TenderMetric Intelligence Team · Last Reviewed: May 2026 · Sources: TED Europa · EU Publications Office
◆ EU Procurement Intelligence — Key Facts
  • The EU public procurement market is worth €2 trillion+ annually — approximately 14% of EU GDP
  • TED Europa publishes 700,000+ contract notices per year across all 27 EU member states
  • EU procurement thresholds in 2026: €143,000 (supplies/services, central) · €5.538M (works)
  • Open procedures account for ~67% of all above-threshold EU contracts — the most accessible route for new bidders
  • All above-threshold contracts must be published in the Official Journal of the EU (OJEU) under Directive 2014/24/EU
Back to Insights
Sector Guide Last Reviewed: April 2026 TM-INS-073 // MARCH 2026

SOC and SIEM Tenders EU: Security Operations Centre Procurement Guide

Summary

Security Operations Centre (SOC) services and SIEM platform procurement represent some of the largest and highest-value cybersecurity contracts in European public procurement. The EU Cyber Solidarity Act has directly funded national SOC establishment, while NIS2 compliance is driving demand for managed detection and response among thousands of public bodies that cannot sustain in-house 24/7 security monitoring. SIEM contracts for Splunk, Microsoft Sentinel, IBM QRadar, and competing platforms — plus the managed services to operate them — are among the fastest-growing segments on TED.

SOC-as-a-Service Procurement Growth

The fundamental driver of SOC procurement is a staffing crisis: EU public sector organisations face severe shortages of qualified security operations analysts. The EU Cybersecurity Skills Framework estimates a shortage of over 300,000 cybersecurity professionals across the EU, with the public sector disproportionately affected due to salary constraints relative to private sector competitors.

This shortage makes SOC-as-a-Service the pragmatic option for the majority of public bodies with NIS2 detection and monitoring obligations. Rather than building and staffing an internal SOC — requiring multiple analysts per shift for genuine 24/7 coverage, plus SIEM infrastructure, threat intelligence feeds, and incident response capability — organisations procure this as a managed service.

Key procurement categories within SOC services:

  • Fully managed SOC: Complete outsourcing of security monitoring. The provider supplies platform, analysts, processes, and reporting. Contract values €200K–€5M+ per year for significant public bodies.
  • SOC co-management: Provider operates SIEM and tier-1/2 analysis; client retains tier-3 and incident response. Hybrid model increasingly favoured by authorities wanting to build internal capability over time.
  • MDR (Managed Detection and Response): Endpoint-focused variant combining EDR tooling with analyst oversight. Often procured separately from network SOC services.
  • CSIRT/CERT services: Computer Security Incident Response Team support — particularly relevant for national-level procurement under the Cyber Solidarity Act.

SIEM Platform Contracts

Many public bodies procure the SIEM platform itself separately from managed services, through software licensing contracts. The dominant platforms appearing in EU public procurement:

  • Microsoft Sentinel: Gaining rapidly due to deep integration with the Microsoft 365 environments already prevalent in government. Azure-native, consumption-based pricing. Often included in broader Microsoft enterprise agreements.
  • Splunk Enterprise/Cloud: Long the incumbent in large government environments. High capability, high cost. Cisco acquisition has raised data sovereignty concerns in some EU member states.
  • IBM QRadar: Strong in defence-adjacent and intelligence-community-adjacent procurement. On-premise deployment option maintains appeal for air-gapped environments.
  • Elastic SIEM / OpenSearch: Open-source options appearing in cost-sensitive procurement, particularly in smaller member states and local government.
  • EU-origin platforms: Data sovereignty concerns are driving some member states to prefer European-headquartered SIEM vendors, creating an opening for vendors like LogPoint (Denmark) and others.

24/7 Monitoring Requirements

NIS2 Article 21 requires significant entities to be capable of detecting and responding to incidents continuously. Contracts for SOC services therefore typically specify:

  • 24/7/365 monitoring with defined response SLAs (e.g., acknowledge critical alerts within 15 minutes)
  • Minimum analyst staffing levels per shift
  • Escalation procedures and named incident response contacts
  • Integration with national CSIRT/CERT for incident reporting under NIS2 Article 23 (24-hour early warning, 72-hour full notification)
  • Threat intelligence feeds and regular threat landscape reporting
  • Monthly KPI reporting covering alert volumes, detection rates, mean-time-to-detect, and mean-time-to-respond

Key CPV Codes

  • 72700000 — Computer network services (primary code for managed network security and SOC)
  • 72212730 — Security software development services
  • 48730000 — Security software package (SIEM platform licensing)
  • 72222300 — Information technology services
  • 72250000 — System and support services (managed service operations)
  • 72315000 — Data network management and support services

