Technical security assistance
At a glance
GIE SESAM-Vitale (Le mans cedex 2, France) is tendering: Technical security assistance. Offers are due 2 Nov 2026, 11:00 CET. Estimated value €1.1m, 36-month contract, 5 lots. Bidders must show, among other things: certificates, references, key people, minimum turnover.
- 2 Nov 2026, 11:00 CET
- Deadline
- €1.1m
- Estimated value
- 36 months
- Duration
- Negotiated with call
- Procedure
- IT services: consulting, software development, Internet and support (72000000)
- Main CPV
- 2 Oct 2026
- Published
Translated from the official notice. The original text is the legally binding one.
What the buyer wants
O The development or analysis of security architectures; o PKI infrastructures, including the writing of certification policies; o The implementation of security training and training materials; o The implementation of security components such as Bastion, Reverse-proxy, authentication server (RSA Access Manager type), SSO server; o The completion of expertise or study on a component, protocol, or security regulation; o The implementation of services related to the Business Continuity Plan of the GIE SESAM-Vitale; o Analysis of security records and computer records and freedoms of publishers applying for a referencing process; o Providing a reversibility file allowing a new Holder to continue work on a complex subject. Lot 1 is awarded to an operator. A Batch 1 operator may also be awarded Batch 2 and 4 but cannot be awarded Batch 3. The contract is awarded in the form of a procedure with negotiation within the meaning of Articles L2124-1, L2124-3, R2124-3, R2142-17 and R2161-12 to R2161-20 of the Code of Public Order.
Le marché porte sur la réalisation de prestations d'assistance technique dans le domaine de la sécurité des systèmes d'information couvrant les domaines suivants : conseils en sécurité, analyses de risques ou audits, expertise en mise en oeuvre en cryptographie.
Lots (5)
Lot 1Conseil et expertise en sécurité des SI
€1.1m · 36 monthsO The development or analysis of security architectures; o PKI infrastructures, including the writing of certification policies; o The implementation of security training and training materials; o The implementation of security components such as Bastion, Reverse-proxy, authentication server (RSA Access Manager type), SSO server; o The completion of expertise or study on a component, protocol, or security regulation; o The implementation of services related to the Business Continuity Plan of the GIE SESAM-Vitale; o Analysis of security records and computer records and freedoms of publishers applying for a referencing process; o Providing a reversibility file allowing a new Holder to continue work on a complex subject. Lot 1 is awarded to an operator. A Batch 1 operator may also be awarded Batch 2 and 4 but cannot be awarded Batch 3. The contract is awarded in the form of a procedure with negotiation within the meaning of Articles L2124-1, L2124-3, R2124-3, R2142-17 and R2161-12 to R2161-20 of the Code of Public Order.
Lot 2Analyses de risques et vie privée
€600,000 · 36 monthsIl s'agit de réaliser des prestations pouvant concerner : o Analyses de risques selon la méthodologie (EBIOS ou préconisée par le GIE SESAM-Vitale) adaptée au contexte du GIE SESAM-Vitale, l'accompagnement des équipes projet ou avant-projet pour identifier, suivre et traiter les risques résiduels. Ces analyses de risques pourront être réalisées sur des applications en phase d'avant-projet ou en phase de réalisation et également sur des applications en production. o Réaliser ou mettre à jour des Analyses d'impact sur la protection des données (AIPD). o Réaliser ou mettre à jour les politiques de gestion de données à caractère personnel. o Fournir un dossier de réversibilité permettant à un nouveau Titulaire de continuer les travaux sur un sujet complexe. Le lot 2 est attribué à un opérateur. Un opérateur titulaire du lot 1 2 peut également être attributaire des lots 2 1 et 4, mais ne peut pas se voir attribuer le lot 3. Le marché est passé sous la forme d'une procédure avec négociation au sens des articles L2124-1, L2124-3, R2124-3, R2142-17 et R2161-12 à R2161-20 du Code de la commande publique.
Lot 3Audits sécuritaires et tests d'intrusion
€700,000 · 36 monthsIl s'agit de réaliser des prestations sécuritaires visant à la préparation et la réalisation d'audits de Sécurité. Les prestations attendues sur les audits pourront porter sur : o Des audits de sécurité physique de site (audit environnemental), o Des audits de conformité à un référentiel, o Des audits organisationnels o Des audits de configuration système ou applicatif, o Des audits des pratiques d'exploitation, o Des audits de codes source, o Des audits d'offres de sécurité d'industriels (participation à l'évaluation dans le cadre des marchés publics) o L'élaboration des référentiels correspondants à ces types d'audits o Des tests d'intrusion réseaux et applicatifs sur des applications Internet, des serveurs connectés à Internet ou à des réseaux TCP-IP privés, des infrastructures de flux TCP-IP (routeur, proxy, reverse proxy, firewall, portail) o Des tests de vérification des correctifs. o Le suivi des plans d'actions associés aux différents audits o Des analyses d'appels d'offres o Des audits de code source embarqué o Des audits sur des dispositifs embarqués o Fournir un dossier de réversibilité permettant à un nouveau Titulaire de continuer les travaux sur un sujet complexe. Le lot 3 est attribué à deux opérateurs. Un opérateur titulaire du lot 3 ne peut pas se voir attribuer les lots 1 et/ou 2 et/ou 4. Le marché est passé sous la forme d'une procédure avec négociation au sens des articles L2124-1, L2124-3, R2124-3, R2142-17 et R2161-12 à R2161-20 du Code de la commande publique.
