Millersoft Apache Kafka Managed Service
Millersoft provides an iSaaS managed Apache Kafka service, delivering design, deployment, security hardening, monitoring, patching, and support of bespoke Kafka clusters on government-aligned cloud or bare-metal infrastructure. The service offers flexible architectures, strong operational security, and ongoing management tailored to customer requirements. Using Kubernetes when necessary.
Features
- Bespoke Apache Kafka architecture design
- Deployment on government cloud, Kubernetes, or bare metal
- Secure configuration aligned with NCSC Cloud Security Principles
- Managed upgrades and security patching
- Continuous monitoring and alerting
- Incident and problem management
- Role-based access control and least-privilege administration
- Backup and recovery configuration support
- Performance tuning and capacity planning
- Named support and service management reviews
Benefits
- Deploy and operate Apache Kafka without building in-house capability
- Reduce operational overhead by outsourcing platform management and maintenance
- Securely ingest large-scale, real-time data with consistent performance
- Scale ingest capacity as data volumes and user demand grow
- Maintain compliance with government security and operational requirements
- Detect and respond to service issues early through proactive monitoring
- Apply security patches and upgrades without disrupting users
- Optimise query performance to support faster decision-making
- Integrate Kafa into existing data pipelines and cloud environments
- Focus internal teams on delivering outcomes rather than managing infrastructure
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 0 1 0 7 8 2 2 6 7 0 3 1 8 9
Contact
MILLERSOFT LIMITED
Calum Miller
Telephone: 0131 507 0256
Email: accounts@millersoftltd.com
About your service
- Service categories
-
Systems Infrastructure Software
System and service management
- IT operations management
- IT service management
IT automation and configuration management
- Workload management
- Datacentre system and application control
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- None
- System requirements
- Linux servers or Kubernetes
User support
- Email or online ticketing support
- Yes
- Support response times
- 4 hrs with cover at weekend by arrangement.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Millersoft provides tiered support levels to meet different operational and service criticality requirements for the managed Apache Kafka service.
Standard Support (9x5) is included as part of the core managed service. It provides support during UK business hours, covering incident management, fault investigation, service requests, and operational queries. Incidents are prioritised by severity with defined response targets. This level is suitable for non-critical or development and test environments and is included in the monthly service charge.
Enhanced Support (24x7) is available as an optional add-on for production or business-critical services. This provides round-the-clock incident response, including out-of-hours support for high-severity incidents, accelerated response times, and proactive operational assistance. Enhanced support is typically priced between £1,500 and £4,000 per month, depending on service scale and complexity.
For customers requiring closer engagement, Millersoft can provide a named Technical Account Manager (TAM) or senior Cloud Support Engineer. This role acts as a primary technical point of contact, providing service oversight, coordination of changes, capacity planning, and regular service reviews. TAM support is offered as an optional service and priced separately, usually on a monthly or retained basis.
Support costs and service levels are agreed contractually and documented in the service schedule. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Millersoft helps users start using the managed Apache Kafka service through a structured onboarding and enablement process designed to minimise time to value. Engagement begins with an onboarding and discovery phase to understand the customer’s use cases, data flows, security requirements, and operational constraints. Based on this, Millersoft designs and deploys a Kafka environment tailored to the customer’s cloud platform and workload needs.
Users are provided with clear onboarding documentation, including service overviews, architecture diagrams, access instructions, and guidance on producing and consuming data using Kafka APIs. Technical documentation covers topic design, security configuration, monitoring, and operational responsibilities.
Millersoft delivers remote onboarding sessions to introduce users to the service, demonstrate core Kafka features, and explain support and operational processes. Optional training workshops can be delivered remotely or onsite, covering developer, operator, and administrator topics such as client configuration, topic management, performance tuning, and troubleshooting.
Ongoing support is available through agreed support channels, with access to experienced Kafka engineers who can answer questions and assist with early implementations. Documentation is maintained throughout the service lifecycle to support continued adoption and effective use of the service. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
When the contract for the Millersoft managed Apache Kafka service ends, users are supported through a structured and secure data extraction process designed to ensure continuity and prevent vendor lock-in. Apache Kafka stores data in open, documented formats and exposes standard APIs, enabling customers to retain control of their data throughout the service lifecycle.
