Published

    Security Culture Programme

    Notice number: 00599141-2026

    🇳🇴 NorwayStatsforvalterens fellestjenesterServices

    KEY INFORMATION

    Submission deadline
    Oct 5, 2026
    Location
    🇳🇴 Norway
    Contracting authority
    Statsforvalterens fellestjenester
    Accepted Languages
    Norwegian
    Tender type
    Services
    Contract Value
    Published date
    Aug 31, 2026

    TENDER DESCRIPTION

    Statsforvalterens fellestjenester invites offers for a Security Culture Programme focusing on providing a tool and/or service for phishing tests, awareness, and training for approximately 2,900 employees to enhance their ability to identify fraudulent emails. Key deliverables include solution implementation, configuration, administrator training, and adherence to a standard Service Level Agreement, with the system required to be fully operational within three months of contract signing. The solution must comply with stringent technical requirements, including functionality in Microsoft Edge, support for role-based access control, secure data handling per NSM recommendations (with personal data processed and stored within EU/EEA, Switzerland, or the UK), compatibility with Microsoft 365 and Entra ID for SSO, and a Norwegian end-user interface. The contract is for an initial one-year term from December 1, 2026, with an option for a one-year extension, and bidders must demonstrate economic capacity with a Creditsafe rating of A, B, or C.

    TENDER BRIEF

    The contract is set to commence on December 1, 2026, and conclude on November 30, 2027. The initial duration of the contract is one year, with an option for the client to extend it for an additional year.

    Key milestones and phases include:

    • Implementation Phase: The solution must be fully implemented, tested, and operational within three months following the contract's signing. A specific plan for this establishment phase is part of the agreement.
    • Temporary Extension: The supplier is required to extend the contract for up to six months post-termination if requested by the client, provided a minimum of 60 calendar days' notice is given.

    Sources

    • 1Vedlegg G - Avtalevilkår.pdf — “- bilag 3 Bilag 2: Leverandørens beskrivelse av tjenesten Leverandørs utfylling av Vedlegg D til Konkurransegrunnlaget vil brukes som bilag 2 i denne avtalen. Side 3 av 10 Bilag til SSA-L- bilag 3 Bilag 3: Plan for etabl…
    • 2Vedlegg E - Oppdragsgivers krav til leveransen.docx — “eller tjenesten. Oppfylt? | Svar/kommentar: Velg et element. | Teknisk løsning og drift Nr. | Type | Beskrivelse av krav: 9.1 | A | Administrator- og sluttbrukergrensesnitt skal fungere i Microsoft Edge. Oppfylt? | Svar/…

    The core scope of work for this tender involves providing a tool and/or executing phishing tests to raise awareness and train approximately 2900 employees (internal staff and those at county governor's offices) on identifying fake emails.

    The Statement of Work (SOW) summary and core deliverables include:

    • Phishing Test Tool/Execution: Delivery and implementation of a tool or service for conducting phishing tests.
    • Awareness and Training: Providing awareness and training related to identifying fake emails.
    • Implementation and Configuration: Assisting with the necessary establishment and configuration of the service.
    • Administrator/Superuser Training: Conducting training for 1-2 administrators/superusers.
    • System Readiness: The solution must be implemented, tested, and ready for use within three months of contract signing.
    • Service Level Agreement (SLA): Adherence to a standard service level agreement provided by the supplier.
    • Technical Requirements:
    • Administrator and end-user interfaces must function in Microsoft Edge.
    • The solution must operate without requiring exceptions in security filters.
    • Support for role-based access control.
    • Data protection during transfer and storage, adhering to NSM recommendations or equivalent standards.
    • Logging of relevant security and administrator events.
    • Established processes for vulnerability management, security updates, and incident handling in line with NSM principles or equivalent standards.
    • Notification of security incidents affecting client data or service.
    • Data Handling: Deletion of client data upon agreement termination, according to client instructions.
    • Optional: Provision of a test environment for evaluating central functionality.

    Sources

    • 1Vedlegg E - Oppdragsgivers krav til leveransen.docx — “Bilag 1 - Oppdragsgivers krav til leveransen Bilag 1 inneholder en beskrivelse av bakgrunnen for anskaffelsen, samt en oppstilling av de krav Oppdragsgiver har til leveransen. Dette dokumentet brukes som bilag 1 til avta…
    • 2Vedlegg G - Avtalevilkår.pdf — “- bilag 3 Bilag 2: Leverandørens beskrivelse av tjenesten Leverandørs utfylling av Vedlegg D til Konkurransegrunnlaget vil brukes som bilag 2 i denne avtalen. Side 3 av 10 Bilag til SSA-L- bilag 3 Bilag 3: Plan for etabl…

    Login to view all answers and insights

    Unlock tender brief for free

    TENDER DOCUMENTS

    DIRECTORY • 9 FILES

    • Vedlegg B - Forpliktelseserklæring.docx
    • Vedlegg A - Tilbudsbrev.docx
    • Vedlegg D - Taushetsbelagte opplysninger.docx

    and 2 other documents

    Login to view and download all tender documents

    Unlock documents for free

    ASK AI ABOUT THIS TENDER

    You

    Can a foreign company apply?

    Riko

    Yes, foreign companies can apply as long as they meet all the requirements set out in the procurement documents.

    Login to ask more questions.

    Unlock AI tender chat for free

    Unlock your tender workflow

    Run your first search, evaluate the results, save a daily monitor and start building a pipeline of tenders worth pursuing.

    First monitor on Day 1All features included in trialNo credit card required

    You may also be interested in

    Similar tenders