Skip to main content

Help us improve the Digital Marketplace - send your feedback

SOFTCAT PLC

Oakland Data Platform Software Service

Oakland’s Data Platform
Software Service delivers a fullstack, cloud-native data
platform, designed to meet the
diverse needs of organisations.
Our service is technologyagnostic, leveraging leading
cloud technologies such as
Azure, AWS, Databricks, and
more, and is tailored to each
client’s requirements for
scalability, security, and costeffectiveness

Features

  • Full-Stack Data Platform Capability
  • Technology-Agnostic Approach
  • Cloud-Native Architecture
  • Rapid “Lighthouse” Pilots
  • Open and Extensible Design
  • Expert Data Engineering
  • Collaborative Delivery Model
  • Agile and Adaptive Implementation
  • Comprehensive Data Governance
  • Structured Onboarding and Offboarding

Benefits

  • Enables seamless data integration and analytics.
  • Always selects best-fit cloud technologies for your needs.
  • Scalable, secure, and costeffective data platform delivery.
  • Delivers immediate operational value and proof of concept.
  • Avoids vendor lock-in; easy to maintain and extend.
  • Modernises infrastructure and supports advanced analytics initiatives.
  • Ensures knowledge transfer and builds internal capability
  • Adapts to change and embeds continuous improvement
  • Ensures data quality, compliance, and regulatory alignment.
  • Smooth adoption, knowledge transfer, and clear exit process.

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at psitq@softcat.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 6 5 9 5 9 2 7 3 5 9 8 7 4 7

Contact

SOFTCAT PLC Public Sector Tenders
Telephone: 01628 403403
Email: psitq@softcat.com

About your service

Service categories

Application Development and Deployment

Integration and orchestration

Business to business middleware

  • B2B Gateway Middleware
  • B2B Collaboration Networks and B2B Managed Services

Integration software

  • Integration Platforms

Event stream processing

  • Messaging Middleware
  • Stream Processing Software
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Oakland’s Data Platform
Software Service can integrate
with other software services
(e.g., cloud platforms, analytics
tools), but it is also designed to
operate independently as a
complete, end-to-end data
platform solution.
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
Our service is tailored to each
client, so technical capabilities
and technologies are defined
after understanding your
requirements and current data
stack. Integration may depend
on the availability of your
internal teams and systems.
Migration projects may require
business process changes and
user training. Some downtime
or business change may be
unavoidable during technology
migration, though we work to
minimise this. Ongoing support
is not included by default and
must be arranged separately.
We do not lock clients into longterm support contracts, ensuring
flexibility and control for your
organisation.
System requirements
  • Modern cloud infrastructure (Azure, AWS, or equivalent required).
  • Secure network connectivity for data integration and access
  • Sufficient storage capacity for data ingestion and analytics
  • Compatible operating systems for platform components and tools
  • User authentication via enterprise identity provider (e.g., Azure AD).
  • API access for integration with existing business systems
  • Supported web browsers for platform management and analytics
  • Minimum bandwidth for reliable data transfer and processing.
  • Access to source data systems for migration and integration
  • Administrative permissions for deployment and configuration activities

User support

Email or online ticketing support
Yes
Support response times
Support response times
Oakland provides both email
and online ticketing support as
part of our managed service
offering. Clients can raise
support requests via a
dedicated email address or through our online ticketing
portal, ensuring prompt and
traceable resolution of issues.
This support is included as
standard, with no extra cost for
core service users. Response
times are different at weekends,
with the majority being
responded to during normal
working hours.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
Oakland’s managed service
provides a dedicated leadership
team for each engagement,
including a service manager
(assigned for five or more
resources), an account leader,
and a director. This team
oversees onboarding, demand
planning, performance, and
quality management. Support is
delivered through: Proactive
resource management and
demand planning Rigorous
quality management of
deliverables Regular KPI
reporting and service reviews
Onboarding and training of
resources to client standards All
clients benefit from these
support features as part of the
managed service. The service is
designed to scale with client
needs, and rates can be
structured as daily resource
rates, fixed monthly fees, or
team-based fees. A dedicated
service manager acts as the
main point of contact for larger
engagements, ensuring
consistent quality and alignment
with client objectives.
Support available to third parties
No