Qualification Requirements

SOC and SIEM contracts carry the highest qualification bars in cybersecurity procurement, reflecting the sensitive nature of the access involved:

  • ISO 27001 certification — mandatory for virtually all SOC service contracts
  • ISO 27035 (Incident Management) — increasingly specified alongside 27001
  • SOC 2 Type II report — for cloud-delivered SOC services, particularly in contracts with data residency requirements
  • National CSIRT accreditation — in several member states, operating a CSIRT/CERT requires formal accreditation by the national authority
  • Data residency documentation — proof that all monitoring data remains within EU jurisdiction; US Cloud Act exposure is a disqualifying factor in some tenders
  • Demonstrable 24/7 operational capability — staffing schedules, analyst CVs, escalation matrices

Outcome-Based SLAs: The New Standard

SOC contract structures are shifting from MSSP (Managed Security Service Provider) retainer models toward outcome-based contracts. Contracting authorities in Germany, France, the Netherlands, and Belgium are now routinely specifying measurable detection and response metrics as binding SLA requirements. The benchmarks that appear most frequently in 2025–2026 award notices:

  • Mean Time to Detect (MTTD): <4 hours for critical and high-severity incidents
  • Mean Time to Respond (MTTR): <1 hour for critical incidents (initial containment action)
  • Alert false positive rate: <5% for tier-1 escalations in some specifications

Bidders who cannot demonstrate these metrics from existing operational contracts — backed by case studies with actual figures — are increasingly excluded at the technical evaluation stage. Generic claims of "industry-leading detection capability" without supporting data are scored at or near zero in MEAT evaluations with structured scoring matrices.

What Wins SOC Tenders

SOC tenders are highly competitive and evaluated on quality scores of 70% or more in most specifications. The factors that separate winning bids from credible also-rans: demonstrated knowledge of the specific threat landscape facing the contracting authority's sector; existing integrations with the platforms already deployed in the client environment; a proven track record presented with actual MTTD/MTTR figures from comparable engagements; a clear knowledge transfer plan for clients who want to build internal capability over time; and EU data residency commitments backed by legal documentation rather than general assurances. Providers that can demonstrate alignment with national CSIRT frameworks and offer documented NIS2 Article 23 incident reporting workflows will consistently score higher than providers offering equivalent technical capability without this regulatory alignment.

End of Briefing // TenderMetric Intelligence Systems — TM-INS-073

◆ Primary Sources & Further Reading

◆ Live EU Tenders — From TED Europa

View all →
Business ServicesCHE

Switzerland – Security services – Mandat de Prestations Sûreté et Accueil

Deadline: 06/08/2026

Business ServicesSweden

Sweden – Business services: law, marketing, consulting, recruitment, printing and security…

Deadline: 05/25/2026

MedicalPoland

Poland – Medical consumables – Dostawa wyrobów medycznych jednorazowych na potrzeby Szpita…

Deadline: 05/22/2026

Business ServicesNOR

Norway – Business services: law, marketing, consulting, recruitment, printing and security…

Deadline: 05/26/2026

TM
TenderMetric Editorial Verified Publisher
EU Procurement Research & Intelligence · Est. 2025

This article was researched and written by the TenderMetric editorial team using primary sources: TED (Tenders Electronic Daily) XML feeds, official EU procurement directives (2014/24/EU, 2014/25/EU), OJEU contract notices, national procurement authority guidelines, and EU Publications Office data. Contract values and award data are sourced from official contract award notices — not estimated.

📅 Last reviewed: 2026-03-28 🔄 Tender data updated daily from TED Europa
◆ Editorial Review Panel
EU Procurement Research Analyst
TED Europa · OJEU notices · CPV classification
Public Law Editor
EU Directives 2014/24 & 2014/25 · national transposition
Procurement Compliance Reviewer
Threshold verification · award data · deadline accuracy
Publisher
TenderMetric
Independent EU Procurement Intelligence
Aggregates 700,000+ EU public procurement notices per year. Coverage spans all 27 EU member states, all procurement procedures, and all CPV divisions — sourced directly from TED and the EU Publications Office.
Research Methodology
Articles are researched from official EU procurement sources: TED XML feeds, EU procurement directives, OJEU contract notices, and national procurement authority guidelines. Award data is sourced from official contract award notices — not estimated.
Primary Data Sources
Accuracy & Updates
Tender deadlines, contract values, and buyer details change frequently. TenderMetric syncs with TED daily. Editorial articles are reviewed quarterly or when EU procurement legislation changes. Always verify tender status directly on TED Europa before submitting a bid.
◆ Live EU Tender Intelligence
Browse Live EU Public Tenders
Updated daily from TED Europa · All 27 EU member states · All CPV sectors
Search Live Tenders →
About TenderMetric → Research Methodology → Legal Disclaimer → LinkedIn →

Editorial Notice: This article was reviewed by the TenderMetric editorial team. EU procurement law and thresholds are revised periodically. For legally binding procurement information, always refer to the official notice on ted.europa.eu. To report an inaccuracy, contact dev@tendermetric.com.

