🏥 CAIH TENDER - COMPLETE & DETAILED SUMMARY
Innovation Partnership "Open Source Alternative"
Tender Reference: E26-01 | Negotiated Procedure
Document References: [PF] = Functional Program v20251222 | [CCAP] = Administrative Specifications v1.0 | [RC] = Consultation Regulations v20260130 | [Annex 1 RC] = Application Response Template
🎯 CONTEXT & STRATEGIC CHALLENGES [RC, Preamble]
Current Situation of Healthcare Institutions
Healthcare and medico-social institutions affiliated with CAIH currently primarily use integrated proprietary software environments and services, depending on dominant international vendors.
Identified Problems
| Problem |
Impact |
| 💸 Operating costs |
Annual global cost has become unsustainable |
| 🔗 Structural dependency |
Uncontrolled foreign technologies |
| 🔒 Technology lock-in |
Loss of data sovereignty |
| ⚡ Poor interoperability |
National/European open source initiatives not integrated |
Sought Solution [RC, Art. 1.2]
Design, experiment, qualify and industrialize a sovereign open source software suite covering:
- Workplace environment
- Digital identity
- Virtualization
- Hospital infrastructure (databases, application platforms)
Innovative and Differentiating Aspects [RC, Art. 2.1]
The ALTERNATIVE model stands out through:
- Single point of contact for support and maintenance
- "Open Source in Healthcare" standard enabling business software vendors to migrate from monopolistic technologies to cost-controlled Open Source solutions
- Data protection against extraterritorial foreign laws
General Information [PF, Articles 1-2 & CCAP, Article 3]
| Element |
Detail |
| Contracting Authority |
CAIH (Central Purchasing Body for Hospital IT) |
| Contract Type |
Innovation Partnership, Composite Framework Agreement |
| Procedure |
Negotiated procedure (articles L2124-3, R2124-3-4°, R2161-12 CCP) |
| Maximum Amount |
€250M excl. VAT (all phases included) |
| No Lots |
Single contract, no lots (joint contracting allowed) |
| APPLICATION DEADLINE |
February 19, 2026 at 12:30 PM (CET) |
| R&D Duration |
12 months max cumulative (3 sequences) |
| Acquisition Duration |
5 years firm + 2 renewals (1-2 years each) |
| Estimated Total Duration |
7-9 years |
CPV Codes [RC, Art. 1.2]
| Code |
Label |
| 72262000-9 |
Software development services |
| 72415000-2 |
Website hosting services |
| 72000000-5 |
IT services: consulting, software development |
Main Strategic Objective [PF, Article 2]
Migrate 100,000+ workstations (250,000+ users) to Open Source by 2030
Provisional Timeline [RC, Article 2.4]
| Stage |
Date |
| Application submission |
February 19, 2026, 12:30 PM |
| Selection of 3 candidates |
March 10, 2026 |
| Request for initial tenders |
Mid-March 2026 |
| Initial tender deadline |
Mid-April 2026 |
Candidate Premium [RC, Article 3.1.7]
- €20,000 incl. VAT paid to candidates who participated in all phases and submitted an acceptable final tender
- For successful tenderer: premium deducted from first contract payments
- Conditions: effective participation in negotiation phases + regular, acceptable and appropriate tender
Beneficiaries [CCAP, Article 2.2]
- Direct: CAIH + 13 member institutions of the consortium
- Potential: All current and future French healthcare institutions
13 Member Institutions of the Consortium [CCAP, Annex 1]
| No. |
Institution |
SIRET |
| 1 |
CHU d'Angers |
26490003600015 |
| 2 |
Union Sanitaire et Sociale pour l'Accompagnement et la Prévention |
32086181800237 |
| 3 |
Hospices Civils de Lyon |
26690027300019 |
| 4 |
CHU de Reims |
26510005700487 |
| 5 |
Assistance Publique – Hôpitaux de Paris |
26750045201928 |
| 6 |
CHU de Brest |
20002305900013 |
| 7 |
Assistance Publique – Hôpitaux de Marseille |
26130008100484 |
| 8 |
CHU de Nîmes |
26300003600032 |
| 9 |
Groupe Hospitalier La Rochelle – Ré – Aunis |
20004783500018 |
| 10 |
Groupe Hospitalier Rance Émeraude |
26350005000012 |
| 11 |
CHI Redon – Carentoir |
26350012600010 |
| 12 |
CHD Vendée |
26850242400016 |
| 13 |
CAIH |
80076579400022 |
Places of Execution [CCAP, Article 3.1]
- Design phase: European Union mandatory
- Experimentation phase: Pilot sites of consortium members
🔒 SECTION 1: SOVEREIGNTY & DATA
Health Data - High Risk [PF, Preamble]
Nature of Data [PF, Preamble - Nature of data]
Legal Definition (Article 4, §15 GDPR):
"All information relating to the physical or mental health status of a natural person, including information related to prevention, diagnosis, care or medico-administrative follow-up"
Classification & Processing [PF, Preamble - Nature of data]
- Classification: Special categories of personal data (Article 9 GDPR)
- Processing: In principle PROHIBITED
- Exceptions: Strictly regulated
- Protection: Enhanced protection mandatory
Risk Level [PF, Preamble - Risk level]
