Compliance requirements
The bidder must confirm that neither it nor its representatives have been convicted within the last five years for participation in a criminal organisation, corruption, fraud, money laundering, terrorism, human trafficking, tax arrears or any other exclusion ground listed in the ESPD. If an exclusion ground applies, the bidder may submit evidence of self-cleaning measures where permitted. The machine-readable notice did not include the full precise exclusion grounds; they must be checked in the tender documents.
Qualification criteria and exclusion grounds
The bidder must have completed at least one 36-month contract or two contracts of at least 24 months each within the last 36 months, matching the contracting authority’s required experience. Under those contracts, the bidder must have provided hosting and administration services for information systems for Java-based applications integrated with external services via X-Road and serving at least 15,000 users and at least 500 concurrent users. As a second experience requirement, the bidder must have at least one 36-month contract or two contracts of at least 24 months each for CI/CD services that ensure build processes and automated deployment pipelines and allow version upgrades without service interruption. The tender must include CVs of the specialists directly involved in contract performance, using the contracting authority’s prescribed form. The bidder must hold a valid ISO 27001 information security management certificate, a completed E-ITS audit, or another equivalent proof of information security compliance. The bidder must submit migration or deployment plans for the RTIP and LTP environments and confirm that the offered hosting environment meets the E-ITS security level S (large) or an equivalent level. The bidder must also provide the required declarations of compliance, a power of attorney for joint bidders if applicable, and equivalence evidence where needed.