Microsoft Licenses
Resell and manage Microsoft cloud licenses (Microsoft 365, Dynamics 365, Azure, Security) via CSP. We handle tenant setup, provisioning, billing, and compliance; optimize spend with right‑sizing, NCE term guidance, incentives, and usage reviews; manage POR, renewals, and migrations; and provide governance, reporting, and support aligned to public sector needs.
Features
- CSP onboarding and tenant setup
- Licensing discovery and SKU right‑sizing
- NCE term planning and renewal management
- Billing consolidation and invoicing management
- Cost optimisation and usage analytics dashboards
- Security baseline enablement (MFA, Conditional Access)
- Compliance mapping and audit‑ready reporting
- Funding and incentive program orchestration
- Migration to CSP and POR/tenant transitions
- Support escalation and named TAM governance
Benefits
- Faster, compliant start with correct policies, billing, and POR
- Lower spend by aligning licences to roles and usage
- Predictable renewals and minimised lock‑in risk
- Simpler finances and clearer cross‑subscription visibility
- Ongoing savings through waste detection and trends tracking
- Reduced breach risk from enforced identity safeguards
- Quicker attestations with prepared evidence packs
- Offset costs via eligible Microsoft funding and rebates
- Minimal downtime; preserve identities and data integrity
- Faster issue resolution with governed escalation paths
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 7 7 1 4 5 7 8 9 4 0 3 2 8 5
Contact
INETUM DIGITAL SERVICES UK LIMITED
Inetum Digital Services UK Ltd
Telephone: 020 3961 6001
Email: accounts.uk@inetum.com
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Microsoft Services
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- Licensing is supplied via Microsoft CSP New Commerce; availability, pricing, programme rules and incentives may change. Some SKUs/geographies/tenants are subject to eligibility, export‑control and credit checks. Azure is usage‑billed; budgets/alerts are buyer‑managed. Cancellations or seat reductions follow NCE policies (e.g., 7‑day window; mid‑term proration limits). Tenant admin consent, billing profile, and tax/VAT validation are required. POR changes/migrations depend on current partner/EA status and Microsoft maintenance windows. Our scope covers licensing and provisioning; product configuration/support is separate unless contracted. Data residency and compliance are governed by Microsoft cloud regions.
- System requirements
-
- Microsoft Entra tenant active with verified domain ownership.
- Global Administrator to accept reseller relationship and permissions.
- Acceptance of Microsoft Customer Agreement and data protection terms.
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- According to SLA
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Essential (included): License provisioning, billing queries, and incident triage during business hours, with escalation to Microsoft as needed.
Enhanced: Adds 8×5 technical helpdesk for Microsoft 365, Azure, and Dynamics 365, standard change requests, and monthly cost/usage insights via our CSP dashboard.
Advanced: 24×7 critical‑incident response, accelerated escalations, a named Service Delivery Manager, quarterly service reviews, and proactive cost and health checks.
Premium: All Advanced features plus advisory/TAM‑style guidance (roadmap, governance, architecture), FastTrack orchestration, adoption and security baselining, and custom reporting.
How much:
Essential is included as part of our CSP reseller responsibility.
Enhanced/Advanced/Premium are priced per tenant, per month, with optional per‑incident or per‑user components.
Discounts are available for multi‑tenant portfolios and 12–36‑month terms.
UK Public Sector: Final rates and maximums are defined in the G‑Cloud Pricing Document for this Service; call‑off contracts can add bespoke SLAs where required.
All tiers include SLA‑backed response targets, clear escalation paths, and access to our proximity centres for round‑the‑clock coverage when selected. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Getting started
Kick‑off & setup – We run a short discovery to confirm scope, roles, SLAs, security/access, and escalation paths. We provision your tenant in our CSP, enable billing, and grant you portal access to dashboards and support.
Onboarding & runbooks – We tailor incident, request, and change runbooks; define comms templates for major incidents; and agree governance (CAB cadence, RACI, reporting).
Enablement & training –
Online training: live, instructor‑led sessions plus recorded modules for admins, service desk, and workload owners.
Onsite training (optional): focussed workshops for executives, IT ops, or business teams.
User documentation: customer‑branded quick‑start guides, admin handbooks, and KB articles in your chosen format; updates included with service changes.
Go‑live readiness – Access tests, handover checklist, and role‑based rehearsals for P1/P2 scenarios.
