Poland's uKSC machine and Germany's AI security bid define the fortnight
Poland generated 48 percent of European public cybersecurity notices in 14 days. Germany's BSI went to market for AI in its secure development lifecycle. Here is what both mean for your pipeline.

Germany's Bundesamt für Sicherheit in der Informationstechnik placed three separate tenders in this window, one of them explicitly for artificial intelligence inside a secure software development lifecycle, a procurement labelled KISDL. That is not a speculative research contract; it is the federal cyber authority buying a capability it has decided it needs now, and it signals to any supplier with a credible AI-augmented DevSecOps story that BSI is a live opportunity rather than a future one. The average bid count across German tenders in this period was 6, the highest of any country in the data, which means the authority attracts competition and will use it.
The larger structural story in this fortnight is Poland. With 178 notices, Poland held a 48 percent share of all cybersecurity procurement activity captured across 30 countries. The engine behind that volume is the Ustawa o krajowym systemie cyberbezpieczeństwa, the national cybersecurity act known as uKSC, which generated 52 tenders in this window alone and has produced 500 across the full measurement period. The buyers are not ministries. They are municipal utilities, water companies and small communal enterprises, each running near-identical projects to harden IT and OT infrastructure under programme titles like Cyberbezpieczne Wodociągi. Four separate Polish communal operators appear as repeat buyers with three tenders each. For a supplier with a repeatable SME-friendly deployment, Poland right now is less a market and more a production line.
Where this market is going
Cybersecurity's share of all classified public procurement notices reached 5.77 percent in this window, a rise of 1.57 percentage points against the same period a year ago when the share stood at 4.2 percent. That is the coverage-neutral figure, and it is the one worth tracking. The monthly trend reinforces it: share sat at 4.46 percent in September 2025, crossed 5 percent in April 2026, touched 6.1 percent in June 2026, and has held above 5.5 percent through July and August. The direction is not ambiguous.
Within that trend, the offering mix is shifting. Custom development notices are running 56 percent above their 12-week weekly average, and managed services are running 48 percent above theirs. Hardware supply, by contrast, is 27 percent below its 12-week average. Buyers are moving spend from kit towards capability, and the tenders reflect it: 157 used open procedure, and award criteria across the corpus skewed heavily towards price, with 138 notices using price as the primary criterion against 26 using quality. That combination, rising demand for services alongside price-led evaluation, is the environment suppliers will be pricing into.
Cybersecurity: share of all classified public IT tenders
Share, not volume. Monthly, last 12 complete months.
Where the tenders were published
Notices by buyer country, 14.04 days to 2026-09-19.
How hard the competition is
The average across all tenders where bid counts were recorded was 2.8, but that average conceals a split that matters to anyone deciding where to focus. Germany averaged 6 bids per tender; Finland averaged 5. Poland averaged 1.9, and the Czech Republic averaged 1.8. Thirty percent of all tenders in the window attracted a single bid. That single-bid rate is high enough to suggest that many of these contracts, particularly the smaller municipal ones in Poland and Czechia, are going uncontested.
For a supplier with the right framework agreements and local delivery capacity, a 1.9-bid average in Poland means the competitive environment is thin relative to the volume on offer. The 78 percent SME bid participation rate confirms that these are not large-prime dominated contests; the buyers are accessible to smaller suppliers. The practical implication is that pricing discipline matters more than competitive positioning in much of this market. In Germany and Finland, where competition is genuine and bid counts are higher, the calculus reverses: differentiation and technical quality become the levers, not price alone.
How these contracts are awarded
Stated award criterion, for the tenders that declared one.
What is driving it
The uKSC, Poland's national cybersecurity act, is the dominant regulatory driver visible in this data, cited across 52 tenders in the window and 500 in the full measurement period. The 30-day tender count under uKSC rose from 212 to 288, a meaningful acceleration. The programme is EU co-funded in part; 10 percent of notices in this window carried EU funding flags, and the project titles reference EU grant schemes explicitly. Suppliers who have not yet mapped their offer to uKSC eligibility criteria are leaving a large and still-growing pipeline untouched.
