Skip to main content

Help us improve the Digital Marketplace - send your feedback

SOFTCAT PLC

Elastic Cloud Hosted

Elastic provides a unified Search AI Platform combining search, observability, and security. It delivers real-time analytics, log and metric monitoring, full-stack APM, SIEM/XDR threat detection, scalable search across any data, and AI-powered retrieval/automation, Deployable on-prem, cloud, or hybrid to improve performance, resilience, and security across the enterprise.

Features

  • Real-time search analytics Instantly query structured and unstructured data.
  • Scalable distributed indexing Horizontally expands to handle growing data volumes.
  • Machine learning detection Identifies anomalies and behavioral threats automatically.
  • Full-stack observability Correlates logs, metrics, traces across all environments.
  • SIEM/XDR automation Accelerates threat investigation with automated response workflows.
  • Vector search retrieval Enhances generative AI with semantic relevance scoring.
  • APM instrumentation Traces application performance for root-cause analysis
  • Role-based access control Enforces granular security and data governance.
  • Cross-cloud replication Ensures HA/DR across multi-region deployments.
  • Real-time dashboards Visualizes operational and security insights instantly.

Benefits

  • Accelerates threat investigations by unifying security data for rapid analysis.
  • Improves uptime by correlating logs, metrics, and traces faster troubleshooting.
  • Reduces storage costs through efficient tiering and searchable cold data.
  • Enhances decision-making with real-time dashboards showing operational performance.
  • Increases analyst productivity using automated detections and guided workflows.
  • Speeds application debugging with end-to-end distributed tracing visibility.
  • Strengthens compliance by enforcing governed access and comprehensive audit logs.
  • Empowers AI workloads with high-relevance vector search retrieval pipelines.
  • Supports hybrid work by enabling secure, remote access to data.
  • Scales seamlessly as teams grow without disrupting existing processes.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at psitq@softcat.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 3 1 4 7 9 0 6 7 4 2 7 1 4 9

Contact

SOFTCAT PLC Public Sector Tenders
Telephone: 01628 403403
Email: psitq@softcat.com

About your service

Service categories

Systems Infrastructure Software

Security

  • Cloud native application protection platform
  • Endpoint security
  • Security analytics
  • Governance, risk and compliance

Identity and access management

  • Access
  • Privilege

Network security

  • Trusted network access and protection
  • Active application security

Data security

  • Information protection
  • Digital trust
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
Elastic Cloud may have constraints such as scheduled maintenance windows, which can temporarily affect service availability. Buyers should be aware of these planned maintenance periods to minimize disruptions. Additionally, while Elastic Cloud supports a wide range of hardware configurations, optimal performance is achieved with recommended system requirements. Support is generally available for standard configurations, but highly customized setups may require additional consultation.
System requirements
  • Modern web browser required for accessing services.
  • Stable internet connection for optimal performance.
  • Compatible with Windows, macOS, and Linux.
  • API access requires authentication credentials.
  • Recommended use of updated antivirus software.

User support

Email or online ticketing support
Yes
Support response times
Our support team operates 24/7/365. Response times are determined by the severity level of the issue and the customer's subscription plan. We prioritize urgent issues to minimize disruptions and ensure timely support.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 A
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Our support portal is WCAG A compliant working towards AA compliance
Onsite support
Yes, at extra cost
Support levels
Onsite support services are offered through two distinct purchase options: Designated Support Engineers (DSE) and Professional Services (PS) for consulting.

DSEs are a single point of contact for technical inquiries, providing continuity and a deep understanding of specific needs and systems. They offer strategic guidance, optimize performance, and resolve issues. DSEs are skilled in addressing complex challenges and aligning insights with business objectives, assisting with architecture, performance tuning, and best practices.

Professional Services focus on consulting for implementation, optimizations, and strategic initiatives, helping achieve project goals and enhance system capabilities. Both DSE and PS are available as separate purchases.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
We provide extensive documentation for self-service implementation, and offer onsite or remote training opportunities, and professional services (consulting) for implementation
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
Users extract data through snapshot restoration to external repositories or via Elasticsearch APIs. Before contract expiration, users can restore snapshots to external destinations (S3, GCS, Azure Storage, or local repositories). The snapshot restore API enables selective index or cluster-wide restoration.

