β—† TenderMetric Intelligence Team Β· Last Reviewed: April 2026 Β· Sources: TED Europa Β· EU Publications Office Β· European Commission
β—† EU Procurement Intelligence β€” Key Facts
  • βœ“ The EU public procurement market is worth €2 trillion+ annually β€” approximately 14% of EU GDP
  • βœ“ TED Europa publishes 700,000+ contract notices per year across all 27 EU member states
  • βœ“ EU procurement thresholds in 2026: €143,000 (supplies/services, central) Β· €5.538M (works)
  • βœ“ Open procedures account for ~67% of all above-threshold EU contracts β€” the most accessible route for new bidders
  • βœ“ All above-threshold contracts must be published in the Official Journal of the EU (OJEU) under Directive 2014/24/EU
← Back to Insights
Sector Guide TM-INS-079 // MARCH 2026

Endpoint Security Tenders EU: EDR and Antivirus Procurement Guide

Summary

Endpoint security is one of the highest-volume procurement categories in EU government cybersecurity, encompassing antivirus and anti-malware software (the most frequently renewed contracts), Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) platforms, and Mobile Device Management (MDM) solutions. The transition from legacy antivirus to AI-powered EDR/XDR has created a major replacement cycle across EU public sector, with virtually every significant government IT estate actively evaluating or refreshing endpoint protection. This guide covers the platforms being procured, the key CPV codes, public tender requirements, EUCS alignment considerations, and the different contract structures vendors and resellers encounter.

The Endpoint Security Market in EU Government

Every government workstation, server, and mobile device requires endpoint protection β€” making this the most universal procurement category in cybersecurity. The market is transitioning from signature-based antivirus (legacy products from Kaspersky, Symantec/Broadcom, McAfee/Trellix) to AI-powered EDR and XDR platforms capable of detecting sophisticated, fileless, and zero-day threats.

Several factors are accelerating this transition in the public sector:

  • Kaspersky ban: Following the 2022 invasion of Ukraine, Germany's BSI and several other EU national cybersecurity agencies issued formal warnings against Kaspersky products. Multiple EU member states have actively replaced Kaspersky in government environments, creating a procurement wave for alternative endpoint protection.
  • NIS2 requirements: Article 21's requirement for malware protection, logging, and incident detection capabilities is pushing authorities to upgrade from basic antivirus to full EDR capability.
  • Microsoft Defender expansion: Many authorities already running Microsoft 365 are consolidating onto Microsoft Defender for Endpoint (included in E3/E5 licensing), creating displacement opportunities for incumbent AV vendors but also for MDR services built on Defender.
  • Ransomware pressure: Government ransomware attacks have created board-level urgency to modernise endpoint protection with genuine behavioural detection capabilities.

EDR/XDR Platform Landscape in EU Government

The leading EDR/XDR platforms in EU government procurement:

  • Microsoft Defender for Endpoint: Dominant in Microsoft-centric government environments. Procurement often flows through Microsoft enterprise agreements rather than standalone security contracts. MDR services and deployment support for Defender create third-party contract opportunities.
  • CrowdStrike Falcon: Leading independent EDR platform. Strong detection performance credentials. Data sovereignty questions around US-based telemetry are raised in some EU government tenders.
  • SentinelOne: Growing market share in European government, particularly in mid-tier public bodies. Autonomous AI-driven response capability is a key differentiator.
  • Trellix (formerly McAfee Enterprise/FireEye): Legacy installed base in government, undergoing active replacement in many environments.
  • Bitdefender: Romanian-origin product with strong EU data residency story. Growing in public sector procurement across CEE member states.
  • WithSecure (formerly F-Secure): Finnish-origin vendor with strong EU credentials and Nordic government market share.

Antivirus Framework Agreements

Traditional antivirus β€” still required for legacy systems, embedded devices, and environments where full EDR is not feasible β€” is frequently procured through national framework agreements. These frameworks allow individual public bodies to call off licences without competitive tender, typically at pre-negotiated per-seat pricing. For software vendors and their resellers, getting onto national AV/endpoint frameworks is a prerequisite for capturing the high-volume, lower-value renewal contracts that form the backbone of endpoint security revenue.

Key national frameworks to monitor for endpoint security lots: France's UGAP IT frameworks, Germany's TVΓΆD-aligned federal IT procurement vehicles, the Netherlands' ICTU frameworks, and UK's G-Cloud (relevant for vendors targeting British public sector).

Mobile Device Management Procurement

MDM and Unified Endpoint Management (UEM) procurement has grown substantially as government workforces have become increasingly mobile and hybrid. MDM contracts cover platform licensing (Microsoft Intune, Jamf, VMware Workspace ONE, IBM MaaS360), deployment and configuration services, and ongoing management. Mobile security considerations β€” enforcing encryption, remote wipe capability, app whitelisting β€” are increasingly specified in tender requirements as NIS2 extends endpoint security obligations to mobile devices.

