Published
Security Culture Programme
Notice number: 00599141-2026
KEY INFORMATION
- Submission deadline
- • Oct 5, 2026
- Location
- 🇳🇴 Norway
- Contracting authority
- Statsforvalterens fellestjenester
- Accepted Languages
- Norwegian
- Tender type
- Services
- Contract Value
- Published date
- Aug 31, 2026
TENDER DESCRIPTION
Statsforvalterens fellestjenester invites offers for a Security Culture Programme focusing on providing a tool and/or service for phishing tests, awareness, and training for approximately 2,900 employees to enhance their ability to identify fraudulent emails. Key deliverables include solution implementation, configuration, administrator training, and adherence to a standard Service Level Agreement, with the system required to be fully operational within three months of contract signing. The solution must comply with stringent technical requirements, including functionality in Microsoft Edge, support for role-based access control, secure data handling per NSM recommendations (with personal data processed and stored within EU/EEA, Switzerland, or the UK), compatibility with Microsoft 365 and Entra ID for SSO, and a Norwegian end-user interface. The contract is for an initial one-year term from December 1, 2026, with an option for a one-year extension, and bidders must demonstrate economic capacity with a Creditsafe rating of A, B, or C.
TENDER BRIEF
The contract is set to commence on December 1, 2026, and conclude on November 30, 2027. The initial duration of the contract is one year, with an option for the client to extend it for an additional year.
Key milestones and phases include:
- Implementation Phase: The solution must be fully implemented, tested, and operational within three months following the contract's signing. A specific plan for this establishment phase is part of the agreement.
- Temporary Extension: The supplier is required to extend the contract for up to six months post-termination if requested by the client, provided a minimum of 60 calendar days' notice is given.
Sources
- 1Vedlegg G - Avtalevilkår.pdf — “- bilag 3 Bilag 2: Leverandørens beskrivelse av tjenesten Leverandørs utfylling av Vedlegg D til Konkurransegrunnlaget vil brukes som bilag 2 i denne avtalen. Side 3 av 10 Bilag til SSA-L- bilag 3 Bilag 3: Plan for etabl…”
- 2Vedlegg E - Oppdragsgivers krav til leveransen.docx — “eller tjenesten. Oppfylt? | Svar/kommentar: Velg et element. | Teknisk løsning og drift Nr. | Type | Beskrivelse av krav: 9.1 | A | Administrator- og sluttbrukergrensesnitt skal fungere i Microsoft Edge. Oppfylt? | Svar/…”
The core scope of work for this tender involves providing a tool and/or executing phishing tests to raise awareness and train approximately 2900 employees (internal staff and those at county governor's offices) on identifying fake emails.
The Statement of Work (SOW) summary and core deliverables include:
- Phishing Test Tool/Execution: Delivery and implementation of a tool or service for conducting phishing tests.
- Awareness and Training: Providing awareness and training related to identifying fake emails.
- Implementation and Configuration: Assisting with the necessary establishment and configuration of the service.
- Administrator/Superuser Training: Conducting training for 1-2 administrators/superusers.
- System Readiness: The solution must be implemented, tested, and ready for use within three months of contract signing.
- Service Level Agreement (SLA): Adherence to a standard service level agreement provided by the supplier.
- Technical Requirements:
- Administrator and end-user interfaces must function in Microsoft Edge.
- The solution must operate without requiring exceptions in security filters.
- Support for role-based access control.
- Data protection during transfer and storage, adhering to NSM recommendations or equivalent standards.
- Logging of relevant security and administrator events.
- Established processes for vulnerability management, security updates, and incident handling in line with NSM principles or equivalent standards.
- Notification of security incidents affecting client data or service.
- Data Handling: Deletion of client data upon agreement termination, according to client instructions.
- Optional: Provision of a test environment for evaluating central functionality.
Sources
- 1Vedlegg E - Oppdragsgivers krav til leveransen.docx — “Bilag 1 - Oppdragsgivers krav til leveransen Bilag 1 inneholder en beskrivelse av bakgrunnen for anskaffelsen, samt en oppstilling av de krav Oppdragsgiver har til leveransen. Dette dokumentet brukes som bilag 1 til avta…”
- 2Vedlegg G - Avtalevilkår.pdf — “- bilag 3 Bilag 2: Leverandørens beskrivelse av tjenesten Leverandørs utfylling av Vedlegg D til Konkurransegrunnlaget vil brukes som bilag 2 i denne avtalen. Side 3 av 10 Bilag til SSA-L- bilag 3 Bilag 3: Plan for etabl…”
Login to view all answers and insights
Unlock tender brief for freeTENDER DOCUMENTS
DIRECTORY • 9 FILES
- Vedlegg B - Forpliktelseserklæring.docx46 KBDOCX
- Vedlegg A - Tilbudsbrev.docx46 KBDOCX
- Vedlegg D - Taushetsbelagte opplysninger.docx45 KBDOCX
and 2 other documents
Login to view and download all tender documents
Unlock documents for freeASK AI ABOUT THIS TENDER
Can a foreign company apply?
Yes, foreign companies can apply as long as they meet all the requirements set out in the procurement documents.
Login to ask more questions.
Unlock AI tender chat for freeUnlock your tender workflow
Run your first search, evaluate the results, save a daily monitor and start building a pipeline of tenders worth pursuing.