Cyber Tenders
See open cyber tenders and awarded contracts for the UK public sector.
This page covers the assessment and assurance end of public sector cyber buying: Cyber Assessment Framework audits, GovAssure reviews, cyber maturity assessments and Cyber Essentials certification work. 171 notices match on record, and 104 of those are awards.
It is consultancy, not product. Individual contracts are small and they recur, and some of the awards arrive as G-Cloud call offs rather than open competitions, which is why the awarded pile here is so much bigger than the open one.
165 results
- Stale Pre-tenderPublished 2 December 2022
GSCIP Knowledge Graph
- Closed tenderPublished 2 December 2022
GSCIP Data Sets
- Stale Pre-tenderPublished 2 December 2022
GSCIP Data analysis and visualisation tools
- Stale Pre-tenderPublished 2 December 2022
GSCIP Data Sets
- Closed tenderPublished 25 November 2022
GB-London: 103349 Cyber Skills Heatmap
- Awarded contract
Cyber Security Criticalities Assessment Service
- Expired contract
ICT: Cyber Security: Arculus Delivery Partner
- Closed tenderPublished 28 July 2022
Cyber Security Criticalities Assessment Service
- Closed tenderPublished 13 June 2022
Scottish National Investment Bank - Investment Management System
- Expired contract
TEN-2122-023 Cyber-Security Assessment
- Expired contract
KPMG Cyber Security Assessment
- Expired contract
UK SBS - PS21262 - Provision of Services to Review the Smart Energy Metering Device Cyber Security Assurance
- Expired contract
UKHSA - SH - Cyber Security Assurance
- Expired contract
Cyber Maturity Assessment and Diagnostics for Plasma
- Expired contract
Cyber Security Assessment
- Expired contract
Cyber Security Assurance Report
- Expired contract
Cyber Security Assurance Management for Cloud Service
- Awarded contract
Specialist IT Support Services
- Closed tenderPublished 11 August 2021
HS2 C1 ALIGN JV - Mechanical and Electrical Installations at the 5 Shafts / Headhouses and 2 Tunnel Portal Buildings
- Expired contract
Network Cyber Security Assessment Programme Demonstrator SIRA, SECURITY ARCHITECTURE and CIS 20 CONTROLS REVIEW
Frequently asked questions
Frequently asked questions about cyber assessment framework, cyber security assurance, cyber security assessment, cyber security audit, cyber maturity, cyber security certification, cyber essentials assessment in the UK public sector.
How do I win public sector cyber assessment contracts?
Two routes. Watch the portals for a live tender, or get in earlier. Most of this work is bought through frameworks and call offs, so the notice you see is often the award rather than the opportunity. On Stotles you can read a buyer's strategy papers, board minutes and budget files, spot the assurance programme before it turns into a tender, and be on the shortlist when it does. Platform-wide there are 2,148 tenders open right now across 100+ portals.
What is the difference between Cyber Essentials and the Cyber Assessment Framework?
Cyber Essentials is a certification. A buyer either self-assesses against it or pays for the Plus version, which is checked by an assessor, and public bodies also buy help getting through it. The Cyber Assessment Framework is the National Cyber Security Centre's framework that organisations are measured against under a government profile, and the notices for it usually ask for an independent audit of a self-assessment the buyer has already done. In procurement terms they are different purchases: one is a certificate, the other is an audit engagement.
Why do so many tenders mention Cyber Essentials without being cyber contracts?
Because it has become standard eligibility boilerplate. Search the bare phrase across the corpus and 1,141 notices come back, covering brickwork, roofing, underfloor heating and address matching, because buyers list the certificate, usually next to an information security management standard, as something bidders must hold. The filter behind this page deliberately drops that phrase and keeps the assessment and audit wording instead, which brings it down to 171 notices that are actually buying cyber work.
What CPV codes are used for cyber assessment and audit tenders?
The two that fit best are 72800000 (Computer audit and testing services) and 72810000 (Computer audit services). Plenty of these notices carry only a broad code such as 72222300 (Information technology services), and some carry no code at all, which is why this page filters on wording rather than on CPV. Codes are useful for sense-checking a notice, less useful for finding one.
How much cyber assessment work is out there right now?
Less open than you might expect. Of the 171 matching notices on record, 104 are awards and only a handful are sitting open at any moment, because the buying happens through framework call offs and mini-competitions that never appear as an open tender. That makes the award history the useful part. It tells you which buyers reassess on a cycle, and roughly when they are due again. Platform-wide, 2 notices were added in the last seven days.
Win more Cyber Tenders contracts with Stotles
Get Cyber Tenders alerts, buyer intelligence and bid tools, all in one place.
