Cybersecurity and data security (pre-qualification criteria)
Article 5
Pre-qualification criteria related to cybersecurity and data security shall require bidders to: (a) take appropriate and proportionate technical, operational and organisational measures that reflect the principles of security by design and by default to ensure the security of the renewable energy installation’s network and information systems including, where relevant, measures listed in Article 21(2) of Directive (EU) 2022/2555; (b) where, 9 months or more before the publication of an auction within the scope of Article 26 of Regulation (EU) 2024/1735, the bidder is subject to the jurisdiction of a third country requiring the bidder to report information on software or hardware vulnerabilities to authorities of that third country prior to those vulnerabilities being known to have been exploited or there is a public statement on behalf of the Union or the Member State carrying out the auction that threat actors operating out of the territory of that third country have carried out malicious cyber activities or campaigns, present a cybersecurity plan outlining how the bidder guarantees the security of the installation and of the overall system and more specifically take the necessary technical, operational and organisational measures to ensure that data used for or generated in their business activities related to the auction are stored in and not transferred outside the European Economic Area; (c) ensure and demonstrate, where the bidder relies on suppliers for the supply of ICT products used in the renewable energy installation or ICT services related to its operation, that the suppliers take the measures referred to in point (a) and where those suppliers meet any of the two conditions set in point (b) for bidders, that those suppliers also take the measures referred to in point (b); (d) ensure that an operator established in the European Economic Area maintains operational control of the installation.