Service market

Penetration testing contracts

UK public sector · 94 contracts awarded in the 12 months to 6 October 2026

Covering 600+ buyer portals · 5 years of records · Updated 6 October 2026 · How we count

Contracts awarded
94
Last 12 months
Median contract
£73k
Recorded value
Recorded value
£23.3m
82 of 91 main-service contracts have a published value
Buyers
70
Suppliers
61

BidSkim assigns contracts to services from the notice text. How services are assigned

What stands out

  • The five suppliers that won the most penetration testing contracts took 26% of them (24 of 94).
  • The median contract, £73k, is 34% below the median across it & software contracts (£110k).
  • Ministry of Defence awarded 10% of the penetration testing contracts (9 of 94).

Who buys penetration testing

By contracts awarded, the 12 months to 6 October 2026.

  1. 1Ministry of Defence9 contracts
  2. 2Driver and Vehicle Standards Agency6 contracts
  3. 3Government Digital Service3 contracts
  4. 4UK Shared Business Services (UK SBS)3 contracts
  5. 5Ofgem2 contracts
  6. 6Home Office2 contracts
  7. 7Ambulance Radio Programme2 contracts
  8. 8United Lincolnshire Teaching Hospitals NHS Trust2 contracts
  9. 9National Savings & Investments (NS&I)2 contracts
  10. 10The National Archives2 contracts

Top penetration testing contractors by contracts won

The 12 months to 6 October 2026.

  1. 1Salus Cyber6 contracts
  2. 2Prism Infosec Ltd6 contracts
  3. 3Dionach Ltd4 contracts
  4. 4Sapphire Technologies Ltd4 contracts
  5. 5Intertek4 contracts
  6. 6Bridewell Consulting Limited3 contracts
  7. 7Coda Security Limited3 contracts
  8. 8QinetiQ3 contracts
  9. 9NCC Group3 contracts
  10. 10Not Specified3 contracts

Latest and largest awards

Each links to the official notice.

Latest

Largest

Contracts awarded by quarter

19Q4 2025*33Q1 202615Q2 202627Q3 20260Q4 2026*
* part quarter

Where the contracts were awarded

England 88 · Wales 4 · Northern Ireland 1 · Scotland 1

London20South West9East of England7North West6East Midlands4South East4Wales4North East3Yorkshire and The Humber3West Midlands2Scotland1Northern Ireland1UK-wide or not stated30

What is included

Independent technical testing of systems and networks by ethical hackers to find weaknesses that can be exploited. It includes IT health checks (ITHC) and red and purple team exercises.

  • Penetration testing
  • IT health checks (ITHC)
  • Ethical hacking
  • Red and purple team exercises
  • Breach and attack simulation and automated adversary emulation

What is not included

  • Automated vulnerability scanning software -> it.cyber.vulnerability-management
  • Document-based assurance reviews such as GovAssure -> it.cyber.security-consultancy-assurance
  • Cyber Essentials Plus assessment -> it.cyber.cyber-essentials-certification

Often bought by the same buyers