This public procurement record has 11 releases in its history.

Award

18 Sep 2026 at 13:36

Award

07 May 2026 at 10:37

TenderCancellation

06 May 2026 at 09:33

Award

02 Apr 2026 at 17:31

TenderCancellation

01 Apr 2026 at 09:24

Award

23 Mar 2026 at 13:07

TenderUpdate

08 Oct 2025 at 16:13

TenderUpdate

22 Sep 2025 at 08:45

Tender

19 Sep 2025 at 12:49

PlanningUpdate

26 Jun 2025 at 11:17

Planning

25 Jun 2025 at 16:17

Summary of the contracting process

BlueLight Commercial Limited has established a multi-supplier open framework for cyber security services for UK police forces and other named public bodies. It covers four service areas: penetration testing and vulnerability-management scanning; cyber security incident response and planning; cyber resilience audits; and cyber security training. Services are intended for delivery across the United Kingdom, Guernsey, the Isle of Man and Jersey. The framework can be used by police authorities, fire and rescue services, central and local government bodies, NHS bodies and other listed public-sector organisations. It is therefore relevant to cyber security consultancies, penetration-testing providers, incident-response specialists, resilience auditors and organisations delivering technical or online security training.

The procurement is complete and the framework contracts were signed on 8 June 2026. Lot 1, penetration testing and vulnerability-management scanning, was awarded to Aristi, BAE Systems Applied Intelligence, Claranet, DigitalXRAID, Dionach, MTI Technology, Prism Infosec and Ruptura Infosecurity, at £38,000,000 excluding VAT (£45,600,000 including VAT), from 8 June 2026 to 7 June 2034. Lot 2, incident response and planning, was awarded to BAE Systems Applied Intelligence, Cy4or Legal, Cypfer, Deloitte, Nettitude, Prism Infosec, ROC Technologies and TNMA Consulting, at £8,000,000 excluding VAT (£9,600,000 including VAT), for the same period. Lot 3, resilience audits, was awarded to Actica Consulting, Arcanum, Deloitte, DigitalXRAID, Dionach, Leonardo, MIAA and ROC Technologies, at £4,000,000 excluding VAT (£4,800,000 including VAT). Lot 4, training, was awarded to Amentum Clean Energy, NCC Group, ROC Technologies, Sudocyber, Telefónica Tech Northern Ireland and TNMA Consulting, at £8,000,000 excluding VAT (£9,600,000 including VAT). The open procedure used price-based evaluation, with economic and technical selection through the Procurement Specific Questionnaire. Earlier awards were cancelled on 23 March and 1 May 2026 after supplier withdrawal and required amendments.

This framework demonstrates sustained public-sector demand for suppliers able to deliver cyber security at national scale across multiple public bodies. Credible competitors will need practical capability in penetration testing, vulnerability scanning, incident response, cyber resilience auditing or cyber security training, with the option to specialise in one service area. The successful supplier mix includes both SMEs and large organisations, showing that specialist firms can compete alongside major technology, consultancy and assurance providers. Delivery requires disciplined account management: agreeing a scoping discussion within two working days, attending within 14 days, producing a written proposal within five working days and, where applicable, completing services within 28 days. Suppliers must also support customer-satisfaction measurement, regular management information, formal debriefing, training progress reporting where relevant, and annual emissions reporting and reduction planning.

How relevant is this notice?

Notice Title

BLC-0201 - Cyber Security Services Framework

Notice Description

BlueLight Commercial has established a multi-supplier Open Framework for the provision of Cyber Security Services. The Framework Agreement will be available for use by all UK Police Forces and all other agencies named in the documentation. The Framework is intended to have a total term of eight (8) years and will provide a route to market for the following Cyber Security Services: Lot 1 - Penetration Testing and Vulnerability Management Scanning Services Lot 2 - Cyber Security Incident Response and Planning Services Lot 3 - Cyber Resilience Audit Services Lot 4 - Cyber Security Training Services The Authority plans to be re-open this framework no later than 07/06/2029 to run for a further 3 years. It will then be re-opened no later than 07/06/2032 to run for a further two years.

