Skip to main content

Help us improve the Digital Marketplace - send your feedback

ROCK I.T. SPECIALISTS LIMITED

Microsoft 365 – Core Productivity and Collaboration Software

Microsoft 365 – Core Productivity and Collaboration Software provides cloud-based productivity and collaboration capabilities including email, document management, messaging and identity services. The service is supplied as Microsoft cloud software and is used by buyers as a foundation for productivity, collaboration and security services delivered under Lot 3.

Features

  • Cloud based email calendaring and contacts through Microsoft Exchange Online
  • Access to secure document storage and collaboration through SharePoint Online
  • Personal file storage and synchronisation using OneDrive for Business
  • Real time messaging meetings and collaboration using Microsoft Teams
  • Web based and desktop productivity applications for document creation
  • Identity and access capabilities provided through Microsoft Entra ID
  • Built-in Microsoft security controls for data protection and access management
  • Centralised administration and user management through Microsoft admin portals
  • Integration across Microsoft productivity services through a unified platform
  • Scalable cloud architecture supporting organisational growth and user demand

Benefits

  • Improves collaboration and communication across distributed teams
  • Enables secure access to information from any location
  • Reduces infrastructure complexity through cloud delivered productivity software
  • Supports flexible working with integrated communication and collaboration tools
  • Improves information sharing and document version control
  • Enhances security through centralised identity and access management
  • Increases productivity using familiar and widely adopted applications
  • Supports organisational scalability without additional on premises infrastructure
  • Improves governance through centralised administration and policy management
  • Provides predictable licensing and subscription based software delivery

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@rock.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 0 2 2 4 3 7 1 4 5 6 7 9 2 4

Contact

ROCK I.T. SPECIALISTS LIMITED Ian Elsbury
Telephone: 0344 310 0585
Email: bidteam@rock.co.uk

About the service

Service categories

Applications

Collaborative

  • Email
  • Team collaboration
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Microsoft 365 provides integrated productivity, collaboration and identity software delivered as a unified Microsoft cloud platform. The software is commonly used alongside managed support, security and optimisation services delivered under Lot 3, but operates independently as a standalone SaaS product.
Cloud deployment model
Public cloud
Service constraints
Microsoft 365 is delivered as a cloud based software platform and requires supported user devices and reliable internet connectivity. Service availability and features depend on the selected Microsoft 365 subscription and supported operating systems. Planned maintenance by Microsoft may temporarily affect access to specific services or administrative functionality.
System requirements
  • Supported operating systems on user devices for Microsoft 365 applications
  • Reliable internet connectivity for accessing Microsoft 365 cloud services
  • Supported web browser for accessing Microsoft 365 web applications
  • Microsoft 365 user licences assigned to users accessing the service
  • Supported desktop or mobile devices for installed productivity applications
  • Microsoft Entra ID tenant for identity and access management (8)
  • User accounts configured with appropriate permissions and security policies
  • Email capable devices for notifications and collaboration features
  • Adequate device performance to run Microsoft 365 applications effectively
  • Time synchronisation enabled on devices for authentication accuracy

User support

Email or online ticketing support
Yes
Support response times
Support is provided via email or online ticketing during standard UK business hours (Monday to Friday). Initial responses to service-related incidents and requests are provided in line with defined service level agreements, with a standard response time of up to four hours during business hours. Response times vary by priority and complexity. Enhanced or out-of-hours support options can be agreed where required as part of a managed service arrangement.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Accessibility considerations are incorporated into the selection and use of web chat and ticketing tools used to support service delivery. Where third-party platforms are used, tools are selected based on published accessibility conformance statements aligned to recognised standards such as WCAG 2.1 AA or later. Alternative communication channels, including email or phone support, are available where required.
Onsite support
Yes, at extra cost
Support levels
Support for this service is provided through defined engagement-based support levels aligned to the scope of cloud services being delivered. Support may include licensing advisory assistance, onboarding guidance and coordination with Microsoft support, and does not include operational management of Microsoft 365 workloads unless separately contracted under Lot 3.

