Alle Artikel
Deep Dive

Dual-use tenders: Connecting export controls, security clearance and bid evidence

How Austrian and DACH suppliers handle dual-use tenders: from goods classification and BVergGVS to SAFE origin rules, evidence, supply chains and revisions.

tendric Editorial TeamJuly 17, 202620 Min. Lesezeit

More budget, five separate reviews

Austria is allocating around EUR 4.761 billion to national defence in 2026. Of this, approximately EUR 1.7 billion will go to investment—25.9% more than in the previous year. Vehicles, air defence, counter-drone systems, digitalisation and infrastructure rank high on the procurement list. The figures come from the Austrian Parliament's deliberations on the 2025/26 double budget.

This opens a market unfamiliar to many companies in sensors, electronics, software, mechanical engineering, materials engineering and aerospace. Entry rarely fails because of a single technical question. The challenge is that five reviews run at the same time: procurement, security clearance, export controls, technical qualification and security of supply. They draw on the same data, but follow different rules and require separate approvals.

A technically suitable product may require an export licence. A capable development partner may not be allowed to see certain documents. A low-cost component may reduce the origin ratio of an EU-financed overall product. And a system that convinces in a prototype may fail to demonstrate serial production capability. The bid is won or lost at these transitions.

Five reviews, no blanket approval

A green technical status does not replace either an export clearance or a security certificate. Effective bid management connects the reviews without conflating their responsibilities.

Eine Anforderung, fünf Entscheidungen
A-147 · Inertialsensor · Revision C
Leistungswert geändert · neuer Unterauftragnehmer · Lieferort Schweiz
Auswirkungsanalyse offen
01
Vergabe
Dürfen wir bieten?
Verfahren · Eignung · Partner
02
Geheimschutz
Dürfen wir es sehen?
Zugang · System · Weitergabe
03
Export
Dürfen wir es übertragen?
Gut · Empfänger · Endverwendung
04
Technik
Können wir es nachweisen?
Kriterium · Test · Konfiguration
05
Versorgung
Können wir es lange liefern?
Herkunft · Obsoleszenz · Support
Abgabefähig, sobald alle fünf Owner freigegeben haben

Dual use is a goods classification, not an industry label

Dual-use goods are products, software and technology that can be used for both civilian and military purposes because of their technical characteristics. Depending on their performance data, they may include inertial sensors, thermal imaging equipment, cryptography, high-performance computers, composite materials, machine tools or development software. Austria's export control authority explains the concept and controlled activities on its overview page for dual-use goods.

What matters is not how a company classifies itself. The decisive factors are the technical parameters of the item, the recipient, end use, destination country and the specific transaction. Regulation (EU) 2021/821 provides the European framework. Annex I contains the controlled items. The list was most recently updated by Delegated Regulation (EU) 2025/2003. Annex IV covers particularly sensitive items whose transfer may require authorisation even within the EU.

The list is only the first review path. Catch-all rules can also cover unlisted goods, for example because of a critical end use. Sanctions and embargoes also apply. The review therefore never ends with the question, “Which list number?” It is equally important to ask: What is being transferred, to whom, where and for what purpose?

A simplified view
A robust assessment
Dual use affects only direct sales to armed forces
Technology, recipient and end use are assessed separately
The customs tariff code is sufficient for classification
Classification follows the technical parameters in the control list
No export review is needed within the EU
Annex IV, sanctions and technology transfer remain relevant
Software and technical data are merely supporting materials
Software, technology and technical assistance are included
One authorisation covers the entire programme
Country, recipient, use and authorisation type remain transaction-specific
The export may begin in the data room

Electronically transferring or making software and technology available outside the EU may also constitute an export. For international development teams, the review can therefore begin with the repository, support access or a technical workshop—long before the first shipment of goods.

Austria: specialised industry meets larger programmes

The domestic security and defence industry is broad-based, but strongly shaped by small and medium-sized enterprises. The Austrian Economic Chamber identifies vehicles and accessories, weapons and ammunition, aerospace components, personal protective equipment, and information, communications and cyber technology as focal areas. A large share of companies produces dual-use goods. The ARGE Security & Economy represents this sector within the Economic Chamber.

For the market, the industrial depth of major contracts matters more than their number. A platform programme consists of sensors, electronics, software baselines, manufacturing processes, test equipment, training, spare parts and decades of support. Each of these building blocks creates its own requirements and can become the work package of a specialised supplier.