- Assessment: HIGH risk for rights and freedoms
- Impact: SEVERE in case of breach (privacy violation, discrimination, moral damage)
- Criticality: INCREASED for service continuity
Non-Negotiable Sovereignty Requirements [PF, Preliminary Article & PF, Preamble]
HDS Certification - MANDATORY [PF, Preamble - HDS Justification]
Health Data Hosting (Article L.1111-8 Public Health Code)
- Public policy obligation
- Applies to hosting, operation or administration of health data
- Guarantees: security, traceability, governance, business continuity
- Status: Non-negotiable [PF, Preliminary Article]
Exclusive European Union Location [PF, Preliminary Article - Minimum sovereignty requirements]
- Hosting exclusively in the EU
- No data transfer to third countries
- 100% administration from EU Member State
Capital Ownership Criteria [PF, Preliminary Article - Capital ownership criteria]
Hosting provider:
- Non-EU Capital: MAX 24% per individual third-party entity
- Non-EU Capital: MAX 39% collective
- No non-EU veto rights
- No non-EU majority in administrative bodies
Critical subcontractors: Same criteria if accessing sensitive data
Continuous Operating Autonomy [PF, Preliminary Article - Sovereign hosting definition]
- Ability to maintain service without dependency on single provider
- OR SecNumCloud 3.2 qualification of subcontractor
- OR access to at least 2 other provider suppliers
SecNumCloud 3.2 - RECOMMENDED (not mandatory) [PF, Preamble - SecNumCloud Justification]
Applied principles:
- Operator capital and governance control
- Legal immunity from extraterritorial laws
- Effective control of subcontracting chain
- Enhanced operational & organizational security
Regulatory Compliance [PF, Article 4.1]
Multidimensional Framework
- GDPR - EU General Data Protection Regulation
- HDS - Health Data Hosting (French Law)
- NIS2 - Network & Information Security Directive
- PGSSI-S - Health IS General Security Policy (ANS)
- AI Act - EU Artificial Intelligence Regulation
- Data Act - Data Access and Portability
Security by Design Principles [PF, Article 4.2]
Integration from design phase:
- Security reviews at each stage
- Automated security tests
- Systematic MFA/SSO
- Default encryption (transit + rest)
- Network segmentation
- Certified logging
- Real-time monitoring
Quantum Computing Risk Anticipation [PF, Article 4.3]
- Mapping of sensitive algorithms (RSA, ECC, TLS, S/MIME)
- Quantum cryptanalysis impact assessment
- Post-quantum cryptography (PQC) migration plan aligned with ANSSI/NIST
- Technology watch (ETSI, ISO, NIST)
- Hybrid encryption implementation (classical + PQC)
💻 SECTION 2: THE 5 TECHNOLOGY BUILDING BLOCKS
Global Architectural Principles [PF, Article 3 & Preliminary Article]
- Interoperability: All blocks integrated and validated as a whole
- Deployment flexibility: ON-PREMISE AND IaaS/PaaS/SaaS mode
- Microsoft coexistence: Mandatory (interoperability required)
- Business continuity: Associated business software vendors
- Minimum standard: 100% Open Source + proprietary tolerance for Microsoft interop only
Block 1: Collaborative Workspace (Modern Workspace) [PF, Article 3.1]
Office Suite
- LibreOffice (DINUM priority): Writer (text), Calc (spreadsheet), Impress (presentation)
- OnlyOffice (alternative): Office-compatible formats (.docx, .xlsx, .pptx)
- WOPI: Web Open Platform Interface for simultaneous multi-user co-editing
Email & Calendar [PF, Article 3.1]
Electronic Document Management (EDM) [PF, Article 3.1]
Video Conferencing & Unified Communications [PF, Article 3.1]
- Video conferencing: Jitsi (open source platform)
- Team chat: Mattermost
Microsoft Word Workaround [PF, Article 3.1]
Solution to bypass local Microsoft Word usage by business software (e.g.: winword.exe for DPI report editing)
Deployment Mode [PF, Article 3.1]
- Mandatory: ON-PREMISE
- Optional: SaaS offered
Block 2: Identity Management (ID CAIH) [PF, Article 3.2]
Centralized Directory
- Technology base: Open source LDAP
- Role: Single source of identity truth
Federated Strong Authentication
Protocols:
- SSO (Single Sign-On): Unique authentication
- MFA (Multi-Factor Authentication): Multiple factors
- IAM: Centralized access management
Implementations: OIDC (OpenID Connect), OAuth 2.0, SAML
Identity Provisioning
- Standard: SCIM (System for Cross-domain Identity Management)
- Properties: Bidirectional synchronization, resource auto-provisioning
Healthcare Professional Interoperability - MANDATORY [PF, Article 3.2]
- Pro Santé Connect: Healthcare access platform
- CPS: Healthcare Professional Card
- e-CPS: Electronic CPS / Hospiconnect
- Compliance: ANS and DNS interoperability frameworks
Deployment Mode [PF, Article 3.2]
- Mandatory: ON-PREMISE
- Optional: Hybrid/cloud extensions
Block 3: Hybrid Infrastructure & Virtualization [PF, Article 3.3]
