Tender detail

Procurement of E-ITS audit services

Summary

The tender concerns the procurement of E-ITS audit services for the Estonian Information System Authority for one audit cycle. The service covers a pre-audit, main audit, interim audits and, if needed, a follow-up audit to assess compliance with the Estonian Information Security Standard. The bidder must also take into account team competence, an information security certificate, and bid form and compliance requirements.

Reference number
313017-0000
Buyer
Riigi Infosüsteemi Amet
Country
Estonia (EST)
Procedure
Open procedure
CPV
79212000 Auditing services
Deadline
2026-09-04
Status
Open
Contract subject
Services
Estimated value
80 000,00 EUR
Source
RHR

Participation requirements

Tender requirements are available in the official tender documents.

Compliance requirements

The exclusion grounds include at least participation in a criminal organisation, corruption and fraud. The bidder must confirm whether it or members of its management, representation or supervisory bodies have been finally convicted of such offences within the last five years, or whether an exclusion period is still in force. If an exclusion ground applies, the bidder may submit evidence of self-cleaning measures where this is permitted. The machine-readable notice did not include precise other exclusion grounds; these must be checked in the tender documents.

Qualification criteria and exclusion grounds

The lead auditor must hold at least one valid certificate during the audit: CISA (ISACA), an ISO 27001 lead auditor certificate issued by IRCA, or an ISO 27001 lead auditor certificate issued by PECB. The bidder must have a valid information security certificate, such as an E-ITS conclusion decision or an ISO certificate. The independence of audit team members must be confirmed by a signed declaration. The bidder must submit CVs for the lead auditor, the auditors included in the audit team and the technical experts, and they must meet the requirements set out in the tender document ‘Requirements for the team’. If the bid is a joint bid, a power of attorney for the joint bidders must be submitted. The bidder must also submit the indicative audit cost in the required Excel table and complete the fields and confirmations required by the tender documents. The machine-readable notice did not include precise other qualification or compliance requirements; these must be checked in the tender documents.