If your company sells software or hardware to Spanish local councils — parking or access-control systems, ANPR/license plate recognition, video surveillance, waste management, or booking platforms for public facilities — you'll increasingly run into tender documents (pliegos) that require a cybersecurity audit and GDPR/LOPDGDD compliance report as a condition to bid, not just as a nice-to-have.

This is especially common for concessions involving access control, license plate recognition (ANPR), video surveillance, traveller registration, or any platform that processes citizens' or users' personal data. Here's what these requirements actually look like, and what you need to have ready before the submission deadline closes.

The clauses that show up most often

  • Cybersecurity audit of the tendered system. Some tenders explicitly ask for a penetration test or vulnerability audit report on the platform being deployed, sometimes referencing INCIBE (Spain's national cybersecurity institute) as a benchmark — without necessarily requiring its direct involvement.
  • GDPR/LOPDGDD compliance. Documentation on the legal basis for processing, technical and organisational measures, data retention periods, and often a data processing agreement with the contracting authority.
  • Disclosure of server location and technology subcontractors. Where the data is hosted, which providers are involved (hosting, payment gateway, communications), and whether there are any transfers outside the EU.
  • Compliance with Spain's National Security Framework (ENS). Increasingly common in video surveillance or infrastructure connected to public administrations.
  • Traveller registration and telematic reporting (RD 933/2021). Mandatory for accommodation, motorhome areas and campsites: secure ID document scanning and automatic notification to law enforcement authorities.
  • Network architecture and data flow diagrams. Proof of what data leaves the local network, what's encrypted, and what contingency measures exist if connectivity fails.

What the technical report needs to include

A generic responsible declaration isn't enough. A report that actually satisfies these requirements typically includes:

  • Vulnerability analysis or penetration testing of the exact system or platform under contract, with documented methodology.
  • A regulatory compliance review scoped specifically to the tendered service — not your company's generic privacy policy.
  • A map of data sub-processors and their role (payment processing, hosting, communications, analytics).
  • An assessment of network architecture: what data travels outside the installation, how it's encrypted, and what happens if connectivity is lost.
  • Documentation written so the evaluation committee can verify it unambiguously — a technical report they can't follow doesn't count as proof of compliance.

The most expensive mistake: leaving it until the last few days

1–2 weeks

The typical timeline to complete a cybersecurity audit and the GDPR compliance report a tender requires — but only if you start with enough margin before the submission deadline.

Tender submission deadlines are fixed and cannot be extended. I've seen companies with an excellent technical and financial proposal get excluded simply because the cybersecurity documentation wasn't ready in time, or didn't specifically cover what the tender asked for. The evaluation committee cannot assess an incomplete bid, no matter how good the rest of it is.

A common case: software vendors bidding to local councils

I've helped companies in the parking management, access control and motorhome/camper area sector prepare this documentation for municipal tenders: a security audit of the platform, a GDPR/LOPDGDD compliance report, and network architecture documentation, all within the bid submission deadline. The same pattern repeats in low-emission zones, municipal video surveillance, waste management access control and public sports facilities: any system that identifies people or vehicles and connects to a public administration tends to require this kind of documentation — regardless of whether the vendor is based in Spain or elsewhere in the EU.

Public tender audit vs. standard security audit

Web security audit
€450–€1,400

Scoped to your own website or application, with no specific format for a public administration. Useful as a baseline, but usually doesn't cover a tender's requirements on its own.

If your company bids on Spanish public tenders regularly, it's worth treating this as a standard part of your bid preparation process rather than a one-off scramble — and, once a concession is awarded, keeping up an annual follow-up audit in line with the ongoing obligations these contracts usually include (breach notification, sub-processor review, updated technical measures).

Bidding on a Spanish public tender with cybersecurity or GDPR requirements?

Tell me your submission deadline and exactly what the tender document asks for. I'll tell you within 24h whether we can make it, and what a fixed-price quote would look like.

Discuss your case →