DevSecOps and Cloud Engineering
Sandhata Technologies offers comprehensive DevSecOps solutions that meet the needs of modern IT environments. Our team of professionals combines expertise in development, operations, and automation to streamline workflows and accelerate time-to-market for clients. A focus on efficiency, reliability, and scalability, empowers businesses to achieve their objectives through cutting-edge DevSecOps practices.
Features
- DevSecOps Consultation, we assess your current infrastructure, workflows, and processes.
- Continuous Integration and Continuous DI/CD pelivery (CI/CD) Pipeline Setup.
- Infrastructure as Code (IaC) Implementation.
- Containerization and Orchestration, - We help modernize your application deployment
- Monitoring and Logging, solutions to ensure applications and infrastructure health.
- Security Compliance, This is embedded into the DevSecOps lifecycle
- Seamless migration of your applications to public/private, or hybrid cloud
- We offer training sessions and workshops to upskill your team
Benefits
- Consultation improves and devises a customer's a DevSecOps strategy.
- CICD ensures rapid and reliable delivery of code changes.
- IaC reduces manual intervention, configuration drift, and enhances environment consistency.
- Containerization improves portability, scalability while streamlining deployment.
- Real-time insights into system metrics, logs, and events.
- Enhance the security posture of your applications and infrastructure.
- We optimize cloud infrastructure for performance, cost-effectiveness, and scalability.
- Provide practical experience in implementing DevSecOps techniques within your organization.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 9 6 4 7 7 1 1 1 3 9 0 1 5 9
Contact
SANDHATA TECHNOLOGIES LIMITED
Kumaravel Narayanan
Telephone: 07818441769
Email: accounts@sandhata.com
About your service
- Service categories
-
Application Development and Deployment
Software quality and life cycle
- Automated software quality
- Software change, configuration and process management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The service can be delivered as a standalone DevSecOps capability or as an extension to existing development and cloud platforms. Where used as an extension, it typically integrates with CI/CD pipelines, cloud platforms, and tooling such as Git based repositories, cloud services, and security solutions already used by the buyer.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- The service is subject to the constraints of the underlying development, cloud, and CI/CD platforms selected. These include tooling capabilities, integration support, configuration limits, and vendor release cycles. Functionality is delivered within supported pipeline, security, and infrastructure features. Customisation is configuration-led and does not extend to modification of core platform software or managed cloud services. Performance, scalability, and availability are influenced by the chosen cloud architecture and deployment model. Security, compliance, and operational controls follow a shared responsibility model between the platform providers and Sandhata.
- System requirements
-
- Requirements agreed per implementation and selected DevSecOps platforms
- Browser based access for management interfaces
- Network connectivity to cloud platforms and integrations
- Role based access via client identity systems
- Supported operating systems defined by platform vendors
- API connectivity for external system integration
- Client security, network, and firewall policies accommodated
- Performance requirements depend on solution scope and usage volumes
- Local software installation may be required for developers
- Detailed requirements confirmed during design and onboarding
User support
- Email or online ticketing support
- Yes
- Support response times
- Support tickets are triaged on receipt and handled according to agreed severity and priority levels. Critical incidents impacting service availability or business operations are acknowledged immediately and worked on continuously until resolution. High-priority issues are responded to within defined SLA windows and progressed with regular updates. Medium and low-priority requests are scheduled and addressed based on impact and urgency. Response and resolution targets are agreed with the client as part of the service onboarding, with clear escalation paths and service reporting to ensure transparency and accountability.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We offer three support levels aligned to service criticality and client need:
- Standard Support provides business-hours support (UK working hours) for non-critical services.
- Enhanced Support provides extended hours support for services with higher operational impact.
- Premium Support provides 24×7 support for business-critical platforms.
Each support level defines response and resolution targets by incident severity, clear escalation routes, and regular service reporting.
Support pricing varies by support level and service complexity and is agreed at contract award. Charges are typically structured as a fixed monthly support fee, with Premium Support priced higher than Standard and Enhanced due to increased coverage and staffing requirements.
For supported services, we provide a named point of contact. Strategic or complex engagements are assigned a Technical Account Manager responsible for service governance, escalation management, and continuous improvement. Day-to-day operational support is provided by Cloud Support Engineers with relevant platform expertise.
The support model is tailored per call-off contract to ensure proportional cost, effective service management, and compliance with requirements. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Users are onboarded through a structured service initiation process. This includes environment setup on the selected platform, user access provisioning with role-based permissions, and configuration aligned to the agreed use case. Users are provided with platform access, documentation, and guidance relevant to their role, such as business users, developers, or administrators. Where required, Sandhata delivers onboarding sessions or knowledge transfer to enable users to become productive quickly. Ongoing support and access requests are managed through agreed support and governance processes.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- At contract end, users can extract their data using the export and reporting capabilities provided by the underlying automation or low-code platform. Platforms provide standard tools, APIs, and notifications to support end-of-contract data extraction in commonly used formats. Sandhata supports clients during offboarding by coordinating data export activities, confirming data scope, and providing guidance on available platform capabilities where required. Responsibility for executing and validating data extraction rests with the customer, in line with their data ownership and governance policies. Following confirmation of data extraction, Sandhata will support orderly service termination in accordance with contractual and platform vendor processes.