Onboarding and offboarding

Getting started
We provide a structured
onboarding process to ensure
users can start using our Data
Platform Software Service
smoothly and confidently. The
process begins with a discovery
session to understand your
current data landscape,
requirements, and objectives.
We then deliver a tailored
onboarding plan, including
technical setup, user access
configuration, and integration
with existing systems.
Comprehensive documentation
and user guides are provided to
support initial adoption. We offer
interactive training sessions,
both remote and onsite,
covering platform features, data
management, and analytics
capabilities. Our team works
closely with your stakeholders
to ensure knowledge transfer
and answer any questions.
Throughout onboarding, we
provide dedicated support,
including access to our
helpdesk and technical experts.
We monitor progress, address
issues promptly, and adapt the
onboarding plan as needed to
meet your organisation’s needs.
Clear milestones and feedback
loops ensure users are
comfortable and confident with
the platform. At the end of
onboarding, we conduct a
review to confirm successful
adoption and provide
recommendations for ongoing
optimisation. Our approach
ensures a seamless transition,
minimises disruption, and
empowers users to realise the full value of the service from day
one.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
  • Other
Other documentation formats
PPT, Word, Excel
End-of-contract data extraction
At contract end, we provide a
clear, structured offboarding
process to ensure users can
extract all their data securely
and efficiently. Users are given
advance notice of contract
termination and receive
comprehensive guidance on
data extraction options. Data
can be exported in commonly
used, open formats (such as
CSV, JSON, or Parquet) to
ensure compatibility with other
systems. We support both selfservice extraction via the
platform’s management
interface and, if required,
provide direct assistance from
our technical team for bulk or
complex exports. All data,
including raw datasets,
processed outputs, and
metadata, is made available for download. We provide detailed
documentation and checklists to
guide users through the
extraction process, ensuring
nothing is missed. Upon
request, we can also supply
data on encrypted physical
media, following strict security
protocols. After confirmation that
all data has been successfully
extracted and received, we
follow a secure data deletion
process, providing evidence of
deletion if required. Our
approach ensures users retain
full control and ownership of
their data, supporting a smooth
and compliant transition to new
services or platforms.
End-of-contract process
At the end of the contract, we
initiate a structured offboarding
process to ensure a smooth
transition. Users receive
advance notice and clear
guidance on data extraction,
with all data made available in
open, standard formats. We
provide documentation and
support to facilitate data
transfer, and, upon confirmation
of successful extraction,
securely delete any remaining
data in line with agreed
protocols. Included in the
contract price are: Initial
onboarding and knowledge
transfer Access to the data
platform and agreed features
Standard user support during
business hours Regular service
reviews and performance
reporting Documentation for
onboarding, usage, and
offboarding Additional costs may
apply for: Custom development or integration beyond the
agreed scope Out-of-hours or
enhanced support Onsite
training or workshops Data
extraction assistance beyond
standard self-service options
Provision of data on physical
media Extended platform
access beyond contract end for
transition purposes Our
approach ensures transparency,
with all included and optional
services clearly defined from the
outset. This enables buyers to
plan effectively and avoid
unexpected costs at contract
end.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile version provides
access to core features such as
dashboards, data visualisation,
and basic management tools
through a responsive web
interface. While users can view
and interact with data, some
advanced configuration and
customisation options may be
limited compared to the desktop
experience. The desktop
version offers the full range of
features, including complex
integrations, detailed analytics
setup, and administrative
controls. Both versions prioritise security and usability, ensuring
users can access essential
functionality wherever they are.
Service interface
No
User support accessibility
WCAG 2.2 AA
API
No
Customisation available
Yes
Description of customisation
Our Data Platform Software
Service is highly customisable
to meet each organisation’s
unique needs. What can be
customised: Data sources,
integrations, and connectors
Data storage and processing
options Analytics, dashboards,
and reporting features Security settings and user access
controls Workflow automation
and business rules Platform
branding and user interface
elements How users can
customise: Customisation is
achieved through configuration
tools within the platform,
supported by comprehensive
documentation and guidance.
Users can select and connect
data sources, define data
models, set up dashboards, and
adjust security settings via
intuitive management
interfaces. Advanced
customisation, such as bespoke
integrations or workflow
automation, can be delivered by
our team in collaboration with
the client. Who can customise:
Authorised users with
appropriate permissions,
typically system administrators,
data engineers, or business
analysts, can perform most
customisations directly. For
more complex requirements,
Oakland’s technical team
provides support and can
implement advanced
customisations as part of the
service. This flexible approach
ensures the platform aligns with
organisational goals, technical
environments, and user
preferences, empowering
clients to maximise value and
adapt as needs evolve.

