Skip to main content

Help us improve the Digital Marketplace - send your feedback

MYDEX DATA SERVICES COMMUNITY INTEREST COMPANY

Safe Secure Cloud API and Application Services

Our Safe Secure Cloud Core API and Web Application Services provide the backbone for seamless service integration for public services across the public, third and independent sectors. We enable networks of service providers to connect with their citizen service users to deliver local, regional and national seamlessly integrated secure services

Features

  • Secure two way personal and service event data exchange
  • Secure identity federation to enable single sign on with MFA
  • Access to curated content from open sources via secure APIs
  • Engagement, Feedback, Research Dashboard services
  • Third party Identity Provider mapping
  • Interoperability across data standards and protocols using configurable templates
  • ​​Personal Data Stores, Holder Services free for citizen service users
  • Self Managed Directory Services and referral management and social prescribing
  • Service Provider front line service management and engagement applications
  • Pre-integrated Feature Blocks for self management & two-way service interactions

Benefits

  • Reduced Friction, Effort , Risk and Cost
  • Improved productivity in operational services
  • Improved user experience
  • Improved timelines and quality of outcomes
  • Improved management, regulatory and compliance reporting
  • Improved research in policy development, innovation, transformation and improvement
  • Ensures GDPR compliance seamlessly
  • Improves data quality, security and reduces data sparsity and duplication
  • Eradicates unnecessary form filling
  • Delivers seamless service integration across multi-disciplinary teams across multiple organisations

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at david@mydex.org. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 4 8 0 1 5 9 6 0 6 0 6 8 4 2

Contact

MYDEX DATA SERVICES COMMUNITY INTEREST COMPANY David E Alexander
Telephone: +442032396245
Email: david@mydex.org

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
  • Education
  • Public Order and Safety
  • Police
  • Social Security Administration
  • Adult Social Care
  • Children's Social Care
  • Other
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The Safe Secure Cloud is operated 24hrs a day 365 days a year using a high availability environment which enables us to deploy updates and perform maintenance within our normal operational window. Should any downtime be required all subscribers are notified in advance but this has not been the case over the last 18 years
System requirements
  • Access to the worldwide web
  • Have a valid subscription
  • Restful APIs for integration

User support

Email or online ticketing support
Yes
Support response times
We operate 24hrs a day 365 days a year. Our ticketing system is always on. We aim to respond within 24hrs in line with our ISO27001:2022 Certification for our whole company including support services
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We employ multi-channel chat services so we can work with our subscribers preferred chat services such as Microsoft Teams, Google Chat, WhatsApp, Signal, Slack and Discord.

These channels are established as part of onboarding. This may include the creation or joining of specific channels created for different aspects of support and the Senior Responsible Office, Management, front line teams and technical, security and compliance teams
Onsite support
No
Support levels
Support levels are agreed based on the nature of subscription, implementation support requirements. We offer a baseline standard support within UK working hours Monday to Friday.

Subscribers are able to agree additional services and service levels through the use of our modular Cloud support services in Lot3 which can define the level and range of support services to meet a subscribers needs
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
We have a comprehensive range of Lot3 Cloud support services to support subscribers getting started. This includes online briefings and training and extensive documentation to support the subscribers executive leadership, service and product owners, project management, service management, front line service, security and information governance, technical teams. Technical teams who undertake integration to their own systems including their third party integration and application providers
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
  • Other
Other documentation formats
  • Online file based sharing
  • Code examples and Tests
  • Interactive visualisations and navigation
End-of-contract data extraction
Subscribers integrate to our Core API Services for two way secure data exchange with their own internal applications under GDPR compliant Data Sharing and Services Agreements that provide the connectivity and exchange services.

Subscribers use our Web Applications to streamline and integrate services and interactions with citizens, communities and wider stakeholders. They can export their data directly at anytime.

Where we provide Master Reference Content Services for subscribers and content curators they have direct access to add, remove and manage their content.
End-of-contract process
Subscribers can end their annual subscriptions at any time stop using them. They are in control of use of these subscriptions and require no intervention or support from Mydex.

We will provide basic off boarding support during the contract period.

If a subscriber requires additional support services they can access these through Lot3 Cloud Support Services using our pre-packaged modular support services or via specific requirements costed against our SFIA rate card
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Our services are fully responsive to device type and orientation. Where specific capabilities are used within Mobile Devices for relevant access tokens and additional security needs these are supported and can be configured by subscribers
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
All subscribers have access via a web application built using common open source components that are configured to create reusable feature blocks for consistency across all web applications
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We automatically test each application with a range of assistive technologies either available by default on the subscribers devices or specifically installed by subscribers in line with their own device policies and preferences.
API
Yes
What users can and can't do using the API
Subscribers can formally request connection to our 3 core APIs which use industry standard protocols including OAuth2.0 and OIDC.

