CERTIFICATION AND AUDIT CENTER · ANALYSIS
HCPL certificates, public procurement and NIS2 requirements
How sector certificates issued by Healthcare Poland Foundation fit into public procurement law and into the requirements arising from the NIS2 Directive for hospitals treated as strategic entities.
Holding sector certificates issued by Healthcare Poland (HCPL) for the healthcare sector — including micro-credentials — is materially relevant to how hospitals and other strategic entities carry out public procurement. This relevance arises both from Polish public procurement law and from the regulations stemming from the NIS2 Directive, which set specific requirements for cybersecurity and the protection of critical infrastructure.
Compliance with public procurement law
The Act of 11 September 2019 — Public Procurement Law (Journal of Laws 2019, item 2019, as amended) sets out the rules and procedures governing public procurement in Poland. Three elements are central where HCPL sector certificates are concerned.
Assessment of technical requirements
Hospitals and other healthcare providers require suppliers and contractors to confirm that defined technical requirements are met. HCPL certificates can serve as evidence that products or services conform to the required quality standards and regulations — which is decisive in tender procedures.
Verification of contractor capability
Public procurement requires documented evidence that a contractor is able to perform the contract, particularly in areas demanding specialist expertise. Certificates confirming conformity with quality, data protection and cybersecurity standards can serve as formal proof that these conditions are satisfied.
Promoting quality and innovation
Sector certificates support innovation and the raising of standards in hospitals, particularly in the deployment of new technologies and IT safeguards — areas that increasingly feature among the criteria for evaluating tenders.
Compliance with NIS2
The NIS2 Directive (Directive (EU) 2022/2555 of the European Parliament and of the Council) obliges strategic entities, hospitals among them, to ensure an appropriate level of security for information systems and critical infrastructure. HCPL certificates support compliance in three key areas.
Cybersecurity of information systems
The Directive sets requirements for protecting hospital information systems. HCPL certificates confirming NIS2 conformity can constitute key evidence that these standards are observed — by hospitals and by their technology suppliers alike.
Security of medical data
NIS2 sets a high bar for the protection of patient data. HCPL certificates aligned with the GDPR help hospitals demonstrate that such data is protected in accordance with European regulation.
Audit and conformity with standards
The Directive introduces an obligation to conduct regular security audits. Certificates issued on the basis of audits and compliance reviews support the documentation of NIS2 conformity — which matters both in public procurement and in internal reviews.
Let us look at what your procedure actually requires
We will review the tender specification and identify which attestation genuinely strengthens the bid — and which would be nothing more than a cost.