Estonia orders a code audit of its e-voting system
Estonia's Information System Authority has gone to market for a code audit of the national e-voting system: a €155,000, five-month engagement published on 29 September. The stated aim is assurance that the code is written to best practice and is "fit for publication", and that the application actually does what its documentation says. Estonia is the only country that offers internet voting to its entire electorate in national elections, and the calendar is tight: online voting for the March 2027 parliamentary election opens on 1 March, and by law the source code must be published before the test vote in February.
Publication is the sore point. Last October the Supreme Court found the electoral office had acted unlawfully by failing to publish the source code before the 2025 trial vote, while also finding the votes could not have been manipulated. The code itself has been public in some form since 2013, and on GitHub since 2017.
The team the authority wants is specific: an architect at home in C++ codebases, a certified cybersecurity expert versed in OWASP's application and mobile standards, and a cryptography specialist with experience analysing zero-knowledge-proof and elliptic-curve implementations. What exactly they will audit is less public. The technical specification goes only to shortlisted candidates who sign a confidentiality declaration carrying a €20,000 penalty per breach, and the draft contract forbids feeding the authority's confidential material into AI tools.
The system has been scrutinised before: a ministry-commissioned security audit reported in 2022, and the state Academy of Sciences ran a risk analysis in 2024. This is, however, the first stand-alone code audit of the e-voting system in our data, and the notice has drawn no press coverage. Requests to participate are due 29 October.
Source: original notice · Estonian translated (machine-assisted)