Skip to main content

Help us improve the Digital Marketplace - send your feedback

TALKTALK BUSINESS DIRECT LIMITED

Cisco Secure Connect - Secure Access Service Edge (SASE)

Managed cloud-delivered Security Service Edge platform, uniting connectivity and security into a unified SASE approach. A service configured and managed by certified experts, it protects hybrid workforces with Secure Web Gateway, Cloud Access Security Broker and Zero Trust Access, enabling organisations to modernise their security and empower their hybrid workforce.

Features

  • Cloud-delivered secure access providing consistent protection for users and applications
  • Integrated SDWAN connectivity enabling optimised routing across branch and cloud.
  • Realtime security analytics detecting threats across user, device and network
  • Zero Trust Access controls enforcing identity, posture and least-privilege principles
  • Secure Web Gateway filtering malicious traffic with advanced inspection capabilities
  • Cloud Firewall delivering unified policy enforcement across distributed environments
  • Encrypted user traffic tunnelling through Cisco Secure Client endpoint agent.
  • Integrated CASB protecting cloud applications with visibility, DLP and controls
  • Unified dashboard offering centralised management of networking and security services.
  • Unified remote access with both modern ZTNA and traditional RAVPN.

Benefits

  • Seamless secure access for users working from any global location
  • Simplified network operations through unified cloud-managed security and connectivity
  • Improved user experience through optimised application paths and reduced latency
  • Strengthened security posture with identity-based policies, reducing network attack surface.
  • Reduce risk by inspecting all traffic through cloud-based security layers
  • Minimise operational overhead through automated updates and centralised configuration
  • Enhanced visibility with real-time insights into user behaviour and threats
  • Support remote workforce productivity with reliable, always-on secure connectivity.
  • Streamline compliance using enforced policies aligned to organisational requirements.
  • Gain visibility of cloud SaaS usage across workforce

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andrew.stokes@talktalk.business. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 9 2 2 3 2 0 0 9 4 1 0 9 1 9

Contact

TALKTALK BUSINESS DIRECT LIMITED Andrew Stokes
Telephone: 07976911843
Email: andrew.stokes@talktalk.business

About your service

Service categories

Systems Infrastructure Software

Network

Network infrastructure software

  • Network application delivery
  • Software-defined networking (SDN)

Network management

  • Network performance management (NPM)
  • Network operations management (NOM)
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
CISCO Meraki Software Defined Wide Area Network (SD-WAN)
Cloud deployment model
Public cloud
Service constraints
The solution requires supported Cisco SD-WAN or Meraki hardware for site connectivity, and uses Cisco Secure Client for endpoint access.
System requirements
  • Supported Cisco SD-WAN or Meraki appliances required for branch connectivity
  • Cisco Secure Client software required on endpoints for secure access
  • Identity provider integration requires SAML or OpenID Connect support (ZTNA).
  • DNS /traffic steering must route through Cisco services for protection

User support

Email or online ticketing support
Yes
Support response times
Service support is provided 24/7/365

Priority 1 (15 minutes): A complete, unplanned outage or interruption to a business-critical IT service, without an available workaround solution, impacting the entire user base or a significant subset of users.

Priority 2 (15 minutes): A degradation to the performance and availability of a business-critical IT service for the entire user base or a significant subset of users.

Priority 3 (1 hour): A failure of or disruption to service for a single user. All other business users would not be impacted .

Priority 4 (24 hours): A request for a new service/function.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
TalkTalk Business (TTB) operates a 24x7x365 Service Management Centre, which identifies, troubleshoots and restores standard operational functionality of the service.

Incident prioritisation

High – Priority 1: Primary business function of customer is stopped with no redundancy or backup, immediate financial impact.
Medium – Priority 2: Primary business function of customer is severely degraded or supported by backup or redundant system, probably significant financial impact.
Low: Non-critical business function is stopped or severely degraded, possible financial impact.

Priority level updates (Business Hours)

Priority 1: 15 minute response.
Priority 2: 15 minute response.
Priority 3: 1 hour response..
Priority 4: 24 hour response.

TTB offers free support as standard as per targets above. In the event the customer requires bespoke service levels, TTB can provide enhanced support where additional costs are dependent upon requirements.

