Why this matters now

On the 19th of June 2026, the Cabinet Office published PPN 025: Protecting the UK's national security through public procurement.

The policy note applies to central government departments, executive agencies and non-departmental public bodies. It is not a general mandatory instruction to local authorities. However, it states that other organisations that are contracting authorities under the Procurement Act 2023 can consider their own pipelines in the context of the guidance, particularly where procurements are high value, complex or related to national interests.

That makes the PPN relevant to councils.

Local authorities may not procure warships or central defence systems, but they do procure and manage services that depend on critical supply chains, infrastructure, data, digital resilience, energy systems, construction materials, cyber security, emergency response, public safety and continuity of local services.

The practical question for councils is not whether every procurement has a national security dimension. Most do not. The question is whether authorities can identify the minority of procurements where resilience, supply dependency, data sensitivity, critical infrastructure or strategic exposure should be considered earlier and more explicitly.

What PPN 025 is focused on

PPN 025 and its accompanying guidance focus on four critical sectors.

Shipbuilding

Steel

Artificial intelligence

Energy infrastructure

The guidance describes national security as extending beyond defence, intelligence and counter-intelligence. It refers to broader considerations such as supply chain resilience, long-term national resilience, economic security and infrastructure vulnerability.

For central government, the immediate actions include identifying relevant procurements in the pipeline, engaging early with sector leads, and deploying the national security exemption under the Procurement Act 2023 where appropriate and justified.

For councils, the legal and operational position is more cautious. Authorities should not treat the PPN as a reason to label ordinary procurements as national security matters. They should also avoid using national security language as a general shortcut around competition.

However, the PPN does provide a useful governance prompt. It encourages public bodies to think more carefully about whether a procurement has strategic supply chain risk and whether a standard price-and-quality approach is sufficient.

Why councils should pay attention

Councils increasingly procure in markets that are affected by national and international resilience risks.

Construction and highways contracts may rely on steel, specialist materials, imported components or constrained supply chains.

Housing, schools and civic estate projects may be affected by infrastructure dependencies, energy performance requirements and availability of suitable contractors.

Digital transformation, social care platforms, customer relationship management systems, cyber security tools, data analytics and AI-enabled services may involve sensitive data and service continuity risks.

Energy infrastructure, heat networks, EV charging, solar, battery storage, decarbonisation projects and building management systems may connect local government procurement to wider energy resilience issues.

Emergency planning, public health response, transport, waste, housing repairs and community safety services may depend on suppliers that need to perform during periods of disruption.

These examples do not automatically create a national security procurement. They do show why procurement teams, commissioners, legal advisers, digital officers, property teams, emergency planning leads and contract managers need a shared understanding of when resilience risk moves beyond routine commercial consideration.

The procurement file should show early consideration

Where a council procurement has a credible security or resilience dimension, the file should show that the issue was considered at the planning stage.

This does not need to be complex for every requirement. A proportionate approach may involve a short decision record explaining why no further security review was needed. For higher-risk procurements, a more detailed review may be appropriate.

The record should identify the nature of the requirement, the services or assets affected, the data involved, the supply chain dependencies, the infrastructure implications, the market risks, the proposed controls and the decision on whether specialist input is required.

This matters because security and resilience concerns are harder to manage once the tender has been issued. If risk is identified late, the authority may have to amend documents, delay the process, introduce clarification, revisit evaluation design or accept that the contract does not contain the controls it needs.

Early consideration allows the council to build risk treatment into the procurement rather than attempting to bolt it on at award stage.

National security language should be used carefully

The Procurement Act 2023 includes an exempted contract provision where the authority considers that a contract should not be subject to all or part of the Act in the interests of national security. The PPN 025 guidance notes that the national security exemption is available to all contracting authorities.

That does not mean it should be used casually.

National security is a serious concept. It should not be used to avoid competition, bypass difficult market engagement, select a preferred supplier or accelerate an ordinary procurement. A council considering reliance on any exemption should obtain appropriate legal and governance advice and create a clear decision record.

For most local authority procurements, the more relevant response will be risk-informed procurement design rather than use of the exemption.

That might include stronger supplier due diligence, supply chain transparency, resilience questions, cyber security requirements, data handling obligations, business continuity provisions, step-in arrangements, performance monitoring, exit planning and carefully designed award criteria.

The aim is to protect public value and service continuity without overreaching.

Supply chain visibility is increasingly important

Many councils contract with a prime supplier but rely indirectly on a wider supply chain.

In construction, materials and subcontractors may determine delivery more than the prime contractor's bid narrative.

In digital services, hosting, support, software dependencies, AI tools, data processors and third-party integrations may create hidden risk.

In energy and infrastructure projects, equipment, installation, maintenance, grid connection, specialist technical support and spare parts may be critical.

