[codicts-css-switcher id=”346″]

Global Law Experts Logo
public procurement reform denmark

Our Expert in Denmark

Denmark Public Procurement Reform (1 July 2026): Security & Preparedness Obligations and Threshold Changes, Practical Guide

By Global Law Experts
– posted 60 minutes ago

Last reviewed: 10 August 2026

The public procurement reform Denmark contracting authorities and suppliers have been anticipating took effect on 1 July 2026, formally embedding security and preparedness obligations into the Danish Public Procurement Act and recalibrating value thresholds that determine which procedural rules apply. For procurement managers, in-house counsel and bidding companies alike, the reform creates a new compliance baseline: tenders must now address continuity-of-service and national-security considerations, evaluation criteria must be reweighted, and contract clauses must be updated across sectors ranging from welfare technology to energy and defence. This guide provides the actionable checklists, sample clauses and scoring models needed to translate the legislative text into day-one compliance.

Quick Summary, What the 1 July 2026 Reform Does

The amended Public Procurement Act introduces a structured obligation for contracting authorities to assess and, where relevant, impose security and preparedness requirements on suppliers whose contracts touch critical services, sensitive data or essential infrastructure. The reform simultaneously adjusts the value floor and EU-aligned thresholds, changing when full procedural obligations, simplified rules or best-practice guidance apply. Below are the six key takeaways every procurement professional should note immediately.

  • Effective date. The reform entered into force on 1 July 2026. Procurements published on or after that date must comply; procurements already in progress before 1 July follow the rules in effect at the time of publication.
  • Security and preparedness duty. Contracting authorities must evaluate whether a procurement involves services, supplies or works that require preparedness measures, and, if so, include proportionate security requirements in the tender documents and resulting contract.
  • Adjusted thresholds and value floor. The value floor for application of the Act’s general rules has been recalibrated alongside the biennial EU threshold update, affecting which procurements fall under full, simplified or voluntary procedures.
  • Sectors most affected. Welfare technology procurement Denmark-wide, energy-sector contracts subject to Energistyrelsen preparedness legislation, IT managed services, and defence/dual-use procurements face the most direct impact.
  • Evaluation criteria changes. Authorities should integrate preparedness capacity, business continuity evidence and incident-reporting capability into their scoring models.
  • Complaints Board scrutiny. The Danish Complaints Board for Public Procurement (Klagenævnet for Udbud) is expected to review whether security requirements imposed by authorities are proportionate and transparently evaluated, making documentation critical from day one.

Timeline and Legislative References for the 2026 Procurement Changes Denmark

Understanding when each element of the public procurement reform Denmark framework activates is essential for compliance planning. The table below maps the critical dates, legislative events and their practical impact on ongoing and upcoming procurements.

Key Dates

Date Event Practical Impact
1 January 2026 Biennial EU threshold update takes effect across all Member States; Denmark transposes revised figures into national guidance Contracting authorities must recalculate whether contracts fall above or below the new EU thresholds; recalibrate procurement planning registers accordingly
1 July 2026 Amended Public Procurement Act enters into force, security and preparedness obligations become a formal part of Danish procurement law; adjusted national value floor applies All tender documents published from this date must include a preparedness assessment; evaluation criteria and contract terms must reflect the new obligations
Ongoing (H2 2026 onwards) Danish Competition and Consumer Authority publishes updated procurement guidance; Complaints Board begins issuing decisions under the amended Act Authorities and suppliers must monitor new guidance and Board decisions to calibrate proportionality assessments; update templates as precedent develops

The primary statutory text is the Danish Public Procurement Act (Udbudsloven), as amended. Practitioners should cross-reference the official consolidated text with the procedural guidance published by the Danish Competition and Consumer Authority. For energy-sector overlays, Energistyrelsen’s dedicated preparedness legislation provides additional sector-specific requirements that must be coordinated with procurement obligations.

Industry observers expect that the Complaints Board will issue its first substantive guidance on the proportionality of security requirements within 12–18 months of the reform’s effective date, meaning that early adopters who document their reasoning thoroughly will be best positioned to defend challenged procurements.

