TenderMetric Intelligence Team · Last Reviewed: May 2026 · Sources: TED Europa · EU Publications Office
◆ EU Procurement Intelligence — Key Facts
  • The EU public procurement market is worth €2 trillion+ annually — approximately 14% of EU GDP
  • TED Europa publishes 700,000+ contract notices per year across all 27 EU member states
  • EU procurement thresholds in 2026: €143,000 (supplies/services, central) · €5.538M (works)
  • Open procedures account for ~67% of all above-threshold EU contracts — the most accessible route for new bidders
  • All above-threshold contracts must be published in the Official Journal of the EU (OJEU) under Directive 2014/24/EU
Back to Insights
Sector Guide Last Reviewed: April 2026 TM-INS-075 // MARCH 2026

Cybersecurity Training Tenders EU: Awareness and Education Contracts

Summary

Cybersecurity training and awareness has become one of the highest-volume, lowest-barrier-to-entry segments in EU public procurement cybersecurity. NIS2 Article 20 explicitly mandates that management bodies of covered entities receive cybersecurity training and that organisations ensure their staff have adequate security awareness. This legal obligation is generating hundreds of training contracts annually across EU public bodies, from e-learning platform licences at €15,000 per year for small municipalities to multi-year managed awareness programmes at €500,000+ for national government departments.

Why Cybersecurity Training Is Now a Mandatory Procurement

NIS2 Article 20 (Governance) is the most directly procurement-driving provision of the directive. It requires that management bodies of essential and important entities — which includes the boards and senior leadership of public administration bodies — approve cybersecurity risk management measures, oversee their implementation, and receive training to identify and assess cybersecurity risks and management practices. This provision does not apply only to IT departments: it applies to the chief executive, the board, the minister — whoever constitutes the management body of a covered entity.

This is not a soft recommendation. Under NIS2, management bodies can be held personally liable for cybersecurity failures, with maximum fines of €10 million or 2% of global turnover for essential entities. That personal liability creates a powerful incentive for senior officials to ensure training is procured, documented, and completed — and that it is credible enough to demonstrate due diligence to a national regulator during an audit.

Beyond leadership, Article 21(2)(g) requires covered entities to implement "basic cyber hygiene practices and cybersecurity training" for all staff. For public authorities with hundreds or thousands of employees, this cannot be delivered through informal internal sessions — it requires a contracted training provider with a scalable platform and documented completion tracking. The combination of the Article 20 board-level mandate and Article 21 all-staff requirement means most covered entities need two separate procurement vehicles: an executive programme and a mass-participation awareness platform.

Named buyers active in this space include EU-OSHA (Bilbao) for health and safety awareness training that increasingly incorporates cybersecurity modules, ENISA (Athens/Heraklion) for technical training development and certification of training content, and NATO CCDCOE (Tallinn) for advanced technical exercises used by national defence and cybersecurity agencies. National CERTs — including BSI (Germany), ANSSI (France), NCSC-NL (Netherlands), and CERT-PL (Poland) — regularly procure national awareness campaign delivery and exercise facilitation services.

Types of Training Procured by Government — with Contract Value Ranges

The training market for public sector cybersecurity breaks into five distinct procurement types, each with its own CPV code pattern, qualification bar, and typical value range. Understanding which type you are competing for matters — the evaluation criteria, qualification thresholds, and likely competitors differ substantially:

