CPV 72-2
CPV 72-2 Software development services
Bespoke software development, systems integration, and digital delivery tender activity under CPV group 72-2 across the UK public sector.
About CPV 72-2
CPV 72-2 is the Common Procurement Vocabulary group covering software programming and consultancy services. It is the build half of IT: developing software rather than licensing it, and the consultancy that surrounds that work.
The group covers bespoke application development, systems integration and interfacing, software consultancy and architecture, agile delivery teams, testing and quality assurance, data migration, and the maintenance and enhancement of custom-built systems.
The public sector buys development work in two quite different shapes, and the distinction determines which suppliers can compete. The first is outcome-based: a buyer contracts for a defined product or service to be built and delivered. The second is capacity-based: a buyer contracts for a multidisciplinary team to work on its priorities for a period. Central government has favoured the second for over a decade, procuring teams through digital outcomes frameworks, while local government and the NHS more often buy the first.
Active CPV 72-2 tenders
Live activity is steady and broad. Legacy system replacement is the largest single driver, as public bodies move off ageing line-of-business systems that are increasingly expensive to support. Integration work is the second: as organisations adopt more packaged software, the work of making those systems talk to each other grows rather than shrinks.
Data and reporting work has expanded considerably, driven by the demands of performance reporting, population health management, and the practical need to combine data held in systems that were never designed to share it.
| Active sub-category | Typical procurement route | Primary buyer pattern |
|---|---|---|
| Multidisciplinary delivery teams | Digital outcomes framework | Central government or large body |
| Bespoke application build | Open procedure or framework | Council, NHS body, agency |
| Systems integration and interfacing | Bespoke competition | Any organisation with multiple systems |
| Data engineering and analytics | Digital outcomes or open | Department, ICB, combined authority |
| Testing and quality assurance | Framework call-off | Large programme owner |
Top buyers procuring CPV 72-2
Central government departments and their agencies are the largest buyers by value. In our own corpus the Scottish Government is the most frequent publisher under this group by a considerable margin, alongside the Scottish Police Authority, Perth and Kinross Council, the University of Strathclyde, the Ministry of Defence, and the Crown Office and Procurator Fiscal Service. That reflects both real programme volume in Scotland and the more granular notice publication practice on the Scottish portal.
Universities are a substantial and often overlooked buyer group, commissioning research computing, student systems, and bespoke academic tooling. Police bodies procure specialist operational systems with demanding security requirements. Local authorities buy integration and bespoke development around packaged line-of-business systems more often than they buy wholly custom applications.
Typical contract values under CPV 72-2
The median notice sits around seven hundred thousand pounds, which is consistent with a team-based engagement of moderate duration or a mid-sized bespoke build. The upper decile reaches well into the tens of millions, covering multi-year platform programmes and large integration efforts.
Team-based procurements are usually priced as day rates against an anticipated team shape, which means the contract value is a function of duration and headcount rather than a fixed deliverable price. Suppliers should read whether the buyer is committing to a period or to an outcome, because the risk profile differs entirely. Outcome-based fixed-price development in the public sector carries significant risk where requirements are not settled, and experienced suppliers price that risk or decline it.
Compliance and certifications for CPV 72-2 bidders
Cyber Essentials Plus is effectively baseline for development work touching public data, and ISO 27001 is commonly required for anything at scale. Secure development practice is assessed directly: buyers ask about secure coding standards, dependency management, vulnerability scanning, and how security testing is built into the delivery process rather than bolted on.
Accessibility is a legal obligation for public sector digital services, so conformance to the specified WCAG level is a requirement rather than an aspiration, and buyers increasingly ask for evidence of accessibility testing including assistive technology testing with users. Central government work is assessed against the Service Standard and the Technology Code of Practice, and suppliers should expect service assessments during delivery, not just at procurement. Health sector development requires the Data Security and Protection Toolkit and, for anything clinical, a named clinical safety officer and documented hazard log. Security clearance for named developers is required more often than suppliers anticipate, particularly in policing, defence, and justice work, and lead times are long.
Frequently asked questions
What is the difference between buying a team and buying an outcome?
Buying a team means the supplier provides named people with specific skills for a period, and the buyer directs their work. Buying an outcome means the supplier commits to deliver a defined thing for a defined price. Central government digital procurement is predominantly the former, because requirements evolve during delivery and fixed scope tends to produce the wrong product. The commercial implications are substantial: team-based work has lower delivery risk for the supplier but requires a bench of available, often cleared, specialists; outcome-based work carries scope risk that must be priced. Read the notice carefully, because the titles are not always clear about which is being bought.
Do I need to work in the open and follow the Service Standard?
For central government digital services, yes, and it affects delivery as well as procurement. The Service Standard requires user research, iterative delivery, accessibility, and service assessments at defined points, and a supplier unfamiliar with that way of working will struggle even after winning. Outside central government, adoption varies: many councils and NHS bodies apply similar principles but assess less formally. Suppliers should be honest at tender about their experience of assessed delivery, because buyers who work this way can tell quickly whether a supplier has done it before.
How much does legacy replacement dominate this market?
It is the largest single driver, and it shapes what buyers value. Most public sector development work is not building something new on a clean slate; it is replacing or extending something that already holds critical data and cannot stop working during the transition. Suppliers who can evidence data migration, parallel running, and phased cutover on comparable systems compete considerably better than those presenting greenfield build experience. The technical risk that buyers worry most about is migration, not development.
Should I watch CPV 72-2 or CPV 48-1 for software work?
Both, because buyers split them inconsistently. Group 48-1 covers software packages, meaning licensed products, while 72-2 covers the development and consultancy work. A procurement that involves configuring and integrating a licensed product might be coded either way depending on where the buyer thinks the value sits. Any supplier whose offering combines product and services should monitor both groups and the two parent divisions, and should treat the coding as an indication of how the buyer is framing the purchase.
| Buyer | Title | Value | Closing date |
|---|---|---|---|
| Notting Hill Genesis (NHG). | Customer Due Diligence (CDD) Platform | £550,000 | 2026-10-19 |
| Natural History Museum | NHM150 Western Galleries - AV Hardware Integrator | £300,000 | 2026-10-23 |
| Department for Energy Security & Net Zero | CSP26751 - Delegates for International Energy Agency Technology Collaboration Programme | £147,934 | 2026-10-13 |
| Historic England | ITT - Taxation and reuse - UID 350 | £29,166.67 | 2026-10-15 |
| Cairn Housing Association | Penetration Testing and Cybersecurity Assessment | 2026-10-16 | |
| Data as of 23 Aug 2026 | |||
Top buyers for this CPV
ministry of defence
626 contracts
home office
547 contracts
ministry of justice
382 contracts
defra network etendering portal
367 contracts
scottish government
317 contracts
Top buyers for CPV 72-2
- ministry of defence
- home office
- ministry of justice
- defra network etendering portal
- scottish government
Related CPVs
Win more CPV 72-2 contracts
KimonBids monitors the UK procurement portals and alerts you to relevant cpv 72-2 software development services contracts.
Find CPV 72-2 tenders free