Award

Provision of PCI-DSS Audit and ASV Scanning Services

HISTORIC ENVIRONMENT SCOTLAND

This public procurement record has 2 releases in its history.

Summary of the contracting process

Historic Environment Scotland has issued a contract for the "Provision of PCI-DSS Audit and ASV Scanning Services," focusing on ensuring compliance with the Payment Card Industry Data Security Standard (PCI DSS). This procurement, categorized under services, primarily involves auditing and security vulnerability scanning across various eCommerce, card-present, and MOTO environments operated by the organisation. PGI - Protection Group International Ltd has been awarded the contract, with the tender process having started on 10th July 2025 and concluded with the contract signing on 26th September 2025. This open procurement process, defined as an 'open procedure', represents a commitment to transparent and competitive procurement practices aimed at ensuring high standards of security and compliance, located in the Edinburgh region in the United Kingdom.

This contract presents significant opportunities for businesses with expertise in cybersecurity, particularly those certified as Qualified Security Assessors (QSA) by the PCI Security Standards Council. It is a particularly lucrative opportunity for large-scale enterprises with the capability to conduct detailed assessments and provide continuous support in maintaining security compliance. Companies that can offer additional expertise in vulnerability assessments, particularly quarterly ASV scans of internet-facing systems, would also find this contract a valuable addition to their portfolio, potentially leading to further collaborations with Historic Environment Scotland. The contract's duration of 36 months with an option to extend for an additional 12 months allows for a long-term engagement, fostering growth and strengthening relationships between the supplier and buyer.

Find more tenders on our Open Data Platform.
How relevant is this notice?

D3 Tenders Premium

Win More Public Sector Contracts

AI-powered tender discovery, pipeline management, and market intelligence — everything you need to grow your public sector business.

Notice Title

Provision of PCI-DSS Audit and ASV Scanning Services

Notice Description

Provision of PCI-DSS Audit and ASV Scanning Services

Lot Information

Lot 1

Historic Environment Scotland (HES) seeks to appoint a Qualified Security Assessor (QSA) certified by the PCI Security Standards Council to perform an independent assessment to validate compliance with the Payment Card Industry Data Security Standard (PCI DSS) across all the environments that HES operates over - eCommerce, card present and MOTO. The appointed QSA will sign-off the Attestations of Compliance and document the findings in a Report of Compliance (RoC). If non-compliance is indicated, the QSA will provide advice and guidance on how to become compliant. They will, thereafter, re-assess for compliance. In addition, the appointed supplier will also be required to undertake quarterly ASV scans of HES' eCommerce environment to help identify vulnerabilities in our internet-facing systems, such as websites and networks, that could be exploited by attackers

Renewal: The initial contract term will be for 36 months, with HES having the option to extend the contract for an additional 12 months. The total possible contract term will therefore be 48 months (3+1 contract)

Publication & Lifecycle

Open Contracting ID
ocds-r6ebe6-0000804089
Publication Source
Public Contracts Scotland
Latest Notice
https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=SEP540160
Current Stage
Award
All Stages
Tender, Award

Procurement Classification

Notice Type
PCS Notice - Website Contract Award Notice
Procurement Type
Standard
Procurement Category
Services
Procurement Method
Open
Procurement Method Details
Open procedure
Tender Suitability
Not specified
Awardee Scale
Large

Common Procurement Vocabulary (CPV)

CPV Divisions

79 - Business services: law, marketing, consulting, recruitment, printing and security


CPV Codes

79212000 - Auditing services

Notice Value(s)

Tender Value
£65,000 Under £100K
Lots Value
£65,000 Under £100K
Awards Value
Not specified
Contracts Value
£64,340 Under £100K

Notice Dates

Publication Date
26 Sep 20255 months ago
Submission Deadline
1 Aug 2025Expired
Future Notice Date
Not specified
Award Date
26 Sep 20255 months ago
Contract Period
Not specified - Not specified
Recurrence
Four years from the contract award date

