Cyber Security tenders

Find live UK public sector cyber security tenders

Find live UK cyber security tenders and InfoSec contracts updated daily. Penetration testing, SOC services, cloud security, GRC and more, distinct from physical security.

Cyber Security tender activity

How cyber security tenders are trending

Share of all UK public sector opportunity notices each month (awards excluded). Share is coverage-robust: it is not skewed by the number of sources we monitor, so it reflects genuine market composition.

This page covers cyber security, information security, and digital security procurement only. It is distinct from TenderSignal's physical security tenders page, which covers manned guarding, CCTV, and access control. If you sell penetration testing, managed security operations, identity management, cloud security, GRC advisory, or related digital services, you are in the right place.

What counts as a cyber security tender

Cyber security procurement covers a wide range of specialist services focused on protecting digital systems, data, and infrastructure. Penetration testing and vulnerability assessment are among the most frequently tendered cyber services, commissioned across central government, NHS, and large councils to satisfy assurance requirements and comply with frameworks such as Cyber Essentials Plus.

Security operations centre (SOC) managed services and managed detection and response are a significant and growing area of spend. Related to this are SIEM platforms (security information and event management systems), which aggregate log data and surface anomalies. Many public sector buyers commission implementation, tuning, and managed operation of SIEM tooling as a single procurement.

Endpoint protection covers antivirus, endpoint detection and response platforms, and mobile device management. Large public sector organisations with thousands of devices frequently retender this category as incumbent licence terms expire or as they migrate to cloud-native tooling. Identity and access management, including privileged access management, single sign-on, and multi-factor authentication, is increasingly procured as a managed service. Cloud security services encompass security configuration review, cloud security posture management, and ongoing monitoring of cloud-hosted assets.

Governance, risk, and compliance advisory covers security policy development, risk assessment, data protection impact assessments, and compliance audit support. Cyber security awareness training and simulated phishing are tendered regularly by HR and IT teams working on workforce education programmes. Cyber Essentials assessment and certification body services appear on procurement portals when buyers are appointing assessors under a framework.

Note: CCTV installation, manned guarding, physical access control, intruder alarms, and lone-worker monitoring are physical security services covered by a separate CPV code family. If a tender involves guards, barriers, or cameras, it belongs on the physical security feed.

Who buys cyber security services in the public sector

Central government is the largest and most structured buyer. The Cabinet Office Government Security Group sets policy and drives adoption of the Cyber Assessment Framework. Individual departments and arm's-length bodies each procure their own security services, often calling off Government Commercial Agency (formerly Crown Commercial Service) frameworks. The Government Digital Service commissions security reviews as part of service assessments, generating regular demand for assessment and advisory services.

NHS England (which absorbed NHS Digital in 2023) and the broader NHS cyber programme represent large and consistent demand. Following the WannaCry incident in 2017, the health sector has significantly increased its cyber security investment. NHS trusts, integrated care boards, and NHS England commission penetration testing, SOC services, endpoint tooling, and training. Police forces buy cyber services for operational IT and digital investigation capabilities. Local authorities with digital transformation programmes are an expanding buyer group, and universities and FE colleges are high-value targets that invest accordingly.

Key cyber security frameworks and routes to market

The Government Commercial Agency Cyber Security Services 3 dynamic purchasing system (RM3764.3) covers penetration testing, security architecture, incident response, and related advisory services, and its successor, Cyber Security 4 (RM3764.4), is being designed. G-Cloud (RM1557) Lot 3 covers cloud support including cloud security services and managed security operations. The Digital Marketplace lists both frameworks. Many NHS and defence procurements run bespoke direct competitions outside these frameworks for specialised requirements.

Cyber Essentials certification is delivered by certification bodies licensed through IASME, the NCSC's Cyber Essentials delivery partner, which is separate from standard public procurement frameworks. Suppliers wanting to offer Cyber Essentials assessments need to become a licensed certification body before they can be selected via procurement.

CPV codes for cyber security procurement

Cyber security tenders use IT CPV codes, not physical security codes. Key codes include 72212000 (programming services of application software), 72222300 (information technology services), 72212730 (security software development services), 72000000 (IT services: consulting, software development, internet and support), and 79000000 (business services). Setting these CPV codes alongside 72200000 (software programming and consultancy) in your TenderSignal profile gives the broadest coverage of cyber security procurement across all sources.

