TenderlineUK
Procurement Intelligence
Official OCDS
Find a Tender
planning
#h6vhtk-06f556
Published 9 Sept 2026, 10:45 BST
Official UK Procurement Procedure

Enhanced Security Operations Managed Service

services
SME eligible
Below threshold
IT services: consulting
software development
Internet and support
UK
Published value
Not published
Contract value exc. VAT
Submission deadline
Open opportunity
planning
Lots published
1
Lots published in procedure
Contract duration
2 yrs 1 mo (with extension options)
Starts 14 Apr 2028, 00:00 BST
Electronic Sourcing Gateway:
Published portal

What is being bought & procurement scope

Procurement Scope & Specification
Tenderline summary generated from the published notice
Executive Summary: Student Loans Company: "Enhanced Security Operations Managed Service". Published status: planning. Published value: Value not published. 1 published lot. Submission deadline not published. See the official notice for participation instructions.

Official Requirement Description:

The Student Loans company (SLC) have an agreement for Enhanced Security Operations Managed Service expiring April 2028. In order to provision for a retender of the agreement SLC are undertaking pre-market engagement with regards to the provision of the following: • Requirement A: Enhanced Security Operations Managed Service - MXDR Service (2026-TR-0109a) • Requirement B: Enhanced Security Operations Managed Service - Vulnerability Management (VM) Service (2026-TR-0109b) • Requirement C: Enhanced Security Operations Managed Service - Breach Attack Simulation (BAS) Service (2026-TR-0109c) • Requirement D: Enhanced Security Operations Managed Service - Cyber Threat Intelligence (CTI) Service (2026-TR-0109d) • Requirement E: Enhanced Security Operations Managed Service - Digital Forensics and Incident Response (DFIR) Retainer Service (2026-TR-0109e) • Requirement F: Enhanced Security Operations Managed Service - Security Architecture and Engineering Support Services (2026-TR-0109f) SLC is considering an approach to the market to give the suppliers an option to bid for one or ALL of the contractual requirements. Requirement A Enhanced Security Operations Managed Service - MXDR Service The Supplier will provide a Managed Extended Detection and Response (MXDR) capability operating on a hybrid customer/supplier model. MXDR Service The Supplier will provide: • 24x7x365 monitoring of SLC security telemetry. • L1 and L2 Security Operations Centre capability (SLC retain L3). • Incident identification, triage and investigation. • Security use-case monitoring and tuning. • Management of Microsoft Sentinel detections. • SOAR playbook execution and optimisation. • Escalation management. • Alert enrichment. • Threat hunting capability. • Malicious activity investigation. • Service governance and performance management. • Security reporting at operational, tactical and strategic levels. Security Engineering (Operational) The Supplier shall provide: • L3 Engineering support for Sentinel. • Analytics rule development and tuning. • SOAR playbook management. • Connector maintenance and health monitoring. • Logging optimisation. • Onboarding and validation of agreed log sources. • Detection engineering support. • Detection gap analysis and monitoring coverage reviews. • Security use case development and continuous improvement. • Monitoring health checks. • Monitoring and remediation of ingestion issues. • Security platform optimisation. • Proactive automation support and development. • Threat intelligence-led detection improvements. Data Loss Prevention (DLP) & Phishing The Supplier shall: • Monitoring, triage and investigation of DLP, phishing, business email compromise (BEC), malicious email, malicious attachment and malicious URL alerts. • Investigation of suspected data loss, data exfiltration and policy breach events. • Support for user reported phishing submissions. • Escalation and coordination of confirmed incidents in accordance with agreed response procedures. • Identification and analysis of phishing campaigns, attacker infrastructure, indicators of compromise and emerging attack trends. • Recommendations for improvements to DLP policies, email security controls, detections and response processes. • Monthly reporting, trend analysis and security improvement recommendations. Reporting The Supplier shall provide: • Weekly operational reports. • Monthly service reports. • Quarterly service reviews. • KPI and SLA reporting. • Security metrics and trend analysis. Requirement B Enhanced Security Operations Managed Service - Vulnerability Management Service The Supplier shall provide Vulnerability Management services Monday to Friday, UK Core Hours (09:00-17:00). Vulnerability Management The Supplier shall: • Monitor vulnerability management queues. • Investigate vulnerability notifications. • Manage vulnerability triage. • Validate vulnerability findings. • Perform exploitability assessments. • Provide remediation recommendations. • Support exposure