This public procurement record has 1 release in its history.

Award

22 Sep 2026 at 11:07

Summary of the contracting process

The Driver and Vehicle Standards Agency (DVSA) procured computer audit and testing services for cyber-security purposes, specifically penetration testing and IT Health Checks. The work covers DVSA’s information-technology security requirements across the UK. The procurement is a services contract and was arranged as a call-off from the Crown Commercial Service Cyber Security 3 framework, RM3764iii. The published scope is brief, but identifies cyber-security testing as the purpose and the DVSA as both the buying organisation and the recorded supplier. The agency is based at Berkeley House, Croydon Street, Bristol. The requirement is therefore relevant to cyber-security consultancies and specialist information-security providers able to deliver penetration testing and IT health-check services for a UK national agency.

The procurement is complete and has been awarded through a limited procedure without prior publication of a competition, as a call-off from the CCS Cyber Security 3 framework RM3764iii. The stated rationale was that the procurement fell outside the relevant directive’s scope. The award date was 29 May 2026 and the contract is active. The contract value is £533,333.33 including the published currency of GBP. The award is recorded as active and names Driver and Vehicle Standards Agency as supplier. The procurement used one lot, which is recorded as cancelled, while the associated award and contract remain active. Price was the stated evaluation criterion. Eighteen bids were recorded for the lot. The process reached award without a separately published call for competition.

This procurement indicates demand from DVSA for sizeable, repeatable cyber-security assurance work delivered through a public-sector framework. A credible competitor would need demonstrable capability in penetration testing, IT Health Checks, computer auditing and technical security testing, with the capacity to support a national agency across the UK. Familiarity with framework call-offs and public-sector security requirements would be important, as would the ability to compete primarily on price where evaluation is price-led. The award shows that an SME can be recorded as the successful supplier, so the requirement is not limited to large technology integrators. Providers should be able to evidence suitably qualified security testers, robust reporting, dependable delivery controls and experience handling sensitive government or regulated information.

How relevant is this notice?

Notice Information

Notice Title

Penetration testing/IT Health Checks 2026

Notice Description

THIS NOTICE IS FOR TRANSPARANCY PURPOSES ONLY. THIS IS BEING PROCURED BY THE DVSA FOR CYBER SECURITY PURPOSES.

Lot Information

Lot 1

THIS NOTICE IS FOR TRANSPARANCY PURPOSES ONLY. THIS IS BEING PROCURED BY THE DVSA FOR CYBER SECURITY PURPOSES.

Procurement Information

THIS WAS A CALL - OFF FROM A CCS FRAMEWORK CYBER SECURITY 3 RM3764iii

Notice Details

Publication & Lifecycle

Open Contracting ID
ocds-h6vhtk-077739
Publication Source
Find A Tender Service
Latest Notice
https://www.find-tender.service.gov.uk/Notice/089503-2026
Current Stage
Award
All Stages
Award

Procurement Classification

Notice Type
Award Notice
Procurement Type
Standard
Procurement Category
Services
Procurement Method
Limited
Procurement Method Details
Award procedure without prior publication of a call for competition
Tender Suitability
Not specified
Awardee Scale
SME

Common Procurement Vocabulary (CPV)

CPV Divisions

72 - IT services: consulting, software development, Internet and support


CPV Codes

72800000 - Computer audit and testing services

Notice Value(s)

Tender Value
Not specified
Lots Value
Not specified
Awards Value
Not specified
Contracts Value
£533,333 £500K-£1M

Notice Dates

Publication Date
22 Sep 20262 weeks ago
Submission Deadline
Not specified
Future Notice Date
Not specified
Award Date
Not specified
Contract Period
Not specified - Not specified
Recurrence
Not specified

Notice Status

Tender Status
Complete
Lots Status
Cancelled
Awards Status
Active
Contracts Status
Active

Buyer & Supplier

Contracting Authority (Buyer)

Main Buyer
Driver and Vehicle Standards Agency
Contact Name
Available with D3 Tenders Premium →
Contact Email
Available with D3 Tenders Premium →
Contact Phone
Available with D3 Tenders Premium →

Buyer Location

Locality
BRISTOL
Postcode
BS5 0DA
Postcode Area
Bristol
Country
England

Major Region (ITL 1)
TLK South West (England)
Basic Region (ITL 2)
TLK5 West of England
Small Region (ITL 3)
TLK51 Bristol, City of
Delivery Location
Not specified

Local Authority
Bristol, City of
Electoral Ward
Lawrence Hill
Westminster Constituency
Bristol East

Supplier Information

Number of Suppliers
1
Supplier Name

Driver and Vehicle Standards Angency

Open Contracting Data Standard (OCDS)

View full OCDS Record for this contracting process

JSON Markdown

The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.

Loading OCDS record...