Response 4103492
Response to request for information
Reference
4103492
Response date
15 September 2026
Request
I am writing to request information under the Freedom of Information Act 2000 regarding the Council's procurement and use of cyber security services. Where available, please provide details for the current contract, supplier and procurement arrangements relating to the following.
- Which procurement platform(s) does the Council use for IT and cyber security procurements?
- Which framework agreements does the Council typically use for cyber security services?
- Penetration Testing and Security Testing. Please provide:
- Current supplier name
- Contract start date
- Contract expiry date
- Contract value or annual spend
- Procurement route or framework used
- Whether services include infrastructure, web application, mobile, cloud, CHECK, IT Health Check or other penetration testing services.
- Cyber Essentials and Cyber Essentials Plus. Please provide:
- Current supplier name
- Contract value or annual spend
- Contract start date
- Contract expiry date
- Procurement route or framework used
- ISO 27001. Please provide details of any external supplier used for:
- ISO 27001 consultancy
- ISO 27001 implementation support
- ISO 27001 internal audit
- ISO 27001 certification preparation
- Including:
- Supplier name
- Contract value or annual spend
- Contract expiry date
- Procurement route used
- Including:
- PCI DSS. Please provide details of any external supplier used for:
- PCI DSS consultancy
- PCI DSS QSA services
- PCI DSS penetration testing
- PCI DSS compliance support
- Including:
- Supplier name
- Contract value or annual spend
- Contract expiry date
- Procurement route used
- Incident Response and Digital Forensics
- Including:
- Please provide details of any external supplier used for:
- Incident response retainers
- Digital forensics retainers
- DFIR services
- Cyber breach response services
- Including:
- Supplier name
- Contract value or annual spend
- Contract expiry date
- Procurement route used
- Including:
- Future Procurement Activity. Where known, please provide:
- The expected renewal or re-procurement date for each service
- Whether the Council currently expects to re-tender, extend or recompete the contract
- Relevant Departments. Please provide the name of the department or team responsible for:
- Cyber Security / Information Security
- ICT / IT Services
- Procurement and Commercial Management
I am not requesting personal information. Generic team names or departmental contact details are sufficient.
Response
- Which procurement platform(s) does the Council use for IT and cyber security procurements? Our Procurement is outsourced to Nottinghamshire County Council. (NCC).
- Which framework agreements does the Council typically use for cyber security services? G cloud, CCS both outsourced to NCC.
- Penetration Testing and Security Testing. Please provide:
- Current supplier name. Intertek & Secarma.
- Contract start date. April 2026.
- Contract expiry date. April 2029.
- Contract value or annual spend. Intertek £2000 pa + VAT. Secarma 3716.67 + VAT.
- Procurement route or framework used. Used three comparable quotes.
- Whether services include infrastructure, web application, mobile, cloud, CHECK, IT Health Check or other penetration testing services. Infrastructure, web application included, pen testing.
- Cyber Essentials and Cyber Essentials Plus. Not Applicable.
- ISO 27001. Not Applicable
- PCI DSS. Please provide details of any external supplier used for:
- PCI DSS consultancy.
- PCI DSS QSA services.
- PCI DSS penetration testing.
- PCI DSS compliance support.
- Including:
- Supplier name. Nessus
- Contract value or annual spend. £3,867.99 + VAT
- Contract expiry date. 25 August 2026
- Procurement route used. Used three comparable quotes.
- Including:
- Incident Response and Digital Forensics. Please provide details of any external supplier used for:
- Incident response retainers
- Digital forensics retainers
- DFIR services
- Cyber breach response services
- Including:
- Supplier name. Cutter Group.
- Contract value or annual spend. £10,000 + VAT.
- Contract expiry date. 1 August 2027.
- Procurement route used. Used three comparable quotes.
- Including:
- Future Procurement Activity. Where known, please provide:
- Whether the Council currently expects to re-tender, extend or recompete the contract.
Intertek – Re-tender
Nessus – Re-tender
Cutter Group – Re-tender
- Relevant Departments. Please provide the name of the department or team responsible for:
- Cyber Security / Information Security. ICT.
- ICT / IT Services. ICT.
- Procurement and Commercial Management. Nottinghamshire County Council.