Notice Status

Tender Status
Complete
Lots Status
Complete
Awards Status
Not Specified
Contracts Status
Active

Contracting Authority (Buyer)

Main Buyer
HISTORIC ENVIRONMENT SCOTLAND
Contact Name
Not specified
Contact Email
procurement@hes.scot
Contact Phone
+44 1316688866

Buyer Location

Locality
EDINBURGH
Postcode
EH9 1SH
Post Town
Edinburgh
Country
Scotland

Major Region (ITL 1)
TLM Scotland
Basic Region (ITL 2)
TLM1 East Central Scotland
Small Region (ITL 3)
TLM13 City of Edinburgh
Delivery Location
TLM Scotland

Local Authority
City of Edinburgh
Electoral Ward
Southside/Newington
Westminster Constituency
Edinburgh South

Supplier Information

Number of Suppliers
1
Supplier Name

PGI - PROTECTION GROUP INTERNATIONAL

Further Information

Notice Documents

Open Contracting Data Standard (OCDS)

View full OCDS Record for this contracting process

Download

The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.

{
    "tag": [
        "compiled"
    ],
    "id": "ocds-r6ebe6-0000804089-2025-09-26T00:00:00Z",
    "date": "2025-09-26T00:00:00Z",
    "ocid": "ocds-r6ebe6-0000804089",
    "initiationType": "tender",
    "parties": [
        {
            "id": "org-127",
            "name": "Historic Environment Scotland",
            "identifier": {
                "legalName": "Historic Environment Scotland"
            },
            "address": {
                "streetAddress": "Longmore House, Salisbury Place",
                "locality": "Edinburgh",
                "region": "UKM75",
                "postalCode": "EH9 1SH"
            },
            "contactPoint": {
                "email": "procurement@hes.scot",
                "telephone": "+44 1316688866",
                "url": "https://www.publiccontractsscotland.gov.uk/"
            },
            "roles": [
                "buyer",
                "centralPurchasingBody"
            ],
            "details": {
                "classifications": [
                    {
                        "id": "National or federal agency/office",
                        "scheme": "TED_CA_TYPE"
                    },
                    {
                        "id": "Tourism, Heritage, Conservation, Built Environment",
                        "scheme": "COFOG"
                    },
                    {
                        "id": "Heritage, Conservation, Tourism, Built Environment",
                        "scheme": "COFOG"
                    },
                    {
                        "id": "Tourism, Heritage, Conservation, Built Environment",
                        "scheme": "COFOG"
                    },
                    {
                        "id": "Heritage, Tourism, Conservation, Built Environment",
                        "scheme": "COFOG"
                    }
                ],
                "url": "http://historicenvironment.scot"
            }
        },
        {
            "id": "org-10",
            "name": "Edinburgh Sheriff Court",
            "identifier": {
                "legalName": "Edinburgh Sheriff Court"
            },
            "address": {
                "streetAddress": "27 Chambers Street",
                "locality": "Edinburgh",
                "postalCode": "EH1 1LB"
            },
            "contactPoint": {
                "url": "http://"
            },
            "roles": [
                "reviewBody"
            ]
        },
        {
            "id": "org-21",
            "name": "Historic Environment Scotland",
            "identifier": {
                "legalName": "Historic Environment Scotland"
            },
            "address": {
                "streetAddress": "Longmore House, Salisbury Place",
                "locality": "Edinburgh",
                "region": "UKM75",
                "postalCode": "EH9 1SH"
            },
            "contactPoint": {
                "email": "procurement@hes.scot",
                "telephone": "+44 1316688866",
                "url": "http://"
            },
            "roles": [
                "buyer",
                "centralPurchasingBody"
            ],
            "details": {
                "classifications": [
                    {
                        "id": "National or federal agency/office",
                        "scheme": "TED_CA_TYPE"
                    },
                    {
                        "id": "Heritage, Tourism, Conservation, Built Environment",
                        "scheme": "COFOG"
                    },
                    {
                        "id": "Tourism, Heritage, Conservation, Built Environment",
                        "scheme": "COFOG"
                    },
                    {
