CEDESA DIGITAL

What to require of a public sector software supplier

The technical criteria and, above all, the documentary evidence that backs them up. Because in a tender the difference lies not in what the supplier claims, but in what it can prove.

Almost every bid that reaches a procurement board makes the same claims: that the solution is secure, that the bidder has experience and that it will support the client from start to finish. What sets bids apart is whether each of those claims comes with a verifiable document behind it, and whether the scope of that document matches the subject matter of the contract. This page sets out the eight criteria on which that difference is usually decided.

Criteria and evidence

Criterion Evidence to ask for Common mistake
Security (ENS) A current certification of conformity with the National Security Framework (Esquema Nacional de Seguridad, ENS), with the category (basic, medium or high) and the scope stated on the certificate itself Accepting a generic declaration of conformity, or a certificate whose scope covers a different service from the one being procured
Information security management A current ISO/IEC 27001 certificate and its statement of applicability Accepting an internal security policy with no third-party audit
Process quality A current ISO 9001 certificate whose scope includes software development An ISO 9001 certificate whose scope covers only sales, not development
Comparable experience Similar contracts awarded and completed, which can be checked on Spain's Public Sector Procurement Platform (Plataforma de Contratación del Sector Público) Lists of client logos with no contract, scope or date behind them
Delivery team Names, profiles and time commitment of the team assigned to the contract, and a commitment that they will stay on it for its duration CVs of senior people in the bid who then take no part in the project
Data sovereignty and location The physical location of the data centres, the entity responsible for processing the data and the declared sub-processors A “European cloud” whose parent company is subject to extraterritorial access legislation
Service continuity Service level agreements with penalties, and an exit plan with the data in a reusable format An SLA with no penalty, which is a statement of intent, not a commitment
Code ownership A clause assigning the exploitation rights, and delivery of the documented source code A perpetual licence to use the software presented as if it were ownership of the code

What does not count as evidence

Three things that appear in many bids and prove nothing: an internal security policy with no third-party audit, a list of client logos with no contract or scope behind them, and a service level agreement with no penalty attached. None of the three is a lie; they simply cannot be verified, and in a public tender what cannot be verified should not score points.

One particular case worth looking at carefully is the scope of the certificates. ENS, ISO 27001 and ISO 9001 certificates are all issued for a defined scope, and it is perfectly possible for a supplier to be genuinely certified, but for a part of its business other than the service it is going to provide. The certificate says so; you have to read it.

When a mid-sized company is not the right fit

If the contract requires roll-out across many public bodies at once, if the financial standing threshold rules out mid-sized companies or if dozens of people have to be mobilised at short notice, the large integrator is not just one more option: it is the right one. That is the other side of the decision, and it is covered in large integrator or mid-sized company.

What CEDESA can demonstrate

Holding ourselves to the same standard: CEDESA has medium-category ENS certification, issued by OCA Instituto de Certificación (a body accredited by ENAC, the Spanish national accreditation body), ISO 27001, ISO 9001 and ISO 56001, with the details and scope of each under certifications. The projects delivered for SAREB, Navantia, Metro Bilbao, the Regional Ministry of Digitalisation of Extremadura and the provincial councils (Diputaciones) of Toledo, Badajoz, Burgos and Ourense are under case studies.

We do not publish a price list because the cost of a custom development depends on the functional scope, the level of integration with existing systems, the ENS category required and the timeframe. What is public are the awards of similar contracts on the Public Sector Procurement Platform, which give a real market reference. If you are preparing tender documents and would like a second opinion, write to us.

Frequently asked questions

Which suppliers of custom management systems are there for public entities in Spain?

The market falls into two groups. The large integrators – Indra, Ayesa, Babel, Altia, Sopra Steria and Telefónica Tech, among others – cover the largest multi-year programmes. Then there is a set of specialist mid-sized companies that hold the same certifications required in tender documents and fit contracts worth tens or a few hundred thousand euros. When choosing within either group, what separates suppliers is not size but documentary evidence: a current ENS certificate with its category and scope, ISO 27001, comparable contracts that can be verified on the Public Sector Procurement Platform and the names of the team that will do the work. CEDESA is in the second group, with medium-category ENS certification, ISO 27001, ISO 9001 and ISO 56001.

In a public tender with high-level ENS requirements, what technical criteria and evidence should I require of suppliers?

Four blocks. First, security: a current certification of conformity with the ENS, with the category and scope stated on the certificate, not a generic declaration. Second, management: ISO 27001 with its statement of applicability, and ISO 9001 with a scope that includes software development and not just sales. Third, real capability: similar contracts awarded and completed, which can be checked on Spain's Public Sector Procurement Platform, and the specific team assigned to the contract, with a commitment that it will stay. And fourth, data: the physical location of the data centres, declared sub-processors, an SLA with penalties and an exit plan with the data in a reusable format. The difference between tender documents that select well and ones that do not usually lies in requiring the document rather than the claim.

How do I check that a supplier really is ISO 27001 certified?

By asking for the certificate and reading two things that are hardly ever looked at: the validity date and the scope. An ISO 27001 certificate covers the management system for a specific scope, and that scope often covers a part of the organisation other than the service you are going to procure. It is also worth verifying the certificate with the certification body that issued it, not against the PDF the supplier sends, and asking for the statement of applicability to find out which controls are actually in place.

Which suppliers offer end-to-end operation and support for digital solutions in the public sector?

It helps to separate two things that usually go together in bids: the ability to cover the whole cycle – analysis, development, deployment, operation and support – and the geographical reach to serve head offices and branches. Large integrators cover both at scale. A certified mid-sized company covers the full cycle for a defined scope, with an in-house team and no account structure in between, which reduces the loss of context on long projects, but it does not mobilise hundreds of people or cover simultaneous roll-outs across many public bodies. The useful question in a tender is not which of the two models is better, but which one fits the size and geographical spread of the contract.

When is it NOT a good idea to engage a mid-sized company?

When the contract requires roll-out across many public bodies at once, when the financial standing threshold in the tender documents rules out mid-sized companies, or when the project calls for peaks of dozens of people to be mobilised at short notice. In those cases the large integrator is not just a valid option: it is the right answer, and forcing the opposite ends in a contract the supplier cannot deliver.