This public procurement record has 1 release in its history.

Award

14 Sep 2026 at 13:55

Summary of the contracting process

WLGA is procuring continuing cyber assessment framework support for Welsh local government. The service supports implementation of the Cyber Assessment Framework (CAF) across Welsh local authorities and Fire and Rescue Services. It covers organisational assessments, quality reviews, critical system mapping, independent feedback and improvement planning, supported by programme methodologies, tooling, templates, dashboards and sector intelligence. The work is intended to strengthen cyber resilience, maintain assurance and identify and reduce risks affecting critical public services. This is a cyber support and consultancy service, classified under CPV 72600000. Delivery is across Wales, for participating local authorities and Fire and Rescue Services. WLGA is the buying organisation and the requirement relates to the next phase of its existing CAF programme.

The procurement is complete and has been awarded through a direct award to Bridewell Consulting Ltd. The award covers one lot and has a net value of £107,100, or £128,520 including VAT. The contract period is 1 October 2026 to 31 March 2027, with a planned signature date of 24 September 2026. The award was published on 14 September 2026. WLGA chose a direct award because changing supplier was considered likely to cause incompatibility, disproportionate technical difficulty, cyber risk and disruption to the existing programme. The decision relies on Bridewell’s established programme knowledge, embedded methods and infrastructure. The procurement is above the relevant threshold and the contract is for services.

This requirement indicates demand for suppliers able to deliver structured cyber assurance across multiple public-sector organisations, particularly in local government and emergency services. A credible competitor would need experience of the Cyber Assessment Framework or comparable cyber maturity and resilience programmes, including assessments, quality assurance, critical system mapping, independent review and improvement planning. It would also need to manage consistent methodologies, reusable tooling, templates, dashboards and sector-level intelligence across participating bodies. Strong understanding of public-sector governance, critical service dependencies and cyber risk management would be important, as would the capacity to coordinate delivery where client organisations have competing commitments. The incumbent’s advantage came from accumulated programme knowledge and continuity, so future competitors would need a robust approach to mobilisation, knowledge transfer, comparability of results and protection of security information.

How relevant is this notice?

Notice Title

Continuation of Support for cyber assessment framework in Local Government

Notice Description

Notice to Direct award contract for the continuation of works to support the implementation of the Cyber assessment framework (CAF) in Welsh local government, provided by Bridewell Consulting Ltd. Direct award justification - Continuation of Existing Supply Change of supplier would cause incompatibility or disproportionate technical difficulty. WLGA proposes to directly award the next phase of the Cyber Assessment Framework (CAF) support contract to Bridewell Consulting Ltd on the basis that changing supplier at this stage would create significant technical, operational and cyber security risks that outweigh any potential benefits of a competitive procurement exercise. The supplier has developed substantial programme-specific knowledge, methodologies, tooling, templates, dashboards and sector intelligence throughout delivery of the CAF programme across Welsh local authorities and Fire and Rescue Services. The supplier has supported organisations through assessment, quality review, critical system mapping, independent feedback and improvement planning activities. As a result, they now possesses a unique understanding of the sector baseline, organisational maturity positions, critical system dependencies and programme governance arrangements. Replacing the current supplier with an alternative supplier would create incompatibility with the existing programme infrastructure, methodologies and assessment approaches already embedded across participating organisations. Significant effort would be required to transfer knowledge, validate prior outputs and align a new supplier to established ways of working, creating a risk of inconsistency in assessment outcomes and reducing comparability with work already completed. This would undermine the continuity and integrity of the national programme. A change of supplier would also introduce material cyber risk. The current programme supports the cyber resilience of critical public services across Wales and provides visibility of sector-wide risks, vulnerabilities and areas requiring intervention. Any interruption to delivery, loss of organisational context or reduction in oversight during transition could weaken security visibility across the sector and delay the identification and mitigation of emerging risks. A prolonged mobilisation period would leave organisations without the level of support and assurance currently available through the programme. In addition, a transition to a new supplier would cause significant service disruption. A full procurement exercise, mobilisation period and knowledge transfer programme would delay delivery of planned activities and divert resources away from improvement work. Participating organisations would experience disruption at a critical stage in their CAF journey, potentially delaying assurance activities, improvement planning and the implementation of risk reduction measures