  • E-learning platform licences: Annual licences for platforms (KnowBe4, Proofpoint Security Awareness, Mimecast, and EU-hosted alternatives with GDPR-compliant data residency) delivering modular online training to all staff with completion tracking. Typical contract value: €15,000–€150,000 per year depending on headcount. Tendered under CPV 80533100-0 or 48731000-7.
  • Phishing simulation and awareness campaigns: Often bundled with the platform — simulated phishing campaigns with click-rate reporting, targeted remedial training for staff who fail, and a measurable susceptibility trend line for regulators. Typical value: €20,000–€80,000. The measurable KPI element is what makes this attractive to procurement evaluators.
  • Tabletop and crisis simulation exercises: Facilitated scenarios where leadership teams and incident response personnel walk through a simulated cyberattack — ransomware, data breach, or DDoS — testing decision-making, communication, and response procedures. Typical value: €10,000–€50,000 per exercise. NATO CCDCOE runs the most advanced version of these for national agencies; private providers compete on national and regional authority contracts.
  • CISO and board-level development programmes: Specialist programmes covering cyber risk quantification, NIS2 personal liability, and crisis communication — often delivered as half-day or full-day workshops by senior consultants with hands-on sector experience. Typical value: €50,000–€200,000 for a multi-session programme.
  • Technical skills training: Hands-on training for IT and security teams — ethical hacking, secure coding, cloud security, incident response. Often certified programmes (CISSP, CISM, CEH, CompTIA Security+) with per-seat costs at €2,000–€5,000. Typical contract value: €30,000–€150,000. Accreditation through bodies like CompTIA, ISACA, (ISC)², EC-Council, or CREST membership for technical penetration testing training is usually a mandatory qualification requirement.
  • Role-specific awareness modules: Targeted content for high-risk roles — HR staff handling personal data, finance staff exposed to payment fraud, procurement officers managing supply chain risks. Usually procured as an add-on to an existing awareness platform contract or as a standalone call-off under a framework.

Key CPV Codes

  • 80533100 — Computer training services (primary code for cybersecurity awareness and technical training)
  • 80000000 — Education and training services (broad code sometimes used)
  • 80510000 — Specialist training services
  • 80531000 — Technical and vocational training services
  • 48731000 — Security management software package (for phishing simulation platforms)
  • 72222300 — Information technology services (sometimes used for e-learning platform provision)

Training contracts are among the easiest to find via keyword search: "security awareness", "cybersecurity training", "phishing simulation", "sensibilisation cybersécurité", "Cybersicherheitsschulung" across European procurement portals.

Framework Agreements: The Primary Route to Repeat Business

Security awareness training frequently appears in framework agreements run by central purchasing bodies, allowing individual public bodies to call off training services without running a full tender. Most large public bodies — national ministries, major agencies, NHS bodies in the UK, federal entities in Germany — run 4-year training frameworks with multiple providers per lot. This multi-supplier structure is standard precisely because training needs vary by audience and no single provider dominates. For suppliers, getting onto a national framework is a high-value investment — once listed, individual call-off contracts are issued without competitive tender, often with minimal formality for contracts below national simplified threshold values.

Pan-government IT services frameworks (which typically include a training lot alongside software and support) are the most common vehicle. Dedicated e-learning or digital skills frameworks are less common but growing. Suppliers should treat framework bids as a primary market entry strategy rather than pursuing individual tenders in isolation — a single framework position can generate multiple years of call-off revenue without re-tendering.

Language requirements are a material qualification factor at the call-off stage. Most member states specify that training delivery must be in the national language — even if the underlying content platform is English, the facilitation, customisation, localised phishing simulation templates, and support must be in the local language. Suppliers without in-country delivery capability either need a local partner or must limit themselves to countries where English-medium delivery is accepted (primarily the Nordic countries, Netherlands, and Ireland for EU institutions).

Qualification Requirements and How to Win

Training contract qualification requirements are lighter than technical cybersecurity service contracts, making this segment genuinely accessible to smaller and specialist providers. The standard qualification bar across European public procurement includes:

  • Demonstrated experience delivering cybersecurity training to public sector organisations — typically references from 2–3 comparable clients within the last 3 years, specifying audience size and contract value
  • Accreditation through recognised bodies: CompTIA, ISACA, (ISC)², EC-Council partnerships for awareness and certification programmes; CREST membership for technical penetration testing training; ISO 29993 (Learning services outside formal education) certification is increasingly requested as a general quality indicator for training organisations
  • GDPR-compliant platform with EU data residency — user completion data, phishing test results, and assessment scores for EU public authority employees cannot be processed outside EU jurisdiction. This is a disqualifying criterion for non-EU cloud platforms that cannot demonstrate an EU data residency option.
  • Evidence of training effectiveness — completion rates, pre/post knowledge assessment scores, phishing susceptibility improvement statistics. Evaluators increasingly request outcome metrics rather than input descriptions.
  • Customisation capability — the ability to adapt scenario content, branding, and simulated phishing templates to the authority's specific sector, systems, and threat environment

