Notice Information
Notice Title
Provision of Airwave Technical Assurance and Security Architecture Services (Information Assurance) for ESMCP
Notice Description
The Home Office Airwave Security Team intends to re-procure the Technical Assurance and Security Architecture Services that will manage the end-to-end encrypted solution for specialist users as well as the interconnect solution between the Airwave service and the developing Emergency Services Network (ESN).
Lot Information
Lot 1
The Home office are re-procuring the Technical Assurance and Security Architecture Services. Estimated date for release of tender is late June 2026 The requirement will be procured through the Government Commercial Agency's Cyber Security Services 3 (DPS) RM3764.3 _____________________________________________________________________________________________________________________ Suppliers will need to be registered to the RM3764.3 DPS and be identifiable against the following DPS filters in order to be invited to the tender exercise: NCSC Assured Services, Cyber Resilience Audit, Audit and Review, Cyber Essentials Plus, Clearance: Security Check, NPPV (Non-Police Personnel Vetting), ISO 27001, Networks, Database, Internet, Cloud, Communications, Government, Critical National Infrastructure, Police, Ambulance, Fire Services, Coast Guard "No Preference" to all other filters. ______________________________________________________________________________________________________________________ Home Office is not responsible for supplier registration. Suppliers will need to contact the Government Commercial Agency and follow its guidance. Suggested links: Government Commercial Agency website: www.gca.gov.uk Become a supplier on a Dynamic Purchasing System: www.gca.gov.uk/how-to-supply/dynamic-purchasing-system-dps Link to Cyber Security Services 3 DPS: https://supplierregistration.cabinetoffice.gov.uk/dps/RM3764.3?nav=0 In addition to registering to the DPS, the tender itself will be run using the Home Office's tender portal (https://homeoffice.app.jaggaer.com/web/login.html) suppliers will need to register to it. Instruction appends the front page to this portal. Overview of requirements The indicative scope of work includes, but not limited to, the following Airwave activities: 1. Provision of independent technical assurance across the Airwave end-to-end ecosystem, including TETRA radio services, bearer and transport technologies, and interfaces with ESN and other interconnected systems. This includes assessing availability, capacity, performance, and resilience impacts arising from proposed or implemented changes 2. Understanding encryption algorithms (note: we use TEA2 and AES), lifecycle considerations, and associated cryptographic service models 3. Assessment of customer element architectures, control room environments, gateways, clusters, and high-impact modifications (e.g. CE refresh or site changes), with a focus on identifying security risks, operational impacts, and emerging dependencies 4. Structured review and assessment of users and suppliers technical submissions, including designs, configuration artefacts, test plans, and assurance or accreditation evidence. This includes identifying security gaps, vulnerabilities, or weaknesses across radio, cryptographic, network, and interworking solutions 5. Production, review, and maintenance of security cases, risk assessments, assurance reports, and risk treatment recommendations. The service includes providing clear, evidence-based input to governance and decision-making forums supporting Airwave service continuity and transition activities. 6. Assessment of Airwave-related services and changes against relevant national and industry frameworks and standards, including the HMG Security Policy Framework, NCSC CAF and Principles-Based Assurance, ETSI standards, TEA requirements, and recognised risk assessment methodologies. 7. Evaluation of risks associated with data hosting, data residency, and any offshoring proposals linked to Airwave services or supporting environments. This includes assessing legal, regulatory, operational, jurisdictional, and national security risks, and providing objective recommendations aligned with government policy and classification requirements. Additional information: 8. Support to the investigation and triage of security-related incidents affecting Airwave, including cryptographic issues, configuration anomalies, or suspected misuse. This includes assessing operational impact, interpreting threat or vulnerability intelligence, and supporting follow-up actions in coordination with relevant stakeholders.
