Cyber Tenders
See open cyber tenders and awarded contracts for the UK public sector.
This page covers the assessment and assurance end of public sector cyber buying: Cyber Assessment Framework audits, GovAssure reviews, cyber maturity assessments and Cyber Essentials certification work. 171 notices match on record, and 104 of those are awards.
It is consultancy, not product. Individual contracts are small and they recur, and some of the awards arrive as G-Cloud call offs rather than open competitions, which is why the awarded pile here is so much bigger than the open one.
165 results
- Expired contract
PS25351 - Cyber Assessment Framework
- Expired contract
Interoperability Assurance as a Service Continuation
- Awarded contract
Cyber Assessment Framework (CAF) Assurance for Local Authorities (Interim)
- Expired contract
Independant GovAssure Assessment review
- Awarded contract
Wavenet Cyber Security Assessment Services
- Expired contract
Provision of Cyber Security Assessment (GovAssure)
- Awarded contract
Provision of Gov Assure 2025
- Stale Pre-tenderPublished 19 November 2025
Harwich Office Upgrades - HVAC
- Closed tenderPublished 11 November 2025
PHW-MIN-61111 - All-Wales Sexual Health Case Management System Alpha phase
- Awarded contract
PHW-MIN-61111 - All-Wales Sexual Health Case Management System Alpha phase
- Stale Pre-tenderPublished 7 November 2025
T25/0018 – Smart Card & Identity Management
- Awarded contract
Cyber Security Support
- Closed tenderPublished 3 October 2025
Digital Transformation Solutions and Enterprise Services
- Awarded contract
Risk and Compliance Management Platform
- Closed tenderPublished 28 August 2025
W201511 [Pre - Procurement] Cyber Security Tooling and Capabilities
- Awarded contract
Cyber Security Assurance Services Framework
- Expired contract
Provision of Continued Targeted Cyber Security Assurance
- Expired contract
Chief Information Security Officer and Cyber Programme Manager
- Closed tenderPublished 11 July 2025
T126 Cyber Assured Audit
- Stale Pre-tenderPublished 7 July 2025
Network and Information Security (NIS) Audit Services for HSCNI
Frequently asked questions
Frequently asked questions about cyber assessment framework, cyber security assurance, cyber security assessment, cyber security audit, cyber maturity, cyber security certification, cyber essentials assessment in the UK public sector.
How do I win public sector cyber assessment contracts?
Two routes. Watch the portals for a live tender, or get in earlier. Most of this work is bought through frameworks and call offs, so the notice you see is often the award rather than the opportunity. On Stotles you can read a buyer's strategy papers, board minutes and budget files, spot the assurance programme before it turns into a tender, and be on the shortlist when it does. Platform-wide there are 2,198 tenders open right now across 100+ portals.
What is the difference between Cyber Essentials and the Cyber Assessment Framework?
Cyber Essentials is a certification. A buyer either self-assesses against it or pays for the Plus version, which is checked by an assessor, and public bodies also buy help getting through it. The Cyber Assessment Framework is the National Cyber Security Centre's framework that organisations are measured against under a government profile, and the notices for it usually ask for an independent audit of a self-assessment the buyer has already done. In procurement terms they are different purchases: one is a certificate, the other is an audit engagement.
Why do so many tenders mention Cyber Essentials without being cyber contracts?
Because it has become standard eligibility boilerplate. Search the bare phrase across the corpus and 1,141 notices come back, covering brickwork, roofing, underfloor heating and address matching, because buyers list the certificate, usually next to an information security management standard, as something bidders must hold. The filter behind this page deliberately drops that phrase and keeps the assessment and audit wording instead, which brings it down to 171 notices that are actually buying cyber work.
What CPV codes are used for cyber assessment and audit tenders?
The two that fit best are 72800000 (Computer audit and testing services) and 72810000 (Computer audit services). Plenty of these notices carry only a broad code such as 72222300 (Information technology services), and some carry no code at all, which is why this page filters on wording rather than on CPV. Codes are useful for sense-checking a notice, less useful for finding one.
How much cyber assessment work is out there right now?
Less open than you might expect. Of the 171 matching notices on record, 104 are awards and only a handful are sitting open at any moment, because the buying happens through framework call offs and mini-competitions that never appear as an open tender. That makes the award history the useful part. It tells you which buyers reassess on a cycle, and roughly when they are due again. Platform-wide, 0 notices were added in the last seven days.
Win more Cyber Tenders contracts with Stotles
Get Cyber Tenders alerts, buyer intelligence and bid tools, all in one place.