Open Source Hypervisors [PF, Article 3.3]
Accepted open technologies:
- Proxmox VE
- oVirt
- KVM
- Xen Project
- OpenStack
Open Source Databases [PF, Article 3.3]
Relational and object:
- PostgreSQL
- MariaDB
- MySQL
- CouchDB
Orchestration & Automation
- Orchestration: Kubernetes, containers
- Infrastructure as Code: Terraform, Ansible, Helm
- Monitoring: OpenObserve (logs), ELK (Elasticsearch, Logstash, Kibana), Prometheus (metrics), Grafana (dashboards)
Interoperability & Migration [PF, Article 3.3]
- GLPI management (IT Asset Management)
- Standardized REST APIs
- Migration tooling for virtualized environments (VM → Proxmox/KVM/…)
Block 4: Fleet & Workstation Management [PF, Article 3.4]
Hospital Linux Distribution
- Qualified secure distributed base
- Adapted to hospital context
- Peripheral drivers
- Ergonomics close to current environments
Mobile Device Management (MDM)
- Desktop/laptop/tablet fleet management
- Deployment policies
- Centralized application configuration
Automated Remote Deployment
- Application push
- Automatic patch management
- Rollback capability
Monitoring & Inventory
- Automatic discovery
- Metrics (CPU, RAM, Disk)
- Threshold alerts
Block 5: Artificial Intelligence [PF, Article 3.5]
"The contractor will propose an open source conversational AI service (LLM) operating in a sovereign and controlled environment, guaranteeing data confidentiality and control over models used. It is complemented by speech recognition functionality with, if possible, a medical extension. The objective is to retain the Open Source distribution and technical components. Their customizations will initially be limited to integration with other blocks."
In summary: Sovereign open source LLM + speech recognition (optional medical). Complementary block to the other 4, with limited customizations.
🔧 SECTION 3: SERVICES & DELIVERABLES
RUN Services (24/7 Daily Operations) [PF, Article 6 - S3C Operations services]
24/7 Monitoring
- Real-time metrics
- Centralized logs
- Application traces
- Continuous security audit
- Centralized platform with CAIH dashboards
- Automated N2/N3 alerting
Security Updates [PF, Article 6 - S3C Operations services]
- Monthly publication of patches
- Urgent: Priority deployment
- Non-urgent: Consolidated version
Functional Updates [PF, Article 6 - S3C Operations services]
- Quarterly publication of major versions
- Integration of new open source features
- Regulatory evolutions (PGSSI-S, NIS2)
Incident Management [PF, Article 6 - S3C Operations services]
- Centralized recording
- Diagnosis and repair
- N2 → N3 escalation if necessary
- Monthly incident reports
Capacity Planning [PF, Article 6 - S3C Operations services]
- Future resource planning
- Infrastructure sizing
- Saturation prevention
MCO Services (Operational Maintenance) [PF, Article 6 - S3D MCO services]
Application Patches
- Continuous
- Bugs and functional issues
- Integration with business software vendors
Periodic Updates
- Quarterly
- Fully tested consolidated version
- Complete release notes
- Rollback procedures
Vulnerability Tracking
- Continuous automated management
- Applicable CVE monitoring
- Risk assessment
- Patch prioritization
Monthly CAIH Reporting [PF, Article 6 - S3D MCO services]
- Incidents occurred
- Measured availability
- Vulnerabilities fixed
- Tolerated anomalies
Annual Roadmap [PF, Article 6 - S3D MCO services]
- Annually validated by CAIH
- Proposed functional evolutions
- Alignment with institution needs
- Implementation prioritization
Support Services [PF, Article 6 - S3E Support services]
N2 Support (Institutions)
- Target: Institution DSI/support teams
- SLA: ≤ 4 business hours
- First-level diagnosis
- N3 escalation if beyond competencies
N3 Support (Integrators/AMOE)
- Target: AMOA/AMOE service providers
- SLA: ≤ 8 business hours
- Deep technical expertise
- Code debugging
- Evolution management
Intervention Schedule [PF, Article 6 - S3E Support services]
- Initial phase: 5d/7, 8am-midnight (Monday-Friday)
- Evolving phase: 24/7 optional
- Decision: CAIH steering committee
Portal & Knowledge Base [PF, Article 6 - S3E Support services]
- Centralized ticket portal
- Shared knowledge base
- Shared CAIH observability
Team Location [CCAP, Article 6.10.2]
- Teams: Based in EU Member State(s)
- Language: Fluent French mandatory
Managed Security Services [PF, Article 6 - S3B Security services]
Identity & Access
- MFA (multi-factor authentication)
- SSO (federated Single Sign-On)
- System hardening
Certified Logging
- Tamper-proof (immutable)
- Timestamped (temporal precision)
- Explorable (forensic)
- Complete (no loss)
- Multi-source security event federation
- Alert correlation
- Centralized dashboard
SOC (Security Operations Center)
- Optional 24/7
- Continuous surveillance
- Reactive incident response
