Find a Tender
planning
#h6vhtk-06f556
Published 9 Sept 2026, 10:45 BST
Official UK Procurement Procedure
Enhanced Security Operations Managed Service
services
SME eligible
Below threshold
IT services: consulting
software development
Internet and support
UK
Published value
Not published
Submission deadline
Open opportunity
Lots published
1
Contract duration
2 yrs 1 mo (with extension options)
Electronic Sourcing Gateway:
Published portal
What is being bought & procurement scope
Procurement Scope & Specification
Executive Summary: Student Loans Company: "Enhanced Security Operations Managed Service". Published status: planning. Published value: Value not published. 1 published lot. Submission deadline not published. See the official notice for participation instructions.
Official Requirement Description:
The Student Loans company (SLC) have an agreement for Enhanced Security Operations Managed Service expiring April 2028. In order to provision for a retender of the agreement SLC are undertaking pre-market engagement with regards to the provision of the following:
• Requirement A: Enhanced Security Operations Managed Service - MXDR Service (2026-TR-0109a)
• Requirement B: Enhanced Security Operations Managed Service - Vulnerability Management (VM) Service (2026-TR-0109b)
• Requirement C: Enhanced Security Operations Managed Service - Breach Attack Simulation (BAS) Service (2026-TR-0109c)
• Requirement D: Enhanced Security Operations Managed Service - Cyber Threat Intelligence (CTI) Service (2026-TR-0109d)
• Requirement E: Enhanced Security Operations Managed Service - Digital Forensics and Incident Response (DFIR) Retainer Service (2026-TR-0109e)
• Requirement F: Enhanced Security Operations Managed Service - Security Architecture and Engineering Support Services (2026-TR-0109f)
SLC is considering an approach to the market to give the suppliers an option to bid for one or ALL of the contractual requirements.
Requirement A
Enhanced Security Operations Managed Service - MXDR Service
The Supplier will provide a Managed Extended Detection and Response (MXDR) capability operating on a hybrid customer/supplier model.
MXDR Service
The Supplier will provide:
• 24x7x365 monitoring of SLC security telemetry.
• L1 and L2 Security Operations Centre capability (SLC retain L3).
• Incident identification, triage and investigation.
• Security use-case monitoring and tuning.
• Management of Microsoft Sentinel detections.
• SOAR playbook execution and optimisation.
• Escalation management.
• Alert enrichment.
• Threat hunting capability.
• Malicious activity investigation.
• Service governance and performance management.
• Security reporting at operational, tactical and strategic levels.
Security Engineering (Operational)
The Supplier shall provide:
• L3 Engineering support for Sentinel.
• Analytics rule development and tuning.
• SOAR playbook management.
• Connector maintenance and health monitoring.
• Logging optimisation.
• Onboarding and validation of agreed log sources.
• Detection engineering support.
• Detection gap analysis and monitoring coverage reviews.
• Security use case development and continuous improvement.
• Monitoring health checks.
• Monitoring and remediation of ingestion issues.
• Security platform optimisation.
• Proactive automation support and development.
• Threat intelligence-led detection improvements.
Data Loss Prevention (DLP) & Phishing
The Supplier shall:
• Monitoring, triage and investigation of DLP, phishing, business email compromise (BEC), malicious email, malicious attachment and malicious URL alerts.
• Investigation of suspected data loss, data exfiltration and policy breach events.
• Support for user reported phishing submissions.
• Escalation and coordination of confirmed incidents in accordance with agreed response procedures.
• Identification and analysis of phishing campaigns, attacker infrastructure, indicators of compromise and emerging attack trends.
• Recommendations for improvements to DLP policies, email security controls, detections and response processes.
• Monthly reporting, trend analysis and security improvement recommendations.
Reporting
The Supplier shall provide:
• Weekly operational reports.
• Monthly service reports.
• Quarterly service reviews.
• KPI and SLA reporting.
• Security metrics and trend analysis.
Requirement B
Enhanced Security Operations Managed Service - Vulnerability Management Service
The Supplier shall provide Vulnerability Management services Monday to Friday, UK Core Hours (09:00-17:00).
Vulnerability Management
The Supplier shall:
• Monitor vulnerability management queues.
• Investigate vulnerability notifications.
• Manage vulnerability triage.
• Validate vulnerability findings.