All customers will be allocated a named Account Manager who will have a team of dedicated technical specialists that will support on any customer requirements.
Support available to third parties
No

Onboarding and offboarding

Getting started
TalkTalk Business, working with the customer, will define a plan for establishing Managed Service Components. This will be delivered as part of structured planning and execution phases. There will be a single point of contact (SPOC) for the customer during this period. They will:

· Compile and complete the Transition Requirement
· Document the in-scope devices necessary to transition
· Assess changes required to the customer’s platform, network, and processes to activate the Managed Components
· Define the required inventory information and topology requirements necessary to activate the Managed Components
· Manage the procurement of hardware, software and licensing.
· Manage the deployment of the managed service and the transition to in-life management.

Offboarding processes will be put in place for both standard contract cessation and early termination by the customer. Offboarding will be managed and coordinated by the SPOC to ensure an efficient and thorough cease of service.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
At the end of a customer’s contract, TTB has a cease process in place. All cease requests must be received by email from the customer with a completed Cease Request Form, available upon request, this will then create a case within Salesforce.

The Customer Service Team will query the address on the Cease Form to confirm that it matches the address held on our records.

Should the customer require access to data upon exit, a full inventory in the form of an ASR report will be provided to the customer, which will contain an up-to-date asset list, including site addresses, post codes, bandwidth, router types, software versions and monthly costs via the customer’s Account Manager.
End-of-contract process
At the end of a contract, TTB has a cease process. After your minimum term, you can end the contract or any connection forming part of a contract by giving 40 days’ notice. Any equipment remains the property of TTB and, upon termination, should be returned. All cease requests must be received by customer email with a completed Cease Request Form, this will then create a case within Salesforce.

The Customer Service Team will query the address on the Cease Form to confirm that it matches the recorded address. Once confirmed the cease process will begin.

Provided the minimum contract term has expired and payment is up to date, no further charges or additional costs will be payable.

As standard, Secure Connect Essentials comes with:
1. Zero‑Trust / Remote Access
2. Core Security (SSE components included)
3. Networking & Connectivity

This package is designed to provide basic SASE coverage, including secure Internet access, remote access and foundational threat protection.

Cisco offers higher‑tier packages such as Advantage and Complete, which include everything in Essentials plus additional capabilities, e.g.:
1. Broader and deeper Zero‑Trust Network Access (ZTNA)
2. Enhanced CASB / SWG / Threat Defense
3. Cisco Secure Connect Complete package features
Documentation accessibility standard
None or don’t know
How the documentation is accessible
The onboarding and offboarding documentation is provided as a PDF that is structured for readability and ease of navigation. Headings are used consistently to support screen reader navigation, and text is selectable rather than image-based to allow assistive technologies to interpret the content.

The document uses clear language, logical ordering of information, and sufficient contrast between text and background to support readability. Where applicable, hyperlinks are descriptive rather than relying on visual cues alone. The PDF can be zoomed without loss of content or functionality, supporting users with visual impairments.

Content is designed to be accessible using keyboard navigation and common screen reader software. If users require the documentation in an alternative format or need additional support, this can be provided upon request to accommodate individual accessibility needs.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Cisco Secure Connect is designed to work on mobile devices through the Cisco Secure Client app, which supports iOS and Android for secure access, ZTNA, and cloud-delivered security enforcement. Both mobile and desktop versions have parity of capability.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Cisco Secure Connect provides a unified, cloud-based management interface designed for simplicity and visibility. Administrators access the service through a web-based dashboard that consolidates networking, security, user access, and policy management into a single console. The interface presents intuitive workflows for onboarding sites, configuring secure access, setting security policies, and monitoring real-time activity.

Visual topology maps, traffic analytics, alerts, and health indicators help administrators quickly assess performance and security posture. Role-based access controls allow delegated management across teams. End users interact through the Cisco Secure Client app, which provides seamless secure connectivity without requiring manual configuration.
Accessibility standards
None or don’t know
Description of accessibility
Cisco Secure Connect provides a cloud-based interface that supports standard web browser accessibility features, allowing users with visual, motor, or cognitive impairments to rely on built-in operating system tools such as screen magnifiers, high-contrast modes, dictation, and keyboard navigation. The interface uses clear visual layouts, consistent navigation patterns, and simplified workflows to support ease of use.
End users can access the service through the Cisco Secure Client app, which requires minimal interaction and supports native mobile accessibility features. However, the service does not claim formal accessibility compliance, and specialised accommodations for screen readers or motor-impaired users are not explicitly documented.
Accessibility testing
Basic testing of the web interface has been conducted internally and, as part of future web interface testing, we plan to roll out full user testing across all areas as part of the product roadmap.