Perimeter Protection
- IDS: Network intrusion detection
- IPS: Intrusion prevention
- Anti-DDoS: Volumetric attack mitigation
- WAF: Application firewall
Vulnerability Management
- Continuous scanning
- Exposure analysis
- Risk prioritization
- Remediation plan
Penetration Testing
- Regular intrusion tests
- Annual + continuous security audit
- Patch validation
Incident Response
- Documented incident plan
- 24/7 escalation
- Forensics and investigation
Availability & Continuity [PF, Article 6 - Availability, continuity, reversibility]
Target SLA
- Availability: ≥ 99.8% monthly
- Measurement: Continuous with monthly reports
- Calculation: Monthly
Recovery & Business Continuity
- DRP (Disaster Recovery Plan): < 4 hours
- BCP (Business Continuity Plan): Multi-zone high availability
- Datacenters: Distinct, uncorrelated, EU proximity
- Latency: Low, compatible with clinical uses
Full Reversibility [PF, Article 6 - Availability, continuity, reversibility]
Export capabilities:
- Virtual machines
- Containers
- Databases
- Files
- Audit logs
- Complete configurations
To be defined in contract: Format, duration, costs, procedures
Alternative Operator Portability
- Guaranteed exit without dependency
- Sovereign operator change capability
LTS Versions (Long Term Support) [PF, Article 8]
- Minimum duration: 36 months per LTS version
- Coverage: Security patches, regulatory compliance, blocking anomalies
- Major updates: Subject to CAIH validation
📦 SECTION 4: DELIVERABLES BY PHASE
R&D Phase - Sequence 1 (Design & Development) [PF, Article 6.1 - Sequence 1]
S1 Deliverables:
- Global target architecture for 5 blocks
- Customized open source distributions
- Initial Security Assurance Plan (PAS)
- Migration kits (technical & organizational)
- IT & user training kits
- First reproducible ISO/OVA
- Detailed functional specifications
- Initial migration trajectories
R&D Phase - Sequence 2 (Prototyping & Experimentation) [PF, Article 6.1 - Sequence 2]
Planned Hackathons:
- "Uses" Hackathon and functional POCs
- "Technologies" Hackathon and technical POCs
- "Financial modeling and pilot generalization plan" Hackathon
S2 Deliverables:
- S2L1: Technical deliverables (prototypes, performance reports)
- S2L2: Functional deliverables (POC/pilot feedback)
- S2L3: Economic deliverables (TCO/ROI model)
- S2L4: Organizational deliverables
- S2L5: Validation synthesis file
R&D Phase - Sequence 3 (Pre-Industrialization) [PF, Article 6.1 - Sequence 3]
Work Streams:
- Technical integration & industrialization
- Operational transfer & AMOA/AMOE kits
- Mutualized MCO & Support service
S3 Deliverables - Services:
- S3A: Hosting & infrastructure services (IaaS/PaaS/SaaS)
- S3B: Managed security services (SIEM, optional SOC, penetration tests)
- S3C: Operations services (24/7 RUN, monitoring, updates)
- S3D: MCO services (maintenance, vulnerabilities, roadmap)
- S3E: Support services (N2/N3, 4h/8h SLA)
- S3F: Support services (AMOA/AMOE, migration, training)
S3 Deliverables - Technical:
- Reproducible deployment kits
- Automation scripts (Ansible/Terraform/Helm)
- Reproducible images (ISO/OVA/containers)
- Complete MCO service catalog
- GDPR/HDS/NIS2 audit report
- Complete AMOA/AMOE kits
- Contract templates
- Final unit price schedule
Acquisition Phase (5 years + 2 renewals 1-2 years) [PF, Article 6.2]
Operational Deliverables:
- Acquisition/operation contract
- Complete service catalog (S3A to S3F)
- Monitored hosted environments
- SI integration guides (APIs, FHIR, SCIM, WOPI)
- Monthly reports (incidents, availability, performance, vulnerabilities)
- Continuous N2/N3 support
- Annual sustainability report (actual costs, savings, 3-5 year vision)
📚 SECTION 5: SUPPORT & RESOURCES
Consulting Services [PF, Article 5 & Article 7]
AMOA (Project Owner Assistance) [PF, Article 5]
Role: Representative of user institutions
Responsibilities:
- Functional requirements validation
- Compliance deliverables validation
- User change management
- End-user training
AMOE (Project Manager Assistance) [PF, Article 5]
Role: Technical execution expertise
Responsibilities:
- Technical architecture validation
- Infrastructure deployment support
- Technical tests (performance, security)
- Operations troubleshooting
IS Audits [PF, Article 5]
Domains:
- Existing system interoperability audit
- HDS/NIS2 compliance security audit
- Migration architecture
Security & Compliance Audit [PF, Article 5]
- Code security audit
- Infrastructure audit
- Penetration test
Change Management [PF, Article 5]
Organizational Transition Guides
Contents:
- Guide for DSI (IT Director)
- Guide for RSI (IS Manager)
- Guide for RSSI (IS Security Manager)
Elements:
- Migration phases
- Identified risks
- Contingency plans
Business Impact Analysis
Identification:
- Ergonomic impacts
- Business process impacts