Support levels may include:

- Standard support, providing access to cloud specialists during UK business hours for queries, guidance and agreed service activities.
- Enhanced support, where agreed, offering increased availability, prioritised response for service-related requests and broader involvement in service optimisation activities.
- Project-based support, aligned to specific cloud migration, optimisation or improvement initiatives.

The applicable support level, scope and cost are agreed with the buyer at Call-Off stage, based on the duration, complexity and level of resource engagement required. Where appropriate, a named Technical Account Manager or Cloud Support Engineer may be assigned to provide a consistent point of contact, coordinate delivery activities and support governance and reporting.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
ROCK supports buyers in starting to use Microsoft 365 through a structured onboarding and implementation process. This includes initial tenant setup, licence configuration, user account creation, identity configuration, and baseline service configuration aligned to organisational requirements.

Buyers are provided with access to Microsoft online documentation, technical guidance and knowledge base resources to support day to day use of the platform. Where required, remote onboarding sessions can be delivered for administrators and key users, covering administration portals, user management, collaboration features and core service functionality.

Ongoing support is available through ROCK’s service desk, providing guidance during early service adoption and assistance with configuration queries, licence management and best practice use of Microsoft 365 within the agreed service scope.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
  • Other
Other documentation formats
  • Word
  • Excel
End-of-contract data extraction
At the end of the contract, buyers can extract their data from Microsoft 365 using standard export, migration and download capabilities provided by the platform. Authorised users and administrators can export emails, files, documents and other content through Microsoft administration tools, service interfaces and supported APIs to buyer owned systems or alternative platforms.

Exported data can be used to support audit, compliance, business continuity or transition to a replacement productivity or collaboration service where required. During the contract termination period, ROCK provides support to assist buyers with planning, executing and validating data extraction activities in line with agreed requirements.

Once data extraction is complete and the contract has ended, buyer access to the service is removed. Any remaining customer data is retained or securely deleted in accordance with Microsoft data retention controls, agreed contractual obligations and applicable legal and regulatory requirements.
End-of-contract process
At the end of the contract, buyers are supported through a structured service exit process to ensure continuity of access to data and services. During the notice period, access to Microsoft 365 remains available, allowing authorised users and administrators to export data using standard Microsoft tools and supported APIs in line with agreed requirements.

The contract price includes access to Microsoft 365 software licences, standard platform functionality, documentation, and remote support during the contract term, including guidance on licence management and data export planning at contract end.

Additional costs may apply where buyers request extended contract periods, enhanced exit assistance, bespoke reporting, large-scale or accelerated data exports, or continued data retention beyond the agreed contract end date. Any additional services or costs are agreed in advance with the buyer.

Following contract completion and confirmation of exit activities, buyer access to the service is removed and remaining data is retained or deleted in accordance with Microsoft data retention controls, contractual obligations, and applicable legal and regulatory requirements.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Other
Application to install
Yes
Compatible operating systems
  • MacOS
  • Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Microsoft 365 is designed to work across desktop and mobile devices using web browsers and native applications. Mobile access supports email, messaging, document access and collaboration. Desktop applications and browsers provide full functionality for content creation, advanced features, administration and configuration tasks.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Microsoft 365 is accessed through secure, web based management and user interfaces provided via Microsoft cloud services. Authorised users and administrators use Microsoft administration portals and end user applications to manage accounts, licences, settings and collaboration features. The interfaces support configuration, monitoring and administration of productivity and collaboration services. Access is controlled through role based permissions and authentication, enabling secure management and use of Microsoft 365 through standard web browsers and supported applications.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The service interface is delivered through a modern web based application designed to be compatible with standard browser accessibility features. The interface supports use with common assistive technologies such as screen readers, keyboard navigation and browser zoom functions. Accessibility considerations are reviewed as part of ongoing platform development, and feedback from users is incorporated to improve usability where appropriate.
API
Yes
What users can and can't do using the API
Microsoft 365 provides a comprehensive set of APIs that allow authorised users and administrators to interact with and manage productivity, collaboration and identity services programmatically. APIs enable organisations to automate user and licence management, access service data, manage groups and permissions, retrieve reporting information, and integrate Microsoft 365 capabilities with third-party applications and internal systems.

