For municipalities, hospitals, water utilities and schools

Public procurement review

Technical and cyber risks in PV and BESS.

Before publishing a tender, check whether the specification meets your operating needs. We help identify uncertainties in the engineering, remote management and future costs, and prepare evidence for an informed decision.

No obligation to commission an audit or purchase equipment.

Photovoltaics since 2009View our project references →Advice commissioned separately

What we review

Four perspectives on one investment

Engineering and operation

Power, capacity, backup operation, controls, service and actual consumption. We distinguish a promised function from one that is evidenced and testable.

Cybersecurity

Remote access, cloud dependencies, updates, data handling and separation from organisational networks. Based on the actual architecture, not the brand alone.

Specification, evaluation and contract

Engineering inputs for proportionate requirements, comparable quality criteria, acceptance tests and support commitments. Final legal wording remains with the authority and its procurement administrator or lawyer.

Whole-life economics

Savings assumptions, operating costs, battery replacement and supplier dependency. We also consider simpler alternatives where they can meet the same need.

Evidence that helps management decide

Deliverables are agreed for the subsequent paid assessment. They typically include:

A clear management summary

What is supported by evidence, what remains uncertain and what to address before the next decision.

Risks and priorities

Findings with their evidence, potential impact and proposed action. Missing documentation is not the same as a proven defect.

Engineering inputs for the tender

Questions for clarification and proposed verifiable requirements for quality evaluation, acceptance and support.

Start with a simple question

Free initial orientation

Send a public tender link or a brief project description, your role and any deadline. We will review the situation at a high level and recommend a next step. This is not a full document review or confirmation of compliance.

Detailed assessment by agreement

If further work is useful, we agree the scope, fee, timing and required specialists before starting. Further work requires your approval. The outcome need not be a recommendation to purchase new technology.

Why address security in the specification?

NÚKIB’s June 2026 ICT procurement guidance was developed with the Czech competition authority, ÚOHS, and the Association for Public Procurement, AVZ. It connects risk management with specifications, evaluation and contractual requirements. We apply these principles to PV and BESS controls and communications; this is not a dedicated solar standard.

The applicable duties depend on the organisation and system. A warning is not an automatic ban on a brand. Security restrictions require evidence-based justification and proportionality.

Operating experience. Transparent roles.

We have worked in photovoltaics since 2009. We combine installation and commissioning experience with our RLHS assessment method. Advice is not conditional on buying from us. If we may later supply or integrate equipment, we disclose that commercial interest and address any conflict before accepting the work.

We do not act on behalf of NÚKIB, ÚOHS or AVZ. Advisory offers are separate from objections or other submissions; buying advice is never a condition for withdrawing them. Legal opinions, authorised design and security testing require separately agreed scope and appropriate specialists.

Detailed guidance for the procurement administrator and engineer

Separate advice from the equipment order

This is a paid advisory service. Scope, fee, delivery date, named specialists and exclusions are agreed in a written proposal before work begins. Sending an enquiry is not an order or an obligation to purchase equipment.

Before publication: turn operating needs into a fair specification

A municipality, hospital or wastewater plant needs more than a nominal inverter rating and battery capacity. First define the loads, metering data, grid constraints and expected service. Separate bill reduction from backup: a battery does not automatically guarantee continuity for every circuit.

  • A functional brief: duty, critical loads, backup duration and operating priorities.
  • Questions for preliminary market consultation: available architectures, interfaces, maintenance and dependence on external services.
  • Draft technical requirements linked to identified risks, with proposed evidence and acceptance tests.
  • Inputs for the procurement administrator: comparable lifecycle costs, support commitments and a proportionate description of required experience.

Preliminary market consultation under Czech procurement law is a transparent preparation tool, not a private agreement to favour one supplier. Its use and disclosure requirements must be addressed by the contracting authority and its administrator. Official procurement guidance and decisions.

Risk assessment informed by NÚKIB — not a brand blacklist

NÚKIB’s June 2026 ICT procurement guidance connects security with fair competition. We use those principles when assessing the control and communications layer of PV/BESS. This is a project-specific application, not a claim that the guidance is a dedicated solar certification standard. NÚKIB guidance, June 2026.

The September 2025 warning addresses data transfers to China and remote administration from China, and explicitly includes solar inverters among examples. It is an input to risk management, not an unconditional ban. Whether an organisation and system fall within regulatory scope must be determined individually. NÚKIB warning, September 2025.

  • An asset and dependency map: battery, PCS/inverter, EMS, gateway, cloud and links to the site network.
  • A data and access map: recipients, jurisdictions, privileged accounts, support access and update paths.
  • Risk scenarios: loss of cloud, unauthorised changes, compromised update, supplier failure or unavailable spare parts.
  • A findings register: evidence, uncertainty, consequence, proposed control, owner and residual risk.
  • A verification plan: what is documented, what needs testing, and what remains unverified.

Where IP addresses, accounts or logs relate to identifiable people, personal-data protection and any international transfers need separate assessment. Not all technical telemetry is personal data. GDPR.

Discuss the scope of a risk assessment

Already published: an evidence-based review, not a promise to cancel

We can review a published PV/BESS specification for the commissioning party agreed in advance. We distinguish unclear technical requirements, missing evidence and possible competitive barriers from proven legal defects. Repeated awards to a supplier or a demanding reference threshold alone do not prove misconduct.

