Methodology for public procurement authorities
This comprehensive methodology provides public contracting authorities with a legally grounded framework for the secure procurement of new and secondary software licenses. It focuses on ensuring legal certainty, maintaining competition, and mitigating risks through standardized tender requirements and audit procedures.
Purpose and scope of the methodology
This document presents a methodological recommendation for public contracting authorities when procuring software and license entitlements for computer programs. Its purpose is to provide contracting authorities with a practical and legally grounded framework for setting tender and contractual conditions so that:
offers are mutually comparable and allow for objective evaluation,
the contracting authority achieves reasonable legal certainty regarding the lawfulness of software use and the auditability of the procurement,
there is no unjustified restriction of economic competition that could lead to an increase in the price of performance,
legal, financial, and operational risks (including the risk of delivering unauthorized copies or licenses without legal title) are minimized.
The authors of this methodology have long monitored public tenders for software within the European Union, tracking their results, the decision-making practice of supervisory and judicial bodies, as well as current developments in legislation, methodological guidelines, and recommendations of European institutions. The methodology is based on the general binding legal framework of the European Union, in particular Directive 2014/24/EU and Directive 2009/24/EC on the legal protection of computer programs, on the established case law of the Court of Justice of the EU, especially in the UsedSoft case (C-128/11), and also on the real-world practice of public contracting authorities and best practices applied across the EU.
The purpose of the document is to facilitate the work of contracting authorities, save time, and reduce the administrative and professional burden associated with the preparation of tender documentation. The methodology provides a ready-made framework of requirements and their justifications, which can be directly used in tender conditions and contractual arrangements. At the same time, it helps contracting authorities avoid recurring errors that often lead to objections, reviews, or problems in subsequent contract implementation. The document emphasizes the protection of the contracting authority, legal certainty of software use, transparency of supplier selection, and the preservation of economic competition, in accordance with the principles of equal treatment, non-discrimination, proportionality, and the 3E principles (economy, efficiency, effectiveness). The methodology is designed as a practical tool to help contracting authorities make informed and defensible decisions and ensure that the resulting public contract is long-term functional, secure, and legally sound.
The target group consists primarily of central state administration bodies, regions, municipalities, contributory organizations, schools, hospitals, state-owned enterprises, and other public contracting authorities.
Preliminary Market Consultations: The law allows the contracting authority to contact the market—potential suppliers or independent experts—before launching the tender to consult on the intended solution, scope, estimated price, etc. This is all legal and transparent; it is one of the most effective ways to improve the quality of the assignment. Consultations help the contracting authority clarify market possibilities—for example, they may find that a ready-made solution exists that is cheaper than custom development, or conversely, that the requirements are too innovative and need adjustment. They also avoid formulations that could be discriminatory or confusing. It is therefore very beneficial for the contracting authority to devote a few weeks before the announcement to a dialogue with the market, as this prevents problems in the competition and implementation. Of course, care must be taken not to give an advantage to any supplier (which is ensured by reflecting information from the consultations in the documentation and making it available to everyone in the form of answers in the tender documentation, as stipulated by law).
Insufficient setting of conditions exposes the contracting authority to the risk of purchasing illegal new or pirated copies. Offers of illegal new or pirated copies not only harm the contracting authority—which incurs damage and criminal liability when using such software—but also other competitors. At the same time, it leads to incomparable offers and unfair competitive behavior. We recommend adjusting the tender conditions so that offers for which the legal origin of the software is not proven with a sufficiently high degree of certainty are excluded.
Requirements for tender documentation
For new perpetual software, always insist on assigning the license directly to the contracting authority's licensing account on the manufacturer's portal (assignment to the supplier's account or an invoice is not sufficient).
For secondary software, it is necessary to require the submission of documentation proving the legal origin of the copy and to reserve the right to an audit by an independent person. Furthermore, requirements for professional liability insurance and other relevant requirements, as stated in this methodology, must be established.
New perpetual software
As previously stated, for new software, it is necessary to always insist on assigning the license directly to the contracting authority's licensing account on the manufacturer's portal (assignment to the supplier's account or an invoice is not sufficient). However, the contracting authority must not, without proper justification, restrict the software distribution channel to a single licensing program, e.g., only delivery via a specific license agreement. The contracting authority is obliged to describe the subject of performance and set the tender conditions in accordance with the principles of public procurement (especially the principles of transparency, equal treatment, and proportionality). Therefore, the contracting authority must not, without an objective and verifiable justification, construct the assignment in a way that effectively prefers a specific licensing program or distribution channel if this restriction is not necessary to fulfill the legitimate needs of the contracting authority. If the contracting authority requires benefits typical of a certain licensing regime, it is appropriate to formulate these needs as functional requirements (equivalent solutions), rather than as a mandatory "prescription" of a specific program.