Security and Preparedness Obligations, Scope, Triggers and Examples

The centrepiece of the reform is the formal integration of security and preparedness procurement requirements into the Act. The objective is straightforward: where a public contract involves the delivery of services, goods or works on which continuity of critical public functions depends, the contracting authority must assess whether, and to what extent, specific security and preparedness conditions should be imposed on the supplier.

Which Procurements Are in Scope?

The reform does not impose a blanket preparedness requirement on every procurement. Instead, it establishes a proportionality-based trigger: the contracting authority must assess the nature of the contract, the criticality of the service and the risk profile of the supply chain. The following table illustrates how different contract types map to security concerns and the corresponding practical procurement requirements.

Contract Type Why Security / Preparedness Matters Practical Procurement Requirement
Welfare technology (patient monitoring, digital health platforms) Service interruption endangers patient safety; personal health data requires protection Require business continuity plans, data residency commitments, patching and incident-reporting schedules
Energy infrastructure (grid management, SCADA systems) Outages affect national energy security; cross-sector preparedness coordination required under Energistyrelsen rules Coordinate procurement clauses with sector emergency legislation; require redundancy and rapid-response evidence
IT managed services (cloud hosting, network operations for public entities) Cyber-attacks can paralyse government operations; data sovereignty concerns Require security certifications, penetration-testing evidence, supply-chain transparency and subcontractor approval rights
Defence / dual-use supplies National security implications; potential export-control overlaps Apply special procurement rules where applicable; require security clearance evidence and supply-chain origin declarations

Practical Tests for Including Security Requirements

Before drafting tender documents, contracting authorities should apply the following yes/no assessment to determine whether preparedness clauses are necessary:

  • Critical-function test. Does the contract support a service whose interruption would directly affect public safety, health or essential government operations?
  • Data-sensitivity test. Does the contract involve processing, storing or transmitting sensitive personal data, classified information or data subject to sector-specific protection rules?
  • Supply-chain dependency test. Is the contracting authority heavily dependent on a single supplier or a geographically concentrated supply chain for the contracted service or supply?
  • Sector-overlay test. Is the procurement subject to additional preparedness legislation (e.g., Energistyrelsen requirements for the energy sector)?

If the answer to any of these questions is “yes,” the authority should include proportionate security and preparedness requirements in the tender and resulting contract.

Sector Examples

In welfare technology procurement Denmark municipalities are the primary contracting authorities. A municipality procuring a remote patient-monitoring platform should require the supplier to maintain 99.9% uptime, provide a documented disaster-recovery plan, and commit to reporting security incidents within a defined timeframe. In the energy sector, Energistyrelsen’s preparedness legislation already imposes obligations on grid operators, the procurement reform now requires that these obligations flow through into contract terms with private suppliers. For defence and dual-use procurements, the special procurement rules under the Defence and Security Directive may apply in parallel, requiring careful coordination to avoid conflicting requirements.

Threshold Changes, Value Floor and Procurement Design Choices

Alongside the security obligations, the reform recalibrates procurement thresholds Denmark contracting authorities use to determine which procedural regime applies. The value floor, the contract value below which the Act’s general procedural rules do not apply, has been adjusted, as have the EU-aligned thresholds that trigger full competitive procedures. Authorities must update their procurement planning tools and decision trees accordingly.

The decision logic remains tiered: contracts at or above the applicable EU threshold require full procedural compliance (open, restricted or negotiated procedures); contracts above the national value floor but below the EU threshold follow the Act’s simplified rules (the so-called “light regime”); and contracts below the value floor are subject only to general principles of transparency and equal treatment.

How Thresholds Affect Frameworks, DPS and Centralized Purchasing

The threshold recalibration directly affects when contracting authorities should use framework agreements, dynamic purchasing systems (DPS) or centralized purchasing Denmark organisations such as SKI. The table below outlines when each procurement vehicle is typically preferred and the associated trade-offs.

