---
title: "Continuation of Support for cyber assessment framework in Local Government"
ocid: "ocds-h6vhtk-06f933"
canonical_url: "https://d3tenders.com/contract/?ocid=ocds-h6vhtk-06f933"
markdown_url: "https://d3tenders.com/contract/ocds-h6vhtk-06f933.md"
json_url: "https://d3tenders.com/contract/ocds-h6vhtk-06f933.json"
source: "Find A Tender Service"
current_stage: "Award"
buyer: "WLGA"
published: "2026-09-14"
---

# Continuation of Support for cyber assessment framework in Local Government

Buyer: WLGA  
Current stage: Award  
OCID: ocds-h6vhtk-06f933

[View canonical contract page](https://d3tenders.com/contract/?ocid=ocds-h6vhtk-06f933)  
[Download OCDS JSON](https://d3tenders.com/contract/ocds-h6vhtk-06f933.json)

## Summary

WLGA is procuring continuing cyber assessment framework support for Welsh local government. The service supports implementation of the Cyber Assessment Framework (CAF) across Welsh local authorities and Fire and Rescue Services. It covers organisational assessments, quality reviews, critical system mapping, independent feedback and improvement planning, supported by programme methodologies, tooling, templates, dashboards and sector intelligence. The work is intended to strengthen cyber resilience, maintain assurance and identify and reduce risks affecting critical public services. This is a cyber support and consultancy service, classified under CPV 72600000. Delivery is across Wales, for participating local authorities and Fire and Rescue Services. WLGA is the buying organisation and the requirement relates to the next phase of its existing CAF programme.

The procurement is complete and has been awarded through a direct award to Bridewell Consulting Ltd. The award covers one lot and has a net value of £107,100, or £128,520 including VAT. The contract period is 1 October 2026 to 31 March 2027, with a planned signature date of 24 September 2026. The award was published on 14 September 2026. WLGA chose a direct award because changing supplier was considered likely to cause incompatibility, disproportionate technical difficulty, cyber risk and disruption to the existing programme. The decision relies on Bridewell’s established programme knowledge, embedded methods and infrastructure. The procurement is above the relevant threshold and the contract is for services.

This requirement indicates demand for suppliers able to deliver structured cyber assurance across multiple public-sector organisations, particularly in local government and emergency services. A credible competitor would need experience of the Cyber Assessment Framework or comparable cyber maturity and resilience programmes, including assessments, quality assurance, critical system mapping, independent review and improvement planning. It would also need to manage consistent methodologies, reusable tooling, templates, dashboards and sector-level intelligence across participating bodies. Strong understanding of public-sector governance, critical service dependencies and cyber risk management would be important, as would the capacity to coordinate delivery where client organisations have competing commitments. The incumbent’s advantage came from accumulated programme knowledge and continuity, so future competitors would need a robust approach to mobilisation, knowledge transfer, comparability of results and protection of security information.

## Notice

Notice to Direct award contract for the continuation of works to support the implementation of the Cyber assessment framework (CAF) in Welsh local government, provided by Bridewell Consulting Ltd. Direct award justification - Continuation of Existing Supply Change of supplier would cause incompatibility or disproportionate technical difficulty. WLGA proposes to directly award the next phase of the Cyber Assessment Framework (CAF) support contract to Bridewell Consulting Ltd on the basis that changing supplier at this stage would create significant technical, operational and cyber security risks that outweigh any potential benefits of a competitive procurement exercise. The supplier has developed substantial programme-specific knowledge, methodologies, tooling, templates, dashboards and sector intelligence throughout delivery of the CAF programme across Welsh local authorities and Fire and Rescue Services. The supplier has supported organisations through assessment, quality review, critical system mapping, independent feedback and improvement planning activities. As a result, they now possesses a unique understanding of the sector baseline, organisational maturity positions, critical system dependencies and programme governance arrangements. Replacing the current supplier with an alternative supplier would create incompatibility with the existing programme infrastructure, methodologies and assessment approaches already embedded across participating organisations. Significant effort would be required to transfer knowledge, validate prior outputs and align a new supplier to established ways of working, creating a risk of inconsistency in assessment outcomes and reducing comparability with work already completed. This would undermine the continuity and integrity of the national programme. A change of supplier would also introduce material cyber risk. The current programme supports the cyber resilience of critical public services across Wales and provides visibility of sector-wide risks, vulnerabilities and areas requiring intervention. Any interruption to delivery, loss of organisational context or reduction in oversight during transition could weaken security visibility across the sector and delay the identification and mitigation of emerging risks. A prolonged mobilisation period would leave organisations without the level of support and assurance currently available through the programme. In addition, a transition to a new supplier would cause significant service disruption. A full procurement exercise, mobilisation period and knowledge transfer programme would delay delivery of planned activities and divert resources away from improvement work. Participating organisations would experience disruption at a critical stage in their CAF journey, potentially delaying assurance activities, improvement planning and the implementation of risk reduction measures