The differentiation in evaluation comes down to outcomes evidence. Evaluators at public bodies — who are increasingly familiar with security awareness as a regulated obligation — score bids that demonstrate measurable behaviour change substantially higher than bids describing content features. A provider that can show, with anonymised case study data, that a comparable public sector client reduced phishing click rates from 24% to 7% over 18 months is proposing a measurably different service from one that lists module topics.

End of Briefing // TenderMetric Intelligence Systems — TM-INS-075

◆ Primary Sources & Further Reading

◆ Live EU Tenders — From TED Europa

View all →
SoftwareRomania

Romania – Training software package – SISTEM DE ANTRENAMENT ÎN REALITATEA VIRTUALĂ ( 4 BUC…

Deadline: 05/25/2026

€1,098,259

EducationIreland

Ireland – Training programme services – 31 - Provision of Course Design Services

Deadline: 05/22/2026

Business ServicesCHE

Switzerland – Security services – Mandat de Prestations Sûreté et Accueil

Deadline: 06/08/2026

Business ServicesSweden

Sweden – Business services: law, marketing, consulting, recruitment, printing and security…

Deadline: 05/25/2026

TM
TenderMetric Editorial Verified Publisher
EU Procurement Research & Intelligence · Est. 2025

This article was researched and written by the TenderMetric editorial team using primary sources: TED (Tenders Electronic Daily) XML feeds, official EU procurement directives (2014/24/EU, 2014/25/EU), OJEU contract notices, national procurement authority guidelines, and EU Publications Office data. Contract values and award data are sourced from official contract award notices — not estimated.

📅 Last reviewed: 2026-03-28 🔄 Tender data updated daily from TED Europa
◆ Editorial Review Panel
EU Procurement Research Analyst
TED Europa · OJEU notices · CPV classification
Public Law Editor
EU Directives 2014/24 & 2014/25 · national transposition
Procurement Compliance Reviewer
Threshold verification · award data · deadline accuracy
Publisher
TenderMetric
Independent EU Procurement Intelligence
Aggregates 700,000+ EU public procurement notices per year. Coverage spans all 27 EU member states, all procurement procedures, and all CPV divisions — sourced directly from TED and the EU Publications Office.
Research Methodology
Articles are researched from official EU procurement sources: TED XML feeds, EU procurement directives, OJEU contract notices, and national procurement authority guidelines. Award data is sourced from official contract award notices — not estimated.
Primary Data Sources
Accuracy & Updates
Tender deadlines, contract values, and buyer details change frequently. TenderMetric syncs with TED daily. Editorial articles are reviewed quarterly or when EU procurement legislation changes. Always verify tender status directly on TED Europa before submitting a bid.
◆ Live EU Tender Intelligence
Browse Live EU Public Tenders
Updated daily from TED Europa · All 27 EU member states · All CPV sectors
Search Live Tenders →
About TenderMetric → Research Methodology → Legal Disclaimer → LinkedIn →

Editorial Notice: This article was reviewed by the TenderMetric editorial team. EU procurement law and thresholds are revised periodically. For legally binding procurement information, always refer to the official notice on ted.europa.eu. To report an inaccuracy, contact dev@tendermetric.com.