Users can extract their data by consuming messages from Kafka topics using standard Kafka consumer APIs and tools, allowing data to be streamed to customer-managed storage or successor platforms. Topic configurations, access control settings, and operational metadata can also be exported using supported administrative tooling to support re-deployment or migration.
Millersoft provides offboarding documentation describing available export options and supports customers in planning extraction activities. Where required, Millersoft can assist with coordinated data export, topic draining, or migration to another Kafka platform, subject to agreed scope. All data extraction is performed over secure, authenticated connections.
Following confirmation that data extraction is complete, Millersoft supports the secure removal of customer access and deletion of remaining customer data in line with agreed retention and security policies. This approach ensures an orderly exit while maintaining data integrity and security. - End-of-contract process
-
At the end of the contract, Millersoft follows a defined end-of-contract process to ensure a controlled and orderly service exit for the managed Apache Kafka service. The process begins with an agreed offboarding plan that sets out timelines, responsibilities, and exit activities. Millersoft supports customers in exporting their data, including consuming messages from Kafka topics, exporting topic configurations, access controls, and relevant operational documentation. Guidance and standard documentation for service exit and data extraction are included as part of the service.
Once data extraction is complete and confirmed by the customer, Millersoft removes customer access, decommissions the Kafka environment, and securely deletes any remaining customer data in accordance with agreed retention and security policies. Knowledge transfer and configuration handover are provided to support transition to a successor service or internal platform.
The contract price includes core managed service activities for the agreed term, standard onboarding and offboarding documentation, routine service exit support, and guidance on data extraction and handover.
Additional costs may apply for activities outside the standard scope, such as large-scale data migration assistance, extended exit support beyond agreed timeframes, bespoke export tooling, onsite support, or accelerated exit schedules. Any additional costs are agreed in advance with the customer. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Millersoft ensures that onboarding and offboarding documentation for the managed Apache Kafka service is accessible, secure, and easy for users to consume throughout the service lifecycle. Documentation is provided electronically and made available through secure, access-controlled channels agreed with the customer, such as a customer portal, secure document repository, or encrypted file transfer. Access is restricted to authorised customer personnel using role-based access controls.
Onboarding documentation includes service overviews, architecture diagrams, security responsibilities, access procedures, and guidance on using Kafka APIs and client tools. Offboarding documentation describes service termination steps, topic and data export options, configuration handover, and knowledge transfer activities. Documentation is written in clear, plain English and structured to support both technical and operational users.
Documents are version-controlled and maintained as living artefacts to ensure users always have access to the latest approved versions. Updates are communicated through service reviews or change notifications. Where required, documentation can be supplied in formats suitable for internal assurance, audit, or governance processes. Millersoft can also provide walkthrough sessions alongside documentation to support understanding and effective use during onboarding and offboarding.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
-
The Apache Kafka service provides APIs that allow users to interact with and manage aspects of the platform in a controlled manner. Users can use standard Kafka APIs and supporting tooling to create and manage topics, publish and consume messages, define retention policies, and configure client access. These APIs allow applications and users to integrate Kafka into data pipelines and event-driven architectures without direct access to management interfaces.
Where supported by the deployment, users can also use APIs and automation tools to manage operational configurations such as topic partitions, replication factors, and access controls, subject to role-based permissions. This enables controlled changes to support scaling and evolving workloads.
Service setup activities such as initial cluster provisioning, core broker configuration, networking, and security baselines are not performed directly by users via APIs and are managed by Millersoft as part of the managed service. This ensures consistency, security, and reliability.
Users cannot make changes that affect the underlying infrastructure, cluster topology, or shared service components through the API. Changes with potential service-wide impact, such as version upgrades, broker scaling, or security configuration changes, are implemented through Millersoft’s change management process rather than directly via APIs. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Users can customise the Millersoft managed Apache Kafka service to meet their functional, performance, and security requirements while retaining the benefits of a managed platform. Customisation includes Kafka topic configuration, retention policies, partitioning, replication factors, and client access controls, allowing users to tailor the service to their data volumes and usage patterns. Users can also customise ingestion and consumption patterns, integration with external systems, and monitoring thresholds.
Customisation is achieved through a combination of standard Kafka APIs, configuration options, and agreed service processes. Authorised users can create and manage topics, adjust topic-level settings, and manage client credentials using APIs and approved tooling. Operational customisation, such as capacity changes, scaling, upgrades, or security configuration changes, is requested through Millersoft’s change management process to ensure stability and compliance.