Microsoft Graph APIs provide unified access to data and services across Microsoft 365, including email, calendars, files, collaboration resources and identity information. These APIs support common automation and integration scenarios such as user provisioning, reporting, workflow integration, and application interoperability. Additional service-specific APIs are available for selected Microsoft 365 workloads where required.

Users can use APIs to retrieve information, perform administrative actions, and automate routine management tasks in line with assigned permissions and security policies. Access to APIs is controlled through Microsoft Entra ID authentication and authorisation, ensuring secure, role-based access to resources.

Core service configuration, tenant-level settings and advanced administrative controls are primarily managed through Microsoft management portals to maintain security, governance and platform integrity. API usage is subject to Microsoft service limits, permissions and throttling controls.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • ODF
  • PDF
  • Other
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Buyers can customise Microsoft 365 through configuration settings available within the Microsoft 365 and Microsoft Entra ID administration portals. Customisation enables organisations to tailor the platform to their operational, security and governance requirements while using standard Microsoft cloud software capabilities.

Customisation options include configuring user accounts, groups and roles; assigning and managing licences; defining identity, authentication and access policies; configuring email, collaboration and document management settings; and applying data governance, retention and sharing controls. Buyers can also configure collaboration features, messaging settings, file storage behaviour and application access to align with organisational policies and working practices.

Users customise the service by accessing Microsoft’s web based administration interfaces and applying configuration and policy settings without modifying the underlying SaaS platform. Changes are applied in line with Microsoft service behaviour, permissions and propagation timelines.

Customisation is restricted to authorised buyer administrators and designated users with appropriate role based access. This ensures buyers retain full control over configuration and governance while maintaining platform security, service integrity and compliance with Microsoft standards and shared responsibility principles.
Configuration and customisation activities are performed by buyer administrators using Microsoft tools, with ROCK providing guidance where required rather than operational delivery.

Scaling

Independence of resources
Microsoft 365 is delivered as a multi-tenant SaaS platform operated by Microsoft, with logical tenant isolation enforced through Microsoft Entra ID and Microsoft’s cloud architecture. Each buyer environment is isolated at tenant level, preventing data or activity from impacting other customers. Platform capacity is managed by Microsoft and scales automatically to meet user demand.

Analytics

Service usage metrics
Yes
Metrics types
Microsoft 365 provides service usage and operational metrics through its administration and reporting portals. Metrics include active user counts, licence usage, storage consumption, email and collaboration activity, service health status, audit events and security related activity reports. These metrics support operational monitoring, capacity planning, governance, audit requirements and service optimisation.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
Resource tagging
Yes
FOCUS resource tagging
No

Supplier type

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Microsoft Corporation

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Microsoft 365 is designed as a resilient, cloud native software platform hosted on Microsoft’s global public cloud infrastructure. Services are deployed with redundancy across core components, including identity, application and data services, to reduce single points of failure. Workloads are distributed across multiple datacentres and availability zones, with automated failover and recovery mechanisms supporting service continuity. Platform health and performance are monitored continuously, with automated detection and response used to mitigate service degradation. Capacity management and elastic scaling are used to maintain performance as demand changes. Further detail on datacentre resilience and certifications is available through Microsoft trust documentation.
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users export data from Microsoft 365 using standard export, migration and download functionality provided by the platform. Authorised users and administrators can export emails, files, documents and other content through Microsoft administration tools, service interfaces and supported APIs to buyer owned systems or cloud environments. Data is exported in usable formats to support audit, compliance, business continuity or transition to alternative productivity or collaboration services where required.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • PST
Data import formats
Other
Other data import formats
  • Emails and mailbox data imported using supported migration tools
  • Files and documents uploaded to supported storage services
  • User and directory data synchronised through supported identity services

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Microsoft 365 is delivered as highly available, cloud-native Software as a Service (SaaS) platform hosted on Microsoft’s global public cloud infrastructure. Availability applies to access to Microsoft 365 workloads and supporting management interfaces and is governed by Microsoft’s published service level commitments, which define uptime targets, service credits and remediation arrangements.

