Skip to main content

Help us improve the Digital Marketplace - send your feedback

ROCK I.T. SPECIALISTS LIMITED

Cove Data Protection – Cloud Backup and Disaster Recovery (SaaS)

Cove Data Protection – Cloud Backup and Disaster Recovery (SaaS) provides cloud-native backup, recovery and disaster recovery for servers, virtual machines and endpoints. The service delivers secure, automated data protection, rapid recovery, ransomware resilience and centralised management through the Cove cloud platform.

Features

  • Cloud native backup for servers virtual machines endpoints and workloads
  • Centralised management through the Cove cloud platform web dashboard
  • Automated policy based backups with configurable schedules and retention
  • Image based backup supporting rapid bare metal system recovery
  • Application aware backup supporting cloud services and business platforms
  • Ransomware detection and recovery using secure immutable backup storage
  • Secure cloud storage with encryption during transfer and storage
  • Multi cloud workload protection across on premises and public clouds
  • Granular file mailbox and item restore capabilities
  • Scalable SaaS architecture without on premises backup infrastructure

Benefits

  • Reduces data loss risk through automated resilient cloud backups
  • Enables rapid recovery of systems and data after incidents
  • Simplifies backup management using a single centralised SaaS platform
  • Protects critical business data beyond native retention and recovery capabilities
  • Improves cyber resilience against ransomware and accidental data deletion
  • Supports business continuity with fast reliable disaster recovery
  • Reduces infrastructure overhead by removing on premises backup hardware
  • Provides predictable costs through scalable subscription based SaaS licensing
  • Improves operational efficiency using automated policies and reduced manual effort
  • Supports multi cloud strategies with consistent data protection controls

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@rock.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 9 2 2 6 2 0 0 6 4 9 9 6 7 9

Contact

ROCK I.T. SPECIALISTS LIMITED Ian Elsbury
Telephone: 0344 310 0585
Email: bidteam@rock.co.uk

About the service

Service categories

Application Development and Deployment

Data management

Data integration and intelligence

  • Data Archiving and Information LifD-Cycle Management
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Cove Data Protection can operate as a standalone backup and recovery service or provide protection for supported cloud-hosted servers, virtual machines and applications. It integrates with supported platforms to deliver backup and recovery without dependency on proprietary software stacks.
Cloud deployment model
Public cloud
Service constraints
Cove Data Protection is delivered as a cloud based SaaS service and requires internet connectivity to protected workloads. Backup and recovery capabilities are dependent on supported operating systems, platforms and applications. Planned maintenance is performed within the Cove cloud platform and may temporarily affect management access, but does not typically interrupt backup operations. End user performance is dependent on network connectivity and bandwidth availability.
System requirements
  • Supported operating systems for servers, endpoints and virtual machines
  • Internet connectivity between protected systems and the Cove cloud platform
  • Local administrative permissions to install and manage Cove backup agents
  • Supported web browser for secure access to Cove management interface
  • Outbound firewall access allowing secure communication with Cove service endpoints
  • Sufficient local storage for backup caching and temporary data processing
  • Time synchronisation enabled on protected systems for accurate backup operations
  • Supported hypervisor or cloud platform for virtual machine backup workloads
  • Ability to schedule backups and retention policies based on requirements
  • Access to email services for delivery of backup alerts notifications

User support

Email or online ticketing support
Yes
Support response times
Support is provided via email or online ticketing during standard UK business hours (Monday to Friday). Initial responses to service-related incidents and requests are provided in line with defined service level agreements, with a standard response time of up to four hours during business hours. Response times vary by priority and complexity. Enhanced or out-of-hours support options can be agreed where required as part of a managed service arrangement.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Accessibility considerations are incorporated into the selection and use of web chat and ticketing tools used to support service delivery. Where third-party platforms are used, tools are selected based on published accessibility conformance statements aligned to recognised standards such as WCAG 2.1 AA or later. Alternative communication channels, including email or phone support, are available where required.
Onsite support
Yes, at extra cost
Support levels
Support for this service is provided through defined engagement-based support levels aligned to the scope of cloud services being delivered. Support may include advisory assistance, delivery support and managed cloud service activities, and does not typically include end-user service desk support.

Support levels may include:

- Standard support, providing access to cloud specialists during UK business hours for queries, guidance and agreed service activities.
- Enhanced support, where agreed, offering increased availability, prioritised response for service-related requests and broader involvement in service optimisation activities.
- Project-based support, aligned to specific cloud migration, optimisation or improvement initiatives.

