← Back to search results

AwardedFind a Tender · award

Managed Security Services

Buyer: GREENSQUAREACCORD LIMITED →

BuyerGREENSQUAREACCORD LIMITED
StatusAwarded
DeadlineNot published
ValueValue not published
Published16 Jun 2026

What is being bought

GSA require a Managed Detection and Response, Security service to mitigation of threats across the GSA's digital environment.

Delivery location

UKC · UKD · UKE · UKF · UKG · UKH · UKI · UKJ · UKK

Categories

Information technology services 72222300

Lot details

Lot 1

The service includes Managed Detection and Response, Security Information and Event Management, Endpoint Detection and Response supported by Next Generation Anti‑Virus, identity monitoring, cyber threat intelligence, threat hunting, cyber maturity assessments, efficiency testing and full incident response readiness. These capabilities collectively enable the proactive identification, investigation and mitigation of threats across the GSA's digital environment. Managed Detection and Response (MDR). Enterprise data will be captured and analysed for indicators of attack or compromise, which, if discovered, shall initiate a first response. This response will be either automated or human, depending on the source of the detection. GSA require Level 1 and 2 support, and the first one hour of any Level 3 investigations. Support levels are defined below. Level 1 The first line of security analysts who manage security tools and run regular reporting. At this level, alerts and alert urgency will be determined by the security team. Decisions about escalation to Level 2 will also be undertaken at this level. Level 2 The second line of security analysts / engineers who have the expertise required to get to the root of a problem and assess which part of the enterprise may be compromised. Remediation and repair of problems is expected and issues for additional investigation will be highlighted. Level 3 The third line of security engineers / incident responders, which consists of highly skilled technical resource. If required, personnel will use advanced detection methods (threat hunting) to identify and neutralise the threat, providing remediation advice to the Client's IT team. Key deliverables: - Managed Detection and Response (MDR) Service o 24/7x365 Threat Detection & Response o Ongoing Detection Engineering o Ongoing Use Case Development o Cyber Threat Intelligence (CTI) o Threat Hunting o Cyber Maturity Assessment o Incident Response (first 1 hour of IR) o Dedicated Customer Success Manager - SIEM Licensing (Splunk) 100GB - CrowdStrike EDR Licensing with Falcon Mobile (1650 endpoints)

Statuscancelled

Award criteria
price

What is included

ItemCategoryQuantity
1Not publishedNot published

Comparable-procurement analytics

Benchmarked against retained Find a Tender procedures with CPV division 72. The category anchor is Information technology services (72222300); this is a deliberately broad market comparator. The comparison is shown at several levels rather than pretending one company or region is always the best benchmark.

Comparison setProceduresReported bids per procedureNamed award suppliersPrice evidence
Market: CPV division 724,1921 median · 7.9 average (1,398 of 4,192 with a bid count)1.7 average (1,612 of 4,192 with named award suppliers)Not published
Same buyer81 median · 1 average (4 of 8 with a bid count)1.2 average (5 of 8 with named award suppliers)Not published
Delivery region: UKC2901 median · 7.3 average (122 of 290 with a bid count)1.4 average (128 of 290 with named award suppliers)Not published

“Reported bids” is an official aggregate, sometimes reported per lot; it is the closest available competition measure. “Named award suppliers” are winners, not all applicants.

Price-outcome signal

Not enough comparable procedures currently publish both a GBP tender value and a usable lowest-valid-bid value to calculate a responsible price-reduction benchmark. Tenderline deliberately does not infer a saving from named award suppliers or from missing award values.

Procurement strategy & market signals

Framework agreementYes
Dynamic purchasing systemNot published
Competitive procurementNot published
Recurring requirementNot published
Procurement method rationaleGSA has undertaken a direct award via an existing compliant framework agreement in accordance with the Public Contracts Regulations. This approach has been justified on the grounds of extreme urgency brought about by events that were unforeseeable and outside the control of the authority. The requirement for a managed security service has arisen due to an immediate and critical need to ensure the continued protection of organisational systems, data, and infrastructure against evolving cyber security risks. The timescales associated with conducting a full competitive procedure would not have enabled the authority to meet these urgent operational and security requirements. The selected framework was originally procured in compliance with the relevant procurement regulations and provides a lawful route to market. The direct award mechanism available within the framework enables the authority to appoint a capable supplier within the required timeframe while maintaining compliance, transparency, and value for money. This approach ensures continuity of service and mitigates significant risk, while remaining fully aligned with procurement regulations and the strict conditions governing the use of urgency provisions. The overarching objective of this procurement is to ensure that GSA have a continued Managed Security Service that ensures the organisation's cybersecurity posture is maintained and continuously improved over the life of the contract. There is insufficient time is available to conduct a competitive procurement, the use of the G Cloud 14 Framework and the continued engagement with the incumbent supplier will ensure value for money is delivered in terms of economy, efficiency, and effectiveness.
Rationale classificationsExtreme urgency brought about by events unforeseeable for the contracting authority/entity and in accordance with the strict conditions stated in the directive
Special regimeNot published
Covered byGPA
Submission policyNot published
Selection criteriaNot published
Risk detailsNot published

