Red Hat Partner Service Provider Offering
Our Red Hat Service Provider offering delivers secure, scalable, fully managed Red Hat platforms for UK public sector clients, enabling consistent hybrid and multi-cloud application delivery. As an authorised provider, we supply licensing, hosting, support and lifecycle management under one wrapper, simplifying procurement and accelerating digital transformation
Features
- Red Hat-certified service provider platform
- Enterprise Linux support for hybrid and cloud-native workloads
- Kubernetes-based application platform (OpenShift)
- Automation for operations, security and CI/CD (Ansible)
- Container security scanning and policy enforcement
- API-driven automation and self-service workflows
- Hybrid and multi-cloud support
Benefits
- Accelerated application and platform delivery
- Reduced operational complexity through automation
- Enterprise security and compliance capabilities
- Full-stack lifecycle management and patch orchestration
- Consistent controls across hybrid and multi-cloud estates
- Reduced vendor lock-in through open standards
- Supports DevSecOps and platform engineering operating models
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 5 6 3 0 6 7 1 4 6 5 6 1 6 6
Contact
FormusPro
Andrew Martin
Telephone: 01432345191
Email: andrewmartin@formuspro.com
About your service
- Service categories
-
Systems Infrastructure Software
Physical and virtual computing
- Virtual client computing
Operating system environments
- Core Operating Systems
- Client Operating Systems
Software defined compute
- Virtual Machine Software
- Container Infrastructure Software
- Cloud System Software
Other computing and storage software
- Remote Desktop Control Software
- Container Data and Infrastructure Management Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The service does not require an existing software service to operate, but can extend infrastructure, CI/CD, identity, and observability platforms as part of a hybrid operating model.
- Cloud deployment model
- Hybrid cloud
- Service constraints
-
Planned maintenance windows for platform upgrades and security patches
Certain infrastructure-level changes must be performed by the provider
Support for on-prem or hybrid deployments may require compatible networking (VPN/Direct Connect)
Custom configurations outside Red Hat support boundaries may not be supported - System requirements
-
- Supported cloud, virtualisation, or bare-metal infrastructure for dedicated installs
- Secure hybrid connectivity where required
User support
- Email or online ticketing support
- Yes
- Support response times
- We provide email and online ticketing support during UK business hours. Support tickets are acknowledged within one hour. Response and resolution times depend on priority. 24/7 support is also available.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide flexible, tiered support for Red Hat Infrastructure and Platform services, aligned to issue priority, impact, and urgency.
Standard Support
Included with entry-level support packages.
Support is provided via email and online ticketing during UK business hours.
Tickets are acknowledged within one hour and managed using response-based SLAs.
Support is delivered by Microsoft-certified cloud engineers covering Red Hat services.
Monthly support costs typically range from £450 to £2,700, depending on environment size, complexity, and required coverage.
Enterprise Support
Designed for larger or more complex Red Hat environments.
Includes priority handling, extended support hours, and 24/7 cover for critical incidents.
A named technical account manager provides escalation management, service reviews, and governance.
Enterprise support pricing starts from £3,150 per month.
Additional Options
Pay-as-you-go support is available at £157.50 per hour.
Optional add-ons include enhanced coverage and support for wider Red Hat ecosystems.
All support follows response-based SLAs, with priorities ranging from critical incidents to low-impact requests. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We provide structured onboarding to help users adopt the service efficiently. This includes discovery workshops, architecture alignment, environment provisioning, identity and CI/CD integration, and initial policy configuration. Users receive platform documentation, runbooks and knowledge articles tailored to their deployment.
We offer optional enablement services such as online training sessions, platform demonstrations, and hands-on labs for DevOps and application teams. For organisations needing deeper adoption support, we provide consultancy and platform engineering assistance covering GitOps, automation, security configuration, workload onboarding and operational best practice. Onsite enablement can be provided subject to requirement. Support teams are available to guide users through early usage, incident handling and service optimisation. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At end-of-contract, users can export all retained configuration, metadata and logs using standard interfaces before the service is deprovisioned. Data can be extracted via the web console, CLI or API, depending on the service components in use. Support is available to guide customers through the export process if required.
- End-of-contract process
- At contract end, the customer is notified in advance and offered time to extract data or extend the service. When the contract expires, access is suspended, data is securely deleted per policy, and the environment is deprovisioned.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service exposes both a web-based management interface and REST APIs for automated integration and operational control.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service is accessible through a web browser without specialist software. Users can adjust zoom, contrast and font size via browser settings, navigate most functions with a keyboard, and some components support screen readers and ARIA labels. However, accessibility varies across Red Hat interfaces, and features such as visual topology views or drag-and-drop elements may not be fully usable with assistive technologies.