Alternatively, users can export data programmatically via APIs to JSON or CSV. Users can also utilise other Elastic software, such as Logstash or Beats, to export data via APIs. Elastic Cloud Hosted maintains automatic snapshots for 14 days as standard; users should complete data extraction before contract termination as Elastic deletes all deployment data per contractual requirements once the contract expires. No assistance from Elastic is required for extraction - customers maintain full control over data export operations through native product functionality.
End-of-contract process
The price includes continued access to the service until the expiration date and support for data extraction. Users can export their data at no additional cost within the contract period. The service agreement typically covers standard support and access to online resources. However, any additional services, such as extended support beyond the contract term, specialized data migration assistance, or consulting services, may incur extra charges.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Elastic Cloud's mobile access primarily offers a streamlined version of the desktop service, focusing on essential management and monitoring tasks. While the core functionalities remain accessible, the mobile interface may have simplified navigation and reduced visual complexity to accommodate smaller screens. Advanced configurations and detailed visualizations might be more suited for desktop use due to screen size and input method limitations. Overall, the mobile experience is designed for quick access and basic management,
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
The service interface is user-friendly and intuitive, designed to facilitate easy navigation and efficient task execution. It features a clean layout with customizable dashboards, for relevant metrics and data. The interface supports drag-and-drop functionality, real-time data visualization, and interactive elements for enhanced user engagement. Users can access various tools and resources directly from the interface, streamlining workflows and improving productivity.
Accessibility standards
WCAG 2.2 A
Accessibility testing
Our support portal is WCAG A compliant working towards AA compliance; testing is ongoing
API
Yes
What users can and can't do using the API
Elastic provides two distinct API layers. The Elastic Cloud API manages deployment lifecycle: provisioning clusters with specific topologies, zones, and memory allocations; scaling resources vertically and horizontally; configuring autoscaling policies; managing snapshots and restoring from repositories; implementing network security policies and traffic filtering; restarting or shutting down deployments; and deploying plugins, extensions, and custom endpoints. Users access deployment metrics, diagnostics bundles, and can orchestrate infrastructure changes programmatically.

The Elasticsearch and Kibana REST APIs manage data and operational concerns: indexing, searching, and aggregating data across indices; managing cluster settings and node configurations; creating and modifying index mappings, templates, and lifecycle policies; configuring security through role-based access control, API keys, and encryption settings; managing machine learning jobs, ingest pipelines, and transforms; and creating dashboards, visualisations, and alerts within Kibana.

Users cannot modify underlying infrastructure-as-a-service resources (AWS/GCP/Azure managed by Elastic), alter physical datacentre security controls, modify system-owned deployments in ECE environments, bypass rate limits, or access platform control plane configurations. All API access requires authentication via API keys, enforces rate limiting per organisation, and certain operations require specific subscription tiers. Destructive operations like wildcard index deletion are configurable but restricted by default for data protection.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Elastic Cloud deployments support extensive customisation of deployment architecture, security configuration, and operational parameters. Users can modify cluster topology by adjusting the number of availability zones, memory and storage allocations per zone, and enabling specific data tiers (hot, warm, cold, frozen) with independent resource scaling. Autoscaling thresholds, node roles, and instance configurations are fully configurable. Users can enable or disable machine learning nodes, Integrations Server, and APM components based on workload requirements.

Security customisation includes role/attribute-based access control implementation, SSO integration via SAML, OpenID Connect, EntraID or LDAP, multi-factor authentication enforcement, custom password policies through identity provider federation, API key management, traffic filtering rules, and Cloud Private Link configurations. Index settings, mappings, lifecycle policies, snapshot repositories, backup frequencies, and retention periods are user-defined. Kibana dashboards, visualisations, and alert rules are fully customisable, as are AI Assistant knowledge sources and data anonymisation settings.