The full list of accessibility standards Cisco Meraki dashboard is compliant with:
https://www.cisco.com/c/dam/en_us/about/responsibility/accessibility/downloads/vpats/VPAT_Cisco_Meraki_Dashboard_Oct2024.pdf

https://www.cisco.com/c/dam/en_us/about/responsibility/accessibility/downloads/vpats/VPAT_Cisco_Secure_Access_October2023.pdf
API
Yes
What users can and can't do using the API
Cisco Secure Connect provides API access through the underlying platforms that deliver the service, including Cisco Meraki Dashboard APIs, Cisco Umbrella APIs, and Cisco SD-WAN/vManage APIs. These APIs allow users to automate provisioning, configure security policies, manage networks, and integrate Secure Connect functions into existing IT workflows. Users can set up core components such as site onboarding, user groups, DNS and web security policies, and SD-WAN routing rules through API calls rather than using the web interface. Authentication is typically performed using API keys or token-based access depending on the platform.

Users can also make ongoing changes via the APIs, such as updating firewall rules, modifying secure access policies, retrieving analytics data, adjusting SD-WAN performance settings, or managing device inventories. The APIs support integration with SIEM, SOAR, and configuration management tools to streamline operations and automate incident response.

However, the Secure Connect service itself does not expose a single unified API. More information can be found at: https://developer.cisco.com/sase/.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Cisco Secure Connect offers extensive customisation options that allow organisations to tailor networking, security, and access policies to their specific operational and compliance requirements. Customising network connectivity by defining SD-WAN routing policies, traffic prioritisation, and cloud on-ramps. Security controls can be adapted through customised Secure Web Gateway rules, DNS filtering policies, cloud-firewall configurations, CASB controls, and data-loss-prevention settings. Zero Trust access can be personalised by defining identity-based access rules, device-posture requirements, and application-specific policies.

The TTB service allows the customer to customise and configure their service via a catalogue of Standard & Normal service changes that may be requested through a documented change control process. The catalogue is provided to the customer at the start of the service as part of the Statement of Works (SoW) document. Change control tickets are raised via phone or email communication.

Changes are managed through a system of Flex Tokens, which are consumed for each change. The number of Flex Tokens will be based upon your specific environment and service level.

Scaling

Independence of resources
Cisco Secure Connect prevents one customer’s usage from impacting another’s through a scalable, cloud-based architecture that separates each organisation’s traffic and policies. Customer environments are logically isolated, ensuring privacy and performance consistency. The service automatically balances demand across Cisco’s global infrastructure and adds capacity as needed to handle increased traffic. Continuous monitoring ensures performance levels remain stable even during peak usage.

Please see the Meraki Cloud scalability guidelines below: https://documentation.meraki.com/Platform_Management/Dashboard_Administration/Design_and_Configure/Architectures_and_Best_Practices/Cisco_Meraki_Best_Practice_Design/Building_a_Scalable_Meraki_Solution

Today Meraki cloud has 1 million+ customers, with 4 million+ customer networks, with over 190 million+ devices being managed in this cloud network globally.

Analytics

Service usage metrics
Yes
Metrics types
Cisco Secure Connect provides comprehensive service usage metrics through its central management dashboard and integrated analytics platforms. Metrics include user activity, application usage, bandwidth consumption, traffic volumes, and session statistics across branches and remote users. Network performance metrics such as latency, jitter, packet loss, and link availability are continuously monitored. Security-related metrics include blocked threats, malicious domains, policy violations, DNS requests, and cloud application access events. Administrators can view real-time dashboards and historical reports to track trends, detect anomalies, and assess service effectiveness. These metrics support capacity planning, performance optimisation, security monitoring, compliance reporting, and proactive operational decision-making.
Reporting types
  • Real-time dashboards
  • Regular reports
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Cisco Secure Connect

