Official UK procurement notice
Continuation of Support for cyber assessment framework in Local Government
Authority: WLGA (Public body)
What is being bought
Published requirement descriptionNotice to Direct award contract for the continuation of works to support the implementation of the Cyber assessment framework (CAF) in Welsh local government, provided by Bridewell Consulting Ltd.
Direct award justification - Continuation of Existing Supply
Change of supplier would cause incompatibility or disproportionate
technical difficulty.
WLGA proposes to directly award the next phase of the Cyber Assessment Framework (CAF) support contract to Bridewell Consulting Ltd on the basis that changing supplier at this stage would create significant technical, operational and cyber security risks that outweigh any potential benefits of a competitive procurement exercise.
The supplier has developed substantial programme-specific knowledge, methodologies, tooling, templates, dashboards and sector intelligence throughout delivery of the CAF programme across Welsh local authorities and Fire and Rescue Services. The supplier has supported organisations through assessment, quality review, critical system mapping, independent feedback and improvement planning activities. As a result, they now possesses a unique understanding of the sector baseline, organisational maturity positions, critical system dependencies and programme governance arrangements.
Read the full description (1,641 more characters)
Replacing the current supplier with an alternative supplier would create incompatibility with the existing programme infrastructure, methodologies and assessment approaches already embedded across participating organisations. Significant effort would be required to transfer knowledge, validate prior outputs and align a new supplier to established ways of working, creating a risk of inconsistency in assessment outcomes and reducing comparability with work already completed. This would undermine the continuity and integrity of the national programme.
A change of supplier would also introduce material cyber risk. The current programme supports the cyber resilience of critical public services across Wales and provides visibility of sector-wide risks, vulnerabilities and areas requiring intervention. Any interruption to delivery, loss of organisational context or reduction in oversight during transition could weaken security visibility across the sector and delay the identification and mitigation of emerging risks. A prolonged mobilisation period would leave organisations without the level of support and assurance currently available through the programme.
In addition, a transition to a new supplier would cause significant service disruption. A full procurement exercise, mobilisation period and knowledge transfer programme would delay delivery of planned activities and divert resources away from improvement work. Participating organisations would experience disruption at a critical stage in their CAF journey, potentially delaying assurance activities, improvement planning and the implementation of risk reduction measures
The lotProcurement structure
single lot · no lot value publishedLot #1Lot 1Awarded
Procedure terms & legal framework
From the official record- Procedure method
- Direct award
- Legal basis
- UKPGA · 2023/54 Procurement Act 2023
- Notice status
- Awarded without competition
- Procurement threshold
- Unspecified in notice
- Regulatory regime
- Standard
- Commercial structure
- Framework agreement
- Competition type
- Direct award — no call for competition
- GPA / WTO covered
- Unspecified in notice
- Recurring procurement
- No (one-off requirement)
- First published
- 14 Sept 2026, 13:55 BST
- Last source update
- 14 Sept 2026, 13:55 BST
- Authority reference
WLGA Cyber 02- Latest notice
- Transparency notice (UK5)
- Delivery area
- Official registry OCID
ocds-h6vhtk-06f933
- Why no open competition
- Additional Repeat Extension Partial Replacement
- Published justification
The supplier has developed substantial programme-specific knowledge, methodologies, tooling, templates, dashboards and sector intelligence throughout delivery of the CAF programme across Welsh local authorities and Fire and Rescue Services. The supplier has supported organisations through assessment, quality review, critical system mapping, independent feedback and improvement planning activities. As a result, they more…
now possesses a unique understanding of the sector baseline, organisational maturity positions, critical system dependencies and programme governance arrangements. Replacing the current supplier with an alternative supplier would create incompatibility with the existing programme infrastructure, methodologies and assessment approaches already embedded across participating organisations. Significant effort would be required to transfer knowledge, validate prior outputs and align a new supplier to established ways of working, creating a risk of inconsistency in assessment outcomes and reducing comparability with work already completed. This would undermine the continuity and integrity of the national programme. A change of supplier would also introduce material cyber risk. The current programme supports the cyber resilience of critical public services across Wales and provides visibility of sector-wide risks, vulnerabilities and areas requiring intervention. Any interruption to delivery, loss of organisational context or reduction in oversight during transition could weaken security visibility across the sector and delay the identification and mitigation of emerging risks. A prolonged mobilisation period would leave organisations without the level of support and assurance currently available through the programme. In addition, a transition to a new supplier would cause significant service disruption. A full procurement exercise, mobilisation period and knowledge transfer programme would delay delivery of planned activities and divert resources away from improvement work. Participating organisations would experience disruption at a critical stage in their CAF journey, potentially delaying assurance activities, improvement planning and the implementation of risk reduction measures For these reasons, the contracting authority considers that competition is not feasible at this time without disproportionate disruption. This direct award is strictly limited to the period of the financial year 26-27, after which a review of activities and dependencies will be undertaken to allow for open market engagement in subsequent support engagements for cyber support in Welsh local government The contract duration reflects the minimum period necessary to ensure continuity within the current programme of work to avoid disruption and potential risk to cyber resilience
- Risks
- Delivery timescales changing due to commitments of local government bodies not allowing for timely co0ordinatioin and delivery of work
Commercial outcome & contract awards
Published awards, contracts and bid statistics — not a forecast| Awarded to | Value | Date | Status |
|---|---|---|---|
| Bridewell Consulting LtdAdditional Support for the CAF programme in Welsh Local Gov1 Oct 2026 — 31 Mar 2027 | £107,100 | — | Standstill |
Notice history
2 events · 1 release on Find a Tender · since 14 Sept 2026- Contract signature expected24 Sept 2026, 23:59 BSTscheduled
- Transparency notice published14 Sept 2026, 13:55 BSTUK5
Contracting authority & participating public bodies
Framework contractors & participating bidders
1 commercial party on the notice- Bridewell Consulting LtdFramework contractorView supplier profile →
Official documents & specifications (2)
Official links; attachments are not copiedTender pack and attachments
- Conflict of interest declarationNot published
Notices published for this procedure
- Transparency notice Transparency notice on Find a Tender