Procurement guidelines for the cybersecurity of hospitals and healthcare providers

Back to all publications

Publication date:July 22, 2026

The procurement guidelines presented in this document are intended to help hospitals and healthcare providers integrate cybersecurity objectives into their procurement processes. Covering all phases of the procurement life cycle, they offer practical guidance for addressing cybersecurity risks in a comprehensive manner. 

The guidelines set out clear cybersecurity requirements, specify the necessary information that suppliers must provide, and are closely aligned with relevant regulatory frameworks such as the NIS2 Directive, the medical device regulations, the general data protection regulation and the European health data space regulation.