Cisco Secure Connect - Secure Access Service Edge (SASE)
Managed cloud-delivered Security Service Edge platform, uniting connectivity and security into a unified SASE approach. A service configured and managed by certified experts, it protects hybrid workforces with Secure Web Gateway, Cloud Access Security Broker and Zero Trust Access, enabling organisations to modernise their security and empower their hybrid workforce.
Features
- Cloud-delivered secure access providing consistent protection for users and applications
- Integrated SDWAN connectivity enabling optimised routing across branch and cloud.
- Realtime security analytics detecting threats across user, device and network
- Zero Trust Access controls enforcing identity, posture and least-privilege principles
- Secure Web Gateway filtering malicious traffic with advanced inspection capabilities
- Cloud Firewall delivering unified policy enforcement across distributed environments
- Encrypted user traffic tunnelling through Cisco Secure Client endpoint agent.
- Integrated CASB protecting cloud applications with visibility, DLP and controls
- Unified dashboard offering centralised management of networking and security services.
- Unified remote access with both modern ZTNA and traditional RAVPN.
Benefits
- Seamless secure access for users working from any global location
- Simplified network operations through unified cloud-managed security and connectivity
- Improved user experience through optimised application paths and reduced latency
- Strengthened security posture with identity-based policies, reducing network attack surface.
- Reduce risk by inspecting all traffic through cloud-based security layers
- Minimise operational overhead through automated updates and centralised configuration
- Enhanced visibility with real-time insights into user behaviour and threats
- Support remote workforce productivity with reliable, always-on secure connectivity.
- Streamline compliance using enforced policies aligned to organisational requirements.
- Gain visibility of cloud SaaS usage across workforce
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 9 2 2 3 2 0 0 9 4 1 0 9 1 9
Contact
TALKTALK BUSINESS DIRECT LIMITED
Andrew Stokes
Telephone: 07976911843
Email: andrew.stokes@talktalk.business
About your service
- Service categories
-
Systems Infrastructure Software
Network
Network infrastructure software
- Network application delivery
- Software-defined networking (SDN)
Network management
- Network performance management (NPM)
- Network operations management (NOM)
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- CISCO Meraki Software Defined Wide Area Network (SD-WAN)
- Cloud deployment model
- Public cloud
- Service constraints
- The solution requires supported Cisco SD-WAN or Meraki hardware for site connectivity, and uses Cisco Secure Client for endpoint access.
- System requirements
-
- Supported Cisco SD-WAN or Meraki appliances required for branch connectivity
- Cisco Secure Client software required on endpoints for secure access
- Identity provider integration requires SAML or OpenID Connect support (ZTNA).
- DNS /traffic steering must route through Cisco services for protection
User support
- Email or online ticketing support
- Yes
- Support response times
-
Service support is provided 24/7/365
Priority 1 (15 minutes): A complete, unplanned outage or interruption to a business-critical IT service, without an available workaround solution, impacting the entire user base or a significant subset of users.
Priority 2 (15 minutes): A degradation to the performance and availability of a business-critical IT service for the entire user base or a significant subset of users.
Priority 3 (1 hour): A failure of or disruption to service for a single user. All other business users would not be impacted .
Priority 4 (24 hours): A request for a new service/function. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
TalkTalk Business (TTB) operates a 24x7x365 Service Management Centre, which identifies, troubleshoots and restores standard operational functionality of the service.
Incident prioritisation
High – Priority 1: Primary business function of customer is stopped with no redundancy or backup, immediate financial impact.
Medium – Priority 2: Primary business function of customer is severely degraded or supported by backup or redundant system, probably significant financial impact.
Low: Non-critical business function is stopped or severely degraded, possible financial impact.
Priority level updates (Business Hours)
Priority 1: 15 minute response.
Priority 2: 15 minute response.
Priority 3: 1 hour response..
Priority 4: 24 hour response.
TTB offers free support as standard as per targets above. In the event the customer requires bespoke service levels, TTB can provide enhanced support where additional costs are dependent upon requirements.