management activities. • Support CTEM activities. Stakeholder Engagement The Supplier shall: • Conduct monthly technical review meetings. • Support resolver teams. • Assist remediation planning. • Review remediation performance. • Provide vulnerability prioritisation guidance. Dashboarding & Reporting The Supplier shall: • Maintain executive dashboards. • Enhance Power BI reporting. • Produce technical reports. • Produce executive reports. • Produce PCI compliance reports. • Produce risk trending reports. Tooling The Supplier shall support: • Microsoft Defender for Endpoint. • Rapid7. • SLC PCI ASV Scanning tooling. • Jira. • Power BI. Requirement C Enhanced Security Operations Managed Service - Breach Attack Simulation Service The Supplier shall provide a Breach Attack Simulation (BAS) capability, currently using AttackIQ or similar. BAS Service The Supplier shall: • Operate and maintain the BAS platform. • Deploy and maintain BAS agents. • Configure integrations. • Execute scheduled simulations. • Execute customer-specific simulations. • Execute retests following remediation activities. Adversary Simulation Testing scenarios shall include: • Initial Access. • Execution. • Persistence. • Privilege Escalation. • Credential Access. • Lateral Movement. • Command and Control. • Exfiltration. • Malware. • Ransomware. • Advanced Persistent Threat activity. Security Validation The Supplier shall assess: • Security control effectiveness. • Security monitoring effectiveness. • Detection coverage. • Response capability. • Incident handling. • Use-case effectiveness. Reporting The Supplier shall produce: • Monthly BAS reports. • Executive summaries. • Technical findings. • Remediation recommendations. • Retest outcomes. Requirement D Enhanced Security Operations Managed Service - Cyber Threat Intelligence Service The Supplier shall provide strategic, operational and tactical Cyber Threat Intelligence services. Threat Intelligence Managed Service The Supplier shall provide: • Threat Intelligence reporting. • Integration into Microsoft Sentinel. • Indicator of Compromise feeds. • Threat actor intelligence. Operational Intelligence The Supplier shall provide: • Threat alerts. • Vulnerability intelligence. • Emerging threat notifications. • Campaign tracking. • Industry specific intelligence. Strategic Intelligence The Supplier shall provide: • Threat landscape assessments. • Quarterly threat reports. • Executive intelligence briefings. • Board level threat summaries. • Sector specific threat reporting. Security Operations Support The Supplier shall provide: • Intelligence support during incidents. • Threat hunting support. • Intelligence driven use-case creation. • Intelligence enrichment services. Requirement E Enhanced Security Operations Managed Service - Digital Forensics & Incident Response Retainer Service The Supplier shall provide a DFIR Retainer available 24x7x365. Cyber Incident Response The Supplier shall provide: • Incident investigation. • Malware analysis. • Threat containment. • Threat eradication. • Recovery support. • Crisis management support. • Regulator support. • On-site support Digital Forensics The Supplier shall provide: • Evidence acquisition. • Chain of custody management. • Endpoint forensics. • Server forensics. • Network forensics. • Cloud forensics. • Forensic reporting. Readiness Services The Supplier shall provide access to: • Tabletop exercises. • Incident simulations. • Executive workshops. • CSIRT training. • Lessons learned reviews. Retained Consultancy The Supplier shall provide specialist support including: • Security strategy input. • Audit support. • Major incident reviews. • Regulatory engagement support. • Ransomware negotiation services. Requirement F Enhanced Security Operations Managed Service - Security Architecture & Engineering Support Services The Supplier shall provide specialist Security Architecture and Engineering services on a call-off basis. Security Architecture The Supplier shall provide: • Security architecture reviews. • Security design authority support. • Secure by Design reviews. • Solution security reviews. • Threat modelling. • Architecture governance. • Security requirements definition. • Architectural risk assessments. Security Engineering The Supplier shall provide: • Technical security engineering. • Security tool implementation. • Security configuration reviews. • Security hardening activities. • Technical control implementation. Strategy & Transformation The Supplier shall provide: • Security roadmap development. • Target operating model development. • Control framework assessments. • Security maturity reviews. • Improvement planning. Governance & Assurance The Supplier shall provide: • Security assessments. • Risk management support. • Audit support. • KPI development. • Board reporting support. • Security governance support. • Independent design and control assurance. • Security exception and risk acceptance reviews. • Third party and supplier security assessments.

