Dutch Grid Operator Signs Up to EUR 21.8 Million Cybersecurity Partner, But Won't Say Who

By Admin | Posted on 19 Aug 2026


Dutch Grid Operator Signs Up to EUR 21.8 Million Cybersecurity Partner, But Won't Say Who

Standfirst

Enexis Groep, one of the Netherlands' largest electricity grid operators, has awarded a strategic cybersecurity partnership worth an estimated EUR 14 530 000, rising to a stated maximum of EUR 21 795 000, to strengthen its IT and industrial control system defences. The notice withholds the winning supplier's identity entirely and the underlying data contains signs it may not have been fully prepared for publication.

Introduction

Electricity grid operators sit near the top of any list of infrastructure worth protecting from cyberattack, spanning both conventional IT systems and the operational technology that actually controls substations and distribution equipment. Enexis Groep, the Dutch grid operator serving large parts of the country, has just locked in a long term partner to help close the gap between where its digital defences stand today and where it wants them to be.

Unusually, the notice recording that decision does not name the winner. Nor does it name the company that lost. Both appear only as "Anonymous 1" and "Anonymous 2," and several other fields in the same record carry the hallmarks of placeholder text rather than finished data.

Why This Contract Matters

Enexis describes the goal of this contract in its own tender documents: a strategic partner that substantially contributes to strengthening its security organisation across both IT and OT, the operational technology layer that runs grid infrastructure directly. The work is commissioned by Enexis's first line security function, its Digital Resilience Center and spans operational, tactical and strategic levels, with the partner expected not just to execute predefined resilience goals but to challenge them critically and help shape targets for future years.

For a company responsible for keeping electricity flowing to a large share of the Netherlands, a multi year, potentially eight year cybersecurity partnership of this depth is a significant statement about how seriously grid operators now treat digital resilience as core infrastructure risk, on par with physical asset maintenance.

Contract Timeline

  • Original tender procedure referenced by this result: a previously published notice on file with the Publications Office
  • Winner selected: 29 May 2026
  • Contract concluded: 23 June 2026
  • Notice dispatched to the Publications Office: 18 August 2026
  • Published in the Official Journal, OJ S 159/2026: 19 August 2026
  • Base contract term: 4 years, with options to extend by 2 years twice, for a maximum of 8 years

Contract Overview

Enexis ran a negotiated procedure with prior publication of a call for competition, under the EU's Utilities Directive, to select a strategic cybersecurity partner. Two tenders were submitted, both electronically and one was selected as the winner, structured as a framework agreement without reopening of competition, meaning the chosen partner holds the relationship exclusively for the contract term.

The notice's value fields do not fully agree. The procedure level and lot level estimated value, along with the notice's overall approximate framework value, are all stated at EUR 14 530 000. The lot result section, however, records a separate maximum framework value of EUR 21 795 000, roughly one and a half times higher, alongside a re-estimated value that matches the lower EUR 14 530 000 figure. Neither the winner's nor the competing bidder's identity, nor several other organisational details, are disclosed in usable form.

Key Contract Details

Contracting authorityEnexis Groep
Contract titleAccelerate Cyber Readiness
CPV code72000000, IT services: consulting, software development, Internet and support
Procedure typeNegotiated procedure with prior publication of a call for competition
Legal basisDirective 2014/25/EU, the Utilities Directive
Estimated / approximate valueEUR 14 530 000, excluding VAT
Maximum framework value (lot result field)EUR 21 795 000, an unreconciled figure roughly 1.5 times the estimate
Base contract term4 years
Renewal optionsTwo renewals of 2 years each, maximum total term 8 years
Tenders received2, both submitted electronically
WinnerIdentity withheld, listed as "Anonymous 1," classified as a medium enterprise
Non-winning tendererIdentity withheld, listed as "Anonymous 2," classified as a large enterprise
Winner selected29 May 2026
Contract signed23 June 2026
GPA coverageYes
Framework structureFramework agreement without reopening of competition
SubcontractingNo, per winner's tender
Complaints received0
Review bodyRechtbank Oost-Brabant ('s-Hertogenbosch)
Notice reference574621-2026, OJ S 159/2026, published 19 August 2026

Project Scope

The contract covers a strategic partnership to strengthen Enexis's security organisation across both IT and operational technology domains, commissioned through the company's Digital Resilience Center, its first line security function. The scope explicitly spans three levels: operational work supporting day to day security functions, tactical work shaping how security programmes are implemented and strategic work setting the direction of Enexis's digital resilience goals over time. The partner is expected to actively challenge existing targets rather than simply execute them and to help define resilience objectives for years beyond the current contract term.

About the Contracting Authority

Enexis Groep is a Dutch electricity distribution grid operator, based in 's-Hertogenbosch in the Noord-Brabant region, classified as a contracting entity active in electricity related activities. Enexis manages electricity and gas distribution infrastructure across a substantial part of the Netherlands, making the resilience of its IT and operational technology systems a matter of direct public interest for the millions of households and businesses it serves.