All customers will be allocated a named Account Manager who will have a team of dedicated technical specialists that will support on any customer requirements. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
TalkTalk Business, working with the customer, will define a plan for establishing Managed Service Components. This will be delivered as part of structured planning and execution phases. There will be a single point of contact (SPOC) for the customer during this period. They will:
· Compile and complete the Transition Requirement
· Document the in-scope devices necessary to transition
· Assess changes required to the customer’s platform, network, and processes to activate the Managed Components
· Define the required inventory information and topology requirements necessary to activate the Managed Components
· Manage the procurement of hardware, software and licensing.
· Manage the deployment of the managed service and the transition to in-life management.
Offboarding processes will be put in place for both standard contract cessation and early termination by the customer. Offboarding will be managed and coordinated by the SPOC to ensure an efficient and thorough cease of service. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
At the end of a customer’s contract, TTB has a cease process in place. All cease requests must be received by email from the customer with a completed Cease Request Form, available upon request, this will then create a case within Salesforce.
The Customer Service Team will query the address on the Cease Form to confirm that it matches the address held on our records.
Should the customer require access to data upon exit, a full inventory in the form of an ASR report will be provided to the customer, which will contain an up-to-date asset list, including site addresses, post codes, bandwidth, router types, software versions and monthly costs via the customer’s Account Manager. - End-of-contract process
-
At the end of a contract, TTB has a cease process. After your minimum term, you can end the contract or any connection forming part of a contract by giving 40 days’ notice. Any equipment remains the property of TTB and, upon termination, should be returned. All cease requests must be received by customer email with a completed Cease Request Form, this will then create a case within Salesforce.
The Customer Service Team will query the address on the Cease Form to confirm that it matches the recorded address. Once confirmed the cease process will begin.
Provided the minimum contract term has expired and payment is up to date, no further charges or additional costs will be payable.
As standard, Secure Connect Essentials comes with:
1. Zero‑Trust / Remote Access
2. Core Security (SSE components included)
3. Networking & Connectivity
This package is designed to provide basic SASE coverage, including secure Internet access, remote access and foundational threat protection.
Cisco offers higher‑tier packages such as Advantage and Complete, which include everything in Essentials plus additional capabilities, e.g.:
1. Broader and deeper Zero‑Trust Network Access (ZTNA)
2. Enhanced CASB / SWG / Threat Defense
3. Cisco Secure Connect Complete package features - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
The onboarding and offboarding documentation is provided as a PDF that is structured for readability and ease of navigation. Headings are used consistently to support screen reader navigation, and text is selectable rather than image-based to allow assistive technologies to interpret the content.
The document uses clear language, logical ordering of information, and sufficient contrast between text and background to support readability. Where applicable, hyperlinks are descriptive rather than relying on visual cues alone. The PDF can be zoomed without loss of content or functionality, supporting users with visual impairments.
Content is designed to be accessible using keyboard navigation and common screen reader software. If users require the documentation in an alternative format or need additional support, this can be provided upon request to accommodate individual accessibility needs.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Cisco Secure Connect is designed to work on mobile devices through the Cisco Secure Client app, which supports iOS and Android for secure access, ZTNA, and cloud-delivered security enforcement. Both mobile and desktop versions have parity of capability.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
Cisco Secure Connect provides a unified, cloud-based management interface designed for simplicity and visibility. Administrators access the service through a web-based dashboard that consolidates networking, security, user access, and policy management into a single console. The interface presents intuitive workflows for onboarding sites, configuring secure access, setting security policies, and monitoring real-time activity.
Visual topology maps, traffic analytics, alerts, and health indicators help administrators quickly assess performance and security posture. Role-based access controls allow delegated management across teams. End users interact through the Cisco Secure Client app, which provides seamless secure connectivity without requiring manual configuration. - Accessibility standards
- None or don’t know
- Description of accessibility
-
Cisco Secure Connect provides a cloud-based interface that supports standard web browser accessibility features, allowing users with visual, motor, or cognitive impairments to rely on built-in operating system tools such as screen magnifiers, high-contrast modes, dictation, and keyboard navigation. The interface uses clear visual layouts, consistent navigation patterns, and simplified workflows to support ease of use.
