Cyber Security Services 3
A flexible commercial agreement that offers an extensive range of cyber security services to help improve organisational cyber resilience and security posture. This dynamic purchasing system (DPS) is available to all UK central government departments, wider public sector organisations and charities. The services available fall under the following categories: NCSC assured services consultancy and advice penetration testing incident response managed security services The DPS allows you to shortlist suppliers based on your needs using a range of filters. Once you have established your shortlist you can use this to run a further competition.
Timeline
- Contract start date14 February 2020
- Tender published20 December 2022
- Submission date11 February 2029in 2 years
- Contract expiry date13 February 2029
Lots (1)
0 suppliers across 1 lots
Call-offs from Cyber Security Services 3
Awarded contracts called off from this framework agreement.
- Awarded contract
DDaT26188 - CHECK Pen Testing (ITHC)
- Expired contract
PS26079 - Cyber Assurance Review for i.AI Platform
- Expired contract
PS26016 - The Provision of Third Party Inspections
- Awarded contract
Provision of Cyber Incident Response Provider
- Closed tender
DHSC: ARP: ITHC (Programme Estate)
- Awarded contract
Provision of Cyber Incident Response Provider
- Awarded contract
DDaT25591 - UKSBS Security Operations Center
- Awarded contract
Cyber Incident Response Partner Service
- Expired contract
PS25364 - GovAssure Assessment
- Awarded contract
Cybersecurity Managed Services
- Awarded contract
Corporate Estate IT Health Check
- Awarded contract
IT Penetration Testing & Health check services
- Awarded contract
Provision of Vulnerability Reporting Service Triage
- Closed tender
Cybersecurity Managed Services
- Expired contract
PS25351 - Cyber Assessment Framework
- Awarded contract
Enhanced Cyber Security Operations Centre
- Awarded contract
Automated Data Classification
- Stale Pre-tender
DSA Cyber Security
- Awarded contract
252 - cyber security tender
- Expired contract
UKSAC25_0074 - Cyber Security Consultancy
- Stale Pre-tender
Cyber Incident Response Partner Service
- Awarded contract
Cyber Security Services 3
- Expired contract
Local Government Cyber Incident Reponse
- Awarded contract
Local Government Cyber Incident Reponse
Framework analysis
Buyers and suppliers active on the Cyber Security Services 3 framework, ranked by contract award volume.
Top suppliers associated with Cyber Security Services 3
Suppliers ranked by total contract award volume through Cyber Security Services 3.
- 6£6.2m
- 6£18.9m
- 6£1.2m
- 3£3.3m
- 2£207.0k
- 2£543.6k
- 2£119.5k
- 2£19.8m
- 2£159.5k
- 2£2.5m
- 1£65.9k
- 1£728.9k
Top buyers associated with Cyber Security Services 3
Buyers ranked by total contract award volume through Cyber Security Services 3.
- 9£842.4k
- 5£1.1m
- 4£8.3m
- 4£293.3k
- 4£256.8k
- 3£801.7m
- 3£1.2m
- 3£39.5m
- 3£1.5m
- Department for Business Energy and Industrial Strategy (BEIS)2£162.0k
- 2£4.5m
- 2£610.0k
Frequently asked questions
Frequently asked questions about the Cyber Security Services 3 framework.
What is the Cyber Security Services 3 DPS?
A Crown Commercial Service dynamic purchasing system for buying cyber security services. Buyers filter a pool of pre-qualified suppliers, shortlist against their needs, and run a further competition. Suppliers apply once, meet the standards, and stay available to be invited. It moved to the Government Commercial Agency on 1 April 2026.
What can I buy through it?
NCSC assured services, consultancy and advice, penetration testing, incident response, data destruction and IT sanitisation, managed security services, and encryption (IP Crypto). Buyers narrow the supplier pool using filters for certification, service type, standards and sector experience.
Is it a framework or a DPS, and why does that matter?
It is a DPS. The supplier pool stays open, so new suppliers can join at any point in the term. There is no direct award. Every purchase runs through a further competition among shortlisted suppliers.
When did it start and when does it end?
It went live on 14 February 2020 for an initial 60-month term. It was extended to 13 February 2029, confirmed in the extension notice published on 12 August 2025.
How long can a Cyber Security Services 3 contract run?
Call-offs run for up to 5 years. Against the current end date, that puts the latest possible call-off expiry in early 2034.
What does it cost to use?
There is no charge to register, and suppliers submit no pricing to join. Price is set at further competition and scored alongside quality, with quality typically weighted 60 to 90 percent and price 10 to 40 percent.
Where can I find the supplier list?
On the DPS Marketplace appointed-suppliers page for RM3764.3. Buyers filter and export a shortlist, valid for 2 working days from creation because new suppliers join continuously.
How do I win business on it?
Being on the DPS makes you eligible, not chosen. Buyers shortlist by filter, sometimes run a capability assessment, then invite shortlisted suppliers to a further competition scored on quality and price. Suppliers who track expiring contracts and engage buyers before requirements return to market are better placed.
How big is the market?
The DPS has an estimated total value of £800m, and buyers have awarded around £153.0m through it so far. For wider context, the 2021 Spending Review committed £2.6bn to cyber security and legacy IT modernisation across 2022 to 2025.
What is changing next?
A fourth iteration, RM3764.4 Cyber Security 4, is in design. The Government Commercial Agency confirmed on 15 July 2026 that it is running buyer and supplier market engagement for the successor agreement.
Ready to get started?
From first signal to bid submission, Stotles turns procurement chaos into predictable pipeline.