Scaling

Independence of resources
We guarantee consistent
performance by using scalable,
cloud-native architecture with
automatic resource allocation.
Each client’s environment is
logically separated, preventing
one user’s demand from
impacting others. Load
balancing and real-time
monitoring proactively manage
spikes in usage, ensuring
reliable service. Service-level
agreements further protect
users from performance
degradation.

Analytics

Service usage metrics
Yes
Metrics types
We provide clear, measurable
service metrics to ensure
transparency and performance
assurance. These include:
Availability/Uptime: 99.9% SLA
for platform services.
Performance: Query response
times and data processing
throughput monitored
continuously. Scalability: Elastic
resource utilisation tracked
against demand. Security:
Vulnerability scan results and
compliance adherence (CSA
CCM v4.0). Incident Response:
Mean Time to Detect (MTTD)
and Mean Time to Resolve
(MTTR) reported monthly.
Support: Ticket resolution times
and user satisfaction scores.
Metrics are accessible via
dashboards and regular reports,
enabling proactive monitoring
and governance
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Reseller (no extras)
Organisation whose services are being resold
Oakland

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export their data
directly from the platform using
built-in export tools. Data is
available in open, standard
formats such as CSV, JSON, or
Parquet. Step-by-step guides
and support are provided to
ensure a smooth export
process. Additional assistance
is available for bulk or complex
data extractions if required
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • Parquet
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • Parquet

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks
We protect data in transit using
TLS v1.2 or above for all
connections, ensuring
encryption and integrity. Legacy
SSL/TLS versions below 1.2 are
not permitted. For secure
remote connectivity, we support
IPsec or TLS VPN gateways
configured with strong cipher
suites and mutual
authentication. Additional
measures: Perfect Forward
Secrecy (PFS) Certificate
pinning and strict key
management Private endpoints
and network segmentation
where feasible Continuous
vulnerability monitoring and
compliance with NCSC Cloud
Security Principle 1
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Protection between networks
We protect data in transit using
TLS v1.2 or above for all
connections, ensuring
encryption and integrity. Legacy
SSL/TLS versions below 1.2 are
not permitted. For secure
remote connectivity, we support
IPsec or TLS VPN gateways
configured with strong cipher
suites and mutual
authentication. Additional
measures: Perfect Forward
Secrecy (PFS) Certificate
pinning and strict key
management Private endpoints
and network segmentation
where feasible Continuous
vulnerability monitoring and
compliance with NCSC Cloud
Security Principle 1