Lots and requirements (1)

Procurement Structure
Published by the contracting authority
  • Lot 1 · #1
    Individual lot title not published
    planning
    Renewal
    Published valueNot published
    The source published no individual title or description for this lot.
    Contract period:
    14 Apr 2028 — 30 Apr 2030 (2 yrs 1 mo)
    Eligibility:
    SME eligible
    Options / extension:
    Renewal options

Qualification snapshot & criteria

Go / No-Go Decision Box
Criteria & entry requirements
Evaluation weighting
Award criteria weighting not published in structured data — consult the tender pack documents.
Incumbent & Market Position
Top Retained Vendor (Authority Spend)TATA CONSULTANCY SERVICES LIMITEDHolds 73.8% of historical attributable spend
High Concentration
Entry requirements & qualification
  • Turnover Benchmark
    Guideline requirement: ~2× annual contract value annual turnover.Per Cabinet Office EFS 2026 & Sourcing Playbook: general proportionality cap (~2× run-rate), not an automatic disqualifier.
  • Insurance Commitments (No Upfront Purchase Needed)
    Standard public thresholds: Employer Liability (£5m), Public Liability (£5m-£10m), Professional Indemnity (£1m-£5m).✓ Commitment required upon award only — no upfront policy purchase needed to bid
  • Accreditations & Security Vetting
    Check tender pack for Cyber Essentials Plus (PPN 014 risk-proportional), ISO 27001/9001, and BPSS / SC security clearance requirements for named delivery personnel.
  • Contract Duration & Term OptionsExpected duration: 2 yrs 1 mo (with extension options)
  • Source: Cabinet Office Sourcing Playbook & EFS Guidance.

    Buyer track record & authority intelligence: Student Loans Company

    Rolling 24 months
    Derived from OCDS data
    Published track record for Student Loans Company. These figures describe a rolling 24-month window, not a forecast of bids or a measure of buyer bias.
    Avg price drop
    Not availableEarly / insufficient sample
    Needs a published budget AND award for the same procedure
    Competition Density
    2Bids / Report (median)
    Single-bidder rate: 50%
    Supplier Concentration
    High Concentration
    TATA CONSULTANCY SERVICES LIMITEDTop vendor: 73.8% of attributable value
    Published spend
    £5,916,396Historical spend
    Cumulative GBP spend across 8 retained awards
    Typical award value
    £143,063Robust (n=8)
    Middle 50% of awards: £48,759 – £508,551
    Awarded spend by half-year
    2024-H2
    2025-H1
    2025-H2
    2026-H1
    2026-H2
    Methodology & coverage notes (8 active published awards)
    Coverage: 8 active published awards; 4 bid reports (which may be per lot); 8 valued awards. Supplier values exclude multi-supplier awards, frameworks and DPS, and use GBP only. They are published award values, not payments. Published-to-award variance compares single-lot, single-award, single-supplier GBP procedures with explicitly non-framework/non-DPS status; increases remain in the average. Every figure carries an evidence level: Robust (5+ observations), Moderate (3–4), Indicative (1–2). Unpublished data stays unknown. Awarded suppliers are winners, not all bidders.
    Historical Awarded Suppliers in this Category (CPV 72):
    Supplier Name
    Historic Awards
    Attributable Value
    Avg. Price Discount
    TATA CONSULTANCY SERVICES LIMITED1 win£4,363,515No published budget
    Precisely Software Limited1 win£684,205No published budget
    DESKOPX LTD1 win£450,000No published budget
    Computacenter Plc2 wins£263,231No published budget
    SOFTCAT PLC3 wins£155,446No published budget