- End-of-contract process
-
At the end of the contract, the service enters a controlled offboarding phase. This includes confirmation of contract closure, support for data extraction using platform-provided tools, removal of user access, and service termination in line with agreed security and governance requirements. Knowledge transfer and handover activities are included where contractually agreed.
Standard offboarding activities, such as coordination, access removal, and service closure, are included in the contract price. Additional services, including extended support periods, bespoke data migration, custom reporting, or platform-specific exit activities beyond standard processes, may incur additional costs. Any additional charges are agreed in advance and documented as part of the contract or call-off agreement. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- DevSecOps services are delivered through selected cloud, development, and CI/CD platforms, providing secure, browser-based interfaces for developers, operations teams, and administrators. These interfaces support pipeline configuration, security scanning, environment management, monitoring, and reporting, with role-based access controls enforced through client identity systems. Where required, the service exposes APIs and integration endpoints for toolchain integration and automation. Sandhata configures and manages the service interfaces in line with client requirements and governance policies, while core platform functionality, user interfaces, and service standards are provided by the underlying platform vendors.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Where DevSecOps services are delivered using third-party cloud, development, or CI/CD platforms, accessibility compliance to WCAG 2.1 AA is generally provided and maintained by the platform vendor as part of their product assurance and certification.
Sandhata ensures that any dashboards, pipelines, reports, scripts, or custom integrations configured as part of the service are designed and reviewed in line with WCAG 2.1 AA principles where applicable. This includes use of platform accessibility features, configuration reviews, and collaboration with client accessibility teams as required.
Formal platform-level accessibility testing and certification remains the responsibility of the platform provider. - API
- Yes
- What users can and can't do using the API
-
Where DevSecOps services are delivered using cloud, CI/CD, or security platforms, secure, standards-based APIs are used to integrate with external systems and toolchains. These APIs enable authorised users and systems to trigger pipelines, submit and retrieve artefacts, execute security scans, collect metrics, and exchange operational data across the delivery lifecycle.
API access is governed through platform security controls, including authentication, authorisation, and role-based permissions. Users and service accounts can only access API operations aligned to their approved roles and use cases. API documentation and schemas are provided by the platform vendors and supplemented by Sandhata for custom integrations.
Platform governance cannot be bypassed. Access to underlying infrastructure and core services remains restricted to approved administrators, with APIs used in line with agreed security and governance policies. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users can configure and customise DevSecOps solutions within the boundaries of the selected cloud, CI/CD, and security platforms. This includes configuring pipelines, security policies, quality gates, environments, dashboards, and integrations using platform supported tooling, subject to role-based permissions. Customisation is primarily configuration-led rather than bespoke code, enabling controlled change without impacting core platform services. Users cannot modify underlying platform software, managed cloud infrastructure, or vendor controlled components. Sandhata supports and governs all customisation to ensure alignment with agreed delivery standards, security policies, and operational requirements.
Scaling
- Independence of resources
- User workloads are isolated through the underlying cloud, container, and CI/CD platform architectures. Platforms provide segregated environments, namespaces, and resource controls to ensure workloads from one team, pipeline, or application do not adversely impact others. Capacity management, scaling, and performance controls are delivered by the cloud and platform infrastructure. Sandhata designs solutions using agreed environments, usage patterns, and governance controls to manage contention and ensure predictable performance. Where required, workload separation, quotas, and capacity thresholds are agreed with the customer during service design and onboarding.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Service usage metrics are primarily provided through the underlying cloud, CI/CD, and security platforms. These typically include pipeline activity, deployment frequency, execution durations, failure rates, security scan results, API usage, and environment utilisation. Platform dashboards and reports are used to monitor performance, stability, and operational health. Sandhata supplements platform metrics with service-level reporting, including incident volumes, response times, change activity, and delivery metrics, in line with the agreed support model. Specific metrics are agreed during service onboarding and reviewed as part of ongoing service governance.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Microsoft, AWS, GoogleCloud, IBM, GitLab, Atlassian, OpenShift, Kubernetes, Datadog, Dynatrace
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can extract their data using the export and reporting capabilities provided by the underlying automation or low-code platform. Platforms provide standard tools, APIs, and notifications to support end-of-contract data extraction in commonly used formats. Sandhata can supports client data export activities, confirming data scope, and providing guidance on available platform capabilities where required. Responsibility for executing and validating data extraction rests with the customer, in line with their data ownership and governance policies.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
-
- CSV
- Other
- Other data import formats
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Service availability is primarily provided by the underlying cloud, CI/CD, and platform infrastructure, which operate under vendor-defined availability targets and resilient architectures. These platforms typically provide high availability through managed cloud services and redundancy.