- Accessibility testing
- No formal user testing has been conducted with assistive technology users specifically for this managed service. Accessibility behaviour is inherited from Red Hat’s native product interfaces, which undergo internal usability and quality testing by Red Hat. Buyers requiring specific assistive technology validation (such as screen readers or alternative input devices) should assess individual components within their intended deployment context.
- API
- Yes
- What users can and can't do using the API
-
The service exposes REST APIs that enable automation and integration with Red Hat platforms such as OpenShift, Ansible Automation Platform and Red Hat Satellite. Users can authenticate, create and configure projects, deploy and scale applications, manage workloads, images and policies, trigger automation playbooks, and retrieve logs and metrics. APIs can also integrate with CI/CD or GitOps workflows for automated delivery.
To set up the service via API, users typically generate access tokens or use federated identity, then bootstrap namespaces, pipelines, automation resources and application deployments programmatically. Changes can be made by submitting configuration updates, deployment revisions or automation requests through standard API calls.
Limitations include no access to underlying infrastructure, host operating systems or hypervisor layers, and no ability to override provider-controlled lifecycle management functions such as cluster upgrades or core security hardening. Some networking configurations and advanced security controls must be performed by the provider for supportability and compliance. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customise the service extensively depending on which Red Hat platforms are in scope. Customisable areas include cluster sizing, node pools, networking configuration, storage classes, RBAC policies, namespaces, CI/CD pipelines, automation workflows, security policies, service mesh configuration, logging and monitoring integrations, and application deployment patterns. Users can also integrate their own identity providers and tooling.
Customisation is performed through web consoles, CLI tools, APIs, GitOps workflows, CI/CD pipelines, and configuration-as-code resources (e.g. YAML manifests, Terraform modules or Ansible playbooks). Some changes, such as resource definitions or namespaces, can be created and modified self-service by platform or DevOps teams.
System-level customisations—such as base OS images, cluster upgrades, networking plugins, security hardening or storage infrastructure—are restricted and performed by the service provider to ensure supportability, compliance and lifecycle consistency.
Scaling
- Independence of resources
- We prevent cross-tenant performance impact through a combination of architectural isolation and automated scaling policies. Each customer runs in logically isolated namespaces or dedicated Red Hat/OpenShift projects, with quotas on CPU, memory, storage and network I/O to prevent resource starvation. Platform-level autoscaling and workload scheduling ensure capacity is added when utilisation increases. Critical control-plane components are reserved and protected from tenant workloads. Continuous monitoring alerts operators if utilisation approaches defined thresholds, allowing proactive scaling. This model ensures that one customer’s demand cannot degrade another’s service performance.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The service provides metrics that help buyers understand performance, consumption and health. This typically includes:
Platform health and availability metrics (uptime, component status)
Performance and capacity metrics (CPU, memory, storage, network utilisation)
Usage and consumption metrics (active users, API calls, workloads, deployments, secrets/issues handled)
Security and audit metrics (authentication events, policy violations, access logs)
Metrics are available via dashboards, API access and downloadable reports, allowing buyers to integrate with their own SIEM, observability or billing tools. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Red Hat Software Consultancy and Support
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data through the self-service console, via the API, or by opening a support request for bulk export. Data is provided in open, standard formats (for example JSON, YAML, CSV, or container/VM images depending on the component). No proprietary tools are required to access exported data.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Red Hat offer platform availability SLAs aligned to the criticality of the Red Hat services deployed. For managed OpenShift and supporting components, availability targets typically range from 99.9% to 99.99%, excluding planned maintenance windows which are communicated in advance. The SLA applies to control plane and core service availability, ensuring users can deploy, scale and operate workloads reliably.
If availability falls below the contracted SLA in a monthly measurement period, customers are eligible for service credits based on the severity and duration of the outage. Higher availability options, multi-zone deployments and active-active architectures can be tailored for buyers with enhanced resilience requirements. - Approach to resilience
-
The service is designed for resilience across platform, infrastructure and operational layers. Red Hat platforms support cluster-based high availability, workload orchestration and health-based self-healing to automatically reschedule applications if nodes fail. Control plane components are deployed redundantly, and workloads can run across multiple nodes, availability zones or datacentres depending on customer requirements. Storage and networking are configured with fault-tolerant backends, and automated monitoring detects failures and triggers recovery actions.