About the Organisations Involved

Enexis Groep

As covered above, Enexis is the buyer for this contract and is also the organisation providing further procedural information and offline access to the tender documents.

Rechtbank Oost-Brabant

Rechtbank Oost-Brabant, based in 's-Hertogenbosch, is named as the review organisation for this contract, the regional court with jurisdiction covering Enexis's registered location, with review deadline details deferred to the underlying tender documentation.

The winner and the non-winning tenderer

Both the winning supplier and the unsuccessful competing tenderer are identified in this notice only as "Anonymous 1" and "Anonymous 2," classified respectively as a medium and a large enterprise. Every other identifying field for both organisations, including postal address, contact name, email address, telephone number and registration number, is populated with generic placeholder text rather than genuine information. Notably, the organisation labelled "Anonymous 1" also appears listed separately among the notice's non-winning tenderers, an internal inconsistency, since the same entity cannot logically be both the winner and an unsuccessful bidder. The winning tender's own identifier field is recorded simply as the word "TEST." Together, these details suggest this notice may not have been fully finalised before publication, rather than reflecting a clean, deliberate anonymisation process.

Procurement Analysis

Enexis used a negotiated procedure with prior publication of a call for competition, a route well suited to complex, relationship driven service contracts like a multi year strategic security partnership, where the buyer benefits from dialogue with bidders before finalising terms. Only two tenders were received, a reasonable field for a specialised, high trust engagement of this kind, where relatively few firms combine deep IT and operational technology security expertise at the scale a national grid operator requires.

Withholding a cybersecurity contractor's identity is not inherently unusual or improper. Publicly naming the firm responsible for hardening a critical infrastructure operator's digital defences could itself provide useful reconnaissance information to a potential attacker and some buyers deliberately redact this kind of detail for exactly that reason. What is unusual here is the specific character of the redaction: professional anonymisation typically removes identifying detail cleanly, whereas this notice retains structurally complete fields populated with generic, template style placeholder text, the word "TEST" as a tender identifier being the clearest signal that this may be incomplete data entry rather than intentional security redaction.

The unreconciled value figures compound the picture. A EUR 14 530 000 estimate appears three times across the notice, while a separate EUR 21 795 000 maximum framework value appears once, in the lot result section, with no explanation offered for the roughly 50 percent gap between the two.

Additional Procurement Facts

  • No complaints were recorded against this award.
  • Neither the winning nor the non-winning tender is recorded as a variant bid.
  • Subcontracting is recorded as not applicable for the winner and not yet known for the non-winning tenderer.
  • This procurement is confirmed as covered by the Government Procurement Agreement.

Market and Industry Perspective

Strategic cybersecurity partnerships spanning both IT and operational technology are an increasingly common structure among European critical infrastructure operators, reflecting growing recognition that grid security requires integrated defence across conventional networks and the industrial control systems that manage physical equipment. Energy sector cybersecurity has drawn sustained attention across Europe amid heightened geopolitical tension and contracts of this scale and duration, potentially running eight years, indicate grid operators are treating this as long term institutional capability building rather than a short term response to any single threat.

Economic Significance

Whether the true ceiling is EUR 14 530 000 or EUR 21 795 000, this is a substantial, multi year investment in critical infrastructure cybersecurity by one of the Netherlands' major grid operators, reflecting the scale of resource national utilities are now committing to digital resilience.

Future Procurement Opportunities

With two available two year renewal options built into the framework, Enexis retains flexibility to extend this partnership incrementally toward its maximum eight year term or to return to the market earlier should the relationship not develop as intended.

Opportunities for Suppliers

Cybersecurity firms with combined IT and operational technology expertise serving European critical infrastructure operators should note that this category of strategic, multi year security partnership continues to be a meaningful growth area for grid operators specifically. Given the redacted nature of this particular notice, firms interested in this market may need to monitor future Enexis and comparable Dutch utility tenders directly rather than relying on this result to identify the current incumbent.

What Businesses Should Watch

  • Whether Enexis or the Publications Office issues a correction clarifying the withheld supplier identities or the unreconciled value figures in this notice.
  • Broader patterns of anonymised or incompletely published notices across Dutch utility cybersecurity procurement.
  • Whether Enexis exercises its renewal options as the base four year term progresses.
  • Comparable strategic cybersecurity partnership tenders from other European grid and utility operators.

NetherlandsTenders.com Procurement Intelligence

This notice sits at an interesting intersection of two legitimate but distinct practices: security conscious redaction of sensitive supplier information and incomplete data preparation before publication. Businesses and analysts relying on TED notices for market intelligence should treat this distinction carefully. A properly redacted notice still conveys genuine, reliable information about contract scale, structure and timing even without naming the parties involved; a notice populated with unfinished template data, by contrast, may contain figures and details that were never meant to be published in their current form, including the apparent duplication of the winning bidder within the losing tenderers list.

