TenderCodes .eu

Guide

Common CPV Code Mistakes in IT Procurement

Common CPV Code Mistakes in IT Procurement

Pick the wrong CPV code on an IT notice and two things happen at once: the suppliers who could do the work never see it, and the suppliers who can't do the work flood your inbox. Both sides lose. This guide walks through the IT-code mix-ups we see most often, using the real "commonly confused" pairs our reviewers flagged while documenting the 72 and 48 software branches.

The pattern under almost all of them is the same. The 48 branch is the product you buy. The 72 branch is the service you commission. Get that one axis right and most of the rest falls into place.

On this page

Why the wrong code costs you

A CPV code is not a label you slap on at the end. It is the routing key for the whole procurement. Suppliers set tender alerts by code. Aggregators index by code. Our own per-code subscriptions fire by code. If the code on the notice does not match the work, the notice goes to the wrong audience.

Three concrete failure modes follow from a wrong code.

You miss the right bidders. A development shop watching the 72212 development codes will never see your contract if you filed it under a 48 software-package code. Fewer bids mean less price competition, which is the opposite of what the procurement rules are there to produce.

You attract the wrong ones. File a bespoke build under a packaged-software code and you get resellers quoting licence prices for software that does not exist yet. Someone on your side then reads, scores, and rejects every one of them. That review time is real money.

You raise a challenge risk. Misclassification can support a challenge where it undermines transparency or distorts the publication threshold. If a losing bidder argues the code steered the notice away from qualified firms, or pushed it under the wrong publication threshold, you can end up defending the classification rather than the award. The European Commission's own guidance treats the CPV code as part of how a contract is defined and advertised, not as decoration.

How common is this? Hard data on misclassification rates across the EU is thin, and any single figure should be treated with caution. What we can show is the size of the prize. In our copy of TED award data (2009-2026), the 48 software-package family and the IT-services branch under Programming services of application software together carry tens of thousands of awards. Sorting your contract into the right one of those is the difference between a competitive field and a quiet inbox.

Mistake 1: buying a package when you mean a build (48 vs 72212)

This is the single most common IT mix-up, and it is the one our reviewers flagged on nearly every software page. The 48 branch and the matching 72212 branch use almost identical words. The difference is whether you are buying a finished product or paying someone to build one.

Read the two titles side by side and the trap is obvious. "Medical software package" and "Medical software development services" describe completely different contracts. One is a licence for software that exists. The other is a team writing software that does not exist yet.

You are buying a finished product (48) You are commissioning a build (72212) Medical software package Medical software development services Educational software package Educational software development services Content management software package Content management software development services Data security software package Data security software development services Inventory management software package Inventory management software development services

The test is one question: does the thing you want already exist as a product you could licence today?

If yes, you are buying a package. A hospital that wants to licence an established clinical records product files under the medical software package code Medical software package. If no, and you need it written or substantially adapted to your specification, you file under the development code Medical software development services.

The data shows how lopsided this gets. In TED award data 2009-2026, the medical software package code Medical software package carries 1,437 awards (median contract value about €249k), while its development twin Medical software development services carries 194. The educational pair runs the same way: Educational software package with 699 awards against Educational software development services at 252. Most authorities buy the package. The ones who file a build under the package code are the ones whose specialist developers never get the alert.

A real shape of this: a regional school authority writes a notice for a "new assessment platform built to our curriculum rules." That is a build. It belongs under Educational software development services. Filed under the package code, it draws licence quotes for off-the-shelf learning tools that cannot meet the curriculum-specific rules, and the dev shops that could write it never look.

Mistake 2: development, implementation, supply, support, maintenance

The 72 services branch splits the software lifecycle into separate codes, and they get used interchangeably when they should not be. Five of them sit close enough to trip people up. Each describes a different stage and a different supplier.

Software development services is building the software from your requirements. Software implementation services is standing up and configuring software whose core already exists. Software supply services is obtaining the licences and the product. Software support services answers questions and resolves incidents on software in use. Software maintenance and repair services patches, upgrades, and changes the code over time.

Why it matters: these attract different firms with different cost structures. A build is priced by the day and won by a development team. Maintenance is priced as an annual fee and won by whoever knows the existing system. Supply is priced by the licence and won by a reseller. Put a multi-year maintenance contract under the development code and you invite firms quoting greenfield build rates for keep-the-lights-on work.

The volumes tell you where the public-sector money actually goes. In TED award data 2009-2026, Software maintenance and repair services is the heaviest of the five at 7,896 awards (median about €315k), ahead of Software development services at 3,777 and Software supply services at 3,836. Far more public IT spend keeps existing systems running than builds new ones. If you are a supplier and you only watch the development code, you are watching the smallest slice.

The cleanest way to separate them: ask what the supplier hands over. New code written to your spec is Software development services. A running, configured instance of something that already existed is Software implementation services. Continued patches and fixes after go-live is Software maintenance and repair services.

Mistake 3: the web-work triad

Three web codes get swapped constantly because all three touch "a website." They are not interchangeable. The boundary is the verb: design it, host it, or buy the box it runs on.

World wide web (www) site design services is the design and build that produces a site. World wide web (www) site operation host services is running and hosting a site that already exists. Confusing these two is the most frequent web mistake we see.

