RFP QuestBeta

ISO 27001 (information security)

Standards you certify to · awarded by Certification body accredited by UKAS · serves: InfoSec consultants & auditors

Notices demanding it
227
a floor
Said “must”
48
explicit obligation
Open right now
2
Value gated
£2.0bn
a floor

Published values on the notices that demand it — a floor, not a total.

The demand curve

Notices demanding it per 10,000 published, by year — rate-normalised so corpus growth never masquerades as demand. Complete years only.

3.7
3.0
1.8
2.5
3.0
3.0
3.1
2019202020212022202320242025

The pale bars are 2025 onward. The Procurement Act went live on 24 February 2025 and changed how notices are written, so the step across that date is partly a change in convention and not only a change in demand. We have not measured how much of it is which, so please do not read this as a trend.

The receipts

Notices that demand it, and the sentence each demand was found in. Nothing is counted here without one.

  • Driver and Vehicle Standards Agency

    Cyber Security - ISO27001 and Cyber Essentials Plus where applicable (Must Have)
  • HM Revenue & Customs

    The service provider must possess, or be able to demonstrate, working towards achieving the current ISO/IEC 9001:2015, ISO/IEC 27001:2022, and ISO/IEC17025 certification, accredited by UKAS or a comparable body.
  • Telephonymandatory

    THE EXTRACARE CHARITABLE TRUST

    The supplier shall hold ISO 27001 (preferred) or Cyber Essentials Plus certification at the time of bidding and maintain certification for the duration of the contract.
  • Natural History Museum

    Any supplier would need to be certified to ISO27001 and Cyber Essentials Plus.
  • NETWORK RAIL INFRASTRUCTURE LIMITED

    Compliance with Network Rail’s information and cyber security standards, as well as relevant industry standards (e.g., ISO 27001, GDPR), is mandatory.
  • The Police and Crime Commissioner for Humberside

    We also require security certification at both ISO 27001 and Cyber Essentials Plus levels, and staff security clearance must conform to BS7858:2019.
  • Vantage RE Limited

    In particular, ISO 27001 certification is a mandatory requirement for all responding vendors.
  • Brighton & Hove City Council

    The service must integrate with our existing Veeam infrastructure, provide a minimum of 600TB storage, and comply with UK GDPR and ISO 27001 standards.
  • Royal Berkshire Fire and Rescue Service

    12.1 Security: Must comply with ISO 27001 and UK Cyber Essentials standards.
  • Associated British Ports

    The supplier should be able to provide physically present forensic support at our group or port locations (within the UK) to assist with a major incident within 4 hours.The security partner must demonstrate having audited security standards in place including ISO 27001.
  • THE UNIVERSITY OF CHICHESTER

    The University is amongst the first of HEIs to achieve institution wide ISO27001, and also has Cyber Essentials and Cyber Essentials Plus Accreditation, where this is required (with additional security protocols) for Defence Contactor work.
  • Ministry of Defence

    DE&S ISO/IEC 27001:2022 - currently certified to ISO/IEC 27001:2013 (to implement on expiry of existing contract which expires in July 2026).

See it live

2 open tenders demand ISO 27001 (information security) right now.

Browse the tenders →

Tell us what you already hold and we will show you which of these notices you were already eligible for — and what one more certificate would open.

Get set up free →

Method: Every count here is a floor. We match the text of the notice, and a notice description is a summary — most tender packs demand things it never mentions.“Said must” counts only explicit obligation language in the matched sentence itself; anything ambiguous is counted as a mention, never as mandatory. Trend compares rates per 10,000 notices per complete calendar year.