Physical and Virtual Infrastructure Management Software
Physical and Virtual Infrastructure Management Software provides a secure, software-delivered capability for managing and governing physical and virtual compute resources. The service enables public sector organisations to monitor, configure and control infrastructure environments across cloud platforms using provider-managed tooling, supported by structured operational oversight and service management.
Features
- Centralised management of physical and virtual infrastructure resources
- Real-time monitoring of compute performance and availability
- Policy-based control of infrastructure configuration changes
- Role-based access management for infrastructure administration
- Audit logging of infrastructure actions and changes
- Integration with cloud provider compute services
- Automated alerting for infrastructure performance anomalies
- API access for infrastructure automation and reporting
- Support for scalable virtualised compute environments
- Multi-cloud infrastructure governance through provider-managed platforms
Benefits
- Improve visibility across physical and virtual infrastructure environments
- Reduce risk from unauthorised infrastructure configuration changes
- Support reliable and resilient infrastructure operations
- Enable faster incident detection and resolution
- Improve operational efficiency managing infrastructure resources
- Support audit and assurance with detailed infrastructure logs
- Strengthen governance of virtualised compute environments
- Reduce operational overhead through centralised infrastructure control
- Improve service reliability through proactive monitoring
- Enable consistent infrastructure management across multi-cloud platforms
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 1 0 0 9 1 7 3 0 5 0 0 9 2 2
Contact
INVOLVED SOLUTIONS LTD
James Reading
Telephone: 0207 9522 444
Email: j.reading@involvedsolutions.com
About your service
- Service categories
-
Systems Infrastructure Software
Physical and virtual computing
Software defined compute
- Virtual Machine Software
- Container Infrastructure Software
- Cloud System Software
Other computing and storage software
- Container Data and Infrastructure Management Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The service can extend and integrate with existing cloud platform services and service management tooling used by public sector organisations. This includes hyperscale cloud infrastructure platforms, identity and access management services, monitoring and logging tools, and standard service management systems, while remaining fully functional as a standalone infrastructure software service.
- Cloud deployment model
-
- Public cloud
- Hybrid cloud
- Service constraints
- The service operates within the constraints of the underlying hyperscale cloud platforms used to deliver it. Planned maintenance may be required to apply updates, patches or platform improvements; where possible, this is scheduled in advance and designed to minimise service impact. The service supports standard, provider-supported configurations and services; unsupported or end-of-life components are excluded. Support is delivered within agreed service hours unless enhanced support options are selected. Any constraints are clearly communicated during onboarding and reviewed throughout the service lifecycle to ensure transparency and effective service planning.
- System requirements
-
- Access to a supported hyperscale public cloud platform
- Internet connectivity for secure service access and management
- Supported web browser for management interfaces
- Identity provider capable of federation and role-based access
- Multi-factor authentication enabled for administrative access
- Network connectivity allowing secure API and CLI access
- Supported operating systems for command line management tools
- Customer-approved data residency configuration within UK or EEA
- Permission to enable logging monitoring and audit services
- Compliance with provider-supported configurations and services
User support
- Email or online ticketing support
- Yes
- Support response times
- Support requests are acknowledged in line with agreed service levels. Priority incidents are acknowledged within one working hour, with standard service requests acknowledged within four working hours during core support hours. Response and resolution targets are aligned to incident severity. Weekend and out-of-hours response is available where enhanced support options are selected and is agreed during onboarding. Response performance is monitored and reviewed through regular service reporting.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide structured, ITIL-aligned support levels designed to meet differing operational and risk requirements.
Standard Support is included as part of the service. It provides access to a UK-based service desk during core business hours (9am–5pm, Monday to Friday), incident and service request management, change control, monitoring, and routine operational support. Priority incidents are acknowledged within one working hour, with standard requests acknowledged within four working hours.
Enhanced Support is available where customers require extended coverage, faster response targets, or additional specialist input. Enhanced options may include extended hours support, out-of-hours incident response, accelerated SLA tiers, and increased cloud engineering capacity. These options are tailored to customer requirements and risk profiles.
