Questions & Answers
Procurements started on or after 24 February 2025 by UK-wide authorities and bodies in England, Wales, and Northern Ireland follow the Procurement Act 2023, with notices published on Find a Tender. Procedures commenced before that date proceed under the Public Contracts Regulations 2015. Devolved Scottish public authorities procure under the Procurement Reform (Scotland) Act 2014 and the Public Contracts (Scotland) Regulations 2015.
The State of Cyber Security Procurement in UK
Updated
Procurement rules and official tender sources
Public procurement across the UK operates under specific statutory frameworks depending on the administration and the date the procedure commenced. The Procurement Act 2023 applies to procurements started on or after 24 February 2025 by contracting authorities in England, Wales and Northern Ireland, as well as UK-wide public bodies. Notices under this legislation appear on Find a Tender, the UK government's central digital platform. Earlier procurements that began prior to 24 February 2025 continue under the Public Contracts Regulations 2015 until their completion.
Devolved Scottish public bodies are not covered by the Procurement Act 2023. Instead, Scottish authorities procure under the Procurement Reform (Scotland) Act 2014 and the Public Contracts (Scotland) Regulations 2015. To reflect these routes, the Lucius catalog indexes open notices across the UK from Find a Tender, Contracts Finder, Public Contracts Scotland, and TED, drawing from a live index of 230,000+ public tenders from 15 official sources in 170+ countries.
UK cyber security tender volumes
On 24 September 2026, across the whole UK, the catalog held 5 open notices whose text mentions cyber security, drawn from Find a Tender, Contracts Finder and TED. The other 1 have deadlines more than a year away. In the same scope on that date, 1,654 notices were open across all sectors.
These notices cover broad technology and defensive requirements across public authorities. Teams tracking these opportunities need early visibility to prepare their responses before submission deadlines approach.
Example open cyber security tenders
Within open cyber security notices from buyers in the UK, matched by the catalog's Cyber Security sector tag or specific keywords such as cyber, cybersecurity, information security, or penetration testing, several tenders were active on that date:
- Cloud Backup & Cyber Recovery Solution, issued by Tonbridge and Malling Borough Council, closing in October 2026.
- Penetration Testing and Cybersecurity Assessment, issued by Cairn Housing Association, closing in October 2026.
- Outsourced ICT Infrastructure Management and associated Services, issued by Worcestershire Acute Hospitals NHS Trust, closing in September 2026.
- CA18385, Nova Education Trust Tender for the provision of IT Security and Internet Filtering Platform, issued by Nova Trust, closing in September 2026.
- ICT Managed Services and Consultancy Support, issued by Stowmarket Town Council, closing in October 2026.
Contracting authorities buying cyber security
Across all open notices in the cyber security example set, 9 different buyers were publishing opportunities. The most active organisations were Nova Trust with 2 notices, alongside Better Security Better Care, Cairn Housing Association, Clackmannanshire Council, and Durham County Council, each with 1 notice.
These contracting bodies include local authorities, housing associations, and multi-academy educational trusts. Each organisation issues bespoke tender documentation containing distinct specifications, commercial conditions, and response instructions.
Preparing cyber security proposals with Lucius AI
Bid and tender writers typically work through the buyer's questions, instructions, word limits and required attachments. Lucius AI reads a public-sector tender pack and extracts every requirement into a register, complete with a citation pointing to the exact page each requirement comes from. It also builds a compliance matrix from that requirement register, helping teams check that every requirement in the pack has an answer before submission.
Tender writers must also plan each answer against the evaluation criteria stated in the pack. Lucius AI provides a bid/no-bid verdict on the tender and scans the contract terms for commercial risk, highlighting clauses such as liquidated damages, liability caps and indemnities. This ensures writers and commercial leads understand the contractual framework before developing detailed technical solutions.
Drafting from past bids and exporting responses
When writing method statements and quality answers, tender writers frequently adapt material from earlier submissions. Lucius AI drafts responses from the company's own past bids, which are stored and organised inside its Bid Library. Writers can take these drafts, align them to the buyer's questions, and tailor technical descriptions to match specific project outcomes.
Once draft answers and compliance checks are compiled, teams need to format and share their outputs. Lucius AI exports its work to Word, Excel and PDF formats, allowing writers to finalise documentation in standard desktop applications before uploading to buyer portals.
Bidders into UK cyber security contracts compete under Find a Tender, Contracts Finder, JCT/NEC4 frameworks and Crown Commercial Service agreements. Sector-specific compliance bars include CHECK / CREST status, Cyber Essentials Plus, ISO 27001 and the NCSC Cyber Assessment Framework. When a tender asks for any of them, Lucius lists that requirement with its page and a quote from the source.
Lucius vs generic LLMs for tender writing in Cyber Security / UK
Instead of checking specifications and clauses manually line by line, bid and tender writers upload the cyber security pack directly into Lucius AI. The software automatically extracts requirements into a cited register and scans contract terms for liabilities, leaving teams free to refine their responses.
Got a tender? Upload it and see your compliance score.
Try Free