23/09/26

The proposed EU public procurement regulation: Key changes and practical implications for Belgium

Introduction

On 9 September 2026, the European Commission published a proposal for a Public Procurement Act in the form of a single, directly applicable Regulation replacing the three 2014 Directives. The shift from directives to a regulation eliminates national transposition and imposes a uniform EU-wide framework. For Belgium, this means the existing legislative architecture must be substantially dismantled.

This newsletter analyses the proposal across three areas of practical relevance:

  • Access to public procurement: the European preference framework, expanded exclusion grounds, and the security and resilience regime;
  • The award procedure: the new procedural architecture, the mandatory best price-quality ratio, and strategic procurement objectives; and
  • Contract execution: the revised modification rules and the implications for Belgium's statutory performance regime.

Practical recommendations for both EU-established and non-EU companies follow at the end.

Of note, defence and security procurements within the meaning of Directive 2009/81/EC fall outside the scope of the proposed Regulation. For Belgium, the Act of 13 August 2011 on public procurement in the fields of defence and security, and its implementing decrees, remain unaffected.

Access to public procurement

European preference framework

The proposal introduces a horizontal European preference framework. Public buyers may restrict participation to Union or covered operators, impose minimum Union-origin content requirements, grant evaluation preferences through price reductions or additional award points, or reject tenders where Union or covered content falls below 50% of the estimated contract value. Any such measures must be stated upfront in the competition public summary. The Commission may separately close specific procurements to non-covered operators or restrict coverage where a third country denies reciprocal access to Union operators.

The framework is permissive, not mandatory. Absent a specific decision by the public buyer or a Commission closure act, non-EU operators retain their existing access. Restrictions are determined by the origin of the economic operator under Regulation (EU) 2022/1031. Public buyers may also disapply European preference requirements in defined circumstances: emergency, absence of Union or covered supply, or disproportionate cost.

A Union-incorporated subsidiary (even if ultimately owned or controlled by a non-EU parent) qualifies in principle as a Union operator and falls outside the preference restrictions. However, EU establishment is not a safe harbour. Under Article 26(1)(g), a public buyer may still exclude any operator that lacks sufficient reliability to exclude risks to the security or public safety interests of the Union or a Member State. This ground (which may be established on the basis of classified information or non-publicly disclosable assessments) is available precisely to address concerns arising from third-country ownership or control structures.

For Belgium, the stakes are real. Belgium's open economy and the concentration of international organisations on its territory — including EU institutions and NATO — have historically made its procurement market accessible to foreign operators outside the defence sector. The European preference tools give Belgian contracting authorities new instruments to restrict or condition that access. How actively they are used, and whether the Commission issues closure acts in specific sectors, will determine the practical impact.

Exclusion grounds: Expanded scope, no self-cleaning for mandatory grounds

The proposal significantly restructures the exclusion grounds regime. The current Directive applies a single set of grounds with self-cleaning available across the board. The Regulation draws a hard line between mandatory and optional grounds — with material consequences for operators facing exclusion.

The list of mandatory grounds is substantially expanded. The Directive covered seven categories of serious criminal offences. The Regulation adds four: environmental criminal offences, criminal offences relating to the violation of Union restrictive measures, fraudulent use of non-cash payment instruments, and sexual abuse and exploitation of children. The critical change is the elimination of self-cleaning for mandatory grounds. Under the Directive, self-cleaning was available for all exclusion grounds. Under the Regulation, it is confined to optional grounds only. An operator convicted of a mandatory offence is excluded regardless of any remedial measures taken.

The optional grounds are also extended. Two new categories are introduced: insufficient reliability to exclude risks to the security or public safety interests of the Union or a Member State, and receipt of foreign subsidies distorting the internal market where established by a Commission implementing act. Self-cleaning remains available for optional grounds. Member States may designate a national authority to assess the sufficiency of the evidence provided.

