17 Matching Annotations
  1. Sep 2026
    1. Finnish procurement specialist spotted 15 digital systems connected to this proposal: Vijftien digitale systemen die uit de nieuwe Europese inkoopregels voortvloeien als noodzakelijke stappen; met artikelnummers: (Bron: Finse procurement specialist)

      1. Een gedeeld EU-netwerk dat nationale aanbestedingssystemen verbindt (art. 128)
      2. Gemeenschappelijke technische normen voor aanbesteding (Art. 129)
      3. Fallback-specificaties als die normen te laat zijn (Art. 130)
      4. Nationale en commerciële aanbestedingsplatforms (Art. 131)
      5. Het eigen aanbestedingsplatform van de Commissie (Art. 132)
      6. De EU-dienst die controleert of een bedrijf mag inbieden (art. 133)
      7. De bedrijfsportemonnee en haar netwerk, midden 2028 (Art. 133)
      8. Het geschiktheidsprofiel van het bedrijf (art. 133)
      9. Het algoritme dat bepaalt wie wordt uitgenodigd onder de nieuwe dynamische procedure (Art. 133)
      10. Verbindingen van nationale registers tot de portemonnee, midden 2029 (art. 29)
      11. Het nationale inkoopdatacentrum (Art. 134)
      12. Het EU-brede inkoopdatacentrum (art. 135)
      13. Toegangsbeheer over de twee datahubs (Art. 136)
      14. De publicatieketen naar het EU-Officieel Tijdschrift (Art. 110–113)
      15. De technische validatiegegevens moeten slagen voordat ze meetellen (art. 112, 134, 135)
    1. The revision was announced in President von der Leyen's Political Guidelines.   It responds to long-standing shortcomings identified by the European Court of Auditors, including declining competition, limited SME and cross-border participation, and the rise of single-bid procedures. It also follows calls from the Council of the EU and the European Parliament for a strategic, simplified, and competitive framework.     It also responds to the recommendations of the Draghi and Letta reports, which highlight public procurement as a strategic tool to strengthen Europe's industrial base, support innovation, advance the green and digital transitions, and reinforce economic security.

      as announced in political guidelines based on Draghi/Letta reports

    2. New provisions on resilience and security of supply would apply to contracts involving entities linked to critical infrastructures and aim to support diversification of supply chains, security of supply and crisis preparedness.

      als cf political guidelines.

    3. enables, and in some cases requires, public buyers to address risks related to security and public safety of the Union or Member States, sensitive information, cybersecurity, and undue third-country influence

      digital sovereignty a factor. Check in which cases it is mandatory, suspect only wrt critical infra.

    4. Public buyers will thus have to systematically consider not only price, but also quality, including environmental, social, innovation, security and resilience, and 'European preference' considerations.

      qualitative (non mandatory) aspects to consider: environment, social, innovation, security, resilience and European preference.

  2. Feb 2026
    1. een versterkte aanpak op het afspreken, invoeren en handhaven van (digitale) standaarden, zoals via Nederlandse Digitaliseringsstrategie. Daarnaast noemt de brief het inzetten op meer steun bij implementatie en toetsing vooraf bij IT-projecten.

      2 takken: meer accent op afspreken van standaarden, de invoer en handhaving (dat laatste is wassen neus al jaren), oa via NDS (welk deel NDS dan? #openvraag) En tak steun bij implementatie en toetsing vooraf bij IT projecten. Ik mis hier het woordje inkoop. Staat dat wel in brief? Ja: [[Brief - Informeren Tweede Kamer over de Meting Informatieveiligheidsstandaarden en Monitor Open Standaarden 2025]]

    1. Ik onderzoek ook hoe we IT-projecten en aanbestedingen bijoverheidsorganisaties vooraf kunnen toetsen en een zwaarwegend advies meekunnen geven over de uit te vragen relevante verplichte standaarden van de ‘Pastoe of leg uit’-lijs

      Ah, ja gaat dus in de brief v Digistas ook om inkoop/aanbesteding.

    1. “Digitale inkoop en aanbestedingen worden gestandaardiseerd en gecentraliseerd, gestuurd op security-by-design, zero-trust, soevereiniteit, open source en ketenveiligheid. De overheid benut haar marktmacht om veilige standaarden af te dwingen en stelt rijksbrede minimumeisen op voor security. Om voor financiering in aanmerking te komen moeten IT-projecten van de overheid (> €5 mln.) aan centrale IT-standaarden worden getoetst”

      is dit ook voor decentrale overheden? 'rijksbreed' is niet overheidsbreed. Wel goed dat uitsluitende voorwaarden lijken te gaan worden gesteld tav standaarden, security by design, zero-trust, soevereiniteit, open source en ketenveiligheid. Maar met 5 miljoen als ondergrens. Daarmee kijkt de VS nog vrolijk mee in alle documenten en zaaksystemen lijkt me. En grotere projecten zullen worden opgeknipt in fasen van elk net geen 5 miljoen. Maar is een begin.

  3. Jan 2026
    1. Procurement requirements could include open supply chain tooling. If an agency requires SBOMs, they could also require that generation doesn’t depend on proprietary services. If they require vulnerability scanning, the scanner could consume open advisory databases. Germany’s ZenDiS and openCode.de initiatives are relevant here. Connecting them with existing open solutions would be more efficient than starting fresh.

      Add (kick-out!) requirements to procurement specs. This is a way ensure open source and standards get adopted. Mentions ZenDiS, openCode.de as relevant examples. - [ ] return to look at ZenDiS and opencode.de

    2. Dries Buytaert extended this to procurement: governments buy from system integrators who package and resell open source, but that money doesn’t reach the maintainers who build it. If procurement scoring rewarded upstream contributions, money would flow differently. Open source is “the only software you can run without permission” and therefore useful for sovereignty, but it needs funding to work.

      See [[Funding Open Source for Digital Sovereignty]]

    1. Data Protection Impact Assessment (DPIA) before deploying any new technology that is "likely to result in a high risk to the rights and freedoms of natural persons." When conducted for US hyperscaler services, these DPIAs invariably flag the CLOUD Act as a significant, often unacceptable, risk. This legal obligation is increasingly becoming the primary driver of public bodies to seek alternatives.

      DPIAs are a key reason US hyperscaler services become red flagged in procurement processes.

  4. Dec 2025
    1. overheden, stimuleer de vraag naar alternatieven voor de diensten van grote Amerikaanse bedrijven zoals Microsoft, Google en Amazon. Doe een percentage – bijvoorbeeld 20 of 30 procent –van de overheidsbestedingen Europees. Dan stimuleer je de vraag en gaan Europese bedrijven die producten en diensten ook ontwikkelen

      public procurement is the easiest way to change things. that money is already being spent on digital, so if more of it is spend on European providers that's a helpful step.