0 million €
Defence budget 2026
Austrian federal budget
0 million €
Investment 2026
+25.9% compared with 2025
0
Pandur Evolution
Additional vehicles ordered in 2024
0+
Austrian suppliers
Involved in the Pandur programme

Sources: the Austrian Parliament on the 2025/26 defence budget and the Austrian Ministry of Defence on the Pandur procurement.

Pandur: a prime contract becomes a chain of evidence

In February 2024, Austria ordered 225 additional Pandur Evolution vehicles in twelve variants. The contract is worth EUR 1.8 billion. According to the Ministry of Defence, more than 200 Austrian companies are involved, with 70% of value creation remaining in the country. A vehicle contract thus becomes a network of several hundred technical and contractual interfaces.

The variants range from personnel carriers to systems for air defence and electronic warfare. Components must therefore do more than fit a vehicle. They require a defined configuration, evidence of qualification, approved interfaces, documented origin and a supply path across the lifecycle. If a module changes, that change flows through system architecture, documentation, export review, spare-parts planning and acceptance.

What platform programmes require
  • The chain of evidence extends from the system requirement through every subsystem to software, test equipment, spare parts and support data.

Three procurement logics, not one dual-use procedure

There is no dedicated procurement type called a “dual-use tender”. The applicable procedure depends on the contracting authority, subject matter and protection needs. For bidders, this classification is the first go/no-go question because it determines access, deadlines, evidence and permissible partners.

1
Civil public procurement

Authorities procure items such as cyber technology, vehicles, sensors or infrastructure under general procurement law. The fact that a product may be subject to export controls does not automatically change the procurement regime.

2
Defence and security procurement

In Austria, the BVergGVS 2012 applies to relevant contracts. Information security and security of supply can form part of the suitability and tender assessment.

3
Industrial RFQ or research programme

Primes award work packages according to their own supplier qualification; FFG and EU programmes assess research, the consortium and impact. Export controls, security clearance and later product qualification remain additional requirements.

Germany follows the same basic logic, with different authorities and national procedures. BAAINBw awards research and development, initial and follow-on procurement, and maintenance. Depending on the contract subject and value, UVgO, VgV or VSVgV apply. The Bundeswehr's procurement fundamentals explain how to enter German procedures.

Switzerland is not an EU member and maintains its own procurement and export control rules. For DACH supply chains, a universal “export clearance” field is therefore insufficient. Each legal system, border crossing and access to technology must be assigned to the specific transaction.

The five reviews behind a tender

1. Procurement and bidder suitability

Austria's BVergGVS 2012 allows contracting authorities to specify information security and security of supply in tender documents. Section 69 addresses the protection of classified information. Section 70 covers, among other matters, the ability to safeguard supply chains and supply even in crisis situations. These obligations do not sit alongside the technical tender; they become requirements in their own right.

Bidders must therefore clarify early whether all consortium partners and subcontractors can provide the required evidence. A capable specialist is of little use if it lacks the necessary security certificate or if required supply-chain information cannot be traced back to its upstream suppliers.

2. Export controls and end use

Goods classification belongs in the technical baseline, not in a loose compliance note. It requires manufacturer documentation, performance parameters, software version and a substantiated assignment to the control list. If engineering changes range, accuracy, frequency, computing power or cryptography, the classification may change.

In parallel, export control reviews the recipient, end user, end use, destination country, sanctions and catch-all circumstances. This second track must not be inferred from the first: even an unlisted item can be controlled; a listed item can be lawfully exported depending on the authorisation and destination.

3. Information security and need-to-know

A document is too coarse an object to manage this. The same attachment can contain public, commercially confidential, export-controlled and classified content. The team therefore needs an information map: Who classified the information? Who may see it? In which system may it be processed? What derivative may a subcontractor receive?

Protection needs and export control remain separate. Unclassified technical data can be export-controlled. Conversely, classified information need not correspond to a dual-use list entry. A common label would handle both cases incorrectly.

4. Technology, quality and evidence

A statement such as “complies” carries weight only once the acceptance criterion, method of proof and configuration state are clear. In defence programmes, product specifications are frequently supplemented by AQAP-series quality assurance requirements, configuration management, First Article Inspection, test planning and special customer approval rights.

Flow-down does not end with the direct supplier. Critical characteristics, testing, change notices, documentation obligations and access rights must reach the relevant subcontractors. Otherwise, the prime confirms a requirement that its supply chain neither knows nor contractually owes.

