Published

    Prestations d'audits de cybersécurité - Ligne C du métro Toulousain

    Notice number: 00597168-2026

    🇫🇷 FranceTisséo Ingénierie, agissant au nom et pour le compte de Tisséo CollectivitésServices

    KEY INFORMATION

    Submission deadline
    Oct 30, 2026
    Location
    🇫🇷 France
    Contracting authority
    Tisséo Ingénierie, agissant au nom et pour le compte de Tisséo Collectivités
    Accepted Languages
    French
    Tender type
    Services
    Contract Value
    Published date
    Aug 31, 2026

    TENDER DESCRIPTION

    This tender seeks comprehensive cybersecurity audit services for the new Line C of the Toulouse metro, a fully automated system scheduled for completion by 2028. The scope of work encompasses project management and a suite of audits, including architecture, configuration, organizational, physical, and penetration testing, with specific focus on critical perimeters like SDT, CFA, PCC, and INFRA-GAD. Technical methodologies are required to align with Référentiel PASSI and the ANSSI Guide de cartographie des systèmes d'information. The contract spans 21 months from the service order, incorporating detailed timelines for audit phases, monthly progress reporting, and a financial standing requirement of a minimum annual global turnover of €500,000 excluding tax.

    TENDER BRIEF

    The contract is for a duration of 21 months, commencing from the Service Order for the start of the services.

    Key milestones and phases include:

    • T0 - Service Order for the start of project management services:
    • Delivery of the Project Management Plan: 1 month from T0.
    • T1 (archi) - Service Order for the start of the architecture audit:
    • Initialization meeting for the architecture audit: 2 weeks from T1 (archi).
    • Start of the architecture audit and availability of input data: 1 month from T1 (archi).
    • Closure of the architecture audit: 3 months from T1 (archi).
    • T1 (conf) - Service Order for the start of the configuration audit:
    • First initialization meeting for the configuration audit: 2 weeks from T1 (conf).
    • Start of the configuration audit and availability of input data: 1 month from T1 (conf).
    • Final restitution meeting and closure of the configuration audit: 8 months from T1 (conf).
    • T1 (intrusion) - Service Order for the start of intrusion tests:
    • Initialization meeting for intrusion tests: 2 weeks from T1 (intrusion).
    • Final restitution meeting for intrusion tests: 4 months from T1 (intrusion).
    • Monthly Progress Reports (RMA): Delivered on the last working day of each month, detailing ongoing tasks, completed actions, consumed and remaining days, and any alerts or points of attention.

    Payment milestones are linked to the delivery of the Project Management Plan, the closure of various audits (architecture, configuration, intrusion tests, organizational and physical), and monthly progress based on RMA and meetings.

    Sources

    • 1CCAP_Prestation d'audit cyber Ligne C.pdf — “marché. Le Titulaire du présent marché reconnaît le caractère évolutif par définition, de son environnement normatif, qu'il soit technique, réglementaire ou autre. A ce titre, il reconnaît avoir la nécessité de se tenir…
    • 2RC_Prestation d'audit cyber Ligne C.pdf — “forme de groupement à l'attributaire. Pour la bonne exécution du marché, si le marché est attribué à un groupement d'entreprises, il sera conclu avec un groupement CONJOINT d'entreprises (avec mandataire SOLIDAIRE) ou un…
    • 3AE_Prestation d'audit cyber Ligne C.docx — “MARCHE Le marché est conclu pour une durée de 21 mois à compter de l’Ordre de Service de démarrage des prestations. PAIEMENTS Le maître d'ouvrage se libérera des sommes dues au titre du présent marché par virement au cré…
    • 4CCTP_Cahier des charges technique des audits de cybersécurité Ligne C.pdf — “les jalons de chaque audit, ainsi que la comitologie et les modalités d'organisation globale de la prestation. Une convention d'audit sera également rédigée par le prestataire au jalon T1 pour encadrer les modalités et a…

    The core scope of work for this tender involves providing cybersecurity audit services for the "Ligne C" of the Toulouse metro. The services are broadly categorized into project management and various types of audits.

    The core statement of work summary includes:

    • Project Management: This encompasses the development of a project management plan and conducting monthly progress reviews and meetings.
    • Audits:
    • Architecture Audit: This involves an initial meeting, data collection, and a comprehensive audit of the system architecture.
    • Configuration Audit: This entails auditing the configuration of various assets across specific perimeters, namely SDT, CFA, PCC, and INFRA-GAD. The audits will generate individual reports for each audited equipment and a final synthesis report.
    • Organizational and Physical Audit: This type of audit is listed as a mission.
    • Penetration Testing (Test d'intrusion): This involves an initial meeting, conducting penetration tests, and providing a global report on the findings.

    The deliverables explicitly stated are:

    • Project Management Plan.
    • Monthly Progress Reports (RMA) and associated meeting minutes.
    • Support documentation and minutes for initial and restitution meetings related to architecture, configuration, and penetration testing audits.
    • Global Architecture Audit Report.
    • Unit Configuration Audit Reports (one per equipment) in Excel format, detailing identification, summary, criteria, results, comments, recommendations, gravity levels, and priority levels for security measures.
    • Final Configuration Audit Synthesis Report.
    • Global Penetration Test Report.

    The overall duration of the market is 21 months from the service order for starting the prestations. The scope also covers specific sub-systems under the CFA perimeter, including data centers, ticketing, video protection, telephony/interphony, radio communication networks, IT networks (outside the transport system), chronometry, station sound systems, passenger counting, access control, and intrusion detection for Line C.

    Sources

    • 1DPGF.xlsx — “DPF Tranche Ferme,, Missions du Titulaire,,Montant en euros HT Management de Projet,, ,Livrable de management de projet : plan de management de projet ,0 ,Avancement Mensuel (RMA et réunions),0 Sous-total - Management de…
    • 2CCTP_Cahier des charges technique des audits de cybersécurité Ligne C.pdf — “de transport incluant le matériel roulant, les automatismes de conduite (type CBTC), la voie, la distribution haute tension privée, l'alimentation en énergie de traction, les façades de quai, les équipements spéciaux de…
    • 3CCAP_Prestation d'audit cyber Ligne C.pdf — “marché. Le Titulaire du présent marché reconnaît le caractère évolutif par définition, de son environnement normatif, qu'il soit technique, réglementaire ou autre. A ce titre, il reconnaît avoir la nécessité de se tenir…

    Login to view all answers and insights

    Unlock tender brief for free

    TENDER DOCUMENTS

    DIRECTORY • 16 FILES

    • Annexe1_CCAP_Note d'organisation générale du projet.pdf
    • Correspondance_MPI_1862843.pdf
    • Annexe2_RC_Engagement confidentialité.docx

    and 9 other documents

    Login to view and download all tender documents

    Unlock documents for free

    ASK AI ABOUT THIS TENDER

    You

    Can a foreign company apply?

    Riko

    Yes, foreign companies can apply as long as they meet all the requirements set out in the procurement documents.

    Login to ask more questions.

    Unlock AI tender chat for free

    Unlock your tender workflow

    Run your first search, evaluate the results, save a daily monitor and start building a pipeline of tenders worth pursuing.

    First monitor on Day 1All features included in trialNo credit card required

    You may also be interested in

    Similar tenders