Incident Response Tenders
See open incident response tenders and awarded contracts for the UK public sector.
Almost all of this market is cyber rather than physical. Buyers put a responder on contract before anything happens: named cyber incident response partners, NCSC-assured retainers, forensics and containment bolted onto a managed security operations centre. Standalone open tenders are rare. Most of the paperwork lands as a direct award or a framework call-off.
313 notices match on record, 186 already awarded and 5 open now. Another 28 sit at pre-tender, where a retainer renewal surfaces first.
311 results
- Awarded contract
Managed Security Operation Centre
- Awarded contract
Cyber Incident Response Retainer
- Awarded contract
Cyber incident response
- Awarded contract
Surge Laboratory Capacity in the event of a Health Emergency
- Awarded contract
BT484 - Cyber Incident Response Retainer
- Stale Pre-tenderPublished 21 May 2026
Managed Security Operations Centre (SOC) and Incident Response Services Agreement
- Awarded contract
Silver Incident Response Retainer
- Awarded contract
Call-off Award via RM1557.14 (G-Cloud 14) - Incident Response Retainer
- Awarded contract
TRGA3390 DfT CIR Contract
- Awarded contract
Endpoint and Threat Protection Software Licence Renewal
- Awarded contract
Provision of Cyber Incident Response Provider
- Awarded contract
R6140 Cyber Security Managed SIEM
- Awarded contract
Provision of Cyber Incident Response Provider
- Awarded contract
Cyber Incident Response Retainer
- Closed tenderPublished 14 April 2026
Cyber Security Services
- Stale Pre-tenderPublished 14 April 2026
Cyber Security Services
- Awarded contract
Managed Security Operations Centre (SOC) & SIEM Service
- Awarded contract
Cyber Incident Response Partner Service
- Closed tenderPublished 26 March 2026
IT Professional Services Framework
- Awarded contract
Cyber Incident Response Partner
Frequently asked questions
Frequently asked questions about cyber incident response, security incident response, cyber security incident, incident response retainer, incident response capability, incident response plan, digital forensics and incident response, cyber incident management in the UK public sector.
How do I win public sector incident response contracts?
Two routes. Track the retainers coming up for renewal, because a cyber incident response partner is nearly always appointed in advance and re-appointed on a cycle. Or get onto the frameworks buyers call off from. Stotles tracks notices from 100+ portals plus the strategy and board papers behind them, so a security team writing an incident response plan shows up well before its tender does. Platform-wide, 2,198 notices are open right now.
What do incident response tenders actually buy?
Mostly a retainer. The contract puts a certified responder on call for a fixed period, with triage, containment, forensics and post-incident reporting priced up front and drawn down only if something happens. Bigger buys wrap it into a managed security operations centre deal, where detection and response sit with one supplier. Preparedness work shows up too: playbooks, readiness reviews and cyber tabletop exercises run against a buyer's own incident response processes.
What CPV codes cover incident response procurement?
There is no dedicated code, so buyers file it under IT services. Alongside this page's keyword filter, 114 notices carry 72000000 (IT services: consulting, software development, Internet and support), 30 carry 72222300 (Information technology services) and 19 carry 72212730 (Security software development services). The codes are recorded as research and not applied as a filter here, because filtering on them would drop every matching notice that carries no code at all.
How many incident response tenders and contracts are there?
313 notices match this page's filter on record, across the UK and Ireland. 186 are awarded contracts, 5 are open and 28 sit at pre-tender. Weekly flow is thin: a single week often brings nothing at all, so read an empty open list as normal for this niche rather than a dead market, and watch the awarded side for expiry dates instead.
Which frameworks are used to buy incident response?
Two recur in the notices behind this page: the Cyber Security Services 3 DPS (RM3764.3), used to appoint NCSC-assured cyber incident response partners, and G-Cloud (RM1557.14), used for retainer call-offs. Direct awards to a single supplier are common as well, so a framework place is worth having before an incident forces the buyer's hand.
Win more Incident Response Tenders contracts with Stotles
Get Incident Response Tenders alerts, buyer intelligence and bid tools, all in one place.