- Training required by role
Internal Communication
Templates:
- Newsletter templates
- Management communications
- User FAQ
Timing: Before, during, after migration
Topics:
- OSS solution governance
- OSS-specific security management
- 24/7 operations management
Business Software Vendor Support Program [CCAP, Article 6.10.6]
The Contractor implements a structured support program for business software vendors to facilitate migration to open, interoperable, secure and sustainable platforms:
- Technical and functional sessions (workshops, webinars, training)
- Complete documentation (migration guides, interoperability references)
- SDK, APIs and code examples facilitating integration
- Participation in "Open Source Vendors UNIHA-CAIH" group
Complete Training [PF, Article 5]
IT Training Kits [PF, Article 5 - L5.1]
Objective: Train and support change for institution IT teams
Deliverables: IT training kits
User Training Kits [PF, Article 5 - L5.2]
Objective: Train end users on functional blocks
Deliverables: User training kits
Key Profiles to Recruit [PF, Article 7 - Intellectual services]
Category A - Sovereign Infrastructure & Hosting
- A1.1: DevOps / Build Infrastructure (Junior to Expert)
- A1.2: Sovereign System Administrator (Junior to Senior)
- A1.3: HDS/SecNumCloud Hosting Engineer (Confirmed to Expert)
- A1.4: Infrastructure Architect (Senior to Expert)
Category B - Identity (ID CAIH / IAM)
- B1: IAM Developer (Junior to Expert)
- B2: IAM Integrator (Confirmed to Senior)
- B3: IAM Architect (Senior to Expert)
Category C - Modern Workspace
- C1: MW Developer (Junior to Senior)
- C2: MW Integrator (Junior to Senior)
- C3: MW Expert (Expert)
Category D - Virtualization / Cloud
- D1: Virtualization Specialist (Junior to Senior)
- D2: Cloud Automation Developer (Junior to Expert)
- D3: Cloud Architect (Senior to Expert)
Category E - Interoperability / Migration / Deployment
- E1: API/FHIR/SCIM Interoperability Engineer (Junior to Senior)
- E2: Migration & Deployment Engineer (Junior to Senior)
- E3: AMOA / Change Management Expert (Senior to Expert)
Category F - Cybersecurity / SOC
- F1: SOC / Operational Security Analyst (Junior to Senior)
- F2: Cybersecurity Engineer (Confirmed to Expert)
- F3: Security Architect (Senior to Expert)
📝 SECTION 6: APPLICATION & SELECTION
Candidate Selection Criteria [RC, Article 6.1.3]
| Criterion |
Weighting |
Evaluated Elements |
| C1 - Financial capacity |
10% |
Total revenue + Open Source revenue (last 3 fiscal years) |
| C2 - Technical capacity |
20% |
Workforce, management, profiles (dev, integration, N2/N3 support, agile) |
| C3 - Professional capacity |
70% |
Open Source references, R&D, innovative solutions, contributions to third-party OS projects |
Maximum 3 candidates will be selected for tender phase (if sufficient number)
Tender Evaluation Criteria [RC, Article 6.3]
| Criterion |
Weighting |
Description |
| Financial criterion |
30% |
Total tender price |
| T1 - Coherence, adequacy, robustness |
15% |
Architecture, OS choices, security, sovereignty, interoperability, continuity |
| T2 - Operational methodology |
15% |
R&D and acquisition phases, deliverables, milestones, acceptance, risk management |
| T3 - OS development cycle mastery |
15% |
Contribution governance, versions, CI/CD, security by design, sustainability |
| T4 - Generalization and funding |
10% |
CAIH member adoption, public funding support, general interest |
| T5 - Support, MCO, operations |
10% |
Support organization, monitoring, business continuity, OS block maintenance |
| T6 - CSR approach |
5% |
Digital sobriety, OS ecosystem contribution, social/territorial impact |
Application Requirements [Annex 1 RC - Response Template]
Significant References (Maximum 4)
- Number: Maximum 4 references
- Format: 1 A4 page front and back per reference
- Period: Initiated or deployed within the last 4 years
| Criterion |
Description |
| Deployment date |
Deployment date |
| Client Company |
Name and address |
| Business sector |
Domain and products handled |
| Project nature |
Scope and perimeter |
| Regulatory requirements |
Standards implemented |
| Project manager |
CV, dedicated time, tools used |
| Schedule |
Study → Development → Implementation → Production |
| Cost |
"Turnkey" solution |
| Maintenance |
Contract type, internalization level, reliability |
| Client contact |
Name, function, phone, email |
Blocks Concerned (to specify per reference)
Workforce and Open Source Contributions [Annex 1 RC]
To provide for the last 3 years (2023, 2024, 2025):
| Company |
Total Workforce |
OS Developers |
R&D Staff |
OS Community Contributions |
| Lead |
|
|
|
|
| Member 2 |
|
|
|
|
| ... |
|
|
|
|
Community contributions: Detail publications to Open Source projects (commits, PRs, documentation, etc.)
