This public procurement record has 5 releases in its history.

AwardUpdate

06 Aug 2026 at 16:00

AwardUpdate

01 Jun 2026 at 15:00

AwardUpdate

06 May 2026 at 14:04

AwardUpdate

19 Mar 2026 at 17:12

Award

13 Jan 2025 at 14:18

Summary of the contracting process

UK Research and Innovation required penetration testing and related cyber-security assessment services, including additional testing and security assessments added during delivery. The requirement was bought by UK Shared Business Services Limited for UK Research and Innovation. The work is associated with the buyer’s operations in Swindon, England. It covers specialist testing of systems and software to identify security weaknesses and provide assessment support. The procurement is categorised as goods, although the substantive requirement is a technical security testing service. The published classification is program testing software development services (CPV 72212984). The selected supplier is NCC Group Security Services Ltd, a large security services provider. The opportunity was suitable for small and medium-sized enterprises, but not for voluntary, community or social enterprises.

This procurement is complete and was awarded to NCC Group Security Services Ltd on 24 November 2024. It used a selective direct award as a call-off from the RM1557.14 G-Cloud 14 framework, rather than an open competition. The tender submission deadline was 25 September 2024 at 23:59. The initial estimated value was £64,000 excluding VAT. The awarded contract value, following six contract variations, is £218,280 excluding VAT. The variations added £52,480, £19,080, £11,780, £8,480 and £47,260 respectively for further assessments and testing, using contingency in the call-off contract. The contract runs from 6 January 2025 to 5 January 2028. The contract has been signed.

This award indicates sustained demand from UK Research and Innovation for external penetration testing, security assessments and related testing support, with the requirement expanding through several variations. A credible future supplier would need established cyber-security testing capability, including the ability to assess software and systems, identify vulnerabilities and deliver additional assessment work as project needs develop. The buyer’s use of the G-Cloud framework shows that suppliers seeking comparable work should understand framework call-off processes and be positioned to respond through an approved route. The requirement was marked as suitable for SMEs, so smaller specialist cyber-security firms may be commercially relevant where they can demonstrate sufficient technical capacity, reliable delivery and experience handling changing assessment requirements.

How relevant is this notice?

Notice Title

UKRI Penetration Testing Services

Notice Description

***Please note this is an award notice, not a call for competition*** UK Research and Innovation had a requirement for Penetration Testing Services. This has been sourced via direct award against the RM1557.14 G-Cloud 14 framework. ***Variation 001 has been conducted to include additional services required for implementation off security assessments, utilising built in contingency as per the call-off contract. This variation is totalled at PS52,480.00 excluding VAT. *** ***Variation 002 has been conducted to include additional services as required for the project, utilising built in contingency as per the call-off contract as per the call-off contract. This variation is totalled at PS19,080.00 excluding VAT.*** ***Variation 003 has been conducted to incorporate additional security security assessments, utilising built in contingency as per the call-off contract. This variation is totalled at PS11,780.00 excluding VAT. *** ***Variation 004 has been conducted to incorporate additional security security assessments, utilising built in contingency as per the call-off contract. This variation is totalled at PS8,480.00 excluding VAT. *** ***Variation 005 has been conducted to incorporate additional testing services, utilising built in contingency as per the call-off contract. This variation is totalled at PS47,260.00 excluding VAT. *** ***As per Contract Variation 006 the new contract value is PS218,280.00. excluding VAT. ***

Publication & Lifecycle

Open Contracting ID
ocds-b5fd17-02ab3ede-3735-4f6d-a280-5b5eea766387
Publication Source
Contracts Finder
Latest Notice
https://www.contractsfinder.service.gov.uk/Notice/792d1f23-b4d2-4138-94a1-8f3a9c0c5f54
Current Stage
Award
All Stages
Award

Procurement Classification

Notice Type
Award Notice
Procurement Type
Framework
Procurement Category
Goods
Procurement Method
Selective
Procurement Method Details
Call-off from a framework agreement
Tender Suitability
SME
Awardee Scale
Large

Common Procurement Vocabulary (CPV)

CPV Divisions

72 - IT services: consulting, software development, Internet and support


CPV Codes

72212984 - Program testing software development services

Notice Value(s)

Tender Value
£64,000 Under £100K
Lots Value
Not specified
Awards Value
£218,280 £100K-£500K
Contracts Value
Not specified

Notice Dates

Publication Date
6 Aug 20262 weeks ago
Submission Deadline
25 Sep 2024Expired
Future Notice Date
Not specified
Award Date
24 Nov 20241 years ago
Contract Period
6 Jan 2025 - 5 Jan 2028 2-3 years
Recurrence
Not specified

Notice Status

Tender Status
Complete
Lots Status
Not Specified
Awards Status
Active
Contracts Status
Not Specified

Contracting Authority (Buyer)

Main Buyer
UK SHARED BUSINESS SERVICES LIMITED
Contact Name
Available with D3 Tenders Premium →
Contact Email
Available with D3 Tenders Premium →
Contact Phone
Available with D3 Tenders Premium →

Buyer Location

Locality
SWINDON
Postcode
SN2 1FL
Postcode Area
Swindon
Country
England

Major Region (ITL 1)
TLK South West (England)
Basic Region (ITL 2)
TLK7 Gloucestershire and Wiltshire
Small Region (ITL 3)
TLK71 Swindon
Delivery Location
Not specified

Local Authority
Swindon
Electoral Ward
Rodbourne Cheney
Westminster Constituency
Swindon North

Supplier Information

Number of Suppliers
1
Supplier Name

NCC Group Security Services Ltd

Open Contracting Data Standard (OCDS)

View full OCDS Record for this contracting process

JSON Markdown

The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.

Loading OCDS record...