• Perform exploitability assessments.
• Provide remediation recommendations.
• Support exposure management activities.
• Support CTEM activities.
Stakeholder Engagement
The Supplier shall:
• Conduct monthly technical review meetings.
• Support resolver teams.
• Assist remediation planning.
• Review remediation performance.
• Provide vulnerability prioritisation guidance.
Dashboarding & Reporting
The Supplier shall:
• Maintain executive dashboards.
• Enhance Power BI reporting.
• Produce technical reports.
• Produce executive reports.
• Produce PCI compliance reports.
• Produce risk trending reports.
Tooling
The Supplier shall support:
• Microsoft Defender for Endpoint.
• Rapid7.
• SLC PCI ASV Scanning tooling.
• Jira.
• Power BI.
Requirement C
Enhanced Security Operations Managed Service - Breach Attack Simulation Service
The Supplier shall provide a Breach Attack Simulation (BAS) capability, currently using AttackIQ or similar.
BAS Service
The Supplier shall:
• Operate and maintain the BAS platform.
• Deploy and maintain BAS agents.
• Configure integrations.
• Execute scheduled simulations.
• Execute customer-specific simulations.
• Execute retests following remediation activities.
Adversary Simulation
Testing scenarios shall include:
• Initial Access.
• Execution.
• Persistence.
• Privilege Escalation.
• Credential Access.
• Lateral Movement.
• Command and Control.
• Exfiltration.
• Malware.
• Ransomware.
• Advanced Persistent Threat activity.
Security Validation
The Supplier shall assess:
• Security control effectiveness.
• Security monitoring effectiveness.
• Detection coverage.
• Response capability.
• Incident handling.
• Use-case effectiveness.
Reporting
The Supplier shall produce:
• Monthly BAS reports.
• Executive summaries.
• Technical findings.
• Remediation recommendations.
• Retest outcomes.
Requirement D
Enhanced Security Operations Managed Service - Cyber Threat Intelligence Service
The Supplier shall provide strategic, operational and tactical Cyber Threat Intelligence services.
Threat Intelligence Managed Service
The Supplier shall provide:
• Threat Intelligence reporting.
• Integration into Microsoft Sentinel.
• Indicator of Compromise feeds.
• Threat actor intelligence.
Operational Intelligence
The Supplier shall provide:
• Threat alerts.
• Vulnerability intelligence.
• Emerging threat notifications.
• Campaign tracking.
• Industry specific intelligence.
Strategic Intelligence
The Supplier shall provide:
• Threat landscape assessments.
• Quarterly threat reports.
• Executive intelligence briefings.
• Board level threat summaries.
• Sector specific threat reporting.
Security Operations Support
The Supplier shall provide:
• Intelligence support during incidents.
• Threat hunting support.
• Intelligence driven use-case creation.
• Intelligence enrichment services.
Requirement E
Enhanced Security Operations Managed Service - Digital Forensics & Incident Response Retainer Service
The Supplier shall provide a DFIR Retainer available 24x7x365.
Cyber Incident Response
The Supplier shall provide:
• Incident investigation.
• Malware analysis.
• Threat containment.
• Threat eradication.
• Recovery support.
• Crisis management support.
• Regulator support.
• On-site support
Digital Forensics
The Supplier shall provide:
• Evidence acquisition.
• Chain of custody management.
• Endpoint forensics.
• Server forensics.
• Network forensics.
• Cloud forensics.
• Forensic reporting.
Readiness Services
The Supplier shall provide access to:
• Tabletop exercises.
• Incident simulations.
• Executive workshops.
• CSIRT training.
• Lessons learned reviews.
Retained Consultancy
The Supplier shall provide specialist support including:
• Security strategy input.
• Audit support.
• Major incident reviews.
• Regulatory engagement support.
• Ransomware negotiation services.
Requirement F
Enhanced Security Operations Managed Service - Security Architecture & Engineering Support Services
The Supplier shall provide specialist Security Architecture and Engineering services on a call-off basis.
Security Architecture
The Supplier shall provide:
• Security architecture reviews.
• Security design authority support.
• Secure by Design reviews.
• Solution security reviews.
• Threat modelling.
• Architecture governance.
• Security requirements definition.
• Architectural risk assessments.
Security Engineering
The Supplier shall provide:
• Technical security engineering.
• Security tool implementation.