                        "id": "Heritage, Conservation, Tourism, Built Environment",
                        "scheme": "COFOG"
                    },
                    {
                        "id": "Tourism, Conservation, Built Environment, Heritage",
                        "scheme": "COFOG"
                    }
                ],
                "url": "http://historicenvironment.scot"
            }
        },
        {
            "id": "org-36",
            "name": "PGI - Protection Group International Ltd",
            "identifier": {
                "legalName": "PGI - Protection Group International Ltd"
            },
            "address": {
                "streetAddress": "13-14 Angel Gate",
                "locality": "London",
                "region": "UKI",
                "postalCode": "EC1V 2PT"
            },
            "roles": [
                "supplier"
            ],
            "details": {
                "scale": "large",
                "url": "http://"
            }
        },
        {
            "id": "org-9",
            "name": "Edinburgh Sheriff Court",
            "identifier": {
                "legalName": "Edinburgh Sheriff Court"
            },
            "address": {
                "streetAddress": "Sheriff Court House, 27 Chambers Street",
                "locality": "EDINBURGH",
                "postalCode": "EH1 1LB"
            },
            "contactPoint": {
                "email": "enquiries@scotcourts.gov.uk",
                "telephone": "+44 1312252525",
                "url": "https://scotcourts.gov.uk/"
            },
            "roles": [
                "reviewBody",
                "reviewContactPoint"
            ]
        }
    ],
    "buyer": {
        "name": "Historic Environment Scotland",
        "id": "org-21"
    },
    "tender": {
        "id": "HES/C4312",
        "title": "Provision of PCI-DSS Audit and ASV Scanning Services",
        "description": "Provision of PCI-DSS Audit and ASV Scanning Services",
        "status": "complete",
        "items": [
            {
                "id": "1",
                "deliveryAddresses": [
                    {
                        "region": "UKM"
                    },
                    {
                        "region": "UKM"
                    }
                ],
                "relatedLot": "1"
            }
        ],
        "value": {
            "amount": 65000,
            "currency": "GBP"
        },
        "procurementMethod": "open",
        "procurementMethodDetails": "Open procedure",
        "mainProcurementCategory": "services",
        "submissionMethod": [
            "electronicSubmission"
        ],
        "submissionMethodDetails": "https://www.publiccontractsscotland.gov.uk/",
        "tenderPeriod": {
            "endDate": "2025-08-01T12:00:00Z"
        },
        "awardPeriod": {
            "startDate": "2025-08-01T12:00:00Z"
        },
        "documents": [
            {
                "id": "JUL534457",
                "documentType": "contractNotice",
                "title": "Provision of PCI-DSS Audit and ASV Scanning Services",
                "description": "Provision of PCI-DSS Audit and ASV Scanning Services",
                "url": "https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=JUL534457",
                "format": "text/html"
            },
            {
                "id": "JUL534457-1",
                "title": "Document 1 - Instructions for Tenderers",
                "url": "https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=1",
                "datePublished": "2025-07-10T15:52:57Z",
                "dateModified": "2025-07-10T15:52:57Z",
                "format": "application/vnd.openxmlformats-officedocument.wordprocessingml.document"
            },
            {
                "id": "JUL534457-2",
                "title": "Document 2 - Specification of Requirements",
                "url": "https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=2",
                "datePublished": "2025-07-10T15:52:57Z",
                "dateModified": "2025-07-10T15:52:57Z",
                "format": "application/vnd.openxmlformats-officedocument.wordprocessingml.document"
            },
            {
                "id": "JUL534457-3",
                "title": "Document 3 - Quality Schedule",
                "url": "https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=3",
                "datePublished": "2025-07-10T15:52:57Z",
                "dateModified": "2025-07-10T15:52:57Z",
                "format": "application/vnd.openxmlformats-officedocument.wordprocessingml.document"
            },
            {
                "id": "JUL534457-4",