5. Security of supply and lifecycle

For systems with useful lives of twenty or thirty years, single sources, country of manufacture, repair rights, source-code access, tool availability, export licences and obsolescence become technical evaluation criteria. A low unit price helps little if a critical module may be repaired only outside Europe or if every update triggers a new technology transfer.

The bid must therefore state the assumptions under which delivery and support remain possible. “Commercially available” is not a lifecycle strategy. What is needed are second sources, last-buy opportunities, redesign paths and clear rights to the data that make maintenance or supplier changes possible at all.

One overall status
Separate approvals
Technology is green even though the export path remains open
Technology, export, security, quality and contract each have their own owner
The document is classified as a whole
Access and processing follow the classification of individual information
The direct supplier confirms the supply chain by proxy
Flow-down and confirmation extend to the relevant sub-tier
Evidence applies without reference to the software or hardware state
Every item of evidence references a unique configuration
Revisions overwrite the previous decision state
Changes trigger a documented impact analysis
The smallest verifiable unit
  • Each requirement needs a source, configuration, response, evidence, owner and the necessary expert approvals.
  • Each controlled item needs a technical classification, recipient, end use, destination and authorisation path.
  • Each protected piece of information needs a classification, authorised group of people, system and dissemination rule.

Europe funds collaboration—and reviews its architecture

In 2024, the 27 EU Member States spent a combined EUR 343 billion on defence, 19% more than in 2023. Of this, EUR 106 billion went to investment, EUR 88 billion to equipment procurement and EUR 13 billion to research and development. These figures come from the European Defence Agency's Defence Data Report 2024/2025.

Total defence expenditure0 billion €
Investment0 billion €
Equipment procurement0 billion €
Research and development0 billion €

Defence expenditure by the 27 EU Member States in 2024. Investment also includes research and development and must therefore not be added to total expenditure. Source: European Defence Agency.

SAFE: origin becomes a verifiable product property

The EU's SAFE instrument provides up to EUR 150 billion in long-term loans for defence investment. As a general rule, at least two participating countries must procure jointly. The priority areas range from cyber and military mobility to air defence, drones, C4ISTAR, space, AI and electronic warfare.

The origin rule is especially consequential: components from countries outside the EU, the EEA/EFTA area and Ukraine may generally account for no more than 35% of the estimated component cost of the end product. The Council of the EU summarises the SAFE rules and the two capability categories.

Origin thereby becomes a property of the configured bill of materials. If engineering swaps a module, technical compliance, export status and financing eligibility may all change at once. A one-off supplier declaration is insufficient; the calculation must withstand every relevant revision.

EDF: the consortium is part of the technical solution

The European Defence Fund makes approximately EUR 1 billion available for 31 topics in its 2026 work programme. The topics range from sensors, cyber and space to air combat, land vehicles and disruptive technologies. The current EDF Work Programme 2026 contains the programme, topic descriptions and amendments.

In collaborative development projects, partner countries, control of companies, workshare, shared capability requirements and later procurement intentions are part of eligibility. A consortium is therefore not an organisation chart added shortly before submission. It determines who can meet which requirement, see which technology and provide which evidence.

0 billion €
SAFE loans
For European defence investment
0 %
SAFE origin limit
General maximum share of external components
0 billion €
EDF 2026
Work-programme budget
0
EDF topics
In the 2026 work programme

An Austrian entry point through research

For companies without a reference in a major defence programme, research can be a useful entry point. KIRAS funds civilian security research; FORTE focuses on defence research and involves the Austrian Ministry of Defence as the requirements authority. The 2025 FORTE call covered cooperative R&D projects and R&D services with funding of up to EUR 2 million. The submission deadline ended on 6 March 2026. The FFG provides the details and guidance.

A research project can prepare maturity, the consortium and technical evidence. It replaces neither subsequent supplier qualification nor export clearance, security certification or product acceptance. Those who plan these transitions in the application are more likely to turn research into a procurable work package.

ADS 15: why maturity is not a colour

The Swiss ADS 15 drone project shows what happens when development status, capability requirements and acceptance diverge. In 2025, the Swiss Federal Audit Office reported that project completion had been postponed to the end of 2026. Even then, the system was expected not to meet key military requirements; under the planning at the time, full compliance was not expected before 2029. The audit report on the operational suitability of the reconnaissance drone also cites higher operating and maintenance costs resulting from additional support aircraft.

Development programmes carry risks; that is not an error. They become a problem when a status fails to show whether a capability is planned, demonstrated, qualified or accepted in the target system. A bid must name these stages and disclose the timing, cost and dependencies of the next item of evidence.

