For the Ukrainian IT sector, which aims to expand its presence and contribute to the country's digital transformation, the public procurement market is a strategically important area. In particular, software procurement via Prozorro serves as a key instrument that ensures transparency and competition in the acquisition of technological solutions for government needs. However, engaging with this market segment requires IT companies to possess not only technical expertise but also a deep understanding of the complex regulatory landscape. This includes legislative acts, certification requirements, cybersecurity standards, and the specifics of document management. The editorial team at ua.software explores how Ukrainian IT companies can effectively work with this promising yet demanding market segment to successfully integrate into state digital initiatives.
Legal framework and specifics of software procurement via Prozorro
Participating in software tenders within the Prozorro system requires IT companies to have a thorough knowledge of the legislation. The primary legal framework is the Law of Ukraine "On Public Procurement," which establishes general principles and procedures. In addition to this law, there are a number of bylaws, Cabinet of Ministers resolutions, and departmental orders that detail procedures, particularly for IT solutions and services.
The subject of procurement in the case of software can be either a license to use a finished product or services for custom software development or maintenance. This creates differences from traditional procurement of "goods" or "services," as software is often an object of intellectual property with its own nuances regarding licensing and the transfer of rights. Companies must carefully study the specific subject of procurement defined by the contracting authority in order to correctly formulate their proposal and avoid formal disqualification.
Qualification criteria for tender participants can be quite stringent. Contracting authorities often require proof of experience in executing similar contracts, the availability of qualified personnel with relevant certifications, and sufficient financial capacity. This is intended to ensure contract performance but can become a barrier for young or small IT companies. The problem of dumping also remains relevant, where participants deliberately lower the price to an economically unjustified level, which complicates competition for companies offering high-quality and innovative solutions.
Understanding these legal frameworks and specifics is critical for successful participation in tenders. Failure to comply with requirements can lead to the rejection of a proposal at the evaluation stage, even if the company offers high-quality software. Therefore, legal support and consultations from public procurement specialists are an integral part of preparing for work with the public sector.
Certification and compliance with standards: key requirements for software in the public sector
For software used in the public sector, compliance with security and quality requirements is of particular importance. These are not just recommendations but strict conditions, often enshrined at the legislative level. State expert examination and certification are mandatory for systems that process state information resources or information with restricted access. Here, the State Service of Special Communications and Information Protection of Ukraine (SSSCIP) plays a key role, confirming that the software meets the requirements for technical information protection and cybersecurity.
Cybersecurity requirements are the cornerstone for any IT solution in the public sector. National standards for cybersecurity and information protection, which are often harmonized with international practices such as ISO/IEC 27001, define mandatory measures. This means that software must be developed according to Security by Design principles and include mechanisms for data protection, user activity auditing, and resistance to cyberattacks. For companies, this requires not only technical implementation but also the existence of relevant development and testing processes that confirm the security of the product.
In addition to security, standards for document management and integration are important. Government agencies are actively transitioning to electronic document management, so new software must be compatible with existing state information systems and standards, such as DSTU 4163:2020 for unified document forms. This ensures seamless data exchange and functional interoperability between different agencies, which is critical for the efficiency of public administration.
The absence of necessary certificates, non-compliance with cybersecurity standards, or the inability to integrate with existing infrastructure are direct reasons for the disqualification of a proposal. This requires IT companies to make significant investments in their own development processes, staff training, and obtaining relevant confirmations of the quality and security of their software. Only such an approach will allow Ukrainian developers to successfully compete and implement projects for the public sector.
How can Ukrainian IT companies optimize their participation in software procurement?
To work effectively in the public software procurement market, Ukrainian IT companies need to build a systematic approach. The first step is a thorough analysis of the tender documentation. This includes a detailed study of technical specifications, functional requirements, evaluation criteria, and all contract terms. Underestimating this stage can lead to the submission of an incomplete or non-compliant proposal, which will automatically result in its rejection.
The second important aspect is building internal company processes adapted to state standards. This means that the processes of software development, testing, implementation, and maintenance must take into account specific requirements for information security, electronic document management, and integration with state registries. Often, this requires the implementation of certain quality or security management systems, for example, based on international standards, even if formal certification has not yet been obtained.
Engaging legal and technical support is highly recommended. Public procurement specialists will help to correctly prepare the tender proposal, avoid typical mistakes, and protect the company's interests in case of disputes. Cybersecurity experts will ensure that the developed or proposed software meets current national requirements and standards, which is critical for projects in the public sector. This investment often pays off by increasing the chances of success in tenders.
Proactive interaction with contracting authorities can also significantly increase the chances of winning. Participation in pre-tender consultations, if held, and the timely submission of questions to clarify procurement terms help to better understand the client's needs and adapt the proposal. This also demonstrates the company's seriousness and professionalism to the client. A systematic approach and readiness to invest in the adaptation of internal processes allow IT companies not only to win individual tenders but also to scale cooperation with the public sector, contributing to its digital transformation.
According to Anton Marrero, a member of the supervisory board and board of directors of Intecracy Ventures, success in the software procurement market requires companies to have a strategic vision that goes beyond a one-time tender win. He emphasizes that it is necessary to constantly invest in compliance with new regulatory requirements and increase the level of expertise in cybersecurity and integration issues. This allows not only to ensure the digital resilience of the state but also contributes to the development of domestic technological solutions with high added value.
Software procurement via Prozorro is a promising but highly regulated segment for Ukrainian IT companies. This market has strategic importance for the development of domestic technologies and ensuring the country's digital sovereignty. Successful work with the public sector requires not only technical excellence of products but also a deep understanding of legislative requirements, cybersecurity standards, and certification processes. Constant adaptation and investment in compliance with these requirements will allow Ukrainian IT companies not only to win tenders but also to play a key role in building a modern, secure, and efficient digital state.
Frequently asked questions
What is state expert examination of software?
State software examination is a mandatory procedure for confirming that software products intended for use in state information systems meet the requirements for technical information protection. It is conducted by the SSSCIP or authorized bodies. Without such an examination, software cannot be legally used in most government agencies.
How does Prozorro affect the transparency of software procurement?
Prozorro ensures a high level of transparency by publishing all information about tenders, participant proposals, and results. This minimizes corruption risks, allows the public and businesses to monitor the process, and creates a competitive environment for software providers.
Are there specific cybersecurity requirements for software in the Ukrainian public sector?
Yes, there are. Software for government agencies must comply with the requirements of national cybersecurity and technical information protection standards and pass the relevant state examination. This applies to data protection, system integrity, and business continuity.
What are the main challenges for Ukrainian IT companies when participating in Prozorro software tenders?
The main challenges are the complexity of tender documentation, the need to have relevant certificates and licenses, high requirements for cybersecurity and integration, and competitive pressure. Companies need to invest in regulatory compliance and have a deep understanding of the process.
Can startups participate in software procurement?
Theoretically yes, but in practice, it is more difficult due to high qualification requirements regarding experience, financial capacity, and the availability of certificates. Startups can consider participating in smaller procurements or working through partners who already have the necessary base.