Such requirements groundlessly exclude both certain suppliers offering new licenses and suppliers offering licenses from the secondary market (secondary licenses) from participating in the tender procedure, as the requirement to deliver software under a specific license agreement excludes other distribution channels for new licenses (e.g., Open Value and Cloud Solution Provider) as well as Microsoft secondary licenses. Although secondary market licenses are functionally and technologically identical to new software, they cannot be delivered under a specific license agreement.
Secondary market software
When addressing licensing issues related to secondary market software, it must be emphasized that for a product such as computer software, setting requirements for it to be "new," "unused," or "unactivated" lacks technical or logical justification. While the use of a physical object can lead to a deterioration of its quality due to normal wear and tear, the use of software has no effect on its functional properties or other parameters. Unlike physical goods such as vehicles or books, software is not subject to "wear and tear" or security risks.
Secondary market licenses represent license entitlements acquired from a previous acquirer. From the perspective of EU law, it is essential that, provided legal conditions are met, the so-called "exhaustion of the right to distribute" a copy of a computer program occurs; in such a case, the further transfer of the copy and the corresponding entitlement to use it is permissible. The case law of the Court of Justice of the EU (notably the UsedSoft case, C-128/11) concluded that when legal requirements are met, the secondary transfer of a copy and the corresponding license entitlement cannot be broadly excluded just because they are not "new" licenses from the primary distribution channel. The installation and activation process for secondary market software is identical to the process for "new" software licenses and takes place using the manufacturer's original installation files. Access to patches and security updates provided by the manufacturer is also ensured in accordance with the product lifecycle policy.
At the same time, however, the secondary market carries an increased risk of legal defects: in practice, offers appear that represent only activation keys or access data without a provable transfer of rights, or copies originating from illegal sources. From the contracting authority's perspective, the decisive factor is not the supplier's declaration, but the provability of the legal title.
For secondary perpetual software, it is necessary to require the submission of documentation proving the legal origin of the copy (ownership documentation) and to reserve the right to an audit by an independent person.
Without this documentation, it is merely a key, not a legal license with the right to use it. Furthermore, requirements for professional liability insurance and other relevant requirements must be established.
To be included in the document "Invitation to tender":
Valid ISO 9001 quality management certificate and valid ISO 27001 certificate. The contracting authority requires, as part of the software delivery, the assignment of the license to a licensing portal to the contracting authority's account, to which it will have direct access. In the case of new licenses, this must be an assignment to the software manufacturer's licensing portal created for the client; in the case of secondary licenses, at least to the extent of their records, the possibility of downloading legal documentation, and providing access to a list of links with installation files, provided its operator has implemented standards at the ISO 27001 level. The same ISO 27001 requirements as those set for the licensing portal should also be set for the variant of fulfillment via cloud storage, which may be operated by a third party and thus represents an additional risk.
Proof of existence of professional liability insurance, covering, in the case of secondary software delivery, the delivery of copies from the open market, with a limit of at least the price of licenses from the primary market. Suppliers shall prove this by submitting a certificate or confirmation from the insurance company.
References: The supplier shall submit a list of significant deliveries over the last 3 years, including at least two deliveries of a similar nature (delivery of license entitlements and their recording in an electronic tool), stating the client, scope, price, and a contact person for verification.
The contracting authority reserves the right, in the case of an offer of secondary licenses, to have all documentation and the information contained therein independently verified. In particular, the right to provide all submitted documents for assessment by external experts (software manufacturer, distributor, or another professional) provided they are contractually bound to protect their content to the same extent as the contracting authority.
ISO 9001
The requirement for a certified quality management system according to ISO 9001 is justified by the need to ensure that the supplier has managed and stable processes for development, delivery, and software support, thereby reducing risks associated with performance quality, service continuity, and the protection of public funds.
ISO 27001
ISO 27001 is crucial not only from the perspective of operating the licensing portal itself but also testifies to the integrity and competence of the supplier in the field of cybersecurity. Certification proves that the supplier systematically manages security risks, is able to prevent security incidents, and responds appropriately to their occurrence, thereby protecting the continuity of activities and public interests.
