This public procurement record has 1 release in its history.

Summary of the contracting process

Scottish Fire and Rescue Service procured independent penetration testing of its ICT estate. The work is to identify and assess vulnerabilities, then provide actionable recommendations to improve vulnerability management. Its purpose is to strengthen protection against cyber threats, improve security maturity, and help the service prioritise and address vulnerabilities according to real-world risk and exploitability. This is cyber security testing and consultancy (CPV 72820000), delivered for the service in Scotland. Scotland Excel managed the procurement on the service’s behalf but is not a party to, or manager of, the resulting contract.

The procurement is complete and the contract was awarded to CyberLab Security Limited. The contract is active and was signed on 16 September 2026, at a value of £51,000. The competition was run as an open procedure under the Scottish Government’s dynamic purchasing system for cyber security and resilience services, with participation restricted to suppliers that had responded to the earlier expression of interest; all such suppliers were invited to bid. Nine bids were received. The process covered one lot. No award date, contract duration or evaluation criteria are stated in the available process information.

This award shows demand from Scottish Fire and Rescue Service for independent penetration testing that produces practical, risk-based recommendations, rather than vulnerability findings alone. A credible competitor for the same requirement would need to assess a public service’s ICT estate, identify vulnerabilities in the context of real-world threats and exploitability, and help the buyer prioritise remediation and strengthen ongoing vulnerability management. The work also calls for an understanding of cyber security maturity and the resilience of digital infrastructure. The contract was awarded through a dynamic purchasing system, following an expression-of-interest stage, so suppliers would need to qualify for the relevant cyber security and resilience route and be able to compete in a call-off competition. The nine bids indicate competition for this requirement.

How relevant is this notice?

Notice Information

Notice Title

Provision of Penetration Testing

Notice Description

Call off from Lot 4 - "Cyber Security and Resilience Services" of the Scottish Government Dynamic Purchasing System (DPS) for the provision of Penetration Testing. Competition run via PCS-T. The purpose of this requirement is to provide independent assessment of SFRS's ICT estate vulnerabilities and providing actionable recommendations to support continuous improvement in vulnerability management. The requirement is critical to maintaining the security and resilience of SFRS digital infrastructure and will support the organisation in: -Strengthening protection against evolving cyber threats - Improving overall cyber security maturity - Ensuring vulnerabilities are identified, prioritised, and addressed based on real world risk and exploitability Participation in this tender was restricted to suppliers that responded to the Expression of Interest under reference ITT_62970, all of whom were invited to submit a bid.

Lot Information

Lot 1

Call off from Lot 4 - "Cyber Security and Resilience Services" of the Scottish Government Dynamic Purchasing System (DPS) for the provision of Penetration Testing. Competition run via PCS-T. Only suppliers that responded to the expression of interest were invited to participate in this procurement.. Scotland Excel was acting on behalf of Scottish Fire and Rescue Service in the execution of this tender but will not be party to the contract or the management of the contract throughout its lifetime.

Notice Details

Publication & Lifecycle

Open Contracting ID
ocds-r6ebe6-0000843120
Publication Source
Public Contracts Scotland
Latest Notice
https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=SEP565122
Current Stage
Award
All Stages
Award

Procurement Classification

Notice Type
PCS Notice - Website Contract Award Notice
Procurement Type
Dynamic
Procurement Category
Services
Procurement Method
Open
Procurement Method Details
Open procedure
Tender Suitability
Not specified
Awardee Scale
Large

Common Procurement Vocabulary (CPV)

CPV Divisions

72 - IT services: consulting, software development, Internet and support


CPV Codes

72820000 - Computer testing services

Notice Value(s)

Tender Value
Not specified
Lots Value
Not specified
Awards Value
Not specified
Contracts Value
£51,000 Under £100K

Notice Dates

Publication Date
23 Sep 20262 weeks ago
Submission Deadline
Not specified
Future Notice Date
Not specified
Award Date
Not specified
Contract Period
Not specified - Not specified
Recurrence
Not specified

Notice Status

Tender Status
Complete
Lots Status
Complete
Awards Status
Not Specified
Contracts Status
Active

Buyer & Supplier

Contracting Authority (Buyer)

Main Buyer
Scottish Fire and Rescue Service
Contact Name
Available with D3 Tenders Premium →
Contact Email
Available with D3 Tenders Premium →
Contact Phone
Available with D3 Tenders Premium →

Buyer Location

Locality
CAMBUSLANG
Postcode
G72 7NA
Postcode Area
Glasgow
Country
Scotland

Major Region (ITL 1)
TLM Scotland
Basic Region (ITL 2)
TLM9 Southern Scotland
Small Region (ITL 3)
TLM95 South Lanarkshire
Delivery Location
TLM Scotland

Local Authority
South Lanarkshire
Electoral Ward
Cambuslang East
Westminster Constituency
Rutherglen

Supplier Information

Number of Suppliers
1
Supplier Name

CYBERLAB SECURITY LIMITED

Further Information

Notice Documents

  • https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=SEP565122
    Provision of Penetration Testing - Call off from Lot 4 - "Cyber Security and Resilience Services" of the Scottish Government Dynamic Purchasing System (DPS) for the provision of Penetration Testing. Competition run via PCS-T. The purpose of this requirement is to provide independent assessment of SFRS's ICT estate vulnerabilities and providing actionable recommendations to support continuous improvement in vulnerability management. The requirement is critical to maintaining the security and resilience of SFRS digital infrastructure and will support the organisation in: -Strengthening protection against evolving cyber threats - Improving overall cyber security maturity - Ensuring vulnerabilities are identified, prioritised, and addressed based on real world risk and exploitability Participation in this tender was restricted to suppliers that responded to the Expression of Interest under reference ITT_62970, all of whom were invited to submit a bid.

Open Contracting Data Standard (OCDS)

View full OCDS Record for this contracting process

JSON Markdown

The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.

Loading OCDS record...