Skip to main content

Help us improve the Digital Marketplace - send your feedback

INETUM DIGITAL SERVICES UK LIMITED

Microsoft Licenses

Resell and manage Microsoft cloud licenses (Microsoft 365, Dynamics 365, Azure, Security) via CSP. We handle tenant setup, provisioning, billing, and compliance; optimize spend with right‑sizing, NCE term guidance, incentives, and usage reviews; manage POR, renewals, and migrations; and provide governance, reporting, and support aligned to public sector needs.

Features

  • CSP onboarding and tenant setup
  • Licensing discovery and SKU right‑sizing
  • NCE term planning and renewal management
  • Billing consolidation and invoicing management
  • Cost optimisation and usage analytics dashboards
  • Security baseline enablement (MFA, Conditional Access)
  • Compliance mapping and audit‑ready reporting
  • Funding and incentive program orchestration
  • Migration to CSP and POR/tenant transitions
  • Support escalation and named TAM governance

Benefits

  • Faster, compliant start with correct policies, billing, and POR
  • Lower spend by aligning licences to roles and usage
  • Predictable renewals and minimised lock‑in risk
  • Simpler finances and clearer cross‑subscription visibility
  • Ongoing savings through waste detection and trends tracking
  • Reduced breach risk from enforced identity safeguards
  • Quicker attestations with prepared evidence packs
  • Offset costs via eligible Microsoft funding and rebates
  • Minimal downtime; preserve identities and data integrity
  • Faster issue resolution with governed escalation paths

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at accounts.uk@inetum.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 7 7 1 4 5 7 8 9 4 0 3 2 8 5

Contact

INETUM DIGITAL SERVICES UK LIMITED Inetum Digital Services UK Ltd
Telephone: 020 3961 6001
Email: accounts.uk@inetum.com

About your service

Service categories

Application Development and Deployment

Application platforms

  • Model driven application platforms
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Microsoft Services
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
Licensing is supplied via Microsoft CSP New Commerce; availability, pricing, programme rules and incentives may change. Some SKUs/geographies/tenants are subject to eligibility, export‑control and credit checks. Azure is usage‑billed; budgets/alerts are buyer‑managed. Cancellations or seat reductions follow NCE policies (e.g., 7‑day window; mid‑term proration limits). Tenant admin consent, billing profile, and tax/VAT validation are required. POR changes/migrations depend on current partner/EA status and Microsoft maintenance windows. Our scope covers licensing and provisioning; product configuration/support is separate unless contracted. Data residency and compliance are governed by Microsoft cloud regions.
System requirements
  • Microsoft Entra tenant active with verified domain ownership.
  • Global Administrator to accept reseller relationship and permissions.
  • Acceptance of Microsoft Customer Agreement and data protection terms.

User support

Email or online ticketing support
Yes, at extra cost
Support response times
According to SLA
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Essential (included): License provisioning, billing queries, and incident triage during business hours, with escalation to Microsoft as needed.
Enhanced: Adds 8×5 technical helpdesk for Microsoft 365, Azure, and Dynamics 365, standard change requests, and monthly cost/usage insights via our CSP dashboard.
Advanced: 24×7 critical‑incident response, accelerated escalations, a named Service Delivery Manager, quarterly service reviews, and proactive cost and health checks.
Premium: All Advanced features plus advisory/TAM‑style guidance (roadmap, governance, architecture), FastTrack orchestration, adoption and security baselining, and custom reporting.
How much:

Essential is included as part of our CSP reseller responsibility.
Enhanced/Advanced/Premium are priced per tenant, per month, with optional per‑incident or per‑user components.
Discounts are available for multi‑tenant portfolios and 12–36‑month terms.
UK Public Sector: Final rates and maximums are defined in the G‑Cloud Pricing Document for this Service; call‑off contracts can add bespoke SLAs where required.

All tiers include SLA‑backed response targets, clear escalation paths, and access to our proximity centres for round‑the‑clock coverage when selected.
Support available to third parties
No

Onboarding and offboarding

Getting started
Getting started

Kick‑off & setup – We run a short discovery to confirm scope, roles, SLAs, security/access, and escalation paths. We provision your tenant in our CSP, enable billing, and grant you portal access to dashboards and support.
Onboarding & runbooks – We tailor incident, request, and change runbooks; define comms templates for major incidents; and agree governance (CAB cadence, RACI, reporting).
Enablement & training –

Online training: live, instructor‑led sessions plus recorded modules for admins, service desk, and workload owners.
Onsite training (optional): focussed workshops for executives, IT ops, or business teams.
User documentation: customer‑branded quick‑start guides, admin handbooks, and KB articles in your chosen format; updates included with service changes.

