Pillar guide

UK Tender Compliance: The Complete Guide for SMEs

Compliance is where most SME tenders are won or lost — before a single word of the proposal is scored. This guide explains the universal gateways, the sector overlays, how to audit your own compliance footprint before a bid lands, and how to keep compliance from eating your bid-writing time.

13 min read

What 'compliance' means in a tender

Compliance is the set of mandatory, pass/fail requirements you must meet to be eligible — certifications, insurance, policies and correct submission. Fail one and the bid is excluded regardless of quality. See What is pass/fail in procurement?.

The core compliance gateways

The gateways that recur across UK public tenders:

  • Certifications — ISO 9001/14001/45001, Cyber Essentials, sector schemes (CHAS, SIA/ACS, BICSc).
  • Insurance — Employer's, Public and Professional Indemnity at the stated limits.
  • Policies — Health & Safety, Equality & Diversity, Modern Slavery, Environmental.
  • PPN 06/21 — a Carbon Reduction Plan for in-scope contracts; see What is PPN 06/21?.
  • Submission — correct formats, signatures, word limits and on-time upload.

Why SMEs fail — and how to avoid it

The failures are almost always avoidable. The most common are catalogued in Top Reasons SMEs Fail Procurement Compliance and Common Tender Disqualification Reasons.

Prevent them with a repeatable process: analyse the tender first, work the Tender Compliance Checklist, and finish with the Tender Submission Checklist.

Sector overlays — the gateways your sector adds

Universal gateways are necessary but not sufficient. Each sector layers its own pass/fail accreditations on top — and a bid that clears every general gateway can still be excluded for a sector accreditation it does not hold.

  • Construction — CHAS / SafeContractor / Constructionline, CDM 2015 duties, sector insurance limits.
  • IT services — Cyber Essentials Plus, ISO 27001, framework rules (G-Cloud, DOS).
  • Healthcare & NHS — CQC registration, DSPT, NHS Standard Contract terms, clinical governance.
  • Social care — CQC for adult services or Ofsted for children's services, TUPE annex review, Care Act duties.
  • Cleaning — TUPE schedule, Real Living Wage, BICSc, COSHH.
  • Security — SIA licensing, ACS Approved Contractor Scheme, BS 7858 screening.
  • Facilities management — ISO 41001, bundled hard/soft FM standards.
  • Catering — Government Buying Standards for Food, Food for Life Served Here, HACCP, Natasha's Law.
  • Professional services — CCS MCF4 / RM6309 rules, IR35, social-value model.
  • Recruitment — IR35, AWR, REC compliance, BS 7858 vetting.
  • Education — KCSiE, DBS, DfE Schools Buying Standards, DPIA.

Audit your compliance footprint before a tender lands

The cheapest way to win compliance is to be ready before the tender drops. Run a quarterly audit of your accreditation set — what is current, what is in renewal, what is missing — and keep an evidence library (certificate numbers, expiry dates, insurance schedules, named policy versions) in one place.

When a tender lands, you should already know whether you can clear its gateways within hours, not days. SMEs that audit quarterly typically reduce gateway-driven no-bids by 30–50% because they have closed the easy gaps in calmer windows.

  • Accreditations — current certificate numbers and expiry dates for every standard you hold.
  • Insurance — Employer's, Public, Professional Indemnity schedules with the named limits.
  • Policies — current version of every named policy with last-review date and named owner.
  • Evidence library — case studies, references, financial accounts, with the metadata evaluators ask for.
  • Sector accreditations — sector schemes you hold and the ones competitors hold that you do not.

Compliance vs scoring — keep the boundary clear

Compliance gateways are pass/fail. They are not where you win — they are what you must clear to be allowed to compete. Spending your best writing time on compliance evidence rather than on scored quality answers is one of the most common SME mistakes — see Why SMEs Lose Tenders for the full pattern.

The discipline is: handle compliance early, fast and structurally — checklist, evidence library, named policy versions. Then spend the bid-writing window on the questions that are actually scored. For the writing method itself, see How to Write a Tender Response.

Automate the compliance read

Manually finding every gateway in a 200-page pack is slow and error-prone. BidPilot extracts the mandatory certifications, insurance limits, deadlines and documents automatically, with a confidence score on each — so nothing is missed. The Tender Compliance Checker is the same engine focused on the compliance read; the Bid/No-Bid Tool adds the scoring weighting and risk overlay. See a worked example report.

For the broader comparison of tooling approaches, see AI Tender Analysis vs Manual Review.

Analyse your tender in minutes

Upload your ITT or PQQ and get a structured compliance and risk breakdown. New verified users get one free analysis.

GDPR compliant Documents deleted after analysis Built for UK SMEs
Analyze This Tender

FAQs

What is tender compliance?

Tender compliance is meeting all mandatory, pass/fail requirements — certifications, insurance, policies and correct submission — that make your bid eligible to be evaluated.

What happens if I miss a compliance requirement?

Your bid is typically excluded automatically, before the quality of your proposal is assessed. Compliance gateways are non-negotiable.

How can I check compliance quickly?

Run the tender through a structured analysis to extract every mandatory requirement, then verify each against a compliance checklist before you submit. The [Tender Compliance Checker](/tools/tender-compliance-checker) does this in under 5 minutes.

Does compliance differ by sector?

The general gateways (insurance, ISO 9001, GDPR, modern slavery, submission rules) are universal. Sector layers on top: construction adds CHAS/CDM, IT adds Cyber Essentials/ISO 27001, healthcare adds CQC/DSPT, social care adds Ofsted/CQC, security adds SIA/ACS, cleaning adds BICSc/TUPE. Check the relevant [industry page](/industries) for your sector's specifics.

How do I prove compliance in the response?

Each mandatory requirement usually needs evidence — a certificate number, an insurance schedule, a named policy with version and review date, or a signed declaration. Compile these in one place before you start writing, not while you write.