Tender detail

Provision of external information security officer services for Tõrva Rural Municipality Government and managed institutions

Summary

The tender concerns the provision of an external information security officer service for Tõrva Rural Municipality Government and six managed institutions. The service covers information security management for the entire IT infrastructure, cloud services (M365) and information processing processes; physical security and direct management of employees’ personal devices are not included. The bidder must take into account the exclusion grounds, turnover requirement, compliance conditions, and proof of the responsible specialist’s experience and competence.

Reference number
310485-0000
Buyer
Tõrva Vallavalitsus
Country
Estonia (EST)
Procedure
Simplified procurement
CPV
72300000 Data services
Deadline
2026-06-01
Status
Open
Contract subject
Services
Estimated value
Not published
Source
RHR

Participation requirements

Tender requirements are available in the official tender documents.

Compliance requirements

The bidder must confirm that neither it nor the members of its management, administrative or supervisory bodies, procurators or other persons with authority to represent it have been finally convicted within the last five years for participation in a criminal organisation, corruption, fraud, terrorist offences or offences related to terrorist activity, money laundering or terrorist financing, child labour or other exclusion grounds listed in the ESPD. If an exclusion ground applies, the bidder may submit evidence of self-cleaning measures where permitted. The machine-readable notice did not set out all precise exclusion grounds; these must be checked in the tender documents.

Qualification criteria and exclusion grounds

The bidder’s average annual turnover for the period 01/01/2023–31/12/2025 must be at least EUR 20,000. The responsible specialist, i.e. the information security officer, must have experience in information security management or consultancy during the last 36 months from the publication of the contract notice, and that experience must include at least one successful contract or project in a local authority or another public-sector body with a similar distributed structure, where information security management, risk management and/or implementation of the Estonian Information Security Standard (E-ITS) was carried out. The bidder must submit the specialist’s CV and/or a list of completed work showing the client name, contract period, and the specialist’s role and activities. The specialist must hold at least one valid certificate: CISM, CISSP, ISO 27001 Lead Auditor or ISO 27001 Lead Implementer, or demonstrably equivalent competence. A copy of the certificate or a digital certificate must be provided; for equivalent competence, evidence must be submitted showing that the specialist’s knowledge and skills meet the required level. The tender must comply with the procurement documents, and in the case of a joint tender, a power of attorney from the joint bidders must be provided. The machine-readable notice did not include precise other qualification or compliance requirements; these must be checked in the tender documents.