How TenderSignal covers cyber security tenders

TenderSignal monitors when the GCA Cyber Security framework and G-Cloud application windows open on Find a Tender, alerting you before the window closes. It also captures direct cyber security tenders from NHS portals, council procurement systems, MOD Defence Sourcing Portal, and central government. Set your cyber security CPV codes and receive a matched digest covering both framework application notices and open market digital security tenders, entirely separate from the physical security feed, weekly free or daily on Pro. See also: G-Cloud framework opportunities and IT and software tenders.

Cyber security tender FAQ

What is the GCA Cyber Security framework?

The Government Commercial Agency Cyber Security Services 3 agreement (RM3764.3) is a dynamic purchasing system that lets UK public sector buyers procure penetration testing, security architecture, incident response, and advisory services from pre-qualified suppliers through a quicker further competition. Suppliers can apply to join at any time while it runs, and a successor agreement (RM3764.4) is being designed.

Do I need Cyber Essentials to bid for government cyber contracts?

Cyber Essentials is mandatory for central government contracts that involve handling personal information or providing certain ICT systems and services, and is increasingly expected as a baseline by NHS and local authority buyers. Cyber Essentials Plus is required for some higher-assurance contracts. If you sell cyber security services, holding Cyber Essentials Plus is a practical prerequisite for most public sector work and demonstrates the baseline you are promising to help your clients achieve.

What is the difference between physical security tenders and cyber security tenders?

Physical security tenders cover manned guarding, CCTV installation and monitoring, access control systems, intruder alarms, and related services. They use CPV codes in the 79710000 to 79730000 range (security services) and 45340000 (fencing, railing and safety equipment installation). Cyber security tenders cover digital and information security services and use IT CPV codes in the 72000000 range. TenderSignal treats these as separate categories so you see only the relevant notices for your specialism.

The problem

  • Cyber security tenders are published using IT CPV codes rather than security codes, so searches for 'security tenders' return physical security guarding and CCTV contracts rather than InfoSec opportunities.
  • Framework application windows for GCA Cyber Security and G-Cloud Lot 3 open infrequently and close quickly, and missing them means waiting for the next iteration.
  • Direct cyber security tenders from NHS, defence, and council sources are spread across dozens of portals and rarely labelled consistently, making manual monitoring unreliable.

With TenderSignal

  • Live cyber security tenders from central government, NHS, defence, and councils, filtered by IT CPV codes, entirely separate from the physical security feed.
  • Alerts when GCA Cyber Security framework and G-Cloud Lot 3 application windows open on Find a Tender, so listing opportunities don't slip past you.
  • Pipeline intelligence for cyber security contract renewals approaching their end date across all public sector buyers.

Cyber Security tenders: frequently asked questions

What is the GCA Cyber Security framework?

The Government Commercial Agency Cyber Security Services 3 agreement (RM3764.3) is a dynamic purchasing system that lets public sector buyers procure penetration testing, security architecture, incident response, and advisory services from pre-qualified suppliers through a quicker further competition. Suppliers can apply to join at any time while it runs, and a successor (RM3764.4) is being designed.

Do I need Cyber Essentials to bid for government cyber contracts?

Cyber Essentials is mandatory for central government contracts that involve handling personal information or providing certain ICT systems and services, and is increasingly expected as a baseline by NHS and council buyers. Cyber Essentials Plus is required for some higher-assurance contracts. If you sell cyber security services, holding Cyber Essentials Plus is a practical prerequisite for most public sector work.

What CPV codes should I use for cyber security tenders?

Use 72000000 (IT services), 72212000 (programming services of application software), 72222300 (information technology services), and 72212730 (security software development services). Set these in your TenderSignal profile alongside 72200000 (software programming and consultancy) for broad coverage. Do not use 79710000-79730000: those are physical security CPV codes.

What is the difference between physical security and cyber security tenders?

Physical security tenders cover manned guarding, CCTV, access control, and intruder alarms, using CPV codes in the 79710000 range. Cyber security tenders cover digital and information security services using IT CPV codes in the 72000000 range. TenderSignal treats these as separate categories.

Find cyber security tenders as soon as they are published

Join TenderSignal free and get matched cyber security opportunities in your inbox.

Related tender categories

Browse all tender categories →