Availability and resilience

Guaranteed availability
Oakland guarantees 99.9%
availability for our Infrastructure
Software as a Service (iSaaS)
Data Platform Software Service,
measured monthly and
excluding scheduled
maintenance windows agreed in
advance. Availability is
monitored continuously, and
performance metrics are shared
via dashboards and monthly
reports to ensure transparency.
Service Level Agreements
(SLAs): Platform Uptime: 99.9%
availability for core services.
Incident Response: Pre-defined
SLAs for common events,
including critical incidents
addressed within 4–8 hours and
lower severity issues within 16–
80 hours, as evidenced in client
support agreements (e.g.,
Network Rail). Resolution:
Issues are prioritised by severity
and resolved within agreed
timelines. Refunds: If availability
falls below the guaranteed level,
Oakland applies proportional
service credits against monthly
fees based on downtime duration. This ensures fairness
and compliance with industry
best practice. Our SLA
framework aligns with
recognised standards such as
CSA CCM v4.0 and supports
proactive monitoring, rapid
remediation, and continuous
improvement. Combined with
robust governance and Zero
Trust principles, this approach
provides clients with confidence
in service resilience and
operational security
Approach to resilience
Approach to Resilience Our
iSaaS Data Platform Software
Service is designed for high
resilience and fault tolerance.
We leverage cloud-native
architectures across leading
providers (Azure, AWS, GCP) to
ensure redundancy and
continuity. Services are
deployed in multiple availability
zones, with automated failover
and load balancing to maintain
performance during component
failures. Data is replicated
across geographically separate
regions to protect against
localised outages, and backups
are encrypted and scheduled
regularly. Datacentre Resilience:
Our hosting environments
comply with Tier III+ standards,
featuring redundant power,
cooling, and network
connectivity. Disaster recovery
plans include Recovery Time
Objectives (RTO) and Recovery
Point Objectives (RPO) aligned
to client SLAs, ensuring rapid
restoration in the event of
disruption. Additional Measures:
Continuous monitoring, proactive health checks, and
automated scaling maintain
service stability under variable
demand. Security and resilience
controls align with CSA CCM
v4.0 and ISO best practices.
Detailed datacentre architecture
and resilience documentation is
available on request for security
reasons. This approach ensures
uninterrupted service delivery,
robust asset protection, and
compliance with government
cloud security principles.
Outage reporting
Outage Reporting Our service
provides transparent and timely
outage reporting through
multiple channels to ensure
clients remain informed: Public
Dashboard: A real-time status
dashboard displays current
service health, planned
maintenance, and incident
updates. This is accessible via a
secure web portal. API Access:
Clients can integrate outage
and status information into their
own monitoring tools through a
RESTful API, enabling
automated alerts and reporting.
Email Alerts: Immediate
notifications are sent to
designated contacts for any
service disruption, including
incident details, estimated
resolution time, and progress
updates. Incident Reports: Postincident summaries are
provided, detailing root cause,
corrective actions, and
preventive measures. Our
approach aligns with
government cloud security
principles and CSA CCM v4.0
standards, ensuring transparency and operational
resilience. Clients can also opt
for SMS alerts or integration
with collaboration tools (e.g.,
Microsoft Teams) for critical
updates. This multi-channel
reporting ensures stakeholders
receive timely, accurate
information to manage business
continuity effectively