Lot 4
€350,000 · 36 monthsLot 5Expertise et mise en œuvre en cryptographie
€350,000 · 36 monthsIl s’agit de réaliser des prestations pouvant concerner : o La réalisation d’une expertise ou étude sur un algorithme cryptographique (ou son implémentation) o Les infrastructures PKI et notamment l’écriture de politiques de certification, o La définition d’une architecture cryptographique et/ou de l’outillage associé o La spécification et/ou le développement de l’outillage (pour la gestion des clés, le pilotage des HSM et les opérations de recette/validation) nécessaire à l’équipe de la gestion des clés. o La recette des outils et mécanismes cryptographiques. o Réalisation d’inventaire cryptographique o Mise en conformité Cryptographie Post Quantique o Définition de politique cryptographique o Fournir un dossier de réversibilité permettant à un nouveau Titulaire de continuer les travaux sur un sujet complexe. Le lot 4 est attribué à un opérateur. Cet opérateur peut également se voir attribuer le lot 1 et le lot 2 et non le lot 3. Le marché est passé sous la forme d’une procédure avec négociation au sens des articles L2124-1, L2124-3, R2124-3, R2142-17 et R2161-12 à R2161-20 du Code de la commande publique.
Can you bid? Your readiness check
These are the conditions this notice asks bidders to prove. In SalesDots each one is checked against your company profile: certificates with their validity dates, delivered references and your people.
- In your profile
Certificates
Company or personnel certificates named in the notice
- In your profile
References
Similar contracts delivered before
- Not in your profile yet
Key people
Named roles, CVs or minimum team
- In your profile
Minimum turnover
Minimum annual turnover or financial standing
Detected automatically in the published notice. Always confirm against the tender documents.
Check it against my companyShow the notice text (13)
Justification 1: The applicant will provide, for the last three available years (or any other means for newly created companies), a statement of the total turnover of his company, as well as the turnover relating to services similar to those provided by his company in this contract. Specific minimum level(s) required for the proof No 1: the minimum annual total turnover required for the: - Lot 1 "SIS Security Advice and Expertise": €393,000 excluding tax; * No percentage statement will be taken into account in the overall assessment of justification #1. Proof No. 1 will be evaluated in the following areas: assessment of the CA for services similar to the object of the lot and the applicant's economic dependence on the PAN-26-8 lot 1 market.
Justification 2: The applicant shall list the main services carried out over the last three (3) years in fields identical to those covered by this contract, indicating the object, amount, date and public or private recipient in the following fields for Lot 1 in Security Advice. The candidate will limit the number of references provided to 10 and number them. Only the first 10 references less than or equal to 3 years will be analysed and if no numbering only the most recent 10. Specific level(s) required for substantiation 2: None. Proof No 2 will be evaluated according to the following lines: number, amount, duration of services similar to those covered by this contract.
Supporting document No. 3: The applicant will present the academic and professional qualifications of the executives of his company and of the service providers of the same nature as those of this tender. Specific level(s) required for substantiation 3: The following academic and professional qualifications must be present: - for Lot 1 : o Security Experts : 5, o Security Engineer : 5. A security expert must have at least 8 years' experience in computer security, a security engineer with 3 years' experience in computer security, and a security auditor with 3 years' experience in information systems security audit or intrusion testing.
Rationale 1: will be evaluated according to 2 axes: assessment of the CA for services similar to the object of the lot over the last three years and the applicant's economic dependence on the PAN-26-8 lot 2 market, as well as overall turnover over the last three years. Minimum annual total turnover required for: Lot 2 - Risk analysis and privacy is EUR 225 000 HT per reference year * No percentage statement will be taken into account in the overall assessment of justification No 1.
Justification 2: will be assessed according to the following axis: the object, number, amount, date, duration and recipient of services similar to those covered by this contract. Only the first 10 numbered references will be analysed. In the absence of numbering, the 10 references, the most recent less than or equal to 3 years will be analysed.
Rationale 3: will be evaluated according to the following axis: the number and level of educational and professional qualifications of the profiles requested under this contract. A security expert must have at least 8 years' experience in computer security, a security engineer with 3 years' experience in computer security, and a security auditor with 3 years' experience in information systems security audit or intrusion testing. The following academic and professional qualifications must be present: for Lot No. 2: Security Experts: 4, Security Engineer: 3.
Case No. 1: The applicant will provide, for the last three available years (or any other means for newly created companies), a statement of the total turnover of his company, as well as the turnover relating to services similar to those covered by the present contract carried out by his company. Specific minimum level(s) required for proof No 1: the minimum annual total turnover required for: Lot No 3 - Security audits and intrusion tests are €262,000 HT per reference year. * No percentage statement will be taken into account in the overall assessment of justification #1.