  • Identify the current document version, procedure, submission deadline and the client’s role.
  • Review the purpose of cumulative references and narrow product parameters; consider technically equivalent, less restrictive ways to demonstrate capability.
  • Check cloud, remote access, updates, data, handover and service requirements against the operating risks.
  • Prepare a technical findings table and draft factual questions for clarification or correction, for review by the procurement administrator or lawyer.

Possible outcomes include no material finding, clarification, a proposed amendment or referral for legal review of further action. We do not guarantee cancellation, extension or the success of an objection. Formal remedies and deadlines depend on the procedure; small-value procurement is not automatically subject to the same remedies as statutory tender proceedings. Czech Public Procurement Act.

An enquiry through this website does not constitute a formal objection or suspend any deadline. Urgent matters require direct contact and an explicitly agreed response time.

Request a technical tender review

Acceptance: a requirement needs a way to verify it

Illustrative criteria, to be tailored to the project. These are not completed tests.
RiskProposed requirementEvidence or test
Cloud failureDefined essential functions remain availableAgreed WAN-disconnection test; record which functions are unavailable
Remote administrationOperator-approved, time-limited accessRevoke permission and verify that the account can no longer act
Supplier lock-inDocumented configuration, access and interfacesDemonstrate backup, recovery and transfer to an authorised operator
Uncertain economicsCompare equal duties and full operating costsBase and adverse scenarios, including a no-battery alternative

Test scope, safe execution and acceptance criteria must be agreed in advance. A document review is not a penetration test or a hardware certification. Intrusive tests require explicit permission and a safe plan; interruption of critical operations is not an acceptable demonstration.

Different sites need different priorities

  • Municipalities and schools: understandable procurement, operating costs, handover to local staff and continuity of service.
  • Hospitals: define interfaces with existing backup and critical circuits; coordinate with the operator and qualified designers.
  • Water utilities and wastewater plants: operating continuity, separation from process control networks and controlled service access.

Impartial findings and clearly separated roles

At the start of each engagement we identify who commissions the work, what decision it supports and any commercial interests. We do not represent opposing sides of the same dispute. If we may subsequently supply or integrate equipment, we disclose that role and address possible competitive advantage before accepting advisory work.

A risk-assessment offer is separate from any objection or request for correction. Purchasing our services is never a condition for withdrawing a finding or deciding not to pursue a remedy. The contracting authority remains free to appoint another adviser.

We use RLHS for internal critical review: could another architecture meet the same need, is the requirement proportionate, and what evidence could overturn our recommendation? Studer, Victron and other candidates face the same project-specific questions. No brand wins in advance.

We do not claim authorisation, endorsement or certification by NÚKIB. Legal opinions and representation require a separately engaged lawyer; authorised design, fire engineering and specialist security testing require the appropriate professionals. Scope, personnel and responsibilities are agreed in the proposal.

Start with the decision and the public tender link

Tell us the organisation type, whether the tender is planned or published, the public document link, the submission deadline and the decision you need. Do not send passwords, detailed network diagrams, patient data or confidential bids through the initial form. We will agree a suitable document-transfer channel separately.

Sources and limits of this guide

Reviewed 3 September 2026. MMR’s explanation stresses that restrictions require a documented risk analysis: a warning alone is not an automatic ban. The proposed services and test examples above are our project approach, not quotations or universal statutory duties. The English text concerns procurement in the Czech Republic.

Our evidence and assessment method →

Minimum requirements are not bonus points

First separate essential conditions from qualities worth comparing. A mandatory safety function must not be traded for a lower price. For scored quality, state the measurement boundary, evidence, scoring rule and how the promised performance becomes enforceable in the contract. We propose project-specific criteria, not universal percentages.

  • Qualification: evidence that a supplier and its team can deliver the task; avoid cumulative references without a reason tied to the project.
  • Technical minimum: the functions, access controls and evidence the site cannot operate without.
  • Quality evaluation: compare supported differences such as lifecycle costs, recovery arrangements and service commitments; do not score vague “security quality”.
  • Contract requirements: evidence at handover, response and restoration targets, update support, data export, responsibility for gaps and a workable exit plan.
  • Acceptance: who tests what, under which conditions, with what threshold and what happens if a requirement is not met.

Final procurement wording, legal proportionality and contract clauses are reviewed by the contracting authority’s administrator or lawyer. We supply the technical rationale and evidence requirements, not a guarantee that the tender cannot be challenged.

Current guidance: evidence before procurement conditions

The June 2026 ICT guidance was prepared with NÚKIB, ÚOHS and the Association for Public Procurement. We apply its risk-led logic to the controls and communications of PV/BESS; it is not a dedicated solar standard. NÚKIB, 11 June 2026.

AVZ stresses that the guidance is neither a universal specification nor a new list of duties. It primarily addresses regulated-service providers, with useful principles for other contracting authorities. AVZ: purpose and scope.

ÚOHS explains in its May 2026 IT-procurement case that a justified, proportionate restriction is not automatically unlawful. That case is not blanket permission to exclude a brand or impose the same requirements on every solar project. ÚOHS, 6 May 2026.

Preparing a tender, or reviewing a published one?

Tell us what decision you need to make. A public link and a brief description are enough to start. We will agree a suitable channel for confidential documents separately.

Do not send passwords, network diagrams or personal data about third parties. The form does not lodge an objection or suspend any deadline. For urgent matters, agree a response time directly by phone.