The honest call: most web contracts bundle a bit of both. You commission a redesign and a year of hosting in one notice. When that happens, pick the code for the deliverable that dominates the budget and the scope. If the contract is mostly a build with hosting as a tail, use World wide web (www) site design services. If it is mostly running an existing site with minor tweaks, use World wide web (www) site operation host services.

In TED award data 2009-2026, the design code World wide web (www) site design services carries 1,229 awards (median about €226k) against 619 for the hosting code World wide web (www) site operation host services. France is the heaviest filer on both, which fits a market where small municipal site refreshes are common.

This is the one place I will hand you a flat opinion. If your contract genuinely bundles a build with ongoing hosting and you cannot tell which dominates, the design-and-build code is usually the safer primary, because it is the part with real supplier differentiation. Hosting is closer to a commodity. You want the alert to reach the firms competing on the part that varies.

Mistake 4: product vs system vs the service that runs it

Two finer traps live inside the 48 and 72 branches, and both come straight from the confused-code data.

First, product versus system within the 48 branch. Database software package is the packaged database product you licence. Database-management system leans toward the engine as deployed, run, and supported rather than bought off the shelf. The titles are nearly identical; the difference is whether you are handed a licence or a working system. If you are licensing a named database product, the package code fits. If the deliverable is a managed, running database capability, the management-system code is closer.

Second, the software versus the service that operates it. Document management system is the configured document system the authority runs itself. Document management services is the outsourced service of running document handling for you. One is a system you own and operate. The other is a service where the supplier does the document work. File an outsourced records-handling contract under the system code and you draw software vendors instead of service providers, and the firms that actually run document operations never see it.

The same product-versus-service line runs through the whole IT vocabulary. Software supply services supplies and licenses a product; the matching 48 code names the product itself. Whenever a 48 code and a 72 code look like near-synonyms, the 48 code is the thing and the 72 code is the doing.

A checklist to avoid all of this

Run a notice through these before you publish. Most IT misclassifications fail at the first question.

Product or service? If you are buying something that exists, look in the 48 branch. If you are paying for work, look in the 72 branch. This one split resolves the majority of IT mistakes.

Does it already exist? A package code (48) only fits software you could licence today. Anything written or substantially adapted to your spec belongs in development (72212 or Software development services).

What stage of the lifecycle? Build, implement, supply, support, and maintain are five different codes. Name the stage that dominates the contract value, then pick its code.

Who do you want to bid? Picture the firm that should win this. If your chosen code would not land in that firm's alert feed, you have the wrong code. This is the fastest sanity check there is.

What dominates the budget? When a contract bundles stages (build plus hosting, software plus maintenance), classify by the largest piece, and add an additional CPV code for the rest rather than picking a vague parent.

Is there a more specific child? A leaf code reaches a tighter audience than its parent. Drop to the most specific code that still honestly describes the work.

If you are a supplier rather than a contracting authority, invert the checklist. Subscribe to your obvious code plus its most-confused neighbours. The 48-package codes leak builds into 72212; the lifecycle codes leak into each other. A few extra alert emails cost you nothing. A missed contract costs you the contract.

Not sure which code the work even falls under? Start from the project description rather than the code tree. Our find a CPV code from a project description guide walks through that route. For the services side specifically, CPV 72000000: IT services explained maps the whole 72 branch, and the EU IT tenders complete guide covers the wider process around it.

What happens if I use the wrong CPV code?
The notice reaches the wrong suppliers. Firms that could do the work miss it, firms that cannot do it bid anyway, and a losing bidder can cite the misclassification as a ground for challenge. The award itself is rarely void over a code alone, but you can spend the process defending the classification instead of the decision.

How do I choose between CPV code 48 and 72?
Ask whether you are buying a product or commissioning a service. The 48 branch is packaged software and systems you licence or buy. The 72 branch is IT services: development, implementation, support, maintenance, hosting. If the thing already exists and you are licensing it, use 48. If you are paying for work, use 72.

Is "software development" the same code as "software package"?
No, and this is the most common IT mistake. Software development services is paying a team to build software. A 48 package code is licensing software that already exists. They reach different suppliers and are priced on different bases.

Can a contract have more than one CPV code?
Yes. Set one primary code for the dominant deliverable, then add additional CPV codes for the secondary parts. A build-plus-hosting contract can carry a development primary and a hosting code alongside it. The primary code is the one that drives publication and most supplier alerts, so choose it for the work that matters most.

How do I pick between development and maintenance?
Ask what the supplier hands over. New software written to your requirements is Software development services. Keeping an existing system patched, fixed, and current is Software maintenance and repair services. Most public IT money is in the second one, so do not default to the development code out of habit.

A note on how this guide is built

I built TenderCodes while running BrotCode, a Berlin Rails consultancy, and after bidding on EU IT contracts myself. The confusion pairs in this guide are not invented. They come from the reviewer notes our team wrote while documenting each code, cross-checked against TED award data. More on who I am and how the site is put together is on the about page. You can also find BrotCode on LinkedIn and me on LinkedIn.

Last reviewed

2026-06-13, Babar.

Watching a specific code? Find your code and set a per-code alert so the right notices come to you.