Go‑live readiness – Access tests, handover checklist, and role‑based rehearsals for P1/P2 scenarios.
Adoption & improvement – Monthly service reviews with action logs, cost/usage insights, and a continuous‑improvement backlog. Where eligible, we also orchestrate Microsoft FastTrack and partner funding to accelerate adoption.

What you get on day one: named Service Delivery Manager, support contacts and SLAs, portal credentials, reporting pack, and your customised escalation matrix.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
End‑of‑contract data extraction

Ownership & portability. You retain ownership of all service data. Our exit plan guarantees portability and handover to your chosen destination without vendor lock‑in.
Offboarding plan. We confirm scope and recipients, schedule exports, transfer runbooks and credentials, remove our access, and provide evidence of data return or destruction.
Microsoft 365. Exports via native tools/APIs (Exchange, SharePoint/OneDrive, Teams, Purview eDiscovery/Content Search). We can assist with tenant‑to‑tenant moves and post‑migration validation.
Dynamics 365 (Dataverse). Structured exports (CSV/API/backup restore) with schema and relationship maps to preserve data integrity for your target system.
Azure. Subscriptions/resources are returned or transferred per the exit plan; we deliver final cost/usage exports and tagging to support reconciliation.
Security & compliance. We follow an agreed “return or destroy” procedure, document retention windows, and—on request—issue a certificate of destruction. International transfer pathways and roles are defined in the contract annexes.
Effort & pricing. Standard exports are included with contract close‑out. Complex tenant moves, bespoke formats, or accelerated timelines are provided as professional services.

A named exit lead coordinates all activities, keeps stakeholders informed, and ensures continuity until you confirm successful ingestion in the destination environment.
End-of-contract process
End‑of‑contract process

Notice & planning. We acknowledge termination, confirm notice period, freeze non‑critical changes, and agree an exit plan with roles, dates, and risks.
Handover & access. We transfer runbooks, configuration baselines, credentials, and support history; remove delegated admin, rotate secrets, and de‑scope our accounts.
Data return. We export tenant data using native tools/APIs, package schema/metadata where applicable, and provide integrity checksums.
Service transition. We brief your replacement supplier, walk through escalation and monitoring, and run agreed cutover rehearsals.
Closure. Final reporting, billing reconciliation, license hand‑back (or transfer), CPOR/PAL updates, and—if selected—certificate of data destruction.

Included in the contract price

Exit planning session and checklist
Standard data exports (native formats)
Knowledge transfer of service docs/runbooks
Access removal and security sign‑off
Final service report and billing reconciliation

Additional cost (on request)

Complex tenant‑to‑tenant migrations or cross‑cloud moves
Data transformation, bespoke formats, or extensive eDiscovery packaging
Dual‑run/extended overlap support beyond contract end
Onsite transition support and accelerated timelines
Third‑party migration tooling/licenses and long‑term archival storage
Post‑exit advisory (e.g., architecture hardening, optimization)

All activities follow your DPA/contract annexes for data return or destruction and are completed upon your written acceptance.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
WCAG 2.2 AA
API
No
Customisation available
Yes
Description of customisation
What can be customised

Coverage & SLAs: hours (8×5/24×7), response/restore targets, severity definitions, change windows.
Scope: Microsoft clouds (M365, Azure, D365), included workloads, standard vs. bespoke changes, automation/runbooks.
Engagement model: named SDM/TAM, escalation paths, CAB cadence, incident/major‑incident comms.
Security & compliance: access model, approvals, audit artefacts, data residency.
Reporting & governance: KPI set, cost/usage dashboards, executive/technical reviews.
Commercials: per‑tenant/per‑user/per‑incident blends, term and volume options.

How users customise

Service design workshop & onboarding questionnaire to select tiers and add‑ons.
Service Catalogue pick‑and‑mix (e.g., 24×7 for critical workloads, 8×5 elsewhere).
Runbook tailoring for incidents, requests, and change workflows.
Governance setup (CAB cadence, RACI, escalation matrix).
Continuous improvement via monthly/quarterly service reviews and change requests.
Self‑service portal to adjust contacts, approvals, and reporting packs.

Who can customise

Customer: Contract/Commercial Lead, Service Owner, Technical Lead/Architect, Security/Compliance, and Finance.
Inetum: Service Delivery Manager, TAM/Architect, Support Manager, and Billing Ops to reflect changes in SLAs, scope, and pricing.