Support costs are transparent and proportionate. Standard Support is included within the service price. Enhanced Support options are priced separately based on the level of coverage, response commitments, and specialist resource required, typically using a monthly uplift, retainer, or agreed day-rate model.
Each engagement includes a named Service Manager responsible for service governance, performance oversight, escalation management and continuity assurance. For more complex environments, a dedicated Cloud Support Engineer or Technical Account Manager can be provided to deliver deeper technical guidance, optimisation support and ongoing platform assurance. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We support customers through a structured onboarding process designed to enable a smooth, secure and efficient start to the service.
Getting started begins with an initial onboarding session, typically delivered remotely, to confirm service scope, configuration requirements, security controls, data residency, access permissions and governance arrangements. Roles, responsibilities, escalation routes and service management processes are agreed at this stage.
Users are provided with clear service documentation, including onboarding guides, operating procedures and links to provider-maintained platform documentation relevant to the service. Documentation is designed to support day-to-day usage, support engagement and governance rather than generic platform training.
Online knowledge-transfer sessions and walkthroughs are provided for buyer-designated administrators and operational users, covering service usage, support processes, incident and change management, and reporting. Training is role-based and focused on practical application of the service.
Where required, onsite onboarding or training can be provided by prior agreement and at additional cost.
Each engagement includes a named Service Manager who coordinates onboarding activities, oversees access provisioning and remains the primary point of contact to ensure users are confident and fully operational from service commencement. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
End-of-contract data extraction
At the end of the contract, customers retain full ownership of their data and can extract it in a controlled and secure manner.
Users can access and export their data through the underlying cloud platform interfaces, APIs and service management tools used to deliver the service, subject to role-based permissions. Supported export mechanisms include standard provider-supported formats and interfaces, enabling customers to retrieve configuration data, logs, audit records and operational information for reuse or migration.
Where required, we provide assisted data extraction as part of the offboarding process. This includes coordination of data exports, confirmation of data completeness, and support for secure transfer to buyer-nominated destinations. Data extraction activities are planned and agreed in advance to minimise operational impact.
Following successful data extraction and customer confirmation, access to the service is revoked and remaining customer data is securely sanitised or erased in line with provider-managed data destruction processes and recognised security standards. A formal offboarding confirmation is provided to evidence completion.
This approach ensures buyers can reliably retrieve their data, meet audit and compliance obligations, and transition away from the service without vendor lock-in. - End-of-contract process
-
End-of-contract process
At the end of the contract, service exit is managed through a structured and controlled offboarding process to ensure continuity, security and transparency.
As part of the standard contract price, we support contract closure activities including confirmation of contract end dates, revocation of user and administrative access, and coordination of service shutdown in line with agreed timelines. Customers retain ownership of their data throughout. Data extraction using standard platform interfaces and supported formats is included, enabling buyers to retrieve configuration, audit and operational data.
Following confirmation that data extraction is complete, remaining customer data is securely sanitised or erased in accordance with provider-managed data destruction processes and recognised security standards. A formal offboarding confirmation is provided to evidence completion.
Additional services can be provided at extra cost where required. These may include extended data retention beyond contract end, assisted migration support, bespoke data export activities, additional reporting, or onsite support during transition. Any additional costs are agreed in advance and priced transparently.
This approach ensures a clear, auditable exit process, protects buyer data, and enables smooth transition without vendor lock-in or unexpected charges. - Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service provides a consistent experience across desktop and mobile devices through responsive, browser-based interfaces. On mobile devices, functionality is optimised for monitoring, status visibility, notifications, ticket updates and approvals. Desktop access provides the full range of configuration, administration and management capabilities. Certain advanced administrative actions may be restricted on mobile devices to maintain security and usability. All access remains subject to role-based permissions, authentication controls and governance policies, ensuring a secure and consistent user experience across device types.
