Абонамент за услуга за провеждане на кампании за проверка на устойчивостта на информационната инфраструктура на ДП РВД срещу кибератаки
At a glance
ДЪРЖАВНО ПРЕДПРИЯТИЕ "РЪКОВОДСТВО НА ВЪЗДУШНОТО ДВИЖЕНИЕ" ТПП (гр. София, Bulgaria) is tendering: Абонамент за услуга за провеждане на кампании за проверка на устойчивостта на информационната инфраструктура на ДП РВД срещу кибератаки. Offers are due 23 Oct 2026, 22:59 CEST. Estimated value €210,000. Bidders must show, among other things: CISM, CISSP, ISO 9001, key people, insurance.
- 23 Oct 2026, 22:59 CEST
- Deadline
- €210,000
- Estimated value
- Open procedure
- Procedure
- Software-related services (72260000)
- Main CPV
- 7 Oct 2026
- Published
Translated from the official notice. The original text is the legally binding one.
What the buyer wants
1.1. The subject matter of the order includes carrying out tests to verify the sustainability (pen tests) of BULATSA information infrastructure against cyberattacks through Platform (hardware and software) based on artificial intelligence. Penn tests will be external and internal. External pen tests will be conducted through a separate instance of Platform (hardware and software) operated by the Contractor outside the entity's perimeter. The internal pen tests will be performed by Contractor employees using Platform (hardware and software) which will be installed on site in BULATSA. The contractor will provide for use Software needed to work on the Platform as well as will support the Platform and update the Software. The platform by which the tests will be carried out should comply with all the requirements of the Contracting Parties referred to in this Technical Specification. 1.2. The subject of the order includes the supply of the necessary hardware, as well as the installation, configuration and testing of the Platform based on artificial intelligence (III) with the possibility of automated and autonomous checks (without human intervention), as well as the possibility of checks managed by a person to perform internal tests by trained employees of the contracting entity. 1.3. The subject-matter of the contract shall include training of contracting authorities to work with the Platform.
Can you bid? Your readiness check
These are the conditions this notice asks bidders to prove. In SalesDots each one is checked against your company profile: certificates with their validity dates, delivered references and your people.
- In your profile
Certificates
CISM · CISSP · ISO 9001
- Not in your profile yet
Key people
Named roles, CVs or minimum team
- Expires before the deadline
Insurance
Professional or liability insurance
Detected automatically in the published notice. Always confirm against the tender documents.
Check it against my companyShow the notice text (3)
The participant should have completed at least one service activity with a subject and volume identical or similar to that of the contract for the last three years from the date of submission of the tender. Notes: An activity for a service with an object and volume identical or similar to that of the order shall be understood as an activity for carrying out penetration tests. Tests must be performed for: - public organisations or - essential or important entities within the meaning of the Cybersecurity Act. A service activity shall be that activity the performance of which has been completed within the period laid down by the Contracting Party, irrespective of the date of execution. When submitting the tender, participants shall declare compliance with the selection criterion by filling in the EEDOP Part IV To demonstrate its technical and professional capabilities, the participant shall provide a list of services which are identical or similar to the subject-matter of the contract with an indication of the values, dates and recipients, together with documents demonstrating the service performed. The documents demonstrating compliance with technical and professional capabilities shall be submitted by the selected contractor before the contract for the award of the contract or upon request in the course of the procedure under the conditions of Art. 67, para. 5 of the Public Procurement Act.
