Greek camera network leads cybersecurity buying
A Greek ministry’s €35.5m camera network tops this week’s cyber notices, while Poland’s uKSC-led demand meets thin competition in key markets.

Υπουργείο Ψηφιακής Διακυβέρνησης has put a €35.5m digital-camera network for recording traffic-code violations into the cybersecurity notice flow. It is the largest published-value tender in the window, ahead of CONSIP S.p.A.’s €30.2m framework for security software, network protection and information-system resilience. For suppliers, that is a reminder that the buying opportunity is not confined to conventional SOC and endpoint lots: ministries are attaching security requirements to national-scale operational infrastructure.
The Greek ministry is also the home of the National Cybersecurity Authority’s EL-SOC work, intended as the hub for sectoral security operations centres. That context makes the ministry worth tracking beyond this camera procurement. Across the window there are 181 notices from 171 buyers in 26 countries, with 96 still carrying an open deadline.
Where this market is going
Cybersecurity’s coverage-neutral share is 5.58%, a fall of 1.23 points. The monthly line is lumpy rather than steadily falling: 6.74% in 2025-10 slipped to 5.86% in 2025-11, 5.44% in 2025-12 and 4.35% in 2026-01, then recovered through 4.56%, 4.65% and 4.91% to 5.74% in 2026-05 and 6.02% in 2026-06.
That recovery did not hold cleanly. Share moved to 5.48% in 2026-07, 5.79% in 2026-08 and 5.53% in 2026-09 before reaching 5.58% now. Bid teams should read this as an uneven return of demand after the January trough, not as market growth inferred from raw notice counts.
Cybersecurity: share of all classified public IT tenders
Share, not volume. Monthly, last 12 complete months.
Where the tenders were published
Notices by buyer country, 7 days to 2026-10-05.
How hard the competition is
The commercially important divide is national. Germany averages 3 bids, Poland 2.4, Czechia 1.8 and Spain 1.7. In Germany and Poland, assume credible competition and win through differentiation, evidence of technical quality and a bid that makes delivery risk easy for the buyer to assess. In Czechia and Spain, lower bid density changes the constraint: qualification, local delivery capacity and the ability to mobilise can matter more than shaving price alone.
The overall average is 2.4 bids across 62 measured awards, but 45% are single-bid outcomes. SMEs account for 83% of bids, so this is not work being won solely by large integrators. Price was stated as an award criterion in 69 notices and quality in 12, while 100 did not state criteria. That combination favours suppliers that can clear qualification gates reliably, then make their technical case intelligible where the evaluation method is opaque.
How these contracts are awarded
Stated award criterion, for the tenders that declared one.
What is driving it
Poland’s amended Ustawa o krajowym systemie cyberbezpieczeństwa, or uKSC, is the immediate regulatory engine. It is cited in 42 tenders in this window, while 30-day citations stand at 263 against 237 in the preceding 30 days. The act requires covered key and important entities to implement an information-security management system and incident reporting and management. This is both product procurement, particularly for monitoring, protection and response, and compliance work around governance and incident processes.
Other regulatory signals are weaker but worth qualifying early. NIS2 has 3 citations in the latest 30 days and 3 in the prior period; DPM 2.0 has 2 after 0; CBAM has 0 after 1; and DORA has 0 after 1. The Solvency II Review requires transposition by 2027-01-29 and applies from 2027-01-30, putting insurance reporting and risk-framework work into the sales window. Bank Account Registries and BARIS apply from 2027-07-10, with BARIS interconnection due by 2029-07-10. These are compliance-led opportunities that should generate both data-security product demand and implementation work.
Regulations named in live tenders
Tenders citing each framework, last 30 days.
The calendar ahead
| Date | Framework | Milestone | Where |
|---|---|---|---|
| 2027-01-29 | Solvency II Review (Directive 2025/2) | transposition deadline | EU |
| 2027-01-30 | Solvency II Review (Directive 2025/2) | applies from | EU |
| 2027-07-10 | Bank Account Registries + BARIS (AMLD6 2024/1640 art. 16) | applies from | EU |
| 2027-07-10 | EU AML Package (AMLR 2024/1624 + AMLA 2024/1620) | applies from | EU |
What shifted this week
Demand by type of work, against its own 12-week average
Percentage difference from the same vertical’s recent baseline.
Whose technology is being named
Palo Alto Networks is the sharpest opening: 6 notices, up 148% against a 12-week average of 2.4. Fortinet has 7 notices, up 20% against 5.8. The more consequential displacement signals run the other way: Check Point has 2 notices, down 23% against 2.6; Microsoft has 4, down 4% against 4.2; and Cisco has 2, down 4% against 2.1. Microsoft’s decline is visible in a live named battleground, Ministerstvo vnútra Slovenskej republiky’s €7.9m support, development and security procurement for selected Microsoft platforms.
