This public procurement record has 1 release in its history.

Award

22 Sep 2026 at 11:28

Summary of the contracting process

The Driver and Vehicle Standards Agency (DVSA) procured penetration testing and IT health checks, classified as computer audit and testing services. The work is intended to assess the security and resilience of the agency’s information technology through security testing and health-check activity. Delivery covers the United Kingdom, the Channel Islands, the Isle of Man, Europe, British Overseas Territories and other locations worldwide. This is a public-sector cyber security services requirement for a supplier able to operate across a wide geographical footprint and support DVSA’s technology assurance needs. The procurement is categorised as services and was structured as a call-off from the Crown Commercial Service Cyber Security 3 framework, RM3764iii. It was suitable for small and medium-sized enterprises, making it relevant to established specialist cyber security consultancies as well as larger testing providers.

The procurement is complete and has been awarded following a selective call-off from the Cyber Security 3 framework, RM3764iii. Bids were due by 29 May 2026 at 2pm. DVSA awarded the contract to Instil Software Limited on 27 August 2026 for £533,333.33 including the stated currency of GBP. The contract runs from 27 August 2026 to 26 August 2028. The original procurement estimate was £533,333 GBP. One supplier is identified as the award recipient. The published information describes the requirement as penetration testing and IT health checks, but does not set out separate lots or detailed scoring criteria. The process therefore demonstrates a framework-based, selective route rather than an open competition, with supplier selection made through the relevant framework call-off arrangements.

This award is evidence of sustained demand from DVSA for specialist cyber security assurance, rather than a one-off purchase of general IT support. Suppliers well placed for a future requirement would need demonstrable capability in penetration testing, IT health checks, computer audit and technical security testing, with the operational capacity to support a major public-sector organisation. The broad delivery footprint means credible providers should be able to work across the UK and potentially internationally, either directly or through an established delivery network. The successful supplier is an SME, showing that the requirement can be delivered by a focused specialist rather than only a large systems integrator. Competitors should also understand and be able to use the relevant CCS cyber security framework call-off route, and should be prepared to provide repeatable, well-governed testing and assurance services at substantial scale.

How relevant is this notice?

Notice Information

Notice Title

Penetration testing/IT Health Checks 2026

Notice Description

THIS WAS A CALL - OFF FROM A CCS FRAMEWORK CYBER SECURITY 3 RM3764iii

Notice Details

Publication & Lifecycle

Open Contracting ID
ocds-b5fd17-f92e1abb-2e96-4cc4-bd97-5e3383e7b55c
Publication Source
Contracts Finder
Latest Notice
https://www.contractsfinder.service.gov.uk/Notice/2b9321c1-1326-4797-8337-5c6f00b037d1
Current Stage
Award
All Stages
Award

Procurement Classification

Notice Type
Award Notice
Procurement Type
Framework
Procurement Category
Services
Procurement Method
Selective
Procurement Method Details
Call-off from a framework agreement
Tender Suitability
SME
Awardee Scale
SME

Common Procurement Vocabulary (CPV)

CPV Divisions

72 - IT services: consulting, software development, Internet and support


CPV Codes

72800000 - Computer audit and testing services

Notice Value(s)

Tender Value
£533,333 £500K-£1M
Lots Value
Not specified
Awards Value
£533,333 £500K-£1M
Contracts Value
Not specified

Notice Dates

Publication Date
22 Sep 20262 weeks ago
Submission Deadline
Not specified
Future Notice Date
Not specified
Award Date
27 Aug 20261 months ago
Contract Period
27 Aug 2026 - 26 Aug 2028 2-3 years
Recurrence
Not specified

Notice Status

Tender Status
Complete
Lots Status
Not Specified
Awards Status
Active
Contracts Status
Not Specified

Buyer & Supplier

Contracting Authority (Buyer)

Main Buyer
Driver and Vehicle Standards Agency
Contact Name
Available with D3 Tenders Premium →
Contact Email
Available with D3 Tenders Premium →
Contact Phone
Available with D3 Tenders Premium →

Buyer Location

Locality
BRISTOL
Postcode
BS5 0DA
Postcode Area
Bristol
Country
England

Major Region (ITL 1)
TLK South West (England)
Basic Region (ITL 2)
TLK5 West of England
Small Region (ITL 3)
TLK51 Bristol, City of
Delivery Location
Not specified

Local Authority
Bristol, City of
Electoral Ward
Lawrence Hill
Westminster Constituency
Bristol East

Supplier Information

Number of Suppliers
1
Supplier Name

INSTIL SOFTWARE LIMITED

Open Contracting Data Standard (OCDS)

View full OCDS Record for this contracting process

JSON Markdown

The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.

Loading OCDS record...