Penetration Testing Tenders
See open penetration testing tenders and awarded contracts for the UK public sector.
Most of this work is bought as an IT health check. Councils, NHS trusts and central departments run an annual ITHC to keep a Public Services Network connection or to satisfy the NHS Data Security and Protection Toolkit, and the notice is titled that way rather than as penetration testing. Scope ranges from one web application to a whole estate.
There are 1,447 notices on record and 854 of them are awards. Buyers often appoint two or three CHECK accredited testers rather than one, then retender on a cycle.
1,418 results
- Expired contractPublished 13 December 2019
IT Health Check
Value not stated
- Expired contractPublished 2 December 2019
UKRI DDaT19266 IUK Private Cloud Hosting and Support Services
£995,815
- Awarded contractPublished 26 November 2019
Software package and information systems
£995,815
- Awarded contractPublished 25 November 2019
The N5 Ballaghaderreen to Scramoge Road Project - Detailed Ground Investigation Contract comprises Section A and B (Lot 1) and Section C and D (Lot 2)
Value not stated
- Expired contractPublished 21 November 2019
Technology Security
£120,000
- Expired contractPublished 20 November 2019
Security software package
Value not stated
- Closed tenderPublished 20 November 2019
GB-M'bro: Annual Penetration Test
£75,000
- Expired contractPublished 18 November 2019
GB-Shrewsbury: DMNH 021- NWRR - Ground Investigation Phase 2
£350,000
- Awarded contractPublished 18 November 2019
ISG High Threat Gateway Security Assurance Co-Ordinator
£389,175
- Closed tenderPublished 18 November 2019
MOJ Cybersecurity Log Collection and Aggregation Platform
£280,000
- Closed tenderPublished 13 November 2019
IT Health Check
Value not stated
- Stale Pre-tenderPublished 11 November 2019
Non-destructive testing services
£1,000,000
- Expired contractPublished 11 November 2019
UK Export Finance ITHC Call-Off Contract
£70,000
- Closed tenderPublished 5 November 2019
Ad-Hoc Application Penetration Testing & Other Security Services
£70,000
- Closed tenderPublished 5 November 2019
Ad-Hoc Application Penetration Testing & Other Security Services
Value not stated
- Closed tenderPublished 1 November 2019
South London and Maudsley NHS Foundation Trust - website redevelopment project
£90,000
- Closed tenderPublished 1 November 2019
South London and Maudsley NHS Foundation Trust - website redevelopment project
£90,000
- Awarded contractPublished 1 November 2019
Provision of a Replacement for PHE's Poisons Information Database (UKPID) Web Portal
£43,065
- Closed tenderPublished 31 October 2019
Digital development, improvement and innovation for Royal Botanic Gardens, Kew
£800,000
- Closed tenderPublished 31 October 2019
Digital development, improvement and innovation for Royal Botanic Gardens, Kew
£800,000
Frequently asked questions
Frequently asked questions about penetration testing, pen testing, ITHC, red team, vulnerability testing, ethical hacking, pentest in the UK public sector.
How do I find penetration testing contracts in the UK?
Two ways in. Watch the portals for live ITHC and penetration testing notices, or move earlier and follow the buyers who retender on an annual cycle. Stotles pulls notices from 100+ portals and sits them next to the strategy documents and budget papers that show the work coming. Platform-wide, 2,126 notices are open right now. Start with what is open, then track the buyers behind it.
Is an IT health check the same thing as a penetration test?
In practice, yes. An IT Health Check, written ITHC, is the UK public sector name for a scope-defined penetration test run once a year, usually to keep a Public Services Network connection or to meet the NHS Data Security and Protection Toolkit. Buyers ask for testers accredited under the NCSC CHECK scheme. Notice titles use the two terms interchangeably, so searching for one and not the other misses a large part of the market.
What CPV codes are used for penetration testing tenders?
The two that recur are 72800000 (Computer audit and testing services) and 72254100 (Systems testing services). Plenty of notices are filed under the much broader parent IT services heading instead, and some carry no code at all. Alongside the keyword filter for this page, 72800000 appears on 112 notices and 72254100 on 38, so codes narrow the picture rather than describe it. Keywords do the work here.
How much penetration testing work is there, and how often does it come round?
There are 1,447 notices on record for this filter, 854 of them awards and 55 still at the pre-tender stage. Six sit at the open stage, which is what an annual testing cycle looks like: small contracts, awarded quickly, then retendered. The awards are the more useful half. They show who tests for which buyer and when the current term runs out.
What should a supplier check before bidding for an ITHC?
Accreditation first. Many notices restrict bidders to NCSC CHECK or equivalent accredited testers, and a lot of the work is called off a cyber security framework or a dynamic purchasing system rather than run as an open competition. Then read the scope, because an external infrastructure and web application test is a different job from a full estate review or a red team exercise. Platform-wide, 0 award notices were published in the last seven days, and recent awards are the quickest way to see how buyers word the requirement.
Win more Penetration Testing Tenders contracts with Stotles
Get Penetration Testing Tenders alerts, buyer intelligence and bid tools, all in one place.