Technical and Organizational Equipment
Description of resources to ensure:
- Service quality
- Available study resources
- Company research resources
📄 SECTION 6bis: INITIAL TENDER DELIVERABLES [RC, Annex 2]
This section details the deliverables expected during Stage 2 - Initial Tender (after selection of 3 candidates)
Mandatory Technical Response Framework [RC, Annex 1]
The technical memo must imperatively follow this structure:
| Chapter |
Title |
RC Criterion |
| 1 |
Solution coherence, adequacy and robustness |
T1 (15%) |
| 2 |
Innovation partnership operational methodology |
T2 (15%) |
| 3 |
Open Source development cycle mastery |
T3 (15%) |
| 4 |
Generalization, promotion and public funding |
T4 (10%) |
| 5 |
Support, MCO and operations in hospital environment |
T5 (10%) |
| 6 |
CSR approach applied to the project |
T6 (5%) |
Initial Tender Deliverables List [RC, Annex 3]
Technical Deliverables
| Ref |
Deliverable |
Content |
| L3 |
General technical memo |
Understanding of challenges, OS strategic vision, objectives alignment |
| L4 |
Target Open Source architecture |
Functional/technical architecture, OS blocks, hospital SI interoperability |
| L5 |
Sovereign hosting note |
Hosting model, EU location, HDS compliance, SecNumCloud guarantees |
| L6 |
BCP/DRP note |
Business continuity, failure scenarios, technology diversification, RTO/RPO |
Security & Compliance Deliverables
| Ref |
Deliverable |
Content |
| L7 |
Security Assurance Plan (PAS) |
Security governance, risk analysis, protection measures, GDPR/HDS/NIS2 alignment |
| L8 |
Regulatory compliance note |
GDPR, HDS compliance, healthcare institution security requirements |
| L9 |
Post-quantum cryptographic strategy |
PQC challenges, orientations, migration trajectory, ANSSI/NIST alignment |
Methodological Deliverables
| Ref |
Deliverable |
Content |
| L10 |
R&D phase conduct methodology |
Sequence breakdown, deliverables per sequence, validation indicators |
| L11 |
Project organization & governance |
Candidate/grouping organization, roles, PI governance |
| L12 |
Support, training, reversibility plan |
OS acculturation, hospital IT training, skill transfer |
Economic Deliverables
| Ref |
Deliverable |
Content |
| L13 |
Partnership economic model |
Economic hypotheses, sustainability, generalization trajectory |
| L14 |
TCO projection and comparison |
Total cost of ownership, proprietary solutions comparison, optimization levers |
Annexes
| Ref |
Deliverable |
Content |
| L15 |
Technical references |
Comparable OS projects, at-scale deployments, critical/sovereign environments |
| L16 |
Certificates and attestations |
HDS certification (mandatory), SecNumCloud 3.2 (if held), professional insurance |
💰 SECTION 7: FINANCIAL CONDITIONS
Price Structure [CCAP, Article 9]
R&D Phase
- Type: Fixed lump-sum prices
- Evolution: Non-revisable
- Maximum modification: +15% by justified amendment [CCAP, Article 12.5]
Acquisition Phase
- Type: Revisable unit prices
- Promotions: Possible on Contractor initiative
- Revision: Annual on anniversary date
Price Revision Formulas [CCAP, Article 9.2]
NTIC Services (Daily Rate)
Index: SYNTEC
Pn = P0 × (0.20 + 0.80 × Sn/S0)
- P0: initial price
- Pn: year n price
- S0: SYNTEC index notification month
- Sn: SYNTEC index year n anniversary month
- 20%: non-revisable fixed portion
- 80%: indexed portion
HDS Hosting
Indices: SYNTEC + INSEE (electricity + services)
Pn = P0 × (0.20 + 0.40 × Sn/S0 + 0.20 × En/E0 + 0.20 × In/I0)
- S: SYNTEC index
- E: INSEE electricity index
- I: INSEE IT services index
Safeguard Clause [CCAP, Article 9.3]
Increase > 5% compared to last applicable price → Termination possible without indemnity
Payment Terms [CCAP, Article 10]
- Payment deadline: 50 days from invoice receipt
- Installments: Possible per R2191-20 to R2191-22 CCP
- Advance: 5% of phase amount (R&D and Acquisition)
- Guarantee retention: 5% deducted from each installment
- Invoicing: Mandatory via CHORUS PRO
⚠️ SECTION 8: PENALTIES [CCAP, Article 11]
R&D Phase Penalties
- Sequence delay: 0.3% of sequence excl. VAT per business day of delay
- Deliverable non-compliance: 1% of sequence amount per week
- Cap: 20% of total R&D phase excl. VAT amount
Acquisition Phase Penalties
- Service delay: 1% of service excl. VAT per business week
- Rejection/Non-acceptance: 2% of service excl. VAT
- Cap: 20% of maximum framework agreement excl. VAT amount
Support SLA Penalties
- Acknowledgment exceeded: €50 per ticket
- Response exceeded:
- Severity 1 (blocking): €150
- Severity 2: €75
- Severity 3: €30
- Resolution exceeded:
- Severity 1: €300/hour
- Severity 2: €150/hour
- Severity 3: €50/hour
Service Unavailability Penalties
| Monthly Availability |
Penalty |
| < 99.5% |
-2% monthly fee |
| < 99% |
-5% monthly fee |
| < 98% |
-10% monthly fee |
| < 96% |
-20% monthly fee |
Security Penalties
- Security obligation non-compliance: 2% of annual support amount per substantial violation
- Monitoring/alerting failure: 0.5% monthly hosting fee per hour of unavailability (cap 10%/month)
🔎 SECTION 9: GRANT RESEARCH [CCAP, Article 6.11]
The Contractor contributes to grant and co-financing research from:
- EDIC Digital Commons (European Digital Infrastructure Consortium)
- DINUM (public action modernization, digital innovation)
- ANS (interoperability, digital identity, cybersecurity)
- France 2030 / Health Innovation / Future Investments
- European programs: Horizon Europe, Digital Europe, Interreg
Deliverables: Active monitoring + financing plan updated at each phase
🏛️ SECTION 10: GOVERNANCE & MANAGEMENT [CCAP, Article 6.10.4]
Quarterly Agile Management
Partnership monitoring is organized in quarterly sprints (3 months), following agile methodology principles.
