Cyber Tenders

See open cyber tenders and awarded contracts for the UK public sector.

This page covers the assessment and assurance end of public sector cyber buying: Cyber Assessment Framework audits, GovAssure reviews, cyber maturity assessments and Cyber Essentials certification work. 171 notices match on record, and 104 of those are awards.

It is consultancy, not product. Individual contracts are small and they recur, and some of the awards arrive as G-Cloud call offs rather than open competitions, which is why the awarded pile here is so much bigger than the open one.

165 results

Showing 21–40 of 165 results

Frequently asked questions

Frequently asked questions about cyber assessment framework, cyber security assurance, cyber security assessment, cyber security audit, cyber maturity, cyber security certification, cyber essentials assessment in the UK public sector.

  • How do I win public sector cyber assessment contracts?

    Two routes. Watch the portals for a live tender, or get in earlier. Most of this work is bought through frameworks and call offs, so the notice you see is often the award rather than the opportunity. On Stotles you can read a buyer's strategy papers, board minutes and budget files, spot the assurance programme before it turns into a tender, and be on the shortlist when it does. Platform-wide there are 2,198 tenders open right now across 100+ portals.

  • What is the difference between Cyber Essentials and the Cyber Assessment Framework?

    Cyber Essentials is a certification. A buyer either self-assesses against it or pays for the Plus version, which is checked by an assessor, and public bodies also buy help getting through it. The Cyber Assessment Framework is the National Cyber Security Centre's framework that organisations are measured against under a government profile, and the notices for it usually ask for an independent audit of a self-assessment the buyer has already done. In procurement terms they are different purchases: one is a certificate, the other is an audit engagement.

  • Why do so many tenders mention Cyber Essentials without being cyber contracts?

    Because it has become standard eligibility boilerplate. Search the bare phrase across the corpus and 1,141 notices come back, covering brickwork, roofing, underfloor heating and address matching, because buyers list the certificate, usually next to an information security management standard, as something bidders must hold. The filter behind this page deliberately drops that phrase and keeps the assessment and audit wording instead, which brings it down to 171 notices that are actually buying cyber work.

  • What CPV codes are used for cyber assessment and audit tenders?

    The two that fit best are 72800000 (Computer audit and testing services) and 72810000 (Computer audit services). Plenty of these notices carry only a broad code such as 72222300 (Information technology services), and some carry no code at all, which is why this page filters on wording rather than on CPV. Codes are useful for sense-checking a notice, less useful for finding one.

  • How much cyber assessment work is out there right now?

    Less open than you might expect. Of the 171 matching notices on record, 104 are awards and only a handful are sitting open at any moment, because the buying happens through framework call offs and mini-competitions that never appear as an open tender. That makes the award history the useful part. It tells you which buyers reassess on a cycle, and roughly when they are due again. Platform-wide, 0 notices were added in the last seven days.

Win more Cyber Tenders contracts with Stotles

Get Cyber Tenders alerts, buyer intelligence and bid tools, all in one place.