Cyber Tenders
See open cyber tenders and awarded contracts for the UK public sector.
This page covers the assessment and assurance end of public sector cyber buying: Cyber Assessment Framework audits, GovAssure reviews, cyber maturity assessments and Cyber Essentials certification work. 171 notices match on record, and 104 of those are awards.
It is consultancy, not product. Individual contracts are small and they recur, and some of the awards arrive as G-Cloud call offs rather than open competitions, which is why the awarded pile here is so much bigger than the open one.
165 results
- Closed tenderPublished 3 June 2021
Specialist IT Support Services
- Expired contract
Network Cyber Security Assessment Demonstrator CIS Controls
- Closed tenderPublished 5 January 2021
2 Cyber Security Specialists for DfT Security Improvement Project
- Expired contract
DS291-19 Protective Monitoring Software
- Closed tenderPublished 1 September 2020
Merlin Emergent Work 2020 to 2025
- Closed tenderPublished 3 August 2020
IRM19/7243 - Provision of a Direct Repair Scheme (DRS) In Support of Land Equipment
- Awarded contract
iHuxley Phase 2 (ASDT0111)
- Closed tenderPublished 28 May 2020
IT services: consulting, software development, Internet and support
- Closed tenderPublished 29 January 2020
iHuxley Phase 2 (ASDT0111)
- Expired contract
Accounting, auditing and fiscal services
- Closed tenderPublished 10 December 2019
GB-Bristol: Procurement of winch bridles
- Awarded contract
SOC Cyber Security Improvement Plan
- Expired contract
Cyber Maturity Assessment & Improvement
- Expired contract
CR19056 - Cyber Assessment Framework Analysis - Energy Sector
- Closed tenderPublished 25 October 2019
RIIO-2 Cyber Security submissions review - Role 2 - Project PMO Support/Analyst
- Closed tenderPublished 25 October 2019
RIIO-2 Cyber Security submissions review - Role 2 - Project PMO Support/Analyst
- Closed tenderPublished 16 August 2019
CR19056 - Cyber Assessment Framework Analysis - Energy Sector
- Closed tenderPublished 7 August 2019
Accounting, auditing and fiscal services
- Awarded contract
Cyber Vulnerability Investigations as a Service (CVIaaS) – Military Maritime Domain
- Awarded contract
Cyber Vulnerability Investigations as a Service (CVIaaS) – Military Land Domain
Frequently asked questions
Frequently asked questions about cyber assessment framework, cyber security assurance, cyber security assessment, cyber security audit, cyber maturity, cyber security certification, cyber essentials assessment in the UK public sector.
How do I win public sector cyber assessment contracts?
Two routes. Watch the portals for a live tender, or get in earlier. Most of this work is bought through frameworks and call offs, so the notice you see is often the award rather than the opportunity. On Stotles you can read a buyer's strategy papers, board minutes and budget files, spot the assurance programme before it turns into a tender, and be on the shortlist when it does. Platform-wide there are 2,147 tenders open right now across 100+ portals.
What is the difference between Cyber Essentials and the Cyber Assessment Framework?
Cyber Essentials is a certification. A buyer either self-assesses against it or pays for the Plus version, which is checked by an assessor, and public bodies also buy help getting through it. The Cyber Assessment Framework is the National Cyber Security Centre's framework that organisations are measured against under a government profile, and the notices for it usually ask for an independent audit of a self-assessment the buyer has already done. In procurement terms they are different purchases: one is a certificate, the other is an audit engagement.
Why do so many tenders mention Cyber Essentials without being cyber contracts?
Because it has become standard eligibility boilerplate. Search the bare phrase across the corpus and 1,141 notices come back, covering brickwork, roofing, underfloor heating and address matching, because buyers list the certificate, usually next to an information security management standard, as something bidders must hold. The filter behind this page deliberately drops that phrase and keeps the assessment and audit wording instead, which brings it down to 171 notices that are actually buying cyber work.
What CPV codes are used for cyber assessment and audit tenders?
The two that fit best are 72800000 (Computer audit and testing services) and 72810000 (Computer audit services). Plenty of these notices carry only a broad code such as 72222300 (Information technology services), and some carry no code at all, which is why this page filters on wording rather than on CPV. Codes are useful for sense-checking a notice, less useful for finding one.
How much cyber assessment work is out there right now?
Less open than you might expect. Of the 171 matching notices on record, 104 are awards and only a handful are sitting open at any moment, because the buying happens through framework call offs and mini-competitions that never appear as an open tender. That makes the award history the useful part. It tells you which buyers reassess on a cycle, and roughly when they are due again. Platform-wide, 2 notices were added in the last seven days.
Win more Cyber Tenders contracts with Stotles
Get Cyber Tenders alerts, buyer intelligence and bid tools, all in one place.
