Cyber Security Services 3

A flexible commercial agreement that offers an extensive range of cyber security services to help improve organisational cyber resilience and security posture. This dynamic purchasing system (DPS) is available to all UK central government departments, wider public sector organisations and charities. The services available fall under the following categories: NCSC assured services consultancy and advice penetration testing incident response managed security services The DPS allows you to shortlist suppliers based on your needs using a range of filters. Once you have established your shortlist you can use this to run a further competition.

Timeline

  1. Contract start date14 February 2020
  2. Tender published20 December 2022
  3. Submission date11 February 2029in 2 years
  4. Contract expiry date13 February 2029

Lots (1)

0 suppliers across 1 lots

CYBER SECURITY SERVICES 3

Call-offs from Cyber Security Services 3

Awarded contracts called off from this framework agreement.

Showing 24 of 68 call-offs

Book a call to see every call-off, supplier and buyer on this framework.

Framework analysis

Buyers and suppliers active on the Cyber Security Services 3 framework, ranked by contract award volume.

Top suppliers associated with Cyber Security Services 3

Suppliers ranked by total contract award volume through Cyber Security Services 3.

Top buyers associated with Cyber Security Services 3

Buyers ranked by total contract award volume through Cyber Security Services 3.

Frequently asked questions

Frequently asked questions about the Cyber Security Services 3 framework.

  • What is the Cyber Security Services 3 DPS?

    A Crown Commercial Service dynamic purchasing system for buying cyber security services. Buyers filter a pool of pre-qualified suppliers, shortlist against their needs, and run a further competition. Suppliers apply once, meet the standards, and stay available to be invited. It moved to the Government Commercial Agency on 1 April 2026.

  • What can I buy through it?

    NCSC assured services, consultancy and advice, penetration testing, incident response, data destruction and IT sanitisation, managed security services, and encryption (IP Crypto). Buyers narrow the supplier pool using filters for certification, service type, standards and sector experience.

  • Is it a framework or a DPS, and why does that matter?

    It is a DPS. The supplier pool stays open, so new suppliers can join at any point in the term. There is no direct award. Every purchase runs through a further competition among shortlisted suppliers.

  • When did it start and when does it end?

    It went live on 14 February 2020 for an initial 60-month term. It was extended to 13 February 2029, confirmed in the extension notice published on 12 August 2025.

  • How long can a Cyber Security Services 3 contract run?

    Call-offs run for up to 5 years. Against the current end date, that puts the latest possible call-off expiry in early 2034.

  • What does it cost to use?

    There is no charge to register, and suppliers submit no pricing to join. Price is set at further competition and scored alongside quality, with quality typically weighted 60 to 90 percent and price 10 to 40 percent.

  • Where can I find the supplier list?

    On the DPS Marketplace appointed-suppliers page for RM3764.3. Buyers filter and export a shortlist, valid for 2 working days from creation because new suppliers join continuously.

  • How do I win business on it?

    Being on the DPS makes you eligible, not chosen. Buyers shortlist by filter, sometimes run a capability assessment, then invite shortlisted suppliers to a further competition scored on quality and price. Suppliers who track expiring contracts and engage buyers before requirements return to market are better placed.

  • How big is the market?

    The DPS has an estimated total value of £800m, and buyers have awarded around £153.0m through it so far. For wider context, the 2021 Spending Review committed £2.6bn to cyber security and legacy IT modernisation across 2022 to 2025.

  • What is changing next?

    A fourth iteration, RM3764.4 Cyber Security 4, is in design. The Government Commercial Agency confirmed on 15 July 2026 that it is running buyer and supplier market engagement for the successor agreement.

Ready to get started?

From first signal to bid submission, Stotles turns procurement chaos into predictable pipeline.