Scaling

Independence of resources
Data/identity isolation: Each customer operates in their own Microsoft tenant; least‑privileged, JIT/PAM access; no cross‑tenant data paths.
Capacity isolation: Per‑subscription quotas, autoscale policies, and landing‑zone guardrails prevent “noisy‑neighbour” contention; rate‑limits on automation/batch jobs.
Support isolation: Dedicated SDM, per‑customer queues with concurrency caps, and surge cells/overflow teams to guarantee SLAs.
Change isolation: CAB‑approved maintenance windows and freeze periods avoid cross‑customer impact.
Monitoring & SLOs: Per‑customer dashboards, alert thresholds, and error‑budget tracking; deviations trigger a scale‑up/redistribute plan and corrective actions captured in the service review.

Provide your feedback on BizChat

Analytics

Service usage metrics
Yes
Metrics types
SLA attainment: response/restore by severity, MTTA/MTTR
Incident quality: first‑contact resolution, reopen rate, major‑incident comms time, problem backlog age
Change & release: success rate, change lead time, failed‑change rollback time, CAB adherence
Availability & performance: uptime SLOs, capacity trends
Security & compliance: patch/vulnerability remediation SLA, privileged‑access reviews
Cost & adoption: Azure/M365/D365 cost variance vs budget, optimization savings, active users/feature adoption
Experience: CSAT/XLA (task completion time, sentiment)
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Microsoft

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
Physical access control, complying with CSA CCM v4.0
Hosted on hyperscale datacentres certified against CSA STAR/CCM v4.0, with 24/7 guards, CCTV, biometrics, mantraps, and strict visitor controls.

Physical access control, complying with SSAE‑18 / ISAE 3402
Independent SOC 1/2/3 audits, documented chain‑of‑custody

Physical access control, complying with another standard
ISO/IEC 27001, 27017, 27018, and ISO 22301 for business continuity.

Encryption of all physical media
SQL TDE; disk encryption (BitLocker/DM‑Crypt); optional customer‑managed keys via Key Vault/Managed HSM and double‑encryption where supported.

Scale, obfuscating techniques, or data storage sharding
Per‑tenant logical isolation, key separation, data sharding/partitioning, immutable/WORM storage options, soft‑delete/versioning, and pseudonymisation/tokenisation.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Degaussing
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Data export approach

We prioritise native Microsoft export paths for fidelity and auditability.
Microsoft 365: Exchange (PST/MAPI), SharePoint/OneDrive/Teams via Export/Graph/CSOM or Purview eDiscovery; optional tenant‑to‑tenant tooling.
Dynamics 365/Dataverse: Structured exports (CSV/API/backup) with schema and lookup maps to preserve relationships.
Azure: Resource/Subscription transfer or export of blobs, databases, and logs, plus final cost/usage reports.
Packaging: Encrypted archives with checksums and a content manifest.
Governance: Planned change freeze, role/access removal, customer acceptance testing, and—on request—certificate of destruction.
Data export formats
  • CSV
  • ODF
Data import formats
  • CSV
  • ODF

Data-in-transit protection

Data protection between buyer and supplier networks
Other
Other protection between networks
Private network or public sector network
Supported via private connectivity (Azure ExpressRoute private peering and Private Link). PSN not required by default; integration available if mandated.

TLS (Version 1.2 or above)
TLS 1.2+ enforced (TLS 1.3 preferred) with modern cipher suites and perfect forward secrecy; certificate lifecycle managed in Azure Key Vault.

IPsec or TLS VPN gateway
Supported: site‑to‑site IPsec/IKEv2 or TLS VPN to buyer gateways; can be combined with ExpressRoute for hybrid scenarios.
Legacy SSL and TLS (under 1.2)
Not permitted; disabled by policy and continuously monitored.
Data protection within supplier network
Other
Other protection within supplier network
Protection within our network (Data‑in‑transit)

TLS (Version 1.2 or above): Enforced for all east‑west traffic (TLS 1.3 preferred) with PFS ciphers; certificates issued and rotated via Azure Key Vault.
IPsec or TLS VPN gateway: IPsec/IKEv2 or TLS tunnels for inter‑site, admin, and management planes.
Legacy SSL and TLS (under 1.2): Not permitted; blocked by policy and monitored.
Other: Mutual TLS at API gateways/service mesh; Private Link/private endpoints to avoid public ingress; strict network segmentation (VNETs/subnets/NSGs, micro‑segmentation), zero‑trust access with JIT/PAM; keys optionally in Managed HSM; continuous telemetry and alerting.

Availability and resilience

Guaranteed availability
Availability target – Defined per service in your Service Delivery Plan and reported monthly. Our reference target for managed OS/services is 99.6%, with higher targets available when the architecture is designed for HA.