Security, resilience and strategic autonomy

The proposal introduces a dedicated chapter on security, resilience and cybersecurity. Public buyers must identify and address security and public safety risks at every stage of a procurement, from planning and market consultation through to contract execution. The relevant considerations are broad and non-exhaustive: protection of critical infrastructure, prevention of espionage and technology leakage, cybersecurity of systems and networks, protection of classified information, and prevention of undue third-country influence. For contracts to be performed by entities designated as critical under Directive (EU) 2022/2557, specific resilience and security-of-supply requirements apply — including supply chain diversification, stockpiling obligations, business continuity planning, and surge capacity commitments. Contracts may be terminated and operators excluded during performance on security grounds.

For technology sector companies, the most acute risk is the mandatory exclusion for suppliers designated as high-risk under the forthcoming Cyber Security Act 2.0 (CSA2) in relation to ICT components to be used in key ICT assets. This exclusion is mandatory, operates without any possibility of self-cleaning, and applies automatically once a designation is made. Public buyers have no discretion. Companies supplying ICT products or services to the public sector must monitor CSA2 developments closely and assess their exposure now.

Award procedure

Streamlined procedures

The proposal replaces the current five procedures with three. The open procedure allows any interested operator to submit a tender from the outset. The dynamic procedure operates through a pre-constituted pool of operators who are subsequently invited to tender or negotiate for individual contracts as they arise. Both may be used with or without selection criteria and with or without negotiations. The innovation procedure is designed for the development and acquisition of solutions that do not yet exist on the market.

Market consultations are encouraged as a standard preparatory tool. Selection criteria are capped at what is necessary and proportionate: excessive turnover thresholds are curtailed, and unjustified requirements for prior public-sector experience are prohibited.

The Regulation retains a direct award procedure for strictly defined circumstances. Public buyers may award a contract by requesting a solution directly from one or more operators without competition or prior publication, subject only to a post-award public summary of result. The procedure is available where competition is objectively absent, in cases of emergency or extreme urgency, or for certain service categories — including catering and food-related services — where the cross-border dimension is limited.

Award criteria: Quality over price

The Best Price-Quality Ratio (BPQR) becomes the default award method. Quality criteria must account for at least 30% of the overall assessment, rising to 50% for labour-intensive contracts. Price-only awards are not prohibited, but public buyers who depart from the BPQR must explain how quality will otherwise be ensured. The comply-or-explain mechanism makes price-only competition the exception, not the rule.

Quality is broadly defined. It may encompass technical merit, environmental and social factors, innovation, security, resilience, and the qualifications and experience of the personnel assigned to perform the contract.

Strategic procurement: Beyond price and quality

The proposal significantly expands the scope for strategic procurement. Public buyers may factor in sustainability, social inclusion, working conditions, accessibility, innovation, and human rights in supply chains throughout the procurement cycle. The legal bases for applying environmental criteria are clarified and strengthened, with a particular emphasis on circularity and energy efficiency. The Commission may impose mandatory environmental requirements for specific product categories through delegated acts. Life-cycle costing is given a stronger role, enabling procurement decisions to account for costs across the full contract life and for broader environmental and climate externalities.

Social objectives receive equal prominence. The proposal codifies the intended outcomes — labour market integration, gender equality, and human rights in supply chains — and preserves dedicated instruments such as reserved contracts and tailored rules for social, health, and educational services.

Contract execution

Contract modifications during their term

The Regulation introduces three notable changes to the contract modification regime.

  • First, the “de minimis threshold” below which a modification is automatically non-substantial is harmonised at 15% across all contract types. Under the current Directive, the threshold was 10% for services and supplies and 15% for works. The Regulation eliminates that distinction and applies a uniform 15% threshold regardless of subject-matter.
  • Second, a prior publication obligation is introduced for major modifications. Where a modification exceeds 50% of the initial estimated contract value, the public buyer must publish a public summary of modification before the modification takes effect. This is a significant addition: the current Directive requires only ex post publication in the Official Journal.
  • Third, the Regulation expressly prohibits the use of contract modifications to remedy performance deficiencies attributable to the contractor. In all cases, the public buyer must document the justification for any modification on the basis of objective and verifiable elements.