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
Access to management
interfaces is restricted using
role-based permissions and
multi-factor authentication. Only
authorised users, such as
administrators, can access
sensitive settings. Support
channels require user
verification before discussing
account-specific information. All
access is logged and regularly
reviewed to ensure compliance
and prevent unauthorised
changes
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users receive audit information on a regular basis
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users receive audit information on a regular basis
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We follow robust information
security policies aligned with
ISO 27001 and Cyber
Essentials+ standards. Our
policies cover data protection,
access control, incident
management, and regular risk
assessments. All staff receive
mandatory security training and
must adhere to strict
confidentiality and acceptable
use guidelines. Our reporting
structure includes a designated
Information Security Officer
responsible for policy oversight,
incident response, and regular
audits. Security incidents are
reported immediately to the
Information Security Officer,
who coordinates investigation,
remediation, and
communication with
stakeholders. Regular internal
audits and external
assessments ensure
compliance and continuous
improvement. We enforce
policies through technical
controls such as role-based
access, encryption, and multifactor authentication. Policy
updates are communicated
promptly, and compliance is
monitored via automated tools
and periodic reviews. Any
breaches or non-compliance are
addressed through corrective
actions and additional training
as needed. We maintain clear
documentation of all policies
and procedures, which are
reviewed and updated annually
or in response to significant
changes. This comprehensive
approach ensures that
information security is embedded in our culture and
operations, protecting client
data and maintaining trust at all
times.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
We maintain a CMDB and
version-controlled
Infrastructure-as-Code (IaC) for
all components, ensuring
traceability from requirement to
deployment. Hardened
baselines (e.g., CIS
Benchmarks) are enforced, and
all changes undergo automated
validation, including linting,
SAST, policy-as-code, and
compliance checks in preproduction. Approved changes
are deployed via CI/CD
pipelines with MFA-protected
approvals and least privilege
service principals. Drift
detection alerts on unauthorised
changes, with remediation or
reconciliation into code. Security
impact is assessed through
dependency scanning,
container image checks, and
runtime hardening. Audit logs and compliance reports are
retained and reviewed regularly
to maintain secure, verifiable
baselines.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We use Microsoft Defender for
Cloud and XDR for continuous
vulnerability scanning across
VMs, containers, and PaaS
services, integrated with MDVM
for endpoints. Threats are
assessed using CVSS scores,
exploitability, and business
context, prioritised via Secure
Score. Patches for critical
vulnerabilities are deployed
within 24–48 hours; high
severity within 7 days. Threat
intelligence is sourced from
Microsoft feeds, industry
advisories, and NCSC
guidance. Automated
remediation enforces policies
and hardening, with emergency
changes following expedited
approvals. All actions are
logged in ITSM, reported
monthly, and aligned with CSA
CCM v4.0 and SSAE‑18 for
compliance and audit evidence.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We continuously monitor
systems, networks, and
identities using Microsoft
Defender for Cloud, XDR, and
Sentinel SIEM. Potential
compromises are identified
through real-time alerts, threat
intelligence feeds, and
behavioural analytics. High-risk
incidents trigger automated
containment actions such as
device isolation and account
lockout. All alerts are triaged by
our SOC, which operates 24/7
or agreed hours, with critical
incidents responded to within
one hour. Investigations include
root cause analysis and
evidence collection for
compliance. Activities are
logged, retained, and reported
monthly, including MTTD and
MTTR metrics. Our approach
aligns with SSAE‑18 and CSA
CCM v4.0 for audit and
governance
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We operate pre-defined
processes for common events,
aligned with ISO 27001 Annex
A.16. Incidents are detected via
automated alerts from Microsoft
Defender and Sentinel, or
reported manually through ITSM
(ServiceNow/Jira). Incidents are
categorised by severity, driving
response SLAs (e.g., Critical:
immediate, High: within 4
hours). Our SOC provides 24/7
monitoring and escalation
support. Investigation includes
triage, containment (e.g., device
isolation, credential revocation),
and forensic evidence
collection. Incident reports detail
root cause, impact, and
corrective actions, shared with
stakeholders post-resolution. All
incidents are logged, retained
for audit, and reviewed to
improve detection and
response.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
NQA
ISO/IEC 27001 accreditation date
Monday 8 April 2024
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
NQA
ISO 9001 accreditation date
Monday 8 April 2024
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
SecurityMetrics
PCI DSS accreditation date
Friday 10 January 2025
What the PCI DSS doesn’t cover
N/A
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
E9fd5f85-7cd1-4ff2-aba9-6f9f5f225b1b
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
181966c9-f0aa-42ed-9271-d1b111bdf43b
Other security certifications
Yes
Any other security certifications
Security Standards dependant on the vendor solution

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at psitq@softcat.com. Tell them what format you need. It will help if you say what assistive technology you use.