Measurement & exclusions – Availability is measured over the agreed period and excludes planned maintenance and events outside our control (e.g., third‑party WAN failures, force majeure).

Service reporting – Monthly service reports show achieved availability and SLA performance against targets, plus actions for any deviations.

Remedies (service credits) – If SLA commitments are missed, service credits apply per incident exceeding contractual resolution time, typically 1/60th of the annual service cost per incident, aggregated and capped at 20% of the annual service cost. Credits are refunded within 30 days of invoice or offset against future payments.

Chronic issues – Hitting 5/60ths across two consecutive quarters triggers a remedial plan; exceeding 7/60ths in any 12‑month period (or failure of the remedial plan) is treated as material breach.
Approach to resilience
Approach to resilience

Resilient architecture: Stateless services on managed PaaS with auto‑healing; stateful stores deployed with zone‑redundant options. Patterns include circuit‑breakers, retries with back‑off, idempotent operations, and queue‑based buffering to absorb spikes.
Datacentre resilience: Hosted in hyperscale regions using physically separate Availability Zones (independent power/cooling/network). Optional multi‑region DR with warm or hot standby and cross‑region backups. Private connectivity and private endpoints reduce exposure.
Backups & recovery: Automated, encrypted backups with immutable/WORM retention where supported, point‑in‑time restore, and replicated copies. RPO/RTO are defined by service tier and validated in recovery drills.
Operations & change: 24×7 monitoring, SLO/error‑budget tracking, alerting, and runbooks for failover/failback. Controlled change windows, blue/green or canary releases with rapid rollback.
Security hardening: DDoS protection, WAF, network segmentation, least‑privileged/JIT admin, keys in dedicated key management (incl. HSM options).
Testing & learning: Regular DR exercises, chaos/game‑day testing, and post‑incident root‑cause analysis with remediation tracking.
Transparency: Monthly resilience reporting and service reviews. Detailed datacentre topology and audit attestations are available on request.
Outage reporting
Outage reporting

Public status dashboard: Real‑time availability and incident timelines per service and region, plus planned maintenance windows. Historical uptime and post‑incident notes are retained.
API & feeds: JSON status API and RSS/Atom feeds for automated monitoring and vendor aggregation; includes current status, components affected, and next update ETA.
Email/SMS alerts: Opt‑in notifications for incidents, maintenance, and resolution. Distribution lists can be scoped by service, region, and severity.
Webhook/ChatOps: Optional webhooks to post updates into Microsoft Teams/Slack and ITSM tools to open/resolve incidents automatically.
In‑product banners: Contextual notices displayed to signed‑in admins when an issue impacts their tenant/workload.
Cadence & transparency:

T+15 min: issue acknowledged with impact summary and first ETA.
Every 30–60 min: status updates or sooner on material change.
On resolve: root cause outline and mitigation.
Within 5 business days (major): detailed post‑incident review and corrective actions.

Subscription management: Admins manage alert preferences (channel, severity, services/regions) and can delegate to multiple recipients.
Accessibility: Dashboard and feeds are publicly accessible; API keys provided for rate‑limited integrations upon request.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Access restrictions for admin interfaces & support
Admin access uses Microsoft Entra ID SSO with MFA and conditional access (device compliance, geo/IP, risk). RBAC least‑privilege; JIT/PAM elevation with approvals; break‑glass accounts sealed and monitored. Admin planes are reachable only via private networks/VPN, with IP allow‑lists, mTLS/API keys rotated in Key Vault, and session timeouts. All actions are audited to SIEM with anomaly alerting.
Support channels: only named, verified requesters; tickets tied to assets and entitlements; encrypted channels (Teams/portal) only—no credentials by email. Screen‑sharing via approved tools with consent; data masking on consoles; session recording; two‑person control for high‑risk operations.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Information security policies and processes

Policy framework: We operate a Group Information Security Policy (ISSP), supported by an Information Security Policy, Data Protection Policy, and a Third‑Party Risk Management process. Policies cover access control, cryptography, secure development, vulnerability/patch management, logging/monitoring, incident response, asset management, data retention/destruction, and acceptable use. They are aligned to internationally recognised controls (e.g., ISO/IEC 27001 family, CSA CCM) and reviewed at least annually.

Governance & reporting: The Group CISO sets strategy and owns the ISSP via the Corporate Security function. Local Security Leads in each business unit ensure implementation. Privacy is overseen by the Group DPO with local DPOs. Security incidents are triaged by operations, escalated to Security Management, and—if personal data is affected—jointly handled with the DPO; major incidents are reported to executive leadership and impacted clients.