Adoption & improvement – Monthly service reviews with action logs, cost/usage insights, and a continuous‑improvement backlog. Where eligible, we also orchestrate Microsoft FastTrack and partner funding to accelerate adoption.
What you get on day one: named Service Delivery Manager, support contacts and SLAs, portal credentials, reporting pack, and your customised escalation matrix. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
End‑of‑contract data extraction
Ownership & portability. You retain ownership of all service data. Our exit plan guarantees portability and handover to your chosen destination without vendor lock‑in.
Offboarding plan. We confirm scope and recipients, schedule exports, transfer runbooks and credentials, remove our access, and provide evidence of data return or destruction.
Microsoft 365. Exports via native tools/APIs (Exchange, SharePoint/OneDrive, Teams, Purview eDiscovery/Content Search). We can assist with tenant‑to‑tenant moves and post‑migration validation.
Dynamics 365 (Dataverse). Structured exports (CSV/API/backup restore) with schema and relationship maps to preserve data integrity for your target system.
Azure. Subscriptions/resources are returned or transferred per the exit plan; we deliver final cost/usage exports and tagging to support reconciliation.
Security & compliance. We follow an agreed “return or destroy” procedure, document retention windows, and—on request—issue a certificate of destruction. International transfer pathways and roles are defined in the contract annexes.
Effort & pricing. Standard exports are included with contract close‑out. Complex tenant moves, bespoke formats, or accelerated timelines are provided as professional services.
A named exit lead coordinates all activities, keeps stakeholders informed, and ensures continuity until you confirm successful ingestion in the destination environment. - End-of-contract process
-
End‑of‑contract process
Notice & planning. We acknowledge termination, confirm notice period, freeze non‑critical changes, and agree an exit plan with roles, dates, and risks.
Handover & access. We transfer runbooks, configuration baselines, credentials, and support history; remove delegated admin, rotate secrets, and de‑scope our accounts.
Data return. We export tenant data using native tools/APIs, package schema/metadata where applicable, and provide integrity checksums.
Service transition. We brief your replacement supplier, walk through escalation and monitoring, and run agreed cutover rehearsals.
Closure. Final reporting, billing reconciliation, license hand‑back (or transfer), CPOR/PAL updates, and—if selected—certificate of data destruction.
Included in the contract price
Exit planning session and checklist
Standard data exports (native formats)
Knowledge transfer of service docs/runbooks
Access removal and security sign‑off
Final service report and billing reconciliation
Additional cost (on request)
Complex tenant‑to‑tenant migrations or cross‑cloud moves
Data transformation, bespoke formats, or extensive eDiscovery packaging
Dual‑run/extended overlap support beyond contract end
Onsite transition support and accelerated timelines
Third‑party migration tooling/licenses and long‑term archival storage
Post‑exit advisory (e.g., architecture hardening, optimization)
All activities follow your DPA/contract annexes for data return or destruction and are completed upon your written acceptance. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- Yes
- Description of customisation
-
What can be customised
Coverage & SLAs: hours (8×5/24×7), response/restore targets, severity definitions, change windows.
Scope: Microsoft clouds (M365, Azure, D365), included workloads, standard vs. bespoke changes, automation/runbooks.
Engagement model: named SDM/TAM, escalation paths, CAB cadence, incident/major‑incident comms.
Security & compliance: access model, approvals, audit artefacts, data residency.
Reporting & governance: KPI set, cost/usage dashboards, executive/technical reviews.
Commercials: per‑tenant/per‑user/per‑incident blends, term and volume options.
How users customise
Service design workshop & onboarding questionnaire to select tiers and add‑ons.
Service Catalogue pick‑and‑mix (e.g., 24×7 for critical workloads, 8×5 elsewhere).
Runbook tailoring for incidents, requests, and change workflows.
Governance setup (CAB cadence, RACI, escalation matrix).
Continuous improvement via monthly/quarterly service reviews and change requests.
Self‑service portal to adjust contacts, approvals, and reporting packs.
Who can customise
Customer: Contract/Commercial Lead, Service Owner, Technical Lead/Architect, Security/Compliance, and Finance.
Inetum: Service Delivery Manager, TAM/Architect, Support Manager, and Billing Ops to reflect changes in SLAs, scope, and pricing.
Scaling
- Independence of resources
-
Data/identity isolation: Each customer operates in their own Microsoft tenant; least‑privileged, JIT/PAM access; no cross‑tenant data paths.
Capacity isolation: Per‑subscription quotas, autoscale policies, and landing‑zone guardrails prevent “noisy‑neighbour” contention; rate‑limits on automation/batch jobs.