                "title": "Document 4- Pricing Schedule",
                "url": "https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=4",
                "datePublished": "2025-07-10T15:52:57Z",
                "dateModified": "2025-07-10T15:52:57Z",
                "format": "application/vnd.openxmlformats-officedocument.spreadsheetml.sheet"
            },
            {
                "id": "JUL534457-5",
                "title": "Document 5 - HES Terms and Conditions",
                "url": "https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=5",
                "datePublished": "2025-07-10T15:52:57Z",
                "dateModified": "2025-07-10T15:52:57Z",
                "format": "application/pdf"
            },
            {
                "id": "JUL534457-6",
                "title": "Document 6 - Self Declaration Form on Russian & Belarusian Links",
                "url": "https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=6",
                "datePublished": "2025-07-10T15:52:57Z",
                "dateModified": "2025-07-10T15:52:57Z",
                "format": "application/vnd.openxmlformats-officedocument.wordprocessingml.document"
            },
            {
                "id": "JUL534457-7",
                "title": "Document 7 - Prompt Payment Form",
                "url": "https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=7",
                "datePublished": "2025-07-10T15:52:57Z",
                "dateModified": "2025-07-10T15:52:57Z",
                "format": "application/vnd.openxmlformats-officedocument.wordprocessingml.document"
            },
            {
                "id": "JUL534457-8",
                "title": "Fair Work First Questionnaire",
                "url": "https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=8",
                "datePublished": "2025-07-10T15:52:58Z",
                "dateModified": "2025-07-10T15:52:58Z",
                "format": "application/vnd.openxmlformats-officedocument.wordprocessingml.document"
            },
            {
                "id": "JUL534457-9",
                "title": "Flexible Working Questionnaire",
                "url": "https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=9",
                "datePublished": "2025-07-10T15:52:58Z",
                "dateModified": "2025-07-10T15:52:58Z",
                "format": "application/vnd.openxmlformats-officedocument.wordprocessingml.document"
            },
            {
                "id": "JUL534457-10",
                "title": "Form of Tender",
                "url": "https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=10",
                "datePublished": "2025-07-10T15:52:58Z",
                "dateModified": "2025-07-10T15:52:58Z",
                "format": "application/vnd.openxmlformats-officedocument.wordprocessingml.document"
            },
            {
                "id": "JUL534457-11",
                "title": "HES Suppliers Privacy Notice",
                "url": "https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=11",
                "datePublished": "2025-07-10T15:52:58Z",
                "dateModified": "2025-07-10T15:52:58Z",
                "format": "application/pdf"
            },
            {
                "id": "SEP540160",
                "documentType": "awardNotice",
                "title": "Provision of PCI-DSS Audit and ASV Scanning Services",
                "description": "Provision of PCI-DSS Audit and ASV Scanning Services",
                "url": "https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=SEP540160",
                "format": "text/html"
            }
        ],
        "lots": [
            {
                "id": "1",
                "description": "Historic Environment Scotland (HES) seeks to appoint a Qualified Security Assessor (QSA) certified by the PCI Security Standards Council to perform an independent assessment to validate compliance with the Payment Card Industry Data Security Standard (PCI DSS) across all the environments that HES operates over - eCommerce, card present and MOTO. The appointed QSA will sign-off the Attestations of Compliance and document the findings in a Report of Compliance (RoC). If non-compliance is indicated, the QSA will provide advice and guidance on how to become compliant. They will, thereafter, re-assess for compliance. In addition, the appointed supplier will also be required to undertake quarterly ASV scans of HES' eCommerce environment to help identify vulnerabilities in our internet-facing systems, such as websites and networks, that could be exploited by attackers",
                "status": "complete",
                "value": {
