version of the Supplement to the Official Journal of the EU, published by the EU Publications Office. It publishes procurement notices above EU thresholds from all 27 member states, EU institutions, and affiliated bodies β€” approximately 700,000+ notices per year. TenderMetric aggregates and enriches this data daily.
What are the EU procurement thresholds in 2026? +
For 2026–2027, the EU procurement thresholds are: €143,000 for supplies and services by central government authorities; €221,000 for supplies and services by sub-central authorities; €5,538,000 for works contracts. Utilities and defence sectors have separate thresholds. Contracts above these values must be published on TED.
Can non-EU companies bid on EU public tenders? +
Third-country participation depends on international agreements. Countries covered by the WTO Government Procurement Agreement (GPA) β€” including the US, UK, Canada, Japan, and others β€” generally have access to EU tenders above GPA thresholds. Countries without GPA coverage may be excluded from specific lots. Always check the contract notice for nationality restrictions.
What is an ESPD and is it required? +
The European Single Procurement Document (ESPD) is a self-declaration form used across the EU as preliminary evidence of a bidder's suitability. It replaces multiple national certificates at the tender stage β€” you only need to submit the actual certificates if you win. The ESPD is mandatory for all above-threshold EU procurements and can be completed via the eESPD online service.
How can SMEs compete for EU public contracts? +
SMEs win approximately 45% of EU public contracts by value. Key strategies: focus on lots (contracting authorities must divide large contracts into lots where feasible); form consortia with complementary firms; target sub-central authorities (municipalities, regions) where competition is lower; use framework agreements as a stepping stone to larger contracts. The ESPD simplifies the qualification process specifically to reduce SME burden.
TenderMetric β€” Independent EU procurement intelligence platform. Not affiliated with the EU Publications Office, the European Commission, or TED (Tenders Electronic Daily). Tender data is sourced from TED for informational purposes only; always verify procurement notices directly at ted.europa.eu before submitting a bid. Full Disclaimer  Β·  Last Reviewed: April 2026  Β·  Data Methodology