The underlying datacentre and cloud infrastructure are resilient, with redundant power, cooling, networking and physical security controls. Multi-zone or multi-region architectures are available to protect against localised failures. Backup, patching and lifecycle management processes further reduce operational risk. Additional resilience design detail can be provided on request. - Outage reporting
- Outages are reported through multiple channels. A service status dashboard provides real-time platform availability information, and customers can opt in to email alerts for incident notifications, updates and resolutions. For automated integration, outage and health information can also be accessed via an API for use in monitoring or SIEM tools.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted using role-based access control (RBAC), MFA and identity federation, ensuring only authorised users can administer the platform. Privileged actions are limited to approved roles, and all access is logged for audit purposes. Support channels are authenticated through the customer portal, and only nominated contacts can raise incidents, request changes or receive sensitive information. Sensitive operations require additional verification, and no unauthorised remote access to customer environments is permitted.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We follow documented information security policies aligned to ISO/IEC 27001, NCSC cloud security principles, and vendor best practice for Red Hat platforms. Policies cover access control, change management, vulnerability management, incident response, data protection, and acceptable use. They are approved by senior management and reviewed regularly.
Security is governed through a defined reporting structure with responsibility assigned to a senior security lead. Compliance is ensured through internal audits, technical controls, automated monitoring, mandatory staff training, and change approval processes. Third-party assessments and penetration tests validate security controls, and non-compliance is tracked and remediated through the risk management process. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Our configuration and change management processes follow controlled lifecycle management. Service components are tracked from deployment through to retirement using asset registers, configuration management databases and version control systems. All changes—including platform updates, security patches and configuration modifications—are recorded and follow an approval workflow.
Before implementation, changes are assessed for potential security, performance and availability impact through technical review, vendor documentation, automated scanning and (where relevant) test environment validation. Security-sensitive changes undergo additional scrutiny and may require risk assessment or customer notification. Approved changes are implemented during agreed maintenance windows, monitored for success, and documented for audit and compliance purposes. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Red Hat operate a continuous vulnerability management process aligned to recognised security standards. Potential threats are assessed through automated scanning, vendor advisories, security bulletins (RHSA), CVE feeds, threat intelligence sources and industry vulnerability databases. Findings are triaged by severity, exploitability and service exposure.
Patches for critical vulnerabilities are prioritised and typically deployed within defined SLAs, with emergency changes applied sooner if active exploitation is identified. Non-critical updates are bundled into scheduled maintenance windows to reduce risk. Configuration changes, mitigations and compensating controls may be applied when patches are not immediately available. All remediation activity is tracked for audit and compliance. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Red Hat use real-time logging, alerting and behavioural analytics to detect potential compromises, including abnormal access patterns, failed authentication attempts, privilege escalation, policy violations, and unexpected workload activity. Alerts are monitored by operations and security personnel.
When a potential compromise is identified, it is triaged, investigated and contained following defined incident response procedures. Actions may include isolating affected workloads, revoking credentials, applying patches, or engaging Red Hat support if required. Incidents are prioritised by severity, and high-severity events are responded to immediately, with other incidents handled within defined response SLAs. Root cause analysis is performed and remediation steps are tracked. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Red Hat maintain predefined incident response procedures for common events such as service degradation, security alerts, access issues and platform failures. Users report incidents through the support portal, email or phone depending on their support tier. Incidents are logged, triaged by severity and handled within defined SLAs. After resolution, we provide incident reports on request, including root cause, impact, remediation actions and preventive measures.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
The “free version of Ansible” refers to the upstream, open-source Community Edition, which includes:
✅ What’s included (free):
Ansible Core (command-line automation engine)
Community Collections & modules
Playbooks, roles, inventories
Agentless automation over SSH/WinRM
Community documentation and forums
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 4%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Sancert Ltd
- ISO/IEC 27001 accreditation date
- Monday 10 February 2025
- What the ISO/IEC 27001 doesn’t cover
- Nothing specific was excluded from our certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation
- ISO 9001 accreditation date
- Sunday 8 October 2023
- What the ISO 9001 doesn’t cover
- Nothing specifically was excluded in the scope for ISO 9001.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- B5d64ed8-d805-47b9-8d6d-d5b8b7930150
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 0f73a075-a547-4fa1-a2bd-df536b1062d2
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-