Skip to main content

Help us improve the Digital Marketplace - send your feedback

FormusPro

Red Hat Partner Service Provider Offering

Our Red Hat Service Provider offering delivers secure, scalable, fully managed Red Hat platforms for UK public sector clients, enabling consistent hybrid and multi-cloud application delivery. As an authorised provider, we supply licensing, hosting, support and lifecycle management under one wrapper, simplifying procurement and accelerating digital transformation

Features

  • Red Hat-certified service provider platform
  • Enterprise Linux support for hybrid and cloud-native workloads
  • Kubernetes-based application platform (OpenShift)
  • Automation for operations, security and CI/CD (Ansible)
  • Container security scanning and policy enforcement
  • API-driven automation and self-service workflows
  • Hybrid and multi-cloud support

Benefits

  • Accelerated application and platform delivery
  • Reduced operational complexity through automation
  • Enterprise security and compliance capabilities
  • Full-stack lifecycle management and patch orchestration
  • Consistent controls across hybrid and multi-cloud estates
  • Reduced vendor lock-in through open standards
  • Supports DevSecOps and platform engineering operating models

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andrewmartin@formuspro.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 5 6 3 0 6 7 1 4 6 5 6 1 6 6

Contact

FormusPro Andrew Martin
Telephone: 01432345191
Email: andrewmartin@formuspro.com

About your service

Service categories

Systems Infrastructure Software

Physical and virtual computing

  • Virtual client computing

Operating system environments

  • Core Operating Systems
  • Client Operating Systems

Software defined compute

  • Virtual Machine Software
  • Container Infrastructure Software
  • Cloud System Software

Other computing and storage software

  • Remote Desktop Control Software
  • Container Data and Infrastructure Management Software
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
The service does not require an existing software service to operate, but can extend infrastructure, CI/CD, identity, and observability platforms as part of a hybrid operating model.
Cloud deployment model
Hybrid cloud
Service constraints
Planned maintenance windows for platform upgrades and security patches

Certain infrastructure-level changes must be performed by the provider

Support for on-prem or hybrid deployments may require compatible networking (VPN/Direct Connect)

Custom configurations outside Red Hat support boundaries may not be supported
System requirements
  • Supported cloud, virtualisation, or bare-metal infrastructure for dedicated installs
  • Secure hybrid connectivity where required

User support

Email or online ticketing support
Yes
Support response times
We provide email and online ticketing support during UK business hours. Support tickets are acknowledged within one hour. Response and resolution times depend on priority. 24/7 support is also available.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We provide flexible, tiered support for Red Hat Infrastructure and Platform services, aligned to issue priority, impact, and urgency.
Standard Support
Included with entry-level support packages.
Support is provided via email and online ticketing during UK business hours.
Tickets are acknowledged within one hour and managed using response-based SLAs.
Support is delivered by Microsoft-certified cloud engineers covering Red Hat services.
Monthly support costs typically range from £450 to £2,700, depending on environment size, complexity, and required coverage.
Enterprise Support
Designed for larger or more complex Red Hat environments.
Includes priority handling, extended support hours, and 24/7 cover for critical incidents.
A named technical account manager provides escalation management, service reviews, and governance.
Enterprise support pricing starts from £3,150 per month.
Additional Options
Pay-as-you-go support is available at £157.50 per hour.
Optional add-ons include enhanced coverage and support for wider Red Hat ecosystems.
All support follows response-based SLAs, with priorities ranging from critical incidents to low-impact requests.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide structured onboarding to help users adopt the service efficiently. This includes discovery workshops, architecture alignment, environment provisioning, identity and CI/CD integration, and initial policy configuration. Users receive platform documentation, runbooks and knowledge articles tailored to their deployment.