Support isolation: Dedicated SDM, per‑customer queues with concurrency caps, and surge cells/overflow teams to guarantee SLAs.
Change isolation: CAB‑approved maintenance windows and freeze periods avoid cross‑customer impact.
Monitoring & SLOs: Per‑customer dashboards, alert thresholds, and error‑budget tracking; deviations trigger a scale‑up/redistribute plan and corrective actions captured in the service review.
Provide your feedback on BizChat
Analytics
- Service usage metrics
- Yes
- Metrics types
-
SLA attainment: response/restore by severity, MTTA/MTTR
Incident quality: first‑contact resolution, reopen rate, major‑incident comms time, problem backlog age
Change & release: success rate, change lead time, failed‑change rollback time, CAB adherence
Availability & performance: uptime SLOs, capacity trends
Security & compliance: patch/vulnerability remediation SLA, privileged‑access reviews
Cost & adoption: Azure/M365/D365 cost variance vs budget, optimization savings, active users/feature adoption
Experience: CSAT/XLA (task completion time, sentiment) - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Microsoft
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
-
Physical access control, complying with CSA CCM v4.0
Hosted on hyperscale datacentres certified against CSA STAR/CCM v4.0, with 24/7 guards, CCTV, biometrics, mantraps, and strict visitor controls.
Physical access control, complying with SSAE‑18 / ISAE 3402
Independent SOC 1/2/3 audits, documented chain‑of‑custody
Physical access control, complying with another standard
ISO/IEC 27001, 27017, 27018, and ISO 22301 for business continuity.
Encryption of all physical media
SQL TDE; disk encryption (BitLocker/DM‑Crypt); optional customer‑managed keys via Key Vault/Managed HSM and double‑encryption where supported.
Scale, obfuscating techniques, or data storage sharding
Per‑tenant logical isolation, key separation, data sharding/partitioning, immutable/WORM storage options, soft‑delete/versioning, and pseudonymisation/tokenisation. - Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Data export approach
We prioritise native Microsoft export paths for fidelity and auditability.
Microsoft 365: Exchange (PST/MAPI), SharePoint/OneDrive/Teams via Export/Graph/CSOM or Purview eDiscovery; optional tenant‑to‑tenant tooling.
Dynamics 365/Dataverse: Structured exports (CSV/API/backup) with schema and lookup maps to preserve relationships.
Azure: Resource/Subscription transfer or export of blobs, databases, and logs, plus final cost/usage reports.
Packaging: Encrypted archives with checksums and a content manifest.
Governance: Planned change freeze, role/access removal, customer acceptance testing, and—on request—certificate of destruction. - Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
- Other
- Other protection between networks
-
Private network or public sector network
Supported via private connectivity (Azure ExpressRoute private peering and Private Link). PSN not required by default; integration available if mandated.
TLS (Version 1.2 or above)
TLS 1.2+ enforced (TLS 1.3 preferred) with modern cipher suites and perfect forward secrecy; certificate lifecycle managed in Azure Key Vault.
IPsec or TLS VPN gateway
Supported: site‑to‑site IPsec/IKEv2 or TLS VPN to buyer gateways; can be combined with ExpressRoute for hybrid scenarios.
Legacy SSL and TLS (under 1.2)
Not permitted; disabled by policy and continuously monitored. - Data protection within supplier network
- Other
- Other protection within supplier network
-
Protection within our network (Data‑in‑transit)
TLS (Version 1.2 or above): Enforced for all east‑west traffic (TLS 1.3 preferred) with PFS ciphers; certificates issued and rotated via Azure Key Vault.
IPsec or TLS VPN gateway: IPsec/IKEv2 or TLS tunnels for inter‑site, admin, and management planes.
Legacy SSL and TLS (under 1.2): Not permitted; blocked by policy and monitored.
Other: Mutual TLS at API gateways/service mesh; Private Link/private endpoints to avoid public ingress; strict network segmentation (VNETs/subnets/NSGs, micro‑segmentation), zero‑trust access with JIT/PAM; keys optionally in Managed HSM; continuous telemetry and alerting.
Availability and resilience
- Guaranteed availability
-
Availability target – Defined per service in your Service Delivery Plan and reported monthly. Our reference target for managed OS/services is 99.6%, with higher targets available when the architecture is designed for HA.
Measurement & exclusions – Availability is measured over the agreed period and excludes planned maintenance and events outside our control (e.g., third‑party WAN failures, force majeure).
