Award

Annual Penetration Testing for NAO

NATIONAL AUDIT OFFICE

This public procurement record has 3 releases in its history.

AwardUpdate

04 Jul 2025 at 15:40

AwardUpdate

28 Sep 2023 at 12:59

Award

30 Aug 2023 at 15:23

Summary of the contracting process

The National Audit Office (NAO), headquartered in London, has concluded the award stage for a contract titled "Annual Penetration Testing for NAO". This procurement falls under the IT services category and aims to provide independent assurance on technical security controls through various assessments, including penetration testing and cyber essentials assessments. The contract, valued at £80,856, was called off from the G-Cloud 13 Framework using a selective procurement method. The initial contract period commenced on 31st July 2023 and runs through to 30th July 2026, with potential extensions. The contract address is set within the United Kingdom.

This tender presents significant growth opportunities for SMEs specialising in IT security services, as demonstrated by PRISM INFOSEC LTD, the awarded supplier. Firms with expertise in cybersecurity and infrastructure assessments are well-suited to engage in similar frameworks, leveraging the potential for repeat contract extensions. Engaging in such contracts can enhance a business's visibility, credibility, and potential for further government contract opportunities.

Find more tenders on our Open Data Platform.
How relevant is this notice?

D3 Tenders Premium

Win More Public Sector Contracts

AI-powered tender discovery, pipeline management, and market intelligence — everything you need to grow your public sector business.

Notice Title

Annual Penetration Testing for NAO

Notice Description

National Audit Office (NAO) has awarded a contract to the supplier for the provision of independent assurance around the effectiveness and robustness of its technical security controls, which will include, security testing based on the following models 1) Annual Penetration Testing 2) Annual Cyber Essentials Plus Assessment and 3) Annual CHECK IT Health Check. The Contract has been called off from the G-Cloud 13 Framework. The Contract Value in this Notice include VAT. The initial contract period is 1 year with the option to extend by 2 further periods of 1 year (1+1+1). The contract has been extended until July 2026 and the maximum estimated contract value is PS88,000 inclusive of VAT.

Publication & Lifecycle

Open Contracting ID
ocds-b5fd17-23514799-ba8e-4ea6-be50-083add6bf819
Publication Source
Contracts Finder
Latest Notice
https://www.contractsfinder.service.gov.uk/Notice/1c715748-61b4-48a3-b587-49ce510a0158
Current Stage
Award
All Stages
Award

Procurement Classification

Notice Type
Award Notice
Procurement Type
Framework
Procurement Category
Services
Procurement Method
Selective
Procurement Method Details
Call-off from a framework agreement
Tender Suitability
SME
Awardee Scale
SME

Common Procurement Vocabulary (CPV)

CPV Divisions

72 - IT services: consulting, software development, Internet and support


CPV Codes

72000000 - IT services: consulting, software development, Internet and support

Notice Value(s)

Tender Value
£88,000 Under £100K
Lots Value
Not specified
Awards Value
£80,856 Under £100K
Contracts Value
Not specified

Notice Dates

Publication Date
4 Jul 20257 months ago
Submission Deadline
17 Jul 2023Expired
Future Notice Date
Not specified
Award Date
26 Jul 20232 years ago
Contract Period
30 Jul 2023 - 30 Jul 2026 3-4 years
Recurrence
Not specified

Notice Status

Tender Status
Complete
Lots Status
Not Specified
Awards Status
Active
Contracts Status
Not Specified

Contracting Authority (Buyer)

Main Buyer
NATIONAL AUDIT OFFICE
Contact Name
Available with D3 Tenders Premium →
Contact Email
Available with D3 Tenders Premium →
Contact Phone
Available with D3 Tenders Premium →

Buyer Location

Locality
LONDON
Postcode
SW1W 9SP
Post Town
South West London
Country
England

Major Region (ITL 1)
TLI London
Basic Region (ITL 2)
TLI3 Inner London - West
Small Region (ITL 3)
TLI35 Westminster and City of London
Delivery Location
Not specified

Local Authority
Westminster
Electoral Ward
Pimlico North
Westminster Constituency
Cities of London and Westminster

Supplier Information

Number of Suppliers
1
Supplier Name

PRISM INFOSEC

Further Information

Notice Documents

Open Contracting Data Standard (OCDS)

View full OCDS Record for this contracting process

Download

The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.

