This opportunity is closed for applications

The deadline was Wednesday 25 January 2023
Strategic Command (UKStratCom) part of the Ministry of Defence (MoD)

CRP - Secure at Reach - Cyber Security Specialist B

7 Incomplete applications

4 SME, 3 large

18 Completed applications

14 SME, 4 large

Important dates

Wednesday 11 January 2023
Deadline for asking questions
Wednesday 18 January 2023 at 11:59pm GMT
Closing date for applications
Wednesday 25 January 2023 at 11:59pm GMT


Specialist role
Cyber security consultant
Off-payroll (IR35) determination
Supply of resource: the off-payroll rules will apply to any workers engaged through a qualifying intermediary, such as their own limited company
Summary of the work
Support the project with strategic technical implementation of cyber risk assessment and solution proposals to mitigate or remediate cyber risks.
Latest start date
Monday 6 March 2023
Expected contract length
12 months, with an option to extend by a further 6 months, subject to financial approvals.
No specific location, for example they can work remotely
Organisation the work is for
Strategic Command (UKStratCom) part of the Ministry of Defence (MoD)
Maximum day rate
£1125.41 (exc VAT) Daily Rate

About the work

Early market engagement
Not applicable.
Who the specialist will work with
Working with Project Manager and Project Technical Lead. Specialist will be part of the core team and will work within the core team to establish work streams that will involve different suppliers where applicable.
What the specialist will work on
To develop a proven & robust process, backed up with policy and technology that will provide cyber risk identification and reduction in the deployed environment. This also include the provision of high priority risk reduction where required.

Work setup

Address where the work will take place
London / Corsham (DD CRP) / Occasional Work at UK Military Sites.
Working arrangements
Hybrid working, where the core team will meet at least once every week (London) and work with assessment locations, e.g. base station of an operation. This will be determined based on the work being undertaken.
Security clearance
Minimum of SC level clearance, DV-held preferred. Clearance must be in place prior to the contract start date and remain valid for the contract duration.

Additional information

Additional terms and conditions
T&S will be reimbursable when travelling to alternate locations (to be confirmed). All expenses must be pre-agreed between the parties and must comply with the MOD Travel and Subsistence (T&S) Policy.

Off-payroll working rules apply (IR35 in-scope). Any Personal Services Company (PSC) candidates will require to come through an umbrella company.

Risk Assessment Ref: RAR-761977443

Cyber risk profile: High

Potential bidders are required to complete a Supplier Assurance Questionnaire (SAQ) against the security controls appropriate to the risk level. Tenderers should complete their SAQ using the form in the following link:

Skills and experience

Buyers will use the essential and nice-to-have skills and experience to help them evaluate suppliers’ technical competence.

Essential skills and experience
  • Proven track record of delivering defined cyber security consultancy services [5%]
  • Experience of implementing cyber security controls and solutions within an operational technology (OT) environment [7.5%]
  • Providing cyber security guidance on critical infrastructure within broad or targeted range of complex systems through normal vs. abnormal contexts of operation [7.5%]
  • Providing cyber security governance, performing cyber security assessments, and providing risk assessment methodologies with outcomes to determine cost effective solution [7.5%]
  • Experience in development of controls, procedures, policies to provide cyber security risk mitigations whilst meeting both operational and regulatory requirements [7.5%]
  • MoD Background or Military with joint effects background preferred [5%]
Nice-to-have skills and experience
  • Have critical national infrastructure projects experience) [2.5%]
  • Proven experience / expertise in Assessment of Operational Technology / Internet of Things systems using IEC 62443 or relevant frameworks e.g. NIST CSF, CAF or others [5%]
  • Assured Consultant certified through the NCSC [] [5%]
  • Management of multiple external stakeholders to the project and resolve any impediments around prioritisation of work required alongside other competing priorities.[5%]
  • Relevant Certified Cyber Professional (CCP) qualifications [2.5%]

How suppliers will be evaluated

All suppliers will be asked to provide a work history.

How many specialists to evaluate
Cultural fit criteria
  • Work as a team with our organisation and other suppliers [collaboration across defence and its service providers] [5%]
  • Be transparent and collaborative when making decisions [Recording all artefacts that support the decision making / rational] [5%]
  • Take responsibility for their Work [Accountability - ability to identify potential blockers, working with multiple stakeholders / contributors to transparently achieve resolution] [5%]
  • Share knowledge and experience with other team members [Building the project knowledge based through sharing of information / artefacts / documentation to support onboarding and growth within organisation. [5%]
Additional assessment methods
Evaluation weighting

Technical competence


Cultural fit




Questions asked by suppliers

1. Is there a current incumbent or preferred supplier for this role?
There is no incumbent or preferred supplier for this requirement.
2. In the “Nice to have skills and experiences”, what accreditation is desirable from NCSC (e.g. CHECK)
CHECK is an example of a scheme from NCSC that will be considered, alongside other NCSC accreditation schemes (Cyber Security Consultancy or Cyber Incident Response).

Any relevant qualifications to support the application will be considered under "Relevant Certified Cyber Professional (CCP) qualifications".
3. How many days will be required on site per week?
Day rate does not include T&S Expenses. T&S expenses are covered separately, hence the rate should be for effort only.
4. Please can you confirm the “assessment locations” and how many days are expected to be required at each assessment location per month?
We are unable to confirm the specifics. This depends on target systems under investigations. They will span across the deployed environment and include systems (non I.T end points, Cyber Physical end points) used across the various front line commands, pan defence.
5. Please can the Authority confirm whether the onsite working requirements for Specialist role A (Ref 19203) and Specialist role B (Ref 19206) are the same. If not, how do they differ?
We are unable to confirm the specifics. But we expect to run paralell assessments. Therefore, this depends on target systems under investigations and its locations. This will differ.
6. Please could the Authority confirm the expected number of days to be worked onsite per week at the base locations, assessment locations and how many days can be worked remotely?
We are unable to confirm the anticipated or likely number of days either onsite or remote working. This will depend on target systems under investigations and its assessment location.
7. So that we may plan resource accordingly, please could you confirm the target assessment location regions and expected number of days required at these locations per week, per month and per annum?
We are unable to confirm the anticipated or likely number of days. Target locations will span across the various front line command base(s) and led by where the trial/operation is being conducted.