Service reporting – Monthly service reports show achieved availability and SLA performance against targets, plus actions for any deviations.
Remedies (service credits) – If SLA commitments are missed, service credits apply per incident exceeding contractual resolution time, typically 1/60th of the annual service cost per incident, aggregated and capped at 20% of the annual service cost. Credits are refunded within 30 days of invoice or offset against future payments.
Chronic issues – Hitting 5/60ths across two consecutive quarters triggers a remedial plan; exceeding 7/60ths in any 12‑month period (or failure of the remedial plan) is treated as material breach. - Approach to resilience
-
Approach to resilience
Resilient architecture: Stateless services on managed PaaS with auto‑healing; stateful stores deployed with zone‑redundant options. Patterns include circuit‑breakers, retries with back‑off, idempotent operations, and queue‑based buffering to absorb spikes.
Datacentre resilience: Hosted in hyperscale regions using physically separate Availability Zones (independent power/cooling/network). Optional multi‑region DR with warm or hot standby and cross‑region backups. Private connectivity and private endpoints reduce exposure.
Backups & recovery: Automated, encrypted backups with immutable/WORM retention where supported, point‑in‑time restore, and replicated copies. RPO/RTO are defined by service tier and validated in recovery drills.
Operations & change: 24×7 monitoring, SLO/error‑budget tracking, alerting, and runbooks for failover/failback. Controlled change windows, blue/green or canary releases with rapid rollback.
Security hardening: DDoS protection, WAF, network segmentation, least‑privileged/JIT admin, keys in dedicated key management (incl. HSM options).
Testing & learning: Regular DR exercises, chaos/game‑day testing, and post‑incident root‑cause analysis with remediation tracking.
Transparency: Monthly resilience reporting and service reviews. Detailed datacentre topology and audit attestations are available on request. - Outage reporting
-
Outage reporting
Public status dashboard: Real‑time availability and incident timelines per service and region, plus planned maintenance windows. Historical uptime and post‑incident notes are retained.
API & feeds: JSON status API and RSS/Atom feeds for automated monitoring and vendor aggregation; includes current status, components affected, and next update ETA.
Email/SMS alerts: Opt‑in notifications for incidents, maintenance, and resolution. Distribution lists can be scoped by service, region, and severity.
Webhook/ChatOps: Optional webhooks to post updates into Microsoft Teams/Slack and ITSM tools to open/resolve incidents automatically.
In‑product banners: Contextual notices displayed to signed‑in admins when an issue impacts their tenant/workload.
Cadence & transparency:
T+15 min: issue acknowledged with impact summary and first ETA.
Every 30–60 min: status updates or sooner on material change.
On resolve: root cause outline and mitigation.
Within 5 business days (major): detailed post‑incident review and corrective actions.
Subscription management: Admins manage alert preferences (channel, severity, services/regions) and can delegate to multiple recipients.
Accessibility: Dashboard and feeds are publicly accessible; API keys provided for rate‑limited integrations upon request.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access restrictions for admin interfaces & support
Admin access uses Microsoft Entra ID SSO with MFA and conditional access (device compliance, geo/IP, risk). RBAC least‑privilege; JIT/PAM elevation with approvals; break‑glass accounts sealed and monitored. Admin planes are reachable only via private networks/VPN, with IP allow‑lists, mTLS/API keys rotated in Key Vault, and session timeouts. All actions are audited to SIEM with anomaly alerting.
Support channels: only named, verified requesters; tickets tied to assets and entitlements; encrypted channels (Teams/portal) only—no credentials by email. Screen‑sharing via approved tools with consent; data masking on consoles; session recording; two‑person control for high‑risk operations. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Information security policies and processes
Policy framework: We operate a Group Information Security Policy (ISSP), supported by an Information Security Policy, Data Protection Policy, and a Third‑Party Risk Management process. Policies cover access control, cryptography, secure development, vulnerability/patch management, logging/monitoring, incident response, asset management, data retention/destruction, and acceptable use. They are aligned to internationally recognised controls (e.g., ISO/IEC 27001 family, CSA CCM) and reviewed at least annually.
Governance & reporting: The Group CISO sets strategy and owns the ISSP via the Corporate Security function. Local Security Leads in each business unit ensure implementation. Privacy is overseen by the Group DPO with local DPOs. Security incidents are triaged by operations, escalated to Security Management, and—if personal data is affected—jointly handled with the DPO; major incidents are reported to executive leadership and impacted clients.