We offer optional enablement services such as online training sessions, platform demonstrations, and hands-on labs for DevOps and application teams. For organisations needing deeper adoption support, we provide consultancy and platform engineering assistance covering GitOps, automation, security configuration, workload onboarding and operational best practice. Onsite enablement can be provided subject to requirement. Support teams are available to guide users through early usage, incident handling and service optimisation.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At end-of-contract, users can export all retained configuration, metadata and logs using standard interfaces before the service is deprovisioned. Data can be extracted via the web console, CLI or API, depending on the service components in use. Support is available to guide customers through the export process if required.
End-of-contract process
At contract end, the customer is notified in advance and offered time to extract data or extend the service. When the contract expires, access is suspended, data is securely deleted per policy, and the environment is deprovisioned.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service exposes both a web-based management interface and REST APIs for automated integration and operational control.
Accessibility standards
None or don’t know
Description of accessibility
The service is accessible through a web browser without specialist software. Users can adjust zoom, contrast and font size via browser settings, navigate most functions with a keyboard, and some components support screen readers and ARIA labels. However, accessibility varies across Red Hat interfaces, and features such as visual topology views or drag-and-drop elements may not be fully usable with assistive technologies.
Accessibility testing
No formal user testing has been conducted with assistive technology users specifically for this managed service. Accessibility behaviour is inherited from Red Hat’s native product interfaces, which undergo internal usability and quality testing by Red Hat. Buyers requiring specific assistive technology validation (such as screen readers or alternative input devices) should assess individual components within their intended deployment context.
API
Yes
What users can and can't do using the API
The service exposes REST APIs that enable automation and integration with Red Hat platforms such as OpenShift, Ansible Automation Platform and Red Hat Satellite. Users can authenticate, create and configure projects, deploy and scale applications, manage workloads, images and policies, trigger automation playbooks, and retrieve logs and metrics. APIs can also integrate with CI/CD or GitOps workflows for automated delivery.

To set up the service via API, users typically generate access tokens or use federated identity, then bootstrap namespaces, pipelines, automation resources and application deployments programmatically. Changes can be made by submitting configuration updates, deployment revisions or automation requests through standard API calls.

Limitations include no access to underlying infrastructure, host operating systems or hypervisor layers, and no ability to override provider-controlled lifecycle management functions such as cluster upgrades or core security hardening. Some networking configurations and advanced security controls must be performed by the provider for supportability and compliance.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customise the service extensively depending on which Red Hat platforms are in scope. Customisable areas include cluster sizing, node pools, networking configuration, storage classes, RBAC policies, namespaces, CI/CD pipelines, automation workflows, security policies, service mesh configuration, logging and monitoring integrations, and application deployment patterns. Users can also integrate their own identity providers and tooling.

Customisation is performed through web consoles, CLI tools, APIs, GitOps workflows, CI/CD pipelines, and configuration-as-code resources (e.g. YAML manifests, Terraform modules or Ansible playbooks). Some changes, such as resource definitions or namespaces, can be created and modified self-service by platform or DevOps teams.

System-level customisations—such as base OS images, cluster upgrades, networking plugins, security hardening or storage infrastructure—are restricted and performed by the service provider to ensure supportability, compliance and lifecycle consistency.

Scaling

Independence of resources
We prevent cross-tenant performance impact through a combination of architectural isolation and automated scaling policies. Each customer runs in logically isolated namespaces or dedicated Red Hat/OpenShift projects, with quotas on CPU, memory, storage and network I/O to prevent resource starvation. Platform-level autoscaling and workload scheduling ensure capacity is added when utilisation increases. Critical control-plane components are reserved and protected from tenant workloads. Continuous monitoring alerts operators if utilisation approaches defined thresholds, allowing proactive scaling. This model ensures that one customer’s demand cannot degrade another’s service performance.

Analytics

Service usage metrics
Yes
Metrics types
The service provides metrics that help buyers understand performance, consumption and health. This typically includes:

Platform health and availability metrics (uptime, component status)

Performance and capacity metrics (CPU, memory, storage, network utilisation)

Usage and consumption metrics (active users, API calls, workloads, deployments, secrets/issues handled)

Security and audit metrics (authentication events, policy violations, access logs)

Metrics are available via dashboards, API access and downloadable reports, allowing buyers to integrate with their own SIEM, observability or billing tools.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Red Hat Software Consultancy and Support

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export their data through the self-service console, via the API, or by opening a support request for bulk export. Data is provided in open, standard formats (for example JSON, YAML, CSV, or container/VM images depending on the component). No proprietary tools are required to access exported data.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Red Hat offer platform availability SLAs aligned to the criticality of the Red Hat services deployed. For managed OpenShift and supporting components, availability targets typically range from 99.9% to 99.99%, excluding planned maintenance windows which are communicated in advance. The SLA applies to control plane and core service availability, ensuring users can deploy, scale and operate workloads reliably.

If availability falls below the contracted SLA in a monthly measurement period, customers are eligible for service credits based on the severity and duration of the outage. Higher availability options, multi-zone deployments and active-active architectures can be tailored for buyers with enhanced resilience requirements.
Approach to resilience
The service is designed for resilience across platform, infrastructure and operational layers. Red Hat platforms support cluster-based high availability, workload orchestration and health-based self-healing to automatically reschedule applications if nodes fail. Control plane components are deployed redundantly, and workloads can run across multiple nodes, availability zones or datacentres depending on customer requirements. Storage and networking are configured with fault-tolerant backends, and automated monitoring detects failures and triggers recovery actions.

