Bitdefender GravityZone Endpoint Security Platform
A unified cybersecurity platform and services portfolio. Bitdefender GravityZone delivers multi-layered prevention/detection/response for endpoints/servers/cloud and virtual workloads/email/and mobile devices from a single console and single agent. Leverages advanced AI/ML, behavioural analytics, and global threat intelligence, and integrates capabilities such as EDR/XDR/risk analytics and hardening/patch management/full disk encryption/CSPM+/email security, (MDR).
Features
- Single console and agent for all enterprise assets.
- next-gen AV, behavioral analysis, exploit, ransomware, network protection.
- rich telemetry, incident correlation, root-cause investigation, guided remediation
- correlates endpoints, network, identity, cloud to surface advanced attacks.
- patching, encryption, device, application, content control, exposure reduction.
- tuned engines minimizing impact on servers, VMs, containers, workloads.
- spam, malware, URL analysis, sandboxing, O365 and Exchange integration.
- Android, iOS, Chromebook protection integrated with existing MDM/UEM platforms.
- 24x7 monitoring, threat hunting, alert triage, containment, expert guidance.
- connect SIEM, SOAR, ITSM, export telemetry/incidents for SOC operations.
Benefits
- multilayer, AI-driven protection.
- Consolidate multiple tools into one platform
- Automate threat detection and response workflow
- Accelerate incident triage and remediation
- Centralize policy management and reporting
- Optimize system performance so users stay productive
- Automate patching and risk remediation
- Provide clear, actionable dashboards that help teams prioritize
- Reduce false positives so analysts focus on real threats
- Enable rapid ransomware containment and recovery
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 8 6 3 5 0 2 4 9 3 3 5 4 5 4
Contact
PHOENIX SOFTWARE LIMITED
Mark Pickersgill
Telephone: 01904 562200
Email: bids@phoenixs.co.uk
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI life cycle
- Trustworthy AI Software
AI software services
- Anomaly Detection AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
-
Bitdefender GravityZone/associated business security services are not built as an extension of a single third‑party product, but provide native integrations, acting as an extension to existing enterprise platforms/tools, including:
Identity/Directory services:
Virtualization, VDI and HCI platforms:
Public cloud/IaaS and cloud‑workload platforms:
Container and cloud‑native platforms:
Backup/storage:
SIEM/analytics:
RMM and PSA/ITSM - Cloud deployment model
- Public cloud
- Service constraints
- Yes. Bitdefender services have some constraints and dependencies that buyers should be aware of. These constraints are typical of the Bitdefender GravityZone and MDR/XDR ecosystem and can generally be addressed through correct sizing, licensing, architecture, and policy design.
- System requirements
-
- Management console (GravityZone)
- Endpoint protection agents (Bitdefender Endpoint Security Tools)
User support
- Email or online ticketing support
- Yes
- Support response times
-
• Product / self-service questions: GravityZone is a cloud-delivered console and integrates with Bitdefender’s online documentation and knowledge base. Console views, searches, and help/KB queries typically return results within a few seconds under normal network conditions, with content delivered in real time from Bitdefender’s back-end services (no formal per-query latency SLA is published).
• Technical support questions: For standard support, target first-response times are:
– Severity 1 (Critical): within 2 hours
– Severity 2 (Major): within 8 hours
– Severity 3 (Minor/Minimal): within 24 hours
– Severity 4 (Trivial / information requests): within 48 hours - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
"Bitdefender provides a live web chat channel as part of the Enterprise Support Center, exposed via a chat widget on the public Support Center pages and used for non‑critical issues. It is available in English on a 24x7, best‑effort basis.
" - Onsite support
- Yes, at extra cost
- Support levels
-
1) Standard Support (all business customers)
- Scope: Included with valid Bitdefender business licenses (on‑prem and cloud). Covers product usage questions, troubleshooting, configuration guidance, and license issues.
- Availability: 24x7 technical support in English; localized language support in key regions during local business hours.
- Channels: Support portal (CustomerZone) for case management, documentation and KB; phone and email for incidents; web/in‑product forms and live chat for non‑critical issues.
2) Business / Enhanced Support
- Adds priority handling and improved SLAs over Standard.
- Dedicated or prioritized phone access.
