IT procurement Romania teams face a structural shift in 2026 as the EU’s cybersecurity framework moves security from a best-practice afterthought to a mandatory, evidenced obligation embedded in tender documents and signed contracts. Contracting authorities and IT suppliers now need concrete, jurisdiction-specific steps to revise request-for-proposal documents, allocate supplier cybersecurity obligations, map certification and incident-reporting duties, and rework performance securities and remedies under Romanian procurement law. This guide sets out a stepwise playbook, with a numbered timeline, required-document checklists, cost tables and sample clause language, written for public buyers, in-house counsel and vendors who must act before the next procurement cycle.
It reflects the interaction between EU instruments such as Directive 2014/24/EU and the NIS2 Directive and the national procedural framework administered by Romania’s national procurement authority. Where the relevant package text or national implementing measures remain pending, that is flagged so you can build update mechanisms into your contracts rather than lock in provisions that will soon change.
The evolving EU cybersecurity framework layers new expectations on top of an already dense regulatory environment. It interacts directly with the NIS2 Directive (Directive (EU) 2022/2555), which defines essential and important entities, and with the public procurement framework in Directive 2014/24/EU, which governs how technical specifications, selection criteria and award criteria may be set. Instruments such as the Cyber Resilience Act (Regulation (EU) 2024/2847), which sets cybersecurity requirements for products with digital elements, are also relevant to connected-product procurements. For IT procurement Romania practitioners, the practical consequence is that cybersecurity can no longer sit in an annex, it must be expressed as measurable contractual obligations, backed by evidence and remedies.
Public procurement officers, in-house counsel for both contracting authorities and suppliers, IT vendors bidding for public contracts, and contract managers responsible for post-award monitoring. Each has a distinct role in the twelve-step process below, and each will find drafting notes tailored to their responsibilities.
Is Romania an IT hub? Romania hosts a substantial software, cloud and managed-services ecosystem supplying both domestic public bodies and cross-border clients. That vendor depth means IT procurement Romania authorities have real competitive choice, but it also raises the compliance stakes: a large supplier base must be assessed consistently against new cybersecurity criteria without breaching the non-discrimination and proportionality rules in Directive 2014/24/EU.
Not every public contract needs rewriting. The task is to identify which procurements are cybersecurity-relevant and therefore in scope for the enhanced obligations. This scoping decision drives everything that follows, so it must be documented and defensible.
Procurement types most likely to be affected include information and communication technology (ICT) supply, cloud services, managed and hosted services, software development, systems integration, and embedded or connected products. Entity types include classic contracting authorities, utilities and, importantly, operators of essential and important services within the NIS2 scope, where the overlap between procurement law and sectoral cybersecurity obligations is most acute.
Treat an award as cybersecurity-relevant where the contract involves processing of sensitive or large-scale data, provision of critical infrastructure or essential-service functions, network-facing systems, or where the supplier will have privileged access to the authority’s environment. The safest approach for IT procurement Romania authorities is a documented risk-classification step (see Step 3 below) rather than an intuitive judgement.
Which suppliers need certification? Those bidding for procurements classified as security-critical, or where recognised EU certification schemes referenced in EU law or in national implementing measures apply. Until final lists are published, reference “recognised EU schemes or equivalents” with a contractual mechanism to update accepted schemes.
The following twelve steps take an authority from scope-mapping to handover. Each step names the owner and gives a realistic duration. Run steps 1–3 sequentially; several later steps (4–8) can be parallelised to compress the overall timeline.
| Step | Who (owner / role) | Typical duration |
|---|---|---|
| 1. Map scope & baseline (identify affected contracts) | Procurement officer + IT security lead | 1–2 weeks |
| 2. Legal review of EU framework & national law applicability | In-house or external counsel | 1 week |
| 3. Risk classification of procurement (security-critical?) | IT security + procurement | 1 week |
| 4. Update procurement documents (tender specs, award criteria) | Procurement officer + counsel | 2–3 weeks |
| 5. Draft supplier cybersecurity clause set | Counsel + IT security | 1 week |
| 6. Define certification & evidence requirements | Procurement officer + supplier engagement | 1–2 weeks |
| 7. Amend performance securities & guarantee wording | Finance/legal + external counsel | 1–2 weeks |
| 8. Update contract templates & forms (SLA, SOW) | Procurement + legal | 1–2 weeks |
| 9. Supplier due diligence & pre-award checks | Procurement + compliance | 2–4 weeks |
| 10. Incorporate audit, reporting & incident-response terms | IT security + legal | 1 week |
| 11. Post-award monitoring processes set up | Contract manager + IT security | Ongoing (initial 2–4 weeks) |
| 12. Training & handover to contract managers | Procurement + training team | 1 week |
Begin by inventorying live and pipeline contracts and tagging those that touch ICT, cloud, managed services or connected products. For each, record data sensitivity, network exposure and NIS2 relevance. The legal review (Step 2) should confirm whether Directive 2014/24/EU procedural constraints, NIS2 obligations, or national implementing acts published in Monitorul Oficial apply. Step 3 assigns a risk tier, this tier determines how demanding the certification, audit and security-obligation clauses need to be, keeping requirements proportionate as Directive 2014/24/EU demands.