Performance monitoring and sanctions

A key question for any company executing public procurements in Belgium is whether the proposed Regulation displaces Belgium's statutory performance sanctions regime. Under the current framework, the Royal Decree of 14 January 2013 establishes a comprehensive, mandatory regime of performance sanctions — covering penalties for late performance, default measures, and unilateral termination procedures — that applies by operation of law to all public contracts unless expressly derogated from in the contract documents. This statutory model differs markedly from the contractual approach adopted in jurisdictions such as the Netherlands, Denmark, or Finland.

The proposed Regulation does not introduce a harmonised regime for contract performance sanctions. It codifies certain principles (the prohibition on using modifications to remedy contractor-attributable deficiencies, and the obligation to document modification justifications) but does not prescribe sanction types, penalty rates, or procedural steps. Belgium's statutory framework under the Royal Decree of 14 January 2013 should therefore, in principle, continue to operate alongside the Regulation, provided it does not conflict with directly applicable provisions. The final text should nevertheless be closely monitored: the co-legislators may introduce additional harmonisation during negotiations.

What comes next?

The text now enters trilogue negotiations between the European Parliament and the Council. It may be amended before adoption. Under the Commission's proposal, the Regulation enters into force twenty days after publication in the Official Journal and applies two years thereafter. The existing framework remains in force throughout the transition period.

The following recommendations apply to companies operating in or seeking access to the Belgian and broader EU public procurement market.

  • First, the BPQR is the default award method, with quality criteria accounting for at least 30% of the assessment — 50% for labour-intensive contracts. Companies must be able to demonstrate quality, sustainability, and innovation credentials in their tenders. Those that cannot will be structurally disadvantaged.
  • Second, the new optional exclusion ground for insufficient reliability to exclude security or public safety risks is a direct threat to companies with third-country ownership or control, even where formally established in the Union. Governance and ownership structures should be audited now. Where exposure is identified, structural or contractual measures should be considered before the Regulation applies.
  • Third, the final text may introduce mandatory European preference requirements in specific sectors. The legislative negotiations should be tracked closely. The outcome could materially alter competitive dynamics in markets where companies currently operate alongside non-covered operators.
  • Fourth, companies supplying ICT products, components, or services to the public sector face a binary risk: designation as a high-risk supplier under CSA2 triggers mandatory exclusion from any procurement involving the relevant ICT components, with no self-cleaning available. Exposure must be assessed now.
  • Fifth, full subcontracting of a public contract is prohibited, as is further full subcontracting down the chain. Disclosure of proposed subcontractors and their share of performance is mandatory for public works contracts, contracts involving security or public safety risks, and contracts subject to European preference requirements. Companies relying on subcontracting arrangements must review their delivery models and adapt their tendering and contract management practices before the Regulation applies.

Non-EU companies face a distinct set of risks. Indeed, the Regulation does not introduce a general ban on non-covered operator participation. It equips public buyers with a toolbox of optional preference mechanisms that may, if activated, restrict or disadvantage participation in specific procedures. Non-covered operators must assess, on a procedure-by-procedure basis, whether European preference requirements have been activated and what their practical impact on eligibility and evaluation will be. In addition, non-EU companies accessing the Belgian and EU procurement markets through Union-established subsidiaries must verify that those subsidiaries satisfy the origin criteria under Article 74(1) of the proposed Regulation. They must also assess whether their ownership or control structure may give rise to exclusion on security grounds under Article 26(1)(g). EU establishment alone is not sufficient protection.

Authors:

  • Kevin Munungu, Senior Associate at Bird & Bird
dotted_texture