Lot Information

Penetration Testing & Vulnerability Management Scanning Services

Renewal: 3+5 Open Framework

Incident Planning and Response Services

Renewal: 3+5 Open Framework

Cyber Resilience Audit Services

Renewal: 3+5 Open Framework

Cyber Security Training Services

Renewal: 3+5 Open Framework

Planning Information

Market Engagement session, to be held on Microsoft Teams. Open to all Cyber Security suppliers including those who deliver Cyber Security Services, including IT Health Checks, Cyber Security Training, Cyber Security Incident Response and Planning, Cyber Resilience Audit and vulnerability management scanning. During the session BLC will present their proposed activity in relation to a future Cyber Security Services framework and seek feedback from suppliers.

Publication & Lifecycle

Open Contracting ID
ocds-h6vhtk-0553a6
Publication Source
Find A Tender Service
Latest Notice
https://www.find-tender.service.gov.uk/Notice/088697-2026
Current Stage
Award
All Stages
Planning, Tender, Award

Procurement Classification

Notice Type
UK7 - Contract Details Notice
Procurement Type
Framework
Procurement Category
Services
Procurement Method
Open
Procurement Method Details
Open procedure
Tender Suitability
SME
Awardee Scale
Large, SME

Common Procurement Vocabulary (CPV)

CPV Divisions

48 - Software package and information systems

72 - IT services: consulting, software development, Internet and support

80 - Education and training services


CPV Codes

48931000 - Training software package

72000000 - IT services: consulting, software development, Internet and support

72150000 - Computer audit consultancy and hardware consultancy services

72220000 - Systems and technical consultancy services

72222000 - Information systems or technology strategic review and planning services

72222100 - Information systems or technology strategic review services

72222300 - Information technology services

72223000 - Information technology requirements review services

72224200 - System quality assurance planning services

72225000 - System quality assurance assessment and review services

72246000 - Systems consultancy services

72254000 - Software testing

72254100 - Systems testing services

72590000 - Computer-related professional services

72610000 - Computer support services

72611000 - Technical computer support services

72800000 - Computer audit and testing services

72810000 - Computer audit services

72820000 - Computer testing services

80500000 - Training services

Notice Value(s)

Tender Value
£59,000,000 £10M-£100M
Lots Value
£58,000,000 £10M-£100M
Awards Value
£50,000,000 £10M-£100M
Contracts Value
£50,000,000 £10M-£100M

Notice Dates

Publication Date
18 Sep 20262 days ago
Submission Deadline
31 Oct 2025Expired
Future Notice Date
19 Aug 2025Expired
Award Date
13 Mar 20266 months ago
Contract Period
8 Jun 2026 - 7 Jun 2034 Over 5 years
Recurrence
Not specified

Notice Status

Tender Status
Complete
Lots Status
Complete
Awards Status
Active, Cancelled
Contracts Status
Active, Cancelled

Contracting Authority (Buyer)

Main Buyer
BlueLight Commercial
Contact Name
Available with D3 Tenders Premium →
Contact Email
Available with D3 Tenders Premium →
Contact Phone
Available with D3 Tenders Premium →

Buyer Location

Locality
LONDON
Postcode
SW1P 3JS
Postcode Area
South West London
Country
England

Major Region (ITL 1)
TLI London
Basic Region (ITL 2)
TLI3 Inner London - West
Small Region (ITL 3)
TLI35 Westminster and City of London
Delivery Location
Not specified

Local Authority
Westminster
Electoral Ward
St James's
Westminster Constituency
Cities of London and Westminster

Supplier Information

Number of Suppliers
25
Supplier Names

Aristi Limited

Claranet Ltd

DIGITALXRAID LTD

Dionach Limited

Goaco Group Ltd

MTI Technology Limited

Prism Infosec Ltd

Ruptura InfoSecurity

BAE SYSTEMS APPLIED INTELLIGENCE LIMITED

CY4OR LEGAL LIMITED

CYPFER Limited

Deloitte LLP

Nettitude Limited

Roc Technologies Limited

TNMA CONSULTING LIMITED

Actica Consulting Ltd

AMETHYST RISK MANAGEMENT LIMITED

Arcanum Information Security Ltd

Leonardo UK Ltd

Amec Nuclear UK Ltd

NCC Group Security Services Limited

SUDOCYBER LIMITED

CANCOM MANAGED SERVICES LTD

Liverpool University Hospital NHS FT

Salus Digital Security Limited

Further Information

Notice Documents

Notice URLs

Open Contracting Data Standard (OCDS)

View full OCDS Record for this contracting process

JSON Markdown

The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.

Loading OCDS record...