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
The Meraki dashboard Application Programming Interface (API) is an interface for software to interact directly with the Meraki cloud platform and Meraki-managed devices. The API contains a set of tools known as "endpoints" for building software and applications that communicate with the Meraki dashboard. Use cases include provisioning, bulk configuration changes, monitoring, and role-based access controls. The dashboard API is a modern, RESTful API using HTTPS requests to a URL and JSON as a human-readable format. The dashboard API is an open-ended tool that can be used for many purposes.
https://documentation.meraki.com/Platform_Management/Workflows/Workflows/Import_and_Export_a_Workflow

https://documentation.meraki.com/Platform_Management/Dashboard_Administration/Operate_and_Maintain/How-Tos/Cisco_Meraki_Dashboard_API
Data export formats
Other
Other data export formats
JSON
Data import formats
Other
Other data import formats
JSON

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks
Cisco Secure Connect protects data in transit using strong encryption standards. Site-to-cloud and site-to-site communications are secured using IPsec VPN tunnels with modern cryptographic algorithms, ensuring confidentiality and integrity of traffic between the buyer’s network and Cisco’s cloud service edges. Remote user connections via Cisco Secure Client are protected using TLS 1.2 or higher with certificate-based authentication and secure cipher suites. Legacy SSL and deprecated encryption protocols are not supported. This ensures data is protected from interception, tampering, or unauthorised access while transiting public or private networks.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Cisco Secure Connect is delivered through Cisco’s globally distributed cloud infrastructure designed for high availability and resilience. The service leverages multiple geographically dispersed data centres, redundant service edges, and automated failover mechanisms to minimise downtime and maintain continuous service delivery. Data Centres are located globally which offer a 99.999% SLA. This SLA covers availability of core connectivity, security enforcement, and management access functions. Please see https://meraki.cisco.com/en-uk/platform/.

If Cisco fails to meet the agreed availability threshold, customers are entitled to service credits in accordance with the Cisco Secure Connect Service Level Agreement. Service credits are calculated as a percentage of the monthly subscription fee and applied to future billing rather than direct financial reimbursement.
Approach to resilience
Cisco Secure Connect is designed with resilience as a core architectural principle to ensure continuous service availability and protection against failures or disruptions. The service is delivered through Cisco’s globally distributed network of secure cloud data centres and service edges, which are deployed across multiple geographic regions. These facilities operate in an active-active configuration, allowing automatic traffic failover if a site becomes unavailable. Redundant infrastructure components, including compute, networking, power, and cooling systems, ensure uninterrupted operation even during hardware failures or maintenance events.

Traffic is intelligently load-balanced across service nodes, enabling dynamic capacity scaling and rapid recovery from unexpected demand spikes or outages. Continuous health monitoring and self-healing mechanisms detect issues in real time and reroute traffic to healthy nodes without manual intervention. Disaster recovery procedures include real-time configuration replication and data synchronisation across regions to minimise data loss and ensure rapid restoration.

Physical and logical security controls protect critical assets, and all data centres meet recognised industry standards for resilience and asset protection.

Cisco Secure Connect is a SaaS model and falls within the Shared Responsibility model of Cloud Compute, and is covered by SLA.
Outage reporting
Customers will be updated via an email alert to a Main Customer Contact indicating which services are impacted. The Main Customer Contact must forward the information to their individual sites. The Main Customer Contact will be determined during onboarding.

The customer can also find information on outages at https://status.umbrella.cisco.com/#/