Professional liability insurance
When delivering secondary software, especially regarding copies of software from the open market, specific risks arise that concern not only technical quality but also the legal integrity of the license rights. In particular, there is a risk of delivering illegal or unauthorizedly acquired licenses, invalidity or ineffectiveness of the license transfer, etc. Professional liability insurance represents a financial mechanism for covering these risks. Furthermore, it serves as a prevention against dishonest or risky suppliers. Professional liability insurance is not commonly available for entities with an opaque business model; insurance companies assess the origin of licenses, processes, and the supplier's history, creating an external control of the supply chain. The requirement thus fulfills a preventive function and reduces the risk of participation by entities that are unable to guarantee the legal certainty of the delivery. The requirement is proportionate to the subject of the contract, as it reflects the real value of the delivered licenses, and is non-discriminatory as it applies to all suppliers equally. At the same time, it is in accordance with the principle of economy and risk prevention.
References
The requirement to submit a list of significant deliveries of a similar nature over the last three years serves to verify the supplier's professional competence in delivering secondary licenses through an electronic platform for license records. Verifiable references allow the contracting authority to verify that the supplier has real experience with comparable performance, thereby reducing the risk of errors in licensing records and protecting the proper and economical expenditure of public funds.
Reservation of the right for independent verification of documentation
The reservation of the contracting authority's right to independent verification of documentation for the offer of secondary licenses is justified by the need to verify the legal integrity and origin of the offered licenses. The involvement of external experts allows for a professional assessment of specific licensing issues, while the protection of the confidentiality of the documentation is ensured by a contractual obligation of non-disclosure to an extent at least identical to the obligations of the contracting authority. The provision serves to protect public funds and prevent legal disputes.
Required prior to contract conclusion
In the case of secondary software delivery, these products must meet all legal requirements and be delivered together with the following documentation (collectively referred to as ownership documentation), which proves that all conditions given by law have been met:
Identification details of the first acquirer of the software and proof that the products were purchased from official distribution.
Identification of products by the contract number under which the products were purchased, as well as identification of the original volume license agreement (inter alia, to clearly establish that these are not EDU/Academic licenses).
A declaration from the first acquirer that the software was paid for in full.
Confirmation that the software product was first placed on the market in the EU, EEA, or Switzerland.
Confirmation that it is a perpetual license.
Complete identification of previous owners of the software.
A signed declaration from the original acquirer of the software (and all other acquirers in the chain of previous owners) stating that all software products have been uninstalled, are not being used, and their future use has been prevented.
Mandatory contractual arrangements (Excerpt)
The contract must be in full compliance with the tender documentation; requirements for origin, documentation, and supplier responsibility must be contractually enforceable. In particular, it is recommended:
The Supplier declares that it is insured against damages caused by its activity, including possible damages caused by the Supplier's workers (liability insurance for damage caused by the supplier), with a minimum limit of [PRIMARY LICENSES VALUE] CZK as the minimum limit of the insured amount. Proof of existence of professional liability insurance covers, in the case of secondary software delivery, the delivery of copies from the open market. The certificate of the concluded insurance policy forms an annex to this Agreement.
The contracting authority requires, as part of the software delivery, the assignment of the license to a licensing portal to the contracting authority's account, to which it will have direct access. In the case of new licenses, this must be an assignment to the software manufacturer's licensing portal created for the client; in the case of secondary licenses, it may also be another licensing portal allowing for license management, at least to the extent of their records, the possibility of downloading legal documentation, and providing access to a list of links with installation files, provided its operator has implemented standards at the ISO 27001 level. The same ISO 27001 requirements as those set for the licensing portal should also be set for the variant of fulfillment via cloud storage, which may be operated by a third party and thus represents an additional risk.
The contracting authority reserves the right, in the case of an offer of secondary licenses, to have all documentation and the information contained therein independently verified. In particular, the right to provide all submitted documents for assessment by external experts (software manufacturer, distributor, or another professional) provided they are contractually bound to protect their content to the same extent as the contracting authority.
Annex: Microsoft reactive letter
In this reactive communication, Microsoft explains its official position on the legal use and sale of secondary software, confirming that regarding a license that was once legally sold and subsequently resold via "exhaustion of rights," the new holder is considered an authorized user, and therefore its use is lawful.