Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Um comando direto ignora o prompt de revisão. Verifique a origem antes de executá-lo.
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified DPO / RSSI / legal counsel before reliance. Citations to ANSSI / CNIL / EU regulations may lag the current text — verify against the source.
You are helping an enterprise architect generate French public procurement documentation (Dossier de Consultation des Entreprises) aligned with the Code de la Commande Publique, UGAP, and DINUM digital doctrine requirements.
User Input
$ARGUMENTS
Instructions
Note: Before generating, scan projects/ for existing project directories. For each project, list all ARC-*.md artifacts, check external/ for reference documents, and check 000-global/ for cross-project policies. If no external docs exist but they would improve output, ask the user.
Step 0: Read existing artifacts from the project context
MANDATORY (warn if missing):
REQ (Requirements) — Extract: functional requirements (FR-xxx) for procurement scope, non-functional requirements (NFR-xxx), integration requirements (INT-xxx), data sovereignty and security requirements
If missing: warn that procurement documentation requires defined requirements to produce a valid requirements statement
Section 7: ANSSI-Qualified Security Provider Selection
If the procurement includes cybersecurity services (audit, incident response, SOC/detection), include selection criteria requiring ANSSI qualification:
ANSSI Qualification
Scope
When to Require
PASSI (Prestataires d'Audit de Sécurité des SI)
Penetration testing, technical audits
Any IS security audit or pentest
PRIS (Prestataires de Réponse aux Incidents de Sécurité)
Incident response, forensics
IR retainer or OIV/OSE obligation
PDIS (Prestataires de Détection des Incidents de Sécurité)
SOC, threat detection, SIEM management
Managed detection services
PDCS (Prestataires de Cybersécurité pour les Collectivités)
Local authority-specific cybersecurity
Collectivités territoriales only
For OIV/OSE systems: require PASSI qualification for any IS audit; PRIS for incident response services — both are mandatory under the sectoral arrêté or NIS2 obligations
Include qualification requirement in the technical specifications (CCTP), not just as selection criterion
Qualification lists are published on ssi.gouv.fr — advise buyers to verify currency at contract signature
ANSSI qualifications are not certifications: they require reassessment — confirm current validity in tender evaluation
Section 8: Digital State Doctrine Compliance
DINUM checklist: cloud-first, RGI, RGAA, RGESN, open source, GDPR/DPA
PSSIE and RGS target level
Cross-reference DINUM artifact conclusions if available
Before writing the file, read .arckit/references/quality-checklist.md and verify all Common Checks pass.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ Procurement File Generated
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📄 Document: projects/{project_id}/ARC-{PROJECT_ID}-MARPUB-v{VERSION}.md
📋 Document ID: {document_id}
📅 Created: {date}
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📋 Procurement Parameters
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Estimated Value: {amount}
Applicable Threshold: {threshold}
Recommended Procedure: {procedure}
BOAMP Publication: {Yes / No}
JOUE Publication: {Yes / No}
Min. Consultation Period: {X days}
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🛡️ Mandatory Clauses Included
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ Security annex (RGS v2.0, PSSIE)
✅ Data localisation clause (EU territory)
✅ Reversibility clause (DINUM standards)
{✅ GDPR/DPA clause (personal data detected)}
{✅ HDS certification clause (health data detected)}
{✅ SecNumCloud clause (sensitive data + cloud)}
{✅ Open source clause (if applicable)}
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📦 Requirements Linked
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
{N} functional requirements extracted
{N} technical requirements (NFR-xxx) included
Next steps:
1. Review and complete UGAP catalogue references (ugap.fr)
2. Legal team validation of contract clauses
3. {If tenders received: Run $arckit-evaluate for scoring}
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Important Notes
Threshold accuracy: The estimated contract value must exclude VAT (hors taxes). Include all option periods in the estimate — the total lifetime value determines the applicable threshold.
UGAP catalogue: UGAP framework references must be verified at ugap.fr before use in official procurement — agreements are updated regularly.
Legal validation: This document generates a draft procurement file. It must be reviewed by the contracting authority's legal team and procurement officer before publication.
Cloud Act clause: The data localisation clause explicitly addresses extraterritorial laws (Cloud Act, FISA). This is a DINUM requirement for any cloud procurement involving sensitive data.
Use Write Tool: Procurement files are typically 3,000–6,000 words. Always use the Write tool.
Note for reviewers: French public procurement is governed by the Code de la commande publique (transposing EU Directives 2014/24 and 2014/25). UGAP is a French central purchasing body — pre-competed framework agreements that public buyers can call off without running a full tender. BOAMP is the mandatory French publication journal for procurement notices above €40,000 (JOUE/TED required above EU thresholds). PASSI, PRIS, and PDIS are ANSSI qualification schemes for security service providers — requiring PASSI-qualified auditors and PRIS-qualified incident responders is mandatory for OIV and recommended for all sensitive IS.
Success Criteria
✅ Procurement document created at projects/{project_id}/ARC-{PROJECT_ID}-MARPUB-v{VERSION}.md
✅ Threshold analysis completed with recommended procedure
✅ BOAMP/JOUE publication requirements determined
✅ Requirements statement linked to REQ artifact (FR-xxx, NFR-xxx)
✅ Sovereignty and security requirements table populated
✅ Award criteria with weighting defined (total = 100%)
✅ Security and sovereignty clauses included (data localisation, reversibility, GDPR/DPA)
✅ HDS clause included if health data detected
✅ SecNumCloud clause included if sensitive data and cloud
✅ UGAP catalogue guidance provided
✅ Indicative timeline Gantt chart generated
✅ DINUM digital doctrine checklist completed
Example Usage
$arckit-fr-marche-public Generate procurement documentation for a digital identity platform for a French ministry, estimated value €2.5M, handling personal data, requires SecNumCloud, RGAA compliance mandatory
$arckit-fr-marche-public Procurement file for 001 — cybersecurity services contract, €800K, MAPA procedure, existing UGAP framework available
$arckit-fr-marche-public Create procurement file for a French regional health authority digital platform, health data in scope, HDS certification required, estimated €3.5M over 3 years
Suggested Next Steps
After completing this command, consider running:
$arckit-evaluate -- Score vendor responses against the award criteria defined in this document (when Tenders received and ready for evaluation)
$arckit-traceability -- Link procurement requirements back to functional and non-functional requirements