Published

    Rahmenvertrag über 4 Jahre - Penetrationstests inkl. Beratungsdienstleistung

    Notice number: ocds-mnwr74-25742126

    🇩🇪 GermanyÜSTRA Hannoversche Verkehrsbetriebe Aktiengesellschaft

    KEY INFORMATION

    Submission deadline
    Sep 21, 2026
    Location
    🇩🇪 Germany
    Contracting authority
    ÜSTRA Hannoversche Verkehrsbetriebe Aktiengesellschaft
    Accepted Languages
    German
    Tender type
    Contract Value
    Published date
    Aug 22, 2026

    TENDER DESCRIPTION

    This tender seeks a framework agreement for a duration of four years, commencing November 1, 2026, and concluding October 31, 2030, with an option for two 12-month extensions, capped at a maximum of 48 months. The core scope of work involves the comprehensive preparation, execution, and follow-up of various penetration tests, including associated consulting services, with individual orders under the framework agreement not exceeding a total value of €400,000.00. The contractor will be responsible for providing expert advice, conducting diverse penetration tests—including external attack, assumed breach, selected IT services, and web application scenarios—and delivering detailed reports within specified timelines, such as an ad-hoc report for critical vulnerabilities within one day. Key technical requirements include adherence to White-Box approaches and OWASP standards (ASVS, Web Security, Mobile Application Security), while testing a wide array of systems such as Microsoft Windows environments (7-11, Server 2012-2022), Linux servers, networking infrastructure (VPN, Firewalls), web applications (HTML, Java/JavaScript), and enterprise systems like SAP, Oracle DB, Infor ERP, and…

    TENDER BRIEF

    The contract is scheduled to start on November 1, 2026, and conclude on October 31, 2030. This indicates a total duration of four years. The contract can commence within 14 days of the award.

    The framework agreement has an initial minimum term of two years. This term automatically extends by one additional year at a time, provided the client does not terminate the contract in writing or via email three months before the respective expiration date. The total duration, including any extensions, is capped at a maximum of four years from the effective date. Specifically, the framework agreement can be extended twice, each for 12 months, under the same conditions, unless the client terminates it with a three-month notice period before its end. Regardless, the agreement will terminate after a maximum of 48 months without requiring further notice.

    Sources

    • 1Unterlagen\Vergabeunterlagen.pdf — “zulässig Nebenangebote | Nebenangebote sind nicht zugelassen Nachlass | Ja Skonto zugelassen | Nein Skonto Zahlungsziel | Tag(e) Verwendung elektronischer Mittel | Die Einreichung der Angebote/Teilnahmeanträge darf nur e…
    • 2Unterlagen\Weitere Dokumente\Anlage 05 - Rahmenvertrag über Durchführung von Penetrationstests.pdf — “EVB-IT AGB, ergeben sich Regelungen zur Vertraulichkeit aus Anlage Nr. 4. ☑ Soweit durch den Auftragnehmer personenbezogene Daten im Auftrag des jeweiligen Auftraggebers verarbeitet werden sollen (Auftragsverarbeitung),…

    The core scope of work for this tender involves the "Durchführung von Penetrationstests" (execution of penetration tests) and associated services.

    The contractor must be capable of preparing, conducting, and post-processing penetration tests, along with providing related consulting services throughout the contract period.

    Key deliverables and service contents include:

    • Consulting: Providing advice on the capabilities and limitations of IT security investigations, both generally and specifically, based on current technological and research standards. This also includes consulting on organizational and technical frameworks, as well as estimated efforts (technical/personnel) for specific IT security investigations.
    • Preparation: Complete preparation for specific IT security investigations, starting from the initial contact.
    • Execution: Full execution of specific IT security investigations. This includes performing penetration tests according to an agreed workflow and test plan, adhering to current technical standards.
    • Follow-up and Reporting: Comprehensive follow-up of IT security investigations, which includes final reporting and presentations. Technical consulting on identified IT security vulnerabilities is also part of this phase. The contractor is required to submit a first draft report within five working days and a quality-assured final report within ten working days after the implementation phase. In cases where critical security vulnerabilities are identified during an ongoing investigation, an ad-hoc report must be provided to the client by 5:00 PM CET the day following the discovery.
    • Types of Penetration Tests: The tender specifies various scenarios for penetration tests:
    • External Attack: Based on automated scans (IP ranges, domains, OSINT) and targeted tests of exposed systems, considering threat and attack scenarios (Scenario 1). This includes tests of RZ/IT infrastructure like WAN connections, VPN gateways, firewalls, and web proxies.
    • Assumed Breach: Scenarios for standard employee clients (Scenario 2) and standard admin clients (Scenario 3).
    • Selected IT Services or Infrastructure: Such as Office IT infrastructure services (e.g., network) (Scenario 4). This involves testing client and server objects (e.g., WIN workstations, Unix/Windows/SAP/DB/Web servers) based on account privilege escalation and existing vulnerabilities.
    • Web Applications: Penetration tests on web applications based on existing vulnerabilities (Scenarios 7 and 8).

    The services are called off through individual orders ("Einzelaufträge") under a framework agreement, with each individual order detailing the specific nature, scope, and deadlines of the services required. The maximum value for call-offs under this framework agreement is €400,000.00.

    Sources

    • 1Unterlagen\Weitere Dokumente\Anlage 05 - Rahmenvertrag über Durchführung von Penetrationstests.pdf — “Nr.1, die als Bestandteil dieses Vertrages und der Einzelverträge gilt. 3 Beschreibung der Leistungen/Laufzeit und Kündigung 3.1 Art, Umfang und Termine Art, Umfang und Termine der auf Abruf zu erbringenden Leistungen er…
    • 2Unterlagen\Weitere Dokumente\Anlage 01 - Leistungsbeschreibung.pdf — “nicht auf das Lieferdatum. 4 Inhalte der Penetrationstests 4.1 Allgemeine Beschreibung der Leistungsinhalte Der AN muss in der Lage sein, über die gesamte Laufzeit des Rahmenvertrags hin- weg, für den AG Penetrationstest…
    • 3Unterlagen\Vergabeunterlagen.pdf — “Dies ist mit der Projektbeschreibung zu dokumentieren: (a.) Penetrationstest einer RZ-/IT-Infrastruktur (z.B. WAN-Anbindung, VPN-Gateways, Firewalls, Web-Proxy etc.) auf Basis einer Perimeteranalyse und anderer Quellen (…

    Login to view all answers and insights

    Unlock tender brief for free

    TENDER DOCUMENTS

    DIRECTORY • 14 FILES

    • Unterlagen\Weitere Dokumente\Anlage 04 - Vertraulichkeitsvereinbarung.pdf
    • Unterlagen\Weitere Dokumente\Anlage 07 - Muster Leistungsnachweis.pdf
    • Unterlagen\Weitere Dokumente\Anlage 06 - Sicherheitsanforderungen Fernzugriff.pdf

    and 7 other documents

    Login to view and download all tender documents

    Unlock documents for free

    ASK AI ABOUT THIS TENDER

    You

    Can a foreign company apply?

    Riko

    Yes, foreign companies can apply as long as they meet all the requirements set out in the procurement documents.

    Login to ask more questions.

    Unlock AI tender chat for free

    Unlock your tender workflow

    Run your first search, evaluate the results, save a daily monitor and start building a pipeline of tenders worth pursuing.

    First monitor on Day 1All features included in trialNo credit card required

    You may also be interested in

    Similar tenders