eSourcing Data - UK procurement software and commercial vehicles
HomeeSourcing OSBuyer guide

eSourcing OS · For contracting authorities

Buyer guide: running a procurement in eSourcing OS

This is the guide for the person who has to run the procurement, not the person signing the contract for the software. It follows one procurement in the order it happens, and at each step it says what the platform does, what it will refuse to let you do, and which Procurement Act 2023 obligation that refusal exists to protect.

Where something is built but not switched on, it says so. You will test these claims in a demo, and a claim that fails a demo costs every other claim on the page.

Setting up

Single stage or multi-stage, and the fields that decide what happens later.

Market engagement

A UK2 notice, invited suppliers, responses you can export, and a tender that inherits the OCID.

Publishing

Three compliance gates, then a held notice that a named person releases.

Clarifications

Published answers with the asker anonymised, and a window that closes when the procurement does.

Evaluation

Four annexes, an assigned panel, and a revision history rather than an overwrite.

Award and standstill

Four checks, section 50 summaries, and eight working days that exclude bank holidays.

The contract record

What confirming the contract creates, and what is locked today.

1. Setting up the procurement

A new tender is created as a draft with a reference drawn from your own organisation’s series, default evaluation weightings, an access mode, and a procurement regime: above threshold, below threshold, or unregulated. The regime is the single most consequential field on the form, because it decides whether Find a Tender notices are produced at all, whether assessment summaries are compulsory before award, and whether a standstill period is applied afterwards. Set it wrongly at the start and you will be corrected by a refusal later rather than by a warning now.

The person who creates the tender becomes its owner. Tender documents are uploaded against a document type rather than into a general folder, which is what lets the platform record precisely which supplier downloaded which document and when.

When you need to sift: the multi-stage procurement

A multi-stage procurement is not a different object with different rules. It is a cohesively managed chain of tenders, each stage a tender in its own right, referenced as your procurement reference followed by -S1, -S2 and so on. Stage one may be open. Every stage after it is forced to restricted access, because by then the field is the suppliers you shortlisted. Awarding from a non-final stage is refused outright: at a non-final stage the action available to you is shortlisting, which invites the successful suppliers into the next stage’s tender and emails everyone else that they are not progressing.

2. Preliminary market engagement

Engagement before you write the specification is the part most teams do in an inbox and then cannot evidence. In the platform you create an engagement, attach documents, invite suppliers by email, publish it, collect responses, answer engagement-specific clarifications, and close it. Responses export as CSV, which matters when you need to show how the market shaped the requirement.

Publishing an engagement builds and holds a UK2 preliminary market engagement notice. The engagement itself stays a draft and only becomes visible to suppliers on the portal when that notice is actually released. An open engagement gets public per-document download links written into the engagement-process field, because UK2 has no structured slot for documents. An invite-only engagement gets a pointer to the portal instead, never public links, so a closed engagement does not quietly become an open one through its own notice.

When the engagement is finished you convert it into a draft tender. It inherits the title, description, category and CPV codes, and, more usefully, the same OCID, so Find a Tender threads the engagement notice and the eventual tender notice together as one procurement rather than two unrelated events.

3. Publishing, and why the notice is the advertisement

Publish runs three compliance checks before anything is committed, and each refusal cites the rule and explains it in plain English:

  • Find a Tender R543. The description must be longer than the title. A description that repeats the title is the most common reason a notice bounces.
  • Find a Tender R906. Contract start and end dates must both be present, and the end must not precede the start.
  • PA23 section 20. An above-threshold stage-one tender must be open access. There is no restricted procedure under the Act, and an invitation-only list at the first stage is not permitted. The refusal tells you to run it as a multi-stage procurement instead, which is the compliant way to get to the same place.

Then the part that surprises people. A regulated tender does not go live when you press Publish.It stays a draft while its UK4 tender notice is built and held for review. The publication date is set at that moment, because that is the notice’s own publication date, but suppliers on the portal cannot see the opportunity until the notice is released to Find a Tender. That ordering is the point: a supplier already on your portal should never get a head start on the market. Below-threshold and unregulated tenders, which produce no Find a Tender tender notice, are advertised immediately.

