This public procurement record has 5 releases in its history.

Award

10 Sep 2026 at 13:00

Award

29 Jul 2026 at 12:25

AwardUpdate

28 Jul 2026 at 12:44

Award

22 Jul 2026 at 15:31

Planning

15 Jul 2026 at 13:59

Summary of the contracting process

The Ministry of Defence procured the Defence Out of Bounds Update Service (DOBUS), a managed cyber-security patch acquisition, assurance, hosting and distribution service for Defence. The work covers a secure, accredited platform for acquiring, verifying and distributing trusted software and firmware patches across Defence networks, including repository management, secure hosting, service desk and out-of-hours support, performance reporting, governance, security compliance, change management and continuous improvement. The service supports systems handling information at OFFICIAL and SECRET classifications and is intended to strengthen cyber resilience and vulnerability remediation. This is a cyber-security and network-management service, classified under CPV 72511000. Delivery is across the United Kingdom, for Defence systems and networks operated by the Ministry of Defence.

The procurement is complete and was awarded to Boxxe Limited on 29 July 2026 under a direct award procedure for defence and security operational reasons, relying on the Procurement Act 2023 and Schedule 5, paragraph 20. The award value is £3,942,100.69 excluding VAT, or £4,730,520.83 including VAT. The contract was signed on 11 August 2026 and runs from 12 August 2026 to 31 July 2029. It is a single-lot requirement. The direct award rationale cites the need for service continuity, operational capability, security and interoperability with established Defence environments while longer-term options are assessed. Contract performance is measured through monthly patching-case response and resolution, platform uptime and delivery performance.

This requirement shows sustained Ministry of Defence demand for suppliers able to operate secure, highly available cyber-security services within sensitive Defence environments. A credible competitor for the next market opportunity would need expertise in software and firmware patch acquisition, verification, assurance, repository management and controlled distribution across networks handling OFFICIAL and SECRET information. Relevant capability also includes secure hosting, accredited platforms, service-desk and out-of-hours support, incident diagnosis, patch-case resolution, uptime management, reporting, governance, security compliance, change control and continuous service improvement. Experience integrating with established Defence infrastructure and technical processes would be important, as would the capacity to maintain uninterrupted service while supporting operationally critical systems. Suppliers should be able to evidence robust cyber resilience, vulnerability-remediation and performance-management arrangements.

How relevant is this notice?

Notice Title

715884522 - DOBUS Core Contract

Notice Description

Provision of the Defence Out of Bounds Update Service (DOBUS), a managed cyber security patch acquisition, assurance, hosting and distribution service for Defence. The requirement includes the operation and maintenance of a secure and accredited platform for the acquisition, verification and distribution of software and firmware patches and updates across Defence networks. Services include secure hosting, repository management, service desk support, out-of-hours assistance, performance reporting, governance, security compliance, change management and continuous service improvement. The Supplier shall provide a highly available service supporting Defence systems operating at OFFICIAL and SECRET classifications, ensuring timely access to trusted patch content to support cyber resilience and vulnerability remediation across Defence.