Procurement Vehicle When to Prefer Pros & Cons
Framework agreement Recurring needs with predictable volume; multiple suppliers can fulfil the requirement; contract value likely above national value floor Pros: Efficiency, pre-qualified supplier pool, streamlined call-offs. Cons: Rigidity once established; aggregate value may trigger full EU-threshold procedures
Dynamic purchasing system (DPS) Markets with rapid innovation (IT, welfare-tech); need to admit new suppliers throughout the contract period Pros: Flexibility, open to new entrants, suits fast-evolving markets. Cons: Higher ongoing administration; each call-off requires its own mini-competition
Centralized purchasing (e.g., SKI) Standard, high-volume needs across multiple authorities; desire to leverage buying power and reduce duplicated effort Pros: Economies of scale, reduced administrative burden per authority. Cons: Less tailoring to specific authority needs; preparedness requirements may need supplementary authority-specific terms

For example, a group of municipalities procuring welfare-tech devices through a centralized purchasing agreement should verify whether the aggregate contract value now crosses the recalibrated EU threshold, and, if so, ensure that the full procedural requirements and the new security obligations are embedded from the outset. Similarly, an IT managed-services DPS that was originally set up below the former value floor may now fall within the simplified regime, requiring the authority to add preparedness assessment documentation.

Practical Checklist, What Contracting Authorities Must Change Now

Contracting authority compliance Denmark-wide requires immediate, structured action. The following prioritised checklist translates the reform’s requirements into concrete steps that procurement teams should implement without delay.

  1. Update procurement strategy and risk registers. Add security and preparedness as a standing assessment category in the authority’s procurement planning documents. Identify all current and upcoming procurements where the critical-function, data-sensitivity, supply-chain dependency or sector-overlay tests apply.
  2. Amend standard tender templates. Insert mandatory preparedness-assessment sections into tender documents, procurement notices and contract drafts. Clearly state which security requirements are minimum conditions and which are evaluation criteria.
  3. Adapt selection and evaluation criteria. Reweight scoring models to include preparedness capacity. Specify what evidence suppliers must submit (e.g., business continuity plans, security certifications, incident-response protocols).
  4. Update contract management KPIs and audit clauses. Add incident-reporting timelines, audit rights and preparedness review triggers to standard contract terms.
  5. Reassess procurement vehicle choices. Re-evaluate whether centralized purchasing agreements, framework agreements or DPS remain appropriate given the recalibrated thresholds and the need for authority-specific security terms.
  6. Conduct supplier outreach. Contact key incumbent and potential suppliers to communicate new expectations. Request preliminary security plans and business continuity evidence so that the market is prepared to respond to updated tenders.
  7. Prepare staff training and internal guidance. Brief procurement officers, legal advisers and contract managers on the new requirements, proportionality principles and documentation expectations.
  8. Document proportionality reasoning. For every procurement where security requirements are included (or deliberately excluded), record the reasoning in writing. This documentation is essential for defending decisions before the Complaints Board.
  9. Coordinate with sector regulators. For energy, transport and defence procurements, confirm that procurement-level preparedness clauses align with, and do not contradict, sector-specific regulatory requirements.
  10. Establish a review cycle. Set a standing review (e.g., quarterly) to monitor Complaints Board decisions, updated Competition Authority guidance and evolving best practice, and update templates accordingly.

Example Scoring Model

Evaluation Criterion Weight Evidence Required
Technical quality and functional compliance 40% Technical proposal, product specifications, demonstration/proof of concept
Security and preparedness capacity 25% Business continuity plan, incident-response protocol, security certification (e.g., ISO 27001), supply-chain risk assessment
Price / total cost of ownership 25% Itemised pricing, lifecycle cost model
Sustainability and social responsibility 10% Environmental management evidence, responsible supply-chain commitments

Tender Wording Checklist

When drafting tender notices and documents, authorities should ensure the following elements are explicitly addressed:

  • Preparedness statement. A clear recital explaining why security and preparedness requirements are included and the proportionality basis for each requirement.
  • Minimum suitability conditions. Specify any mandatory certifications, clearances or minimum business-continuity capabilities that are pass/fail prerequisites.
  • Evaluation criteria disclosure. State the weighting given to preparedness-related evaluation criteria and describe how supplier evidence will be assessed.
  • Contract-term summary. Summarise the key security obligations that will be included in the resulting contract (incident reporting, audit rights, remediation timelines).
  • Subcontractor requirements. State whether preparedness obligations flow down to subcontractors and what evidence of subcontractor compliance is required at bid stage.

