Skip to main content

Help us improve the Digital Marketplace - send your feedback

BECHTLE LIMITED

Bechtle Network as a Service (NaaS)

Bechtle’s Network as a Service provides fully managed, secure and scalable network infrastructure delivered on a subscription model. Designed for public sector organisations, it simplifies operations, enhances compliance, and ensures reliable connectivity while reducing complexity, risk and capital expenditure.

Features

  • Secure, compliant network infrastructure aligned to UK public sector standards
  • Fully managed operations reducing administrative and technical burdens
  • Predictable subscription pricing supporting long‑term budget planning
  • Scalable network capacity for changing citizen‑service demands
  • Proactive monitoring ensuring resilient, always‑available connectivity
  • Rapid deployment minimising disruption to essential services
  • Robust data protection meeting strict governance requirements
  • Centralised visibility for simplified multi‑site management
  • Automated updates ensuring security and performance continuity
  • Expert support improving service delivery and operational confidence

Benefits

  • Streamline network operations with fully managed, expert-led service delivery
  • Reduce administrative workload by automating routine network tasks
  • Improve service continuity through proactive issue detection and remediation
  • Strengthen data security by enforcing consistent, compliant configurations
  • Accelerate project delivery with fast, scalable network deployment
  • Simplify multi‑site management using centralised dashboards and controls
  • Enhance workforce productivity with reliable, high‑performance connectivity
  • Optimise budgets using predictable, subscription‑based network costs
  • Improve decision‑making with clear performance insights and reporting
  • Support hybrid working by delivering secure access across all locations

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at publicsector.uk@bechtle.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 5 7 3 9 3 8 0 1 7 6 9 9 6 6

Contact

BECHTLE LIMITED Public Sector
Telephone: 01249 467900
Email: publicsector.uk@bechtle.com

About your service

Service categories

Application Development and Deployment

Application platforms

Deployment centric application platforms

  • Cloud Deployment-Centric Application Platforms
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Bechtle NaaS extends leading cloud‑managed networking platforms, including Cisco, HPE Aruba & Juniper, Fortinet, Ubiquity, etc, and enhances multicloud connectivity through software‑defined networking for secure, scalable public‑sector networking
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
Bechtle NaaS may rely on specific vendor ecosystems such as Cisco Meraki and HPE Aruba & Juniper etc, meaning support and features align to those hardware and cloud‑managed platforms.

Some services may also depend on third‑party networks for multicloud connectivity, which can introduce scheduled maintenance windows or platform‑specific limitations
System requirements
  • Compatible vendor network hardware installed
  • Valid vendor licences for cloud management
  • Stable internet connection for cloud‑managed network control
  • Supported WAN links for SD‑WAN or hybrid connectivity
  • Access to secure management credentials for deployed devices
  • Appropriate power and rack space for network equipment
  • Customer VLAN or IP scheme aligned to service design
  • Modern endpoint devices supporting current Wi‑Fi standards
  • Compliant security policies for network segmentation enforcement
  • Ability to accommodate scheduled maintenance windows

User support

Email or online ticketing support
Yes
Support response times
8 second average time to answer phone, 10 minute average time to answer emails, 40% first line resolution of service tickets.

We categorise tickets by three prioritisation levels:

Critical: target resolution time 1hr
Major: target resolution time 2hrs
Minor: target resolution time 48hrs
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AAA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AAA
Web chat accessibility testing
Planned compliance with WCAG 2.2 AA/AAA and EN 301 549 when implemented
Onsite support
Yes, at extra cost
Support levels
Standard Care (business hours): Incident triage, configuration changes, vendor escalation, monthly reports. Target response: 4 business hours.

Enhanced Care (extended hours): As Standard + 06:00–22:00 coverage, quarterly service reviews. Target response: 2 business hours.

Premium 24×7: Full 24×7 NOC, proactive remediation, change windows, weekly reports. Target response: 1 business hours.

Mission‑Critical 24×7: All Premium features + priority engineers, major‑incident management, continuity planning.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Bechtle deliver:
- Online training sessions to introduce dashboards, alerts, and integrations.
- Onsite training for teams needing hands-on operational guidance.
- User documentation and quick-start guides covering dashboards, sensors, and system configuration.
- Support from Bechtle's Service Delivery Management (SDM) team, who can advise during rollout.