- Enhanced remote assistance and case handling.
3) Enterprise Support
- Priority response and faster SLAs for high‑critical environments.
- Additional services such as routine health checks, configuration reviews, and remote training to optimize deployment and security posture.
4) Enterprise Plus / Premium Support
- Highest tier for mission‑critical customers.
- Includes a dedicated Technical Account Manager (TAM), proactive service management, regular service and case reviews (e.g., quarterly), and coordinated escalation into development for complex issues.
5) Professional Services (available with all levels as an add‑on)
- Deployment and migration services.
- Optimization and tuning services.
- Formal training for administrators and users.
- Security assessments and expert consulting. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
"Bitdefender helps users start using the service through structured onboarding, in‑product guidance, and included professional services.
For GravityZone and endpoint security, new customers receive console access and step‑by‑step onboarding materials guiding first login, 2FA/SSO configuration, license activation, and creation of initial security policies and deployment packages. Built‑in wizards help generate installers, choose modules (AV, EDR, ATS, etc.), and distribute agents, while default policies and preconfigured dashboards/reports provide immediate visibility and protection without complex setup.
MSP partners benefit from dedicated onboarding programs and documentation that cover portal access, customer company creation, license provisioning, and best practices for multi‑tenant management.
For MDR/XDR services, onboarding includes professional services that assist with agent deployment, MDR portal configuration, definition of emergency contacts and escalation workflows, and validation of coverage across the environment. The MDR team reviews prerequisites with the customer and guides them through configuration so the service can be safely and quickly put into production.
Across all services, Bitdefender supplements onboarding with online documentation, feature‑specific deployment guides, and ongoing training/awareness so administrators can operate the platforms securely and effectively." - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
• During the contract: Customers can export logs, incidents, alerts, reports and configuration data directly from the GravityZone console (e.g., CSV/PDF reports, usage reports, incident listings). Where configured, they can also continuously forward raw EDR/XDR data to external systems (SIEM/SOAR, syslog, data lakes) and thus keep their own full history.
• GravityZone data at/after expiry: Data remains available in GravityZone only within the product’s defined retention windows (for example, incidents/alerts typically 90 days, notifications up to 365 days, reporting data 2 years, sandbox reports up to 2 years depending on configuration, mobile security console data contract + 60 days, etc.). Customers are expected to export or forward the data they need via the console and integrations while licenses and access are active and before those retention periods elapse.
• MDR service data at/after expiry: For Bitdefender MDR, customers can self‑export investigation and SOC data via the MDR Portal during the contract and for 30 days after contract end. After that grace period, customer portal access is removed, but MDR SOC objects remain retained (e.g., up to 3 years for investigations and related objects, 180 days for telemetry). - End-of-contract process
-
"At the end of the contract (license/subscription expiry), Bitdefender stops providing the licensed services and access to paid features, and your environment gradually loses the associated protections and advanced capabilities.
In summary, when the contract ends and the license is not renewed, service delivery ceases, and your data remains only for the documented technical and legal retention periods, after which it is automatically and/or manually deleted in line with Bitdefender’s retention policies, internal cleanup procedures, the EULA/DPA, and applicable privacy laws." - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Other
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
On desktops and laptops, Bitdefender offers full endpoint protection and EDR/XDR platform managed in GravityZone Control Center. It provides next‑generation antimalware with on‑access and on‑demand scanning, exploit and ransomware protection, firewall and network controls, device control, application control, and deep EDR/XDR telemetry and response.
On mobile devices Bitdefender delivers a cloud‑based Mobile Threat Defense (Security for Mobile/Mobile Security) solution. It focuses on mobile‑specific risks: malicious or high‑risk apps, OS compromise, OS vulnerability exposure, mobile phishing and web protection, app‑centric risk and compliance assessment, and mobile‑oriented forensics and threat hunting. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Bitdefender delivers its services primarily through the GravityZone platform, which provides both graphical and programmatic interfaces.
