FOI release

Procurement

Case reference FOI2026/01939

Received 10 September 2026

Published 1 October 2026

Request

I am writing to request information under the Freedom of Information Act 2000 regarding the Council's procurement and use of cyber security services.

Where available, please provide details for the current contract(s), supplier(s) and procurement arrangements relating to the following services.

1. Procurement Routes

  a)  Which procurement platform(s) does the Council use for IT and cyber security procurements (for example Contracts Finder, Proactis, YORtender, Chest, Delta eSourcing or similar)?

  b)  Which framework agreements does the Council typically use for cyber security services (for example G-Cloud, DOS, CCS frameworks, Bloom or equivalent)?

 

2. Penetration Testing and Security Testing

Please provide:

  *   Current supplier name(s)

  *   Contract start date

  *   Contract expiry date

  *   Contract value or annual spend

  *   Procurement route or framework used

  *   Whether services include infrastructure, web application, mobile, cloud, CHECK, IT Health Check or other penetration testing services

 

3. Cyber Essentials and Cyber Essentials Plus

Please provide:

  *   Current supplier name

  *   Contract value or annual spend

  *   Contract start date

  *   Contract expiry date

  *   Procurement route or framework used

 

4. ISO 27001

Please provide details of any external supplier used for:

  *   ISO 27001 consultancy

  *   ISO 27001 implementation support

  *   ISO 27001 internal audit

  *   ISO 27001 certification preparation

Including:

  *   Supplier name

  *   Contract value or annual spend

  *   Contract expiry date

  *   Procurement route used

 

5. PCI DSS

Please provide details of any external supplier used for:

  *   PCI DSS consultancy

  *   PCI DSS QSA services

  *   PCI DSS penetration testing

  *   PCI DSS compliance support

Including:

  *   Supplier name

  *   Contract value or annual spend

  *   Contract expiry date

  *   Procurement route used

 

6. Incident Response and Digital Forensics

Please provide details of any external supplier used for:

  *   Incident response retainers

  *   Digital forensics retainers

  *   DFIR services

  *   Cyber breach response services

Including:

  *   Supplier name

  *   Contract value or annual spend

  *   Contract expiry date

  *   Procurement route used

 

7. Future Procurement Activity

Where known, please provide:

  *   The expected renewal or re-procurement date for each service

  *   Whether the Council currently expects to re-tender, extend or recompete the contract

 

8. Relevant Departments

Please provide the name of the department or team responsible for:

  *   Cyber Security / Information Security

  *   ICT / IT Services

  *   Procurement and Commercial Management

                                                                        

Response

Thank you for your recent request under the Freedom of Information Act.

Please find the answers to your queries below:

I am writing to you under the Freedom of Information Act to request the following information:

I am writing to request information under the Freedom of Information Act 2000 regarding the Council's procurement and use of cyber security services.

Where available, please provide details for the current contract(s), supplier(s) and procurement arrangements relating to the following services.

1. Procurement Routes

  a)  Which procurement platform(s) does the Council use for IT and cyber security procurements (for example Contracts Finder, Proactis, YORtender, Chest, Delta eSourcing or similar)?

This is dependant on the procurement process undertaken. The procurement platform the Council uses is InTend.

  b)  Which framework agreements does the Council typically use for cyber security services (for example G-Cloud, DOS, CCS frameworks, Bloom or equivalent)?

G-Cloud.

2. Penetration Testing and Security Testing

Please provide:

  *   Current supplier name(s)

  *   Contract start date

  *   Contract expiry date

  *   Contract value or annual spend

  *   Procurement route or framework used

  *   Whether services include infrastructure, web application, mobile, cloud, CHECK, IT Health Check or other penetration testing services

Supplier: NTA Monitor Limited

Last used: Purchase Order was sent in January 2026 following this year’s desktop exercise

No ongoing contracts used, we engage the market and review options for each IT Health Check.

Desktop exercises are used to evaluate the market

Services used: IT Health Check]

 

3. Cyber Essentials and Cyber Essentials Plus

Please provide:

  *   Current supplier name

  *   Contract value or annual spend

  *   Contract start date

  *   Contract expiry date

  *   Procurement route or framework used

The Council does not have Cyber Essentials or Cyber Essentials Plus.

 

4. ISO 27001

Please provide details of any external supplier used for:

  *   ISO 27001 consultancy

  *   ISO 27001 implementation support

  *   ISO 27001 internal audit

  *   ISO 27001 certification preparation

Including:

  *   Supplier name

  *   Contract value or annual spend

  *   Contract expiry date

  *   Procurement route used

The Council does not have ISO 27001.

 

5. PCI DSS

Please provide details of any external supplier used for:

  *   PCI DSS consultancy

  *   PCI DSS QSA services

  *   PCI DSS penetration testing

  *   PCI DSS compliance support

Including:

  *   Supplier name

  *   Contract value or annual spend

  *   Contract expiry date

  *   Procurement route used

Guildford Borough Council self-certifies due to the kinds of transactions we process.

 

6. Incident Response and Digital Forensics

Please provide details of any external supplier used for:

  *   Incident response retainers

  *   Digital forensics retainers

  *   DFIR services

  *   Cyber breach response services

Including:

  *   Supplier name

  *   Contract value or annual spend

  *   Contract expiry date

  *   Procurement route used

The Council does not use Incident Response or Digital Forensics services.

 

7. Future Procurement Activity

Where known, please provide:

  *   The expected renewal or re-procurement date for each service

  *   Whether the Council currently expects to re-tender, extend or recompete the contract

Guildford Borough Council is currently going through Local Government Reorganisation and will be superseded by West Surrey Council in April 2027. Procurement plans from April 2027 will be arranged by the new organisation. 

 

8. Relevant Departments

Please provide the name of the department or team responsible for:

  *   Cyber Security / Information Security

  *   ICT / IT Services

  *   Procurement and Commercial Management

Cyber Security / Information Security – Guildford Borough Council – Communications and Customer Services

ICT / IT Services - Guildford Borough Council – Communications and Customer Services

Procurement and Commercial Management – Finance

Please note that we do not publish the names and contact details of Guildford Borough Council employees, because it constitutes personal data under Section 40 of the Freedom of Information Act 2000 for employees whose names are not already publicly available. However, I can confirm that the contact details for the Directors of Communications and Customer Services and Finance can be found on our website:

https://www.guildford.gov.uk/article/26474/Directors-for-Finance-and-Resources

 

Yours sincerely,

FOI Team

Guildford Borough Council

Documents

There are no documents for this release.

This is Guildford Council's response to a freedom of information (FOI) or environmental information regulations (EIR) request.

You can browse our other responses or make a new FOI request.