---
title: "Provision of PCI-DSS Audit and ASV Scanning Services"
ocid: "ocds-r6ebe6-0000804089"
canonical_url: "https://d3tenders.com/contract/?ocid=ocds-r6ebe6-0000804089"
markdown_url: "https://d3tenders.com/contract/ocds-r6ebe6-0000804089.md"
json_url: "https://d3tenders.com/contract/ocds-r6ebe6-0000804089.json"
source: "Public Contracts Scotland"
current_stage: "Award"
buyer: "HISTORIC ENVIRONMENT SCOTLAND"
published: "2025-09-26"
---

# Provision of PCI-DSS Audit and ASV Scanning Services

Buyer: HISTORIC ENVIRONMENT SCOTLAND  
Current stage: Award  
OCID: ocds-r6ebe6-0000804089

[View canonical contract page](https://d3tenders.com/contract/?ocid=ocds-r6ebe6-0000804089)  
[Download OCDS JSON](https://d3tenders.com/contract/ocds-r6ebe6-0000804089.json)

## Summary

Historic Environment Scotland has issued a contract for the "Provision of PCI-DSS Audit and ASV Scanning Services," focusing on ensuring compliance with the Payment Card Industry Data Security Standard (PCI DSS). This procurement, categorized under services, primarily involves auditing and security vulnerability scanning across various eCommerce, card-present, and MOTO environments operated by the organisation. PGI - Protection Group International Ltd has been awarded the contract, with the tender process having started on 10th July 2025 and concluded with the contract signing on 26th September 2025. This open procurement process, defined as an 'open procedure', represents a commitment to transparent and competitive procurement practices aimed at ensuring high standards of security and compliance, located in the Edinburgh region in the United Kingdom.

This contract presents significant opportunities for businesses with expertise in cybersecurity, particularly those certified as Qualified Security Assessors (QSA) by the PCI Security Standards Council. It is a particularly lucrative opportunity for large-scale enterprises with the capability to conduct detailed assessments and provide continuous support in maintaining security compliance. Companies that can offer additional expertise in vulnerability assessments, particularly quarterly ASV scans of internet-facing systems, would also find this contract a valuable addition to their portfolio, potentially leading to further collaborations with Historic Environment Scotland. The contract's duration of 36 months with an option to extend for an additional 12 months allows for a long-term engagement, fostering growth and strengthening relationships between the supplier and buyer.

## Notice

Provision of PCI-DSS Audit and ASV Scanning Services

### Lot Information

Lot 1

Historic Environment Scotland (HES) seeks to appoint a Qualified Security Assessor (QSA) certified by the PCI Security Standards Council to perform an independent assessment to validate compliance with the Payment Card Industry Data Security Standard (PCI DSS) across all the environments that HES operates over - eCommerce, card present and MOTO. The appointed QSA will sign-off the Attestations of Compliance and document the findings in a Report of Compliance (RoC). If non-compliance is indicated, the QSA will provide advice and guidance on how to become compliant. They will, thereafter, re-assess for compliance. In addition, the appointed supplier will also be required to undertake quarterly ASV scans of HES' eCommerce environment to help identify vulnerabilities in our internet-facing systems, such as websites and networks, that could be exploited by attackers

Renewal: The initial contract term will be for 36 months, with HES having the option to extend the contract for an additional 12 months. The total possible contract term will therefore be 48 months (3+1 contract)

## Key Details

| Field | Value |
| --- | --- |
| Publication source | Public Contracts Scotland |
| Latest notice | https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=SEP540160 |
| Notice type | PCS Notice - Website Contract Award Notice |
| Procurement type | Standard |
| Procurement category | Services |
| Procurement method | Open |
| Procurement method details | Open procedure |
| Tender suitability | Not specified |
| Awardee scale | Large |
| All stages | Tender, Award |

## Dates

| Field | Value |
| --- | --- |
| Publication date | 26 Sep 2025 |
| Submission deadline | 1 Aug 2025 |
| Future notice date | Not specified |
| Award date | 26 Sep 2025 |
| Contract period | Not specified |
| Recurrence | Four years from the contract award date |

## Values

| Field | Value |
| --- | --- |
| Tender value | £65,000 |
| Lots value | £65,000 |
| Awards value | Not specified |
| Contracts value | £64,340 |

## Status

| Field | Value |
| --- | --- |
| Tender status | Complete |
| Lots status | Complete |
| Awards status | Not specified |
| Contracts status | Active |

## Buyer

| Field | Value |
| --- | --- |
| Main buyer | HISTORIC ENVIRONMENT SCOTLAND |
| Locality | EDINBURGH |
| Post town | Edinburgh |
| Postcode | EH9 1SH |
| Country | Scotland |
| ITL 1 | TLM Scotland |
| ITL 2 | TLM1 East Central Scotland |
| ITL 3 | TLM13 City of Edinburgh |
| Local authority | City of Edinburgh |
| Electoral ward | Southside/Newington |
| Westminster constituency | Edinburgh South |
| Delivery location | TLM Scotland |

## Supplier

| Field | Value |
| --- | --- |
| Number of suppliers | 1 |
| Supplier names | PGI - PROTECTION GROUP INTERNATIONAL |

## CPV Codes

### Divisions

- 79 - Business services: law, marketing, consulting, recruitment, printing and security

### Codes

- 79212000 - Auditing services

## Release History

- 26 Sep 2025 at 00:00 - Award - PCS Notice - Website Contract Award Notice - https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=SEP540160
- 10 Jul 2025 at 00:00 - Tender - PCS Notice - Website Contract Notice - https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=JUL534457

## Documents

- https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=8
  10th July 2025 - Fair Work First Questionnaire
- https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=9
  10th July 2025 - Flexible Working Questionnaire
- https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=10
  10th July 2025 - Form of Tender
- https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=11
  10th July 2025 - HES Suppliers Privacy Notice
- https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=1
  10th July 2025 - Document 1 - Instructions for Tenderers
- https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=2
  10th July 2025 - Document 2 - Specification of Requirements
- https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=3
  10th July 2025 - Document 3 - Quality Schedule
- https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=4
  10th July 2025 - Document 4- Pricing Schedule
- https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=5
  10th July 2025 - Document 5 - HES Terms and Conditions
- https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=6
  10th July 2025 - Document 6 - Self Declaration Form on Russian & Belarusian Links
- https://www.publiccontractsscotland.gov.uk/NoticeDownload/DownloadDocument.aspx?id=JUL534457&idx=7
  10th July 2025 - Document 7 - Prompt Payment Form
- https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=JUL534457
  Provision of PCI-DSS Audit and ASV Scanning Services - Provision of PCI-DSS Audit and ASV Scanning Services
- https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=SEP540160
  Provision of PCI-DSS Audit and ASV Scanning Services - Provision of PCI-DSS Audit and ASV Scanning Services

## Notice URLs

- http://
- http://historicenvironment.scot
- https://api.publiccontractsscotland.gov.uk/v1/Notice?id=ocds-r6ebe6-0000804089
- https://scotcourts.gov.uk/
- https://www.publiccontractsscotland.gov.uk/

## Provenance

This Markdown file is an alternate public rendering of the D3 Tenders contract record. The canonical page is https://d3tenders.com/contract/?ocid=ocds-r6ebe6-0000804089. The underlying structured data is available as OCDS JSON at https://d3tenders.com/contract/ocds-r6ebe6-0000804089.json.
