[codicts-css-switcher id=”346″]

Global Law Experts Logo
it procurement romania

How to Update IT Public Procurement Contracts in Romania for the 2026 EU Cybersecurity Resilience Package

By Global Law Experts
– posted 2 hours ago

IT procurement Romania teams face a structural shift in 2026 as the EU’s cybersecurity framework moves security from a best-practice afterthought to a mandatory, evidenced obligation embedded in tender documents and signed contracts. Contracting authorities and IT suppliers now need concrete, jurisdiction-specific steps to revise request-for-proposal documents, allocate supplier cybersecurity obligations, map certification and incident-reporting duties, and rework performance securities and remedies under Romanian procurement law. This guide sets out a stepwise playbook, with a numbered timeline, required-document checklists, cost tables and sample clause language, written for public buyers, in-house counsel and vendors who must act before the next procurement cycle.

It reflects the interaction between EU instruments such as Directive 2014/24/EU and the NIS2 Directive and the national procedural framework administered by Romania’s national procurement authority. Where the relevant package text or national implementing measures remain pending, that is flagged so you can build update mechanisms into your contracts rather than lock in provisions that will soon change.

Overview, why update IT procurement contracts now

The evolving EU cybersecurity framework layers new expectations on top of an already dense regulatory environment. It interacts directly with the NIS2 Directive (Directive (EU) 2022/2555), which defines essential and important entities, and with the public procurement framework in Directive 2014/24/EU, which governs how technical specifications, selection criteria and award criteria may be set. Instruments such as the Cyber Resilience Act (Regulation (EU) 2024/2847), which sets cybersecurity requirements for products with digital elements, are also relevant to connected-product procurements. For IT procurement Romania practitioners, the practical consequence is that cybersecurity can no longer sit in an annex, it must be expressed as measurable contractual obligations, backed by evidence and remedies.

What the current EU framework changes

  • Mandatory baselines. Supplier security obligations move from voluntary best practice toward express, minimum-standard contractual duties.
  • Certification. Recognised EU certification schemes may become relevant preconditions for certain cybersecurity-relevant procurements.
  • Incident reporting. Stricter notification timelines and coordination duties toward national authorities apply, particularly under NIS2.
  • Securities and remedies. Performance securities may need to cover cyber-related non-performance and remediation costs explicitly.
  • Audit rights. Stronger rights to testing, audit and supplier cooperation.

Who should read this guide

Public procurement officers, in-house counsel for both contracting authorities and suppliers, IT vendors bidding for public contracts, and contract managers responsible for post-award monitoring. Each has a distinct role in the twelve-step process below, and each will find drafting notes tailored to their responsibilities.

Is Romania an IT hub? Romania hosts a substantial software, cloud and managed-services ecosystem supplying both domestic public bodies and cross-border clients. That vendor depth means IT procurement Romania authorities have real competitive choice, but it also raises the compliance stakes: a large supplier base must be assessed consistently against new cybersecurity criteria without breaching the non-discrimination and proportionality rules in Directive 2014/24/EU.

Eligibility, which contracts and procurements are affected

Not every public contract needs rewriting. The task is to identify which procurements are cybersecurity-relevant and therefore in scope for the enhanced obligations. This scoping decision drives everything that follows, so it must be documented and defensible.

Procurement types most likely to be affected include information and communication technology (ICT) supply, cloud services, managed and hosted services, software development, systems integration, and embedded or connected products. Entity types include classic contracting authorities, utilities and, importantly, operators of essential and important services within the NIS2 scope, where the overlap between procurement law and sectoral cybersecurity obligations is most acute.

Types of procurement procedures and implications

  • Open procedure. Widest competition; security requirements must be set clearly in the specification up front, as there is limited scope to negotiate afterward.
  • Restricted procedure. Allows a selection stage where cybersecurity capability and certification can be tested before invitation to tender.
  • Competitive procedure with negotiation / competitive dialogue. Useful for complex, security-critical systems where the authority needs to refine security requirements with the market before finalising terms.

When to treat an award as cybersecurity-relevant

Treat an award as cybersecurity-relevant where the contract involves processing of sensitive or large-scale data, provision of critical infrastructure or essential-service functions, network-facing systems, or where the supplier will have privileged access to the authority’s environment. The safest approach for IT procurement Romania authorities is a documented risk-classification step (see Step 3 below) rather than an intuitive judgement.

Which suppliers need certification? Those bidding for procurements classified as security-critical, or where recognised EU certification schemes referenced in EU law or in national implementing measures apply. Until final lists are published, reference “recognised EU schemes or equivalents” with a contractual mechanism to update accepted schemes.

