October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

G-Cloud 15’s Supplier Requirements: Why SMEs Say the Rules Could Lock Them Out

G-Cloud 15’s financial, certification and insurance conditions have prompted claims that smaller cloud providers could struggle to access higher-security public-sector hosting work. The key distinction: the £75m insurance figure applies to Lot 1b, not every supplier.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

G-Cloud 15’s toughest proposed entry conditions apply to cloud-hosting suppliers, not every supplier on the framework. The main flashpoints are a detailed financial-readiness assessment, Cyber Essentials Plus, six ISO standards and, for Lot 1b, a reported minimum of £75 million in combined insurance cover. Suppliers and experts say the package could deter smaller providers from higher-security public-sector work. That is a concern about a possible de facto barrier—not a formal ban on SMEs.

As of 18 August 2026, the planned award date of 17 September 2026 is still in the future. The requirements have not yet produced a published result showing how many suppliers, or how many SMEs, will be admitted.

What is G-Cloud 15?

G-Cloud is a UK public-sector procurement framework for cloud hosting, software and support. The procurement, run by the Crown Commercial Service (CCS) under reference RM1557.15, is intended to replace G-Cloud 14, G-Cloud 14 Lot 4 and Cloud Compute 2. It is being procured under the Procurement Act 2023. The current tender notice calls it the largest framework of its kind in the public sector. (Find a Tender, Notice 067801-2025)

The notice estimates the framework’s total value at £8 billion excluding VAT (£9.6 billion including VAT). It separately gives an estimated £14 billion excluding VAT for each of Lots 1a and 1b, while warning that lot values may be shared. Those are procurement estimates, not guaranteed supplier revenue or figures to add together. CCS also reported FY2023–24 framework spend of £3.1 billion for G-Cloud and £0.5 million for Cloud Compute; these are figures in the procurement documents, not estimates of the entire UK public-cloud market. (Find a Tender, Notice 068082-2025; Notice 067801-2025)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CCS became the Government Commercial Agency (GCA) on 1 April 2026. “CCS” remains the appropriate name when describing the 2025 procurement debate and the contemporary responses. (GCA, G-Cloud 14 agreement page)

Which services sit in each lot?

Lot Scope
1a Cloud Hosting: core IaaS and PaaS subscription services.
1b Cloud Hosting for IaaS and PaaS services used for information above the “Official” security classification.
2a Infrastructure Software as a Service.
2b Software as a Service.
3 Cloud Support.

G-Cloud 15 removes the separate Lot 4 arrangement and incorporates the relevant purchasing function into the new framework. Lot 1b should not be casually described as covering all “classified” or national-security information: the notice specifies information above “Official.” (Computer Weekly; Find a Tender)

What requirements triggered the anti-SME criticism?

The disputed conditions fall most heavily on hosting applicants in Lots 1a and 1b. The official tender-document list includes separate technical-ability certificates and a Gold Financial Viability Readiness Assessment (FVRA) document for these lots. The table summarises the requirements and the practical concern suppliers raised; it does not establish that every supplier will incur the same cost or fail the same test. (GCA, G-Cloud 15 tender documents; Computer Weekly)

Requirement Lots Why suppliers objected
Gold Standard Financial Viability Readiness Assessment 1a and 1b Requires more detailed financial information and preparation than a basic credit-screening route, which can be demanding for smaller or fast-growing businesses.
Cyber Essentials Plus 1a and 1b Assessment and any remediation can add cost and work.
ISO 9001 1a and 1b Quality-management certification adds audit and maintenance obligations.
ISO 20000-1 1a and 1b Requires certification for IT service management.
ISO 27001 1a and 1b Requires certification for information-security management.
ISO 27017 1a and 1b Addresses cloud-specific security controls; suppliers said the timetable was difficult.
ISO 27018 1a and 1b Addresses protection of personally identifiable information in public cloud.
At least £75 million aggregate insurance cover, as reported 1b Could require insurance capacity and premiums beyond what a smaller provider can secure.

The ISO change was a timing concession, not a waiver. Suppliers without the required certifications could demonstrate by the 30 January 2026 submission deadline that the certification process had begun, with confirmation from an authorised third-party accreditation body. The standards remained mandatory for Lots 1a and 1b. (Computer Weekly)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why is Lot 1b the sharpest point of dispute?

The supplier concern

Above-“Official” hosting is a specialist market in which UK SMEs may have capabilities that buyers want. Critics argue that a high insurance floor can exclude a technically capable supplier because of its balance sheet or access to insurance, rather than the security quality of its service. If fewer providers can compete, the result could be greater dependence on a smaller group of large suppliers, with possible consequences for choice, resilience and prices. Those are plausible risks, not outcomes established before award.

“Anti-SME” is the critics’ characterisation, not a finding that CCS formally barred smaller businesses. The tender notice identifies SMEs as suitable participants and does not set a numerical limit on the number of suppliers. The question is whether the costs, time and compliance capacity required amount in practice to a barrier to entry. (Find a Tender, Notice 068082-2025)

The assurance case

A buyer procuring hosting for higher-consequence workloads may reasonably seek evidence that a supplier has robust security and service-management controls, can withstand financial stress and can meet liabilities after a serious incident. Certifications, financial assessment and insurance can each provide part of that assurance. The policy question is whether the required level is calibrated to the actual risks and contractual liabilities, rather than simply whether stronger controls sound preferable.

