TenderMetric Intelligence Team · Last Reviewed: May 2026 · Sources: TED Europa · EU Publications Office
◆ EU Procurement Intelligence — Key Facts
  • The EU public procurement market is worth €2 trillion+ annually — approximately 14% of EU GDP
  • TED Europa publishes 700,000+ contract notices per year across all 27 EU member states
  • EU procurement thresholds in 2026: €143,000 (supplies/services, central) · €5.538M (works)
  • Open procedures account for ~67% of all above-threshold EU contracts — the most accessible route for new bidders
  • All above-threshold contracts must be published in the Official Journal of the EU (OJEU) under Directive 2014/24/EU
Back to Insights
Sector Guide Last Reviewed: April 2026 TM-INS-072 // MARCH 2026

Penetration Testing Tenders EU: How to Win Government Pen Test Contracts

Summary

Penetration testing has become one of the most active sub-categories in EU public procurement cybersecurity, driven by NIS2 compliance requirements, mandatory security testing for critical national infrastructure, and growing regulatory pressure on public health, transport, and digital services. Government pen test contracts typically range from €50,000 for a focused web application test to over €500,000 for comprehensive red team exercises or multi-year retainer frameworks.

The Government Pen Test Market in 2026

Public sector penetration testing procurement has grown substantially as EU governments transition from reactive to proactive cybersecurity postures. The NIS2 Directive's explicit requirement for "regular security testing" has converted pen testing from an optional best practice to a compliance necessity for thousands of public bodies. National cybersecurity agencies in France (ANSSI), Germany (BSI), the Netherlands (NCSC), and others actively encourage or mandate regular penetration testing for critical infrastructure operators.

The procurement pipeline spans all government tiers:

  • Central government ministries — IT systems handling tax, benefits, identity, and national security
  • National health services — Patient record systems, connected medical devices, telemedicine platforms
  • Transport authorities — Rail, aviation, port, and road management systems
  • Energy utilities — Industrial control systems (ICS/SCADA), smart meter infrastructure
  • Local governments — Citizen-facing portals, payment systems, planning applications
  • EU institutions — European Commission, Parliament, and agencies via DIGIT and CERT-EU

Types of Pen Tests Procured by Government

Government tenders for penetration testing cover a wide range of test types, often bundled into a single contract or framework:

  • Web application penetration testing: The most common type. Testing of citizen portals, internal web applications, APIs, and cloud-hosted systems for OWASP Top 10 vulnerabilities and beyond. Typical value: €15,000–€80,000 per engagement.
  • Network infrastructure testing: External and internal network testing covering firewalls, routers, VPNs, and segmentation. Often procured alongside web app testing. Typical value: €20,000–€120,000.
  • Red team exercises: Adversary simulation engagements testing the full kill chain — from initial access through lateral movement to data exfiltration. Typically reserved for higher-security environments. Value: €80,000–€500,000+.
  • Social engineering assessments: Phishing simulations, vishing, and physical security testing. Increasingly bundled with awareness training programmes.
  • OT/ICS/SCADA security testing: Specialist testing of operational technology environments in energy, water, and transport. High barriers to entry but premium contract values.
  • Cloud penetration testing: Testing of cloud-hosted workloads, container environments, and cloud configuration against CIS Benchmarks.
  • Mobile application testing: Government apps for citizen services, healthcare, and transport.

CPV Codes to Monitor

Penetration testing lacks a dedicated CPV code — contracting authorities use a range of codes:

  • 72220000 — Systems and technical consultancy services (most commonly used for pen testing)
  • 72212730 — Security software development services (sometimes used for automated scanning tools)
  • 72222300 — Information technology services
  • 79212000 — Auditing services (used when pen testing is framed as a security audit)
  • 72212517 — IT software development services

Because no single code reliably captures all pen testing tenders, set up broad keyword alerts ("penetration test", "pen test", "ethical hacking", "vulnerability assessment", "red team") alongside CPV monitoring on TED and national portals.

Contract Value Benchmarks

Contract values vary substantially by scope and authority size. Based on published TED award notices, the typical ranges for EU government pen testing contracts are:

  • Web application penetration test: €8,000–€25,000 per engagement (single application scope)
  • Infrastructure assessment (external + internal): €15,000–€40,000 per engagement
  • Red team exercise: €50,000–€200,000 (adversary simulation, multi-week engagement)
  • Multi-year framework (national authority): €500,000–€5M+ across the framework term

OT/ICS/SCADA testing commands the highest per-day rates due to specialist scarcity and safety-of-life risk — expect 30–50% premium over equivalent IT scope.

