Freedom of Information Request - Procurement Routes
Case reference FOI2026/01025
Received 10 September 2026
Published 6 October 2026
Request
Response
1. Procurement Routes
1.1 Which procurement platform(s) does the Council use for IT and cyber security procurements?
The Council uses In-tend as its e-procurement platform.
1.2 Which framework agreements does the Council typically use for cyber security services?
The Council has procured cyber security services through the HealthTrust Europe LLP Framework Agreement for ICT Digital Technology Solutions (ComIT 3).
2. Penetration Testing and Security Testing
The Council commissions independent security testing of its systems and environment. However, the information requested regarding supplier names, contract dates, contract value/annual spend, procurement arrangements and the scope of testing is withheld under section 31(1)(a) of the Freedom of Information Act 2000.
Section 31(1)(a) exempts information where disclosure would, or would be likely to, prejudice the prevention or detection of crime.
Disclosure under the Act is disclosure to the world at large, not only to the requester. Providing details of the Council's security testing arrangements, including who undertakes testing, the types of testing carried out, contract periods and associated arrangements, could assist a malicious actor in building a picture of the Council's security arrangements. This could reveal areas of testing coverage, periods when arrangements may change or lapse, and information that could facilitate social engineering, cyber-attacks or attacks involving the Council's supply chain.
Public Interest Test
The Council recognises the public interest in transparency concerning the expenditure of public money and in demonstrating that appropriate cyber security arrangements are in place.
However, there is a strong public interest in protecting the Council's systems, the personal data held within those systems and the continued delivery of essential public services. Disclosure of detailed information concerning security testing arrangements would be likely to increase the risk of cybercrime.
On balance, the Council considers that the public interest in maintaining the exemption outweighs the public interest in disclosure.
3. Cyber Essentials and Cyber Essentials Plus
The Council does not hold a contract with any supplier for Cyber Essentials or Cyber Essentials Plus services.
The information requested is therefore not held.
4. ISO 27001
The Council does not use an external supplier for ISO 27001 consultancy, implementation support, internal audit or certification preparation. The information requested is therefore not held.
5. PCI DSS
The Council neither confirms nor denies whether it holds the information requested in relation to external PCI DSS services, in reliance on section 31(3) of the Freedom of Information Act 2000.
6. Incident Response and Digital Forensics
The Council neither confirms nor denies whether it holds the information requested in relation to incident response retainers, digital forensics retainers, DFIR services or cyber breach response services, in reliance on section 31(3) of the Freedom of Information Act 2000.
Section 31(3) – Neither Confirm Nor Deny
Section 31(3) removes the duty to confirm or deny whether information is held where doing so would, or would be likely to, prejudice any of the matters specified in section 31(1).
Confirming whether or not the Council holds incident response or digital forensic retainers, or uses external PCI DSS services, would itself reveal information about the Council's security and resilience arrangements that could assist someone planning a cyber-attack.
The Council has considered the public interest in transparency and accountability against the public interest in protecting its systems, security arrangements, personal data and essential public services.
On balance, the Council considers that the public interest in maintaining the exclusion of the duty to confirm or deny outweighs the public interest in confirming or denying whether the information is held.
This response should not be taken as an indication of whether or not the information requested under Questions 5 and 6 is held.
7. Future Procurement Activity
For the services covered by Questions 3 and 4, this is not applicable as no contracts are held.
For the security testing services covered by Question 2, information concerning renewal and re-procurement is withheld under section 31(1)(a) for the reasons explained above.
For the services covered by Questions 5 and 6, the Council neither confirms nor denies whether the requested information is held, in reliance on section 31(3).
Future tendering opportunities are advertised through the Council's In-tend e-procurement portal and, where required, through the national Find a Tender service.
8. Relevant Departments
Cyber Security / Information Security: ICT, City and Citizen Services
ICT / IT Services: ICT, City and Citizen Services
Procurement and Commercial Management: Procurement, Financial Services
Section 21 – Information accessible by other means
The Council's Register of Current Contracts is publicly available on its website.
The register contains details of the Council's current and pending contracts.
As this information is reasonably accessible to you by other means, it is exempt from disclosure under section 21 of the Freedom of Information Act 2000.
The Contract Register can be accessed here:
Oxford City Council – Council contracts and Register of Current Contracts
Section 21 is an absolute exemption and therefore does not require a public interest test.
Documents
This is Oxford City Council's response to a freedom of information (FOI) or environmental information regulations (EIR) request.
You can browse our other responses or make a new FOI request.