When updating specifications and award criteria, ensure cybersecurity criteria are linked to the subject matter of the contract, as required for lawful award criteria under Directive 2014/24/EU. A sample security-obligations clause:
“The Supplier shall implement and maintain, throughout the Term, technical and organisational security measures no less protective than [recognised EU baseline / referenced scheme], shall not degrade such measures without the Authority’s prior written consent, and shall promptly remediate any identified vulnerability within the timeframes set out in Schedule [X].”
For certification (Step 6), reference accepted schemes and versions, and include an evidence obligation:
“The Supplier shall hold and maintain valid certification under [recognised EU certification scheme or equivalent] for the duration of the Contract, and shall provide the certifying body’s current attestation on award and upon each renewal or surveillance audit.”
Amend guarantee wording so that drawdown triggers include cyber-specific failures. A sample redraft note for the performance-security clause:
“The Authority may call on the Performance Security where the Supplier fails to meet a Security Obligation, fails to notify a reportable incident within the Notification Window, or fails to complete Remediation within the Cure Period, to the extent of the reasonable costs of remediation and any liquidated sums specified.”
Then align the SLA and statement of work with these definitions so the security terms, reporting windows and remedies are internally consistent.
Pre-award due diligence should validate certificates with certifying bodies and review the supplier’s incident-response plan and subcontractor matrix. Build in flow-down and audit rights:
“The Supplier shall procure that each subcontractor performing Security-Relevant Services accepts obligations equivalent to those in this Contract, and shall permit the Authority (or its appointed auditor) to audit compliance on reasonable notice, and without notice following a reportable incident.”
Establish a post-award monitoring cadence, evidence collection, certificate-expiry tracking and incident logs, and hand the contract to managers with training on the new obligations. For any IT procurement Romania programme, this final step is where compliance either becomes operational or quietly lapses; treat it as a controlled handover, not an afterthought.
Standardise the document set so bids can be compared consistently and post-award files support enforcement. Define confidentiality and retention terms for sensitive evidence such as penetration-test reports.
| Document | Who provides | Purpose / notes |
|---|---|---|
| Supplier cybersecurity policy & attestation | Supplier | Baseline security posture |
| Relevant certificates (per EU / ENISA-recognised schemes) | Supplier | Evidence of certification; state accepted schemes and versions |
| Evidence of incident response capability (IR plan) | Supplier | Demonstrates preparedness & contact points |
| Subcontractor flow-down matrix | Supplier | Shows subcontractor dependencies & compliance |
| Performance security instrument (bond/guarantee) | Supplier / guarantor | Financial security linked to performance and remedies |
| Insurance certificates (cyber insurance) | Supplier | Risk transfer / mitigation evidence |
| Audit & penetration test reports (redacted) | Supplier | For higher-risk procurements; define retention & confidentiality |
| Declaration of compliance with procurement specifications | Supplier | Standard tender submission requirement |
| Post-award monitoring plan | Contracting authority | Internal control & compliance tracking |
Enhanced cybersecurity checks add verification time to the procurement calendar, so build the following buffers into your schedule rather than compressing the standstill or evaluation phases.
Across a full IT procurement Romania cycle, expect the cybersecurity enhancements to add several weeks in aggregate; plan procurement launch dates accordingly.