Qualification Requirements

Government pen test contracts carry specific professional qualification requirements that vary by country and contract type. Commonly required:

  • CREST membership: The Council of Registered Ethical Security Testers (CREST) is the de facto gold standard accreditation for EU government pen test contracts. CREST membership — and specifically CREST Certified Tester (CCT) and CREST Certified Infrastructure Tester (CCIT) individual certifications — is the primary differentiating qualification in the Netherlands, Belgium, and Ireland, and is increasingly referenced in French and German specifications. For companies without CREST accreditation, winning significant government pen test contracts in these markets is substantially harder.
  • CHECK scheme membership: NCSC CHECK (UK) status is required for testing UK government systems. While post-Brexit UK contracts are outside EU procurement rules, CHECK is still referenced in some EU specifications as a quality benchmark, particularly in member states with strong UK security sector relationships (Netherlands, Denmark, Ireland).
  • OSCP / OSEP / OSED: Offensive Security certifications are commonly listed as "desirable" or "required" for individual testers on the project team.
  • CEH (Certified Ethical Hacker): Widely recognised in Southern and Eastern European government tenders.
  • ISO 27001 company certification: Required for corporate qualification, not just individual testers.
  • Security clearances: Personnel clearances required for testing classified or law enforcement systems — plan 6–18 months ahead.

Framework Agreements for Pen Testing

Several national frameworks cover penetration testing services, allowing public bodies to call off contracts without running full open procedures:

  • Germany: BSI-certified information security service providers (CISS) list — companies must apply for BSI certification to be eligible for federal security contracts.
  • France: ANSSI PRIS (Prestataires de réponse aux incidents de sécurité) and PDIS (Prestataires de détection des incidents de sécurité) qualification schemes.
  • Netherlands: Central government IT security framework via NCSC-NL affiliated procurement.
  • EU institutions: DIGIT cybersecurity frameworks and CERT-EU approved supplier lists.

Winning Strategy for Government Pen Test Tenders

Government evaluators for pen testing contracts are typically technical but not always senior practitioners — they are often IT security managers or procurement officers guided by technical advisors. Your bid must be credible at both levels: technically rigorous for the security experts reviewing methodology, and clearly structured for the procurement team evaluating compliance.

Differentiate your bids by including: a clear testing methodology aligned to recognised frameworks (OWASP, OSSTMM, PTES, TIBER-EU); named testers with specific certifications; a sample deliverable showing the quality and clarity of your reporting; a remediation support offer (fixing identified vulnerabilities or advising on fixes); and references from comparable public sector engagements. Pricing transparency — showing day rates and estimated effort by phase — also builds evaluator confidence in contracts where the scope is fixed.

End of Briefing // TenderMetric Intelligence Systems — TM-INS-072

◆ Primary Sources & Further Reading

◆ Live EU Tenders — From TED Europa

View all →
Business ServicesCHE

Switzerland – Security services – Mandat de Prestations Sûreté et Accueil

Deadline: 06/08/2026

Business ServicesSweden

Sweden – Business services: law, marketing, consulting, recruitment, printing and security…

Deadline: 05/25/2026

Business ServicesNOR

Norway – Business services: law, marketing, consulting, recruitment, printing and security…

Deadline: 05/26/2026

Business ServicesSweden

Sweden – Business services: law, marketing, consulting, recruitment, printing and security…

Deadline: 05/25/2026

€6,000,000

TM
TenderMetric Editorial Verified Publisher
EU Procurement Research & Intelligence · Est. 2025

This article was researched and written by the TenderMetric editorial team using primary sources: TED (Tenders Electronic Daily) XML feeds, official EU procurement directives (2014/24/EU, 2014/25/EU), OJEU contract notices, national procurement authority guidelines, and EU Publications Office data. Contract values and award data are sourced from official contract award notices — not estimated.

📅 Last reviewed: 2026-03-28 🔄 Tender data updated daily from TED Europa
◆ Editorial Review Panel
EU Procurement Research Analyst
TED Europa · OJEU notices · CPV classification
Public Law Editor
EU Directives 2014/24 & 2014/25 · national transposition
Procurement Compliance Reviewer
Threshold verification · award data · deadline accuracy
Publisher
TenderMetric
Independent EU Procurement Intelligence
Aggregates 700,000+ EU public procurement notices per year. Coverage spans all 27 EU member states, all procurement procedures, and all CPV divisions — sourced directly from TED and the EU Publications Office.
Research Methodology
Articles are researched from official EU procurement sources: TED XML feeds, EU procurement directives, OJEU contract notices, and national procurement authority guidelines. Award data is sourced from official contract award notices — not estimated.
Primary Data Sources
Accuracy & Updates
Tender deadlines, contract values, and buyer details change frequently. TenderMetric syncs with TED daily. Editorial articles are reviewed quarterly or when EU procurement legislation changes. Always verify tender status directly on TED Europa before submitting a bid.
◆ Live EU Tender Intelligence
Browse Live EU Public Tenders
Updated daily from TED Europa · All 27 EU member states · All CPV sectors
Search Live Tenders →
About TenderMetric → Research Methodology → Legal Disclaimer → LinkedIn →

Editorial Notice: This article was reviewed by the TenderMetric editorial team. EU procurement law and thresholds are revised periodically. For legally binding procurement information, always refer to the official notice on ted.europa.eu. To report an inaccuracy, contact dev@tendermetric.com.