Assurance & enforcement: Mandatory onboarding/annual training, phishing simulations, and role‑based modules. Technical guardrails (MFA, PAM/JIT, least privilege, network segmentation, SIEM use cases, DLP) enforce policies. We run risk assessments and DPIAs, internal audits, corrective action tracking, and supplier due diligence. Exceptions require documented, time‑bound approvals. Breaches of policy trigger disciplinary procedures and remediation. External attestations can be shared under NDA on request.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Configuration tracking: All components are registered as Configuration Items (CIs) in the CMDB, with owner, environment, version, dependencies, and security classification. We maintain baselines, automate discovery where possible, and record full CI lifecycle (create → modify → retire) with audit trails.

Change process: Changes are raised with purpose, implementation plan, backout/rollback, test evidence, and monitoring plan. We classify standard/normal/emergency, assess risk and security impact (data sensitivity, identity/network touchpoints, keys/certs, exposure), and check conflicts against the change calendar. Approval flows run via CAB/ECAB. Pre‑prod validation is required; production releases use controlled windows. Every change undergoes post‑implementation review and metrics tracking.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Assessing threats: Continuous discovery and authenticated scanning across cloud/endpoints; container/SBOM/SCA in CI/CD; risk scored with CVSS + exploitability (known‑exploited), asset criticality, internet exposure, and lateral‑movement factors. Findings are triaged in our ticketing system with owner and due date.
Patching SLAs: Emergency/actively exploited: out‑of‑band, change‑controlled, target <24–72h. High: ≤7 days. Medium: ≤30 days. Low: ≤90 days. Compensating controls (WAF, EDR hardening) applied if a patch isn’t immediately possible; all changes have rollback plans and PIRs.
Threat sources: Microsoft MSRC, CISA KEV, national CERT/NCSC advisories, vendor PSIRTs, ISAC feeds/MISP, and managed threat‑intel services.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Identify potential compromises: 24×7 SOC using SIEM (Microsoft Sentinel), XDR/EDR telemetry, UEBA, cloud‑posture signals, and curated threat intel. Correlations and anomaly baselines flag suspicious behavior; high‑fidelity alerts auto‑enrich with IOCs, asset criticality, and blast‑radius graphs.
Respond to potential compromises: Triage → contain (isolate endpoints, block IOCs, revoke tokens, disable accounts) → eradicate (patch/remove) → recover. SOAR playbooks automate first actions; DFIR engaged as needed. Post‑incident review captures root cause and hardening actions.
Response times: P1 acknowledge ≤15 minutes, investigation start ≤30 minutes, containment target ≤4 hours. P2 acknowledge ≤1 hour, containment ≤8 hours.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Pre‑defined processes: ITIL‑aligned workflows and runbooks for common events (account compromise, phishing/malware, service degradation, data loss, DDoS). Major Incident (P1) playbook includes 24×7 on‑call, bridge/war‑room, stakeholder comms, and rapid workaround/rollback paths.
How users report: Service Desk portal (preferred), email to the support alias, or phone hotline. Monitoring/XDR automatically opens incidents with enrichment; Virtual Agent can triage and deflect where suitable.
How we provide reports: Initial notification on registration, regular status updates until resolution, and a closure note. For P1s, a Post‑Incident Review (root cause, timeline, impact, corrective actions) is issued within five business days and stored in the portal.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
6%
Between £1,000,001 and £2,500,000
7%
Between £2,500,001 and £5,000,000
8%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Schellman Compliance, LLC
ISO/IEC 27001 accreditation date
Tuesday 7 October 2025
What the ISO/IEC 27001 doesn’t cover
Excluded from the scope are all operations of third-party data centers, Microsoft Azure, AWS, and GCP.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Certi-Trust Eastern & Southern Africa
ISO 9001 accreditation date
Wednesday 15 January 2025
What the ISO 9001 doesn’t cover
Excluded from the scope are all operations of third-party data centres for Azure and Amazon AWS.
Quality management systems (QMS)
Yes
CSA STAR certification
Yes
CSA STAR accreditation date
Friday 5 December 2025
CSA STAR certification level
Level 2: CSA STAR Attestation
What the CSA STAR doesn’t cover
The scope of the CSA STAR certification is aligned to the scope of the ISO/IEC 27001:2022 certification is limited to the information security management system (ISMS) supporting ServiceNow as a provider of cloud-based solutions that define, structure, manage, and automate services across the global enterprise.
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
511e8310-880f-4412-b76c-45c03544d185
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
60bc774c-f0d5-4ffd-b64a-760f02f80e87
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
    • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
    • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at accounts.uk@inetum.com. Tell them what format you need. It will help if you say what assistive technology you use.