View

Cyber Security Frameworks UK: CSS3, G-Cloud 15 and More

Cyber Security Frameworks UK: CSS3, G-Cloud 15 and More

Date
Category
Procurement
Share

Public sector cyber security spend is rising, driven by NHS supply chain mandates, central government assurance programmes and the threat landscape facing councils, universities and defence. Almost all of it is bought through frameworks. If you sell cyber security services or technology to government, the routes you are on decide which opportunities you ever see.

This guide explains the cyber security frameworks that matter for UK suppliers in 2026: which are open to join now, which reopen on a schedule, what each requires, and how buyers use them to shortlist. It is written for cyber consultancies, managed security providers, penetration testers, security software vendors and IT resellers with a security offer.

Cyber security frameworks at a glance

  • Cyber Security Services 3 (RM3764.3) (operator: Government Commercial Agency; status: Open now, to 13 Feb 2029; best for: Cyber services to central and wider government)
  • Spark (RM6094) (operator: Government Commercial Agency; status: Open now, to 15 Feb 2029; best for: Innovative security products)
  • Dstl R-Cloud (operator: Defence Science and Technology Laboratory; status: Open during term; best for: Defence cyber research)
  • Quality Assurance and Testing 2 (RM6148) (operator: Government Commercial Agency; status: Open now, to 23 Feb 2029; best for: Security testing)
  • Non-Clinical Systems DPS (operator: NHS NOE CPC; status: Open now, to 18 Feb 2029; best for: NHS infrastructure and cyber)
  • Digital Technology and Cyber Services DPS (operator: Scottish Government; status: Open now; best for: Scottish public sector)
  • Digital Technology and Cyber Services DPS (operator: APUC; status: Open now, to 3 Jan 2027; best for: Scottish universities and colleges)
  • Cyber Security Services Framework (BLC-0201) (operator: Bluelight Commercial; status: Open framework, reopens periodically; best for: Policing and fire)
  • G-Cloud 15 (operator: Government Commercial Agency; status: Reopens at 18 and 36 months; best for: Cloud security and security software)
  • DOS7 (operator: Government Commercial Agency; status: Reopens every 18 months; best for: Security specialists and outcomes)
  • Technology Services 4 (RM6190) (operator: Government Commercial Agency; status: Open framework, next window not yet set; best for: Security within wider IT services)

Cyber Security Services 3 (RM3764.3): the main national route

Operator: Government Commercial Agency (formerly Crown Commercial Service)
Type: Dynamic purchasing system
Open until: 13 February 2029
Estimated value: £800 million
Buyers: UK central government, the wider public sector and charities

CSS3 is the principal national route for buying cyber security services in the UK public sector and the only dedicated, always-open cyber DPS run by central government. There is no cap on supplier numbers. Buyers must refresh their filtered supplier list every two working days when running a competition, so newly appointed suppliers become visible quickly.

What CSS3 covers

  • NCSC Assured Services: services for which the supplier holds NCSC assurance, such as CHECK, Cyber Incident Response, Cyber Incident Exercising, Assured Cyber Security Consultancy and Cyber Advisor.
  • Consultancy and advice: risk assessment, audit and review, security architecture, certification support, training, policy, supply chain analysis, cyber transformation and security strategy.
  • Penetration testing: including NCSC CHECK and IT health checks.
  • Incident management: incident response, threat intelligence, business continuity and disaster recovery.
  • Data destruction and IT sanitisation.
  • Managed security services: including CREST-accredited SOC and managed detection and response.

How buyers shortlist on CSS3

Buyers apply filters to build a shortlist before running a further competition. The filters you tick in your application decide which call-offs you are visible for. Key filters include service type, NCSC assurance status, accreditations such as CREST, IASME and ISO 27001, security clearance levels, geographic coverage, contract value bands and social value commitments. Central government buyers procuring NCSC-assured services are expected to use CSS3, which makes the assured filters commercially important.

How to apply

  1. Go to the GCA Supplier Registration Service page for RM3764.3.
  2. Download the bid pack and read the "Read First" document.
  3. Register and complete the selection questionnaire: company information, financial standing, relevant experience (typically three contracts from the last three years), certifications, insurance, services and filter selections.
  4. Submit and await assessment. Once appointed, you are live and visible to buyers.

Cyber Essentials is mandatory, and certificates must be current under the latest IASME question set. GCA also publishes template statements of requirements for CSS3 buyers covering security architecture, incident response, SOC, penetration testing, risk assessment and GovAssure. These are worth reading, because they show exactly how buyers will describe their needs.

Apply: supplierregistration.cabinetoffice.gov.uk/dps/RM3764.3

Spark (RM6094): for innovative security products

Operator: Government Commercial Agency
Type: Dynamic purchasing system
Open until: 15 February 2029

Spark is GCA's technology innovation marketplace. Security is one of its technology areas, covering AI-powered threat detection and response, new approaches to identity and access, PKI innovation, advanced cryptography including post-quantum approaches, and autonomous security tooling.

Applicants must evidence that their offer is a radical innovation (a genuinely new product or approach that replaces existing technology) or a disruptive innovation (one that creates a new market or displaces established players). Assessment takes up to 15 working days. Spark suits security vendors with something genuinely new. Suppliers with both an established service and an innovative product can put the service on CSS3 and the product on Spark.

Further information: GCA RM6094 Spark

Dstl R-Cloud: defence cyber research

Operator: Defence Science and Technology Laboratory
Type: Dynamic agreement
Buyers: Ministry of Defence and Dstl

R-Cloud is Dstl's marketplace for science and technology research. Suppliers can join at any point during its term and contract directly with the MoD on research tasks. Cyber-relevant areas include cyber research and development, threat intelligence and analysis, cryptographic research, secure systems and security engineering, and defensive cyber operations research.