Workflow for dual-use tenders

The following workflow is intended for Austrian bidders and can be applied to DACH and EU procedures. It structures technical and regulatory decisions; it does not replace legal advice or official approvals.

1
Determine the procedure and information environment

Clarify the contracting authority, legal regime, countries, procedure type, classification levels, data rooms and permissible bidder structure before detailed analysis.

2
Establish an unambiguous baseline

Requirements, attachments, questions, answers and revisions receive unique references. No response exists only in an email or spreadsheet copy.

3
Atomise requirements

Multi-part clauses become verifiable individual requirements. Tags assign them to technology, export, security, quality, contract and supply.

4
Classify the solution and goods

Experts classify components, software and technology. Recipients, end uses, countries, sanctions and catch-all circumstances are assessed separately.

5
Assign evidence and approvals

Each commitment receives an acceptance criterion, evidence type, configuration state, deadline and technical owner. Export, security and contract are approved independently.

6
Close the supply chain and origin loop

Critical subcontractors confirm flow-down, quality, data access, origin, licensing assumptions and lifecycle capability in the same baseline.

7
Cross-check revisions

Before submission, an independent team checks mandatory gaps, conflicting commitments, open assumptions and every change since the last approval.

A small change can reopen five reviews

A higher performance value can change the goods classification. A different delivery location can trigger a new export or transit review. An additional subcontractor may need a security clearance. A replacement module changes the origin ratio, qualification and obsolescence risk. Every revision therefore requires an impact analysis across technology, export, security clearance, contract and supply chain.

Where automation helps—and where it stops

Repetitive structural work can be automated effectively: extracting requirements, preserving references, grouping similar clauses, comparing revisions and linking evidence. tendric brings together requirements, responses, owners, evidence and changes in a shared working foundation.

A model can flag a potential dual-use control-list entry. Binding classification remains the responsibility of the competent export control authority. Software can identify a missing end-use document, but cannot grant an authorisation. And a marked security requirement may still only be processed in a system approved for that purpose.

In tendric, technical assessments and expert approvals can therefore be managed separately. Export control, security responsibility, engineering, quality and legal each retain their decision, rationale and timestamp. Automation shortens the search; it does not assume responsibility.

Automation pays off at the handover

The greatest time saving comes when a new or changed requirement immediately reaches the right expert together with its source, context and affected configuration.

Go/no-go: seven questions before the bid

  • Do we have access to all required information and the necessary security clearances?
  • Have the product, software, technology, recipient and end use been provisionally classified, and is a realistic authorisation path apparent?
  • Can we prove every mandatory requirement or close it with a funded, scheduled qualification plan?
  • Do critical subcontractors meet the technical, quality and regulatory flow-down requirements?
  • Will the solution remain supportable, repairable and configuration-controlled across the required lifecycle?
  • Will the bid remain eligible for financing and export when origin, partners or architecture change?
  • Are open assumptions visibly reflected in the price, schedule, evidence plan and contract?

A go decision does not require a flawless starting position. Clearly identified deviations, approved assumptions and a realistic evidence plan can be sufficient. A green status without a basis for decision is not.

Conclusion: success is won at the interfaces

Austrian suppliers do not need to build complete weapons systems to contribute to security and defence programmes. Their opportunity lies in sensors, electronics, software, manufacturing technology and materials. But a strong civilian technology becomes a suitable work package only when it can be procured, handled securely, exported, verified and supplied for years.

The decisions required for this belong in a shared requirements baseline, but not in a shared status. Every requirement needs its evidence, every configuration its classification and every expert approval a responsible person. Those who close this chain during the bid make commitments with known risk—and can fulfil them reliably later.

In brief
  • Dual use is a technical and end-use-related goods classification, not a procurement type.
  • Procurement, security clearance, export controls, technology and supply remain independent approvals.
  • Origin and data access are part of solution architecture in European programmes.
  • Evidence needs unambiguous requirements and configuration states.
  • Every relevant revision must pass through technology, export, security, contract and supply chain.
  • Automation structures the work; authorised experts make the decision.
t
tendric Editorial Team

Das tendric-Team entwickelt KI-gestützte Werkzeuge für die Ausschreibungsbearbeitung in der Industrie. Wir schreiben über Best Practices, Branchentrends und die Zukunft des Angebotsmanagements.

Wollen Sie tendric in Aktion sehen?