EU proposes Public Procurement Act consolidating directives and amending regulations

Original title: Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on public contracts and concessions, repealing Directives 2014/23/EU, 2014/24/EU and 2014/25/EU, and amending Regulations (EC) N

The European Commission proposes a new Public Procurement Act that consolidates the three 2014 procurement directives (2014/23/EU, 2014/24/EU, and 2014/25/EU) into a single regulation and amends multiple EU regulations and directives. This reform aims to modernize public procurement rules and strengthen their alignment with recent EU legislation, including cybersecurity requirements under the Cyber Resilience Act and sustainability standards. Entities conducting public procurement will need to comply with updated requirements that integrate horizontal cybersecurity standards for products with digital elements.

What changed

  • Consolidation of three separate procurement directives (2014/23/EU, 2014/24/EU, 2014/25/EU) into a single Public Procurement Regulation, replacing the previous directive-based framework with a binding regulation that applies directly across Member States.
  • Integration of cybersecurity requirements from the Cyber Resilience Act (Regulation EU 2024/2847) into public procurement rules, requiring contracting authorities to apply horizontal cybersecurity standards when procuring products with digital elements.
  • Amendments to Regulations (EC) No 1370/2007, (EU) 2023/1542, (EU) 2024/1157, (EU) 2024/1252, (EU) 2024/1735, (EU) 2024/1781, (EU) 2024/2847, (EU) 2024/3110 and (EU) 2025/40 to ensure alignment with the new public procurement framework and horizontal policy objectives.
  • Amendments to Directives 2008/98/EC, (EU) 2019/882, (EU) 2022/2381, (EU) 2023/1791 and (EU) 2024/1760 to coordinate waste, accessibility, corporate sustainability, energy labelling and anti-greenwashing requirements with public procurement obligations.
  • Modernization of public procurement procedures and criteria to better reflect EU priorities on cybersecurity, sustainability, and circular economy principles.

Who is affected

Contracting authorities (public bodies and entities) conducting public procurement across the EU; suppliers and bidders on public contracts; manufacturers of products with digital elements; entities subject to both procurement and cybersecurity regulations; all Member States responsible for implementing and enforcing the new regulation.

Summary generated by a language model; the official text prevails. Not legal advice.