Sector
AI and Data Centre Bid Writing and Framework Support
Two very different markets share this page because they are usually confused with each other. AI and software suppliers have a real public sector framework pipeline and can be placed on it. The data centre supply chain mostly does not, and the honest route in is approved vendor list entry rather than a tender pipeline. We work both, and we will tell you which one you are actually in.
If you sell AI or software: the routes that exist
The most common question we get from AI companies is a version of "which schemes should we be on". The answer is shorter than most people expect, because the wrong framework is worse than no framework: it consumes a quarter of effort and returns nothing. What follows is the practical set, with what each one is actually for.
Artificial Intelligence DPS
Government Commercial AgencyA dynamic purchasing system rather than a closed framework, so it accepts applications on a rolling basis rather than through a single window. That makes it the usual first route for an AI supplier with no public sector track record. Confirm current lot dates with the GCA before you plan around them: the published lot and framework end dates have not been consistent.
Cyber Security Services 3 DPS
Government Commercial AgencyOpen continuously. Relevant to AI suppliers more often than they expect, because model security, assurance and testing work is frequently bought here rather than through an AI-specific route.
Innovation Marketplace
Government Commercial AgencyPreliminary market engagement is running now, with the invitation to tender expected in February 2027. Engagement at the PME stage is the cheapest influence any supplier ever buys, and almost nobody does it.
Health Systems Support Framework
NHS EnglandThe accreditation route for population health management, analytics and system transformation suppliers selling to Integrated Care Boards. The natural home for health analytics and clinical decision support.
Healthcare AI Solutions
NHS Shared Business ServicesAn open framework, which under the Procurement Act means it must reopen. Suppliers who miss the current round should be on a list for the next window rather than waiting to notice it.
Alongside these, G-Cloud remains the route for hosted software and Digital Outcomes and Specialists for outcome-based delivery. See our G-Cloud framework guide and Digital Outcomes and Specialists guide for how the two differ and which fits which kind of supplier.
Selling AI into the NHS is a compliance problem before it is a bid problem
Healthcare is where most UK AI suppliers find their first serious public sector revenue, and it is also where most of them discover a compliance layer they had not budgeted for. The Data Security and Protection Toolkit is effectively mandatory. Clinical risk management under DCB0129 for manufacturers and DCB0160 for deploying organisations is assessed, and a supplier without a named clinical safety officer will struggle to answer the question at all. Software meeting the definition of a medical device may require UKCA marking and MHRA oversight depending on its intended purpose.
These are not scored criteria you can write your way through. They decide whether you are eligible to bid, and they have lead times measured in months. An AI supplier planning to bid an NHS opportunity in the first half of 2027 should be starting the compliance work now, not when the invitation to tender publishes. That sequencing decision is worth more than any amount of writing quality applied later.
On evaluation itself, NHS AI procurements weight heavily towards clinical safety, information governance, interoperability against NHS data standards, and demonstrable outcomes rather than model performance in the abstract. Evaluators are increasingly sceptical of accuracy claims presented without a clinical context, a comparator and a named deployment. The suppliers that score well describe a real deployment in a named organisation with a measured before and after. See our NHS and healthcare bid writing page for how the wider NHS evaluation model works.
If you serve data centres: what is actually true
There is a great deal of noise in this market and comparatively little contracting that works the way suppliers assume. Four things are worth being clear about before you commit business development budget to it.
The money is real
National Grid contracted demand moved from 41GW to 125GW inside a year, with roughly 80GW of that attributable to data centres. That is a generational load growth figure and it drags an entire construction and engineering supply chain behind it.
The contracting mostly is not public
The bulk of AI and data centre capital is privately contracted. It does not appear on Find a Tender, it is not awarded under the Procurement Act, and there is no pipeline to monitor. A consultancy selling you a data centre tender pipeline is selling you something that does not exist at the scale implied.
The route in is the vendor list
For high voltage electrical, cooling, fire suppression, structured cabling, commissioning and specialist civils firms, the way into this market is approved vendor list entry with the hyperscalers, the colocation operators and their tier one contractors. That is a prequalification and capability evidence exercise, and it uses the same evidence base as a framework application.
Programmes move and pause
Stargate UK at Cambois is currently paused. Announced capital is not contracted capital, and positioning a business around a single announced programme is how firms end up with a sales team and no pipeline. Build for the category, not for the headline.
