Contracts for Innovation: Cyber Scale in Critical Sectors (2026)
Historical reference for Innovate UK’s closed 2026 Contracts for Innovation competition, which offered up to £3.5 million for cybersecurity solutions at TRL 7 to demonstrate, improve, and commercialise them in real critical-sector environments.
Contracts for Innovation: Cyber Scale in Critical Sectors (2026)
Historical status
Innovate UK’s Contracts for Innovation: Cyber scale in critical sectors was a single-phase 2026 competition for cyber security organisations developing solutions for critical-sector environments. The official UKRI opportunity page now lists the opportunity status as Closed, and the official Innovation Funding Service (IFS) record states that the competition is closed. The official pages reviewed for this update do not announce a subsequent round. This page is therefore a historical reference to the 2026 call, not an open application listing.
The published competition opened on 1 May 2026 at 9:00am UK time and closed on 10 June 2026 at 11:00am UK time. The closing date remains in the front matter because it identifies the archived cycle; historicalReference = true tells the site that this is an intentional archive entry. There is no current application window to join through the links below.
At a glance
| Key detail | Official 2026 position |
|---|---|
| Programme | Contracts for Innovation: Cyber scale in critical sectors |
| Funder and contracting authority | Innovate UK, part of UK Research and Innovation (UKRI) |
| Status | Closed; historical reference |
| Published | 29 April 2026 |
| Opened | 1 May 2026 at 9:00am UK time |
| Closed | 10 June 2026 at 11:00am UK time |
| Total competition budget | Up to £3.5 million inclusive of VAT |
| Maximum project value | Up to £300,000 inclusive of VAT per contract |
| Project length | 12 months |
| Project dates | Start by 1 September 2026; end by 31 August 2027 |
| Expected portfolio | Up to 20 projects, subject to the quality of applications and available funding |
| Technology stage | TRL 7 at entry, with TRL 8 or above expected at project end |
| Delivery setting | A real operational environment within a critical-sector organisation |
| Official opportunity page | https://www.ukri.org/opportunity/contracts-for-innovation-cyber-scale-in-critical-sectors |
| IFS competition record | https://apply-for-innovation-funding.service.gov.uk/competition/2452/overview/df0addbf-9146-4b7f-b8b5-e78470917675 |
What the 2026 competition was for
Innovate UK described the call as support for cyber security organisations in their growth efforts. The intended work was not only laboratory development. A successful project had to demonstrate the operation and value of an innovative cyber security solution in a real environment within a critical-sector organisation, improve it using end-user feedback, and produce evidence that could support commercialisation.
The official brief targeted promising organisations with solutions at Technology Readiness Level 7 and the potential to commercialise and grow at scale. By the end of the project, the innovation was expected to have demonstrated user acceptability and market fit, been improved after feedback from end users, and produced a completed business plan and development case study for commercialisation. Any later adoption or implementation would have required a separate, potentially competitive procurement exercise; this competition did not purchase a finished solution for permanent deployment.
The focus was narrower than general cyber research. The project had to address cyber security challenges faced by organisations in critical sectors, work closely with potential end users and customers, operate the solution in a real operational environment, and show a practical route to market. That combination made the call most relevant to teams with a mature product or service, a credible deployment setting, and enough delivery capability to learn from operational use.
Eligible applicants and delivery structure
An organisation of any size could lead a project. The applicant could work alone or use subcontracted skills and expertise from business, research organisations, research and technology organisations, or the third sector. The contract itself was awarded to a single legal entity. A consortium-style project was therefore possible only within that contracting structure: one applicant held the contract and remained responsible for the work, while subcontractors supplied specialist capabilities.
All project work and key deliverables had to be completed by the applicant and carried out in the UK. Subcontractors had to be based in the UK and could be used only for specialist skills. A proposal that depended on overseas delivery, left core deliverables with an uncontracted partner, or treated the lead as a nominal administrator would not match the published applicant rules.
The call welcomed and prioritised start-ups and SMEs in early stages of growth, but size alone did not establish fit. The applicant needed to show that it could manage a 12-month technical and commercial project, coordinate access to an operational environment, document results, and pursue commercialisation after the contract. The record also included sanctions, animal-welfare, permit, licence, export-control, and trusted-research questions that applicants had to address where relevant.
Scope and critical sectors
The IFS scope listed four challenge areas. A project could address:
- proactive cyber security defence of Critical National Infrastructure systems, including operation and incident response;
- advanced and innovative cyber security for detecting and evicting sophisticated actors from Critical National Infrastructure networks;
- innovative threat-hunting solutions for Critical National Infrastructure organisations; or
- advanced and innovative cyber security for vulnerabilities in legacy systems.
The project also had to focus on at least one of these critical sectors: Chemicals, Communications, Emergency Services, Energy, Food, Health, Space, Transport, or Water. The proposal needed to connect the technical work to a genuine organisational challenge in one or more of those sectors. Generic security software, a broad framework, or a method without a deployable cyber security application would not satisfy the scope.
The official “projects we will not fund” section excluded work that duplicated someone else’s work, lacked a critical-sector cyber security application, could not be demonstrated in a relevant operational environment, focused on frameworks and methodologies, or consisted of consultancy services. A strong archived example of fit would therefore combine an original technical intervention, a named type of critical-sector setting, a testable operational use case, and a plan to turn the results into a commercial offering.
Funding, costs, and R&D requirements
Innovate UK allocated up to £3.5 million inclusive of VAT to the competition. Individual contracts could be up to £300,000 inclusive of VAT, and projects were expected to last 12 months. The official record said the programme expected to fund up to 20 projects, while also warning that the number depended on the quality of applications and that a portfolio approach could mean that not every strong proposal was funded.
