Cyber Tenders
See open cyber tenders and awarded contracts for the UK public sector.
This page covers the assessment and assurance end of public sector cyber buying: Cyber Assessment Framework audits, GovAssure reviews, cyber maturity assessments and Cyber Essentials certification work. 171 notices match on record, and 104 of those are awards.
It is consultancy, not product. Individual contracts are small and they recur, and some of the awards arrive as G-Cloud call offs rather than open competitions, which is why the awarded pile here is so much bigger than the open one.
165 results
- Awarded contract
Cyber Vulnerability Investigations as a Service (CVIaaS) – Military Air Domain
- Stale Pre-tenderPublished 30 April 2019
Cyber Security Services
- Closed tenderPublished 21 February 2019
Cyber Vulnerability Investigations as a Service (CVIaaS) – Military Joint Domain
- Closed tenderPublished 21 February 2019
Cyber Vulnerability Investigations as a Service (CVIaaS) – Military Joint Domain
- Closed tenderPublished 13 February 2019
Cyber Vulnerability Investigations as a Service (CVIaaS) – Military Maritime Domain
- Closed tenderPublished 6 February 2019
Cyber Vulnerability Investigations as a Service (CVIaaS) – Military Land Domain
- Expired contract
Contract Award - Solution Assurance for HMPPS Electronic Monitoring 2
- Closed tenderPublished 29 November 2018
Cyber Vulnerability Investigations as a Service (CVIaaS) – Military Air Domain
- Awarded contract
IT Security Manager
- Expired contract
UK Export Finance Cyber Security Audit
- Closed tenderPublished 19 December 2017
IT services: consulting, software development, Internet and support
- Closed tenderPublished 8 December 2017
Cyber Security Governance Risk and Compliance (GRC) Implementation Partner
- Closed tenderPublished 8 December 2017
Cyber Security Governance Risk and Compliance (GRC) Implementation Partner
- Expired contract
Information systems or technology strategic review and planning services
- Awarded contract
IT Security Services
- Stale Pre-tenderPublished 21 August 2017
HCON01170PME - Specialist Security Testing
- Stale Pre-tenderPublished 16 August 2017
Computer-related professional services
- Stale Pre-tenderPublished 29 June 2017
IT services: consulting, software development, Internet and support
- Expired contract
Cyber Security Assurance Service for HMPPS Digital and Change Programme
- Closed tenderPublished 27 February 2017
Information systems or technology strategic review and planning services
Frequently asked questions
Frequently asked questions about cyber assessment framework, cyber security assurance, cyber security assessment, cyber security audit, cyber maturity, cyber security certification, cyber essentials assessment in the UK public sector.
How do I win public sector cyber assessment contracts?
Two routes. Watch the portals for a live tender, or get in earlier. Most of this work is bought through frameworks and call offs, so the notice you see is often the award rather than the opportunity. On Stotles you can read a buyer's strategy papers, board minutes and budget files, spot the assurance programme before it turns into a tender, and be on the shortlist when it does. Platform-wide there are 2,156 tenders open right now across 100+ portals.
What is the difference between Cyber Essentials and the Cyber Assessment Framework?
Cyber Essentials is a certification. A buyer either self-assesses against it or pays for the Plus version, which is checked by an assessor, and public bodies also buy help getting through it. The Cyber Assessment Framework is the National Cyber Security Centre's framework that organisations are measured against under a government profile, and the notices for it usually ask for an independent audit of a self-assessment the buyer has already done. In procurement terms they are different purchases: one is a certificate, the other is an audit engagement.
Why do so many tenders mention Cyber Essentials without being cyber contracts?
Because it has become standard eligibility boilerplate. Search the bare phrase across the corpus and 1,141 notices come back, covering brickwork, roofing, underfloor heating and address matching, because buyers list the certificate, usually next to an information security management standard, as something bidders must hold. The filter behind this page deliberately drops that phrase and keeps the assessment and audit wording instead, which brings it down to 171 notices that are actually buying cyber work.
What CPV codes are used for cyber assessment and audit tenders?
The two that fit best are 72800000 (Computer audit and testing services) and 72810000 (Computer audit services). Plenty of these notices carry only a broad code such as 72222300 (Information technology services), and some carry no code at all, which is why this page filters on wording rather than on CPV. Codes are useful for sense-checking a notice, less useful for finding one.
How much cyber assessment work is out there right now?
Less open than you might expect. Of the 171 matching notices on record, 104 are awards and only a handful are sitting open at any moment, because the buying happens through framework call offs and mini-competitions that never appear as an open tender. That makes the award history the useful part. It tells you which buyers reassess on a cycle, and roughly when they are due again. Platform-wide, 2 notices were added in the last seven days.
Win more Cyber Tenders contracts with Stotles
Get Cyber Tenders alerts, buyer intelligence and bid tools, all in one place.