The participant must have personnel with professional competence for the execution of the contract, as follows: 1. Service Delivery Manager and Information Security Expert, who must meet the following minimum requirements: • Higher education degree in the field of “Communication and Computer Engineering”, “Informatics and Computer Science”, “Information Technology”, or equivalent; • Minimum of 5 (five) years of professional experience in the field of information security, of which at least 3 (three) in project management related to penetration testing, cybersecurity, or vulnerability management; • Experience as a manager of at least 2 projects for penetration testing of information infrastructure and systems; • At least one valid certificate in the field of penetration testing: OSCP, GPEN, CEH, or equivalent; • At least one valid management certificate in the field of information security: CISSP, CISM, ISSMP, or equivalent. 2. Minimum of one “Penetration Tester” Expert specializing in network infrastructure, who must meet the following minimum requirements: • Higher education degree in the field of “Communication and Computer Engineering”, “Informatics and Computer Science”, “Information Technology”, or equivalent; • Minimum of 3 years of professional experience in penetration testing, of which at least 2 with a focus on network and infrastructure security; • Participation in a minimum of 2 network infrastructure penetration testing projects; • At least one valid certificate in the field of network penetration testing: OSCP, OSEP, GPEN, GXPN, PNPT, CRTP, CRTE, or equivalent. 3. Minimum of one “Penetration Tester” Expert specializing in server infrastructure, who must meet the following minimum requirements: • Higher education degree in the field of “Communication and Computer Engineering”, “Informatics and Computer Science”, “Information Technology”, or equivalent; • Minimum of 3 years of professional experience in penetration testing, of which at least 2 years with a focus on server infrastructure and operating systems (Windows, Linux/Unix); • Participation in a minimum of 2 server infrastructure penetration testing projects; • At least one valid certificate in the field of penetration testing: OSCP, OSEP, OSCE3, CRTP, CRTE, GCIH, GPEN, or equivalent. 4. Minimum of one “Penetration Tester” Expert specializing in web applications and APIs, who must meet the following minimum requirements: • Higher education degree in the field of “Communication and Computer Engineering”, “Informatics and Computer Science”, “Information Technology”, or equivalent; • Minimum of 3 years of professional experience in penetration testing, of which at least 2 with a focus on web applications and APIs; • Participation in a minimum of 2 web application penetration testing projects; • At least one valid certificate in the field: OSCP, OSWE, GWAPT, BSCP, or equivalent; • Proven experience with OWASP methodologies (Web Security Testing Guide, ASVS, API Security Top 10). When submitting the tender, participants declare their compliance with the selection criterion in the ESPD by filling in the relevant field of Part IV “Selection criteria”, Section C “Technical and professional ability”, field “Educational and professional qualifications” as follows: for each person in the proposed team, participants provide the information necessary to establish compliance with the requirements, indicating, as applicable according to the requirement for the specific person: - Full name of the person; - Team position; - Details of the document for acquired education/completed course/acquired professional qualification – educational institution, No. and date of the document, educational degree, professional field, and specialty; - Professional experience; - Certificates; Each expert may combine no more than 2 (two) roles, provided that they prove compliance with the minimum requirements for each of the expert roles. To prove its technical and professional abilities, the p…
The participant should hold a valid certificate for an implemented quality management system in the field of the subject-matter of this contract, according to standard EN ISO 9001:2015 or equivalent, or other evidence of equivalent quality assurance measures. When submitting the tender, participants shall declare compliance with the selection criterion by filling in the EEDOP Part IV For demonstration of its technical and professional capabilities, the participant shall provide a copy of a valid certificate for an integrated quality management system in the field of information technology, according to standard EN ISO 9001:2015 or equivalent, or other evidence of equivalent quality assurance measures. The documents demonstrating compliance with technical and professional capabilities shall be submitted by the selected contractor before the contract for the award of the contract or upon request in the course of the procedure under the conditions of Art. 67, para. 5 of the Public Procurement Act.
How offers are scored
- На първо място се класира участникът, който е предложил най-ниска о…
What this buyer bought before
Recent IT contracts awarded by the same buyer, from published award notices.
Доставка на оборудване за пренос и комутация на KVM
Winner: Guntermann & Drunck GmbH · 1 bid
€2m
14 Aug 2026
Доставка на хардуер за модернизация на система CIMACT
Winner: СИЕНСИС АД · 3 bids
€643,288
12 Aug 2026
Разширена извънгаранционна софтуерна поддръжка на софтуерни продукти на „ТехноЛогика“ ЕАД
Winner: ТехноЛогика ЕАД · 1 bid
€45,000
7 Aug 2026
Доставка на мрежово оборудване за център за възстановяване при инциденти в реално време
Winner: СИСКОМ ИНЖЕНЕРИНГ АД · 2 bids
€970,701
3 Jul 2026
Обновяване на софтуера и хардуера за EBI системата в ЕЦ за УВД
Winner: СМАРТ БИЛДИНГ ТЕХНОЛОДЖИС ООД · 1 bid
€319,536
24 Jun 2026
Извънгаранционна поддръжка на Система за дистрибутиране на обзорна информация SDDS-NG
Winner: Frequentis Comsoft GmbH · 1 bid
€165,000
22 Jun 2026
Win it with SalesDots
Read the documents for you
SalesDots fetches the tender documents (or takes your upload when a platform does not allow it) and answers the two questions that matter first: what the buyer wants built, and what you must prove to take part, each with the exact quote and page.
Analyse documentsMatch it with your profile
Every certificate, reference and role is checked against your company: green when you have it, amber when it expires before the deadline, grey when it needs a look.
Check my fitPrepare your response
Turn the conditions into a bid checklist with owners and due dates, draft the questions to the buyer and keep the team on one plan.
Start a responseNever miss a change
Track the deadline, amendments and answers to clarification questions, and get similar tenders and re-tenders before they are published.
Track this tenderSource: Tenders Electronic Daily (TED), Official Journal of the EU. SalesDots is not the contracting authority; offers are submitted only through the buyer's platform.