Planning & early market engagement

BudgetNot published
No-engagement rationaleNot published
Planning documents0
Planning milestones0

No planning milestones published.

Related procurements

No linked framework, prior procurement or reprocurement published.

Awards

Contracts

056502-2026-1

Statusactive
Value£441,880

Documents & submission route

No documents are published in the current source record.

Source data inventory

Diagnostic view. “Not published” means this current release does not provide a value.

OCIDocds-h6vhtk-06b5a4
Latest release ID056502-2026
Latest release timestampTue Jun 16 2026 09:49:45 GMT+0000 (Coordinated Universal Time)
Sourcefind-a-tender
Official notice URLNot published
Tender statuscomplete
Procurement methodlimited
Procurement method detailsAward procedure without prior publication of a call for competition
Main procurement categoryservices
Above thresholdNot published
Legal basis32014L0024
Tender period: startNot published
Tender period: endNot published
Expression of interest deadlineNot published
Enquiry deadlineNot published
Award period: startNot published
Award period: endNot published
Submission method detailsNot published
Submission languagesNot published
Electronic catalogue policyNot published
Total tender valueNot published
Tender lots in source1
Tender items in source1
Tender documents in source0
Awards in latest release1
Contracts in latest release1
Parties in latest release3

Notice history

DateEventReference
16 Jun 2026award, contract056502-2026

All source data

Unmodified official OCDS data retained by Tenderline for this procurement process.