Together, these approaches help users quickly become confident in using Bechtle services.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
When a Bechtle service contract ends, customers have the ability to export all data they own. This would usually include environmental readings, network health metrics, device logs, alerts, and dashboard configurations.

Users would typically extract data through:

1. Self‑Service Exports

* A downloadable export (CSV, JSON, or Excel) from the Vision dashboard.
* Bulk export tools allowing selection of date ranges, sensor sets, or sites.

2. API-Based Extraction

If API access was enabled during the contract, users can pull historical telemetry, alerts, and metadata before access is disabled.

3. Assisted Data Export

Bechtle's Service Delivery Management team can provide:

* A full dataset archive (encrypted ZIP)
* Documentation describing fields and structures
* Optional chargeable professional services for complex exports

Limitations

* Exports must be completed before the contract fully terminates.
* Third‑party data (e.g., SaaS telemetry) may have restrictions due to vendor licensing.
* Dashboard layouts and custom mappings may export only as configuration files, not interactive formats.
End-of-contract process
At the end of a Bechtle service contract, access to the platform typically begins a "managed wind‑down period".

First, customers are given a "defined offboarding window" (usually 30–90 days) during which they can continue accessing dashboards, export data, and request support. Bechtle would notify the customer of key dates, including when data access ends and when services are deactivated.

During this period, Bechtle's Service Delivery Management team would normally assist with data extraction, provide any required documentation, and guide users through shutting down integrations (e.g., disconnecting SaaS services or removing API keys).

Once the contract fully ends, user accounts are deactivated, integrations are disconnected, and data is securely removed from Bechtle's systems after a retention period agreed in the contract (commonly 30–180 days). Hardware sensors or gateways provided as part of a service bundle are either returned, purchased, or decommissioned, depending on the customer’s arrangement.

If desired, Bechtle may offer paid offboarding services, such as data archiving, migration assistance, or support transitioning to a successor system.
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
On desktop, users can expect a fuller dashboard layout with more simultaneous metrics visible, easier navigation, and richer drill‑downs.

On mobile, the experience is likely simplified, stacked views, reduced chart density, and touch‑optimised controls, making it better for quick checks rather than detailed analysis.
Service interface
No
User support accessibility
WCAG 2.2 AAA
API
Yes
What users can and can't do using the API
What users can do:
+ Set up the service programmatically by onboarding sites, registering devices, and applying baseline configurations through API endpoints.
+ Automate network provisioning, including creating SSIDs, VLANs, traffic policies, access control rules, and monitoring settings.
+ Make real‑time changes such as updating configuration templates, modifying bandwidth profiles, activating security features, or pushing firmware updates across multiple locations.
+ Retrieve analytics and performance data, including device health, utilisation, alerts, and event logs for reporting and compliance.
+ Integrate the network with ITSM, monitoring, automation, and orchestration tools to streamline public‑sector operational workflows.

What users cannot do:
+ Bypass mandatory security or compliance controls, such as encryption, audit logging, or role‑based permissions.
+ Change vendor‑controlled infrastructure settings, including low‑level hardware behaviour or restricted firmware parameters.
+ Perform unsupported hardware actions, such as modifying devices not aligned to the approved vendor ecosystem.
+ Deploy configurations that violate design constraints, such as unsupported network topologies or conflicting policy sets.
+ Avoid maintenance windows, as certain updates or API functions may be temporarily unavailable during scheduled service work.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Users can customise Bechtle’s NaaS service in several flexible ways, allowing public‑sector teams to tailor networks to operational, security, and compliance needs.

What can be customised

Users can customise network configurations such as SSIDs, VLANs, security policies, bandwidth profiles, content‑filtering rules, device configurations, and monitoring thresholds. They can also adapt scalability options, site‑specific templates, access controls, and integration settings for ITSM or automation platforms.

How users can customise

Customisation is done through the management portal or automation APIs. Users can apply templates across multiple sites, adjust configurations in real time, push firmware updates, or activate advanced security features. Policy‑driven automation ensures consistent setup across large public‑sector estates while still allowing localised exceptions where required.