End users can access the service through the Cisco Secure Client app, which requires minimal interaction and supports native mobile accessibility features. However, the service does not claim formal accessibility compliance, and specialised accommodations for screen readers or motor-impaired users are not explicitly documented. - Accessibility testing
-
Basic testing of the web interface has been conducted internally and, as part of future web interface testing, we plan to roll out full user testing across all areas as part of the product roadmap.
The full list of accessibility standards Cisco Meraki dashboard is compliant with:
https://www.cisco.com/c/dam/en_us/about/responsibility/accessibility/downloads/vpats/VPAT_Cisco_Meraki_Dashboard_Oct2024.pdf
https://www.cisco.com/c/dam/en_us/about/responsibility/accessibility/downloads/vpats/VPAT_Cisco_Secure_Access_October2023.pdf - API
- Yes
- What users can and can't do using the API
-
Cisco Secure Connect provides API access through the underlying platforms that deliver the service, including Cisco Meraki Dashboard APIs, Cisco Umbrella APIs, and Cisco SD-WAN/vManage APIs. These APIs allow users to automate provisioning, configure security policies, manage networks, and integrate Secure Connect functions into existing IT workflows. Users can set up core components such as site onboarding, user groups, DNS and web security policies, and SD-WAN routing rules through API calls rather than using the web interface. Authentication is typically performed using API keys or token-based access depending on the platform.
Users can also make ongoing changes via the APIs, such as updating firewall rules, modifying secure access policies, retrieving analytics data, adjusting SD-WAN performance settings, or managing device inventories. The APIs support integration with SIEM, SOAR, and configuration management tools to streamline operations and automate incident response.
However, the Secure Connect service itself does not expose a single unified API. More information can be found at: https://developer.cisco.com/sase/. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Cisco Secure Connect offers extensive customisation options that allow organisations to tailor networking, security, and access policies to their specific operational and compliance requirements. Customising network connectivity by defining SD-WAN routing policies, traffic prioritisation, and cloud on-ramps. Security controls can be adapted through customised Secure Web Gateway rules, DNS filtering policies, cloud-firewall configurations, CASB controls, and data-loss-prevention settings. Zero Trust access can be personalised by defining identity-based access rules, device-posture requirements, and application-specific policies.
The TTB service allows the customer to customise and configure their service via a catalogue of Standard & Normal service changes that may be requested through a documented change control process. The catalogue is provided to the customer at the start of the service as part of the Statement of Works (SoW) document. Change control tickets are raised via phone or email communication.
Changes are managed through a system of Flex Tokens, which are consumed for each change. The number of Flex Tokens will be based upon your specific environment and service level.
Scaling
- Independence of resources
-
Cisco Secure Connect prevents one customer’s usage from impacting another’s through a scalable, cloud-based architecture that separates each organisation’s traffic and policies. Customer environments are logically isolated, ensuring privacy and performance consistency. The service automatically balances demand across Cisco’s global infrastructure and adds capacity as needed to handle increased traffic. Continuous monitoring ensures performance levels remain stable even during peak usage.
Please see the Meraki Cloud scalability guidelines below: https://documentation.meraki.com/Platform_Management/Dashboard_Administration/Design_and_Configure/Architectures_and_Best_Practices/Cisco_Meraki_Best_Practice_Design/Building_a_Scalable_Meraki_Solution
Today Meraki cloud has 1 million+ customers, with 4 million+ customer networks, with over 190 million+ devices being managed in this cloud network globally.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Cisco Secure Connect provides comprehensive service usage metrics through its central management dashboard and integrated analytics platforms. Metrics include user activity, application usage, bandwidth consumption, traffic volumes, and session statistics across branches and remote users. Network performance metrics such as latency, jitter, packet loss, and link availability are continuously monitored. Security-related metrics include blocked threats, malicious domains, policy violations, DNS requests, and cloud application access events. Administrators can view real-time dashboards and historical reports to track trends, detect anomalies, and assess service effectiveness. These metrics support capacity planning, performance optimisation, security monitoring, compliance reporting, and proactive operational decision-making.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Cisco Secure Connect
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
The Meraki dashboard Application Programming Interface (API) is an interface for software to interact directly with the Meraki cloud platform and Meraki-managed devices. The API contains a set of tools known as "endpoints" for building software and applications that communicate with the Meraki dashboard. Use cases include provisioning, bulk configuration changes, monitoring, and role-based access controls. The dashboard API is a modern, RESTful API using HTTPS requests to a URL and JSON as a human-readable format. The dashboard API is an open-ended tool that can be used for many purposes.
