Document template · Free

Information security statement

What wins points

A detailed, measurable security statement demonstrates compliance with Article 42 and can earn positive weighting under Article 67 when the authority values risk mitigation.

What gets bids disqualified

Missing or vague security statements cause failure of eligibility checks and may lead to exclusion under technical specifications (Article 42).

Evaluator's view

Look for explicit references to GDPR, encryption standards, ISO certifications, and clear responsibility contacts; assess whether measures are proportionate and verifiable.

Information security statement

What this is

A concise declaration of the measures you will take to protect the confidentiality, integrity and availability of data and communications throughout the procurement process.

When you need it

Required at the eligibility stage for contracts that involve processing personal or sensitive data, especially where the tender documents request a security statement (e.g., under Article 42 “Technical specifications” and supported by evidence per Article 60 "Means of proof"). It is usually mandatory for ICT services and any contract involving electronic exchanges.

How to fill it in

  1. Identify the applicable national and EU data‑protection rules (e.g., GDPR) that the authority expects you to comply with.
  2. Describe the technical and organisational measures you will implement: encryption level, secure authentication, pseudonymisation, regular security testing, incident‑response procedures, and a Data Protection Impact Assessment if required.
  3. Reference any certifications you hold (ISO 27001, EN ISA/IEC 62443) and provide their validity dates.
  4. State the person responsible for security within your organisation and how they can be contacted during the contract period.
  5. Indicate where supporting evidence (certificates, test reports) will be attached to the tender documentation.

Template

[Company Name]
Information Security Statement – Tender Ref: [Tender Identifier]

1. Applicable legal framework:
   - GDPR (Regulation (EU) 2016/679)
   - National data‑protection law: [Country] Law No. XXXXXX

2. Technical measures:
   - Data encryption at rest and in transit: AES‑256 / TLS 1.3
   - Access control: Role‑based, MFA for all staff handling tender data
   - Pseudonymisation of personal data where feasible
   - Regular security testing: quarterly penetration test reports (ISO 27001 ISO/IEC 27001)

3. Certifications:
   - ISO 27001:2022 – Certificate No. XXXXX (valid until YYYY‑MM)
   - EN ISA/IEC 62443‑4‑2 – Security Level 3 compliance

4. Responsible security officer:
   Name: [Full Name]
   Title: Chief Information Security Officer
   Email: [email@company.com]
   Phone: [+XX XXXX XXX XXX]

5. Supporting evidence attached:
   - ISO‑27001 certificate copy
   - Latest penetration test report (Executive Summary)
   - DPIA summary (if applicable)

Paste your draft response — free teaser, €9 full report

Already filled this in? We'll score your actual text against the same wins-points / disqualifies rubric above and quote your own words back for every finding.

Evaluate my draft →

Get the daily EU tender brief

Free templates, plus the live tenders that match your capability — one email a day, no card required.

First month free · no card, no sign-up needed.

Used this template already? Get this bid evaluated →

← All free templates

Information security statement — free EU tender template