The applicable support level, scope and cost are agreed with the buyer at Call-Off stage, based on the duration, complexity and level of resource engagement required. Where appropriate, a named Technical Account Manager or Cloud Support Engineer may be assigned to provide a consistent point of contact, coordinate delivery activities and support governance and reporting.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
ROCK supports buyers in starting to use Cove Data Protection through a structured onboarding and implementation process. This includes initial service setup, tenant configuration, deployment of backup agents, and configuration of backup, retention and recovery policies aligned to buyer requirements.

Buyers are provided with access to online user documentation, technical guides and knowledge base resources to support day to day use of the service. Remote training sessions can be delivered for administrators and operational users, covering platform navigation, monitoring, reporting and recovery processes.

Ongoing support is available through ROCK’s service desk, with guidance provided during early service adoption and assistance with optimisation, configuration changes and best practice use of the Cove platform.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
  • Other
Other documentation formats
  • Word
  • Excel
End-of-contract data extraction
At the end of the contract, buyers can extract their data from Cove Data Protection using standard recovery and export capabilities available within the platform. Authorised users can perform full or granular restores of backed up data, including files, folders and system images, to buyer owned locations or alternative environments.

Data can be restored to on premises systems, cloud hosted infrastructure or other supported storage locations, enabling transition to a replacement service if required. During the contract termination period, ROCK provides support to assist buyers with planning, executing and validating data extraction activities.

Once data extraction is complete and the contract has ended, remaining customer data is retained or securely deleted in accordance with agreed retention periods, contractual obligations and applicable regulatory requirements.
End-of-contract process
At the end of the contract, ROCK supports a structured and controlled service exit in line with G-Cloud requirements. This includes confirmation of contract termination, agreement of exit timelines, and continued access to the service during the agreed wind-down period. Buyers retain access to the platform to complete data extraction activities. ROCK provides reasonable support to assist with exit planning, validation of data recovery and transition to an alternative service. Once the contract has ended and data extraction is complete, customer data is securely retained or deleted in accordance with agreed retention periods, contractual obligations and regulatory requirements. Standard exit activities are included in the contract price; any additional bespoke transition support is agreed separately.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Other
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • ChromeOS
  • Other
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The Cove Data Protection service can be accessed via mobile web browsers for monitoring and basic management tasks. Mobile access supports viewing backup status, alerts and reports. Full configuration, policy management and advanced recovery operations are designed for desktop browsers, providing enhanced functionality, usability and administrative control compared to mobile access.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Cove Data Protection is accessed through a secure, web based management interface provided via the Cove cloud platform. The interface enables authorised users to configure backup policies, monitor backup status, manage protected workloads, view alerts and reports, and initiate recovery operations. Access is controlled through role based permissions and authentication, providing secure administrative and operational management via standard web browsers.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The service interface is delivered through a modern web based application designed to be compatible with standard browser accessibility features. While formal certification against specific accessibility standards has not been undertaken, the interface supports use with common assistive technologies such as screen readers, keyboard navigation and browser zoom functions. Accessibility considerations are reviewed as part of ongoing platform development, and feedback from users is incorporated to improve usability where appropriate.
API
Yes
What users can and can't do using the API
Cove Data Protection provides an API that enables authorised users to integrate the service with external systems and automate operational tasks. The API can be used to retrieve backup status, job results, alerts, protected device information and reporting data, and to support integration with monitoring, service management and reporting platforms.

Service setup activities such as tenant creation, core configuration and policy definition are typically performed through the web based management interface rather than exclusively through the API. The API supports making operational changes including managing devices, retrieving configuration information and automating reporting workflows.

Limitations apply to prevent unauthorised or unsafe configuration changes, and some advanced administrative and recovery actions remain restricted to the management interface to maintain service integrity and security.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • ODF
  • PDF
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Buyers can customise Cove Data Protection through configuration settings available within the secure Cove cloud management platform. Customisation includes defining backup schedules, frequency and retention policies; selecting workloads to protect such as servers, virtual machines and endpoints; configuring storage locations and recovery options; and setting alerting, reporting and notification preferences.

Users customise the service by accessing the web based management interface and applying policy based settings without modifying the underlying SaaS platform. Configuration changes are applied in line with defined schedules and permissions.

Customisation is restricted to authorised buyer administrators and designated users with appropriate role based access. This ensures buyers retain control over service configuration while maintaining security, service integrity and compliance with platform standards.