Complete current OCDS release JSON
{
  "id": "056502-2026",
  "tag": [
    "award",
    "contract"
  ],
  "bids": {
    "statistics": [
      {
        "id": "1",
        "value": 1,
        "measure": "bids",
        "relatedLot": "1"
      }
    ]
  },
  "date": "2026-06-16T10:49:45+01:00",
  "ocid": "ocds-h6vhtk-06b5a4",
  "buyer": {
    "id": "GB-COH-RS027052",
    "name": "GREENSQUAREACCORD LIMITED"
  },
  "awards": [
    {
      "id": "056502-2026-1",
      "status": "active",
      "suppliers": [
        {
          "id": "GB-COH-11422969",
          "name": "Cysiam Limited"
        }
      ],
      "relatedLots": [
        "1"
      ]
    }
  ],
  "tender": {
    "id": "00001474",
    "lots": [
      {
        "id": "1",
        "status": "cancelled",
        "hasOptions": false,
        "description": "The service includes Managed Detection and Response, Security Information and Event Management, Endpoint Detection and Response supported by Next Generation Anti‑Virus, identity monitoring, cyber threat intelligence, threat hunting, cyber maturity assessments, efficiency testing and full incident response readiness. These capabilities collectively enable the proactive identification, investigation and mitigation of threats across the GSA's digital environment. \nManaged Detection and Response (MDR). Enterprise data will be captured and analysed for indicators of attack or compromise, which, if discovered, shall initiate a first response. This response will be either automated or human, depending on the source of the detection. GSA require Level 1 and 2 support, and the first one hour of any Level 3 investigations. Support levels are defined below. \nLevel 1\nThe first line of security analysts who manage security tools and run regular\nreporting. At this level, alerts and alert urgency will be determined by the security\nteam. Decisions about escalation to Level 2 will also be undertaken at this level.\nLevel 2\nThe second line of security analysts / engineers who have the expertise required to\nget to the root of a problem and assess which part of the enterprise may be\ncompromised. Remediation and repair of problems is expected and issues for\nadditional investigation will be highlighted.\nLevel 3\nThe third line of security engineers / incident responders, which consists of highly\nskilled technical resource. If required, personnel will use advanced detection\nmethods (threat hunting) to identify and neutralise the threat, providing remediation\nadvice to the Client's IT team.\nKey deliverables:\n-\tManaged Detection and Response (MDR) Service \no 24/7x365 Threat Detection & Response\no Ongoing Detection Engineering\no Ongoing Use Case Development\no Cyber Threat Intelligence (CTI)\no Threat Hunting\no Cyber Maturity Assessment\no Incident Response (first 1 hour of IR)\no Dedicated Customer Success Manager\n-\tSIEM Licensing (Splunk) 100GB \n-\tCrowdStrike EDR Licensing with Falcon Mobile (1650 endpoints)",
        "awardCriteria": {
          "criteria": [
            {
              "type": "price"
            }
          ]
        }
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "deliveryAddresses": [
          {
            "region": "UKC"
          },
          {
            "region": "UKD"
          },
          {
            "region": "UKE"
          },
          {
            "region": "UKF"
          },
          {
            "region": "UKG"
          },
          {
            "region": "UKH"
          },
          {
            "region": "UKI"
          },
          {
            "region": "UKJ"
          },
          {
            "region": "UKK"
          }
        ]
      }
    ],
    "title": "Managed Security Services",
    "status": "complete",
    "coveredBy": [
      "GPA"
    ],
    "legalBasis": {
      "id": "32014L0024",
      "scheme": "CELEX"
    },
    "techniques": {
      "hasFrameworkAgreement": true
    },
    "description": "GSA require a Managed Detection and Response, Security service to mitigation of threats across the GSA's digital environment.",
    "classification": {
      "id": "72222300",
      "scheme": "CPV",
      "description": "Information technology services"
    },
    "procurementMethod": "limited",
    "mainProcurementCategory": "services",
    "procurementMethodDetails": "Award procedure without prior publication of a call for competition",
    "procurementMethodRationale": "GSA has undertaken a direct award via an existing compliant framework agreement in accordance with the Public Contracts Regulations. This approach has been justified on the grounds of extreme urgency brought about by events that were unforeseeable and outside the control of the authority.\nThe requirement for a managed security service has arisen due to an immediate and critical need to ensure the continued protection of organisational systems, data, and infrastructure against evolving cyber security risks. The timescales associated with conducting a full competitive procedure would not have enabled the authority to meet these urgent operational and security requirements.\nThe selected framework was originally procured in compliance with the relevant procurement regulations and provides a lawful route to market. The direct award mechanism available within the framework enables the authority to appoint a capable supplier within the required timeframe while maintaining compliance, transparency, and value for money.\nThis approach ensures continuity of service and mitigates significant risk, while remaining fully aligned with procurement regulations and the strict conditions governing the use of urgency provisions. The overarching objective of this procurement is to ensure that GSA have a continued Managed Security Service that ensures the organisation's cybersecurity posture is maintained and continuously improved over the life of the contract. There is  insufficient time is available to conduct a competitive procurement, the use of the G Cloud 14 Framework and the continued engagement with the incumbent supplier will ensure value for money is delivered in terms of economy, efficiency, and effectiveness.",