• Security configuration reviews.
• Security hardening activities.
• Technical control implementation.
Strategy & Transformation
The Supplier shall provide:
• Security roadmap development.
• Target operating model development.
• Control framework assessments.
• Security maturity reviews.
• Improvement planning.
Governance & Assurance
The Supplier shall provide:
• Security assessments.
• Risk management support.
• Audit support.
• KPI development.
• Board reporting support.
• Security governance support.
• Independent design and control assurance.
• Security exception and risk acceptance reviews.
• Third party and supplier security assessments.
Lots and requirements (1)
Procurement Structure
- Lot 1 · #1Individual lot title not publishedplanningRenewalPublished valueNot publishedThe source published no individual title or description for this lot.Contract period:14 Apr 2028 — 30 Apr 2030 (2 yrs 1 mo)Eligibility:SME eligibleOptions / extension:Renewal options
Qualification snapshot & criteria
Go / No-Go Decision Box
Evaluation weighting
Award criteria weighting not published in structured data — consult the tender pack documents.
Incumbent & Market Position
Top Retained Vendor (Authority Spend)TATA CONSULTANCY SERVICES LIMITEDHolds 73.8% of historical attributable spend
High ConcentrationEntry requirements & qualification
Turnover Benchmark
Insurance Commitments (No Upfront Purchase Needed)
Accreditations & Security Vetting
Contract Duration & Term OptionsExpected duration: 2 yrs 1 mo (with extension options)
Published track record for Student Loans Company. These figures describe a rolling 24-month window, not a forecast of bids or a measure of buyer bias.
Avg price drop
Not availableEarly / insufficient sample
Competition Density
2Bids / Report (median)
Supplier Concentration
Published spend
£5,916,396Historical spend
Typical award value
£143,063Robust (n=8)
Awarded spend by half-year
2024-H2
2025-H1
2025-H2
2026-H1
2026-H2
Methodology & coverage notes (8 active published awards)
Coverage: 8 active published awards; 4 bid reports (which may be per lot); 8 valued awards. Supplier values exclude multi-supplier awards, frameworks and DPS, and use GBP only. They are published award values, not payments. Published-to-award variance compares single-lot, single-award, single-supplier GBP procedures with explicitly non-framework/non-DPS status; increases remain in the average. Every figure carries an evidence level: Robust (5+ observations), Moderate (3–4), Indicative (1–2). Unpublished data stays unknown. Awarded suppliers are winners, not all bidders.
Historical Awarded Suppliers in this Category (CPV 72):
Supplier Name | Historic Awards | Attributable Value | Avg. Price Discount |
|---|---|---|---|
| TATA CONSULTANCY SERVICES LIMITED | 1 win | £4,363,515 | No published budget |
| Precisely Software Limited | 1 win | £684,205 | No published budget |
| DESKOPX LTD | 1 win | £450,000 | No published budget |
| Computacenter Plc | 2 wins | £263,231 | No published budget |
| SOFTCAT PLC | 3 wins | £155,446 | No published budget |
Sector Market Benchmark & Opportunity Radar
CPV 72 · UK Sector Analysis
Observed CPV-sector evidence
Suitable for SMEs
Prepared 9 Sept 2026, 12:22 BST
Observed CPV-sector evidence where it exists, with clearly labelled UK all-sector context for sparse fields; this is market context, not a bid forecast.
Median Winning Discount
0.22%
Typical Bids Received
2reported bids
Decision Velocity
~62 days
Notice Stability
Stable notice
Historical Incumbency: SOFTCAT PLC has won 3 previous contracts with this contracting authority in this sector.
Procurement history indicates repeat engagement with this buyer in this sector. All public competitions remain open to qualifying tenderers under UK procurement regulations.
