Service of an audit of the information network HIL according to ISO 27001 based on IT-Grundschutz
At a glance
HIL Heeresinstandsetzungslogistik GmbH (Bonn, Germany) is tendering: Service of an audit of the information network HIL according to ISO 27001 based on IT-Grundschutz. Offers are due 20 Oct 2026, 18:00 CEST. 48-month contract. Bidders must show, among other things: BSI IT-Grundschutz, ISO 27001, ISO 9001, references, key people, minimum turnover, insurance.
- 20 Oct 2026, 18:00 CEST
- Deadline
- 48 months
- Duration
- Negotiated with call
- Procedure
- IT services: consulting, software development, Internet and support (72000000)
- Main CPV
- 21 Sept 2026
- Published
Translated from the official notice. The original text is the legally binding one.
What the buyer wants
The subject of the service is the conclusion of a long-term framework contract (term 4 years) for audit services as part of a co-sourcing to support the internal information security of HIL GmbH. The aim is the regular, risk- and order-related auditing of the information network on the basis of relevant regulations in order to identify potential for improvement and derive solution-oriented measures. These continuous reviews are intended to ensure compliance with the audit processes and to ensure the mandatory ISO 27001 certification targeted for the year 2028.
Technologies named
- ISO 27001
- IT-Grundschutz
Can you bid? Your readiness check
These are the conditions this notice asks bidders to prove. In SalesDots each one is checked against your company profile: certificates with their validity dates, delivered references and your people.
- In your profile
Certificates
BSI IT-Grundschutz · ISO 27001 · ISO 9001
- In your profile
References
Similar contracts delivered before
- Not in your profile yet
Key people
auditor
- In your profile
Minimum turnover
Minimum annual turnover or financial standing
- Expires before the deadline
Insurance
Professional or liability insurance
Detected automatically in the published notice. Always confirm against the tender documents.
Check it against my companyShow the notice text (21)
Information on the use of a qualifying loan (Annex 2) (with the request to participate); By self-declaration: information on the use of capacity of another company (ownership loan) to provide the service in view of the necessary economic and financial, technical and professional capacity.
Subcontracting information (Annex 1) (with request to participate); By self-declaration: Declaration on the planned allocation of service shares to subcontractors (if necessary). See in addition the note on the self-execution bid for certain core services (Appendix 3 TNA+suitability).
Code of Conduct (Appendix 4) (With request to participate; by self-declaration): It must be confirmed that the Code of Conduct is complied with.
DIN ISO 9001 certification (with the application for participation); By means of a third-party declaration: certification according to ISO 9001 or an equivalent quality management system by an accredited company is available. The existing certification by an accredited company is proven by the attached certificate. The certificate must be valid at the time of submission of the request for participation.
GDPR (with the request for participation); By self-declaration: confirmation of recognition and compliance with the data protection notice in accordance with art. 13 GDPR
Liability insurance confirmation (not older than 1 year when submitting the application for participation) (With the application for participation; by means of a third-party declaration): The existence of a company liability insurance for personal injury with a coverage sum of at least 2 million. EURO and for other damages with a coverage of at least 1 million. EURO twice maximized in each insurance year. Note: If the duration of the insurance contract does not cover the duration of the contract (including any extensions) of the advertised service, the applicant declares by submitting the application that he will extend the insurance according to the duration of the contract. If the current amount of cover at the time of the application for participation is lower than the amount specified in this document, the applicant declares by ticking the subordinate field and his signature that, in the event of the award of the contract, an increase to the required amount of cover will take place at the latest one week after the award of the contract and this will be proven to the client by submitting suitable documentation without being requested. The existence of liability insurance must be proven by submitting a copy of the insurance confirmation with the submission of this request for participation. The proof must not be older than 1 year.
Annual turnover (with the application for participation; by means of self-declaration): Information on the total turnover (net) and the turnover (net) for services comparable to the subject of the contract (for the years 2023 - 2025).
Copy of the entry in the commercial register or comparable proof (not older than 6 months upon submission of the request to participate) (with the request to participate); By means of a third-party declaration: Proof of competence and permission to practice the profession submit the entry in a professional or commercial register (e.g. trade register extract) or another certificate or declaration in accordance with Annex XI of Directive 2014/24/EU / Annex VII Part B and C of Directive 2009/81/EC, if this is in accordance with the legislation of the respective establishment or company. The country of origin is a prerequisite for the permitted professional practice. The proof must not be older than 6 months at the time of submission of the request to participate.
LkSG (with the request to participate); By self-declaration: confirmation that no fines have been imposed under the LkSG (Supply Chain Due Diligence Act) or under comparable regulations of other EU Member States against my/our company or a person whose conduct is attributable to my/our company and who, for a reasonable time until proven self-cleaning pursuant to § 125 GWB, entitle them to an exclusion from participation in a procurement procedure pursuant to § 22 LkSG.
MiLoG (with the application for participation; by means of self-declaration): confirmation that no prerequisites for exclusion according to § 19 para. 1 MiLoG.