NIS2, the EU network and information security directive, appeared in only 1 tender in this window despite covering 16 countries in the broader momentum data, where its 30-day count held flat at 3. That flatness suggests NIS2 demand is still working through national transposition at varying speeds rather than producing a uniform procurement wave. DORA, the digital operational resilience act for financial services, recorded 1 tender in the last 30 days against zero in the prior period, a first signal of procurement activity. Looking further ahead, the Solvency II Review transposes by 29 January 2027 and applies from 30 January 2027, and the EU AML Package including the new AMLA authority applies from 10 July 2027. Both create compliance technology requirements in the insurance and financial intelligence sectors, and the procurement sales window for both is 2026.
Regulations named in live tenders
Tenders citing each framework, last 30 days.
The calendar ahead
| Date | Framework | Milestone | Where |
|---|---|---|---|
| 2027-01-29 | Solvency II Review (Directive 2025/2) | transposition deadline | EU |
| 2027-01-30 | Solvency II Review (Directive 2025/2) | applies from | EU |
| 2027-07-10 | Bank Account Registries + BARIS (AMLD6 2024/1640 art. 16) | applies from | EU |
| 2027-07-10 | EU AML Package (AMLR 2024/1624 + AMLA 2024/1620) | applies from | EU |
What shifted this week
Demand by type of work, against its own 12-week average
Percentage difference from the same vertical’s recent baseline.
Whose technology is being named
Fortinet appeared in 13 notices across 2 countries, running 32 percent above its 12-week weekly average of 9.9, and is the most frequently named vendor in this window by a considerable margin. Cisco appeared in 4 notices but its delta against its weekly average was 99 percent, meaning it is appearing at roughly twice its recent rate. Palo Alto Networks and Check Point each appeared in 5 notices across 3 and 4 countries respectively, both modestly above their averages. Microsoft moved in the opposite direction, appearing in 3 notices against a weekly average of 4.7, a fall of 36 percent, and across 3 countries.
The Hessische Zentrale für Datenverarbeitung in Germany published a tender specifically for Secure-Web-Gateway-Systeme worth 7.7 million euros, the kind of contract where Fortinet, Palo Alto and Check Point all compete directly. Splunk appeared in 3 notices, all within a single country, which typically indicates a national programme or framework refresh rather than organic demand. The technology fields in these notices are empty in the underlying data, so vendor appearances are the clearest signal of what buyers are actually specifying, and the pattern points firmly towards network security and gateway infrastructure as the dominant purchase category in this fortnight.
Vendors named in this window’s tenders
Notices naming each vendor, with movement against the same vertical’s 12-week average.
Who is buying repeatedly
| Tenders | Buyer | Country | Example |
|---|---|---|---|
| 4 | Територіальне управління Державної судової адміністрації України в Одеській області | UA | Послуги з забезпечення функціонування засобів криптографічного захисту інформації в місцевих загальних судах О |
| 3 | Iarnród Eireann-Irish Rail | IE | Ireland – IT services: consulting, software development, Internet and support – CIE Group Penetration Testing |
| 3 | Bundesamt für Sicherheit in der Informationstechnik | DE | Germany – IT services: consulting, software development, Internet and support – KI im Secure Software Developm |
| 3 | PRZEDSIĘBIORSTWO USŁUG KOMUNALNYCH SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ | PL | Dostawa, wdrożenie zintegrowanego systemu bezpieczeństwa informacji i infrastruktury IT oraz OT dla Przedsiębi |
| 3 | Nemocnice Dačice, a.s. | CZ | Czechia – Servers – Modernizace ICT pro zvýšení úrovně kybernetické bezpečnosti Nemocnice Dačice, a.s. II. |
| 3 | Zakład Gospodarki Komunalnej Czernica Sp. z o. o. | PL | Dostawa i wdrożenie infrastruktury IT/OT oraz systemów cyberbezpieczeństwa w ramach projektu „Cyberbezpieczne |
| 3 | GMINA POTOK GÓRNY | PL | Zakup sprzętu IT wraz z oprogramowaniem w ramach projektu Zwiększenie cyberbezpieczeństwa Gminy Potok Górny |
| 3 | Miejski Zakład Komunalny w Kazimierzu Dolnym Sp. z o.o | PL | Dostawa i wdrożenie rozwiązań cyberbezpieczeństwa dla Miejskiego Zakładu Komunalnego w Kazimierzu Dolnym Sp. z |
An organisation running several tenders in one window is usually working through a programme rather than buying once.