Notice Details
Publication & Lifecycle
- Open Contracting ID
- ocds-h6vhtk-0699b5
- Publication Source
- Find A Tender Service
- Latest Notice
- https://www.find-tender.service.gov.uk/Notice/044782-2026
- Current Stage
- Planning
- All Stages
- Planning
Procurement Classification
- Notice Type
- Planning Notice
- Procurement Type
- Standard
- Procurement Category
- Services
- Procurement Method
- Not Specified
- Procurement Method Details
- Not specified
- Tender Suitability
- Not specified
- Awardee Scale
- Not specified
Common Procurement Vocabulary (CPV)
- CPV Divisions
32 - Radio, television, communication, telecommunication and related equipment
72 - IT services: consulting, software development, Internet and support
-
- CPV Codes
32510000 - Wireless telecommunications system
72220000 - Systems and technical consultancy services
Notice Value(s)
- Tender Value
- £3,054,540 £1M-£10M
- Lots Value
- Not specified
- Awards Value
- Not specified
- Contracts Value
- Not specified
Notice Dates
- Publication Date
- 15 May 20262 weeks ago
- Submission Deadline
- Not specified
- Future Notice Date
- 21 Jun 20263 weeks to go
- Award Date
- Not specified
- Contract Period
- Not specified - Not specified
- Recurrence
- Not specified
Notice Status
- Tender Status
- Planned
- Lots Status
- Planned
- Awards Status
- Not Specified
- Contracts Status
- Not Specified
Buyer & Supplier
Contracting Authority (Buyer)
- Main Buyer
- HOME OFFICE
- Contact Name
- Available with D3 Tenders Premium →
- Contact Email
- Available with D3 Tenders Premium →
- Contact Phone
- Available with D3 Tenders Premium →
Buyer Location
- Locality
- LONDON
- Postcode
- SW1P 4DF
- Post Town
- South West London
- Country
- England
-
- Major Region (ITL 1)
- TLI London
- Basic Region (ITL 2)
- TLI3 Inner London - West
- Small Region (ITL 3)
- TLI35 Westminster and City of London
- Delivery Location
- Not specified
-
- Local Authority
- Westminster
- Electoral Ward
- St James's
- Westminster Constituency
- Cities of London and Westminster
Further Information
Open Contracting Data Standard (OCDS)
View full OCDS Record for this contracting process
The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.
{
"tag": [
"compiled"
],
"id": "ocds-h6vhtk-0699b5-2026-05-15T09:54:11+01:00",
"date": "2026-05-15T09:54:11+01:00",
"ocid": "ocds-h6vhtk-0699b5",
"description": "If your organisation fits the procurement criteria set out in the description and would like to register your interest or have any questions for this opportunity please contact Adam.griffiths1@homeoffice.gov.uk.",
"initiationType": "tender",
"tender": {
"id": "project_19768",
"legalBasis": {
"id": "32014L0024",
"scheme": "CELEX"
},
"title": "Provision of Airwave Technical Assurance and Security Architecture Services (Information Assurance) for ESMCP",
"status": "planned",
"classification": {
"scheme": "CPV",
"id": "72220000",
"description": "Systems and technical consultancy services"
},
"mainProcurementCategory": "services",
"description": "The Home Office Airwave Security Team intends to re-procure the Technical Assurance and Security Architecture Services that will manage the end-to-end encrypted solution for specialist users as well as the interconnect solution between the Airwave service and the developing Emergency Services Network (ESN).",
"value": {
"amount": 3054540,
"currency": "GBP"
},
"lots": [
{
"id": "1",
"description": "The Home office are re-procuring the Technical Assurance and Security Architecture Services. Estimated date for release of tender is late June 2026 The requirement will be procured through the Government Commercial Agency's Cyber Security Services 3 (DPS) RM3764.3 _____________________________________________________________________________________________________________________ Suppliers will need to be registered to the RM3764.3 DPS and be identifiable against the following DPS filters in order to be invited to the tender exercise: NCSC Assured Services, Cyber Resilience Audit, Audit and Review, Cyber Essentials Plus, Clearance: Security Check, NPPV (Non-Police Personnel Vetting), ISO 27001, Networks, Database, Internet, Cloud, Communications, Government, Critical National Infrastructure, Police, Ambulance, Fire Services, Coast Guard \"No Preference\" to all other