The underlying datacentre and cloud infrastructure are resilient, with redundant power, cooling, networking and physical security controls. Multi-zone or multi-region architectures are available to protect against localised failures. Backup, patching and lifecycle management processes further reduce operational risk. Additional resilience design detail can be provided on request.
Outage reporting
Outages are reported through multiple channels. A service status dashboard provides real-time platform availability information, and customers can opt in to email alerts for incident notifications, updates and resolutions. For automated integration, outage and health information can also be accessed via an API for use in monitoring or SIEM tools.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted using role-based access control (RBAC), MFA and identity federation, ensuring only authorised users can administer the platform. Privileged actions are limited to approved roles, and all access is logged for audit purposes. Support channels are authenticated through the customer portal, and only nominated contacts can raise incidents, request changes or receive sensitive information. Sensitive operations require additional verification, and no unauthorised remote access to customer environments is permitted.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We follow documented information security policies aligned to ISO/IEC 27001, NCSC cloud security principles, and vendor best practice for Red Hat platforms. Policies cover access control, change management, vulnerability management, incident response, data protection, and acceptable use. They are approved by senior management and reviewed regularly.

Security is governed through a defined reporting structure with responsibility assigned to a senior security lead. Compliance is ensured through internal audits, technical controls, automated monitoring, mandatory staff training, and change approval processes. Third-party assessments and penetration tests validate security controls, and non-compliance is tracked and remediated through the risk management process.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Our configuration and change management processes follow controlled lifecycle management. Service components are tracked from deployment through to retirement using asset registers, configuration management databases and version control systems. All changes—including platform updates, security patches and configuration modifications—are recorded and follow an approval workflow.

Before implementation, changes are assessed for potential security, performance and availability impact through technical review, vendor documentation, automated scanning and (where relevant) test environment validation. Security-sensitive changes undergo additional scrutiny and may require risk assessment or customer notification. Approved changes are implemented during agreed maintenance windows, monitored for success, and documented for audit and compliance purposes.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Red Hat operate a continuous vulnerability management process aligned to recognised security standards. Potential threats are assessed through automated scanning, vendor advisories, security bulletins (RHSA), CVE feeds, threat intelligence sources and industry vulnerability databases. Findings are triaged by severity, exploitability and service exposure.

Patches for critical vulnerabilities are prioritised and typically deployed within defined SLAs, with emergency changes applied sooner if active exploitation is identified. Non-critical updates are bundled into scheduled maintenance windows to reduce risk. Configuration changes, mitigations and compensating controls may be applied when patches are not immediately available. All remediation activity is tracked for audit and compliance.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Red Hat use real-time logging, alerting and behavioural analytics to detect potential compromises, including abnormal access patterns, failed authentication attempts, privilege escalation, policy violations, and unexpected workload activity. Alerts are monitored by operations and security personnel.

When a potential compromise is identified, it is triaged, investigated and contained following defined incident response procedures. Actions may include isolating affected workloads, revoking credentials, applying patches, or engaging Red Hat support if required. Incidents are prioritised by severity, and high-severity events are responded to immediately, with other incidents handled within defined response SLAs. Root cause analysis is performed and remediation steps are tracked.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Red Hat maintain predefined incident response procedures for common events such as service degradation, security alerts, access issues and platform failures. Users report incidents through the support portal, email or phone depending on their support tier. Incidents are logged, triaged by severity and handled within defined SLAs. After resolution, we provide incident reports on request, including root cause, impact, remediation actions and preventive measures.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
The “free version of Ansible” refers to the upstream, open-source Community Edition, which includes:

✅ What’s included (free):

Ansible Core (command-line automation engine)

Community Collections & modules

Playbooks, roles, inventories

Agentless automation over SSH/WinRM

Community documentation and forums

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
1%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
3%
Between £1,000,001 and £2,500,000
4%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Sancert Ltd
ISO/IEC 27001 accreditation date
Monday 10 February 2025
What the ISO/IEC 27001 doesn’t cover
Nothing specific was excluded from our certification.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Citation
ISO 9001 accreditation date
Sunday 8 October 2023
What the ISO 9001 doesn’t cover
Nothing specifically was excluded in the scope for ISO 9001.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
B5d64ed8-d805-47b9-8d6d-d5b8b7930150
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
0f73a075-a547-4fa1-a2bd-df536b1062d2
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andrewmartin@formuspro.com. Tell them what format you need. It will help if you say what assistive technology you use.