Reviewing and releasing a notice

Notices sit on their own screen with a preview and a release action that requires an explicit confirmation. Release is refused if the payload was built for a different Find a Tender environment, if it has already been delivered to that environment, or under rule R074, which prevents a UK5, UK6 or UK7 going out before the linked UK4’s deadline. That last check runs from our own record, so it holds even on the sandbox. Everything is XSD-validated and rule-validated at the production weight regardless of which environment you are releasing to, so you meet the live bar during a rehearsal rather than on the day. If a submission times out it is recorded as an unknown outcome rather than as a clean failure, because the difference matters when you are deciding whether to resend.

4. Inviting suppliers, and how access is actually granted

You invite by email, either from the supplier directory or as free text. Each invitation mints its own token, so the emailed link resolves with no account at all: the landing page shows the buyer name, reference, title, deadline and a masked version of the invited email address, and nothing else. No documents, no values. The supplier signs in or registers, then accepts, and acceptance binds the invitation to their organisation so their colleagues get in too. An invitation already bound to a different supplier is never re-pointed.

Three routes count as invited: a matching supplier record, an exact email match, or the company email domain. Domain-granted access binds itself on first use and records how it was claimed, so you can see who came in that way and revoke it. Re-inviting an address resends on the same record rather than creating a second one, which preserves who invited whom and when, and clears any earlier revocation. An uninvited supplier who guesses the address of a restricted tender gets a 404, not a 403, so its existence is not confirmed.

5. Clarifications, and equal treatment you can evidence

A supplier opens a thread with a subject, a body and up to ten attachments. You see every thread on the tender, reply with attachments of your own, and where the answer affects everybody you set the thread to published. It is then broadcast to every supplier on that tender with the asker anonymised to “A supplier” and their attachments hidden. Suppliers see their own threads plus every published thread.

Two design decisions are worth knowing before your first live exercise. First, the channel stays open past the enquiry deadline and past the tender deadline, and closes only when the procurement is concluded, because a bidder who has just been told they were unsuccessful still needs to be able to read the answers their bid was written against. When posting is closed the interface shows a read-only notice with the reason rather than a composer that will be rejected. Second, every document download is written to your audit trail with the supplier, the document and the timestamp. That log is the evidence of what was made available, and when at the same time, which is not something you can demonstrate afterwards from an inbox.

6. Evaluation: the four annexes

Bids arrive through the portal, not by email, and cannot be created, edited or amended after the deadline: a supplier can withdraw or reopen a bid before the deadline and not after it. Scoring is restricted to assigned evaluators, administrators and the entity owner, and ownership is read from the ownership record rather than from whoever created the tender, so a departing colleague does not take the permission with them.

  • Annex A, supplier information. Pass or fail. A fail marks the bid disqualified with a recorded reason.
  • Annex B, commercial. The price.
  • Annex C, technical and social value. Scored per question, per evaluator, capped at that question’s maximum marks.
  • Annex D, compliance. Pass or fail, with the same disqualification effect as Annex A.

Weighted totals recompute after every write. Every score write reads the prior score first and records it as a previous score with a revision flag, which is the difference between a correction made during moderation and a score that changed after the bidders were known. Alongside the annexes you have conflict-of-interest declarations, Procurement Act exclusion-ground checks per submission, a responses CSV, per-submission document downloads and a documents ZIP, and an evaluation PDF. An optional AI analysis can suggest a score, and the suggestion is stored beside the human score with its reasoning rather than in place of it.

Moderation, and the permission that makes it real

The panel has a status, and an assigned evaluator can move it in exactly one direction: to moderation. They cannot reopen it, complete it, or move it back, and the attempt is refused. Moderation notes are held on the panel, and the owners are notified both when it is submitted for moderation and when it is completed. That single asymmetry is what makes the moderation record worth having.

7. Assessment summaries, award and standstill

Before any above-threshold award you generate assessment summaries under section 50. Each bidder gets their own letter, award, unsuccessful or disqualified, ranked on final score with disqualified bids excluded from the ranking, carrying that bidder’s own commercial, technical and final scores. Sending delivers an in-app notification to every user at that supplier plus an email with the letter attached.