The platform is architected for resilience using distributed datacentres, redundancy across core service components and automated failover mechanisms to minimise service disruption. Microsoft manages service availability, infrastructure resilience and capacity scaling as part of its shared responsibility model.

Planned maintenance activities are managed by Microsoft and are designed to minimise user impact. Where possible, maintenance is performed without service interruption and is communicated in advance through Microsoft service health notifications and administration portals. Unplanned incidents and service degradations are tracked and communicated by Microsoft through official service status channels.

ROCK does not control underlying platform availability but supports buyers by providing guidance on service health communications, assisting with interpretation of Microsoft incident updates, and coordinating escalation with Microsoft where this forms part of a wider Lot 3 managed or support service. Availability monitoring, incident coordination and service reporting can be enhanced through separately contracted support services under Lot 3.
Approach to resilience
Microsoft 365 is designed for resilience using redundant cloud architecture, geographic distribution and automated failover mechanisms within Microsoft’s global datacentre estate. Core productivity, collaboration and identity services are deployed across multiple locations to reduce single points of failure and support continued service operation during infrastructure incidents or planned maintenance.

Service continuity, data durability and platform resilience are managed by Microsoft as part of the shared responsibility model. Microsoft is responsible for the resilience of the underlying infrastructure, platform services and core application components, including capacity management, fault tolerance and recovery processes. Platform health and service performance are monitored continuously, with automated detection and response used to mitigate service degradation.

Data stored within Microsoft 365 is protected through resilient storage services designed for high durability, with built-in replication and redundancy to reduce the risk of data loss. Native backup, recovery and retention capabilities are provided through configurable tenant controls.

Buyers retain control over configuration, data retention and access policies within their Microsoft 365 tenant. ROCK supports buyers by advising on resilience-related configuration, governance controls and best-practice use of Microsoft 365 features where this forms part of a wider Lot 3 support service.
Outage reporting
Microsoft 365 reports service outages and service degradation through multiple communication channels. Service health and operational status information is available through Microsoft 365 administration portals, allowing authorised users to view current and historical service status across workloads.

Automated service health notifications and alerts are generated for significant service events and can be delivered by email to administrators. Status information and service event data can also be accessed through supported APIs to enable integration with external monitoring or service management tools.

Planned maintenance activities and major incidents are communicated in advance where possible, or as soon as reasonably practicable, with updates provided until service restoration is complete. ROCK’s service desk provides additional communication and support to buyers during service incidents, including assistance with understanding impact and coordinating updates where required.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using role-based access control and strong authentication. Permissions are assigned to defined roles and scoped resources to enforce least privilege access. Management access requires authenticated user accounts and supports multi factor authentication.

Administrative actions are logged and auditable through platform activity logging and monitoring services. Support access is restricted to authorised users through cloud support portals and ticketing systems. Customers manage identities, roles and permissions within their cloud tenancy, subject to the agreed service scope.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
ROCK follows a structured information security management framework supported by documented policies and operational processes designed to protect information assets and customer data. Core policies cover information security, access control, data protection, incident management, risk management and supplier assurance.

Information security responsibilities are clearly defined, with executive oversight provided by senior management and day to day security operations managed by designated security and technical leads. Policies are approved at board or senior management level and reviewed regularly to ensure continued relevance and compliance with legal, regulatory and contractual requirements.

Compliance with information security policies is enforced through role based access controls, secure configuration standards, logging and monitoring, staff training and incident reporting procedures. Security incidents are reported, investigated and managed in line with documented incident response processes, with escalation to senior management and customers where required.

Supplier and platform security assurances are reviewed as part of onboarding and ongoing service management to ensure continued alignment with security standards and buyer requirements.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
ROCK follows documented configuration and change management processes aligned to operational security best practice. Service components are identified, versioned and tracked throughout their lifecycle using configuration records and asset registers.