                    "amount": 65000,
                    "currency": "GBP"
                },
                "hasOptions": false,
                "submissionTerms": {
                    "variantPolicy": "notAllowed"
                },
                "contractPeriod": {
                    "durationInDays": 1440
                },
                "hasRenewal": true,
                "renewal": {
                    "description": "The initial contract term will be for 36 months, with HES having the option to extend the contract for an additional 12 months. The total possible contract term will therefore be 48 months (3+1 contract)"
                }
            }
        ],
        "bidOpening": {
            "date": "2025-08-01T12:00:00Z"
        },
        "contractTerms": {
            "hasElectronicPayment": true,
            "hasElectronicOrdering": true,
            "electronicInvoicingPolicy": "allowed"
        },
        "coveredBy": [
            "GPA"
        ],
        "otherRequirements": {
            "requiresStaffNamesAndQualifications": true
        },
        "selectionCriteria": {
            "criteria": [
                {
                    "type": "economic",
                    "description": "HES use Scotbis, an independent provider of business credit reports, to assess the financial standing of tenderers. The overall aim of this assessment is to ensure, as far as possible, that any potential Supplier will not have financial difficulties that endanger their ability to perform the Contract. If financial information cannot be gained from that source Historic Environment Scotland will request that you provide full audited accounts for the last full financial year. If Suppliers cannot provide any of the assurances as detailed above, and it is determined by HES that your financial strength is not adequate, then your company may not pass the financial evaluation. If you can provide the assurances as detailed above, HES may explore these options with you before determining whether your company can be taken forward in this procurement exercise. Bank details may also be sought to support the above.",
                    "minimum": "Employers Liability Insurance - 5 million GDP Public Liability Insurance - 10 million GDP Professional Indemnity - 5 million GBP"
                }
            ]
        },
        "submissionTerms": {
            "languages": [
                "en"
            ],
            "bidValidityPeriod": {
                "durationInDays": 90
            }
        },
        "classification": {
            "id": "79212000",
            "scheme": "CPV"
        },
        "hasRecurrence": true,
        "recurrence": {
            "description": "Four years from the contract award date"
        }
    },
    "language": "EN",
    "description": "(SC Ref:811439)",
    "links": [
        {
            "rel": "canonical",
            "href": "https://api.publiccontractsscotland.gov.uk/v1/Notice?id=ocds-r6ebe6-0000804089"
        },
        {
            "rel": "canonical",
            "href": "https://api.publiccontractsscotland.gov.uk/v1/Notice?id=ocds-r6ebe6-0000804089"
        }
    ],
    "noticetype": "PCS Notice - Website Contract Award Notice",
    "awards": [
        {
            "id": "HES/C/4312",
            "suppliers": [
                {
                    "id": "org-36",
                    "name": "PGI - Protection Group International Ltd"
                }
            ],
            "relatedLots": [
                "1"
            ]
        }
    ],
    "contracts": [
        {
            "id": "HES/C/4312",
            "awardID": "HES/C/4312",
            "status": "active",
            "value": {
                "amount": 64340,
                "currency": "GBP"
            },
            "dateSigned": "2025-09-26T00:00:00Z"
        }
    ],
    "bids": {
        "statistics": [
            {
                "id": "81",
                "measure": "bids",
                "value": 2,
                "relatedLot": "1"
            },
            {
                "id": "82",
                "measure": "smeBids",
                "value": 0,
                "relatedLot": "1"
            },
            {
                "id": "83",
                "measure": "foreignBidsFromEU",
                "value": 0,
                "relatedLot": "1"
            },
            {
                "id": "84",
                "measure": "foreignBidsFromNonEU",
                "value": 2,
                "relatedLot": "1"
            },
            {
                "id": "85",
                "measure": "electronicBids",
                "value": 2,
                "relatedLot": "1"
            }
        ]
    }
}