In the contemporary response reported by Computer Weekly, CCS directed suppliers to the formal clarification process rather than publicly defending the disputed requirements. It would therefore be inaccurate to present a specific proportionality argument as an official CCS explanation. (Computer Weekly)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does the £75 million insurance figure mean?

Computer Weekly reported that Lot 1b requires professional-indemnity, public-liability and employers’ liability insurance whose combined total reaches at least £75 million. This is not the same as saying every Lot 1b supplier must hold one £75 million professional-indemnity policy. The relevant contractual document is Joint Schedule 3: Insurance Requirements, listed on the GCA tender-documents page. Suppliers should check its wording for the policy types, insured entity, limits and other conditions that apply to their bid. (Computer Weekly; GCA tender documents)

The reported comparison with G-Cloud 14 helps explain the reaction. G-Cloud 14 ultimately required about £1 million professional indemnity, £1 million public liability and £5 million employers’ liability—a combined £7 million. The reported G-Cloud 15 baseline for Lots 1a, 2a, 2b and 3 was also about £7 million, while the £75 million figure was associated with Lot 1b. It is not a threshold for every G-Cloud 15 supplier. (Computer Weekly)

During the previous G-Cloud 14 procurement, CCS initially proposed higher insurance levels, suppliers objected that SMEs could be priced out, and the requirements were later reduced to the £1 million/£1 million/£5 million structure. That history explains why some G-Cloud 15 suppliers expected another change; it does not prove that the Lot 1b requirement will be revised. (Computer Weekly)

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What was the timetable, and what is the status now?

Milestone Date
Invitation to tender published 23 October 2025
Clarification-question deadline 12 December 2025 at 3pm
Tender-submission deadline 30 January 2026 at 3pm
Planned framework award 17 September 2026
Planned framework period 17 September 2026 to 16 September 2030

These are the published timetable dates; the planned award and framework period remain subject to the procurement timetable and any challenge or delay. As of 18 August 2026, the submission deadline has passed but the planned award is still ahead. The available evidence does not establish the final number of admitted suppliers, any later change to the requirements, or actual competition and prices on Lot 1b. (GCA agreement page; Find a Tender, Notice 068082-2025)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

GCA describes G-Cloud 15 as an open framework, but the available official information cited here does not establish the operational date or process for a later joining window. Suppliers should not assume a specific future admission date without checking the final framework documents. (GCA tender documents)

What should suppliers and buyers consider?

For suppliers

  • Choose the target lot first. The strongest disputed requirements concern Lots 1a and 1b. A SaaS, infrastructure-software or support business may instead be suited to Lot 2a, Lot 2b or Lot 3, but these routes do not provide equivalent access to higher-security hosting work.
  • Check insurance mechanics, not just the headline limit. Review limits, policy types, exclusions, territorial scope, named entities, group arrangements and whether cover must be maintained through framework and call-off terms. Ask a broker and procurement lawyer to assess the actual Joint Schedule 3 wording rather than assuming a group policy or a partner’s cover will satisfy it.
  • Verify certification scope and timing. Check that certificates cover the legal entity, sites, services and environments being offered, and that expiry dates and any evidence-of-progress route meet the tender conditions.
  • Prepare for the financial assessment. Establish whether the business can provide the requested accounts, forecasts, liquidity information or group support, and understand how rapid growth or a recent funding round may affect the assessment.
  • Map the delivery model. Identify infrastructure ownership, subcontractors, data-location controls, incident response and service continuity. A hyperscaler or accredited partner may add scale, but does not automatically make an applicant eligible.
  • Test the business case. Compare the cost of insurance, certifications and audits with realistic pipeline and the ability to recover those fixed costs through catalogue pricing.

For buyers

  • Assess whether Lot 1b provides enough genuine supplier choice, including technically capable smaller providers.
  • Consider whether the insurance threshold matches the workload and contractual exposure, and whether it could narrow competition or increase prices.
  • Check whether a specialist SME can participate through a prime contractor, partnership or consortium, while recognising that this is not the same as direct framework access.
  • Balance supplier financial resilience against the risk of concentrating critical services among a few providers.

Why framework admission is not the same as winning work

Joining a lot is a gateway to that framework’s purchasing routes, not a guarantee of call-offs or revenue. Buyers may use direct award or a further competition, depending on the framework rules and requirement. Suppliers can also participate through subcontracting or partnerships, but those arrangements do not necessarily give them the same position as a framework supplier. Conversely, inability to join Lot 1b may prevent a provider from competing directly for the category of hosting work covered by that lot.

The eventual market effect can only be assessed with evidence such as admitted-supplier numbers by lot, SME participation, call-off competition and contract outcomes. Before award, the defensible conclusion is narrower: G-Cloud 15 raised a credible question about whether assurance requirements for higher-risk hosting protect buyers without excluding capable smaller suppliers.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.