Cybersecurity compliance carries real cost, most of which suppliers price into bids. Contracting authorities should evaluate price against compliance transparently and avoid criteria that disproportionately favour incumbents. All figures below are indicative market estimates for budgeting only, not guaranteed prices, and will vary significantly by scope, scheme and provider.
| Cost item | Typical payer | Notes |
|---|---|---|
| Supplier certification (initial) | Supplier (priced into bid) | Cost depends on scope and scheme; obtain current quotes |
| Certification renewal / surveillance | Supplier | Annual recurring cost |
| Independent security audit / pentest | Supplier / sometimes buyer (high risk) | Depends on complexity and scope |
| Cyber insurance premium | Supplier | Varies by sector/risk; may be required at award |
| Administrative compliance & verification | Contracting authority | Internal resource time + possible external counsel fees |
| Performance bond (financial security) | Supplier (cost of bond) | Bank fee typically a small percentage of bond value |
| External legal advice (procurement & guarantees) | Either party (buyer often pays) | Varies; include in procurement budget |
The EU cybersecurity framework is expected to continue converting several previously discretionary practices into express obligations, but the precise applicability in any given tender will depend on Member State implementation and national procurement rules administered by Romania’s procurement authority. Until relevant implementing acts appear in Monitorul Oficial, treat the specifics below as the expected direction of travel and build update mechanisms into contracts.
Anticipated obligations include express supplier-security duties with a minimum baseline; certification requirements tied to recognised EU schemes for defined procurement categories; stricter incident-reporting timelines coordinated with national authorities and consistent with ENISA guidance; and a clearer liability and remedy regime for cyber-related non-performance. The overlap with the NIS2 Directive means that where a supplier is itself an essential or important entity, its statutory obligations and its contractual obligations must be aligned to avoid gaps.
| Area | Traditional position | Direction of travel |
|---|---|---|
| Supplier security obligations | Best practice; contractual | Express, possibly mandatory obligations with minimum baseline |
| Certification | Voluntary / sectoral | Specified schemes may be required for certain procurements |
| Incident reporting | Contract-defined, flexible SLAs | Stricter timelines and mandatory reporting to national/EU authorities |
| Performance securities | Financial focus (delivery defaults) | May need to cover cyber non-performance / remediation costs |
| Audit & testing rights | Negotiated | Stronger rights to testing/audits & supplier cooperation duties |
Wider digital-single-market instruments, including proposals such as the Digital Networks Act, form a further regulatory overlay that can interact with connectivity-heavy procurements; where relevant, cross-reference those rules so that security and network-resilience obligations do not conflict. For IT procurement Romania authorities, the safest posture is to draft to the higher expected standard while retaining a contractual variation right to conform to the final national text.
The clauses below are illustrative templates for adaptation by qualified counsel, not legal advice. They should be tailored to the risk tier of each procurement and reconciled with your national procurement rules and the applicable EU framework.
Security obligations. “The Supplier shall implement, maintain and continually improve technical and organisational measures no less protective than [named baseline/scheme], and shall not materially reduce such measures without the Authority’s prior written consent.”
Certification & evidence. “The Supplier warrants that it holds valid certification under [recognised EU scheme or equivalent] and shall furnish current attestations on award, on renewal, and within [10] business days of any request by the Authority.”
Incident reporting. “The Supplier shall notify the Authority and, where required, the competent national authority of any reportable incident within the period specified in Schedule [X] of becoming aware, providing the information specified therein and updates until closure.”
Audit rights. “The Authority may audit the Supplier’s compliance on [30] days’ notice, and without notice following a reportable incident, and the Supplier shall provide reasonable cooperation and access.”
Performance-security drawdown. “The Authority may call the Performance Security to the extent of remediation costs and any liquidated sums where the Supplier breaches a Security Obligation, fails to report within the Notification Window, or fails to remediate within the Cure Period.”
For deeper drafting, an IT Procurement Cybersecurity Contract Update Checklist (Romania) can be used as a working document alongside these clauses. Authorities and suppliers seeking jurisdiction-specific drafting should consult a qualified Romanian technology and commercial lawyer, and may review the Romania technology practice resources and the Romania/Technology lawyer directory for specialist counsel.
In summary, IT procurement Romania authorities and suppliers should treat the developing EU cybersecurity framework as a prompt to rebuild their procurement documents around measurable security obligations, evidenced certification, disciplined incident reporting and remedies-backed performance securities, while retaining update mechanisms until the final EU and national texts are settled. Acting now, before the next procurement cycle, converts a compliance risk into an orderly, defensible process.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Razvan Alexandru Olaru at Olawru, a member of the Global Law Experts network.
posted 34 minutes ago
posted 57 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message