Justification 2: will be evaluated according to the following axis: the object, the recipient, the number, the amount, the duration of the services similar to those covered by this contract. Only the first 10 numbered references will be analysed. In the absence of numbering, the 10 references, the most recent less than or equal to 3 years will be analysed.
Justification 3: will be assessed according to the following lines: The candidate will present the academic and professional qualifications of the executives of his company and of the service providers of the same nature as those of this call for tenders. Specific level(s) required for substantiation 3: The following academic and professional qualifications must be present: for Lot 3 : Security Experts : 4, Security Engineer : 3, Security Auditor : 3, Security Auditor : 2. A security expert must have at least 8 years of experience in computer security, a security engineer with 3 years of experience in computer security, a security auditor with 3 years of experience in security audit of information systems or intrusion tests and a security auditor with 3 years of experience in the development and audits of embedded systems (devices and source code (language C)).
Justification 4: The candidate will present the list of PASSI certificates issued by the ANSSI which he or she has at his or her disposal attesting to his or her qualification to carry out security audits of information systems. Further evidence of equivalent measures, particularly the fact that the candidate is engaged in a PASSI qualification process, is accepted. Specific level(s) of qualification(s) required for substantiation #4 will be taken into account for substantiation #3 of qualification(s) or qualification(s) (with ANSSI) on all PASSI competencies (except PASSI LPM), namely: architecture audit, configuration audit, source code audit, intrusion tests, organizational and physical audit. A candidate who declares himself or herself to be PASSI qualified or in the process of being qualified without providing the supporting evidence will be rejected for Lot 3.
Justification 5: The following areas will be evaluated: the rationale for the CESTI accreditation with the ANSSI on all the following ranges, intrusion detection, anti-virus, malicious code protection, firewall, data erasure, security administration and supervision, identification, authentication and access control, secure communication, secure messaging, secure storage, secure execution environment. Only applications presenting the proof of accreditation in all the scopes described above will be analysed. Any applications that submit a declaration of approval without presenting the supporting documents, or if the supporting documents do not contain all the scopes mentioned, will be rejected.
Case No. 1: The applicant will provide, for the last three available years (or any other means for newly created companies), a statement of the total turnover of his company, as well as the turnover relating to services similar to those covered by this contract carried out by his company. Specific level(s) required for proof No 1: the minimum annual total turnover required for: Lot No 4 - Expertise and implementation in cryptography is 131,000 euros HT per reference year. * No percentage statement will be taken into account in the overall assessment of justification #1.
Supporting document No. 3: The applicant will present the academic and professional qualifications of the executives of his company and of the service providers of the same nature as those of this tender. Specific level(s) required for substantiation 3: The following educational and professional qualifications must be present: For Lot 4 : Expert Cryptography : 2, Engineer Cryptography : 2, Developer Security Embarked Systems : 2, Developer Security Software : 2, Validator Security Embarked Systems : 2, Validator Security Software : 2. An expert in Cryptography must have at least 8 years of experience in the field. A Cryptography Engineer must have at least 5 years of experience in the field. An Embarked Systems Security Developer must have at least 5 years of experience in the field. A software security developer must demonstrate at least 3 years of experience in the field. An Embarked Systems Security Validator must have at least 5 years of experience in the field. A Software Security validator must demonstrate at least 3 years of experience in the field.
How offers are scored
- Critère financier de l'offre50%
- Critère technique40%
- Critère RSE10%
What this buyer bought before
Recent IT contracts awarded by the same buyer, from published award notices.
Assistance technique réalisation
Winner: ACCENTURE SAS
€26.2m
7 Jul 2026
PAN-25-2 Assistance technique études fonctionnelles
Winner: Ernst & Young Advisory
€990,792
27 Jan 2026
Numérisation des photos pour la personnalisation des cartes Vitale
Winner: LUMINESS
€7.6m
19 Mar 2025
Ingénierie et visualisation data
Winner: MICROPOLE
€2.5m
24 Feb 2025
France-Le Mans: Computer-related services
Winner: worldline
€12.4m
France-Le Mans: Information technology requirements review services
Winner: wavestone
€472,235
Win it with SalesDots
Read the documents for you
SalesDots fetches the tender documents (or takes your upload when a platform does not allow it) and answers the two questions that matter first: what the buyer wants built, and what you must prove to take part, each with the exact quote and page.
Analyse documentsMatch it with your profile
Every certificate, reference and role is checked against your company: green when you have it, amber when it expires before the deadline, grey when it needs a look.
Check my fitPrepare your response
Turn the conditions into a bid checklist with owners and due dates, draft the questions to the buyer and keep the team on one plan.
Start a responseNever miss a change
Track the deadline, amendments and answers to clarification questions, and get similar tenders and re-tenders before they are published.
Track this tenderSource: Tenders Electronic Daily (TED), Official Journal of the EU. SalesDots is not the contracting authority; offers are submitted only through the buyer's platform.