Dstl issues task specifications to the supplier pool, and suppliers submit proposals. It suits organisations that can mobilise quickly on short, well-defined research tasks. Cyber Essentials and often Defence Cyber Certification apply, and some tasks need SC or DV cleared staff. Register on the Defence Sourcing Portal to apply.

Other open routes with cyber scope

Quality Assurance and Testing for IT Systems 2 (RM6148)

Open until 23 February 2029. Security testing is one of its core services alongside functional, performance and usability testing. It is a useful second route for penetration testing firms that also deliver wider assurance. GCA RM6148

NHS NOE CPC Non-Clinical Systems DPS

Open until 18 February 2029, with a projected value of £1.5 billion. Its IT infrastructure category includes cyber security services for NHS bodies. NOE CPC

Scottish Government and APUC Digital Technology and Cyber Services DPS

The two main open routes into Scottish public sector and Scottish higher education cyber spend. APUC's DPS ends on 3 January 2027, so apply soon. Scottish Government DPS | APUC

Bluelight Commercial Cyber Security Services Framework (BLC-0201)

An open framework for police and fire services, with a projected value of £70 million. It reopens to new suppliers at set points rather than continuously.

Major open frameworks: plan for the next window

G-Cloud 15

G-Cloud 15 was awarded in August 2026, replacing G-Cloud 14 and Cloud Compute 2. Over 4,000 suppliers won a place, around 90% of them SMEs. It is the first G-Cloud run as an open framework, so it reopens to new suppliers at 18 months and 36 months. G-Cloud 14 closes on 28 October 2026. Cyber Essentials is now required for all G-Cloud 15 suppliers, and Cyber Essentials Plus for Lots 1a and 1b. Cloud security, identity and security software vendors should prepare well ahead of the first reopening.

Digital Outcomes and Specialists 7

DOS7 replaced DOS6 in 2026 and runs for six years, reopening to new suppliers every 18 months. Security is explicitly in scope across outcomes and specialist roles. Suppliers that missed the first window should prepare now for the next refresh.

Technology Services 4 (RM6190)

Launched in December 2025 as an open framework of up to eight years. Cyber security is named in Lot 1 (technology strategy and service design) and Lot 4 (infrastructure management, including network and security management). Lower value sub-lots offer a lighter route for SMEs. The next supplier window has not been scheduled.

Network Services 4 (RM6377)

The replacement for Network Services 3, which covers secure connectivity, SD-WAN, SASE and managed network security. Procured in 2026, it will be a key route for network security providers for years to come.

Sector-specific cyber routes

  • Education: Jisc provides network connectivity and cyber security services to further and higher education, including the Janet network and a 24/7 incident response team. It is the dominant cyber buying route for universities and colleges, and Jisc runs further cyber frameworks for vulnerability assessment and simulated phishing.
  • NHS: The NHS Shared Business Services cyber security framework has expired and a refresh is expected. Watch it closely: NHS cyber spend is rising, and suppliers increasingly need to evidence resilience under the NHS Cyber Security Supply Chain Charter.
  • Councils and education buying groups: broader ICT routes from YPO, NEPO, ESPO, Kent Commercial Services and Pagabo often include security elements and are used by councils and schools.
  • Defence: the Defence Sourcing Portal, DASA open calls and R-Cloud are the main routes for novel defence cyber work. Expect Cyber Essentials and Defence Cyber Certification requirements.

What cyber suppliers need in place

  • Cyber Essentials, and ideally Cyber Essentials Plus: mandatory on CSS3 and G-Cloud 15, and expected on almost all government contracts.
  • ISO 27001: a common filter and evaluation point.
  • NCSC assurance: CHECK, CIR, Cyber Advisor and other NCSC schemes unlock the assured route on CSS3.
  • CREST accreditation: widely used for penetration testing and SOC services.
  • Security clearances: SC and DV cleared staff open up central government and defence work.
  • Strong case studies: most applications ask for three relevant contracts from the last three years.

Frequently asked questions

What is the main framework for public sector cyber security?

Cyber Security Services 3 (RM3764.3), run by the Government Commercial Agency, is the main national route. It is a DPS open to new suppliers until 13 February 2029.

How do I get on the Cyber Security Services 3 DPS?

Register on the GCA Supplier Registration Service, download the bid pack, and complete the selection questionnaire with your services, accreditations and filter selections. Cyber Essentials is mandatory.

Can cyber suppliers join G-Cloud 15 now?

Not until it reopens. G-Cloud 15 is an open framework that reopens to new suppliers at 18 and 36 months after award.

Do I need NCSC assurance to win government cyber work?

No, but it helps. CSS3 has both assured and non-assured routes. Central government buyers procuring NCSC-assured services are expected to use the assured route.

Which cyber framework suits an innovative security product?

Spark (RM6094) is designed for radical and disruptive innovations, including AI threat detection, identity, PKI and post-quantum cryptography.

How Athena can help

Athena Commercial has worked with cyber security providers across PKI, identity and access management, SOC, MDR and defence cyber. We secured a £5 million MoD contract for a cyber security client, delivered three successful framework awards for a cyber security IT reseller, and helped Unsung Ltd win defence cyber security contracts worth £2 million and £3 million. Our consultants are security cleared, and we hold places on G-Cloud 15, DOS7 and ESPO frameworks ourselves.

We support cyber suppliers with framework registrations including CSS3, G-Cloud and DOS, public sector bidding and cyber security policies for compliance. Read our guide to cyber security procurement, see our case studies, or contact us to plan your route to marke

Frequently Asked Questions

No items found.