Threat Detection Tenders
See open threat detection tenders and awarded contracts for the UK public sector.
Threat detection covers EDR, XDR, MDR, malware detection and breach detection: the tools buyers use to catch and respond to cyber incidents, from single antivirus renewals to multi-year managed SOC contracts.
There are 303 notices on record, most already awarded: 174 awarded against 10 open now, plus 29 at pre-tender. Buyers are usually renewing an existing EDR or SOC service rather than starting fresh. The UK government committed £2.6 billion to cyber security and legacy IT modernisation between 2022 and 2025.
287 results
- Awarded contract
Award of Mini-Competition for Managed Detection and Response, Security Operations Centre & Security Incident & Event Management
- Stale Pre-tenderPublished 9 December 2024
Dmarc Check Tools
- Expired contract
Managed Detection & Response Services Endpoint Detection & Response Managed Service plus Carbon Black EDR Licences (Year 1 and Year 2 costs)
- Closed tenderPublished 31 October 2024
Provision of Cybersecurity Systems and Services
- Awarded contract
SVUH-24010 ICT Security Systems and Associated Services for St Vincent's University Hospital (SVUH)
- Closed tenderPublished 21 October 2024
SVUH-24010 ICT Security Systems and Associated Services for St Vincent's University Hospital (SVUH)
- Closed tenderPublished 10 October 2024
Provision of Security Information and Event Management (SIEM) Security Operations Centre (SOC) Managed Detection and Response (MDR) and Endpoint Detection and Response (EDR) in Two Lots
- Expired contract
Managed Extended Detection and Response
- Closed tenderPublished 1 October 2024
Managed Security Service Provider
- Closed tenderPublished 17 September 2024
2024/005 Establishment of a single party framework agreement for the provision of cyber security monitoring, managed threat detection and response services to Enterprise Ireland
- Awarded contract
Provision of Managed Mail Services
- Closed tenderPublished 6 September 2024
Provision of Managed Mail Services
- Stale Pre-tenderPublished 2 September 2024
IT Security Services
- Awarded contract
Managed Security Services
- Stale Pre-tenderPublished 10 August 2024
Network Operations Centre (NOC) and Security Operations Centre (SOC)
- Stale Pre-tenderPublished 7 August 2024
Security Managed Detection and Response Service
- Closed tenderPublished 7 August 2024
Security Managed Detection and Response Service
- Closed tenderPublished 23 July 2024
Supply Chain Notice: Cyber threat hunting hardware kit
- Expired contract
SIA 874 - IT Managed Detection and Response Solution 2024
- Awarded contract
Provision of Managed Detection and Response (MDR) Solution
Frequently asked questions
Frequently asked questions about threat detection, managed detection and response, endpoint detection, extended detection and response, malware detection, breach detection in the UK public sector.
What counts as a threat detection tender?
Threat detection covers cyber security tooling and services that catch and respond to intrusions: endpoint detection and response (EDR), extended detection and response (XDR), managed detection and response (MDR), malware detection, breach detection and the SIEM and SOC contracts built around them. Some notices are single software licence renewals; others are multi-year managed services covering monitoring, triage and incident response.
How do I find threat detection contracts in the UK public sector?
Search live tenders on the portals, or get ahead of them on Stotles by tracking buyers' cyber security strategy documents and budget papers before a notice goes out. Filter by stage to separate what is open now from what has already been awarded, and set an alert so a new threat detection notice reaches you the day it publishes.
Are threat detection tenders mostly open or already awarded?
Mostly awarded. Of the 303 threat detection notices on record, 174 are awarded contracts, 29 sit at pre-tender or early market engagement, and 10 are open for bids right now. Most buyers already run an EDR or MDR service and are renewing or re-competing it rather than building one from nothing, so watch expiry dates on existing contracts as much as new notices.
What CPV codes cover threat detection procurement?
The two CPV codes that come up most often are 48730000 (Security software package) and 48732000 (Data security software package). Neither is used to filter this page: buyers code these notices inconsistently, and filtering on CPV code alone would hide a large share of genuinely on-topic tenders, so the search runs on keywords instead.
What's the difference between EDR, XDR and MDR tenders?
EDR (endpoint detection and response) watches laptops and servers for suspicious activity. XDR (extended detection and response) pulls that together with network, email and cloud signals into one view. MDR (managed detection and response) is the service wrapper: a third party runs the monitoring and responds on the buyer's behalf, day and night. Public sector notices increasingly ask for MDR as a single service rather than the underlying tooling bought separately.
How current is the threat detection tender data on Stotles?
Corpus notices update continuously rather than on a fixed schedule. Platform-wide, 2 new notices are added to Stotles every week, and a threat detection alert catches one the moment it is tagged, rather than waiting on a periodic re-scrape.
Win more Threat Detection Tenders contracts with Stotles
Get Threat Detection Tenders alerts, buyer intelligence and bid tools, all in one place.
