TSCNET Services GmbH, based in Munich and ISO 27001:2022 certified, seeks a qualified third-party Regulatory Information Security Auditor to perform audits aligned with EU energy sector regulations. The contractor must be an experienced ISO 27001:2022 Lead Auditor with strong service delivery and expertise in regulatory audits. Audits must comply with frameworks from ENTSO-E and ACER, and adapt to evolving EU and national cybersecurity, data protection, and energy governance requirements. The contract is expected to span at least four years.
TSCNET Services GmbH (TSCNET) located in Munich, Germany, is an ISO 27001:2022 certified organization providing services 24 hours a day, 7 days a week, 365 days a year, to Contracting Authorities operating critical infrastructure connected to the Central and Eastern European power grid. As part of TSCNET's requestor’s input for Regulatory Information Security Auditor Services, TSCNET wishes to contract a specialist third-party to undertake regulatory information security audits. The third-party needs to be a qualified ISO 27001:2022 Lead Auditor with not only best of breed expertise, but excellent service delivery and multiple years' experience in regulatory audits. The audits must be aligned with the regulatory expectations and frameworks established by: a) ENTSO-E (European Network of Transmission System Operators for Electricity) – https://www.entso-e.eu, which coordinates the operation of Europe’s electricity transmission networks and sets cybersecurity and operational standards for TSOs. b) ACER (European Union Agency for the Cooperation of Energy Regulators) – https://www.acer.europa.eu, which oversees the implementation of EU energy regulations, including cybersecurity and data protection obligations under the Network Code on Cybersecurity and other relevant EU legislation. Given that the contract is expected to span at least four years, TSCNET anticipates that additional compliance requirements may emerge over time. Therefore, the scope of regulatory alignment shall not be limited to ENTSO-E or ACER alone. The selected auditor must demonstrate the capacity to adapt to evolving EU and national regulatory frameworks, including but not limited to cybersecurity, data protection, and energy sector governance, as defined by current and future mandates from ENTSO-E, ACER, and other relevant authorities.
Lassen Sie die KI die Vergabeunterlagen analysieren und strukturierte Informationen zu Fristen, Anforderungen und Bewertungskriterien extrahieren.
20251028_TSCNET_EU Tender_ESPEAS_QA.pdf
PDF • 38.8 KB
Nachricht_vom__2025-10-27T002837.html
HTML • 1.6 KB
20250801_Tender_ESPEAS_10_BP_External Business Partner Screening Questionnaire_company name.docx
DOCX • 295.6 KB
20250801_Tender_ESPEAS_04_Ref_Reference List_company name.docx
DOCX • 40.1 KB
20250801_Tender_ESPEAS_03_GFEX_Grounds for exclusion_company name.docx
DOCX • 210.4 KB
20250929_TSCNET_Public procurement procedure documents guideline.pdf
PDF • 48.7 KB
20250929_TSCNET_EU Tender_QA.xlsx
XLSX • 18.6 KB
Nachweis eines zertifizierten ISMS für den gesamten Projektzeitraum.
Sämtliche Kernmitglieder müssen Deutschkenntnisse auf C1-Niveau nachweisen.
Mindestens drei vergleichbare Projekte in Bundes- oder Landesbehörden in den letzten 5 Jahren.