Service market

Vulnerability assessment contracts

UK public sector · 51 contracts awarded in the 12 months to 6 October 2026

Covering 600+ buyer portals · 5 years of records · Updated 6 October 2026 · How we count

Contracts awarded
51
Last 12 months
Median contract
£69k
Recorded value
Recorded value
£11.3m
49 of 50 main-service contracts have a published value
Buyers
42
Suppliers
17

BidSkim assigns contracts to services from the notice text. How services are assigned

What stands out

  • The five suppliers that won the most vulnerability assessment contracts took 63% of them (32 of 51).
  • The median contract, £69k, is 37% below the median across it & software contracts (£110k).
  • Intellectual Property Office awarded 8% of the vulnerability assessment contracts (4 of 51).

Who buys vulnerability assessment

By contracts awarded, the 12 months to 6 October 2026.

  1. 1Intellectual Property Office4 contracts
  2. 2H M REVENUE & CUSTOMS2 contracts
  3. 3Companies House2 contracts
  4. 4Financial Conduct Authority2 contracts
  5. 5Office for National Statistics2 contracts
  6. 6Police Digital Service2 contracts
  7. 7NHS England2 contracts
  8. 8NPL Management Limited1 contract
  9. 9NHS Blood and Transplant1 contract
  10. 10Driver and Vehicle Licensing Agency1 contract

Top vulnerability assessment contractors by contracts won

The 12 months to 6 October 2026.

  1. 1Softcat13 contracts
  2. 2Phoenix Software8 contracts
  3. 3Computacenter4 contracts
  4. 4Insight4 contracts
  5. 5Specialist Computer Centres (SCC)3 contracts
  6. 6Boxxe3 contracts
  7. 7Bechtle2 contracts
  8. 8Bytes Software Services2 contracts
  9. 9Black Duck Software Limited1 contract
  10. 10Academia1 contract

Latest and largest awards

Each links to the official notice.

Latest

Largest

Contracts awarded by quarter

14Q4 2025*9Q1 202612Q2 202616Q3 20260Q4 2026*
* part quarter

Where the contracts were awarded

England 40 · Wales 8 · Scotland 3

London8Wales8Yorkshire and The Humber4South West4North East3East Midlands2West Midlands2South East2Scotland2UK-wide or not stated16

What is included

Software that regularly scans the estate for known vulnerabilities and misconfigurations and tracks their fixes. It includes configuration benchmarking and hardening assessment tools.

  • Vulnerability scanners (e.g. Rapid7 Nexpose)
  • Enterprise or national vulnerability management licences
  • Configuration benchmarks and hardening assessment (CIS SecureSuite)

What is not included

  • People-led penetration testing and IT health checks -> it.cyber.penetration-testing
  • Public cloud posture scanning -> it.cyber.cloud-security-posture
  • Deploying patches on a specific application -> another family: application support and maintenance

Often bought by the same buyers