Key CPV Codes

  • 48761000 β€” Anti-virus software package (primary code for antivirus and EDR licensing)
  • 48730000 β€” Security software package (broader security software including EDR/XDR)
  • 48000000 β€” Software packages and information systems
  • 72212517 β€” IT software development services (for endpoint security management tools)
  • 72250000 β€” System and support services (managed EDR services)
  • 32250000 β€” Mobile phones (MDM often bundled with device procurement)

EUCS Alignment and Data Sovereignty

For cloud-delivered endpoint security platforms (which now includes virtually all EDR/XDR products), data sovereignty is an active evaluation criterion in sensitive government tenders. Telemetry data β€” threat detection events, file hashes, process information β€” flows continuously from endpoints to vendor cloud infrastructure. Where this data is processed and stored, and whether it is subject to US government access requests under the Cloud Act or FISA, is a legitimate procurement question that vendors must be prepared to answer with specificity.

Vendors with EU-hosted telemetry processing options (CrowdStrike's EU cloud, Microsoft's EU Data Boundary, SentinelOne's EU instance) are better positioned for sensitive government contracts than those processing all telemetry through US infrastructure.

Winning Strategy

For software supply contracts, independent test results (AV-TEST, AV-Comparatives, SE Labs certifications) provide objective quality evidence. For managed EDR services, demonstrating response capability β€” mean-time-to-detect, mean-time-to-respond, case studies of real threat hunting engagements β€” is decisive. For resellers, the combination of vendor certifications, local implementation references, and competitive pricing on renewals drives market share. In all cases, addressing data sovereignty concerns directly and proactively β€” rather than waiting for evaluators to raise them β€” signals the maturity and public sector awareness that distinguishes winning bids.

End of Briefing // TenderMetric Intelligence Systems β€” TM-INS-079

Related Articles

Sector Guide
Network Security Tenders EU: Firewall and Infrastructure Contracts
Sector Guide
SOC and SIEM Tenders EU: Security Operations Centre Procurement Guide
Sector Guide
EU Cybersecurity Tenders 2026: How to Win Government Security Contracts
β—†
TenderMetric Intelligence Team
EU Procurement Research & Analysis Β· Last updated April 2026
Analysis compiled from TED Europa (Official Journal of the EU), European Commission procurement data, and CPV code classifications. TenderMetric tracks 10,000+ active EU procurement notices across all 27 member states, updated daily from the TED open data feed.
Get Weekly EU Tender Alerts
New tenders from TED Europa across all 27 EU member states β€” every Monday. Free forever.
β—† EU Procurement Intelligence at a Glance
10K+
Active tenders tracked
27
EU member states
€2T+
Annual market value
Daily
Data refresh from TED
β—† EU Contract Value Distribution (above-threshold)
Works contracts (construction, infrastructure) ~52%
Services contracts (IT, consulting, healthcare) ~35%
Supplies contracts (equipment, goods) ~13%
SME award rate (% of contracts to SMEs) ~45%
Source: European Commission Public Procurement Statistics β€” approximate figures based on TED Europa data.
β—† EU Procurement Lifecycle (Open Procedure)
Day 1
Contract Notice Published (TED)
Day 1–35
Tender Preparation & Submission
Day 35–70
Evaluation & Clarifications
Day 70–85
Standstill Period (10 days)
Day 85
Contract Award Decision
Day 90+
Contract Signature & Start
Timeline is indicative. Open procedure minimum: 35 days from publication to submission deadline (Directive 2014/24/EU).
β—†
About the Author
TenderMetric Research Team
EU Procurement Intelligence Specialists Β· tendermetric.com
Our analysts monitor 10,000+ EU procurement notices daily across construction, IT, healthcare, defense, and energy sectors. All data sourced from TED Europa and the EU Publications Office.
πŸ“‹ 10K+ tenders tracked πŸ‡ͺπŸ‡Ί 27 member states πŸ”„ Updated: April 2026
β—† Common Questions About EU Procurement
What is TED Europa and where do EU tenders come from? +
TED (Tenders Electronic Daily) is the online version of the Supplement to the Official Journal of the EU, published by the EU Publications Office. It publishes procurement notices above EU thresholds from all 27 member states, EU institutions, and affiliated bodies β€” approximately 700,000+ notices per year. TenderMetric aggregates and enriches this data daily.
What are the EU procurement thresholds in 2026? +
For 2026–2027, the EU procurement thresholds are: €143,000 for supplies and services by central government authorities; €221,000 for supplies and services by sub-central authorities; €5,538,000 for works contracts. Utilities and defence sectors have separate thresholds. Contracts above these values must be published on TED.
Can non-EU companies bid on EU public tenders? +
Third-country participation depends on international agreements. Countries covered by the WTO Government Procurement Agreement (GPA) β€” including the US, UK, Canada, Japan, and others β€” generally have access to EU tenders above GPA thresholds. Countries without GPA coverage may be excluded from specific lots. Always check the contract notice for nationality restrictions.
What is an ESPD and is it required? +
The European Single Procurement Document (ESPD) is a self-declaration form used across the EU as preliminary evidence of a bidder's suitability. It replaces multiple national certificates at the tender stage β€” you only need to submit the actual certificates if you win. The ESPD is mandatory for all above-threshold EU procurements and can be completed via the eESPD online service.
How can SMEs compete for EU public contracts? +
SMEs win approximately 45% of EU public contracts by value. Key strategies: focus on lots (contracting authorities must divide large contracts into lots where feasible); form consortia with complementary firms; target sub-central authorities (municipalities, regions) where competition is lower; use framework agreements as a stepping stone to larger contracts. The ESPD simplifies the qualification process specifically to reduce SME burden.