Service market

Cyber security assurance contracts

UK public sector · 133 contracts awarded in the 12 months to 6 October 2026

Covering 600+ buyer portals · 5 years of records · Updated 6 October 2026 · How we count

Contracts awarded
133
Last 12 months
Median contract
£83k
Recorded value
Recorded value
£108m
121 of 126 main-service contracts have a published value
Buyers
80
Suppliers
72

BidSkim assigns contracts to services from the notice text. How services are assigned

What stands out

  • The five suppliers that won the most cyber security assurance contracts took 32% of them (42 of 133).
  • Contracts awarded per quarter fell 45% from the first half of the period to the second.
  • The median contract, £83k, is 24% below the median across it & software contracts (£110k).

Who buys cyber security assurance

By contracts awarded, the 12 months to 6 October 2026.

  1. 1Financial Conduct Authority8 contracts
  2. 2Police Digital Service7 contracts
  3. 3UK Shared Business Services (UK SBS)6 contracts
  4. 4Department for Science, Innovation and Technology (DSIT)6 contracts
  5. 5Ministry of Defence5 contracts
  6. 6Cabinet Office5 contracts
  7. 7UK Health Security Agency4 contracts
  8. 8Driver and Vehicle Standards Agency3 contracts
  9. 9Driver and Vehicle Licensing Agency3 contracts
  10. 10City of London Corporation3 contracts

Top cyber security assurance contractors by contracts won

The 12 months to 6 October 2026.

  1. 1Actica Consulting Ltd11 contracts
  2. 2NCC Group11 contracts
  3. 3Softcat9 contracts
  4. 4Permanent Futures6 contracts
  5. 5Bridewell Consulting Limited5 contracts
  6. 6Avella Security Limited5 contracts
  7. 7LOGIQ CONSULTING LTD4 contracts
  8. 8PA Consulting3 contracts
  9. 9KPMG3 contracts
  10. 10Arcanum Information Security Ltd3 contracts

Latest and largest awards

Each links to the official notice.

Latest

Largest

Contracts awarded by quarter

31Q4 2025*40Q1 202640Q2 202622Q3 20260Q4 2026*
* part quarter

Where the contracts were awarded

England 117 · Scotland 7 · Wales 6 · Northern Ireland 3

London47South West7South East6Wales5North West4East Midlands3East of England3Northern Ireland3Scotland2North East1West Midlands1UK-wide or not stated51

What is included

Advice on an organisation's security: strategy and target operating model, policy writing, ISO 27001 readiness, benchmarking, independent assurance reviews such as GovAssure, and interim security specialists.

  • Information security strategy and target operating model
  • Security policy development
  • ISO 27001 scoping and gap analysis
  • Cyber maturity benchmarking
  • Independent assurance reviews (GovAssure, pre-production readiness reviews)
  • Interim and contract security managers and engineers

What is not included

  • Technical testing -> it.cyber.penetration-testing
  • Cyber Essentials assessment -> it.cyber.cyber-essentials-certification
  • Implementing a specific security product -> that product's service
  • Courses and crisis exercises -> it.cyber.security-training-exercises
  • 24x7 monitoring by a provider -> it.cyber.managed-soc-mdr
  • GRC and ISMS software -> it.ent.governance-risk-compliance
  • Forensic analysis for criminal investigations -> it.lob.digital-forensics-management

Often bought by the same buyers