Procurement Information

The supplier has developed substantial programme-specific knowledge, methodologies, tooling, templates, dashboards and sector intelligence throughout delivery of the CAF programme across Welsh local authorities and Fire and Rescue Services. The supplier has supported organisations through assessment, quality review, critical system mapping, independent feedback and improvement planning activities. As a result, they now possesses a unique understanding of the sector baseline, organisational maturity positions, critical system dependencies and programme governance arrangements. Replacing the current supplier with an alternative supplier would create incompatibility with the existing programme infrastructure, methodologies and assessment approaches already embedded across participating organisations. Significant effort would be required to transfer knowledge, validate prior outputs and align a new supplier to established ways of working, creating a risk of inconsistency in assessment outcomes and reducing comparability with work already completed. This would undermine the continuity and integrity of the national programme. A change of supplier would also introduce material cyber risk. The current programme supports the cyber resilience of critical public services across Wales and provides visibility of sector-wide risks, vulnerabilities and areas requiring intervention. Any interruption to delivery, loss of organisational context or reduction in oversight during transition could weaken security visibility across the sector and delay the identification and mitigation of emerging risks. A prolonged mobilisation period would leave organisations without the level of support and assurance currently available through the programme. In addition, a transition to a new supplier would cause significant service disruption. A full procurement exercise, mobilisation period and knowledge transfer programme would delay delivery of planned activities and divert resources away from improvement work. Participating organisations would experience disruption at a critical stage in their CAF journey, potentially delaying assurance activities, improvement planning and the implementation of risk reduction measures For these reasons, the contracting authority considers that competition is not feasible at this time without disproportionate disruption. This direct award is strictly limited to the period of the financial year 26-27, after which a review of activities and dependencies will be undertaken to allow for open market engagement in subsequent support engagements for cyber support in Welsh local government The contract duration reflects the minimum period necessary to ensure continuity within the current programme of work to avoid disruption and potential risk to cyber resilience

Publication & Lifecycle

Open Contracting ID
ocds-h6vhtk-06f933
Publication Source
Find A Tender Service
Latest Notice
https://www.find-tender.service.gov.uk/Notice/086890-2026
Current Stage
Award
All Stages
Award

Procurement Classification

Notice Type
UK5 - Transparency Notice
Procurement Type
Standard
Procurement Category
Services
Procurement Method
Direct
Procurement Method Details
Direct award
Tender Suitability
Not specified
Awardee Scale
Large

Common Procurement Vocabulary (CPV)

CPV Divisions

72 - IT services: consulting, software development, Internet and support


CPV Codes

72600000 - Computer support and consultancy services

Notice Value(s)

Tender Value
Not specified
Lots Value
Not specified
Awards Value
£107,100 £100K-£500K
Contracts Value
Not specified

Notice Dates

Publication Date
14 Sep 2026Yesterday
Submission Deadline
Not specified
Future Notice Date
Not specified
Award Date
Not specified
Contract Period
1 Oct 2026 - 31 Mar 2027 6-12 months
Recurrence
Not specified

Notice Status

Tender Status
Complete
Lots Status
Complete
Awards Status
Pending
Contracts Status
Not Specified

Contracting Authority (Buyer)

Main Buyer
WLGA
Contact Name
Available with D3 Tenders Premium →
Contact Email
Available with D3 Tenders Premium →
Contact Phone
Available with D3 Tenders Premium →

Buyer Location

Locality
CARDIFF
Postcode
CF10 5BF
Postcode Area
Cardiff
Country
Wales

Major Region (ITL 1)
TLL Wales
Basic Region (ITL 2)
TLL5 South East Wales
Small Region (ITL 3)
TLL52 Cardiff and Vale of Glamorgan
Delivery Location
Not specified

Local Authority
Cardiff
Electoral Ward
Butetown
Westminster Constituency
Cardiff South and Penarth

Supplier Information

Number of Suppliers
1
Supplier Name

Bridewell Consulting Limited

Further Information

Open Contracting Data Standard (OCDS)

View full OCDS Record for this contracting process

JSON Markdown

The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.

Loading OCDS record...