    Sector Market Benchmark & Opportunity Radar

    CPV 72 · UK Sector Analysis
    Observed CPV-sector evidence
    Suitable for SMEs
    Prepared 9 Sept 2026, 12:22 BST
    Observed CPV-sector evidence where it exists, with clearly labelled UK all-sector context for sparse fields; this is market context, not a bid forecast.
    Median Winning Discount
    0.22%
    CPV sector evidence · 242 comparable price observations
    Typical Bids Received
    2reported bids
    CPV sector evidence · 4,591 published bid reports
    Decision Velocity
    ~62 days
    CPV sector evidence · median from 318 completed procedures
    Notice Stability
    Stable notice
    Published terms remained unchanged
    Top Contenders in this Sector (CPV 72)
    Active commercial suppliers winning public contracts in this field
    Supplier
    Awards won
    Total awarded value
    Avg. winning discount
    13 contracts£3,026,000,000At ceiling / not disclosed
    9 contracts£3,014,480,000At ceiling / not disclosed
    IBM UNITED KINGDOM LIMITEDCRN: PNQM-8935-PYGQ
    95 contracts£2,492,222,568At ceiling / not disclosed
    CAPITA BUSINESS SERVICES LTDCRN: PGJV-4881-DTGT
    37 contracts£2,206,136,398-0% below budget
    11 contracts£2,000,000,000At ceiling / not disclosed
    FUJITSU SERVICES LIMITEDCRN: PPBL-5581-QQWX
    67 contracts£1,711,219,332At ceiling / not disclosed
    82 contracts£1,631,279,568At ceiling / not disclosed
    FORDWAY SOLUTIONS LIMITEDCRN: PMPQ-9591-CTJL
    8 contracts£1,500,229,006At ceiling / not disclosed
    2 contracts£1,500,000,000At ceiling / not disclosed
    2 contracts£1,500,000,000At ceiling / not disclosed
    Comparable Published Opportunities & Re-tender Precedents
    Ranked by multi-factor similarity score
    Historic records ranked from matching published evidence. They serve as research precedents for contract scoping, specifications, and previous awardees.
    Published procedure
    Published value
    Matching evidence
    Outsourced ICT Infrastructure Management and associated ServicesWorcestershire Acute Hospitals NHS Trust · 3 Sept 2026, 15:47 BST
    £49,999,999
    same CPV family
    same region
    matching published text
    Central Service Desk and Lead IntegratorHM Treasury · 30 Jul 2026, 13:33 BST
    £14,800,000
    same CPV family
    same region
    matching published text
    Managed Service Provider (MSP) & Security Operations Centre (SOC) / SEIM ProviderWaste & Resources Action Programme · 24 Apr 2025, 10:52 BST
    £180,000
    same CPV family
    same region
    matching published text
    Managed Security Operations Centre (SOC) and Incident Response Services AgreementUNITED KINGDOM NATIONAL NUCLEAR LABORATORY LIMITED · 23 Jul 2026, 19:29 BST
    £2,500,000
    same CPV family
    same region
    matching published text
    £100,000,000
    same CPV family
    same region
    matching published text
    Method: tender-intelligence-v1. Empirical OCDS facts and cross-sector percentiles; missing fields remain unrecorded.SME Friendly Qualification Criteria

    Procedure terms & legal framework

    Procedure methodStandard public procedureLegal basis
    UKPGA · 2023/54
    Procurement Act 2023
    Procurement categoryservices
    Notice statusplanningProcurement thresholdSub-thresholdRegulatory regimeStandard commercial regime
    Commercial structureStand-alone contract (No framework)Competition typeCompetitive procedureGPA WTO coveredUnspecified in notice
    Recurring procurementNo (One-off requirement)First published9 Sept 2026, 10:45 BSTLast source update9 Sept 2026, 10:45 BST
    Estimated future notice7 May 2027, 23:59 BSTClassification (CPV)IT services: consulting, software development, Internet and support
    Delivery area
    UK
    Official Registry OCIDocds-h6vhtk-06f556
    Timeline
    1. Pipeline notice
      9 Sept 2026, 10:45 BST
    2. Procedure published
      9 Sept 2026, 10:45 BST
    3. engagement
      22 Oct 2026, 23:59 BST · scheduled
      All communication regarding this questionnaire shall take place via Delta E Sourcing and must state the appropriate contract reference number (2026-TR-0109) in all instances. Your sole contact for the purposes of this questionnaire is: Contact: Kenneth McKay Title: Commercial Manager Email: [email protected] Responses to this questionnaire must be submitted via Delta Esourcing Access Code: 96G7G98ZY3 End date: 22/10/2026 10:00am.

    Commercial outcome and contract awards

    Awards (0)No award published
    Contracts (0)No contract published
    Bid statisticsNo aggregate bid statistics published
    Notice history
    From official release and amendment events
    1. Official notice release published
      9 Sept 2026, 10:45 BST

    Buyer and organisations in this procedure

    Student Loans Company

    Contracting authority
    GB-PPON-PMXL-3278-BCWT
    View buyer profile →

    Official Documents & Specifications (1)

    Official links; attachments are not copied