Compliance requirements
The bidder must confirm that neither it nor the members of its management, administrative or supervisory bodies, procurators or other persons with authority to represent it have been finally convicted within the last five years for participation in a criminal organisation, corruption, fraud, terrorist offences or offences related to terrorist activity, money laundering or terrorist financing, child labour or other exclusion grounds listed in the ESPD. If an exclusion ground applies, the bidder may submit evidence of self-cleaning measures where permitted. The machine-readable notice did not set out all precise exclusion grounds; these must be checked in the tender documents.
Qualification criteria and exclusion grounds
The bidder’s average annual turnover for the period 01/01/2023–31/12/2025 must be at least EUR 20,000. The responsible specialist, i.e. the information security officer, must have experience in information security management or consultancy during the last 36 months from the publication of the contract notice, and that experience must include at least one successful contract or project in a local authority or another public-sector body with a similar distributed structure, where information security management, risk management and/or implementation of the Estonian Information Security Standard (E-ITS) was carried out. The bidder must submit the specialist’s CV and/or a list of completed work showing the client name, contract period, and the specialist’s role and activities. The specialist must hold at least one valid certificate: CISM, CISSP, ISO 27001 Lead Auditor or ISO 27001 Lead Implementer, or demonstrably equivalent competence. A copy of the certificate or a digital certificate must be provided; for equivalent competence, evidence must be submitted showing that the specialist’s knowledge and skills meet the required level. The tender must comply with the procurement documents, and in the case of a joint tender, a power of attorney from the joint bidders must be provided. The machine-readable notice did not include precise other qualification or compliance requirements; these must be checked in the tender documents.