The biggest tenders
The largest single tender in the window is the Austrian federal government's Cybersecurity 2027 framework, valued at 149.2 million euros, procured through Bundesbeschaffung GmbH on behalf of the Republic of Austria and all contracting authorities within its scope. It is a framework, which means multiple suppliers can be admitted and call-off contracts will follow over the agreement's life. The Netherlands' Stichting Participatiefonds voor het Onderwijs, the education participation fund, published a 16 million euro tender for managed workplace, cloud and security services. Hessen's state data processing centre went to market for secure web gateway systems at 7.7 million euros. Finland's Digi- ja väestötietovirasto, the digital and population data services agency, published a 3 million euro framework for cyber and data protection expert services. Iarnród Éireann, Ireland's national rail operator, placed a 2.65 million euro contract for cyber security consultancy covering both IT and operational technology environments, and also appears as a repeat buyer with three separate tenders in the window.
Values as published by the buyer, for the 109 of 369 tenders in this window that stated one in EUR.
Deadlines worth watching
Who won
Suppliers with the most awards this window
Awards published in the window, by named winner.
Elsewhere this week
Poland’s NIS2 transposition remains pending: on 31 July 2025, the government’s draft amendment to the Act on the National Cybersecurity System (uKSC) was submitted to Parliament, with the bill proposing to implement Directive (EU) 2022/2555. [Polish Government, “Projekt ustawy o zmianie ustawy o krajowym systemie cyberbezpieczeństwa oraz niektórych innych ustaw,” 31 July 2025: https://www.gov.pl/web/premier/projekt-ustawy-o-zmianie-ustawy-o-krajowym-systemie-cyberbezpieczenstwa-oraz-niektorych-innych-ustaw]
The revised Solvency II Directive entered into force on 30 December 2025; Member States must transpose it by 29 January 2027, with most provisions applying from 30 January 2027. [Directive (EU) 2025/2, Arts. 2–3: https://eur-lex.europa.eu/eli/dir/2025/2/oj]
Found by an automated web search and shown with its sources; not part of the measured figures above.
Austria's 149.2 million euro framework closes the largest opportunity in the immediate pipeline, but the structural opportunity sits further east and at smaller ticket sizes: Poland's uKSC programme is accelerating, its municipal buyers are competitive-bid-light, and the fortnight's data shows no sign of the volume slowing.
Method
Built from 369 public procurement notices published between 2026-09-05 and 2026-09-19, classified into the Cybersecurity vertical. Every figure on this page is computed from those notices; the commentary is written around them. Sources: bzp, doe, ted, prozorro, worldbank. Tenders featured in earlier editions of this column are excluded from the named lists above.
Frequently Asked Questions
Which country produced the most cybersecurity procurement notices in this period?
Poland produced 178 notices, representing a 48 percent share of all cybersecurity notices captured across 30 countries in the 14-day window. The primary driver is the national cybersecurity act, uKSC, which generated 52 tenders in the window alone.
How competitive are public cybersecurity tenders across Europe right now?
The average across tenders where bid counts were measured was 2.8 bids, recorded on 64 tenders. Thirty percent attracted only a single bid. Germany averaged 6 bids per tender and Finland averaged 5, while Poland averaged 1.9 and the Czech Republic 1.8. SMEs accounted for 78 percent of bids recorded.
What is the largest cybersecurity tender currently open in Europe?
The Austrian federal Cybersecurity 2027 framework, procured through Bundesbeschaffung GmbH on behalf of the Republic of Austria, is valued at 149.2 million euros. It is a framework agreement, meaning multiple suppliers can qualify and call-off contracts will follow.