The practical consequence for a high voltage electrical, cooling, fire suppression, commissioning or specialist civils firm is that the work to be done is prequalification work: certifications the tier one contractors actually check, capability statements with verified figures, safety and quality evidence, financial standing, and referenceable delivery at comparable scale and criticality. That evidence base is the same one a public framework application needs, which is why we recommend building it once and pointing it at both. If the private pipeline moves, and it does, nothing is wasted.
PPN 025 and the national security narrative
PPN 025 brings national security considerations into procurement, applying to artificial intelligence contracts above a defined threshold and to energy infrastructure. In practice it means a national security narrative forms part of the response: supply chain provenance, data residency, personnel vetting, and who controls the model and the infrastructure it runs on.
This is standing content, not per-bid content. The facts about where your data sits, who your subprocessors are and how your staff are vetted do not change between submissions, and improvising them under deadline produces exactly the kind of vague answer that draws follow-up clarifications. Suppliers bidding at this level should hold a maintained national security pack the same way they hold a maintained social value library.
Cyber Essentials v3.3 has applied since 27 April 2026, and Central Digital Platform registration has been mandatory for below-threshold winners since 1 April 2026. Both are cheap to hold and expensive to be caught without.
AI and data centre procurement: common questions
Which UK government procurement schemes should an AI company be on?
For most AI and software suppliers the practical starting set is the Government Commercial Agency Artificial Intelligence DPS (RM6200), which accepts applications on a rolling basis, plus G-Cloud for hosted software and Digital Outcomes and Specialists for outcome-based delivery. Cyber Security Services 3 (RM3764.3) is worth checking, because assurance and model security work is often bought there. In health, the Health Systems Support Framework and NHS Shared Business Services healthcare AI arrangements are the routes that matter. Which of these is worth the effort depends entirely on what you sell and who buys it, and the wrong framework is worse than no framework because it consumes a quarter for nothing.
Is there a public tender pipeline for AI data centre construction?
Largely no, and this is the most common misconception in the market. UK data centre capital is overwhelmingly privately contracted by hyperscalers, colocation operators and their tier one contractors, so it does not publish on Find a Tender and is not awarded under the Procurement Act. The supply chain route in is approved vendor list entry and prequalification with those buyers, which is a different sales motion from bidding. The exception is where public sector estates, universities or NHS bodies procure their own compute or facilities, which does tender in the normal way.
What is PPN 025 and does it apply to AI procurements?
PPN 025 introduces national security considerations into procurement. It applies to artificial intelligence procurements above a defined threshold and to energy infrastructure, and it requires a national security narrative as part of the response. Suppliers bidding larger AI contracts should assume they will have to evidence supply chain provenance, data residency, personnel vetting and model and infrastructure control, and should prepare that content once centrally rather than improvising it per bid.
What compliance does an AI supplier need to sell into the NHS?
Expect the Data Security and Protection Toolkit as a baseline, clinical risk management under DCB0129 for manufacturers and DCB0160 for deploying organisations, and a named clinical safety officer. Software meeting the definition of a medical device may need UKCA marking and MHRA oversight depending on its intended purpose. Cyber Essentials Plus and ISO 27001 are routinely required rather than preferred, and evaluators assess interoperability against NHS data standards. These have long lead times, so they decide whether you can bid at all rather than how well you score.
We are an AI SME with no public sector track record. Can we win anything?
Yes, and the dynamic purchasing systems exist precisely for this. A DPS has no fixed closing window and lower barriers to entry than a closed framework, so it is the standard route for a supplier building a first public sector record. The realistic sequence is accreditation and certifications first, then DPS entry, then small call-offs that generate referenceable delivery, then the larger closed frameworks once you have case studies an evaluator can verify. Attempting the last step first is the usual reason a first application fails.
What should a data centre supply chain firm do first?
Get the prequalification pack in order before chasing any specific programme. That means the certifications the tier one contractors actually check, capability statements with verified figures, safety and quality evidence, financial standing and referenceable delivery at comparable scale and criticality. The same evidence base serves public framework applications, so it is not wasted if the private pipeline moves. Then approach the operators and tier ones for approved vendor list entry as a named category, rather than waiting for a tender that will not be published.
Framework references and dates on this page were last reviewed on 18 August 2026 against Find a Tender and gca.gov.uk. Published pipeline dates have been wrong before, so confirm on the buyer's own portal before planning a bid around them.
Tell us what you sell and we will tell you which route fits
Book a call at bookings.glaxtons.co.uk, or send the outline below.
AI and data centre procurement
What do you sell, who buys it today, and which frameworks are you already on?