{
    "tag": [
        "compiled"
    ],
    "id": "ocds-b5fd17-23514799-ba8e-4ea6-be50-083add6bf819-2025-07-04T16:40:16+01:00",
    "date": "2025-07-04T16:40:16+01:00",
    "ocid": "ocds-b5fd17-23514799-ba8e-4ea6-be50-083add6bf819",
    "language": "en",
    "initiationType": "tender",
    "tender": {
        "id": "CPT_23_31",
        "title": "Annual Penetration Testing for NAO",
        "description": "National Audit Office (NAO) has awarded a contract to the supplier for the provision of independent assurance around the effectiveness and robustness of its technical security controls, which will include, security testing based on the following models 1) Annual Penetration Testing 2) Annual Cyber Essentials Plus Assessment and 3) Annual CHECK IT Health Check. The Contract has been called off from the G-Cloud 13 Framework. The Contract Value in this Notice include VAT. The initial contract period is 1 year with the option to extend by 2 further periods of 1 year (1+1+1). The contract has been extended until July 2026 and the maximum estimated contract value is PS88,000 inclusive of VAT.",
        "status": "complete",
        "classification": {
            "scheme": "CPV",
            "id": "72000000",
            "description": "IT services: consulting, software development, Internet and support"
        },
        "items": [
            {
                "id": "1",
                "deliveryAddresses": [
                    {
                        "countryName": "United Kingdom"
                    },
                    {
                        "countryName": "United Kingdom"
                    },
                    {
                        "countryName": "United Kingdom"
                    }
                ]
            }
        ],
        "value": {
            "amount": 88000,
            "currency": "GBP"
        },
        "procurementMethod": "selective",
        "procurementMethodDetails": "Call-off from a framework agreement",
        "tenderPeriod": {
            "endDate": "2023-07-17T13:00:00+01:00"
        },
        "contractPeriod": {
            "startDate": "2023-07-31T00:00:00+01:00",
            "endDate": "2026-07-30T23:59:59+01:00"
        },
        "suitability": {
            "sme": true,
            "vcse": false
        },
        "mainProcurementCategory": "services"
    },
    "parties": [
        {
            "id": "GB-SRS-sid4gov.cabinetoffice.gov.uk/sBN45ywB",
            "name": "National Audit Office",
            "identifier": {
                "legalName": "National Audit Office",
                "scheme": "GB-SRS",
                "id": "sid4gov.cabinetoffice.gov.uk/sBN45ywB"
            },
            "address": {
                "streetAddress": "Room B253,157-197 Buckingham Palace Road",
                "locality": "LONDON",
                "postalCode": "SW1W9SP",
                "countryName": "England"
            },
            "contactPoint": {
                "name": "Dashini Ramrous",
                "email": "dashini.ramrous@nao.org.uk",
                "telephone": "02077987015"
            },
            "roles": [
                "buyer"
            ]
        },
        {
            "id": "GB-COH-05985734",
            "name": "PRISM INFOSEC LTD",
            "identifier": {
                "legalName": "PRISM INFOSEC LTD",
                "scheme": "GB-COH",
                "id": "05985734"
            },
            "address": {
                "streetAddress": "Eagle Tower,803 Montpellier Drive CHELTENHAM Gloucestershire GL50 1TA GB"
            },
            "details": {
                "scale": "sme",
                "vcse": false
            },
            "roles": [
                "supplier"
            ]
        }
    ],
    "buyer": {
        "id": "GB-SRS-sid4gov.cabinetoffice.gov.uk/sBN45ywB",
        "name": "National Audit Office"
    },
    "awards": [
        {
            "id": "ocds-b5fd17-23514799-ba8e-4ea6-be50-083add6bf819-1",
            "status": "active",
            "date": "2023-07-27T00:00:00+01:00",
            "datePublished": "2023-08-30T16:23:34+01:00",
            "value": {
                "amount": 80856,
                "currency": "GBP"
            },
            "suppliers": [
                {
                    "id": "GB-COH-05985734",
                    "name": "PRISM INFOSEC LTD"
                }
            ],
            "contractPeriod": {
                "startDate": "2023-07-31T00:00:00+01:00",
                "endDate": "2026-07-30T23:59:59+01:00"
            },
            "documents": [
                {
                    "id": "1",
                    "documentType": "awardNotice",
                    "description": "Awarded contract notice on Contracts Finder",
                    "url": "https://www.contractsfinder.service.gov.uk/Notice/1c715748-61b4-48a3-b587-49ce510a0158",
                    "datePublished": "2023-08-30T16:23:34+01:00",
                    "format": "text/html",
                    "language": "en",
                    "dateModified": "2025-07-04T16:40:16+01:00"
                }
            ]
        }
    ]
}