This page covers cyber security, information security, and digital security procurement only. It is distinct from TenderSignal's physical security tenders page, which covers manned guarding, CCTV, and access control. If you sell penetration testing, managed security operations, identity management, cloud security, GRC advisory, or related digital services, you are in the right place.
What counts as a cyber security tender
Cyber security procurement covers a wide range of specialist services focused on protecting digital systems, data, and infrastructure. Penetration testing and vulnerability assessment are among the most frequently tendered cyber services, commissioned across central government, NHS, and large councils to satisfy assurance requirements and comply with frameworks such as Cyber Essentials Plus.
Security operations centre (SOC) managed services and managed detection and response are a significant and growing area of spend. Related to this are SIEM platforms -- security information and event management systems -- which aggregate log data and surface anomalies. Many public sector buyers commission implementation, tuning, and managed operation of SIEM tooling as a single procurement.
Endpoint protection covers antivirus, endpoint detection and response platforms, and mobile device management. Large public sector organisations with thousands of devices frequently retender this category as incumbent licence terms expire or as they migrate to cloud-native tooling. Identity and access management, including privileged access management, single sign-on, and multi-factor authentication, is increasingly procured as a managed service. Cloud security services encompass security configuration review, cloud security posture management, and ongoing monitoring of cloud-hosted assets.
Governance, risk, and compliance advisory covers security policy development, risk assessment, data protection impact assessments, and compliance audit support. Cyber security awareness training and simulated phishing are tendered regularly by HR and IT teams working on workforce education programmes. Cyber Essentials assessment and certification body services appear on procurement portals when buyers are appointing assessors under a framework.
Note: CCTV installation, manned guarding, physical access control, intruder alarms, and lone-worker monitoring are physical security services covered by a separate CPV code family. If a tender involves guards, barriers, or cameras, it belongs on the physical security feed.
Who buys cyber security services in the public sector
Central government is the largest and most structured buyer. The Cabinet Office Government Security Group sets policy and drives adoption of the Cyber Assessment Framework. Individual departments and arm's-length bodies each procure their own security services, often calling off Crown Commercial Service frameworks. The Government Digital Service commissions security reviews as part of service assessments, generating regular demand for assessment and advisory services.
NHS Digital and the broader NHS cyber programme represent large and consistent demand. Following the WannaCry incident in 2017, the health sector has significantly increased its cyber security investment. NHS trusts, integrated care boards, and NHS England commission penetration testing, SOC services, endpoint tooling, and training. Police forces buy cyber services for operational IT and digital investigation capabilities. Local authorities with digital transformation programmes are an expanding buyer group, and universities and FE colleges are high-value targets that invest accordingly.
Key cyber security frameworks and routes to market
The Crown Commercial Service Cyber Security Services framework (RM6004) covers penetration testing, security architecture, incident response, and related advisory services across all lots. G-Cloud (RM1557) Lot 3 covers cloud support including cloud security services and managed security operations. The Digital Marketplace lists both frameworks. Many NHS and defence procurements run bespoke direct competitions outside these frameworks for specialised requirements.
Cyber Essentials certification body services are procured through the NCSC certification body scheme, which is separate from standard public procurement frameworks. Suppliers wanting to offer Cyber Essentials assessments need NCSC authorisation as an assurance service provider before they can be selected via procurement.
CPV codes for cyber security procurement
Cyber security tenders use IT CPV codes, not physical security codes. Key codes include 72212000 (programming services of application software), 72222300 (information technology services), 72212224 (intrusion detection software development), 72000000 (IT services: consulting, software development, internet and support), and 79000000 (business services). Setting these CPV codes alongside 72200000 (software programming and consultancy) in your TenderSignal profile gives the most complete coverage of cyber security procurement across all sources.
How TenderSignal covers cyber security tenders
TenderSignal monitors when the CCS Cyber Security framework and G-Cloud application windows open on Find a Tender, alerting you before the window closes. It also captures direct cyber security tenders from NHS portals, council procurement systems, MOD Defence Sourcing Portal, and central government. Set your cyber security CPV codes and receive a daily matched digest covering both framework application notices and open market digital security tenders -- entirely separate from the physical security feed. See also: G-Cloud framework opportunities and IT and software tenders.
Cyber security tender FAQ
What is the CCS Cyber Security framework?
The Crown Commercial Service Cyber Security Services framework (RM6004) is a pre-competed agreement that lets UK public sector buyers procure penetration testing, security architecture, incident response, and advisory services from approved suppliers without running a full procurement competition each time. Suppliers apply during an open window, and successful applicants can be called off by any public sector buyer for the framework's duration.
Do I need Cyber Essentials to bid for government cyber contracts?
Cyber Essentials is a mandatory requirement for all suppliers handling government information at OFFICIAL classification and above, and is increasingly expected as a baseline by NHS and local authority buyers. Cyber Essentials Plus is required for some higher-assurance contracts. If you sell cyber security services, holding Cyber Essentials Plus is a practical prerequisite for most public sector work and demonstrates the baseline you are promising to help your clients achieve.
What is the difference between physical security tenders and cyber security tenders?
Physical security tenders cover manned guarding, CCTV installation and monitoring, access control systems, intruder alarms, and related services. They use CPV codes in the 79710000 to 79730000 range (security services) and 45340000 (fencing, railing and safety equipment installation). Cyber security tenders cover digital and information security services and use IT CPV codes in the 72000000 range. TenderSignal treats these as separate categories so you see only the relevant notices for your specialism.