Appendix 3 Annex 8 References (with request to participate); By self-declaration: References to the minimum requirement Three completed reference projects of the last five years from the date of publication which are comparable to the subject matter of the contract (preparation/implementation of audit according to ISO 27001 on the basis of IT-Grundschutz) and must each meet the following requirements: - At least 2 references should have been jointly participated in at least 2 of the 4 project managers required for the project team of HIL - At least 2 of the 3 references should have been in the defence sector (providers of security-critical products, technologies and services for armed forces and/or security authorities) - An audit must have been successfully carried out in at least 2 of the 3 references references for deposition 1) It will be max. three completed reference projects of the last five years from the date of publication, which are comparable to the subject matter of the contract (preparation/implementation of audit according to ISO 27001 based on IT basic protection). The focus here is on the number of references of the project managers, which are intended for the HIL project team. A maximum of three completed reference projects of the last five years from the date of publication, which have been comparable to the subject of the contract (preparation/implementation of audit according to ISO 27001 on the basis of IT basic protection) and in the defence sector (providers of security-critical products, technologies and services for armed forces and/or security authorities), will be assessed. 3) A maximum of three completed reference projects of the last five years from the date of publication are assessed, which are comparable to the subject matter of the contract (preparation/implementation of audit according to ISO 27001 on the basis of IT basic protection) and maintain a successfully completed audit. 4) A maximum of three completed reference projects of the last five years from the date of publication, which are comparable to the subject of the contract (preparation/implementation of audit according to ISO 27001 on the basis of IT-Grundschutz) and are part of Log Sys BW (Logistical System of the Bundeswehr).
Language level German language (with the application for participation; by means of self-declaration): self-declaration on the processing of contracts and orders in German language It must be confirmed that the staff intended for the processing of contracts and the execution of orders speaks and writes the German language (Level C1 of the Common European Framework of Reference for Languages, GER).
DIN ISO 27001 certification (with the application for participation); By means of a third-party declaration: certification according to ISO 27001 or an equivalent level of information security by an accredited company. The certificate must cover the required performance. The existing certification by an accredited company is proven by the attached certificate. The certificate must be valid at the time of submission of the request for participation.
Proof of business activity with focus on information security, KRITIS, cyber security (with the application for participation; by self-declaration): The bidder must submit a written description of the activity, which proves at least three years of active business activity in the field of information security in the market. The documentation must show that the content focus of the company is demonstrably on information and cyber security. In addition, a description of activities from the last 3 years in the regulatory environment of KRITIS operators must be provided, which clearly shows the sector, the security measures and the reference to § 8a BSIG. In order to protect non-disclosure agreements, this job description may be completely anonymized, provided that the technical content remains auditable for the client.
Proof of qualification as a qualified IT security service provider (with the request to participate; by self-declaration): To prove the required expertise, reliability and technical performance in the field of IT security, the bidder must prove that he is recognized and listed by the Federal Office for Information Security (BSI) as an IT security service provider. The proof shall be provided by giving the unique body ID/laboratory ID. Note: The awarding authority reserves the right to check the information of the tenderer for timeliness and validity by comparison with the official and publicly available BSI lists. If the applicant/tenderer uses other companies to prove the suitability of the capacities (eligibility loan / subcontractor), the corresponding proof of the BSI must be submitted for the company that performs the partial service operationally.
Project team (with the application for participation; by means of self-declaration): Proof of personnel performance through submission of short CVs (CVs) initially anonymized in the competition for the HIL intended core team. Minimum Requirement: The team must fill at least the following roles: - 4 x project manager - 3 - 5 team members - 1 x basic protection consultant The minimum requirements for each role are set out in the separate Annexes Appendix 3 Annex 9.1 CV template Project Manager, Appendix 3 Annex 9.2 CV template Team member and Appendix 3 Annex 9.3 CV template Basic Protection Advisor.
3.4 Turnover - Proof of economic performance, total turnover (net) and turnover (net) for the services to be provided that are comparable to the object of the contract (preparation/implementation of audit according to ISO 27001 based on IT basic protection)
4.2 References in a comparable environment taking into account the number of project managers - max. three completed reference projects of the last five years from the date of publication, which are comparable to the subject matter of the contract (preparation/implementation of audit according to ISO 27001 based on IT basic protection). The focus here is on the number of references of the project managers, which are intended for the HIL project team.
4.3 References in the field of defence (provider of security-critical products, technologies and services for armed forces and/or security authorities) - max. three completed reference projects in the last five years from the date of publication, which have been comparable to the subject of the contract (preparation/implementation of audit according to ISO 27001 based on IT basic protection) and in the defence sector (providers of security-critical products, technologies and services for armed forces and/or security authorities).
4.4 References with successfully performed auditing - It will be max. three completed reference projects of the last five years from the date of publication, which are comparable to the subject-matter of the contract (preparation/implementation of audit according to ISO 27001 on the basis of IT-Grundschutz) and include a successfully executed audit.
4.5 References in Log Sys BW - It will be max. three completed reference projects of the last five years from the date of publication, which are comparable to the subject of the contract (preparation/implementation of audit according to ISO 27001 on the basis of IT-Grundschutz) and part of the Log Sys BW (Logistical System of the Bundeswehr).
What this buyer bought before
Recent IT contracts awarded by the same buyer, from published award notices.
Einführung S/4 HANA ex-Post 2
Winner: abat AG
€22.8m
Betrieb IT Syteme HIL
Winner: CGI
Einführung S/4 HANA ex-Post
Winner: abat AG
Verfahrensbetreuung SAP 2026+
Winner: abat AG
Win it with SalesDots
Read the documents for you
SalesDots fetches the tender documents (or takes your upload when a platform does not allow it) and answers the two questions that matter first: what the buyer wants built, and what you must prove to take part, each with the exact quote and page.
Analyse documentsMatch it with your profile
Every certificate, reference and role is checked against your company: green when you have it, amber when it expires before the deadline, grey when it needs a look.
Check my fitPrepare your response
Turn the conditions into a bid checklist with owners and due dates, draft the questions to the buyer and keep the team on one plan.
Start a responseNever miss a change
Track the deadline, amendments and answers to clarification questions, and get similar tenders and re-tenders before they are published.
Track this tenderSource: Tenders Electronic Daily (TED), Official Journal of the EU. SalesDots is not the contracting authority; offers are submitted only through the buyer's platform.