- Service interface
- Yes
- User support accessibility
- EN 301 549
- Description of service interface
- The service interface is delivered through secure, browser-based management portals, APIs and service management tools provided by the underlying cloud platforms. The interface enables authorised users to configure and manage infrastructure software settings, view monitoring and audit information, raise and track support requests, and access service documentation and reports. Access is role-based and protected by strong authentication controls. The interface is responsive and accessible from desktop and mobile devices, providing visibility and operational oversight while maintaining appropriate security and governance controls.
- Accessibility standards
- EN 301 549
- Accessibility testing
- We do not operate a bespoke service interface and therefore do not carry out independent assistive technology usability testing. The service interface is delivered through established, third-party cloud platform and service management interfaces that are widely used across the public sector. These platforms are designed, tested and maintained by their providers to meet recognised accessibility standards, including EN 301 549, and to support common assistive technologies such as screen readers, keyboard navigation, magnification tools and browser accessibility features. Accessibility considerations are reviewed during onboarding, and where reasonable adjustments are required, alternative access methods or assisted service processes are agreed with the customer to ensure effective and inclusive service use.
- API
- Yes
- What users can and can't do using the API
-
Users can interact with the service through APIs provided by the underlying cloud platforms and service management tooling used to deliver the infrastructure software capability. APIs enable authorised users to automate configuration, monitoring, logging and integration activities within their environments, subject to role-based access controls and agreed governance.
Initial service setup is performed by our engineering team to ensure secure baseline configuration and compliance. Once access and permissions are established, users can use APIs to integrate the service with their own systems, retrieve operational and audit data, automate permitted configuration changes and support workflows, and embed monitoring or reporting into existing processes.
Users can make changes through APIs where permissions allow and within the boundaries of the agreed architecture. Changes that could affect security, resilience or compliance are subject to formal change management and approval processes and are implemented by authorised engineers.
Users cannot bypass security controls, governance policies or approval requirements through the API. Privileged actions, core architectural changes and initial environment design are restricted to authorised service personnel. - API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
How users can customise the service
The service can be customised through configuration rather than bespoke development, ensuring flexibility while maintaining security and compliance.
What can be customised
Buyers can customise configuration settings including access roles and permissions, policy controls, monitoring and alerting thresholds, logging and audit retention, integration points, support levels, and operational governance parameters. Data residency, resilience options and reporting frequency can also be tailored to organisational requirements.
How users can customise
Customisation is carried out through secure, browser-based management interfaces, APIs and command line tools provided by the underlying cloud platforms and service management systems. Configuration changes are applied in line with agreed governance and change management processes to ensure continued security, availability and compliance.
Who can customise
Customisation is restricted to authorised users based on role-based access controls. Buyer-designated administrators can make permitted configuration changes within agreed boundaries. Changes that may affect security, resilience or compliance are implemented by authorised service personnel following formal approval. This approach ensures buyers retain appropriate control while maintaining consistent service assurance.
Scaling
- Independence of resources
-
Independence of resources
The service is delivered using logically isolated, virtualised cloud resources provided by hyperscale cloud platforms. Customer environments are segregated through tenant isolation, role-based access controls and provider-enforced security boundaries. Capacity is allocated dynamically and governed by platform controls to prevent resource contention between customers. Monitoring and performance management ensure workloads operate within defined thresholds, and scaling mechanisms are used to maintain service performance. This approach ensures that demand from one customer does not adversely affect the availability, performance or security of another customer’s service.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide service usage and operational metrics through provider-supported monitoring, logging and reporting tools. Metrics include service availability, incident and request volumes, response and resolution times, platform utilisation indicators, audit events and service performance trends. Where applicable, metrics are presented through dashboards and regular service reports. Metrics support operational oversight, service assurance, capacity planning and continuous improvement. Access to metrics is controlled through role-based permissions and aligned to agreed governance and reporting requirements.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Data export approach
Users export their data using provider-supported interfaces, including secure web portals, APIs and command line tools, subject to role-based access controls. Data can be retrieved in standard, non-proprietary formats supported by the underlying platforms, enabling reuse or migration. Exports can be performed directly by authorised users or coordinated by our support team where assistance is required. Data export activities are planned to minimise service impact and are governed by agreed security and change management controls to ensure data integrity, confidentiality and auditability throughout the process. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- Plain text (TXT)
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- Plain text (TXT)
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- In addition to TLS encryption, data within the service is protected using provider-managed network isolation, logical segmentation and tenant separation controls. Service-to-service communication is restricted using identity-based access policies and least-privilege principles. Internal traffic is monitored and logged to detect anomalous behaviour, and security controls are centrally enforced to prevent unauthorised access or lateral movement. Network security configurations are managed through approved change processes and regularly reviewed to maintain confidentiality, integrity and availability of data within the service environment.