Award itself is refused unless each of these holds:

  • It is the final stage, if this is a multi-stage procurement.
  • The winner’s evaluation is complete: Annex A passed, Annex D passed, Annex C scored, not disqualified. Every outstanding item is named at once rather than one refusal at a time.
  • For a direct award, a UK5 transparency notice exists and at least eight days have elapsed under section 44, with the days remaining reported back to you.
  • For an above-threshold procurement, assessment summaries have been sent.

On success the tender becomes awarded and, for above-threshold only, an eight working day standstill is set, calculated with weekends and UK bank holidays excluded. Below-threshold and unregulated procurements get no standstill, because none is owed.

Awarding does not publish anything. It drops a prefilled draft UK6 contract award notice into Notices, carrying the winner’s registered identity, their PPON or company number and its identifier scheme, so the published notice can name them under their own register as R309 requires. An owner reviews it, completes it and releases it through the same confirm step as every other notice.

8. The contract record

Confirming the contract is refused while the standstill end date is in the future, and the refusal tells you the date and how many days are left. It is also refused if a contract already exists, returning the existing one rather than creating a duplicate. On success it creates the contract with its own reference, a value taken from the winning bid price and falling back to the tender estimate, a start date of now and an end date two years out, the tender’s owners inherited, and three default KPIs: service delivery against a 99% monthly SLA, customer satisfaction at 85% quarterly, and social value delivery at 100% annually. Adjust the dates, value and KPIs to the contract you actually awarded.

Be clear about what is available today. The contract record itself is reachable and workable, and the backend genuinely supports KPIs, risks, social-value commitments, modifications, termination and manual payment recording for payment-compliance statistics. The contracts list page is locked for every account and shows an “available on request” panel, so contract management is enabled by arrangement rather than switched on by default. The winning supplier can see the contract and its KPIs read-only, with no route to update a KPI actual, upload evidence or submit an invoice.

9. What is not there, so you can plan around it

A guide that only lists capabilities is not much use when you are scoping an implementation. Six buyer areas are locked in the interface for every account today, administrators included: the contracts list, social value, frameworks, grants, dynamic markets, advanced reporting and the AI assistant. Their backends are real and working, and access is arranged rather than self-served, but no buyer reaches them through the product as it ships.

Beyond that: there is no e-signature integration, so award and contract creation are records rather than signatures. There is no purchase-to-pay, no purchase orders, no invoice matching and no payment execution; what exists is manual payment recording so days-to-pay can be computed. There is no single sign-on, SAML, OIDC or Entra ID federation: authentication is email and password with optional two-factor by authenticator app or emailed code. There are no e-auctions and no catalogue or punchout purchasing. And the platform publishes to Find a Tender rather than pulling from it, so suppliers browsing the portal see only opportunities hosted here.

Central Digital Platform, stated accurately

Notice submission to Find a Tender is live and real: notices are composed against the UK-native schema, validated, held for a named person, and released over the eSender API, with test and live environments kept strictly apart by a check that refuses any call whose destination contradicts its environment. Data sharing is a separate thing. Suppliers can save their share code, PPON and SSQ code on their profile today and you can see them, but redeeming a share code to pull verified details is switched off and needs Central Digital Platform credentials from onboarding. Nothing on the platform verifies a company number or a share code, so treat both as references on file, not as verified identity.

Where to start

Run one real procurement rather than migrating a programme. A below-threshold exercise is the cleanest first run, because it advertises immediately and carries no standstill, which lets you learn the clarification and evaluation mechanics without a notice deadline in the way. Then do an above-threshold open procurement, and validate before releasing: validation runs at the production weight either way, so a rehearsal tells you what the live release will do.

Questions

What buyers ask before the first procurement

Does publishing a tender make it visible to suppliers straight away?

Not for a regulated procurement. Pressing Publish on an above-threshold tender builds and holds its UK4 tender notice and sets the publication date, but the tender stays a draft. It becomes visible to suppliers on the portal only when that notice is actually released to Find a Tender, so no supplier can see an opportunity the wider market has not been told about. Below-threshold and unregulated tenders produce no Find a Tender tender notice, so they are advertised immediately.