Each Sprint includes:
- Sprint review in technical committee (CAIH + pilot institutions + industrials + vendors)
- Performance, compliance and usage indicator updates
- Backlog adjustment (functional, security, ergonomic, interoperability, R&D priorities)
Indicators by Domain [CCAP, Article 6.10.4]
| Domain |
Indicator Type |
Examples |
| Technical |
Performance, interoperability, availability |
Test success rate, compatibility, uptime % |
| Security |
GDPR/HDS/NIS2 compliance, vulnerabilities |
Nb non-compliances, correction delay, audits |
| Functional |
Usage, ergonomics, adoption |
Active user rate, satisfaction (rating /5) |
| Economic |
Costs / savings / TCO |
Avoided cost ratio vs target, OSS share |
| R&D / Innovation |
New features, modularity |
Nb OS contributions, patents, modules |
| Funding |
Grants and co-financing |
Amount mobilized, R&D coverage rate |
Capitalization & Feedback [CCAP, Article 6.10.5]
Central REX Registry
- Feedback registry accessible to CAIH, pilot institutions and industrial partners
- Quarterly capitalization workshops
- Systematic integration into technical and strategic committees
Capitalization Deliverables
- REX and indicator tracking table
- Annual capitalization report (distributed to CAIH, DINUM, ANS, ANSSI)
- Mutualized "Open Source Healthcare" best practices
Key Governance Deadlines
| Event |
Deadline |
| Deliverable acceptance |
30 days after delivery (CCAP Art. 6.9.1) |
| Formal notice |
If no decision within 30 days |
| Tacit acceptance |
30 additional days after formal notice |
| Data breach notification |
24h maximum (CCAP Annex 3) |
| Joint contractor replacement |
30 days to propose alternative (CCAP Art. 12.4) |
- CAIH DPO: dpo@caih.fr
- Notifications: dpo@caih.org
Negotiation Procedure [RC, Art. 6.3]
- Number of phases: 2 to 3 negotiation phases (indicative)
- Possible rejection: After each phase, tenders may be rejected after intermediate ranking
- Final tender: Invitation to submit final tender after conclusion of negotiations
- Non-negotiable elements: Minimum requirements (PF Preliminary Article) and award criteria
Confidentiality [RC, Art. 8.3]
- ✅ CAIH commits to keeping strictly confidential all information shared by candidates
- ✅ Candidates commit not to disclose information provided by CAIH
- ✅ Exception: right to effective remedy and court production
Competent Court [RC, Art. 8.4]
- Jurisdiction: Lyon Administrative Court
- Address: 184 Rue Duguesclin, 69433 Lyon Cedex 03
- Contact: 04 78 14 10 10 | greffe.ta-lyon@juradm.fr
🎯 SECTION 11: RESPONSE STRUCTURE
Joint Contracting Allowed [RC, Art. 3.3 & CCAP, Art. 3.2]
- ✅ Economic operator grouping possible
- ✅ Single lead contractor + joint contractors
- ✅ Lead jointly liable for other member(s) in case of joint grouping
- ✅ Each member complies with sovereignty criteria
- ✅ Joint contractor replacement possible under conditions (30-day deadline)
Multiple Application Rules [RC, Art. 3.3]
- ✅ An operator can be individual candidate AND member of grouping(s)
- ✅ An operator can be member of multiple groupings
- ⚠️ An operator can only be lead of one grouping
Composition Modification During Consultation [RC, Art. 3.3]
Allowed in the following cases:
- Restructuring of a member
- Inability to perform task (external reasons)
- Replacement required by buyer (exclusion reason) - 10-day deadline
- Grouping constitution/modification from existing candidates (subject to maintaining guarantees)
Recommended Architecture
JOINT CONTRACTING GROUPING (ONE APPLICATION)
│
├─ LEAD (Administrative leader)
│ └─ Experienced open source integrator
│
├─ + JOINT CONTRACTOR 1: Infrastructure/Hosting
│ └─ HDS/SecNumCloud certified
│
├─ + JOINT CONTRACTOR 2: Software Development
│ └─ OSS block experts (Workspace, ID, Infra)
│
├─ + JOINT CONTRACTOR 3: Support
│ └─ Hospital change management
│
└─ + JOINT CONTRACTOR 4: Support
└─ N2/N3 Support
ECONOMIC OPERATOR GROUPING
Contractor Commercial Neutrality [CCAP, Article 6.10.7.1.D]
In all promotional actions, the Contractor:
- Respects the commercial neutrality principle
- Exercises no pressure on institutions
- Promotes free competition among service providers
- Commits not to claim exclusivity on associated services
Actions are conducted under CAIH management, which validates messages, materials, commitments and formats.