Related Insights

Intelligence
CEF Digital: New Tender Opportunities Released — Q2 2026 Connectivity Funding Guide
Read →
Sector Guide
Cleaning Services Tenders EU 2026: Public Procurement for Facility Cleaning Contracts
Read →
Sector Guide
Cloud Security Tenders EU: Government Cloud Procurement Requirements 2026
Read →
Sector Guide
EU Construction Tenders 2026: How to Find and Win Public Works Contracts
Read →
TenderMetric Intelligence Team
EU Procurement Research & Analysis · Last updated May 2026
Analysis compiled from TED Europa (Official Journal of the EU), European Commission procurement data, and CPV code classifications. TenderMetric tracks 10,000+ active EU procurement notices across all 27 member states, updated daily from the TED open data feed.
Get Weekly EU Tender Alerts
New tenders from TED Europa across all 27 EU member states — every Monday. Free forever.
◆ EU Procurement Intelligence at a Glance
10K+
Active tenders tracked
27
EU member states
€2T+
Annual market value
Daily
Data refresh from TED
◆ EU Contract Value Distribution (above-threshold)
Works contracts (construction, infrastructure) ~52%
Services contracts (IT, consulting, healthcare) ~35%
Supplies contracts (equipment, goods) ~13%
SME award rate (% of contracts to SMEs) ~45%
Source: European Commission Public Procurement Statistics — approximate figures based on TED Europa data.
◆ EU Procurement Lifecycle (Open Procedure)
Day 1
Contract Notice Published (TED)
Day 1–35
Tender Preparation & Submission
Day 35–70
Evaluation & Clarifications
Day 70–85
Standstill Period (10 days)
Day 85
Contract Award Decision
Day 90+
Contract Signature & Start
Timeline is indicative. Open procedure minimum: 35 days from publication to submission deadline (Directive 2014/24/EU).
About the Author
TenderMetric Research Team
EU Procurement Intelligence Specialists · tendermetric.com
Our analysts monitor 10,000+ EU procurement notices daily across construction, IT, healthcare, defense, and energy sectors. All data sourced from TED Europa and the EU Publications Office.
📋 10K+ tenders tracked 🇪🇺 27 member states 🔄 Updated: May 2026
◆ Common Questions About EU Procurement
What is TED Europa and where do EU tenders come from? +
TED (Tenders Electronic Daily) is the online version of the Supplement to the Official Journal of the EU, published by the EU Publications Office. It publishes procurement notices above EU thresholds from all 27 member states, EU institutions, and affiliated bodies — approximately 700,000+ notices per year. TenderMetric aggregates and enriches this data daily.
What are the EU procurement thresholds in 2026? +
For 2026–2027, the EU procurement thresholds are: €143,000 for supplies and services by central government authorities; €221,000 for supplies and services by sub-central authorities; €5,538,000 for works contracts. Utilities and defence sectors have separate thresholds. Contracts above these values must be published on TED.
Can non-EU companies bid on EU public tenders? +
Third-country participation depends on international agreements. Countries covered by the WTO Government Procurement Agreement (GPA) — including the US, UK, Canada, Japan, and others — generally have access to EU tenders above GPA thresholds. Countries without GPA coverage may be excluded from specific lots. Always check the contract notice for nationality restrictions.
What is an ESPD and is it required? +
The European Single Procurement Document (ESPD) is a self-declaration form used across the EU as preliminary evidence of a bidder's suitability. It replaces multiple national certificates at the tender stage — you only need to submit the actual certificates if you win. The ESPD is mandatory for all above-threshold EU procurements and can be completed via the eESPD online service.
How can SMEs compete for EU public contracts? +
SMEs win approximately 45% of EU public contracts by value. Key strategies: focus on lots (contracting authorities must divide large contracts into lots where feasible); form consortia with complementary firms; target sub-central authorities (municipalities, regions) where competition is lower; use framework agreements as a stepping stone to larger contracts. The ESPD simplifies the qualification process specifically to reduce SME burden.
TenderMetric — Independent EU procurement intelligence platform. Not affiliated with the EU Publications Office, the European Commission, or TED (Tenders Electronic Daily). Tender data is sourced from TED for informational purposes only; always verify procurement notices directly at ted.europa.eu before submitting a bid. Full Disclaimer  ·  Last Reviewed: April 2026  ·  Data Methodology