Depending on the nature and scope of API use they can configure a GDPR Compliant Data Sharing and Service Agreement directly through our web interface. All such requests are reviewed and when approved the necessary secrets are generated and issued to the subscriber via secure channels concurrently with deployment to the Sandbox and Live Safe Secure Cloud
API documentation
Yes
API documentation formats
  • HTML
  • ODF
  • PDF
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The Safe Secure Cloud offers a wide range of configuration options including the creation of new interoperability templates for two way data exchange and operationally through API parameters and options.

Typically subscriber's own integration teams create these customisations or request specific configurations via the use of our interoperability templates engine.

Any templates and configurations we create are designed to become a library of reusable templates that other subscribers can make use of to accelerate ease of integration, interoperability and adoption at low cost and ease of ongoing maintenance and support.

End users working via our web applications can control their own preferences and experience.

Scaling

Independence of resources
Our software as a services are hosted in the UK on a resilient, highly available infrastructure that is horizontally and vertically scalable with dynamically available capacity on demand. Horizontal scaling is spread across three distinct datacentres isolated physically from one another. The service operates from all three datacentres in real-time with no single point of failure.

We closely monitor performance of capacity and demand and ensure we deliver the availability and capacity required to support our subscribers to ensure one subscriber's demands do not impact other subscribers.

Analytics

Service usage metrics
Yes
Metrics types
Subscribers can generate usage metrics from their use of our Core APIs and Web Applications.

We also provide the capability to extract specific combinations of statistics covering the use of our Core APIs and Web Applications. Covering activity and interaction analysis between themselves, citizens and configuration of service providers who have formed a cluster of services delivered by multi-disciplinary teams across multiple organisations
Reporting types
  • API access
  • Real-time dashboards
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
We provide a web interface and API interface for data export. These can be configured for specific requirements such as operational management and performance, regulatory and compliance reporting, and a range of research purposes e.g. public health, service transformation and improvement, innovation
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • Structured JSON payloads
  • Microsoft Word where relevant
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • Structured JSON payloads
  • Microsoft Word where relevant
  • PDF

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks
Each subscriber's connections to our Software as a Service are protected by an additional layer of security and encryption that is unique to their connections.

Mydex supports callback connections to the Subscriber's service via authenticated means and offers static IP addresses that the Subscriber can allow-list in their firewall for those callback requests.

Mydex operates network and system logging and intrusion detection systems 24x7 which are monitored by engineers both day and night.

Mydex domains are also protected with DNSSEC should the Subscriber service wish to validate against DNS MITM attacks.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Each connection between our portfolio of Software as a Service (e.g inter-connected APIs) is uniquely encrypted as an additional layer of protection during transit.

Where traffic does not transit the internet it occurs over internal-only Virtual Private Networks through internal loadbalancers that do not have public IP addresses.

Backend auto-scaling compute clusters do not have public IP addresses attached to them.

Egress firewalls are locked down to only the necessary ports/services via Security Groups and additional software firewalls.

Availability and resilience

Guaranteed availability
We strive to provide 99.99% availability at all times.

We manage our development, maintenance, testing and update processes in such a way as to dynamically upgrade our SaaS services and the infrastructure it operates on. Changes are only rolled out to production once they have satisfied testing in lower environments.

We use real-time monitoring and response capabilities which alert on-call engineers 24x7. This is operated under our independently certified Information Security Management System operating under ISO27001:2022 with automated evidence collection and mapping to the relevant controls to support ongoing operational management and management reviews.

As we use public cloud infrastructure we are also subject to the SLAs offered by the cloud provider.
Approach to resilience
The Mydex Safe Secure Cloud (including its APIs and public-facing web applications) operate across three distinct physical datacentres in the UK. Traffic is balanced across the three physical zones in real time. In most cases, this is an active-active set up, otherwise an automatic active/passive failover between zones depending on the impacted service and its nature.

The cloud provider has designed these three physical zones to be appropriately distanced so as to avoid physical disaster risks such as bomb blasts and other power grid issues.

The services operated by Mydex always run in a highly-available setup with more than one replica of the service operating, with each replica always distributed in different zones (anti-affinity). Mydex can tolerate two out of three physical datacentre losses and still remain operational.

The platform uses container orchestration technology that detects unexpected failure of service components and automatically re-spawns (and re-balances) where required. Operational infrastructure also features automatic self-healing to protect against physical hypervisor failure.

Mydex also synchronises data to several separate cloud vendors as 'warm standby' disaster recovery zones. The data on these DR zones are tested quarterly for integrity.
Outage reporting
We publish a public status page for our Core APIs and web applications which also supports RSS feed subscription.

If in the unlikely event we have to perform a maintenance activity that would require any form of downtime this is managed via notifications to affected parties and via the public status page if necessary.

We select the lowest activity period historically across our Core APIs and Web Application to perform this type of maintenance, which is very rare due to our dynamic upgrade and maintenance processes across our high availability infrastructure. We have engineers who work night shifts to handle these tasks.

Subscribers can be notified by email from our monitoring services if desired.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Other user authentication
Mydex personnel use Public Key authentication to access operational/internal tooling services, also typically over dedicated VPN. Customers (Subscribers to the platform) and citizens typically do not need to use such means, however VPNs and PKI can be arranged with subscribers for server-to-server API integrations.

