Request for Proposal - CONSULTING SERVICES – FIRMS SELECTION
Name of Project: Western Balkans Trade and Transport Facilitation Phase 2 (TTFP) Assignment Title: Consulting Services for Project Supervision National Port Community System (PCS) The Government of Montenegro has received financing in the total amount of USD 15,000,000.00 (equivalent) from the World Bank, toward the costs of the “Western Balkans Trade and Transport Facilitation Phase 2” (TTFP). Ministry of Transport (MoT) is the umbrella ministry under which the transport sector falls and will serve as the lead implementing body for the project and intends to apply part of the proceeds of this loan towards payment for Consulting services under the Contract Ref. The Consultant will work closely with relevant stakeholders ensuring compliance with Montenegro’s policies, EU regulations, and international best practices. The services of the consultants or firm are expected to be required for a time period of approximately 640 days between November, 2026, and April 30, 2028, which marks the end of the project design, supply, implementation, commissioning and maintenance phase 1 period. The attention of interested Consultants is drawn to Section III, paragraphs, 3.14, 3.16, and 3.17 of the World Bank’s “Procurement Regulations for IPF Borrowers” seventh edition, September 2025 (“Procurement Regulations”), setting forth the World Bank’s policy on conflict of interest. Consultants may associate with other firms to enhance their qualifications, but should indicate clearly the form of the association (Joint-venture, Consortium, sub-consultancy; member in charge; other member/s and or sub- consultants).
Read more
Sovereignty at the core: how the Netherlands is contributing to Europe’s cloud future
Muriel Sinselmeijer, Project Manager Marketing and Communications at Centre of Excellence for Data Sharing & Cloud Cloud sovereignty is at the heart of the recent activities of the Dutch Gaia-X Hub, represented by the Centre of Excellence for Data Sharing & Cloud (CoE-DSC). During the Data Sharing Festival in Rotterdam, more than 300 professionals from the Netherlands and abroad came together for two days of sharp insights, open conversations, collaboration and concrete examples around the theme of sovereignty. Sectors can only share data safely and responsibly when they jointly invest in shared frameworks such as the Gaia-X Trust Framework, interoperability and privacy-enhancing technologies. Download the keynote presentations and watch the after movie, including a contribution by Gaia-X CTO Christoph Strnadl: Data Sharing Festival 2026 – Centre of Excellence for Data Sharing & Cloud. The team won the first prize with the development of a neurosymbolic workflow that combines different types of AI to enable a smart search function in digital marketplaces, automatic checks on whether services are compatible (e.g. Through technological innovation, national and international collaboration, and a strong focus on high-value use cases, the Netherlands is becoming a driving force in European cloud sovereignty.
Read more
EMPOWER-X in DS4PED Rubí: trusted energy data for renewable EV charging
Paco Conde, Co-Founder & Jose David Doria, Chief Operations Officer & Gio Dal Mas, Project Manager at Zertifier, Catalonia Energy data spaces become relevant when they help cities solve operational problems. EMPOWER-X, recently recognised as a Gaia-X Lighthouse Ecosystem, applies this approach to the DS4PED pilot in Rubí, where trusted data sharing is used to certify renewable energy use in electric mobility and support the deployment of Positive Energy Districts. The Rubí pilot therefore links municipal PV production, EV charging consumption, smartmeter data and mobility services through a traceability layer that can verify the renewable origin of charging events. The marketplace and data services layer, supported by Ocean Enterprise Collective, enables publication, discovery and controlled use of datasets, algorithms and Compute-toData services. This is important for public infrastructure, where EMPOWER-X in DS4PED Rubí: trusted energy data for renewable EV charging IMAGE 1- DS4PED Rubí energy traceability dashboard: certified renewable energy, surplus solar production, EV charging consumption and hourly solar/grid contribution. IMAGE 2 – EMPOWER-X in DS4PED Rubí architecture diagram75 EDITION 8 – 2026 data may be sensitive, commercially valuable or linked to citizens, and where controlled execution of algorithms can be preferable to moving raw datasets.
Read more
Comment on We Must Open the Frontier: OSI, OFAI Support Calls for the U.S. to Develop More Open Models by Linux’s 35th Anniversary and the Open Frontier – Open Source Initiative
to Develop More Open Models – Open Source Initiative We’ll never share your details and you can un with a click! Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the r or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network. The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the r or user. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you. The technical storage or access is required to create user profiles to send , or to track the user on a website or across several websites for similar marketing purposes.
Read more
Comment on 2025 Annual Report by Linux’s 35th Anniversary and the Open Frontier – Open Source Initiative
2025 Annual Report – Open Source Initiative To provide the best experiences, we use technologies like s to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the r or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network. The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the r or user. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you. The technical storage or access is required to create user profiles to send , or to track the user on a website or across several websites for similar marketing purposes.
Read more
Secure your place for the 2026 annual gathering of the Advanced Virtual Human Twins (VHT) Platform
Registration is now open for the open session of the Advanced VHT Platform Annual Event 2026, organised by DG CNECT with support from the VHTnet consortium. This hybrid event will take place on 20–21 October 2026, allowing participants to join either in Brussels or online.
Over two days, the event will bring together the Advanced VHT Platform User Group, the wider Virtual Human Twins community and the European Commission to review progress and discuss the future Platform for Advanced VHT Models. The discussions will focus on improving usability, adoption, interoperability and trust, while ensuring the platform reflects user needs and community feedback.