filters. ______________________________________________________________________________________________________________________ Home Office is not responsible for supplier registration. Suppliers will need to contact the Government Commercial Agency and follow its guidance. Suggested links: Government Commercial Agency website: www.gca.gov.uk Become a supplier on a Dynamic Purchasing System: www.gca.gov.uk/how-to-supply/dynamic-purchasing-system-dps Link to Cyber Security Services 3 DPS: https://supplierregistration.cabinetoffice.gov.uk/dps/RM3764.3?nav=0 In addition to registering to the DPS, the tender itself will be run using the Home Office's tender portal (https://homeoffice.app.jaggaer.com/web/login.html) suppliers will need to register to it. Instruction appends the front page to this portal. Overview of requirements The indicative scope of work includes, but not limited to, the following Airwave activities: 1. Provision of independent technical assurance across the Airwave end-to-end ecosystem, including TETRA radio services, bearer and transport technologies, and interfaces with ESN and other interconnected systems. This includes assessing availability, capacity, performance, and resilience impacts arising from proposed or implemented changes 2. Understanding encryption algorithms (note: we use TEA2 and AES), lifecycle considerations, and associated cryptographic service models 3. Assessment of customer element architectures, control room environments, gateways, clusters, and high-impact modifications (e.g. CE refresh or site changes), with a focus on identifying security risks, operational impacts, and emerging dependencies 4. Structured review and assessment of users and suppliers technical submissions, including designs, configuration artefacts, test plans, and assurance or accreditation evidence. This includes identifying security gaps, vulnerabilities, or weaknesses across radio, cryptographic, network, and interworking solutions 5. Production, review, and maintenance of security cases, risk assessments, assurance reports, and risk treatment recommendations. The service includes providing clear, evidence-based input to governance and decision-making forums supporting Airwave service continuity and transition activities. 6. Assessment of Airwave-related services and changes against relevant national and industry frameworks and standards, including the HMG Security Policy Framework, NCSC CAF and Principles-Based Assurance, ETSI standards, TEA requirements, and recognised risk assessment methodologies. 7. Evaluation of risks associated with data hosting, data residency, and any offshoring proposals linked to Airwave services or supporting environments. This includes assessing legal, regulatory, operational, jurisdictional, and national security risks, and providing objective recommendations aligned with government policy and classification requirements. Additional information: 8. Support to the investigation and triage of security-related incidents affecting Airwave, including cryptographic issues, configuration anomalies, or suspected misuse. This includes assessing operational impact, interpreting threat or vulnerability intelligence, and supporting follow-up actions in coordination with relevant stakeholders.",
"status": "planned"
}
],
"items": [
{
"id": "1",
"additionalClassifications": [
{
"scheme": "CPV",
"id": "32510000",
"description": "Wireless telecommunications system"
}
],
"deliveryAddresses": [
{
"region": "UK"
}
],
"relatedLot": "1"
}
],
"communication": {
"futureNoticeDate": "2026-06-22T00:00:00+01:00"
},
"coveredBy": [
"GPA"
]
},
"parties": [
{
"id": "GB-FTS-1007",
"name": "Home Office",
"identifier": {
"legalName": "Home Office"
},
"address": {
"streetAddress": "2 Marsham Street",
"locality": "London",
"region": "UK",
"postalCode": "SW1P 4DF",
"countryName": "United Kingdom"
},
"contactPoint": {
"name": "Adam Griffiths",
"email": "Adam.griffiths1@homeoffice.gov.uk"
},
"roles": [
"buyer"
],
"details": {
"url": "https://www.gov.uk/government/organisations/home-office",
"classifications": [
{
"id": "MINISTRY",
"scheme": "TED_CA_TYPE",
"description": "Ministry or any other national or federal authority, including their regional or local subdivisions"
},
{
"id": "03",
"scheme": "COFOG",
"description": "Public order and safety"
}
]
}
}
],
"buyer": {
"id": "GB-FTS-1007",
"name": "Home Office"
},
"language": "en"
}