Related Insights

Social // 2026
EU Social Services Tenders 2026: Care, Housing, Employment, and Community Contracts
Read →
Intelligence
CEF Digital: New Tender Opportunities Released — Q2 2026 Connectivity Funding Guide
Read →
Sector Guide
Cleaning Services Tenders EU 2026: Public Procurement for Facility Cleaning Contracts
Read →
Sector Guide
Cloud Security Tenders EU: Government Cloud Procurement Requirements 2026
Read →
TenderMetric Intelligence Team
EU Procurement Research & Analysis · Last updated May 2026
Analysis compiled from TED Europa (Official Journal of the EU), European Commission procurement data, and CPV code classifications. TenderMetric tracks 10,000+ active EU procurement notices across all 27 member states, updated daily from the TED open data feed.
Get Weekly EU Tender Alerts
New tenders from TED Europa across all 27 EU member states — every Monday. Free forever.
◆ EU Procurement Intelligence at a Glance
10K+
Active tenders tracked
27
EU member states
€2T+
Annual market value
Daily
Data refresh from TED
◆ EU Contract Value Distribution (above-threshold)
Works contracts (construction, infrastructure) ~52%
Services contracts (IT, consulting, healthcare) ~35%
Supplies contracts (equipment, goods) ~13%
SME award rate (% of contracts to SMEs) ~45%
Source: European Commission Public Procurement Statistics — approximate figures based on TED Europa data.
◆ EU Procurement Lifecycle (Open Procedure)
Day 1
Contract Notice Published (TED)
Day 1–35
Tender Preparation & Submission
Day 35–70
Evaluation & Clarifications
Day 70–85
Standstill Period (10 days)
Day 85
Contract Award Decision
Day 90+
Contract Signature & Start
Timeline is indicative. Open procedure minimum: 35 days from publication to submission deadline (Directive 2014/24/EU).
About the Author
TenderMetric Research Team
EU Procurement Intelligence Specialists · tendermetric.com
Our analysts monitor 10,000+ EU procurement notices daily across construction, IT, healthcare, defense, and energy sectors. All data sourced from TED Europa and the EU Publications Office.
📋 10K+ tenders tracked 🇪🇺 27 member states 🔄 Updated: May 2026
◆ Common Questions About EU Procurement
What is TED Europa and where do EU tenders come from? +
TED (Tenders Electronic Daily) is the online version of the Supplement to the Official Journal of the EU, published by the EU Publications Office. It publishes procurement notices above EU thresholds from all 27 member states, EU institutions, and affiliated bodies — approximately 700,000+ notices per year. TenderMetric aggregates and enriches this data daily.
What are the EU procurement thresholds in 2026? +
For 2026–2027, the EU procurement thresholds are: €143,000 for supplies and services by central government authorities; €221,000 for supplies and services by sub-central authorities; €5,538,000 for works contracts. Utilities and defence sectors have separate thresholds. Contracts above these values must be published on TED.
Can non-EU companies bid on EU public tenders? +
Third-country participation depends on international agreements. Countries covered by the WTO Government Procurement Agreement (GPA) — including the US, UK, Canada, Japan, and others — generally have access to EU tenders above GPA thresholds. Countries without GPA coverage may be excluded from specific lots. Always check the contract notice for nationality restrictions.
What is an ESPD and is it required? +
The European Single Procurement Document (ESPD) is a self-declaration form used across the EU as preliminary evidence of a bidder's suitability. It replaces multiple national certificates at the tender stage — you only need to submit the actual certificates if you win. The ESPD is mandatory for all above-threshold EU procurements and can be completed via the eESPD online service.
How can SMEs compete for EU public contracts? +
SMEs win approximately 45% of EU public contracts by value. Key strategies: focus on lots (contracting authorities must divide large contracts into lots where feasible); form consortia with complementary firms; target sub-central authorities (municipalities, regions) where competition is lower; use framework agreements as a stepping stone to larger contracts. The ESPD simplifies the qualification process specifically to reduce SME burden.
TenderMetric — Independent EU procurement intelligence platform. Not affiliated with the EU Publications Office, the European Commission, or TED (Tenders Electronic Daily). Tender data is sourced from TED for informational purposes only; always verify procurement notices directly at ted.europa.eu before submitting a bid. Full Disclaimer  ·  Last Reviewed: April 2026  ·  Data Methodology