Availability and resilience
- Guaranteed availability
-
The service is delivered using resilient, hyperscale cloud platforms designed to support high availability and fault tolerance. Availability is measured at the service level and supported by provider-managed infrastructure deployed across multiple availability zones or fault domains where appropriate.
We offer a minimum service availability target of 99.9% per calendar month, excluding pre-agreed planned maintenance. Availability commitments are defined within the service agreement and are supported by continuous monitoring and operational management.
Where availability falls below the agreed target, service credits are applied in accordance with the contract. Service credits are calculated proportionately based on the duration and severity of the service impact and are applied as a credit against future service charges. The application of service credits is transparent and supported by monitoring data and incident records.
Availability performance is reviewed through regular service reporting and governance meetings. Repeated or material availability issues are subject to root cause analysis and corrective action planning to prevent recurrence. This approach ensures clear accountability, measurable service performance and alignment with public sector expectations for reliability and value for money. - Approach to resilience
-
The service is designed for resilience using provider-managed hyperscale cloud infrastructure engineered to withstand component failure without service disruption. Datacentres are built with redundant power, cooling, networking and physical security controls, and are independently certified against recognised security and resilience standards.
Services are deployed using virtualised, logically isolated resources and can be configured across multiple availability zones or fault domains to reduce the risk of single points of failure. Automated monitoring continuously assesses platform health and performance, enabling rapid detection and response to service degradation.
Data protection mechanisms include regular backups, configurable retention policies and tested recovery procedures. Where required, customers can adopt multi-zone or regional resilience patterns aligned to their risk profile and operational requirements.
Resilience is further supported by structured incident, problem and change management processes, ensuring that issues are investigated, remediated and prevented from recurring. Service performance and resilience are reviewed through regular governance and reporting cycles.
Detailed datacentre design, resilience architecture and recovery capabilities are available on request for buyers requiring deeper assurance. This layered approach ensures the service remains available, secure and recoverable in line with public sector resilience expectations. - Outage reporting
-
Service outages and service-affecting incidents are communicated through a structured and transparent reporting approach. Customers receive timely notifications via email alerts for confirmed incidents, including initial impact assessment, progress updates and resolution confirmation.
Operational status and service health information is available through provider-managed service status dashboards, which provide near real-time visibility of platform availability, incidents and maintenance activity affecting the service. These dashboards are widely used across the public sector and support independent verification of service status.
Where applicable, APIs provided by the underlying platforms enable customers to integrate service status and incident information into their own monitoring and reporting tools.
In addition, incidents and outages are recorded and tracked through the service management system, allowing authorised users to view incident status, updates and post-incident summaries. Root cause analysis and corrective actions are provided for material incidents through formal incident reports and service reviews.
This multi-channel approach ensures customers receive timely, accurate and auditable outage information, supporting operational assurance and effective service governance.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access controls and least-privilege principles. Users are granted permissions based on their role and approved responsibilities, with elevated privileges limited to authorised administrators. Authentication is enforced using multi-factor authentication and federated identity where applicable. Support access is similarly controlled, ensuring only authorised users can raise, view or manage tickets. Access rights are reviewed regularly and updated as roles change. All access activity is logged and monitored to support audit, accountability and security oversight.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We operate a formal information security management framework aligned to recognised standards, including ISO/IEC 27001 principles and the Government Cloud Security Principles. Our policies cover information security governance, access control, data protection, incident management, vulnerability management, change control, supplier assurance and business continuity.