The cost ceiling applied to total eligible project costs. VAT treatment depended on the applicant’s registration status: a VAT-registered business entered eligible costs exclusive of VAT, after which VAT was added automatically, and the inclusive total could not exceed £300,000. A business that was not VAT registered entered costs exclusive of VAT without a later VAT addition, and its total still could not exceed £300,000. The record advised applicants to obtain independent HMRC advice for VAT questions.
At least 50% of the contract value had to be attributed directly and exclusively to R&D services, including solution exploration and design. R&D could include prototyping and field-testing where that work produced technical improvements and demonstrated that the solution could be made to acceptable quality standards. The brief excluded commercial development such as quantity production, supply intended to establish commercial viability or recover R&D costs, and integration, customisation, or incremental adaptations to existing products or processes from that R&D category.
Projects had to start by 1 September 2026, end by 31 August 2027, and last 12 months. Projects had to start on the first day of the month, and the applicant could not begin work until Innovate UK had approved the contract. If total cost or duration fell outside the standard criteria, the applicant had to send justification to support@iuk.ukri.org at least 10 working days before the closing date and receive approval. Without that approval, the application would be ineligible and would not be sent for assessment.
What the project needed to deliver
The scope required more than a demonstration in a controlled environment. The solution had to be deployed and operated in a real operational environment of critical-sector organisations and reach TRL 8 or above by the end of the project. The applicant also had to establish and evidence acceptability by critical-sector organisations, complete a comprehensive business model and plan for commercialisation, capture success-case metrics, develop a use case for future commercialisation, and understand standards or homologation needed in the target sector.
That set of requirements shaped the project plan. A suitable application would identify the operational user, define how access and safety would be managed, set measurable technical and user outcomes, and explain how feedback would change the product or service. It would also explain the path from the funded R&D activity to later sales or procurement. A proposal that treated the end user as a letter of support only, without a real operating role, would be weaker than the competition intended.
The brief used a portfolio approach. Innovate UK wanted variety in organisation sizes, sectors, technologies, locations, and eligible project costs, while still considering value for money. High technical scores did not guarantee funding because the available competition budget was limited and portfolio decisions could affect the final selection.
How applications were submitted in the closed cycle
Applications were made through the Innovation Funding Service. The process was available only during the 2026 window, which has now closed, but the original structure is useful for understanding the archived opportunity:
- The lead applicant created an IFS account or signed in as a representative of the organisation, then entered the project title, proposed start date, duration, organisation details, and relevant applicant information.
- The applicant checked that the project matched the critical-sector scope, selected a main sector, chose one or more listed challenges, and confirmed any relevant animal-testing, permits, international-collaboration, export-control, and trusted-research information.
- The applicant completed the four application areas: project details, application questions, finances, and project impact. The IFS record said that questions 1 to 7 were not scored, while the remaining questions were assessed against the competition criteria.
- The proposal described the idea or technology, current readiness, technical approach, state of the art and intellectual property, project plan, milestones, technical team, and route to technical and commercial feasibility. URLs were not to be included in application answers because the assessors would not open them.
- The applicant uploaded the required supporting information. The proposed idea or technology could be supported by one PDF appendix of no more than 10MB and up to two A4 pages. The project plan or Gantt chart also had to be a legible PDF of no more than 10MB and up to two A4 pages.
- Before submission, the lead applicant confirmed that all information was correct, the eligibility and scope criteria were met, every section was marked complete, the proposed milestones matched the finance summary, and any required exception had been approved in advance.
- The completed application had to be submitted by 10 June 2026 at 11:00am UK time. An application could be reopened after submission up to the deadline, but it had to be resubmitted before the competition closed.
The official timeline recorded feedback on 15 July 2026, applicant notifications on 15 July 2026 at 12:33pm, contract awards on 31 August 2026, and project starts from 1 September 2026. These are historical milestones for the closed cycle, not current instructions or promises about a future round.
What a reviewer would have expected
The application questions show the evidence the competition sought. The technology section asked how the proposal met the selected challenge and what made it innovative. The technical summary asked for the main technical challenges, the innovation, technical deliverables, and the R&D that would establish scientific, environmental, and commercial merit. The state-of-the-art section required discussion of comparable products, differentiation, existing intellectual property, freedom to operate, and any new concepts or tools.
The project-plan section required resources, success criteria, management processes, a route to technical and commercial feasibility, and mitigation for technical, commercial, and environmental risks. Milestones had to be specific, measurable, achievable, realistic, and time-bound; they also had to connect to deliverables and payments, with the payment schedule by month matching the finance summary.
For a cyber security project, practical risks could include safe access to a live environment, disruption during testing, false positives, integration with legacy systems, confidentiality of operational data, and the ability of the end-user organisation to evaluate results. The official application structure did not provide a shortcut around these issues. It required the applicant to identify risks, show controls, and prove that the intended benefits could be achieved in the proposed setting.
Official links and archive note
The authoritative sources for this historical entry are the UKRI opportunity page and the Innovation Funding Service competition overview. The UKRI page identifies Innovate UK as the funder, records the closed status, and gives the headline dates and total fund. The IFS record provides the detailed eligibility, scope, funding, application questions, supporting-information requirements, and original timeline.
Because both official records show the 2026 competition as closed and neither announces a next cycle, readers should not treat this page as a live opportunity or rely on it for a new submission date. It remains useful for understanding the completed call, its contracting model, its technical maturity expectations, and the type of evidence Innovate UK requested from cyber security organisations working with critical-sector users.
