Procurement support

Buying certified equipment, without surprises late in the process

Most of our customers buy under public procurement rules. This page sets out the routes we deliver through, what we can supply as tender documentation, and how to word a requirement so that it cannot be met by equipment that only claims to be certified.

Routes

How we can be procured

  1. Direct award

    When: Below the threshold value, or when only one supplier can meet the requirement.

    What we supply: Quote, technical specification and delivery terms. Fastest route to a working installation.

  2. Published tender (LOU / LUFS)

    When: Above the threshold. LUFS applies to defence and security procurement specifically.

    What we supply: Tender response, certification evidence, references and the documentation the contracting authority asks for.

  3. Call-off from a framework agreement

    When: Your organisation already has a framework covering secure IT equipment.

    What we supply: Delivery through the framework holder. Tell us which agreement and we will confirm the route.

  4. Security-protected procurement (SUA)

    When: The assignment involves classified information or protection-worthy activity.

    What we supply: We work under security protection agreements as a main supplier to the Swedish Total Defence. The process is driven by your authority; we take part in it.

Writing the requirement

Five clauses that keep uncertified equipment out

The most common problem we see is a specification that describes the function but not the approval. It lets a cheaper, uncertified product qualify on paper — and the gap is discovered after delivery, when it is expensive.

  1. Certification level

    State the required level rather than a product name — "TEMPEST Level A in accordance with SDIP-27, corresponding to RÖS U1" leaves no room for a cheaper substitute that is not certified.

  2. Evidence of certification

    Require certification issued by an accredited laboratory, and require the certificate to be presented with the tender. A datasheet claim is not a certificate.

  3. Country of design and manufacture

    If supply-chain control matters, say so explicitly. Design, development and production in one country is a requirement that can be verified.

  4. Lifecycle and spare parts

    State the required support period and spare parts availability. Secure installations outlive ordinary IT procurement cycles.

  5. M-number where applicable

    For Swedish Armed Forces deliveries, require the equipment to carry an M-number. It is the approval that matters in that context.

Documentation

What we can supply with a tender

All published documents
  • Datasheets and technical specifications
  • Certification evidence, TEMPEST Level A/B and RÖS U1/U2
  • ISO 9001 and ISO 14001 certificates
  • Conflict minerals declaration and code of conduct
  • M-numbers where the equipment carries one
  • References, on request and subject to customer consent

Test reports and specific approvals are not published openly. Ask for them in your request and state the tender they relate to.

Export control

Destination decides what is possible

TEMPEST-certified equipment is export-controlled. The destination country — not the sector you work in — governs what may be delivered and what approvals are required. Tell us the country at the start of the conversation rather than at the end; it is the single fastest way to establish what is possible, and it is why country is a required field on the quote form.

100Requirement clausesReady to paste into a specification, with the reasoning stated.

Next step

Send us the requirement specification

We will tell you what we can meet, what needs rewording, and what documentation to expect – before you publish it.

Verified credentials

All certifications