Related Insights

Sector Guide
Cybersecurity Audit Tenders EU: Government Security Assessment Contracts
Read →
Sector Guide
EU Cybersecurity Tenders 2026: How to Win Government Security Contracts
Read →
Market Intelligence
EU Cybersecurity Tenders 2026: NIS2, ENISA, and Digital Security Procurement
Read →
Sector Guide
Cloud Security Tenders EU: Government Cloud Procurement Requirements 2026
Read →
TenderMetric Intelligence Team
EU Procurement Research & Analysis · Last updated May 2026
Analysis compiled from TED Europa (Official Journal of the EU), European Commission procurement data, and CPV code classifications. TenderMetric tracks 10,000+ active EU procurement notices across all 27 member states, updated daily from the TED open data feed.
Get Weekly EU Tender Alerts
New tenders from TED Europa across all 27 EU member states — every Monday. Free forever.
◆ EU Procurement Intelligence at a Glance
10K+
Active tenders tracked
27
EU member states
€2T+
Annual market value
Daily
Data refresh from TED
◆ EU Contract Value Distribution (above-threshold)
Works contracts (construction, infrastructure) ~52%
Services contracts (IT, consulting, healthcare) ~35%
Supplies contracts (equipment, goods) ~13%
SME award rate (% of contracts to SMEs) ~45%
Source: European Commission Public Procurement Statistics — approximate figures based on TED Europa data.
◆ EU Procurement Lifecycle (Open Procedure)
Day 1
Contract Notice Published (TED)
Day 1–35
Tender Preparation & Submission
Day 35–70
Evaluation & Clarifications
Day 70–85
Standstill Period (10 days)
Day 85
Contract Award Decision
Day 90+
Contract Signature & Start
Timeline is indicative. Open procedure minimum: 35 days from publication to submission deadline (Directive 2014/24/EU).
About the Author
TenderMetric Research Team
EU Procurement Intelligence Specialists · tendermetric.com
Our analysts monitor 10,000+ EU procurement notices daily across construction, IT, healthcare, defense, and energy sectors. All data sourced from TED Europa and the EU Publications Office.
📋 10K+ tenders tracked 🇪🇺 27 member states 🔄 Updated: May 2026
◆ Common Questions About EU Procurement
What is TED Europa and where do EU tenders come from? +
TED (Tenders Electronic Daily) is the online version of the Supplement to the Official Journal of the EU, published by the EU Publications Office. It publishes procurement notices above EU thresholds from all 27 member states, EU institutions, and affiliated bodies — approximately 700,000+ notices per year. TenderMetric aggregates and enriches this data daily.
What are the EU procurement thresholds in 2026? +
For 2026–2027, the EU procurement thresholds are: €143,000 for supplies and services by central government authorities; €221,000 for supplies and services by sub-central authorities; €5,538,000 for works contracts. Utilities and defence sectors have separate thresholds. Contracts above these values must be published on TED.
Can non-EU companies bid on EU public tenders? +
Third-country participation depends on international agreements. Countries covered by the WTO Government Procurement Agreement (GPA) — including the US, UK, Canada, Japan, and others — generally have access to EU tenders above GPA thresholds. Countries without GPA coverage may be excluded from specific lots. Always check the contract notice for nationality restrictions.
What is an ESPD and is it required? +
The European Single Procurement Document (ESPD) is a self-declaration form used across the EU as preliminary evidence of a bidder's suitability. It replaces multiple national certificates at the tender stage — you only need to submit the actual certificates if you win. The ESPD is mandatory for all above-threshold EU procurements and can be completed via the eESPD online service.
How can SMEs compete for EU public contracts? +
SMEs win approximately 45% of EU public contracts by value. Key strategies: focus on lots (contracting authorities must divide large contracts into lots where feasible); form consortia with complementary firms; target sub-central authorities (municipalities, regions) where competition is lower; use framework agreements as a stepping stone to larger contracts. The ESPD simplifies the qualification process specifically to reduce SME burden.
TenderMetric — Independent EU procurement intelligence platform. Not affiliated with the EU Publications Office, the European Commission, or TED (Tenders Electronic Daily). Tender data is sourced from TED for informational purposes only; always verify procurement notices directly at ted.europa.eu before submitting a bid. Full Disclaimer  ·  Last Reviewed: April 2026  ·  Data Methodology