Scaling

Independence of resources
Cove Data Protection is delivered as a multi tenant SaaS platform designed to isolate customer workloads logically. Resources are managed through scalable cloud infrastructure with workload segregation, policy based controls and capacity management to prevent individual tenant activity impacting others. Backup processing, storage and management operations are monitored continuously, with automated scaling and performance management used to maintain consistent service levels as demand changes across the platform.

Analytics

Service usage metrics
Yes
Metrics types
Cove Data Protection provides service usage and operational metrics through its management platform. Metrics include backup success and failure rates, protected device and workload counts, storage consumption, backup frequency, recovery activity, alert history and service availability status. Reporting also covers backup coverage, retention status and data growth trends across protected workloads. These metrics support operational monitoring, capacity planning, audit requirements and service optimisation.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
Resource tagging
Yes
FOCUS resource tagging
Yes

Supplier type

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Cove Data Protection (N-able)

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with SSAE-18 / ISAE 3402
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users export data from Cove Data Protection using standard restore and export functionality within the platform. Authorised users can perform full system restores or granular exports of files, folders and system data to buyer owned infrastructure, cloud environments or supported storage locations. Data is exported in usable formats to support transition to alternative backup or storage solutions where required.
Data export formats
  • CSV
  • Other
Other data export formats
  • DOCX
  • XLSX
  • PDF
  • PST
  • VHD/VHDX
Data import formats
Other
Other data import formats
  • Native file system formats uploaded via backup agents
  • Virtual machine disk images from supported virtualisation platforms
  • Server and endpoint data captured from supported operating systems

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Cove Data Protection is delivered as a cloud based SaaS platform designed for high availability and resilience. The service is hosted on scalable public cloud infrastructure with redundancy across core components to minimise service disruption. Availability applies to access to the management platform and supporting service components.

Service availability targets and operational performance are monitored continuously. Planned maintenance activities are scheduled in advance where possible and designed to minimise impact on service availability. Backup operations are engineered to continue during most maintenance activities.

Service level agreements for availability are defined contractually with buyers and form part of the agreed service terms. Where availability levels fall below agreed thresholds, service credits or fee adjustments may be applied in line with the contract. Refunds or credits are calculated based on the extent and duration of the availability shortfall and are agreed with the buyer as part of the contractual SLA framework.
Approach to resilience
Cove Data Protection is designed as a resilient, cloud native SaaS platform hosted on enterprise grade public cloud infrastructure. The service uses redundancy across core platform components, including management services, backup processing and storage, to reduce single points of failure.

Data is stored in resilient cloud storage services with built in replication and durability controls to protect against infrastructure failure. Backup jobs are designed to resume automatically following transient service interruptions, and recovery services are engineered to remain available during maintenance activities where possible.

The platform is monitored continuously, with automated alerting and operational response processes in place to identify and address service degradation. Capacity management and elastic scaling are used to maintain performance as demand changes.

The underlying datacentre architecture, including geographic resilience and physical security controls, is provided by the cloud hosting provider. Detailed datacentre resilience and certification information is available to buyers on request, where required for assurance or compliance purposes.
Outage reporting
Cove Data Protection reports service outages and service degradation through multiple communication channels. Service status and operational health information is available via the Cove cloud management interface, allowing users to view current and historical service status.

Automated alerts and notifications are generated for significant service events and can be delivered by email to authorised users and administrators. Where applicable, status information and operational data can also be accessed through the service API to support integration with external monitoring or service management tools.

Planned maintenance activities and major incidents are communicated in advance or as soon as reasonably practicable, with updates provided until service restoration is complete. ROCK’s service desk also provides direct communication and support during service incidents, including incident updates and post incident reporting where required.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using role-based access control and strong authentication. Permissions are assigned to defined roles and scoped resources to enforce least privilege access. Management access requires authenticated user accounts and supports multi factor authentication.

Administrative actions are logged and auditable through platform activity logging and monitoring services. Support access is restricted to authorised users through cloud support portals and ticketing systems. Customers manage identities, roles and permissions within their cloud tenancy, subject to the agreed service scope.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
ROCK follows a structured information security management framework supported by documented policies and operational processes designed to protect information assets and customer data. Core policies cover information security, access control, data protection, incident management, risk management and supplier assurance.

Information security responsibilities are clearly defined, with executive oversight provided by senior management and day to day security operations managed by designated security and technical leads. Policies are approved at board or senior management level and reviewed regularly to ensure continued relevance and compliance with legal, regulatory and contractual requirements.

Compliance with information security policies is enforced through role based access controls, secure configuration standards, logging and monitoring, staff training and incident reporting procedures. Security incidents are reported, investigated and managed in line with documented incident response processes, with escalation to senior management and customers where required.

