Decoding the world of cybersecurity

· ·

EU procurement reform puts resilience in bids

The European Commission’s proposed Public Procurement Act would give security, resilience and European economic sovereignty a more explicit role in public contracting.

EU procurement reform puts resilience in bids
Summary
  • The Commission proposes replacing the three principal 2014 procurement directives with a single Public Procurement Act.
  • Security and resilience would be integrated more explicitly into procurement alongside environmental, social and innovation objectives.
  • Proposed European preference criteria would use public purchasing to address economic dependency and supply resilience in strategic sectors.

The European Commission has proposed an overhaul of EU procurement rules that would give security, resilience and economic sovereignty a more explicit role in how public bodies award contracts.

The proposed Public Procurement Act, adopted by the Commission on 9 September, would replace the three main 2014 directives governing public contracts, utilities and concessions with a single regulation directly applicable across the bloc.

The reform is broader than cybersecurity and should not be treated as a cyber-specific law. Its relevance to technology risk lies in the Commission’s intention to make security and resilience formal considerations within a procurement system used to buy cloud services, data infrastructure, connected technology and systems supporting essential public functions.

The Commission says the proposal is intended to simplify procedures, create a more coherent legal framework and establish a digital EU procurement marketplace. It also proposes European preference criteria in strategic sectors, within the EU’s international legal commitments, as part of a wider effort to strengthen economic security, sovereignty and resilience.

Public procurement is one of the largest levers available to European governments. It accounts for roughly a seventh of EU economic output and covers sectors including health, energy, transport, defence, ICT and cloud services.

The Commission’s procurement material says the revised framework would provide a more coherent architecture for integrating environmental, social, innovation, security and resilience considerations into purchasing decisions.

That changes the context in which technology contracts are assessed. Procurement rules have traditionally had to balance competition, transparency and value for money. The proposed Act would make it easier to consider whether dependence on a supplier, jurisdiction or product ecosystem creates a broader resilience problem.

Those questions are already appearing elsewhere in European digital regulation. NIS2 requires many covered entities to address supply chain security as part of cyber-risk management, while DORA imposes detailed requirements around ICT third-party dependencies in financial services. The Cyber Resilience Act is imposing lifecycle-security duties on manufacturers of products with digital elements.

Procurement sits upstream of those controls. Contract terms determine which supplier is selected, what information it must provide, how vulnerabilities and incidents are handled and how difficult it will be to change provider if a dependency later becomes unacceptable.

The proposed European preference criteria add a geopolitical dimension. European institutions have become increasingly concerned about strategic dependence in technology and infrastructure markets, but reducing that dependence is difficult where domestic alternatives are limited or more expensive.

A preference for European supply can therefore create trade-offs between resilience, competition, capability and cost. Those trade-offs will be especially visible in cloud computing and other digital markets dominated by a small number of global providers.

The proposal also envisages greater digitalisation of procurement itself through an EU marketplace. Centralising more contracting activity can improve efficiency and visibility, but it will also make the resulting procurement infrastructure an important information system in its own right, handling commercially sensitive data across a large number of public bodies and suppliers.

The Act is at the beginning of the legislative process. The European Parliament and Council will now consider the proposal, and provisions covering preference criteria, security and procurement procedure may change before adoption.

The direction is nevertheless clear at proposal stage: resilience is being moved further upstream into purchasing policy. For technology contracts, that means dependency and security can increasingly be considered before an organisation becomes locked into a supplier rather than only after operational or regulatory problems emerge.

×