Information security accountability sits with senior management, supported by designated security and service management roles responsible for day-to-day implementation, oversight and assurance. Clear reporting lines are in place to ensure security risks, incidents and non-conformities are escalated appropriately and addressed promptly.
Policies are embedded into operational processes and enforced through role-based access controls, least-privilege principles, monitoring and audit logging. Compliance is maintained through regular reviews of access rights, change approvals, incident records and service performance metrics. Security controls provided by underlying cloud platforms are configured and managed in line with documented policies and customer requirements.
Staff are required to follow defined security procedures and receive appropriate training relevant to their role. Adherence to policies is supported through periodic internal reviews, supplier assurance activities and service governance meetings, ensuring continuous alignment with regulatory requirements, customer obligations and evolving security best practice. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Service components are tracked throughout their lifecycle using provider-managed configuration management, asset inventories and service management records. Configuration baselines are defined during onboarding and maintained through controlled change processes. All changes are logged, categorised and assessed for operational, security and compliance impact prior to implementation. Security-sensitive changes are subject to additional review and approval by authorised personnel. Changes are tested where appropriate and implemented in line with agreed maintenance windows. Post-change validation and monitoring confirm successful deployment and identify any unintended impact, ensuring continued service integrity and security.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Vulnerabilities are assessed using provider-managed security tooling, threat intelligence feeds and continuous monitoring of the service environment. Potential threats are evaluated based on severity, exploitability and impact. Patching is prioritised accordingly, with critical security updates deployed as soon as practicable and in line with agreed change processes. Routine patches are applied through scheduled maintenance. Threat intelligence is sourced from cloud platform providers, industry security advisories, vendor notifications and government guidance, including NCSC publications. Vulnerability status and remediation actions are monitored and reviewed through operational reporting and service governance processes.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Protective monitoring is delivered through provider-managed security monitoring, logging and alerting capabilities. Potential compromises are identified through continuous analysis of security events, access logs, network activity and system behaviour against defined thresholds and indicators of compromise. Alerts are prioritised based on severity and potential impact. When a potential compromise is detected, incidents are investigated promptly in line with defined incident management procedures, including containment and remediation where required. Response times are aligned to incident severity, with high-risk events acted upon immediately and escalated through established governance and reporting channels.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate defined, documented incident management processes aligned to recognised standards. Pre-defined procedures exist for common events, including service outages, security incidents and performance degradation. Users report incidents through email, phone or the online service management system, with incidents logged, prioritised and tracked in line with agreed SLAs. Customers receive timely updates throughout the incident lifecycle. For material incidents, formal incident reports are provided, including impact assessment, root cause analysis, corrective actions and prevention measures. Incident performance and trends are reviewed through regular service reporting and governance meetings.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- UKAS
- ISO 9001 accreditation date
- Wednesday 7 January 2026
- What the ISO 9001 doesn’t cover
-
Our ISO 9001 certification covers the core quality management system governing service delivery, operational processes, and organisational management controls. Activities outside the certification scope relate primarily to third-party supplier environments, customer-controlled infrastructure, and external platforms that are not owned or directly operated by our organisation.
While these external components are not included within the formal certification boundary, supplier management and assurance processes are embedded within our quality framework. We apply documented supplier selection, monitoring, and performance review controls to maintain consistent service standards across the delivery chain.
Customer-owned systems, environments, and integrations are governed through agreed engagement controls but fall outside the ISO 9001 audit scope because they are not under our operational control. This does not reduce the quality management practices applied to services delivered.
The certification scope is reviewed regularly to ensure alignment with service delivery responsibilities. All in-scope operational activities are subject to internal audit, continuous improvement processes, and management review to maintain compliance with ISO 9001 requirements. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- D152b113-aa37-455f-aa7c-b8fd1d55dbf2
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 8acf2c2e-0d5e-4afe-ae7b-e18b74b89b9e
- Other security certifications
- Yes
- Any other security certifications
-
- IASME Cyber Assurance
- ISO 20000-1
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-