ESET has 2 notices with no delta supplied; IBM Cloud has 2, also without a delta; SentinelOne, Trellix and Trend Micro have 1 each, again without a delta. The buying mix is moving towards support and maintenance, with 21 notices and a 112% rise against its 12-week average; licences and SaaS account for 42 notices, up 48%. Repeat buying is also visible at Komenda Główna Straży Granicznej, which has 2 firewall tenders, and at Gmina Mińsk Mazowiecki, with 2 tenders under the Cyberbezpieczny Samorząd project.
Vendors named in this window’s tenders
Notices naming each vendor, with movement against the same vertical’s 12-week average.
Who is buying repeatedly
| Tenders | Buyer | Country | Example |
|---|---|---|---|
| 2 | ТЕРИТОРІАЛЬНЕ УПРАВЛІННЯ ДЕРЖАВНОЇ СУДОВОЇ АДМІНІСТРАЦІЇ УКРАЇНИ У ЧЕРНІГІВСЬКІЙ ОБЛАСТІ | UA | Послуги із забезпечення функціонування засобів криптографічного захисту інформації (для місцевих загальних суд |
| 2 | Komenda Główna Straży Granicznej | PL | Poland – Network components – Zakup urządzeń typu firewall |
| 2 | Bundesimmobiliengesellschaft m.b.H. | AT | Austria – IT services: consulting, software development, Internet and support – BIG – Incident Response Retain |
| 2 | Gmina Mińsk Mazowiecki | PL | Zakup wyposażenia w ramach Projektu „Cyberbezpieczny Samorząd” Część II |
| 2 | Centrum Zakupów dla Sądownictwa Instytucja Gospodarki Budżetowej reprezentująca Sąd Apelacyjny w Krakowie | PL | Poland – IT software package – Dostawa rozwiązania informatycznego obejmującego funkcjonalność rozszerzonego w |
| 2 | Uniwersytet Śląski w Katowicach | PL | Poland – Software package suites – Dostawa oprogramowania klasy EDR |
| 2 | Urząd Patentowy Rzeczypospolitej Polskiej | PL | Dostawa i wdrożenie urządzenia deszyfrującego ruch sieciowy TLS |
| 2 | Politechnika Morska w Szczecinie | PL | Dostawa subskrypcji licencji i wsparcia technicznego dla urządzeń klasy Web Application Firewall (WAF) eksploa |
An organisation running several tenders in one window is usually working through a programme rather than buying once.
The biggest tenders
Published euro values cover only 55 notices, not the market as a whole, with €81.9m recorded in that subset. Beyond Greece and CONSIP, Ministerstvo vnútra Slovenskej republiky’s €7.9m Microsoft-platform support tender sits alongside its Recovery and Resilience Plan MDR project for monitoring and incident response. Valtori’s €1.4m framework is for cloud security and data-protection specialists within its central-government security-services renewal programme. GIE SESAM-Vitale has a €1.1m security technical-assistance framework. CONSIP’s framework is part of Italy’s public-administration cybersecurity procurement supporting strategic ICT and PNRR digitalisation objectives.
Values as published by the buyer, for the 55 of 181 tenders in this window that stated one in EUR.
Deadlines worth watching
Who won
Suppliers with the most awards this window
Awards published in the window, by named winner.
Sources consulted
Pages the writer read for context while drafting this column. The figures above come from the notices, not from these.
Watch whether Poland’s uKSC citations keep accelerating and whether Palo Alto Networks sustains its 148% notice surge. The next bids should be shaped around operational support capacity as much as product capability, because maintenance demand is moving faster than the wider cyber share.
Method
Built from 181 public procurement notices published between 2026-09-28 and 2026-10-05, classified into the Cybersecurity vertical. Every figure on this page is computed from those notices; the commentary is written around them. Sources: bzp, doe, ted, prozorro. Tenders featured in earlier editions of this column are excluded from the named lists above.
Frequently Asked Questions
How many cybersecurity notices are in the current window?
181 notices from 171 buyers across 26 countries, with 96 open deadlines.
Which country has the highest measured bid average?
Germany averages 3 bids, compared with Poland at 2.4, Czechia at 1.8 and Spain at 1.7.
Which vendor has the strongest notice increase?
Palo Alto Networks has 6 notices, up 148% against a 12-week average of 2.4.