For grid operators and other critical infrastructure buyers considering how much detail to disclose in cybersecurity related procurement notices, this case is a useful cautionary example: redaction protects security, but it should be applied cleanly and consistently, not left showing template artefacts like literal placeholder words, which can undermine confidence in the notice's other, more substantive figures.

Strategically, the underlying contract itself, a long term, high value strategic partnership spanning both IT and operational technology security for a major European grid operator, is a genuinely significant data point about where utility cybersecurity investment is heading, even if this particular notice cannot confirm who ultimately won the work.

Supplier Takeaways

  • This notice withholds both the winning and losing bidders' identities, illustrating that critical infrastructure cybersecurity contracts sometimes involve deliberate confidentiality around supplier identity.
  • Several data fields in this notice, including a tender identifier literally recorded as "TEST," suggest incomplete preparation rather than a clean anonymisation process.
  • The notice's value figures range from EUR 14 530 000 to EUR 21 795 000 depending on which field is read, an unreconciled discrepancy worth independent verification.
  • Strategic, multi year IT and operational technology security partnerships remain a significant growth category for firms serving European grid and utility operators.
  • The contract's potential eight year term, through two available renewal options, underscores how long term these critical infrastructure security relationships are structured to run.

Key Takeaways

  • Enexis Groep awarded a strategic IT and operational technology cybersecurity partnership worth an estimated EUR 14 530 000, with a separately stated maximum of EUR 21 795 000.
  • Both the winning and losing bidders' identities are withheld in this notice, replaced with generic placeholder labels.
  • Data quality issues in the notice, including a literal "TEST" tender identifier and a winner also appearing among non-winning tenderers, suggest incomplete data preparation.
  • The contract runs a base term of 4 years, extendable by up to two further 2 year periods, for a maximum of 8 years.
  • Only two tenders were received under this negotiated procedure.
  • No complaints were recorded against the award.

Conclusion

A major Dutch grid operator has committed to strengthening its cyber defences across both office IT and the operational technology that keeps electricity flowing, in a partnership that could run the better part of a decade. Who exactly is doing that work and precisely how much it will ultimately cost, are questions this particular public record cannot yet answer, a reminder that even in an era of mandated procurement transparency, the paperwork does not always keep pace with the deal itself.

Source: Tenders Electronic Daily (TED), Contract Award Notice 574621-2026, Official Journal of the European Union, OJ S 159/2026, published on 19 August 2026.

Frequently Asked Questions (FAQs)

The contracting authority is Enexis Groep, one of the Netherlands' main electricity distribution network operators based in 's-Hertogenbosch. Official notice details can be reviewed directly on the TED Notice 574621-2026 Result Page.
The official result notice withheld the identity of both the winning medium enterprise (ANONIEM 1) and the non-winning large enterprise bidder (ANONIEM 2), as analyzed on NetherlandsTenders Blog.
The contract covers strategic IT and OT (Operational Technology) cybersecurity services, industrial control system (ICS) protection, and digital resilience architecture managed through Enexis’s Digital Resilience Center.
The procedure-level estimated value is €14,530,000.00 EUR, while the maximum lot-level framework value is stated at €21,795,000.00 EUR excluding VAT over an 8-year potential term.
A comprehensive procurement analysis detailing the anonymous bidding outcome, IT/OT security scope, value discrepancies, and framework duration is published on NetherlandsTenders.com's Blog.
Enexis conducted a Negotiated procedure with prior publication of a call for competition under EU Utilities Directive 2014/25/EU.
The framework agreement has a primary base term of 4 years (48 months), with two 2-year extension options, allowing a maximum total duration of 8 years.
A total of 2 tenders were received during the competitive negotiated procedure, with both bids submitted electronically.
The primary Common Procurement Vocabulary classification code is 72000000 (IT services: consulting, software development, Internet and support).
Cybersecurity suppliers, grid infrastructure consultants, and bidding practices can monitor Dutch utility tenders, framework agreements, and official award result notices via NetherlandsTenders Blog and the official EU TED Supplement Portal.
NetherlandsTenders Features
NetherlandsTenders Features

Fresh and verified Tenders from Netherlands. Find, search and filter Tenders/Call for bids/RFIs/RFPs/RFQs/Auctions published by the government, public sector undertakings (PSUs) and private entities.

  • 1,000+ Tenders
  • Verified Tenders Only
  • New Tenders Every Day
  • Tenders Result Data
  • Archive & Historical Tenders Access
  • Consultants for RFI/RFP/RFQ
  • Tender Notifications & Alerts
  • Search, Sort, and Filter Tenders
  • Bidding Assistance & Consulting
  • Customer Support
  • Publish your Tenders
  • Export data to Excel
  • API for Tender Data
  • Tender Documents
Tender Experts
Get A Call From Tender Experts

Fill out the form below and you will receive a call from us within 24 hours.

Thank You for Contacting NetherlandsTenders !!
Email Id is already exist !!
Captcha Image
Invalid Captcha !

Get FREE SAMPLE TENDERS from Netherlands in your email inbox.