Assurance & enforcement: Mandatory onboarding/annual training, phishing simulations, and role‑based modules. Technical guardrails (MFA, PAM/JIT, least privilege, network segmentation, SIEM use cases, DLP) enforce policies. We run risk assessments and DPIAs, internal audits, corrective action tracking, and supplier due diligence. Exceptions require documented, time‑bound approvals. Breaches of policy trigger disciplinary procedures and remediation. External attestations can be shared under NDA on request. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Configuration tracking: All components are registered as Configuration Items (CIs) in the CMDB, with owner, environment, version, dependencies, and security classification. We maintain baselines, automate discovery where possible, and record full CI lifecycle (create → modify → retire) with audit trails.
Change process: Changes are raised with purpose, implementation plan, backout/rollback, test evidence, and monitoring plan. We classify standard/normal/emergency, assess risk and security impact (data sensitivity, identity/network touchpoints, keys/certs, exposure), and check conflicts against the change calendar. Approval flows run via CAB/ECAB. Pre‑prod validation is required; production releases use controlled windows. Every change undergoes post‑implementation review and metrics tracking. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Assessing threats: Continuous discovery and authenticated scanning across cloud/endpoints; container/SBOM/SCA in CI/CD; risk scored with CVSS + exploitability (known‑exploited), asset criticality, internet exposure, and lateral‑movement factors. Findings are triaged in our ticketing system with owner and due date.
Patching SLAs: Emergency/actively exploited: out‑of‑band, change‑controlled, target <24–72h. High: ≤7 days. Medium: ≤30 days. Low: ≤90 days. Compensating controls (WAF, EDR hardening) applied if a patch isn’t immediately possible; all changes have rollback plans and PIRs.
Threat sources: Microsoft MSRC, CISA KEV, national CERT/NCSC advisories, vendor PSIRTs, ISAC feeds/MISP, and managed threat‑intel services. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Identify potential compromises: 24×7 SOC using SIEM (Microsoft Sentinel), XDR/EDR telemetry, UEBA, cloud‑posture signals, and curated threat intel. Correlations and anomaly baselines flag suspicious behavior; high‑fidelity alerts auto‑enrich with IOCs, asset criticality, and blast‑radius graphs.
Respond to potential compromises: Triage → contain (isolate endpoints, block IOCs, revoke tokens, disable accounts) → eradicate (patch/remove) → recover. SOAR playbooks automate first actions; DFIR engaged as needed. Post‑incident review captures root cause and hardening actions.
Response times: P1 acknowledge ≤15 minutes, investigation start ≤30 minutes, containment target ≤4 hours. P2 acknowledge ≤1 hour, containment ≤8 hours. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Pre‑defined processes: ITIL‑aligned workflows and runbooks for common events (account compromise, phishing/malware, service degradation, data loss, DDoS). Major Incident (P1) playbook includes 24×7 on‑call, bridge/war‑room, stakeholder comms, and rapid workaround/rollback paths.
How users report: Service Desk portal (preferred), email to the support alias, or phone hotline. Monitoring/XDR automatically opens incidents with enrichment; Virtual Agent can triage and deflect where suitable.
How we provide reports: Initial notification on registration, regular status updates until resolution, and a closure note. For P1s, a Post‑Incident Review (root cause, timeline, impact, corrective actions) is issued within five business days and stored in the portal. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 6%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 8%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Schellman Compliance, LLC
- ISO/IEC 27001 accreditation date
- Tuesday 7 October 2025
- What the ISO/IEC 27001 doesn’t cover
- Excluded from the scope are all operations of third-party data centers, Microsoft Azure, AWS, and GCP.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Certi-Trust Eastern & Southern Africa
- ISO 9001 accreditation date
- Wednesday 15 January 2025
- What the ISO 9001 doesn’t cover
- Excluded from the scope are all operations of third-party data centres for Azure and Amazon AWS.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Friday 5 December 2025
- CSA STAR certification level
- Level 2: CSA STAR Attestation
- What the CSA STAR doesn’t cover
- The scope of the CSA STAR certification is aligned to the scope of the ISO/IEC 27001:2022 certification is limited to the information security management system (ISMS) supporting ServiceNow as a provider of cloud-based solutions that define, structure, manage, and automate services across the global enterprise.
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 511e8310-880f-4412-b76c-45c03544d185
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 60bc774c-f0d5-4ffd-b64a-760f02f80e87
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-