Compliance requirements
The notice states that the bidder must not be excluded on the grounds listed in Section 95(1) of the Public Procurement Act, including convictions for organised crime, corruption, fraud, terrorist offences, money laundering or terrorist financing, illegal employment of foreigners, child labour or trafficking in human beings, tax or social security debt, and sanctions-related grounds. In addition, only bidders established in an EU Member State, an EEA contracting state or a country that has acceded to the WTO Government Procurement Agreement may participate.
Qualification criteria and exclusion grounds
The bidder must hold an ISO 27001 or SOC 2 Type II certificate, and the offered ICT third-party risk and security management platform must fall within the certificate’s scope of applicability. Compliance must be demonstrated by submitting a copy of a valid certificate. If the bidder relies on an equivalent standard or proof, the bidder must justify and evidence equivalence.
If the bidder offers the software and related support services, a manufacturer’s authorisation or certificate must be submitted. For technical support, the bidder must provide the support terms and confirm that support will be available throughout the contract period in Estonian or English and will comply with the technical description.
The bidder must submit a technical tender, including the software’s technical specification or standard terms, technical information for checking compliance with the requirements, and the completed non-functional requirements table. The detailed cost form must also be completed according to the prescribed structure.
The bidder must confirm that it has reviewed the procurement documents and the draft contract, and that the tender complies with the conditions set out in the tender documents. If the bid is joint, a power of attorney from the joint bidders must be attached.
The platform must be hosted in the European Union or in other territories providing adequate data protection, and the service provider must be certified under ISO 27001. No additional costs may arise for the contracting authority’s third parties.