Customisation activities are restricted to authorised customer users with appropriate roles and permissions. Millersoft engineers retain responsibility for changes that affect the underlying infrastructure, cluster topology, or shared service components. This shared responsibility model ensures users have flexibility where appropriate while maintaining consistent security, resilience, and service quality across the platform.
Scaling
- Independence of resources
- Millersoft ensures users are not affected by demand from other users through logical and operational isolation. Apache Kafka environments are deployed as dedicated clusters per customer, preventing cross-tenant resource contention. Capacity is sized based on agreed workloads, with separate resources allocated for query processing, ingestion, and coordination. Resource limits and scaling controls are applied to manage peak demand and maintain performance. Continuous monitoring identifies saturation risks early, allowing proactive scaling or optimisation. This approach ensures predictable performance, protects service availability, and prevents one customer’s usage from impacting another’s service.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The managed Apache Kafka service provides operational and usage metrics to support monitoring, performance management, and capacity planning. Metrics include broker availability, message throughput, consumer lag, partition replication status, disk utilisation, and latency. Ingestion and consumption rates, error rates, and topic-level activity are monitored to identify performance issues. Service health metrics and alerts are available through monitoring dashboards and logs, and can be integrated with customer monitoring tools where supported. Summary reports may include availability, incidents, and trends over time to support service reviews and operational decision-making.
- Reporting types
-
- API access
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users export their data from the managed Apache Kafka service using standard Kafka consumer APIs and supported tooling. Data can be consumed from Kafka topics and streamed to customer-managed storage, analytics platforms, or successor services in real time or during controlled offboarding. Topic configurations, schemas, and access controls can also be exported using administrative tools. All data export is performed over secure, authenticated connections. Millersoft provides documentation and guidance to support data export and can assist with planning or execution where required, ensuring customers retain full control of their data and can exit the service without vendor lock-in.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
-
Millersoft guarantees service availability for the managed Apache Kafka service through defined service level agreements (SLAs) agreed with customers. Unless otherwise specified in the contract, the service has a target availability of 99.5% per calendar month, excluding planned maintenance and customer-caused outages. Availability applies to the core Kafka broker service and agreed supporting components and is measured using agreed monitoring metrics.
The service is designed with redundancy, monitoring, and operational controls to minimise unplanned outages. Planned maintenance is scheduled in advance and communicated to customers and is excluded from availability calculations.
If service availability falls below the agreed SLA in a given month, customers may be entitled to service credits. Service credits are calculated as a percentage of the monthly service charge, based on the level of availability achieved. Credits are applied as adjustments to future invoices and are not paid as cash refunds. Total service credits are capped to ensure they remain proportionate.
Service credits are the customer’s sole and exclusive remedy for availability SLA breaches. Repeated or significant SLA failures trigger a service review and corrective action plan to address underlying causes and improve service resilience. - Approach to resilience
-
The Millersoft managed Apache Kafka service is designed to be resilient, ensuring continuity of data streaming and messaging in the presence of failures, maintenance activities, and changing demand. Apache Kafka is deployed as a distributed system, with data replicated across multiple brokers to protect against node failure. Replication and leader election mechanisms allow partitions to remain available even when individual brokers become unavailable.
The service is deployed on resilient, government-aligned cloud infrastructure or dedicated hardware, with high-availability networking and storage. Where Kubernetes is used, resilience is enhanced through pod replication, health checks, automated restarts, and controlled rolling updates. On bare metal deployments, redundancy is achieved through clustered brokers, replicated storage, and failover configurations.
Continuous monitoring of broker health, replication status, and consumer lag enables early detection of issues and rapid response. Capacity planning and scaling controls help prevent performance degradation during peak load. Regular backups of configuration and metadata support recovery from corruption or misconfiguration.
Operational resilience is supported by controlled change management, defined incident response processes, and regular service reviews. Together, these architectural and operational measures ensure the service can tolerate failures, recover quickly, and deliver consistent performance to users. - Outage reporting
-
Millersoft reports service outages and significant incidents through clear, timely, and transparent communication channels agreed with customers. When an outage or service degradation is detected through monitoring or customer reports, the incident is logged and assessed to determine severity and potential impact. For high-severity incidents, customers are notified promptly using agreed notification methods, such as email, secure messaging, or a customer support portal.