https://documentation.meraki.com/Platform_Management/Workflows/Workflows/Import_and_Export_a_Workflow
https://documentation.meraki.com/Platform_Management/Dashboard_Administration/Operate_and_Maintain/How-Tos/Cisco_Meraki_Dashboard_API - Data export formats
- Other
- Other data export formats
- JSON
- Data import formats
- Other
- Other data import formats
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- Cisco Secure Connect protects data in transit using strong encryption standards. Site-to-cloud and site-to-site communications are secured using IPsec VPN tunnels with modern cryptographic algorithms, ensuring confidentiality and integrity of traffic between the buyer’s network and Cisco’s cloud service edges. Remote user connections via Cisco Secure Client are protected using TLS 1.2 or higher with certificate-based authentication and secure cipher suites. Legacy SSL and deprecated encryption protocols are not supported. This ensures data is protected from interception, tampering, or unauthorised access while transiting public or private networks.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Cisco Secure Connect is delivered through Cisco’s globally distributed cloud infrastructure designed for high availability and resilience. The service leverages multiple geographically dispersed data centres, redundant service edges, and automated failover mechanisms to minimise downtime and maintain continuous service delivery. Data Centres are located globally which offer a 99.999% SLA. This SLA covers availability of core connectivity, security enforcement, and management access functions. Please see https://meraki.cisco.com/en-uk/platform/.
If Cisco fails to meet the agreed availability threshold, customers are entitled to service credits in accordance with the Cisco Secure Connect Service Level Agreement. Service credits are calculated as a percentage of the monthly subscription fee and applied to future billing rather than direct financial reimbursement. - Approach to resilience
-
Cisco Secure Connect is designed with resilience as a core architectural principle to ensure continuous service availability and protection against failures or disruptions. The service is delivered through Cisco’s globally distributed network of secure cloud data centres and service edges, which are deployed across multiple geographic regions. These facilities operate in an active-active configuration, allowing automatic traffic failover if a site becomes unavailable. Redundant infrastructure components, including compute, networking, power, and cooling systems, ensure uninterrupted operation even during hardware failures or maintenance events.
Traffic is intelligently load-balanced across service nodes, enabling dynamic capacity scaling and rapid recovery from unexpected demand spikes or outages. Continuous health monitoring and self-healing mechanisms detect issues in real time and reroute traffic to healthy nodes without manual intervention. Disaster recovery procedures include real-time configuration replication and data synchronisation across regions to minimise data loss and ensure rapid restoration.
Physical and logical security controls protect critical assets, and all data centres meet recognised industry standards for resilience and asset protection.
Cisco Secure Connect is a SaaS model and falls within the Shared Responsibility model of Cloud Compute, and is covered by SLA. - Outage reporting
-
Customers will be updated via an email alert to a Main Customer Contact indicating which services are impacted. The Main Customer Contact must forward the information to their individual sites. The Main Customer Contact will be determined during onboarding.
The customer can also find information on outages at https://status.umbrella.cisco.com/#/
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- Cisco Meraki user authentication involves various methods for network access, including Meraki Cloud Auth (built-in users), 802.1X with RADIUS/Active Directory, SAML/SSO (for dashboard or network access via IdPs like Azure AD/Google), and Splash Pages (for guest/captive portals), all configured via the Meraki Dashboard to secure Wi-Fi, VPN, and Switch ports. The core idea is validating user credentials against a chosen backend (Meraki cloud, external directory, or IdP) before granting network access, often using email/username and password, with options for MFA such as Cisco DUO.