Customisation occurs through the web console interface, Elastic Cloud REST API, Elasticsearch and Kibana APIs, Terraform provider, or command-line tools. Access is controlled through role-based permissions; organisation administrators and users with deployment management privileges perform configuration changes. Document and field-level security determines data visibility per user role.

Scaling

Independence of resources
We guarantee users aren't affected by others' demand through resource isolation and dynamic scaling. Each user is allocated dedicated resources, preventing interference from other users. Our infrastructure supports auto-scaling, adjusting resources in real-time based on demand to maintain optimal performance. Load balancing efficiently distributes traffic across servers, ensuring service stability. Continuous monitoring and proactive measures address potential bottlenecks, providing a seamless user experience regardless of demand fluctuations.

Analytics

Service usage metrics
Yes
Metrics types
We provide comprehensive infrastructure and application metrics, including CPU usage, memory utilization, disk I/O, network traffic, and application-specific performance indicators. These metrics help in monitoring system health, optimizing resource allocation, and ensuring efficient operation. Additionally, we offer real-time alerts and historical data analysis to assist in proactive management and troubleshooting.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Reseller (no extras)
Organisation whose services are being resold
Elastic

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export their data through the service's interface or API, allowing for seamless data retrieval and integration with other systems. The export process is straightforward, enabling users to select specific datasets or entire collections for export. Data can be exported in open formats such as CSV and ODF, ensuring compatibility with a wide range of applications and systems. Additionally, users can upload their data in formats like CSV and ODF, facilitating easy data import and integration into the service.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
JSON
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • https://www.elastic.co/docs/manage-data/ingest/upload-data-files
  • RTF
  • TXT
  • Word
  • Excel
  • PowerPoint
  • NDJSON
  • PDF

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Elastic Cloud Hosted deployments support private connectivity via AWS PrivateLink, Azure Private Link, and GCP Private Service Connect. These establish secure connections between customer VPCs/VNets and Elastic deployments within the same region, routing traffic entirely within the cloud provider's datacentre infrastructure without public internet exposure. Connections are customer-initiated; Elastic cannot initiate connections into customer networks.

Optional VPC ingress filters restrict traffic to specific endpoints. IP-based traffic filtering (CIDR blocks or individual addresses) available across all providers, combinable with private links. Multiple policies per deployment supported.

Available at all subscription tiers without additional cost.

https://www.elastic.co/docs/deploy-manage/security/private-connectivity
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The uptime Service Level Agreement will differ based on customer configuration. For Elastic Cloud, Platinum, and Enterprise customers, an uptime SLA is offered with a monthly uptime percentage of at least 99.95%. This SLA requires customers to run High Availability (HA) configurations with clusters having at least one replica. High availability is achieved within a region by hosting the deployment in multiple availability zones. This configuration is enabled by default and is recommended for production deployments to be in at least two availability zones. This setup ensures that the system can withstand failures within a single zone without impacting overall availability.

Cross-Cluster Replication: Customers can configure tenant-triggered failover or high availability across regions using Cross-Cluster Replication (CCR) to meet their specific SLA requirements. CCR enables data replication across clusters in different regions, providing geographical redundancy and enhancing system reliability. Elastic Cloud Status can be viewed at https://status.elastic.co/
Approach to resilience
Elastic utilizes an Infrastructure as a Service (IaaS) provider and does not maintain its own data centers. Elastic Cloud customers have the flexibility to choose the underlying IaaS provider and geographical region for their data on a per-deployment basis. Physical security, media, and hardware controls are the responsibility of the IaaS provider. More details on the controls they have in place can be found at:
- For AWS, see https://aws.amazon.com/compliance/programs/
- For GCP, see https://cloud.google.com/security/compliance/#/
- For Azure, see https://docs.microsoft.com/en-us/azure/compliance/

Elastic Cloud customers have complete control to select the cloud (IAAS) provider and geographic region on a per-deployment basis. Elastic does not share RTO/RPO externally, as this may differ based on customer configuration. High availability is achieved within the selected region by hosting the deployment in multiple availability zones. This is configurable by the customer and enabled by default. Elastic recommends that production deployments be in at least two availability zones.
Outage reporting
1. A public dashboard is available at https://status.elastic.co, where users can view real-time status updates and historical data on service performance and outages.