In transport or facilities services, subcontracted elements may affect safety, continuity and responsiveness.

A standard supplier name on the contract register may therefore tell the authority very little about where risk actually sits.

Councils should consider when they need greater visibility of key subcontractors, critical dependencies, overseas supply chains, data-processing arrangements, maintenance obligations and alternative supply options. The level of visibility should be proportionate to the procurement. It should also be reflected in the contract, not requested informally after award.

AI and digital procurement require particular care

The inclusion of artificial intelligence within the PPN 025 critical sectors is significant.

Councils are increasingly approached by suppliers offering AI-enabled tools for customer services, analytics, case management, fraud detection, procurement support, care technology, planning, environmental monitoring and administrative automation. Some AI uses may be low risk. Others may involve personal data, automated recommendations, bias risk, explainability issues, service dependency, cyber risk or public trust concerns.

Authorities should consider how AI interacts with security, procurement transparency and operational resilience.

Does the system use council or resident data?

Where is the data processed or stored?

What third-party models, platforms or providers are involved?

Can the authority explain and challenge outputs?

What happens if the supplier withdraws support or changes the model?

Is the system critical to service delivery?

Are contractual controls sufficient for audit, transparency, data protection and continuity?

These questions should be asked before procurement documents are finalised. They may affect specification, evaluation, contractual terms, information governance review and contract management.

Value for money is broader than lowest cost

PPN 025 is also relevant because it reinforces a wider shift in thinking about value for money.

The lowest immediate cost may not represent the best public value where a procurement exposes an authority to service failure, supply shock, poor data control, cyber risk, price volatility or strategic dependency. Councils should therefore ensure that value for money assessments consider deliverability, resilience and risk, not only tendered price.

This does not mean paying more without evidence. It means evaluating the full risk-adjusted position.

A tender with a lower price but weak supply chain assurance may be more expensive if it fails.

A digital solution with attractive functionality may create long-term cost if exit is difficult.

An energy infrastructure contract may appear affordable but expose the authority to maintenance, availability or component supply risk.

A construction bid may rely on unrealistic assumptions about materials availability.

Procurement teams should work with finance, technical, legal and operational colleagues to ensure that resilience is properly reflected in the decision.

What councils should do now

Screen the procurement pipeline.

Councils should identify upcoming procurements involving energy infrastructure, AI, high-value digital services, construction materials, critical infrastructure, emergency response, public safety or strategic service continuity.

Introduce a proportionate security and resilience question at planning stage.

Procurement strategy templates should prompt officers to consider whether the requirement has data, cyber, supply chain, infrastructure or continuity risks requiring specialist review.

Engage the right internal leads early.

Digital, information governance, cyber security, emergency planning, property, finance, legal, sustainability and service leads may need to input before documents are issued.

Review supplier and supply chain due diligence.

Authorities should understand when they need information about key subcontractors, hosting, data processors, critical materials, maintenance dependencies and continuity arrangements.

Avoid casual use of exemptions.

Any reliance on a national security exemption should be carefully justified, legally reviewed and properly authorised. Most council procurements will require better risk controls rather than exemption.

Strengthen contract management.

Security and resilience commitments should be monitored after award. Contract managers need evidence, reporting routes, incident procedures, escalation triggers and exit plans.

Use capability support where needed.

Security, AI, infrastructure and resilience procurement often require cross-functional understanding. Structured learning through the PCC Learning Platform and practical resources through the Prestige Commercial Consulting support hub can support teams building confidence in these areas.

The supplier perspective

Suppliers should expect buyers to ask more detailed questions about supply chains, cyber security, data handling, continuity, subcontractors and resilience where the contract justifies it.

This should not be treated as unnecessary bureaucracy. A supplier that can explain its dependencies, risk controls, continuity arrangements and delivery model clearly will be better placed to build confidence with public sector buyers.

Suppliers using AI or digital infrastructure should be ready to explain how systems work, where data is processed, what third parties are involved, how outputs are assured and how the authority can exit or transition if required.

For smaller suppliers, the key is proportionality. Councils should not impose national-security-style documentation on low-risk contracts. However, where a supplier supports a critical service, a clear and credible assurance position is commercially valuable.

Closing takeaway

PPN 025 does not make national security the central issue in every council procurement. It does, however, provide an important reminder that procurement decisions can affect resilience, supply chains, data, infrastructure and long-term public value.

Councils should use the guidance as a prompt to review pipeline screening, supplier due diligence, digital and AI controls, infrastructure risk and contract management arrangements.

The strongest approach is proportionate, evidence-based and early. Councils should identify the procurements where security and resilience matter before the tender is issued, not after the contract is already exposed.

For support with procurement risk review, route-to-market planning, supplier assurance or governance documentation, contact Prestige Commercial Consulting Limited.