Sample Procurement Contract Clauses Security and Preparedness

Proportionality is the governing principle when drafting security clauses. Clauses should be specific enough to be enforceable and measurable, but not so onerous that they unjustifiably restrict competition or impose impossible certification demands. Below are four sample clauses, each with drafting notes, that authorities can adapt for different procurement contexts.

Clause 1, Security and Preparedness General Obligation

“The Supplier shall maintain a documented security and preparedness plan addressing risk assessment, contingency operations, and incident response for the services delivered under this Contract. The plan shall be submitted to the Contracting Authority within [30] days of contract signature and updated annually or upon material change in threat landscape.”

Drafting note: Adapt the submission timeline to the contract’s risk profile. For critical-infrastructure contracts, consider requiring the plan before service commencement rather than post-signature.

Clause 2, Welfare-Tech Operational Resilience and Data Protection

“The Supplier shall ensure that welfare-technology systems delivered under this Contract maintain [99.9%] availability, implement security patches within [14] days of release, and report any data breach or service disruption to the Contracting Authority within [24] hours of detection.”

Drafting note: Align the availability target and patching timeline with the clinical or operational criticality of the system. Consider including a remediation-plan obligation for downtime exceeding the agreed threshold.

Clause 3, Subcontracting and Supply-Chain Transparency

“The Supplier shall not subcontract any security-critical element of the Contract without the prior written consent of the Contracting Authority. The Supplier shall ensure that all subcontractors comply with the security and preparedness obligations set out in this Contract and shall grant the Contracting Authority the right to audit subcontractor compliance upon [5] business days’ notice.”

Drafting note: Define “security-critical element” in a schedule to avoid disputes. For IT contracts, this typically includes hosting, data processing and network management.

Clause 4, Remedial Action and Graduated Penalties for Preparedness Breaches

“In the event of a material breach of the Supplier’s preparedness obligations, the Contracting Authority may: (a) require submission of a remediation plan within [10] business days; (b) withhold [5%] of the next milestone payment until compliance is verified; or (c) terminate the Contract with [30] days’ notice if the breach is not remedied.”

Drafting note: Graduated remedies demonstrate proportionality and reduce Complaints Board risk. Avoid automatic termination for minor preparedness gaps; instead, reserve termination for persistent or critical breaches.

Red Flags to Avoid in Clause Drafting

  • Overbroad security demands. Requiring the highest-level security certification for a low-risk service contract will be viewed as disproportionate and may deter competition.
  • Impossible certification requirements. Demanding certifications that do not exist or that no supplier in the relevant market holds effectively excludes all bidders.
  • Disproportionate insurance obligations. Requiring cyber-insurance coverage vastly exceeding the contract value or the realistic risk profile invites challenge.
  • Unilateral amendment rights. Clauses allowing the authority to change security requirements without limit during contract performance undermine legal certainty and risk being set aside by the Complaints Board.

Complaints Board Practice, Risk Mitigation and Dispute Readiness

The Danish Complaints Board for Public Procurement (Klagenævnet for Udbud) has consistently emphasised proportionality and transparency as the two pillars of lawful procurement. Early indications suggest that the Board will apply the same principles to the new security and preparedness obligations: requirements must be proportionate to the contract’s risk profile, clearly disclosed in the tender documents, and applied equally to all bidders.