Proposed changes are logged, assessed and approved through a defined change process that considers operational, security and customer impact. Security implications are reviewed as part of change assessment, with testing and rollback plans defined where appropriate. Changes are implemented in a controlled manner, with logging, monitoring and post change review to confirm successful and secure deployment.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
ROCK operates a structured vulnerability management process to identify, assess and remediate security risks. Potential threats are assessed using risk based analysis informed by asset criticality, exposure and exploitability. Vulnerability information is sourced from vendor security advisories, cloud provider notifications, threat intelligence feeds and industry best practice guidance.

Patches and mitigations are prioritised based on risk and severity and deployed within defined timescales. Critical security updates are applied as soon as practicable, with testing and change controls applied to maintain service stability.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
ROCK uses protective monitoring processes to detect and respond to potential security incidents. Service activity, access events and system logs are monitored for indicators of compromise using automated alerts and operational review.

When a potential compromise is identified, incidents are assessed, contained and investigated in line with documented incident response procedures. Escalation paths ensure timely involvement of technical and security personnel. Response times are prioritised based on incident severity, with critical incidents investigated immediately and customers notified in accordance with contractual and regulatory requirements.
Incident management type
Supplier-defined controls
Incident management approach
ROCK follows documented incident management processes with predefined procedures for common service and security events. Users can report incidents through ROCK’s service desk using email or ticketing channels.

Incidents are logged, prioritised and managed in line with agreed response procedures, with escalation based on severity and impact. Incident updates are provided during resolution, and post incident reports are issued where appropriate, detailing root cause, actions taken and any preventive measures implemented.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
20%
Between £2,500,001 and £5,000,000
23%
Over £5,000,001
25%

Standards and certifications

ISO/IEC 27001 certification
Yes
ISO/IEC 27001 accredited by
NDC Certification Bureau Ltd
ISO/IEC 27001 accreditation date
Wednesday 22 January 2025
What the ISO/IEC 27001 doesn’t cover
None - ROCK’s ISO/IEC 27001:2022 certification applies to the whole organisation and covers all activities, systems, staff, and processes involved in the delivery of Cloud Support services.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
ISO 9001 certification accredited by
SGS
ISO 9001 accreditation date
Friday 20 October 2017
What the ISO 9001 doesn’t cover
None - ROCK’s ISO 9001:2015 Quality Management System applies to the whole organisation and covers all service delivery, operational, and management processes relevant to Cloud Support services.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
627384ad-afe1-4eca-bbaa-1e197073ca0d
Cyber essentials plus
Yes
Cyber Essentials Plus Certificate Number
0781e990-0c6f-4799-9b1b-9e723da53bbf
Other security certifications
No

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
  • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
  • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
  • Plans to engage the contract workforce in deciding the most important workplace issues to address
  • Ensuring new workers are informed of their right to join a trade union
  • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
  • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
  • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
  • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
  • Activities to cascade good practice on fair working conditions throughout the supply chain
  • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
  • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
  • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
  • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
  • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
  • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
  • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Volunteering opportunities for staff
  • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
  • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
  • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
  • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
  • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract

Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

  • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract

Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

  • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
  • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
  • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
  • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
  • Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
  • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
  • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
  • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
  • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
  • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Plans for positive actions with community groups.
  • Measures for making facilities used in the delivery of the contract available for community groups, education or training
  • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
  • Plans to respond flexibly and adapt approaches to community engagement and initiatives
  • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
Mission: Make Britain a clean energy superpower

To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

  • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
Mission: Break down barriers to opportunity

By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

Policy Outcome 6: Employment and training: For those who face barriers to employment

  • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
  • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
  • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
  • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
  • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
  • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
  • Introducing transparency to pay and reward processes
  • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
  • Working conditions which promote an inclusive working environment and promote retention and progression
  • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
  • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition

Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

  • Understanding of the issues affecting the development of new skills by target cohort
  • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
  • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
  • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Understanding of issues relating to entering the contract workforce
  • Creation of outreach activities to create a pipeline of employees for the future contract delivery
  • Content of the outreach activity is designed to suit the target cohort
  • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
Mission: Build an NHS fit for the future

That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

  • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
  • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
  • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
  • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@rock.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.