Step-by-step: how to update IT procurement contracts

The following twelve steps take an authority from scope-mapping to handover. Each step names the owner and gives a realistic duration. Run steps 1–3 sequentially; several later steps (4–8) can be parallelised to compress the overall timeline.

Step Who (owner / role) Typical duration
1. Map scope & baseline (identify affected contracts) Procurement officer + IT security lead 1–2 weeks
2. Legal review of EU framework & national law applicability In-house or external counsel 1 week
3. Risk classification of procurement (security-critical?) IT security + procurement 1 week
4. Update procurement documents (tender specs, award criteria) Procurement officer + counsel 2–3 weeks
5. Draft supplier cybersecurity clause set Counsel + IT security 1 week
6. Define certification & evidence requirements Procurement officer + supplier engagement 1–2 weeks
7. Amend performance securities & guarantee wording Finance/legal + external counsel 1–2 weeks
8. Update contract templates & forms (SLA, SOW) Procurement + legal 1–2 weeks
9. Supplier due diligence & pre-award checks Procurement + compliance 2–4 weeks
10. Incorporate audit, reporting & incident-response terms IT security + legal 1 week
11. Post-award monitoring processes set up Contract manager + IT security Ongoing (initial 2–4 weeks)
12. Training & handover to contract managers Procurement + training team 1 week

Steps 1–3: scope, legal review and risk classification

Begin by inventorying live and pipeline contracts and tagging those that touch ICT, cloud, managed services or connected products. For each, record data sensitivity, network exposure and NIS2 relevance. The legal review (Step 2) should confirm whether Directive 2014/24/EU procedural constraints, NIS2 obligations, or national implementing acts published in Monitorul Oficial apply. Step 3 assigns a risk tier, this tier determines how demanding the certification, audit and security-obligation clauses need to be, keeping requirements proportionate as Directive 2014/24/EU demands.

Steps 4–6: procurement documents, security clauses and certification

When updating specifications and award criteria, ensure cybersecurity criteria are linked to the subject matter of the contract, as required for lawful award criteria under Directive 2014/24/EU. A sample security-obligations clause:

“The Supplier shall implement and maintain, throughout the Term, technical and organisational security measures no less protective than [recognised EU baseline / referenced scheme], shall not degrade such measures without the Authority’s prior written consent, and shall promptly remediate any identified vulnerability within the timeframes set out in Schedule [X].”

For certification (Step 6), reference accepted schemes and versions, and include an evidence obligation:

“The Supplier shall hold and maintain valid certification under [recognised EU certification scheme or equivalent] for the duration of the Contract, and shall provide the certifying body’s current attestation on award and upon each renewal or surveillance audit.”

Steps 7–8: performance securities and contract templates

Amend guarantee wording so that drawdown triggers include cyber-specific failures. A sample redraft note for the performance-security clause:

“The Authority may call on the Performance Security where the Supplier fails to meet a Security Obligation, fails to notify a reportable incident within the Notification Window, or fails to complete Remediation within the Cure Period, to the extent of the reasonable costs of remediation and any liquidated sums specified.”

Then align the SLA and statement of work with these definitions so the security terms, reporting windows and remedies are internally consistent.

Steps 9–10: due diligence, audit and incident-response terms

Pre-award due diligence should validate certificates with certifying bodies and review the supplier’s incident-response plan and subcontractor matrix. Build in flow-down and audit rights:

“The Supplier shall procure that each subcontractor performing Security-Relevant Services accepts obligations equivalent to those in this Contract, and shall permit the Authority (or its appointed auditor) to audit compliance on reasonable notice, and without notice following a reportable incident.”

Steps 11–12: monitoring and handover

Establish a post-award monitoring cadence, evidence collection, certificate-expiry tracking and incident logs, and hand the contract to managers with training on the new obligations. For any IT procurement Romania programme, this final step is where compliance either becomes operational or quietly lapses; treat it as a controlled handover, not an afterthought.

Required documents, what to collect pre- and post-award

Standardise the document set so bids can be compared consistently and post-award files support enforcement. Define confidentiality and retention terms for sensitive evidence such as penetration-test reports.