2. An API is available for users to integrate outage information into their own systems, allowing for automated monitoring and alerts.

3. Customers can subscribe to updates through various channels, including email, text messages, webhooks, and social media, ensuring they receive timely notifications about any service disruptions.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Elastic restricts access through Role-Based Access Control (RBAC) and the principle of least privilege. Privileged access to production systems and supporting tools is only allowed via a VPN protected with MFA. VPN accounts provide access based on a role-based system. Access requires documented requests and functional leader approval. All internal users have unique usernames and passwords. Access to the production environment is authenticated, authorized, and audited. For support, Elastic employees only access customer deployments with express written permission from the customer. Access is reviewed quarterly.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Elastic holds certifications including ISO 27001/27017/27018, SOC 2 Type II, FedRAMP Moderate, and PCI/DSS.

The Elastic Stack supports BSI C5 compliance. Elastic is committed to adhering to global privacy regulations like GDPR and CCPA.

View all up-to-date certifications at https://www.elastic.co/trust/security-and-compliance.
Information security policies and processes
Elastic follows comprehensive information security policies and processes to protect data and ensure compliance with industry standards. Our security framework is based on ISO/IEC 27001, which provides a systematic approach to managing sensitive company information. We have a dedicated security team responsible for implementing and maintaining security measures, conducting regular audits, and ensuring compliance with our policies. Our reporting structure includes regular updates to senior management and stakeholders on security performance and incidents. We enforce policies through employee training, access controls, and continuous monitoring of systems and networks. Any security incidents are promptly addressed and reviewed to prevent future occurrences.

Please visit https://elastic.co/trust
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Elastic's Change Management Standard governs all software and infrastructure changes to production environments. This ensures changes are reviewed, authorized, tested, implemented, and released in a controlled, documented, and monitored manner, including provisions for Emergency Changes.

The Standard includes formal requirements for our Systems Development Life Cycle (SDLC), covering the multistep process from initiation and analysis to disposal. We do not share these policies externally.

Furthermore, Elastic utilizes version-controlled configuration management to enable efficient, quick, and reliable updates and rollbacks of agent configurations.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Elastic assesses potential threats through monthly application vulnerability scans and annual application/network penetration tests. Vulnerabilities are also identified from code reviews and updates in third-party and open-source libraries. Critical and high vulnerabilities are remediated, with immediate security risks addressed urgently. All findings follow a standard vulnerability management process considering criticality, mitigations, and business requirements.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Elastic maintains a public vulnerability submission process at https://www.elastic.co/community/security.

Internally, a dedicated, security-knowledgeable team follows a documented process to evaluate and respond to reports via a private mailing list. Public vulnerability announcements are posted at https://discuss.elastic.co/c/security-announcements

Continuous application, network, and OS scans are conducted. A remediation plan is developed, and changes are implemented to remediate all critical and high findings at a minimum.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Elastic maintains a documented Incident Response and Recovery Plan that complies with, and is regularly audited against, industry standards.

The Security Incident Management Standard outlines customer notification requirements for security incidents, in accordance with regulatory and contractual obligations. The Incident Response Plan includes steps for evaluating the need for customer notification.

Tenants are not permitted to define or customize our internal policies and standards.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We offer a free trial that includes basic features and access to online resources for a limited time period. Advanced features, dedicated support, and extended usage are not included in the free trial.
Link to free trial
https://cloud.elastic.co/registration

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
NQA
ISO/IEC 27001 accreditation date
Monday 8 April 2024
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
NQA
ISO 9001 accreditation date
Monday 8 April 2024
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
SecurityMetrics
PCI DSS accreditation date
Friday 10 January 2025
What the PCI DSS doesn’t cover
N/A
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
E9fd5f85-7cd1-4ff2-aba9-6f9f5f225b1b
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
181966c9-f0aa-42ed-9271-d1b111bdf43b
Other security certifications
Yes
Any other security certifications
Security Standards dependant on the vendor solution

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at psitq@softcat.com. Tell them what format you need. It will help if you say what assistive technology you use.