- Access restrictions in management interfaces and support channels
- Full Role Based Access Control. Cisco Secure Connect restricts access to management interfaces and support channels through role-based access control, strong authentication, and least-privilege design principles. Administrative access to the management dashboard is limited to authorised users and protected by identity federation, multi-factor authentication, and certificate-based controls where configured. Roles and permissions define what actions individual users can perform, such as viewing metrics, modifying policies, or managing devices.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
- Cisco Meraki provides role-based access control (RBAC) for administrative users, allowing granular permissions per organisation and network. Administrative access is logged and audited via detailed event logs in the Meraki Dashboard. IP address whitelisting can be enforced to restrict management access to trusted locations. API access is authenticated using API keys with configurable scopes and logging. All management traffic is encrypted using HTTPS/TLS to Cisco’s cloud-hosted Dashboard.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials
- Information security policies and processes
-
TTB has a Master Security Policy in place and operates an Information Security Management System via its Security Operations Centre (SOC) for the reporting of all potential security breaches. The system is based on industry good practice (NIST CSF, PCI DSS) and is externally certified to ISO 27001. This covers a range of policies and procedures to ensure the confidentiality, integrity and availability of information, including a Master Security Policy, Privacy Policy and GDPR Policy.
The reporting of any security incidents is done directly to the Security team security@talktalkplc.com or via the internal Secureville web page. The escalation of incidents will be to the Head of Security for review and resolution. All colleagues must follow the data handling requirements in this policy and share the responsibility to protect data. It is mandatory for all employees new and current to do security training at least once a year. All colleagues have set timescales for training completion and this is reported against to ensure compliance. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Configuration Changes are assessed, logged and components tracked through our Service Management tool, which is managed by the Network Engineering team from the point at which we raise the initial change request until that change is closed off.
Quality comes as standard throughout the change process, with everyone involved having the requisite training. Managers of teams carrying out changes will be accountable for the quality of the work undertaken. There is zero tolerance for unauthorised changes.
Security impact will be assessed through a risk assessment and structured model to ensure all risks are captured and clearly identified. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- The Network Security Team conducts security scanning of all our infrastructure on a bi-weekly basis. We also conduct weekly threat and vulnerability scanning of all our network assets via InsightVM. Critical/high risk vulnerabilities patches will be applied within 14 days. All other updates are applied as soon as possible using a monthly patching cycle. Security updates will be assessed and prioritised based on threat level, likelihood of compromise, consequences of compromise, environmental characteristics and regulatory or accreditation-based requirements. We receive information about potential threats from InsightVM from weekly scanning and we use Altiris for Patch Management.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
TTB operates a security incident management program for the alerting of any potential compromises and deploys endpoint protection technology. All incidents are logged on the action plan tracker and updated with notes/associated actions to mitigate risk through to restoration.
Users can report Priority level 1/level 2 incidents by telephone and a response will be given within 1 hour. Incidents can be reported by email/web portal.
Incident reports will be provided upon request. For network incidents, these reports are distributed to impacted customers via email. Reason for Outage reports for priority 1 faults are provided by email within 10 working days. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
We have a pre-defined process for common events and fault-related reporting through our 24/7 Technical Support Centre (TSC).
Users can report Priority level 1 and level 2 incidents by telephone (08454566541/08453103444) and by email/web portal.
Incidents, when resolved, will be notified to the customer as part of the logged ticket fault. Reports will be provided upon request for network incidents, and these reports distributed to impacted customers via email. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 4%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- ISOQAR
- ISO/IEC 27001 accreditation date
- Tuesday 27 January 2026
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Alcumus ISOQAR
- ISO 9001 accreditation date
- Monday 26 May 2025
- What the ISO 9001 doesn’t cover
-
Exclusions:
8.3 Design and Development of products and services
7.1.5.2 Measurement traceability
Location: Gateshead - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Viking Cloud
- PCI DSS accreditation date
- Monday 3 November 2025
- What the PCI DSS doesn’t cover
- None - The Non PCI is not covered by our certification, all PCI is covered under this certification.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 41015739-ac20-4a9f-a558-edbab61126e0
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-