    "procurementMethodRationaleClassifications": [
      {
        "id": "D_EXTREME_URGENCY",
        "scheme": "TED_PT_AWARD_CONTRACT_WITHOUT_CALL",
        "description": "Extreme urgency brought about by events unforeseeable for the contracting authority/entity and in accordance with the strict conditions stated in the directive"
      }
    ]
  },
  "parties": [
    {
      "id": "GB-COH-RS027052",
      "name": "GREENSQUAREACCORD LIMITED",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UKG31",
        "locality": "Birmingham",
        "postalCode": "B12JB",
        "countryName": "United Kingdom",
        "streetAddress": "Second Floor, 10 Brindley Place"
      },
      "details": {
        "url": "https://greensquareaccord.co.uk",
        "classifications": [
          {
            "id": "BODY_PUBLIC",
            "scheme": "TED_CA_TYPE",
            "description": "Body governed by public law"
          },
          {
            "id": "01",
            "scheme": "COFOG",
            "description": "General public services"
          }
        ]
      },
      "identifier": {
        "id": "RS027052",
        "scheme": "GB-COH",
        "legalName": "GREENSQUAREACCORD LIMITED"
      },
      "contactPoint": {
        "name": "Charlene Joseph",
        "email": "charlene.joseph@greensquareaccord.co.uk"
      }
    },
    {
      "id": "GB-COH-11422969",
      "name": "Cysiam Limited",
      "roles": [
        "supplier"
      ],
      "address": {
        "region": "UK",
        "locality": "Somerset",
        "countryName": "United Kingdom"
      },
      "details": {
        "scale": "sme"
      },
      "identifier": {
        "id": "11422969",
        "scheme": "GB-COH",
        "legalName": "Cysiam Limited"
      }
    },
    {
      "id": "GB-FTS-183350",
      "name": "GreenSquareAccord",
      "roles": [
        "reviewBody"
      ],
      "address": {
        "locality": "Birmingham",
        "postalCode": "B1 2JB",
        "countryName": "United Kingdom",
        "streetAddress": "10 Brindley Place"
      },
      "identifier": {
        "legalName": "GreenSquareAccord"
      }
    }
  ],
  "language": "en",
  "contracts": [
    {
      "id": "056502-2026-1",
      "value": {
        "amount": 441880,
        "currency": "GBP"
      },
      "status": "active",
      "awardID": "056502-2026-1",
      "dateSigned": "2026-04-14T00:00:00+01:00"
    }
  ],
  "initiationType": "tender"
}
Complete JSON history (1 releases)
16 Jun 2026 · 056502-2026 · award, contract
{
  "id": "056502-2026",
  "tag": [
    "award",
    "contract"
  ],
  "bids": {
    "statistics": [
      {
        "id": "1",
        "value": 1,
        "measure": "bids",
        "relatedLot": "1"
      }
    ]
  },
  "date": "2026-06-16T10:49:45+01:00",
  "ocid": "ocds-h6vhtk-06b5a4",
  "buyer": {
    "id": "GB-COH-RS027052",
    "name": "GREENSQUAREACCORD LIMITED"
  },
  "awards": [
    {
      "id": "056502-2026-1",
      "status": "active",
      "suppliers": [
        {
          "id": "GB-COH-11422969",
          "name": "Cysiam Limited"
        }
      ],
      "relatedLots": [
        "1"
      ]
    }
  ],
  "tender": {
    "id": "00001474",
    "lots": [
      {
        "id": "1",
        "status": "cancelled",
        "hasOptions": false,
        "description": "The service includes Managed Detection and Response, Security Information and Event Management, Endpoint Detection and Response supported by Next Generation Anti‑Virus, identity monitoring, cyber threat intelligence, threat hunting, cyber maturity assessments, efficiency testing and full incident response readiness. These capabilities collectively enable the proactive identification, investigation and mitigation of threats across the GSA's digital environment. \nManaged Detection and Response (MDR). Enterprise data will be captured and analysed for indicators of attack or compromise, which, if discovered, shall initiate a first response. This response will be either automated or human, depending on the source of the detection. GSA require Level 1 and 2 support, and the first one hour of any Level 3 investigations. Support levels are defined below. \nLevel 1\nThe first line of security analysts who manage security tools and run regular\nreporting. At this level, alerts and alert urgency will be determined by the security\nteam. Decisions about escalation to Level 2 will also be undertaken at this level.\nLevel 2\nThe second line of security analysts / engineers who have the expertise required to\nget to the root of a problem and assess which part of the enterprise may be\ncompromised. Remediation and repair of problems is expected and issues for\nadditional investigation will be highlighted.\nLevel 3\nThe third line of security engineers / incident responders, which consists of highly\nskilled technical resource. If required, personnel will use advanced detection\nmethods (threat hunting) to identify and neutralise the threat, providing remediation\nadvice to the Client's IT team.\nKey deliverables:\n-\tManaged Detection and Response (MDR) Service \no 24/7x365 Threat Detection & Response\no Ongoing Detection Engineering\no Ongoing Use Case Development\no Cyber Threat Intelligence (CTI)\no Threat Hunting\no Cyber Maturity Assessment\no Incident Response (first 1 hour of IR)\no Dedicated Customer Success Manager\n-\tSIEM Licensing (Splunk) 100GB \n-\tCrowdStrike EDR Licensing with Falcon Mobile (1650 endpoints)",
