Questions & Answers
Above the EU thresholds, German public procurement follows EU Directive 2014/24/EU, transposed through the Act against Restraints of Competition (GWB) and the Regulation on the Award of Public Contracts (VgV). Above-threshold notices from German buyers are published in the EU's Tenders Electronic Daily (TED).
The State of Cyber Security Procurement in Germany
Updated
Procurement rules for Germany
Above the EU thresholds, German public procurement follows EU Directive 2014/24/EU, transposed through the Act against Restraints of Competition (GWB) and the Regulation on the Award of Public Contracts (VgV). Above-threshold notices from German buyers are published in the EU's Tenders Electronic Daily (TED).
Where the notices come from
For Germany, the Lucius catalog indexes open notices from: TED.
Cyber security notices in the catalog
On 24 September 2026, across Germany, Austria and Switzerland combined, the catalog held 1 open notice whose text mentions cyber security, drawn from TED. Across all sectors, 6,686 notices were open in the same scope.
Examples of open cyber security notices from buyers in Germany on 24 September 2026:
- Projekt 1034: Technische Umsetzung einer SBOM für KI (SBOM4AI), from Bundesamt für Sicherheit in der Informationstechnik, closing in September 2026. In English: The Federal Office for Information Security (BSI) is procuring the technical implementation of a Software Bill of Materials for Artificial Intelligence (SBOM4AI).
- Evaluation des Sofortprogramms Cybersicherheit, from Bundesministerium für Gesundheit, closing in October 2026. In English: The German Federal Ministry of Health (Bundesministerium für Gesundheit) is procuring an evaluation of the IT and digitalization maturity level for critical healthcare...
- Berlin TXL, ISO-IEC 27001 Zertifizierungsvorbereitung, from Berlin TXL Management GmbH, closing in October 2026. In English: Berlin TXL Management GmbH is seeking a service provider to prepare the company for ISO/IEC 27001 certification.
- weite Ausschreibung einer Software-Lösung für Security Awareness und Phishing-Simulation, from ITEBO GmbH, closing in October 2026. In English: ITEBO GmbH is procuring a framework agreement for a web-based Software-as-a-Service (SaaS) solution for security awareness training and phishing simulations.
- External Information Security Officer for the Brandenburg IT Service Provider, from Brandenburgischer IT-Dienstleister, closing in October 2026. In English: Brandenburgischer IT-Dienstleister is procuring an external Information Security Officer (ISB).
Across all open notices in this set, 31 different buyers were publishing; the most active were Bundesrepublik Deutschland, vertreten durch das Bundesministerium des Innern, vertreten durch das Beschaffungsamt des BMI (7 notices); Bundesamt für Sicherheit in der Informationstechnik (5 notices); ALDB GmbH (2 notices); Bundesdruckerei GmbH (2 notices); and ekom21, Kommunales Gebietsrechenzentrum Hessen (2 notices).
What bid and tender writers prepare
Tender writers work through the buyer's questions, instructions, word limits and required attachments. They plan each answer against the evaluation criteria stated in the pack. They write method statements and quality answers, often adapting material from earlier bids. They check that every requirement in the pack has an answer before submission.
How Lucius AI helps
Lucius AI reads a public-sector tender pack and extracts every requirement into a register, with a citation to the page each requirement comes from. From that register it builds a compliance matrix. The contract terms are scanned for commercial risk, such as liquidated damages, liability caps and indemnities, and the tender gets a bid/no-bid verdict. Responses are drafted from the company's own past bids, kept in its Bid Library, and the work exports to Word, Excel and PDF. The catalog behind it is a live index of 230,000+ public tenders from 15 official sources in 170+ countries.
Bidders into Germany cyber security contracts compete under TED, e-Vergabe and the German Federal Procurement Office (BeschA). Sector-specific compliance bars include penetration-testing accreditation, information-security certification (ISO 27001) and a recognised cyber-assessment framework. When a tender asks for any of them, Lucius lists that requirement with its page and a quote from the source.
Lucius vs generic LLMs for tender writing in Cyber Security / Germany
Reading a tender pack by hand means finding each requirement and contract term across separate documents. Lucius AI puts every requirement in a register with a citation to its page, builds a compliance matrix and scans the contract terms for commercial risk.
Got a tender? Upload it and see your compliance score.
Try Free