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Other user authentication
Cisco Meraki user authentication involves various methods for network access, including Meraki Cloud Auth (built-in users), 802.1X with RADIUS/Active Directory, SAML/SSO (for dashboard or network access via IdPs like Azure AD/Google), and Splash Pages (for guest/captive portals), all configured via the Meraki Dashboard to secure Wi-Fi, VPN, and Switch ports. The core idea is validating user credentials against a chosen backend (Meraki cloud, external directory, or IdP) before granting network access, often using email/username and password, with options for MFA such as Cisco DUO.
Access restrictions in management interfaces and support channels
Full Role Based Access Control. Cisco Secure Connect restricts access to management interfaces and support channels through role-based access control, strong authentication, and least-privilege design principles. Administrative access to the management dashboard is limited to authorised users and protected by identity federation, multi-factor authentication, and certificate-based controls where configured. Roles and permissions define what actions individual users can perform, such as viewing metrics, modifying policies, or managing devices.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
Cisco Meraki provides role-based access control (RBAC) for administrative users, allowing granular permissions per organisation and network. Administrative access is logged and audited via detailed event logs in the Meraki Dashboard. IP address whitelisting can be enforced to restrict management access to trusted locations. API access is authenticated using API keys with configurable scopes and logging. All management traffic is encrypted using HTTPS/TLS to Cisco’s cloud-hosted Dashboard.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials
Information security policies and processes
TTB has a Master Security Policy in place and operates an Information Security Management System via its Security Operations Centre (SOC) for the reporting of all potential security breaches. The system is based on industry good practice (NIST CSF, PCI DSS) and is externally certified to ISO 27001. This covers a range of policies and procedures to ensure the confidentiality, integrity and availability of information, including a Master Security Policy, Privacy Policy and GDPR Policy.

The reporting of any security incidents is done directly to the Security team security@talktalkplc.com or via the internal Secureville web page. The escalation of incidents will be to the Head of Security for review and resolution. All colleagues must follow the data handling requirements in this policy and share the responsibility to protect data. It is mandatory for all employees new and current to do security training at least once a year. All colleagues have set timescales for training completion and this is reported against to ensure compliance.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Configuration Changes are assessed, logged and components tracked through our Service Management tool, which is managed by the Network Engineering team from the point at which we raise the initial change request until that change is closed off.
Quality comes as standard throughout the change process, with everyone involved having the requisite training. Managers of teams carrying out changes will be accountable for the quality of the work undertaken. There is zero tolerance for unauthorised changes.

Security impact will be assessed through a risk assessment and structured model to ensure all risks are captured and clearly identified.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
The Network Security Team conducts security scanning of all our infrastructure on a bi-weekly basis. We also conduct weekly threat and vulnerability scanning of all our network assets via InsightVM. Critical/high risk vulnerabilities patches will be applied within 14 days. All other updates are applied as soon as possible using a monthly patching cycle. Security updates will be assessed and prioritised based on threat level, likelihood of compromise, consequences of compromise, environmental characteristics and regulatory or accreditation-based requirements. We receive information about potential threats from InsightVM from weekly scanning and we use Altiris for Patch Management.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
TTB operates a security incident management program for the alerting of any potential compromises and deploys endpoint protection technology. All incidents are logged on the action plan tracker and updated with notes/associated actions to mitigate risk through to restoration.

Users can report Priority level 1/level 2 incidents by telephone and a response will be given within 1 hour. Incidents can be reported by email/web portal.

Incident reports will be provided upon request. For network incidents, these reports are distributed to impacted customers via email. Reason for Outage reports for priority 1 faults are provided by email within 10 working days.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We have a pre-defined process for common events and fault-related reporting through our 24/7 Technical Support Centre (TSC).

Users can report Priority level 1 and level 2 incidents by telephone (08454566541/08453103444) and by email/web portal.

Incidents, when resolved, will be notified to the customer as part of the logged ticket fault. Reports will be provided upon request for network incidents, and these reports distributed to impacted customers via email.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
1%
Between £500,001 and £1,000,000
2%
Between £1,000,001 and £2,500,000
3%
Between £2,500,001 and £5,000,000
4%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
ISOQAR
ISO/IEC 27001 accreditation date
Tuesday 27 January 2026
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Alcumus ISOQAR
ISO 9001 accreditation date
Monday 26 May 2025
What the ISO 9001 doesn’t cover
Exclusions:
8.3 Design and Development of products and services
7.1.5.2 Measurement traceability
Location: Gateshead
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
Viking Cloud
PCI DSS accreditation date
Monday 3 November 2025
What the PCI DSS doesn’t cover
None - The Non PCI is not covered by our certification, all PCI is covered under this certification.
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
41015739-ac20-4a9f-a558-edbab61126e0
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andrew.stokes@talktalk.business. Tell them what format you need. It will help if you say what assistive technology you use.