        "awardCriteria": {
          "criteria": [
            {
              "type": "price"
            }
          ]
        }
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "deliveryAddresses": [
          {
            "region": "UKC"
          },
          {
            "region": "UKD"
          },
          {
            "region": "UKE"
          },
          {
            "region": "UKF"
          },
          {
            "region": "UKG"
          },
          {
            "region": "UKH"
          },
          {
            "region": "UKI"
          },
          {
            "region": "UKJ"
          },
          {
            "region": "UKK"
          }
        ]
      }
    ],
    "title": "Managed Security Services",
    "status": "complete",
    "coveredBy": [
      "GPA"
    ],
    "legalBasis": {
      "id": "32014L0024",
      "scheme": "CELEX"
    },
    "techniques": {
      "hasFrameworkAgreement": true
    },
    "description": "GSA require a Managed Detection and Response, Security service to mitigation of threats across the GSA's digital environment.",
    "classification": {
      "id": "72222300",
      "scheme": "CPV",
      "description": "Information technology services"
    },
    "procurementMethod": "limited",
    "mainProcurementCategory": "services",
    "procurementMethodDetails": "Award procedure without prior publication of a call for competition",
    "procurementMethodRationale": "GSA has undertaken a direct award via an existing compliant framework agreement in accordance with the Public Contracts Regulations. This approach has been justified on the grounds of extreme urgency brought about by events that were unforeseeable and outside the control of the authority.\nThe requirement for a managed security service has arisen due to an immediate and critical need to ensure the continued protection of organisational systems, data, and infrastructure against evolving cyber security risks. The timescales associated with conducting a full competitive procedure would not have enabled the authority to meet these urgent operational and security requirements.\nThe selected framework was originally procured in compliance with the relevant procurement regulations and provides a lawful route to market. The direct award mechanism available within the framework enables the authority to appoint a capable supplier within the required timeframe while maintaining compliance, transparency, and value for money.\nThis approach ensures continuity of service and mitigates significant risk, while remaining fully aligned with procurement regulations and the strict conditions governing the use of urgency provisions. The overarching objective of this procurement is to ensure that GSA have a continued Managed Security Service that ensures the organisation's cybersecurity posture is maintained and continuously improved over the life of the contract. There is  insufficient time is available to conduct a competitive procurement, the use of the G Cloud 14 Framework and the continued engagement with the incumbent supplier will ensure value for money is delivered in terms of economy, efficiency, and effectiveness.",
    "procurementMethodRationaleClassifications": [
      {
        "id": "D_EXTREME_URGENCY",
        "scheme": "TED_PT_AWARD_CONTRACT_WITHOUT_CALL",
        "description": "Extreme urgency brought about by events unforeseeable for the contracting authority/entity and in accordance with the strict conditions stated in the directive"
      }
    ]
  },
  "parties": [
    {
      "id": "GB-COH-RS027052",
      "name": "GREENSQUAREACCORD LIMITED",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UKG31",
        "locality": "Birmingham",
        "postalCode": "B12JB",
        "countryName": "United Kingdom",
        "streetAddress": "Second Floor, 10 Brindley Place"
      },
      "details": {
        "url": "https://greensquareaccord.co.uk",
        "classifications": [
          {
            "id": "BODY_PUBLIC",
            "scheme": "TED_CA_TYPE",
            "description": "Body governed by public law"
          },
          {
            "id": "01",
            "scheme": "COFOG",
            "description": "General public services"
          }
        ]
      },
      "identifier": {
        "id": "RS027052",
        "scheme": "GB-COH",
        "legalName": "GREENSQUAREACCORD LIMITED"
      },
      "contactPoint": {
        "name": "Charlene Joseph",
        "email": "charlene.joseph@greensquareaccord.co.uk"
      }
    },
    {
      "id": "GB-COH-11422969",
      "name": "Cysiam Limited",
      "roles": [
        "supplier"
      ],
      "address": {
        "region": "UK",
        "locality": "Somerset",
        "countryName": "United Kingdom"
      },
      "details": {
        "scale": "sme"
      },
      "identifier": {
        "id": "11422969",
        "scheme": "GB-COH",
        "legalName": "Cysiam Limited"
      }
    },
    {
      "id": "GB-FTS-183350",
      "name": "GreenSquareAccord",
      "roles": [
        "reviewBody"
      ],
      "address": {
        "locality": "Birmingham",
        "postalCode": "B1 2JB",
        "countryName": "United Kingdom",
        "streetAddress": "10 Brindley Place"
      },
      "identifier": {
        "legalName": "GreenSquareAccord"
      }
    }
  ],
  "language": "en",
  "contracts": [
    {
      "id": "056502-2026-1",
      "value": {
        "amount": 441880,
        "currency": "GBP"
      },
      "status": "active",
      "awardID": "056502-2026-1",
      "dateSigned": "2026-04-14T00:00:00+01:00"
    }
  ],
  "initiationType": "tender"
}