Initial notifications provide a summary of the issue, affected services, and immediate actions being taken. During an ongoing outage, Millersoft provides regular status updates at defined intervals, particularly for critical incidents, to keep customers informed of progress toward restoration. Updates include changes in impact, mitigation steps, and estimated time to resolution where available.
Once the incident is resolved, a closure notification is issued confirming service restoration. For significant outages, Millersoft can provide a post-incident report outlining the root cause, resolution steps, and any corrective actions to prevent recurrence. Outage information may also be reviewed as part of regular service management meetings. This approach ensures customers are kept informed throughout incidents and have clear visibility of service health and reliability.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Millersoft restricts access to management interfaces and support channels using role-based access control and the principle of least privilege. Administrative access is limited to authorised personnel with a legitimate business need and is protected using strong authentication, including multi-factor authentication where supported. Management interfaces are not publicly exposed and are accessed only via private networks, VPNs, or IP allow-listing. Support channels are access-controlled, with identity verification required before sensitive actions are performed. All administrative access and support activities are logged and reviewed regularly to maintain security and accountability.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
Millersoft follows a structured set of information security policies and processes designed to protect the confidentiality, integrity, and availability of customer information and services. Our approach is aligned with recognised industry good practice and the UK Government Cloud Security Principles.
We maintain documented policies covering information security governance, risk management, access control, incident management, change management, vulnerability management, and data protection. These policies define roles and responsibilities, including senior management oversight, and are reviewed regularly to ensure they remain effective and up to date.
Access to systems and data is controlled using the principle of least privilege, supported by role-based access controls and strong authentication. Security risks are identified and assessed through threat monitoring, vulnerability tracking, and regular reviews of system configuration and operational practices. Identified risks are prioritised and treated using appropriate technical and organisational controls.
We operate defined processes for incident detection, response, escalation, and post-incident review, ensuring security events are handled promptly and lessons learned are applied. Data protection processes support compliance with applicable legislation, including UK GDPR.
Security considerations are embedded into service design, change management, and operational activities, ensuring that information security is maintained throughout the service lifecycle - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Millersoft operates controlled configuration and change management processes to ensure service stability and security. Configuration baselines are defined and maintained for Apache Kafka environments, with changes managed through a formal change process. Proposed changes are assessed for risk and impact, approved before implementation, and tested in non-production environments where applicable. Changes are scheduled during agreed maintenance windows and communicated to customers in advance. Rollback procedures are in place to restore service if issues occur. Configuration and change records are maintained to support auditability and continual service improvement.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Millersoft operates a structured vulnerability management process aligned with industry good practice and government cloud security principles. Potential threats are assessed using Apache Software Foundation security advisories, CVE databases, dependency monitoring, and reviews of service configuration and exposure. Vulnerabilities are prioritised based on severity, exploitability, and impact on confidentiality, integrity, and availability. Security patches and upstream fixes are deployed promptly following validation, with critical issues addressed as soon as practicable. Where immediate patching is not possible, mitigating controls are applied. Threat intelligence is sourced from ASF advisories, CVE feeds, vendor notifications, and security research relevant to the platform and dependencies.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Millersoft operates continuous protective monitoring to identify potential security compromises across the service. System, application, and access logs are centrally collected and monitored for anomalous behaviour, unauthorised access attempts, and policy violations. Automated alerts highlight suspicious activity and service degradation. When a potential compromise is identified, incidents are triaged promptly, affected components may be isolated, and corrective actions are taken to contain and remediate the issue. High-severity security incidents are prioritised for immediate investigation and response. We respond to suspected security incidents as soon as practicable, with critical incidents addressed without delay and managed through a defined incident response process.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Millersoft operates defined incident management processes aligned with industry good practice. Pre-defined procedures exist for common events such as service outages, performance degradation, and security incidents, ensuring consistent and timely response. Users can report incidents through agreed support channels, including email or a secure support portal, with incidents logged and prioritised by severity and impact. Customers are kept informed through regular status updates during incident resolution. For significant incidents, Millersoft provides incident reports summarising the issue, impact, root cause, resolution actions, and any corrective measures to prevent recurrence.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-