Sandhata does not independently guarantee platform availability, but supports service availability through operational monitoring, incident management, and escalation in line with the agreed support model.
Availability targets, service levels, and any service credits are agreed per call-off contract and aligned to the platform providers’ published SLAs. Where applicable, service credits are applied in accordance with contractual terms if agreed availability levels are not met. - Approach to resilience
- Available on request.
- Outage reporting
- Service outages are reported through a combination of platform-native status dashboards, alerts, and service communications. Where supported by the underlying platform, buyers can view service status via public or authenticated dashboards and receive notifications through platform alerting mechanisms or APIs. Sandhata supplements platform reporting with service communications, including email notifications and incident updates, in line with the agreed support and incident management processes.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is restricted through role based access control and the principle of least privilege. Administrative access is limited to authorised Sandhata personnel and, where applicable, customer nominated users.
Management interfaces are protected using federated identity and Multi Factor Authentication, with access granted based on defined roles and approved change requests. Privileged access is time bound where supported by the underlying platform.
Support channels are restricted to authenticated users via controlled ticketing systems and named contacts. All access and administrative actions are logged and monitored, with regular access reviews performed as part of delivery governance. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- No
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- We are certified to the UK Government’s Cyber Essentials standard, demonstrating compliance with baseline cyber security controls across access management, secure configuration, patching, malware protection and network security. Cyber Essentials provides assurance that appropriate technical and organisational measures are in place to protect systems and data.
- Information security policies and processes
-
Sandhata follows a structured information security management approach aligned to UK best practice and proportional to the services delivered. Our information security policies and processes are defined, maintained and reviewed with the support of an independent Principal Information Security Consultant to ensure ongoing relevance, effectiveness and compliance.
Our core policies include Information Security, Access Control, Data Protection, Incident Management, Business Continuity, Supplier Security and Acceptable Use. These policies define how information assets are classified, protected, accessed, monitored and disposed of.
We operate formal processes covering user access management, secure configuration, vulnerability and patch management, incident response, backup and recovery, and supplier risk management. Security responsibilities are clearly defined, and staff are required to complete regular security awareness training.
Compliance is evidenced through our Cyber Essentials certification and ongoing internal reviews. Policies and controls are reviewed at least annually, or following material change, to ensure continued alignment with evolving threats, regulatory expectations and client requirements.
Where platform services are used, we align our operational controls with the security capabilities and standards of those platforms, ensuring a shared responsibility model is clearly defined and enforced. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Sandhata operates a controlled configuration and change management process aligned to ITIL and secure engineering best practice. Service components including infrastructure, platforms, integrations and configurations are version-controlled and tracked throughout their lifecycle using approved tooling.
All changes follow a defined change process, including impact assessment, security review, testing and approval prior to deployment. Changes are assessed for potential security, data protection and operational risk, with higher-risk changes subject to additional review and rollback planning.
Configuration baselines are documented, monitored and reviewed regularly to ensure integrity, traceability and ongoing compliance. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Sandhata operates a documented vulnerability management process maintained by our principal Information Security consultant. Potential threats are assessed through a combination of automated vulnerability scanning, vendor security advisories, threat intelligence feeds, and periodic risk reviews. Vulnerabilities are triaged based on severity, exploitability, and service impact. Critical and high-risk patches are prioritised and deployed in line with defined SLAs, following testing and change control. Patch timelines are aligned to vendor guidance and risk classification. Threat intelligence is sourced from platform vendors, cloud providers, NCSC advisories, and industry security bulletins.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Sandhata applies protective monitoring through a combination of platform-native logging, cloud provider security controls, and operational monitoring processes. Potential compromises are identified via audit logs, access monitoring, alerting on anomalous activity, and security events raised by underlying platforms and infrastructure providers. Suspected incidents are triaged immediately, with containment, investigation, and remediation actions initiated in line with our incident management process. Critical security incidents are responded to within defined SLAs, typically within hours, with escalation to senior technical and security leadership where required. Customers are notified promptly in accordance with contractual and regulatory obligations.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Sandhata operates a documented incident management process aligned to ITIL principles, with predefined runbooks for common incident types (e.g. availability, security, data, integration failures). Incidents are reported via agreed service channels such as ticketing systems, email or client service desks, depending on the engagement model. Incidents are triaged by severity with defined response and escalation paths. For material incidents, we provide incident reports including root cause analysis, impact assessment, remediation actions, and preventative measures. Incident communication and reporting are tailored to client governance and contractual SLAs.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Sandhata may provide limited free or trial access for Sandhata developed components or time bound proof of concept engagements. Trials are typically restricted in scope, users, and duration, and exclude production use, formal support, and service level commitments. Platform licences remain subject to the underlying vendor’s terms.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 1%
- Between £2,500,001 and £5,000,000
- 2%
- Over £5,000,001
- 3%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 3ce7532e-2816-4e8c-8ca5-bb8ec39759ad
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-