FOI release

Freedom of Information Request - Procurement Routes

Case reference FOI2026/01025

Received 10 September 2026

Published 6 October 2026

Request

I am writing to request information under the Freedom of Information Act 2000 regarding the Council's procurement and use of cyber security services. Where available, please provide details for the current contract(s), supplier(s) and procurement arrangements relating to the following services. 1. Procurement Routes 1. Which procurement platform(s) does the Council use for IT and cyber security procurements (for example Contracts Finder, Proactis, YORtender, Chest, Delta eSourcing or similar)? 2. Which framework agreements does the Council typically use for cyber security services (for example G-Cloud, DOS, CCS frameworks, Bloom or equivalent)? 2. Penetration Testing and Security Testing Please provide: * Current supplier name(s) * Contract start date * Contract expiry date * Contract value or annual spend * Procurement route or framework used * Whether services include infrastructure, web application, mobile, cloud, CHECK, IT Health Check or other penetration testing services 3. Cyber Essentials and Cyber Essentials Plus Please provide: * Current supplier name * Contract value or annual spend * Contract start date * Contract expiry date * Procurement route or framework used 4. ISO 27001 Please provide details of any external supplier used for: * ISO 27001 consultancy * ISO 27001 implementation support * ISO 27001 internal audit * ISO 27001 certification preparation Including: * Supplier name * Contract value or annual spend * Contract expiry date * Procurement route used 5. PCI DSS Please provide details of any external supplier used for: * PCI DSS consultancy * PCI DSS QSA services * PCI DSS penetration testing * PCI DSS compliance support Including: * Supplier name * Contract value or annual spend * Contract expiry date * Procurement route used 6. Incident Response and Digital Forensics Please provide details of any external supplier used for: * Incident response retainers * Digital forensics retainers * DFIR services * Cyber breach response services Including: * Supplier name * Contract value or annual spend * Contract expiry date * Procurement route used 7. Future Procurement Activity Where known, please provide: * The expected renewal or re-procurement date for each service * Whether the Council currently expects to re-tender, extend or recompete the contract 8. Relevant Departments Please provide the name of the department or team responsible for: * Cyber Security / Information Security * ICT / IT Services * Procurement and Commercial Management I am not requesting personal information. Generic team names or departmental contact details are sufficient. Where information is already publicly available, please provide links to the relevant contract award notice, procurement record or contract register entry. Electronic response by email would be appreciated.

Response

1. Procurement Routes

1.1 Which procurement platform(s) does the Council use for IT and cyber security procurements?


The Council uses In-tend as its e-procurement platform.


1.2 Which framework agreements does the Council typically use for cyber security services?

The Council has procured cyber security services through the HealthTrust Europe LLP Framework Agreement for ICT Digital Technology Solutions (ComIT 3).

 

2. Penetration Testing and Security Testing

 

The Council commissions independent security testing of its systems and environment. However, the information requested regarding supplier names, contract dates, contract value/annual spend, procurement arrangements and the scope of testing is withheld under section 31(1)(a) of the Freedom of Information Act 2000.

 

Section 31(1)(a) exempts information where disclosure would, or would be likely to, prejudice the prevention or detection of crime.

 

Disclosure under the Act is disclosure to the world at large, not only to the requester. Providing details of the Council's security testing arrangements, including who undertakes testing, the types of testing carried out, contract periods and associated arrangements, could assist a malicious actor in building a picture of the Council's security arrangements. This could reveal areas of testing coverage, periods when arrangements may change or lapse, and information that could facilitate social engineering, cyber-attacks or attacks involving the Council's supply chain.

 

Public Interest Test

The Council recognises the public interest in transparency concerning the expenditure of public money and in demonstrating that appropriate cyber security arrangements are in place.

 

However, there is a strong public interest in protecting the Council's systems, the personal data held within those systems and the continued delivery of essential public services. Disclosure of detailed information concerning security testing arrangements would be likely to increase the risk of cybercrime.

 

On balance, the Council considers that the public interest in maintaining the exemption outweighs the public interest in disclosure.

 

3. Cyber Essentials and Cyber Essentials Plus

The Council does not hold a contract with any supplier for Cyber Essentials or Cyber Essentials Plus services.

 

The information requested is therefore not held.

 

4. ISO 27001

The Council does not use an external supplier for ISO 27001 consultancy, implementation support, internal audit or certification preparation. The information requested is therefore not held.

 

5. PCI DSS

The Council neither confirms nor denies whether it holds the information requested in relation to external PCI DSS services, in reliance on section 31(3) of the Freedom of Information Act 2000.

 

6. Incident Response and Digital Forensics

The Council neither confirms nor denies whether it holds the information requested in relation to incident response retainers, digital forensics retainers, DFIR services or cyber breach response services, in reliance on section 31(3) of the Freedom of Information Act 2000.

 

Section 31(3) – Neither Confirm Nor Deny

Section 31(3) removes the duty to confirm or deny whether information is held where doing so would, or would be likely to, prejudice any of the matters specified in section 31(1).

 

Confirming whether or not the Council holds incident response or digital forensic retainers, or uses external PCI DSS services, would itself reveal information about the Council's security and resilience arrangements that could assist someone planning a cyber-attack.

 

The Council has considered the public interest in transparency and accountability against the public interest in protecting its systems, security arrangements, personal data and essential public services.

 

On balance, the Council considers that the public interest in maintaining the exclusion of the duty to confirm or deny outweighs the public interest in confirming or denying whether the information is held.

 

This response should not be taken as an indication of whether or not the information requested under Questions 5 and 6 is held.

 

7. Future Procurement Activity

For the services covered by Questions 3 and 4, this is not applicable as no contracts are held.

For the security testing services covered by Question 2, information concerning renewal and re-procurement is withheld under section 31(1)(a) for the reasons explained above.

 

For the services covered by Questions 5 and 6, the Council neither confirms nor denies whether the requested information is held, in reliance on section 31(3).

 

Future tendering opportunities are advertised through the Council's In-tend e-procurement portal and, where required, through the national Find a Tender service.

 

8. Relevant Departments

Cyber Security / Information Security: ICT, City and Citizen Services

ICT / IT Services: ICT, City and Citizen Services

Procurement and Commercial Management: Procurement, Financial Services

 

Section 21 – Information accessible by other means

The Council's Register of Current Contracts is publicly available on its website.

 

The register contains details of the Council's current and pending contracts.

 

As this information is reasonably accessible to you by other means, it is exempt from disclosure under section 21 of the Freedom of Information Act 2000.

 

The Contract Register can be accessed here:

Oxford City Council – Council contracts and Register of Current Contracts

 

Section 21 is an absolute exemption and therefore does not require a public interest test.

Documents

There are no documents for this release.

This is Oxford City Council's response to a freedom of information (FOI) or environmental information regulations (EIR) request.

You can browse our other responses or make a new FOI request.