Procurement Information

1. Legal Basis This contract will be awarded in accordance with Section 41 of the Procurement Act 2023 (Direct Award in Special Cases), relying on Schedule 5, Paragraph 20. The Authority is satisfied that this is a defence authority contract and a defence and security contract within the meaning of Section 7 of the Procurement Act 2023. The requirement supports the maintenance and ongoing operation of Defence systems through the provision, assurance and distribution of security updates and patches and is considered to fall within Section 7(1)(c) as services necessary for the maintenance of military and/or sensitive equipment. The Authority is satisfied that direct award is necessary to maintain and enhance the operational capability, effectiveness, readiness, safety and security of the Armed Forces during the contract period. 2. Justification The Authority considers that continuation of the service is necessary to maintain operational effectiveness and support the ongoing management of cyber security risks. A sustained reduction in the service would increase operational risk and reduce the efficiency and resilience of Defence digital and information systems. The contract includes the continued sustainment and enhancement of the existing service to ensure it continues to meet Defence requirements. The Authority has therefore determined that a direct award is necessary and proportionate to maintain the operational effectiveness, resilience and security of this Defence capability while future requirements and procurement options are considered. DOBUS is a Defence cyber security service that supports the provision of software and firmware security updates across Defence systems and contributes to the security and resilience of Defence digital services. DOBUS supports the provision of software and firmware updates across Defence systems and contributes to the effective operation and resilience of Defence digital services. The Authority considers that continuation of the service is necessary to maintain operational effectiveness and ensure continuity of service delivery. This capability supports the ongoing management and distribution of software updates across the Defence estate and remains a critical component of wider Defence digital services. The current capability has been established within Defence infrastructure, processes and technical environments over an extended period. The Authority has identified significant interoperability, transition and delivery considerations associated with introducing alternative arrangements within the required timescales. Consequently, further work is required to assess future technical options, undertake market engagement and develop an informed approach to any future procurement activity. The contract includes sustainment and enhancement activities essential to support the continued operation and development of the service while this work is undertaken. The Authority has therefore determined that a direct award is necessary and proportionate to maintain service continuity and operational effectiveness whilst future requirements and procurement options are developed and assessed. In addition to the grounds relied upon under Schedule 5, Paragraph 20 and Section 7(1)(c) of the Procurement Act 2023, the Authority also considers that technical reasons support the direct award. The services are necessary for the maintenance and ongoing operation of military and sensitive equipment and systems. The capability is closely integrated within Defence technical environments and processes, and any disruption, compromise or unplanned transition would present risks to operational capability, service continuity and security. 3. Reasons for Duration The contract term of 3 years (01 Aug 2026 to 31 July 2029), with break points at the end of Years 1 and 2, represents the period required to maintain continuity of this cyber security capability whilst undertaking service sustainment activities, reviewing longer-term requirements, and assessing future procurement options. The contract duration balances operational necessity with the Authority's intention to consider future competitive procurement arrangements and longer-term capability requirements. 4. Future Procurement During the contract term, the Authority intends to undertake additional market engagement, technical assessment and option analysis to inform the long-term Enterprise Patching strategy. Subject to the outcome of this activity and future approvals, the Authority may undertake a future competitive procurement for the enduring capability.

Publication & Lifecycle

Open Contracting ID
ocds-h6vhtk-06cbff
Publication Source
Find A Tender Service
Latest Notice
https://www.find-tender.service.gov.uk/Notice/085869-2026
Current Stage
Award
All Stages
Planning, Award

Procurement Classification

Notice Type
UK7 - Contract Details Notice
Procurement Type
Standard
Procurement Category
Services
Procurement Method
Direct
Procurement Method Details
Direct award
Tender Suitability
Not specified
Awardee Scale
Large

Common Procurement Vocabulary (CPV)

CPV Divisions

72 - IT services: consulting, software development, Internet and support


CPV Codes

72511000 - Network management software services

Notice Value(s)

Tender Value
£4,900,000 £1M-£10M
Lots Value
Not specified
Awards Value
£3,942,100 £1M-£10M
Contracts Value
£3,942,100 £1M-£10M

Notice Dates

Publication Date
10 Sep 20265 days ago
Submission Deadline
Not specified
Future Notice Date
20 Jul 2026Expired
Award Date
29 Jul 20261 months ago
Contract Period
12 Aug 2026 - 31 Jul 2029 2-3 years
Recurrence
Not specified

Notice Status

Tender Status
Complete
Lots Status
Complete
Awards Status
Active
Contracts Status
Active

Contracting Authority (Buyer)

Main Buyer
Ministry of Defence
Contact Name
Available with D3 Tenders Premium →
Contact Email
Available with D3 Tenders Premium →
Contact Phone
Available with D3 Tenders Premium →

Buyer Location

Locality
CORSHAM
Postcode
SN13 9NR
Postcode Area
Swindon
Country
England

Major Region (ITL 1)
TLK South West (England)
Basic Region (ITL 2)
TLK7 Gloucestershire and Wiltshire
Small Region (ITL 3)
TLK72 Wiltshire
Delivery Location
Not specified

Local Authority
Wiltshire
Electoral Ward
Corsham Without
Westminster Constituency
Chippenham

Supplier Information

Number of Suppliers
1
Supplier Name

boxxe Limited

Further Information

Notice Documents

Open Contracting Data Standard (OCDS)

View full OCDS Record for this contracting process

JSON Markdown

The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.

Loading OCDS record...