On 20 October (afternoon), the Annual VHT Event will be open to the wider VHT community and interested stakeholders, including researchers, developers, patient organisations, regulators and industry representatives. The session will examine high-level priorities for a future VHT collaboration hub, such as barriers to adoption, expected services and features, and training and support needs. Registration is now open via the dedicated webpage: https://digital-strategy.ec.europa.eu/en/events/advanced-virtual-human-twins-vht-platform-annual-event
On 21 October (full day), the Final Requirements Elicitation Session will be open to Advanced VHT Platform User Group members only. It will build on the requirements gathered so far and support the collaborative prioritisation of needs for the first version of the platform, including stakeholder engagement, user support, adoption, and interoperability. Registration will open soon.
Read more
Newsletter: We’re hiring a Director of Technology, supporting memory safety, and kicking off conference season
Email on 14 September: We’re hiring a Director of Technology, supporting memory safety, and kicking off conference season There’s a new position open in our leadership team: we’re looking for a Director of Technology to shape and develop the technology strategy of the Sovereign Tech Agency. Together with the German Federal Office for Information Security (BSI), we’re endorsing a statement that calls for more support for the large-scale adoption of memory-safe technology, a crucial part of cybersecurity that’s often overlooked. You will lead a team of technologists and research-focused colleagues, and work as part of our management team to ensure that our mission remains grounded in technical understanding and our work strengthens the most critical open infrastructure that digital sovereignty depends upon. In an increasingly digital world, software bugs are no longer merely technical issues, they can be security challenges of strategic significance. In Europe, ensuring that software is memory safe is crucial for building open digital infrastructure, protecting sensitive data, supporting economic stability, and fostering innovation. That’s why we are, together with the German Federal Office for Information Security (BSI), endorsing the statement "Improving Europe's cybersecurity posture through memory safety," which calls for more support for the large-scale adoption of memory-safe technology.
Read more
The CRA Single Reporting Platform is launched
The EU Agency for Cybersecurity (ENISA) has deployed the initial operating capability of the Single Reporting Platform (SRP).
The Agency has developed, operates and maintains the online tool to enable manufacturers and open-source software stewards to meet their new Cyber Resilience Act (CRA) reporting obligations for actively exploited vulnerabilities and severe incidents. Designed to support effective vulnerability management across the EU, the SRP allows users to report once and communicate the relevant information to all appropriate authorities.
Developing the first stage of the platform marks an important milestone in the implementation of the CRA and supports a more coordinated EU approach to the reporting and handling of cybersecurity risks affecting products with digital elements available on the EU market. This is why the CRA is also critical for the protection of end-users and the safeguarding of our shared connected ecosystem from cyber threats.
ENISA’s Executive Director Juhan Lepassaar said: “Vulnerabilities in digital products are often exploited by threat actors to subvert or hamper critical services, such as healthcare, energy, transport or telecommunications. The streamlined reporting and sharing of information on actively exploited vulnerabilities and severe incidents helps to build a more resilient Digital Single Market.”
What is the Cyber Resilience Act’s Single Reporting Platform?
The CRA is the EU’s horizontal regulatory framework that introduces mandatory cybersecurity requirements for products with digital elements throughout their lifecycle. The CRA’s reporting obligations apply to manufacturers from 11 September 2026, while its main cybersecurity requirements obligations apply from 11 December 2027. ENISA was mandated to develop and operate the Single Reporting Platformas the common electronic reporting mechanism supporting these new obligations. The SRP enables manufacturers and open-source stewards to fulfil their CRA reporting obligations through a single platform, while ENISA will continue to improve and expand its functionalities over the coming months based on operational experience and user needs.
ENISA would like to thank all stakeholders who contributed to the development, scanning and testing of the platform, including national CSIRTs, the CRA Expert Group, selected manufacturers and other users whose feedback helped strengthen its functionality, security and usability.
Manufacturers and open-source software stewards can now report through a single platform. Once a notification is submitted, the Computer Security Incident Response Team (CSIRT) designated as a coordinator that initially receives it, disseminates the information to other relevant CSIRTs in Member States where the affected product is also available, while the notification is simultaneously made available to ENISA. This coordinated approach helps relevant CSIRTs receive the information they need more efficiently and supports faster action to mitigate cybersecurity risks and strengthen resilience.
The CRA and the SRP support a more coordinated approach to vulnerability and incident reporting across the EU and a better understanding of the cyber threat landscape and emerging trends. The SRP also enables national CSIRTs and other relevant authorities to coordinate and act on the information received and mitigate risks stemming from these vulnerabilities.
The platform was developed to be functional and user-friendly while meeting all security requirements.
From today, 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe incidents having an impact on the security of products with digital elements. In accordance with Article 24(3) of the CRA, these reporting obligations will also apply to open-source software stewards to the extent that they are involved in the development of products with digital elements. This article shall apply from 11 December 2027.
The platform will be used by EU CSIRTs to receive and disseminate the relevant notifications.
The platform incorporates security measures to protect the confidentiality of the information submitted. ENISA has developed a range of supporting materials to help manufacturers and open-source software stewards including an FAQ, user manuals, tutorial videos, the SRP glossary and a dedicated factsheet in different EU languages. ENISA will continue to update and expand this supporting material as necessary.
A dedicated help desk is also available for questions related to reporting not addressed in the published guidance materials.
For broader guidance on the CRA reporting obligations, the European Commission provides additional resources including its dedicated Cyber Resilience Act - Reporting obligations webpage, and further clarifications on reporting obligations in Section 9.1 of the Commission guidance on the application of the CRA, as well as in Section 5 of its Frequently Asked Questions on the CRA imple
Read more