Skip to content
TrustList
News

Greece’s National Cybersecurity Authority tenders DDoS and web and API protection services: bids are due by 5 November 2026

Editorial

By TrustList Editorial

Greece’s National Cybersecurity Authority has opened an EU-wide electronic tender for services protecting web applications and APIs against DDoS and application-layer attacks. Bids go through ESIDIS (ID 515094) by 5 November 2026, 17:00.

About Greece’s National Cybersecurity Authority tenders DDoS and web and API protection services: bids are due by 5 November 2026

Greece’s National Cybersecurity Authority tenders DDoS and web and API protection services: bids are due by 5 November 2026

2 October 2026 — Greece's National Cybersecurity Authority announced on 30 September 2026 an open, above-threshold electronic tender for a contractor to provide advanced services protecting web applications and APIs against distributed denial-of-service (DDoS) and application-layer attacks. Bids must be submitted through the national e-procurement system, ESIDIS, at promitheus.gov.gr, under system number 515094, by 5 November 2026 at 17:00.

Not yet independently verified. This rests on the Authority’s own announcement, read in Greek; the tender documents on ESIDIS, which carry the budget, lots and technical requirements, were not read. No independent report was checked. We will update this when it can be confirmed, and remove this note.

What is being bought

The announcement describes services rather than equipment: protection of web applications and APIs against volumetric DDoS and attacks at the application layer. In practice that is the territory of web application firewalls, API security gateways and DDoS scrubbing services, delivered as a managed service. Because the tender is above the EU threshold, it is open to suppliers from across the European Union, and to partnerships between international providers and Greek integrators.

Why it matters

Under the NIS2 directive, the availability of digital services is a compliance issue as well as a reputational one. A national authority buying these services centrally is a signal of where demand is going in Greek public-sector security.

What to do

  • Security vendors and managed service providers offering WAF, API protection and DDoS mitigation: register on ESIDIS if you have not, download the tender documents for number 515094, and check the qualification criteria, which often require certifications, prior public-sector references and local presence.
  • Greek integrators: consider partnering with a provider whose platform meets the technical requirements.
  • Plan the timeline: clarification questions usually close well before the bid deadline, so read the documents now.

Sources

Categories & features