Cyber Security Services 3 (CSS3) remains an important route into public sector cyber security work. The Dynamic Purchasing System has now been extended for the final time to 13 February 2029, with the estimated total value remaining at £800 million. It gives central government and the wider public sector access to suppliers across a broad range of cyber security services.
For suppliers, the extension matters because CSS3 is not a closed framework with a single historic application window. Eligible organisations can still seek admission to the DPS and, once appointed, compete for relevant opportunities issued by public sector buyers.
If CSS3 is relevant to your cyber security services, speak to Thornton & Lowe about your readiness and the evidence you will need to compete effectively.
What is Cyber Security Services 3?
CSS3 was established to give public sector organisations a compliant route to cyber security suppliers. The DPS uses filters covering areas such as certification, service capability, standards and experience so buyers can identify suppliers that fit a particular requirement before running a further competition.
The latest Contracts Finder update confirms that the DPS has been extended to 13 February 2029 and that the estimated total value remains £800 million. The notice also makes clear that this is the final extension. Suppliers should therefore treat the remaining period as a defined window in which to secure admission and build a pipeline of relevant competitions.
The official CSS3 Contracts Finder notice should be used alongside the bid pack and current supplier guidance when preparing an application.
Who can use the DPS?
CSS3 supports central government departments and the wider UK public sector. This creates potential demand across local government, healthcare, education, defence and other public bodies that need specialist cyber security support.
For suppliers, the commercial value of the DPS comes from access to buyer competitions rather than appointment alone. Admission gives you a route into the market, but buyers will still evaluate capability, quality, price and any requirement-specific criteria when they procure services.
Our guide to IT, digital and technology tenders provides broader advice on how public sector technology buyers assess technical capability, delivery and value.
What services can suppliers provide through CSS3?
The DPS is designed for a range of cyber security services rather than one narrow requirement. Buyers can use the system to identify suppliers by the categories and qualifications relevant to their need.
Depending on the competition, suppliers may need to evidence recognised certifications or specialist assurance, alongside delivery capability in areas such as security testing, incident response, managed security, consultancy and related cyber services.
The important point for bidders is to keep the application and future competition responses evidence-led. General statements about technical expertise are unlikely to be enough when a buyer can compare suppliers with specialist credentials and relevant contract examples.
How suppliers should prepare
Start by checking that the services and certifications listed in your CSS3 profile still reflect your current offer. A DPS profile can become commercially limiting if it is no longer aligned with the work you are capable of delivering.
You should also prepare a focused bank of evidence covering:
- relevant public sector or regulated-sector cyber security contracts
- technical accreditations and specialist certifications
- mobilisation and service transition
- incident management and escalation
- information security and data protection
- service levels, reporting and continuous improvement
- resourcing, business continuity and capacity
- measurable outcomes from previous assignments
Once admitted, monitor competitions closely and apply a disciplined bid/no-bid process. Not every opportunity released through CSS3 will be equally suitable, and competing selectively can help protect bid resource for requirements where your technical strengths and evidence are a close match.
Quick facts
- Commercial route: Dynamic Purchasing System
- Estimated value: £800 million
- Coverage: UK public sector
- Supplier suitability: SMEs are included
- Current status: Open opportunity
- Final end date: 13 February 2029
- Call-off route: Buyer competitions among suitably filtered suppliers
Make the most of the remaining CSS3 window
The final extension gives cyber security suppliers additional time to join CSS3 and compete for public sector requirements, but the value of admission depends on what happens afterwards. Suppliers need a clear opportunity pipeline, current evidence and the capacity to respond quickly when suitable competitions appear.
At Thornton & Lowe, we support technology suppliers with bid strategy, tender writing and independent review. Contact our team if you want practical support with CSS3 or another public sector cyber security opportunity.