Chapter 2 — Research and development procurement Proposed — COM(2026) 567

Article 28 — Security considerations in R&D procurement

In brief

This article requires public buyers to take appropriate, additional measures to protect the security and public safety interests of the Union or its Member States whenever an R&D procurement procedure is identified as presenting a security or public-safety risk. The obligation applies across the whole procedure, from planning and market consultation to contract award and performance. It operates alongside, and without prejudice to, other applicable Union legislation.

Key points

  • It lists illustrative security and public-safety interests, such as protecting critical and dual-use infrastructure, preventing espionage, sabotage or technology leakage, cybersecurity, crisis preparedness and public health.
  • Risks may stem from the subject matter of the contract (for example sensitive assets, sensitive data, dual-use results or critical third-country dependency) or from the characteristics of economic operators (for example ownership, control, financing, security track record or exposure to third-country laws).
  • Buyers should specify proportionate, non-discriminatory measures in the procurement documents, through technical specifications, selection and award criteria, and contract performance conditions.
  • Buyers may restrict invitations to tender to operators meeting objective security requirements, provided this intention is flagged in the contract notice.
  • Operators identified as high-risk suppliers under the referenced Cyber Security Act framework must be excluded in relation to key ICT assets, and the Commission may adopt delegated acts setting mandatory requirements where internal-market disparities arise.

What it means in practice

Public buyers running R&D procurement will need to assess security and public-safety risks early and translate them into clear, proportionate requirements in their tender documents. Innovative firms, start-ups and SMEs bidding for such contracts may face security-related specifications, selection or award criteria, vetting or clearance obligations, and oversight clauses, and could be excluded where they are identified as high-risk suppliers for key ICT assets.

Anthony Bochon’s analysis

In my view this provision marks a decisive shift in how the Union treats security as a horizontal dimension of R&D procurement rather than a matter left to defence-specific rules. The article deliberately runs security across the whole lifecycle — from planning and market consultation through to award and performance — and its open-ended list of interests (critical infrastructure, dual-use results, supply-chain dependencies, protection of IP and classified information) mirrors the wider policy turn we already see in the FDI screening framework, the economic-security agenda and the forthcoming Cyber Security Act 2 reference in paragraph 5. What I would watch is the tension between these security measures and the Treaty principles of non-discrimination and proportionality that the text itself invokes: the empowerment of the Commission under paragraph 6 to adopt mandatory technical specifications and criteria by delegated act is where the real harmonisation — and the real litigation risk over ownership and third-country exposure — will play out.

For addressees, my reading is that this article rewards early, documented risk assessment. Because the buyer must specify measures “in a clear and sufficiently detailed manner” in the procurement documents, contracting authorities that fail to articulate proportionate, evidence-based security requirements up front will be exposed to challenge, while operators with credible security-management systems and clean ownership structures will find these criteria a genuine competitive advantage.

Official text — Article 28 (COM(2026) 567)
1. Public buyers shall take appropriate measures, in addition to measures required or imposed by virtue of other Union legislation, where relevant, at any stage of the R&D procurement procedure, from planning and market consultation to contra ct award and contract performance, to ensure the protection of the security and public safety interests of the Union or one or more Member States for any R&D procurement procedure identified as presenting or including a risk for security or public safety. This Chapter is without prejudice to other requirements under relevant Union legislation. 2. Security and public safety interests of the Union or a Member State relevant for a given R&D procurement contract may include, but are not limited to, the following: (a) protection of critical infrastructure, strategic dual -use infrastructure, identified by Member States in accordance with [Article 33 of the Military Mobility Regulation], especially for those located on a military mobility corridor, essential services, critical supply chains, critical technologies, resilience against physical, cyber, or hybrid threats, and prevention across and protection against risks of any disruption including due to harmful strategic dependencies on third-country suppliers; (b) prevention of espionage, sabotage or technology leakage; (c) crisis preparedness, including business continuity and contingency planning for disruptions in case of natural disasters or geopolitical instability, pandemics or cyberattacks; (d) the prevention of other harmful interference, including third -country and third- country State-controlled influence; (e) the cybersecurity of systems, networks, and data processed; (f) the protection of classified information, sensitive data, research, or intellectual property from unauthorised access or transfer; (g) ensuring public health, including crisis -prepared and self -sufficient health services; or (h) protection of the environment and resilience to climate-related disruptions. 3. Risks for security and public safety in a R&D procurement contract may arise in particular from: (a) the subject matter of the R&D procurement contract, including: (i) sensitivity of the assets involved or to be developed in its implementation; (ii) access to and handling sensitive data; (iii) critical dependency or risk of critical dependency on a limited number of third-country suppliers, goods, services or technologies; (iv) risks associated with access to critical infrastructure, strategic dual -use infrastructure identified by Member States in accordance with [Article 33 of the Military Mobility Regulation], research facilities, IT systems, or critical materials; (v) dual-use nature of the results of research and development services procured; (vi) the nature of the publi c interests attached to it and the potential consequences of a malfunction or malperformance, such as harm to public safety, national security, economic stability, health security or fundamental rights. (b) the characteristics of economic operators, including: (i) ownership, control, or financing structure bearing risks of undue interference or influence over the economic operator; (ii) security track record, including past breaches, non -compliance with security standards, or exclusion from other procureme nt procedures on security grounds; (iii) capacity to meet applicable security clearance, personnel vetting, or information security requirements; (iv) exposure to third -country legislation that may compel disclosure of sensitive information or interference with contract performance. 4. Public buyers shall, to the extent possible specify in the procurement documents in a clear and sufficiently detailed manner appropriate measures that are proportionate to the risks referred to in paragraph 3 and non -discriminatory. Such measures may be implemented, in particular through: (a) specifications and market consultation documents, including mandatory security standards, certifications, personnel vetting or security clearance obligations, or risk management and assurance requirements; (b) award criteria, such as evaluating bidders’ security management systems, security compliance standards, incident response capabilities, supply chain security; (c) conditions for the performance of contracts, including clauses enabling security oversight of suppliers through audits, inspections, or documentation reviews and implementation of corrective measures in the case of breaches, as well as provisions on subcontracting, ownership change notification, and the protection of classified or sensitive information; (d) selection criteria, where justified, such as possessing security clearances or otherwise requiring tenderers to establish that they do not present risks for security or public safety pursuant to paragraph 3, point (b) of t his Article. This shall be without prejudice to Article 14. (e) invite to submit a tender only those economic operators who meet specific objective and non -discriminatory security -related requirements, provided that the public buyer has indicated its inten tion to do so, and the security -related requirements it intends to apply, in the contract notice for the R&D procurement in question. Public buyers may also indicate in the procurement documents which security measures they intend to implement where risks for security or public safety arise during the R&D procurement procedure. 5. Public buyers shall at any time during an R&D procurement procedure exclude an economic operator from participation in a R&D procurement procedure where the operator has been identified as a high -risk supplier pursuant to Regulation (EU) XXXX/XXX [Cyber Security Act 2] in relation to the provision of ICT components or components that include ICT components to be used in key ICT assets. 6. Where there is evidence that disparitie s in measures affect the functioning of the internal market, the Commission is empowered to adopt delegated acts in accordance with Article 39 in order to supplement this Regulation by establishing mandatory technical specifications, selection criteria, aw ard criteria or contract performance clauses, for specific categories of R&D procurement services or their intended results where such elements address an identified specific security and public safety interest of the Union.

Source: European Commission, proposal for a Regulation establishing the European Innovation Act, COM(2026) 567 final, 9 September 2026. Read the official proposal (PDF). Text may change during the legislative process.

© 2026 · All rights reserved · Made with by MogaCode