Who can customise

Customisation can be performed by authorised IT administrators, network engineers, or automation teams within the organisation. Role‑based access control ensures sensitive changes (such as security configurations or compliance‑related policies) can only be made by privileged users. Customers can also request Bechtle engineers to perform customisation on their behalf, especially for complex or multi‑site deployments.

Scaling

Independence of resources
Bechtle uses standard multi‑tenant cloud isolation techniques. These prevent “noisy‑neighbor” impact through resource partitioning, workload separation, and fair‑share allocation, ensuring one customer’s usage cannot degrade another’s performance.

Analytics

Service usage metrics
Yes
Metrics types
Bechtle NaaS provides clear, actionable service metrics to help public‑sector teams monitor performance and compliance. Metrics typically include network availability, incident response and resolution times, bandwidth utilisation, device health, security event counts, configuration compliance status, and change‑management activity. Customers receive dashboards and scheduled reports, enabling audit readiness, operational insight, and ongoing service optimisation.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
Other
Other data at rest protection approach
Physical access control aligned with ISO 27001.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Degaussing
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can export their data through several options. The Bechtle service dashboard typically offer self‑service exports (CSV, Excel, or JSON) for telemetrics, sensor readings, alerts, and device data. Users with API access can pull historical data programmatically before access ends. During contract wind‑down, Bechtle's Service Delivery Management team may also provide a full archived export on request.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Segmentation and zero-trust principles applied

Availability and resilience

Guaranteed availability
SLA-driven uptime of 99.9% for core services
Approach to resilience
Redundant infrastructure across multiple datacentres.
Automated failover and disaster recovery plans.
Outage reporting
Email alerts and governance reporting.
Public dashboard and API integration planned for roadmap.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password
Access restrictions in management interfaces and support channels
Bechtle NaaS restricts access through role‑based permissions, allowing only authorised administrators to change configuration settings.

Management interfaces use SSO, MFA, and least‑privilege access to prevent unauthorised control. Support channels, such as the "Ask My SDM" feature, require authenticated user accounts, ensuring only verified staff can request changes or view sensitive information.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Bechtle have mature security practices, with solutions for environments that must meet UK Government CESG (now NCSC) standards when delivering hosted services, demonstrating compliance with strict public‑sector security expectations.

An overview of policies and processes include:

* ISO 27001‑aligned security governance, covering confidentiality, integrity, and availability.
* Access control policies, enforcing least privilege, MFA, and identity‑based network access.
* Endpoint and device security policies, supported by unified endpoint management with zero‑trust controls and continuous threat detection.
* Data protection policies, including encryption in transit and at rest, secure key management, and mandatory logging and monitoring.
* Supplier and third‑party risk management, reviewing partners, integrations, and hosting locations.
* Incident response and business continuity processes, including clear escalation routes and defined recovery objectives.
* Regular vulnerability assessments and security reviews, with updates applied across all tenants.

These measures collectively ensure Bechtle services operate securely within a shared, multi‑tenant environment.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
ISO 27001 and ITIL4 CAB process.
Components tracked via CMDB; changes assessed for security impact.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
ISO 27001 and Cyber Essentials Plus.
Threat intelligence from NCSC, vendor advisories, CVE databases.
Critical patches deployed within 24 hours
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
SIEM and SOC integration for real-time threat detection.
Rapid response within SLA windows.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
ISO/IEC 27035:2011 and ITIL4 processes.
Pre-defined playbooks, user reporting via service desk, formal incident reports.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0.01%
Between £250,000 and £500,000
0.01%
Between £500,001 and £1,000,000
0.5%
Between £1,000,001 and £2,500,000
0.5%
Between £2,500,001 and £5,000,000
1%
Over £5,000,001
2%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Tuesday 4 February 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau
ISO 9001 accreditation date
Tuesday 4 February 2025
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
1558ec47-32b1-40ed-b801-d45188947349
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
96b7d157-8818-433b-b7f5-60dfc598a1ec
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at publicsector.uk@bechtle.com. Tell them what format you need. It will help if you say what assistive technology you use.