Public procurement · latest award notice published 11 August 2026
DGPI's security lab,
lot by lot
Ten awarded procurement lots outline a lab for testing the security of Romania's Interior Ministry systems: finding exposed assets, probing vulnerabilities, simulating attacks and testing resilience to ransomware.
- awarded lots
- 10
- RON, total value
- RON 6,779,090
- named products
- 4
- described functions
- 5
- title without product
- 1
Institutional position
Where the lab fits
DGPI is the Interior Ministry directorate responsible for internal protection. CERT-INT, the ministry's cyber incident-response centre, operates within DGPI. The laboratory is one component of SAT, a project funded through Romania's National Recovery and Resilience Plan with a total value of RON 106.42 million including VAT. SAT is intended to protect the electronic identity-card ecosystem and the ministry's digital services.
- DGPI
- CERT-INT
- Interior Ministry cyber infrastructure
- SAT · electronic identity card · Interior Ministry digital services
The procurement map
The ten lots
Choose a module for details. Each plate shows the function, any product named in the procurement documents, the supplier and the award value.
- Product namedThe tender names the product. Configuration and use remain unknown.
- Function describedThe lot's role is public. The exact product does not appear in the records reviewed.
- Lot title onlyThe title, supplier and value are public. The product and precise role remain unknown.
Function describedThe lot's role is public. The exact product does not appear in the records reviewed.
Contextual interpretation
What the ten components reveal together
Burp Suite Professional, Burp Suite Enterprise, Core Impact Enterprise and Cobalt Strike appear in the procurement material. Lots 1, 6, 7, 8 and 10 publish a function without naming the product. Lot 9 preserves only its title, supplier and value.
Cobalt Strike and Core Impact are dual-use products. The same procurement covers vulnerability scanning, application analysis, traffic simulation and ransomware-resilience testing. DGPI says CERT-INT's "offensive" work consists of preventive testing and proactive action. Taken together and in the context of CERT-INT's stated mission, the lots are consistent with controlled testing from an attacker's perspective.
- 01find exposure
- 02probe weaknesses
- 03simulate attack methods
- 04collect findings
- 05test resilience
What the records do not show
Lot 9 remains unclear
The exact procurement title is "Componentă software remote data acquisition". The records describe one software component and show that the lot was awarded to Dendrio Innovations for RON 380,100 before VAT.
The title does not establish a precise function. The records reviewed do not disclose the product, access method, data type, target systems or how the component would be used. They do not establish a surveillance function. The surrounding lab makes a security or incident-response role plausible. That remains an inference.
- product
- access method
- data type
- target systems
Limit of the record
What the records do not establish
The notices show which lots DGPI awarded. Four questions that affect interpretation remain open:
- 01
Installation
Award notices do not establish that every product was installed and accepted.
- 02
Integration
The sequence on this page explains the functions. The records do not describe one technical workflow connecting every component.
- 03
Use
The records do not show how the products were used after award or which configurations were used.
- 04
Targets
The material reviewed does not identify use against organizations outside the Interior Ministry.
Complete ledger
Suppliers and values
The award values for the ten lots add up to exactly RON 6,779,090 before VAT.
| Lot | Function | Named product | Record | Supplier | Value |
|---|---|---|---|---|---|
| 1 | Attack surface management | Product not identified | Function described | Logic Computer | 506,880 |
| 2 | Web vulnerability scanning, type 1 | Burp Suite Professional | Product named | Pragma Computers | 13,707 |
| 3 | Web vulnerability scanning, type 2 | Burp Suite Enterprise | Product named | Pragma Computers | 315,673 |
| 4 | Penetration testing, type 1 | Fortra Core Impact Enterprise | Product named | Pragma Computers | 259,385 |
| 5 | Penetration testing, type 2 | Fortra Cobalt Strike | Product named | Pragma Computers | 197,045 |
| 6 | Static and dynamic application analysis | Product not identified | Function described | Power Net Consulting | 923,000 |
| 7 | Centralized vulnerability management | Product not identified | Function described | Simple IT | 524,900 |
| 8 | Network traffic and cyberattack simulation | Product not identified | Function described | Dendrio Innovations | 2,660,000 |
| 9 | Remote Data Acquisition | Product not identified | Lot title only | Dendrio Innovations | 380,100 |
| 10 | Ransomware resilience testing | Product not identified | Function described | Logic Computer | 998,400 |
| Total | 6,779,090 | ||||
Documentary basis
Sources and calculation
We added the eight values in the original procedure and the two values in the re-tender. The sum is exact. A product counts as named only when it appears explicitly in the procurement material.
"Function described" means that the records specify the lot's role without naming the product. For lot 9, the public records reviewed provide its generic title, supplier and value.
Checked 23 August 2026.
Documents reviewed
La vedere captured the earlier stage, when eight lots had awards. This map begins with publication of the final two results.