CyberOne has been selected as an approved supplier on G-Cloud 15, enabling public sector organisations to procure our cyber security services through the UK Government’s Digital Marketplace.
This appointment gives eligible public sector organisations a clear route to access CyberOne’s cybersecurity consultancy, professional services and managed security capabilities. G-Cloud 15 has been awarded but is not yet open for public sector use.
The Government Commercial Agency expects G-Cloud 15 to become available during the week commencing 7th September 2026. The updated framework will give public sector organisations a streamlined route to cloud services that support stronger security, operational resilience and reliable service delivery.
What Is G-Cloud?
G-Cloud is a UK government procurement framework that allows eligible public sector organisations to buy cloud-based services from pre-evaluated suppliers.
It provides an established route to market for cloud hosting, cloud software and cloud support services, including off-the-shelf and pay-as-you-go solutions. Supplier information, service descriptions and associated commercial details are made available through the Digital Marketplace, helping buyers identify and compare options relevant to their requirements.
Since 2012, G-Cloud has helped public sector organisations access cloud services while maintaining the governance and transparency required for public procurement. Instead of running a new sourcing process for every need, eligible organisations can use the framework’s defined procedures to buy what they need more efficiently.
What Is Different About G-Cloud 15?
The Government Commercial Agency calls G-Cloud 15 the biggest upgrade in the framework’s history. One key change is consolidating three separate commercial agreements into a single structure.
G-Cloud 15 brings together Cloud Compute 2 and the services previously covered by G-Cloud 14. This broader structure is intended to give public sector organisations one agreement through which they can address a wider range of cloud requirements.
The framework is estimated to be worth approximately £14 billion over its four-year term, with around £3 billion of public sector cloud spending expected to flow through it each year. Call-off contracts may run for up to 60 months, giving buyers greater scope to establish longer-term relationships where this is appropriate for the service and procurement requirement.
G-Cloud 15 is the first version to operate under the Procurement Act 2023 and to use an open-framework model. This means eligible providers can apply at set intervals during the framework’s term, making it easier for new and growing suppliers to join without waiting for the next full G-Cloud cycle.
The new framework brings the most thorough supplier assessment to date, covering quality, technical capability and pricing. Buyers can still test solutions at the call-off stage or run a competition if needed, but the expanded evaluation is designed to give greater confidence when selecting suppliers.
Who Can Use G-Cloud 15?
G-Cloud 15 is designed for eligible UK public sector organisations, not for private businesses buying cloud services for their own operations.
Potential users include:
- Central government departments and agencies
- Local authorities
- NHS trusts and other healthcare organisations
- Schools, colleges and universities
- Police, fire and other emergency services
- Housing associations
- Non-departmental public bodies
- Other eligible organisations delivering public services
The framework covers cloud hosting, software and support. Its consolidated structure helps public sector buyers manage more of the cloud lifecycle through a single agreement.
G-Cloud does not replace the need for strong procurement governance. Buyers still need to define the outcomes they want, confirm eligibility and follow the right buying process. Service suitability, value for money, technical fit and organisational risk all remain important.
Final buyer documentation should be checked against each organisation’s procurement, legal, information governance and cyber security policies.
Why Cyber Security Matters in Public Sector Cloud Procurement
Cloud technology supports many of the systems public services depend on. It can help organisations modernise ageing technology, improve service accessibility and create more flexible ways of working. At the same time, cloud adoption changes where information is held, how people access it and how responsibility is shared between customers and technology providers.
Public sector organisations handle sensitive information about citizens, employees, finances and operations. A cyber incident can disrupt more than internal systems. It can affect frontline services, delay essential work and reduce public trust.
Cyber security should be built into procurement decisions from the start, not treated as a separate technical step after selection. Buyers need to check how a service supports secure data handling, identity and access management, threat detection, incident response and operational continuity. It is also important to understand how the service fits with existing technology and how security responsibilities are shared between the organisation and its suppliers.
CyberOne’s Inclusion on G-Cloud 15
CyberOne’s appointment on G-Cloud 15 gives public sector buyers clear visibility of our cyber security capabilities through the Digital Marketplace.
CyberOne supports organisations with cyber security Consultancy, Professional and Managed Security Services. Our Digital Marketplace profile highlights our experience with government departments, agencies and public bodies, backed by 24x7 Global Security Operations Centre and Network Operations Centre expertise.
Our services are backed by recognised industry standards, including NCSC and CREST. These capabilities help organisations assess how specialist advice, continuous monitoring, incident response and operational oversight support their wider cloud and resilience strategies.
CyberOne brings deep expertise in Microsoft Security. This is especially valuable for public sector organisations already using Microsoft 365, Azure or Microsoft security technologies, but who have not yet fully integrated these capabilities or aligned them to a consistent operating model.
Getting more value from Microsoft investments is not just about turning on extra products. Organisations need to understand their risk priorities, improve configuration, connect security signals and put in place the right processes to investigate and respond to incidents.
For public sector leaders, the goal is greater visibility, better decision-making and stronger operational resilience, using technology the organisation may already own.
CyberOne’s listing currently gives organisations an opportunity to familiarise themselves with the company’s profile and the wider supplier landscape before the framework becomes operational.
For more details on CyberOne’s services, view CyberOne’s G-Cloud 15 supplier profile.
Want to learn more about our services? Connect with a CyberOne expert for a complimentary 30-minute consultation.