Practical Mitigation Steps

Issue Raised by Complainant Likely Board Focus How to Document to Mitigate Risk
Security requirements are disproportionate to the contract Whether the authority conducted a proportionality assessment and linked requirements to identified risks Prepare and retain a written proportionality memorandum referencing the critical-function, data-sensitivity and supply-chain tests
Preparedness evaluation criteria are unclear or subjective Whether criteria were sufficiently transparent and whether evaluation was consistent across bidders Include detailed scoring descriptors in the tender documents; retain individual evaluator worksheets showing how each bid was assessed
Subcontractor security requirements restrict competition Whether flow-down obligations are proportionate and whether alternatives were considered Document market analysis showing that qualified subcontractors exist; record any supplier-dialogue feedback on the feasibility of proposed requirements

Contracting authorities should treat documentation as a non-negotiable compliance step. Maintaining a contemporaneous record of every decision, from the initial risk assessment to the final evaluation scoring, provides the strongest defence against complaints and demonstrates adherence to the principles the Board will scrutinise.

Obligations by Entity Type, Comparison Table

Entity Type Typical Reporting / Obligation Triggered by Reform Practical Implication for Tender Drafting
Central government contracting authority Mandatory preparedness clauses for critical-infrastructure suppliers; higher documentation and attestation requirements Use standardised preparedness templates and require independent attestations (e.g., third-party security audits)
Municipalities / welfare providers Proportional preparedness obligations for welfare-tech; data protection and patient-safety focus Include clear technical and incident-reporting requirements; allow supplier remediation plans before escalating to penalties
Utilities / energy sector Sector-specific preparedness obligations plus cross-sector coordination under energy-law overlays Coordinate procurement obligations with Energistyrelsen sector emergency rules; require redundancy and rapid-response evidence

Conclusion, Next Steps for Public Procurement Reform Denmark Compliance

The public procurement reform Denmark enacted on 1 July 2026 is not a distant policy aspiration, it is a live compliance obligation. Contracting authorities, suppliers and in-house counsel should take three immediate actions: first, run every current and planned procurement through the four-part preparedness assessment test; second, update all tender templates, evaluation models and standard contract clauses using the checklists and samples provided above; and third, establish a documentation protocol that records proportionality reasoning for every security requirement imposed or omitted. Authorities and suppliers seeking tailored template reviews or sector-specific drafting guidance can consult a procurement specialist through the Global Law Experts lawyer directory.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Anja Piening at NP advokater, a member of the Global Law Experts network.

Sources

  1. Danish Competition and Consumer Authority, Public Procurement
  2. Danish Competition and Consumer Authority, Procurement Rules
  3. Consolidated Public Procurement Act (Udbudsloven), Official Text
  4. Business in Denmark, Public Procurement Rules
  5. Økonomistyrelsen, Strategy for Green Public Procurement
  6. European Commission, Denmark Public Procurement Country Profile
  7. Energistyrelsen (ENS), Preparedness Legislation for the Energy Sector

FAQs

What changes to Danish procurement law take effect 1 July 2026?
The amended Public Procurement Act introduces mandatory security and preparedness obligations for contracting authorities and adjusts the national value floor and EU-aligned thresholds that determine procedural requirements.
Contracting authorities must assess whether a procurement supports critical services or involves sensitive data, and, if so, include proportionate security requirements in the tender documents and resulting contract.
The biennial EU threshold update took effect on 1 January 2026, while the adjusted national value floor applies from 1 July 2026. Authorities should consult the Danish Competition and Consumer Authority’s current published figures for exact amounts.
Assign a specific weight (e.g., 20–25%) to security and preparedness capacity. Require evidence such as business continuity plans, security certifications and incident-response protocols. Publish detailed scoring descriptors in the tender documents.
Yes. Framework agreements and centralized purchasing arrangements published on or after 1 July 2026 must incorporate preparedness assessments. Existing frameworks are not retrospectively affected, but authorities should add supplementary security terms at the next renewal or call-off where permitted.
Suppliers should prepare a documented business continuity plan, obtain relevant security certifications, map their subcontractor supply chain and be ready to provide incident-response protocols and audit-access commitments as part of their bid.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Denmark Public Procurement Reform (1 July 2026): Security & Preparedness Obligations and Threshold Changes, Practical Guide

Send welcome message

Custom Message