Third party customers and citizens use their personal Private Key and other cryptographic secrets to approve or access the citizen's encrypted-at-rest Personal Data Store provided by the Mydex Personal Data Exchange API, which forms a core part of Mydex's innovations to accessing and storing personal data securely with citizen consent. All such traffic occurs over TLS.
Access restrictions in management interfaces and support channels
All our operational channels are controlled by role based access control as well as VPNs and other PKI for operational access to different management layers of our infrastructure, Core API Services and Web Applications. No internal management interfaces are directly exposed to the internet.

We also control access via OAuth 2.0 and defined scopes to constrain access to specific API Services.

All subscriber staff must be authenticated with the expected username and have the role/s required to access management interfaces and support channels provided by Mydex on a case by case basis to those approved usernames.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Description of management access authentication
We want to note that management access to our operational services over Identity Federation are also subject to a pre-defined subset of approved identities (it is not enough to have an identity with the service, but only a subset of approved engineers within that service can obtain access to certain management interfaces). These policies are defined in configuration as code and require approve from the CISO to change.

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
FairData, a Trustmark operated by the Market Research Society with full recertification by an independent auditor every 3 years (surveillance audits every year). A certified company must meet the 12 Fair Data principles which reinforce GDPR https://www.mrs.org.uk/standards/fairdata.

Our cloud provider is also compliant with CSA CCM v4.0.
Information security policies and processes
Our Information Security Management System follows ISO27001:2022 standard and its Controls. Our processes are mapped to each control. We automatically collect and map Control evidence from across our Core API and Application Services and our internal applications/processes.

Our reporting structure is a Board of Directors including the Chief Executive who is also the Chief Architect, Chief Information Security Office and Chief Data Officer who is support by a senior team covering Infrastructure operations including System Security, Development Operations and Software Engineering.

We also have a Director of business development and finance and we provide project and subscriber implementation and support services.

Our company wide ISMS is audited internally on a regular cycle along with annual surveillance audits and full recertification audits every three years. We have been successfully independently certified for over 12 years with no major non conforities and no more than three minor non conformities which were remediated within agreed timescales.

We operate continual improvement programmes including horizon scanning for emerging threat vectors and legislative and regulatory changes which are integrated into our ISMS and operations proactively in advance of their date of commencement.

We also horizon scan for additional independent certifications that may extend trust and confidence
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We operate company wide under an Information Security Management System that is independently certified to ISO27001:2022. Our configuration and change management processes are defined to meet our operational and strategic requires and can be audited at a granular level at any time.

All changes are assessed for potential security impact and are tracked in detail through out their lifetime.

All system configuration and software is captured in version-controlled code and peer-reviewed. All cloud infrastructure manifests are equally captured in code. All deployment of software and platform changes are automated (CI/CD) with full rollback functionality.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Our vulnerability management processes are defined in our ISO27001:2022 independently certified Information Security Management System.

We continually test and horizon scan for potential attack vectors and vulnerability threats through our Core APIs/Web Applications, operational tooling and our high availability infrastructure and cloud service provider.

Our code repositories are automatically monitored for supply chain threats/dependency updates.

We subscribe to all relevant security notification channels including upstream patch notifications, collaborative notification services for specific environments including the NCSC Early Warning System which provides a common point of entry to a number of the NCSC’s Active Cyber Defence (ACD) services.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We use a suite of open source automatic monitoring, protection and intrusion detection tools at all layers of our Infrastructure, Core APIs and Web Applications.

These integrated tools trigger immediate notifications in real-time which are logged and triaged by the DevOps, SysAdmin and Security team and any remedial action taken. Such notifications and investigations are automatically cross referenced into our ISMS and ISO27001:2022 Dashboards.

We also publish a vulnerability reporting policy and process for anyone identifying an issue to report it responsibly.

We are always looking for improvements in protective and proactive monitoring using a range of defined thresholds.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Within our company wide independently certified ISO27001:2022 Information Security Management we have pre-planned incident management processes in place. These ensure we are effective in managing any incidents and enables prompt decisions when incidents occur. This includes Business Continuity plans which are tested between quarterly and 6 months. Evidence of DR zone testing is captured in our evidence platform after each test.

Incidents reported internally or from customers are captured within our internal tracking system, which are added to our ISMS Key Evidence Engine. Post-Incident reports can be supplied via the issue tracking system or by other communications channels.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
NQA National Quality Assurance https://www.nqa.com/en-gb/about-us
ISO/IEC 27001 accreditation date
Tuesday 8 April 2025
What the ISO/IEC 27001 doesn’t cover
The whole company is certified to ISO27001:2022 standard covering all aspects of our operations
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
    • Plans for positive actions with community groups.
    • Measures for making facilities used in the delivery of the contract available for community groups, education or training
    • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
    • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at david@mydex.org. Tell them what format you need. It will help if you say what assistive technology you use.