📌 CRITICAL POINTS TO REMEMBER
| Criterion |
Requirement |
Source |
| HDS |
Mandatory (non-negotiable) |
[PF, Preamble] |
| Location |
European Union exclusively |
[PF, Preliminary Article] |
| Non-EU Capital |
Max 24% individual, 39% collective |
[PF, Preliminary Article] |
| Open Source |
100% minimum (Microsoft interop tolerance) |
[PF, Preliminary Article] |
| SLA |
99.8% monthly |
[PF, Article 6] |
| DRP |
< 4 hours |
[PF, Article 6] |
| N2 Support |
≤ 4 business hours |
[PF, Article 6] |
| N3 Support |
≤ 8 business hours |
[PF, Article 6] |
| Teams |
EU + French-speaking mandatory |
[CCAP, Article 6.10.2] |
| LTS |
36 months minimum |
[PF, Article 8] |
| Source code |
Delivered to CAIH + open licenses |
[CCAP, Article 6.13] |
| R&D duration |
12 months max cumulative |
[CCAP, Article 3.5] |
| R&D modification |
Max +15% by amendment |
[CCAP, Article 12.5] |
| References |
Max 4, A4 front-back, last 4 years |
[Annex 1 RC] |
| Payment deadline |
50 days |
[CCAP, Article 10.3] |
| Acceptance deadline |
30 days |
[CCAP, Article 6.9.1] |
| Joint contractor replacement |
30 days |
[CCAP, Article 12.4] |
| Breach notification |
24h |
[CCAP, Annex 3] |
| APPLICATION DEADLINE |
February 19, 2026, 12:30 PM |
[RC] |
🚀 NEXT STEPS
🌐 PLACE: https://www.marches-publics.gouv.fr
| Element |
Detail |
| Submission mode |
Exclusively via PLACE buyer profile |
| Communication |
Electronic mandatory |
| Registration |
Recommended for automatic DCE modification tracking |
| File format |
Short names (< 30 characters), naming: 26_01_DC_[type]_[SupplierName] |
| Backup copy |
Possible (paper/physical or electronic) with "Backup copy" mention |
Application Phase (Absolute Priority)
- ✅ Understand the 5 functional blocks [PF, Article 3]
- ⏳ Prepare max 4 references (1 A4 page front-back each)
- ⏳ Cover blocks: Workspace, ID CAIH, Infrastructure, Fleet & Workstations
- ⏳ Prepare workforce & OS contributions table (2023-2025)
- ⏳ Verify internal capabilities on 5 blocks
- ⏳ Identify joint contracting partners (HDS mandatory)
- ⏳ Validate sovereignty compliance (HDS, EU capital, EU location)
- ⏳ Prepare grouping agreement
- ⏳ Prepare sworn statement (articles L.2141-1 to L.2141-11 CCP)
- ⏳ Attach HDS certification + SecNumCloud 3.2 (optional)
- ⏳ SUBMIT ON PLACE BEFORE February 19, 2026, 12:30 PM
Tender Phase (if selected among 3 candidates - ~March 10, 2026)
- ⏳ Receive invitation to tender
- ⏳ Prepare deliverables L3 to L16 (see Section 6bis)
- ⏳ Draft technical memo (6 mandatory chapters)
- ⏳ Participate in negotiations (2-3 phases)
- ⏳ Submit final tender
R&D Phase (if successful)
- ⏳ Develop 5-block prototypes
- ⏳ POCs & pilots in 13 institutions
- ⏳ Industrialization & pre-production
- ⏳ Complete MCO/Support service catalog
Complete document created: January 15, 2026
Major update: February 3, 2026 (Full enrichment with RC v20260130 - tender deliverables, negotiation, groupings)
Structure: Consistent with RESUME_SHORT_EN.md
Sources: Functional Program v20251222, CCAP v1.0, RC v20260130, Annex 1 RC, Institutions List
Legend:
- [PF] = Functional Program
- [CCAP] = Administrative Specifications
- [RC] = Consultation Regulations v20260130
- [Annex 1 RC] = Application Response Template
- [BOAMP] = Official Bulletin of Public Contract Announcements