Published
Sikkerhetskulturprogram
Notice number: 2026-113718
KEY INFORMATION
- Submission deadline
- • Oct 5, 2026
- Location
- 🇳🇴 Norway
- Contracting authority
- Statsforvalterens fellestjenester
- Accepted Languages
- Norwegian
- Tender type
- Contract Value
- Published date
- Sep 1, 2026
TENDER DESCRIPTION
This tender invites proposals for a comprehensive Security Culture Programme, primarily focused on delivering phishing tests and a corresponding awareness and training program for approximately 2900 employees across internal departments and state administrative offices, with the objective of enhancing their ability to identify fraudulent emails. The solution must be fully implemented, tested, and operational within three months of contract signing, feature administrator and end-user interfaces compatible with Microsoft Edge, function without requiring exceptions in security filters, and support integration with Microsoft 365, Single Sign-On (SSO), and Microsoft Entra ID, with an end-user interface in Norwegian. Key technical requirements include role-based access control, robust data protection during transfer and storage, logging of security and administrator events, documented processes for vulnerability management and incident handling, and the processing and storage of personal data within the EU/EØS, Switzerland, or the United Kingdom. Furthermore, the program must incorporate a continuous learning loop with regular phishing simulations and reporting capabilities, while…
TENDER BRIEF
The contract starts on December 1, 2026. The initial duration of the agreement is two years, extending until November 30, 2028. There is an option for the client to extend the contract by one year, twice (1+1 year), making the total potential duration four years.
Key milestones include:
- The solution must be implemented, tested, and ready for use no later than three months after the contract is signed.
- A plan for the establishment phase, which includes roles, responsibilities, and a progress schedule, should be prepared by the supplier in cooperation with the client and is to be included in Annex 3.
Sources
- 1Vedlegg G - Avtalevilkår.pdf — “- bilag 3 Bilag 2: Leverandørens beskrivelse av tjenesten Leverandørs utfylling av Vedlegg D til Konkurransegrunnlaget vil brukes som bilag 2 i denne avtalen. Side 3 av 10 Bilag til SSA-L- bilag 3 Bilag 3: Plan for etabl…”
- 2Konkurransegrunnlag.pdf — “på to år fra 1. desember 2026 til 30. november 2028. Det er opsjon, for oppdragsgiver, på forlengelse med ett år to ganger (1+1 år). 1.5 Økonomisk ramme Det er budsjettert med en ytre kostnadsramme på 2,2 millioner krone…”
- 3Vedlegg E - Oppdragsgivers krav til leveransen.docx — “eller tjenesten. Oppfylt? | Svar/kommentar: Velg et element. | Teknisk løsning og drift Nr. | Type | Beskrivelse av krav: 9.1 | A | Administrator- og sluttbrukergrensesnitt skal fungere i Microsoft Edge. Oppfylt? | Svar/…”
The core scope of work for this tender involves the provision of a tool or implementation for phishing tests. The primary objective is to raise awareness and provide training to approximately 2900 employees across internal departments and state administrative offices, enabling them to identify fake emails.
A summary of the Statement of Work and core deliverables includes:
- Phishing Test and Awareness Program: Delivering a tool or implementing phishing tests, coupled with a consciousness-raising and training program to help employees identify fraudulent emails.
- Implementation and Readiness: The solution must be fully implemented, tested, and operational within three months of the contract signing.
- Establishment and Configuration Support: The supplier is required to assist with the necessary setup and configuration of the service.
- Administrator Training: Provision of training for 1-2 administrators or superusers.
- Service Level Agreement (SLA): A standard Service Level Agreement, including standardized compensations, must be provided by the supplier.
- Technical Solution and Operation: The administrator and end-user interfaces must function with Microsoft Edge, and the solution must operate without requiring exceptions in security filters.
- Information Security: The solution must support role-based access control, ensure data protection during transfer and storage, log relevant security and administrator events, and adhere to documented processes for vulnerability management, security updates, and incident handling. The supplier must notify the client of security incidents. Client data must be deleted upon agreement termination as per client instructions.
- Test Environment: The supplier should ideally make a test environment available for evaluating key functionalities.
- Third-Party Deliveries: If the service includes third-party components, the terms and conditions for the client's access and use must be disclosed. This includes outlining client obligations, liability limitations, details on error correction, and applicable guarantees or SLA requirements from the third party.
Sources
- 1Vedlegg E - Oppdragsgivers krav til leveransen.docx — “Bilag 1 - Oppdragsgivers krav til leveransen Bilag 1 inneholder en beskrivelse av bakgrunnen for anskaffelsen, samt en oppstilling av de krav Oppdragsgiver har til leveransen. Dette dokumentet brukes som bilag 1 til avta…”
- 2Vedlegg G - Avtalevilkår.pdf — “- bilag 3 Bilag 2: Leverandørens beskrivelse av tjenesten Leverandørs utfylling av Vedlegg D til Konkurransegrunnlaget vil brukes som bilag 2 i denne avtalen. Side 3 av 10 Bilag til SSA-L- bilag 3 Bilag 3: Plan for etabl…”
Login to view all answers and insights
Unlock tender brief for freeTENDER DOCUMENTS
DIRECTORY • 9 FILES
- Vedlegg D - Taushetsbelagte opplysninger.docx45 KBDOCX
- Konkurransegrunnlag.pdf322 KBPDF
- Vedlegg C - Forbehold og avvik.docx45 KBDOCX
and 2 other documents
Login to view and download all tender documents
Unlock documents for freeASK AI ABOUT THIS TENDER
Can a foreign company apply?
Yes, foreign companies can apply as long as they meet all the requirements set out in the procurement documents.
Login to ask more questions.
Unlock AI tender chat for freeUnlock your tender workflow
Run your first search, evaluate the results, save a daily monitor and start building a pipeline of tenders worth pursuing.