Supplier and platform security assurances are reviewed as part of onboarding and ongoing service management to ensure continued alignment with security standards and buyer requirements.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
ROCK follows documented configuration and change management processes aligned to operational security best practice. Service components are identified, versioned and tracked throughout their lifecycle using configuration records and asset registers.

Proposed changes are logged, assessed and approved through a defined change process that considers operational, security and customer impact. Security implications are reviewed as part of change assessment, with testing and rollback plans defined where appropriate. Changes are implemented in a controlled manner, with logging, monitoring and post change review to confirm successful and secure deployment.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
ROCK operates a structured vulnerability management process to identify, assess and remediate security risks. Potential threats are assessed using risk based analysis informed by asset criticality, exposure and exploitability. Vulnerability information is sourced from vendor security advisories, cloud provider notifications, threat intelligence feeds and industry best practice guidance.

Patches and mitigations are prioritised based on risk and severity and deployed within defined timescales. Critical security updates are applied as soon as practicable, with testing and change controls applied to maintain service stability.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
ROCK uses protective monitoring processes to detect and respond to potential security incidents. Service activity, access events and system logs are monitored for indicators of compromise using automated alerts and operational review.

When a potential compromise is identified, incidents are assessed, contained and investigated in line with documented incident response procedures. Escalation paths ensure timely involvement of technical and security personnel. Response times are prioritised based on incident severity, with critical incidents investigated immediately and customers notified in accordance with contractual and regulatory requirements.
Incident management type
Supplier-defined controls
Incident management approach
ROCK follows documented incident management processes with predefined procedures for common service and security events. Users can report incidents through ROCK’s service desk using email or ticketing channels.

Incidents are logged, prioritised and managed in line with agreed response procedures, with escalation based on severity and impact. Incident updates are provided during resolution, and post incident reports are issued where appropriate, detailing root cause, actions taken and any preventive measures implemented.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
20%
Between £2,500,001 and £5,000,000
23%
Over £5,000,001
25%

Standards and certifications

ISO/IEC 27001 certification
Yes
ISO/IEC 27001 accredited by
NDC Certification Bureau Ltd
ISO/IEC 27001 accreditation date
Wednesday 22 January 2025
What the ISO/IEC 27001 doesn’t cover
None - ROCK’s ISO/IEC 27001:2022 certification applies to the whole organisation and covers all activities, systems, staff, and processes involved in the delivery of Cloud Support services.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
ISO 9001 certification accredited by
SGS
ISO 9001 accreditation date
Friday 20 October 2017
What the ISO 9001 doesn’t cover
None - ROCK’s ISO 9001:2015 Quality Management System applies to the whole organisation and covers all service delivery, operational, and management processes relevant to Cloud Support services.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
627384ad-afe1-4eca-bbaa-1e197073ca0d
Cyber essentials plus
Yes
Cyber Essentials Plus Certificate Number
0781e990-0c6f-4799-9b1b-9e723da53bbf
Other security certifications
No

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
  • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
  • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
  • Plans to engage the contract workforce in deciding the most important workplace issues to address
  • Ensuring new workers are informed of their right to join a trade union
  • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
  • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
  • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
  • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
  • Activities to cascade good practice on fair working conditions throughout the supply chain
  • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
  • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
  • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
  • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
  • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
  • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
  • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Volunteering opportunities for staff
  • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
  • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
  • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
  • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
  • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract

Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

  • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract

Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

  • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
  • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
  • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
  • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
  • Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
  • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
  • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
  • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
  • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
  • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Plans for positive actions with community groups.
  • Measures for making facilities used in the delivery of the contract available for community groups, education or training
  • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
  • Plans to respond flexibly and adapt approaches to community engagement and initiatives
  • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
Mission: Make Britain a clean energy superpower

To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

  • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
Mission: Break down barriers to opportunity

By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

Policy Outcome 6: Employment and training: For those who face barriers to employment

  • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
  • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
  • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
  • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
  • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
  • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
  • Introducing transparency to pay and reward processes
  • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
  • Working conditions which promote an inclusive working environment and promote retention and progression
  • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
  • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition

Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

  • Understanding of the issues affecting the development of new skills by target cohort
  • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
  • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
  • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Understanding of issues relating to entering the contract workforce
  • Creation of outreach activities to create a pipeline of employees for the future contract delivery
  • Content of the outreach activity is designed to suit the target cohort
  • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
Mission: Build an NHS fit for the future

That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

  • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
  • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
  • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
  • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@rock.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.