Document Who provides Purpose / notes
Supplier cybersecurity policy & attestation Supplier Baseline security posture
Relevant certificates (per EU / ENISA-recognised schemes) Supplier Evidence of certification; state accepted schemes and versions
Evidence of incident response capability (IR plan) Supplier Demonstrates preparedness & contact points
Subcontractor flow-down matrix Supplier Shows subcontractor dependencies & compliance
Performance security instrument (bond/guarantee) Supplier / guarantor Financial security linked to performance and remedies
Insurance certificates (cyber insurance) Supplier Risk transfer / mitigation evidence
Audit & penetration test reports (redacted) Supplier For higher-risk procurements; define retention & confidentiality
Declaration of compliance with procurement specifications Supplier Standard tender submission requirement
Post-award monitoring plan Contracting authority Internal control & compliance tracking

Timeline & deadlines for it procurement Romania stages

Enhanced cybersecurity checks add verification time to the procurement calendar, so build the following buffers into your schedule rather than compressing the standstill or evaluation phases.

  • Pre-award certification verification: allow time (as a working estimate, several weeks) to validate certificates with certifying bodies and to review incident-response and subcontractor documentation before award.
  • Evaluation of security award criteria: add time where cybersecurity is scored, so the panel can assess evidence properly.
  • Mandatory standstill: preserve the standstill period required under national procurement rules before contract signature; do not shorten it to recover time lost elsewhere. The applicable duration is set by Romanian procurement legislation and depends on the value and notification method.
  • Contract signature: confirm the performance security instrument and current certification are in place before signing.
  • Certification-update deadlines: set contractual dates for renewal and surveillance evidence, and a fixed window for the supplier to supply updated attestations.

Across a full IT procurement Romania cycle, expect the cybersecurity enhancements to add several weeks in aggregate; plan procurement launch dates accordingly.

Costs & fees, who bears what and budgeting

Cybersecurity compliance carries real cost, most of which suppliers price into bids. Contracting authorities should evaluate price against compliance transparently and avoid criteria that disproportionately favour incumbents. All figures below are indicative market estimates for budgeting only, not guaranteed prices, and will vary significantly by scope, scheme and provider.

Cost item Typical payer Notes
Supplier certification (initial) Supplier (priced into bid) Cost depends on scope and scheme; obtain current quotes
Certification renewal / surveillance Supplier Annual recurring cost
Independent security audit / pentest Supplier / sometimes buyer (high risk) Depends on complexity and scope
Cyber insurance premium Supplier Varies by sector/risk; may be required at award
Administrative compliance & verification Contracting authority Internal resource time + possible external counsel fees
Performance bond (financial security) Supplier (cost of bond) Bank fee typically a small percentage of bond value
External legal advice (procurement & guarantees) Either party (buyer often pays) Varies; include in procurement budget

What may change further, obligations flowing from the EU framework

The EU cybersecurity framework is expected to continue converting several previously discretionary practices into express obligations, but the precise applicability in any given tender will depend on Member State implementation and national procurement rules administered by Romania’s procurement authority. Until relevant implementing acts appear in Monitorul Oficial, treat the specifics below as the expected direction of travel and build update mechanisms into contracts.

Anticipated obligations include express supplier-security duties with a minimum baseline; certification requirements tied to recognised EU schemes for defined procurement categories; stricter incident-reporting timelines coordinated with national authorities and consistent with ENISA guidance; and a clearer liability and remedy regime for cyber-related non-performance. The overlap with the NIS2 Directive means that where a supplier is itself an essential or important entity, its statutory obligations and its contractual obligations must be aligned to avoid gaps.

Area Traditional position Direction of travel
Supplier security obligations Best practice; contractual Express, possibly mandatory obligations with minimum baseline
Certification Voluntary / sectoral Specified schemes may be required for certain procurements
Incident reporting Contract-defined, flexible SLAs Stricter timelines and mandatory reporting to national/EU authorities
Performance securities Financial focus (delivery defaults) May need to cover cyber non-performance / remediation costs
Audit & testing rights Negotiated Stronger rights to testing/audits & supplier cooperation duties

Wider digital-single-market instruments, including proposals such as the Digital Networks Act, form a further regulatory overlay that can interact with connectivity-heavy procurements; where relevant, cross-reference those rules so that security and network-resilience obligations do not conflict. For IT procurement Romania authorities, the safest posture is to draft to the higher expected standard while retaining a contractual variation right to conform to the final national text.

Common pitfalls & recommended drafting fixes

  • Vague security obligations. “Reasonable security measures” is difficult to enforce. Fix: reference a named baseline or scheme and attach measurable requirements in a schedule.
  • Missing subcontractor flow-down. Obligations that stop at the prime supplier leave the real risk uncovered. Fix: require equivalent obligations down the chain and disclosure of security-relevant subcontractors.
  • Unclear incident remedies. Contracts that mention reporting but not consequences give the authority no leverage. Fix: define notification windows, cure periods, liquidated remediation sums and drawdown triggers.
  • Improper bond language. A performance bond drafted only for delivery default will not respond to a cyber failure. Fix: extend drawdown triggers to security-obligation and remediation failures with precise definitions.
  • Certification with no update mechanism. Hard-coding a scheme that is later superseded creates non-compliance. Fix: reference “recognised EU schemes or equivalents” plus a right to update accepted schemes.
  • Disproportionate criteria. Over-specified requirements can breach Directive 2014/24/EU proportionality and non-discrimination rules. Fix: calibrate requirements to the documented risk tier.