Top Contenders in this Sector (CPV 72)
Supplier | Awards won | Total awarded value | Avg. winning discount |
|---|---|---|---|
| 13 contracts | £3,026,000,000 | At ceiling / not disclosed | |
| 9 contracts | £3,014,480,000 | At ceiling / not disclosed | |
IBM UNITED KINGDOM LIMITEDCRN: PNQM-8935-PYGQ | 95 contracts | £2,492,222,568 | At ceiling / not disclosed |
CAPITA BUSINESS SERVICES LTDCRN: PGJV-4881-DTGT | 37 contracts | £2,206,136,398 | -0% below budget |
| 11 contracts | £2,000,000,000 | At ceiling / not disclosed | |
FUJITSU SERVICES LIMITEDCRN: PPBL-5581-QQWX | 67 contracts | £1,711,219,332 | At ceiling / not disclosed |
ORACLE CORPORATION UK LIMITEDCRN: PMDX-4517-DZXP | 82 contracts | £1,631,279,568 | At ceiling / not disclosed |
FORDWAY SOLUTIONS LIMITEDCRN: PMPQ-9591-CTJL | 8 contracts | £1,500,229,006 | At ceiling / not disclosed |
| 2 contracts | £1,500,000,000 | At ceiling / not disclosed | |
| 2 contracts | £1,500,000,000 | At ceiling / not disclosed |
Comparable Published Opportunities & Re-tender Precedents
Historic records ranked from matching published evidence. They serve as research precedents for contract scoping, specifications, and previous awardees.
Published procedure | Published value | Matching evidence |
|---|---|---|
Outsourced ICT Infrastructure Management and associated ServicesWorcestershire Acute Hospitals NHS Trust · 3 Sept 2026, 15:47 BST | £49,999,999 | same CPV family same region matching published text |
Central Service Desk and Lead IntegratorHM Treasury · 30 Jul 2026, 13:33 BST | £14,800,000 | same CPV family same region matching published text |
Managed Service Provider (MSP) & Security Operations Centre (SOC) / SEIM ProviderWaste & Resources Action Programme · 24 Apr 2025, 10:52 BST | £180,000 | same CPV family same region matching published text |
Managed Security Operations Centre (SOC) and Incident Response Services AgreementUNITED KINGDOM NATIONAL NUCLEAR LABORATORY LIMITED · 23 Jul 2026, 19:29 BST | £2,500,000 | same CPV family same region matching published text |
On Vehicle Digital Technology (AVL, CCTV, APC, TLP, Comms, On Bus Destination, AVA, Bridge Strike Systems & Vehicle Compute Capability) Franchising and Wider Transport Ticketing & Payment Consultancy ServicesSOUTH WEST SMART APPLICATIONS LIMITED · 9 Sept 2026, 08:29 BST | £100,000,000 | same CPV family same region matching published text |
Method: tender-intelligence-v1. Empirical OCDS facts and cross-sector percentiles; missing fields remain unrecorded.SME Friendly Qualification Criteria
Procedure terms & legal framework
| Procedure method | Standard public procedure | Legal basis | UKPGA · 2023/54 Procurement Act 2023 | Procurement category | services |
|---|---|---|---|---|---|
| Notice status | planning | Procurement threshold | Sub-threshold | Regulatory regime | Standard commercial regime |
| Commercial structure | Stand-alone contract (No framework) | Competition type | Competitive procedure | GPA WTO covered | Unspecified in notice |
| Recurring procurement | No (One-off requirement) | First published | 9 Sept 2026, 10:45 BST | Last source update | 9 Sept 2026, 10:45 BST |
| Estimated future notice | 7 May 2027, 23:59 BST | Classification (CPV) | IT services: consulting, software development, Internet and support | ||
| Delivery area | UK | ||||
| Official Registry OCID | ocds-h6vhtk-06f556 | ||||
Timeline
- Pipeline notice
9 Sept 2026, 10:45 BST - Procedure published
9 Sept 2026, 10:45 BST - engagement
22 Oct 2026, 23:59 BST · scheduledAll communication regarding this questionnaire shall take place via Delta E Sourcing and must state the appropriate contract reference number (2026-TR-0109) in all instances. Your sole contact for the purposes of this questionnaire is: Contact: Kenneth McKay Title: Commercial Manager Email: [email protected] Responses to this questionnaire must be submitted via Delta Esourcing Access Code: 96G7G98ZY3 End date: 22/10/2026 10:00am.
Commercial outcome and contract awards
Awards (0)No award published |
Contracts (0)No contract published |
Bid statisticsNo aggregate bid statistics published |
Notice history
From official release and amendment events
- Official notice release published
9 Sept 2026, 10:45 BST
Buyer and organisations in this procedure
Student Loans Company
Contracting authority
Official Documents & Specifications (1)
Official links; attachments are not copied
- 9 Sept 2026, 10:45 BST