Can I run an above-threshold procurement as invitation-only?

No, and the platform refuses to publish it. Under section 20 of the Procurement Act 2023 there is no restricted procedure and an invitation-only supplier list is not permitted at the first stage of an above-threshold procurement. If you need to sift before you evaluate, create a multi-stage procurement: stage one is open, and stage two onwards is automatically restricted to the suppliers you shortlist.

How does the platform stop me publishing a non-compliant notice?

Publish is refused before anything is committed, with the rule cited and plain-English guidance, when the description is not longer than the title (Find a Tender rule R543), when a contract start or end date is missing or the end precedes the start (R906), or when an above-threshold first stage is not set to open access (PA23 section 20). Notices are then XSD-validated and rule-validated at the production weight even when you are releasing to the test environment, so you see the live bar before it matters.

When does the clarification window close?

The channel stays open past the enquiry deadline and past the tender deadline, and shuts only when the procurement is concluded. Suppliers keep read access to answers throughout, so a bidder can always see the answers their bid was written against. When posting is closed the interface shows a read-only notice with the reason rather than a composer that will be rejected.

How do I answer a question to everyone at once?

Reply on the thread, then set the thread to published. It is broadcast to every supplier on that tender with the original asker anonymised to "A supplier" and their attachments hidden. Suppliers see their own threads plus every published thread, which is the equal-treatment record you would otherwise be assembling from an inbox.

Can an evaluator change a score after the fact?

Yes, and the change is recorded rather than overwritten. Every score write reads the prior score first and stores it as previousScore with an isRevision flag in the audit log. That is what separates a correction from a scoring challenge months later. Weighted totals recompute after every write.

What has to be true before I can award?

Four checks, and all of them run before anything changes. It must be the final stage if the procurement is multi-stage. The winner must be fully evaluated: Annex A passed, Annex D passed, Annex C scored and not disqualified, with every outstanding item named at once rather than one at a time. For a direct award, a UK5 transparency notice must exist and at least eight days must have elapsed under section 44. For an above-threshold procurement, assessment summaries must already have been sent under section 50.

How is the standstill period calculated?

Above-threshold awards get an eight working day standstill, with weekends and UK bank holidays excluded. Below-threshold and unregulated procurements get no standstill. Confirming the contract is refused while the standstill end date is in the future, and the refusal tells you the date and the days remaining.

Does awarding publish the contract award notice automatically?

No, deliberately. Awarding drops a prefilled draft UK6 into your Notices screen, carrying the winner’s registered identity so the published notice can name them under their own register as rule R309 requires. An owner reviews, completes and releases it through the same confirm step as every other notice. Nothing goes to Find a Tender without a named person choosing to send it.

Can I manage the contract in the platform after award?

Partly, and it is worth being precise. Confirming the contract after standstill creates the contract record with a reference, value, dates, your tender’s owners and three default KPIs, and that record is reachable at its own address. The contracts list page is currently locked for every account and shows an "available on request" panel instead, so full contract management is enabled by arrangement rather than switched on by default.

Does the platform pull supplier details from the Central Digital Platform?

Not yet. Suppliers can save their Central Digital Platform share code, PPON and SSQ code on their profile today, and buyers can see them. Redeeming a share code to pull verified details is built but switched off, and it needs Central Digital Platform credentials that only come from onboarding. Treat those fields as references on file rather than as verified identity.

Does it do e-signature, purchase orders or single sign-on?

No to all three. Award and contract creation are recorded in the platform, not signed in it. There are no requisitions, purchase orders, invoice matching or payment execution: what exists is manual payment recording against a contract so that days-to-pay can be computed for payment compliance statistics. Authentication is email and password with optional two-factor, either an authenticator app or an emailed code. There is no SAML, OIDC or Entra ID federation.

Bring the procurement you are worried about

The useful conversation is about the exercise you have to run next, its regime, its deadline and where you think it will go wrong. If the platform is the wrong fit for it, that is a useful answer too.

Start a conversationAbout eSourcing OS