Practical annexes & sample clauses

The clauses below are illustrative templates for adaptation by qualified counsel, not legal advice. They should be tailored to the risk tier of each procurement and reconciled with your national procurement rules and the applicable EU framework.

Security obligations. “The Supplier shall implement, maintain and continually improve technical and organisational measures no less protective than [named baseline/scheme], and shall not materially reduce such measures without the Authority’s prior written consent.”

Certification & evidence. “The Supplier warrants that it holds valid certification under [recognised EU scheme or equivalent] and shall furnish current attestations on award, on renewal, and within [10] business days of any request by the Authority.”

Incident reporting. “The Supplier shall notify the Authority and, where required, the competent national authority of any reportable incident within the period specified in Schedule [X] of becoming aware, providing the information specified therein and updates until closure.”

Audit rights. “The Authority may audit the Supplier’s compliance on [30] days’ notice, and without notice following a reportable incident, and the Supplier shall provide reasonable cooperation and access.”

Performance-security drawdown. “The Authority may call the Performance Security to the extent of remediation costs and any liquidated sums where the Supplier breaches a Security Obligation, fails to report within the Notification Window, or fails to remediate within the Cure Period.”

For deeper drafting, an IT Procurement Cybersecurity Contract Update Checklist (Romania) can be used as a working document alongside these clauses. Authorities and suppliers seeking jurisdiction-specific drafting should consult a qualified Romanian technology and commercial lawyer, and may review the Romania technology practice resources and the Romania/Technology lawyer directory for specialist counsel.

In summary, IT procurement Romania authorities and suppliers should treat the developing EU cybersecurity framework as a prompt to rebuild their procurement documents around measurable security obligations, evidenced certification, disciplined incident reporting and remedies-backed performance securities, while retaining update mechanisms until the final EU and national texts are settled. Acting now, before the next procurement cycle, converts a compliance risk into an orderly, defensible process.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Razvan Alexandru Olaru at Olawru, a member of the Global Law Experts network.

Sources

  1. Directive 2014/24/EU on public procurement (EUR-Lex)
  2. Directive (EU) 2022/2555 (NIS2) (EUR-Lex)
  3. Regulation (EU) 2024/2847 (Cyber Resilience Act) (EUR-Lex)
  4. European Commission, Digital & Cybersecurity policy
  5. ENISA, European Union Agency for Cybersecurity
  6. Agenția Națională pentru Achiziții Publice (ANAP), Romania
  7. Monitorul Oficial / Official Gazette of Romania

FAQs

Do all Romanian public IT contracts need to change?
No. Update contracts that procure cybersecurity-relevant products or services, cloud and managed services, or where NIS2 or sectoral rules apply. Carry out the scope-mapping step first so your decision is documented and defensible across every IT procurement Romania file.
The contracting authority sets verification steps in the tender documents. Verification usually happens pre-award and may include document checks, validation with certifying bodies, or third-party attestations.
It may be possible, subject to proportionality and non-discrimination rules under Directive 2014/24/EU and Romanian procurement legislation. Include insurance as a selection or award criterion only where it is genuinely related to contract performance.
Include express drawdown triggers, failure to meet security obligations, failure to remediate after an incident, and define notification and cure periods. Use precise definitions and link recoverable remedial costs to those triggers.
Statutory reporting timelines for essential and important entities are set by NIS2 and its Romanian implementing legislation, and typically involve an early warning followed by more detailed notifications within defined periods. Reflect these as fixed SLA windows in the contract rather than open-ended obligations, and align them with the applicable statutory deadlines.
Reference the applicable EU legislative text and ENISA guidance; when national implementing acts are published in Monitorul Oficial, list the accepted schemes. Until final lists exist, use “recognised EU schemes or equivalents” with a mechanism to update.
No, this guide concerns technology and public procurement, not labour law or legal-qualification routes. Readers seeking counsel can consult the Global Law Experts network for Romanian technology and procurement advice.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Update IT Public Procurement Contracts in Romania for the 2026 EU Cybersecurity Resilience Package

Send welcome message

Custom Message