### Procurement Information

The supplier has developed substantial programme-specific knowledge, methodologies, tooling, templates, dashboards and sector intelligence throughout delivery of the CAF programme across Welsh local authorities and Fire and Rescue Services. The supplier has supported organisations through assessment, quality review, critical system mapping, independent feedback and improvement planning activities. As a result, they now possesses a unique understanding of the sector baseline, organisational maturity positions, critical system dependencies and programme governance arrangements. Replacing the current supplier with an alternative supplier would create incompatibility with the existing programme infrastructure, methodologies and assessment approaches already embedded across participating organisations. Significant effort would be required to transfer knowledge, validate prior outputs and align a new supplier to established ways of working, creating a risk of inconsistency in assessment outcomes and reducing comparability with work already completed. This would undermine the continuity and integrity of the national programme. A change of supplier would also introduce material cyber risk. The current programme supports the cyber resilience of critical public services across Wales and provides visibility of sector-wide risks, vulnerabilities and areas requiring intervention. Any interruption to delivery, loss of organisational context or reduction in oversight during transition could weaken security visibility across the sector and delay the identification and mitigation of emerging risks. A prolonged mobilisation period would leave organisations without the level of support and assurance currently available through the programme. In addition, a transition to a new supplier would cause significant service disruption. A full procurement exercise, mobilisation period and knowledge transfer programme would delay delivery of planned activities and divert resources away from improvement work. Participating organisations would experience disruption at a critical stage in their CAF journey, potentially delaying assurance activities, improvement planning and the implementation of risk reduction measures For these reasons, the contracting authority considers that competition is not feasible at this time without disproportionate disruption. This direct award is strictly limited to the period of the financial year 26-27, after which a review of activities and dependencies will be undertaken to allow for open market engagement in subsequent support engagements for cyber support in Welsh local government The contract duration reflects the minimum period necessary to ensure continuity within the current programme of work to avoid disruption and potential risk to cyber resilience

## Key Details

| Field | Value |
| --- | --- |
| Publication source | Find A Tender Service |
| Latest notice | https://www.find-tender.service.gov.uk/Notice/086890-2026 |
| Notice type | UK5 - Transparency Notice |
| Procurement type | Standard |
| Procurement category | Services |
| Procurement method | Direct |
| Procurement method details | Direct award |
| Tender suitability | Not specified |
| Awardee scale | Large |
| All stages | Award |

## Dates

| Field | Value |
| --- | --- |
| Publication date | 14 Sep 2026 |
| Submission deadline | Not specified |
| Future notice date | Not specified |
| Award date | Not specified |
| Contract period | 1 Oct 2026 - 31 Mar 2027 |
| Recurrence | Not specified |

## Values

| Field | Value |
| --- | --- |
| Tender value | Not specified |
| Lots value | Not specified |
| Awards value | £107,100 |
| Contracts value | Not specified |

## Status

| Field | Value |
| --- | --- |
| Tender status | Complete |
| Lots status | Complete |
| Awards status | Pending |
| Contracts status | Not specified |

## Buyer

| Field | Value |
| --- | --- |
| Main buyer | WLGA |
| Locality | CARDIFF |
| Postcode area | Cardiff |
| Postcode | CF10 5BF |
| Country | Wales |
| ITL 1 | TLL Wales |
| ITL 2 | TLL5 South East Wales |
| ITL 3 | TLL52 Cardiff and Vale of Glamorgan |
| Local authority | Cardiff |
| Electoral ward | Butetown |
| Westminster constituency | Cardiff South and Penarth |
| Delivery location | Not specified |

## Supplier

| Field | Value |
| --- | --- |
| Number of suppliers | 1 |
| Supplier names | Bridewell Consulting Limited |

## CPV Codes

### Divisions

- 72 - IT services: consulting, software development, Internet and support

### Codes

- 72600000 - Computer support and consultancy services

## Release History

- 14 Sep 2026 at 13:55 - Award - UK5 - Transparency Notice - https://www.find-tender.service.gov.uk/Notice/086890-2026

## Documents

- https://www.find-tender.service.gov.uk/Notice/086890-2026
  14th September 2026 - Transparency notice on Find a Tender

## Notice URLs

- http://www.wlga.wales
- https://www.bridewell.com/
- https://www.legislation.gov.uk/ukpga/2023/54/contents

## Provenance

This Markdown file is an alternate public rendering of the D3 Tenders contract record. The canonical page is https://d3tenders.com/contract/?ocid=ocds-h6vhtk-06f933. The underlying structured data is available as OCDS JSON at https://d3tenders.com/contract/ocds-h6vhtk-06f933.json.