GravityZone Control Center is a secure, web-based management console available as Bitdefender-hosted SaaS or as an on-premises virtual appliance. It acts as a single pane of glass to deploy and manage security for any number of endpoints and workloads. Through the console, administrators access dashboards, incident and threat views, policies and configuration profiles, risk and inventory views, reporting, and add-on modules (e.g., Email Security, Mobile Security). Multi-tenancy is native: partners and MSPs can manage multiple customer “companies” from a single interface with delegated administration. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
"Bitdefender does not publish evidence of formal interface testing specifically conducted with users of assistive technologies, and the available documentation does not describe such studies, methods, user groups, or outcomes.
What we can state based on current sources is:
- For GravityZone Control Center, Bitdefender documents that the UI is designed with Web Content Accessibility Guidelines (WCAG) 2.2 in mind and targets AA conformance, and that it includes accessibility‑oriented UI options such as dark and high‑contrast themes and the ability to follow system theme settings.
- For other products (e.g., Bitdefender Endpoint Security Tools), documentation mentions features such as following system light/dark mode but does not describe explicit assistive‑technology testing." - API
- Yes
- What users can and can't do using the API
- Bitdefender GravityZone provides a JSON-RPC 2.0 API that allows automation of security workflows, integration with SIEM tools, and retrieval of reports or event data. You can interact with it using HTTPS POST requests authenticated via an API key. Users may fully use the officially documented Bitdefender APIs to automate and integrate all exposed functions, within their role and license, but may not exceed those documented capabilities, bypass security or access controls, abuse the service (e.g., via rate‑limit violations), or perform any non‑documented or unlawful operations via the API.
- API documentation
- Yes
- API documentation formats
-
- HTML
- ODF
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Policy-based configuration: Administrators define granular policies for antimalware, firewall, network/content control, device control, risk management/PHASR, patch management, full disk encryption, email and storage security, etc.
• Flexible assignment and structure: Policies are assigned using user rules, location rules, and dynamic tags, so different configurations can automatically apply to servers vs. workstations, BUs, sites, or risk profiles. Tenants/companies and folders allow strong separation between environments or customers.
• Console, access and operations: Customers customize user roles and permissions, SSO/SAML login, 2FA, notification rules, update rings, and lifecycle options. This lets each operator see and manage only the relevant entities.
• Detection, response and MDR/MXDR: For EDR/XDR and MDR/MXDR tenants, customers can tune policies, sensor coverage, and automated response actions; MDR/MXDR engagements additionally tailor runbooks, escalation paths and response authority during onboarding.
• Dashboards and reporting: GravityZone dashboards and reports are configurable by scope, time range, severity, and module, and can be scheduled for different audiences.
• APIs and integrations: The GravityZone Public API exposes full control over policies, tasks, companies, endpoints and reporting, enabling policy‑as‑code, automation and integration with external systems. The Event Push API and Security Telemetry allow streaming events and raw telemetry to SIEM/SOAR/ITSM platforms.
Scaling
- Independence of resources
-
Bitdefender’s SaaS services are designed so that one customer’s load does not materially degrade service for others through a combination of architecture, capacity management, and operational controls.
Taken together—multi‑instance/load‑balanced architecture, horizontally scalable cloud infrastructure, anti‑storm and optimization mechanisms, local update/traffic distribution, and formal capacity and continuity management—these controls ensure that demand generated by some customers does not adversely affect the performance or protection provided to others.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
• 24x7x365 coverage: Continuous monitoring/detection/response from global SOCs operating in a follow‑the‑sun model.
• Critical/High incident notification time: For MDR, our SOC notifies the customer of critical and high‑severity incidents within 30 minutes.
• Post‑incident monitoring: After a significant incident, MDR performs enhanced monitoring for 72 hours.
• Threat hunting cadence: Targeted threat hunting is conducted for MDR customers on a recurring basis.
• Reporting metrics: MDR provides dashboards and periodic reports (operational and executive).
Internal service and continuity metrics relevant to service delivery:
• Recovery Time Objectives (RTOs) for critical systems:
• Incident response performance: - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller (no extras)
- Organisation whose services are being resold
- Bit Defender
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
"Beyond the core security functions, Bitdefender protects data at rest through multiple additional layers:
• Endpoint full‑disk encryption (GravityZone Full Disk Encryption)
• Centralized key management and recovery ensure that disk‑encryption recovery keys are stored securely in the GravityZone console, with controlled administrative access and dedicated recovery workflows for lost/stolen devices.
• Strong internal cryptographic standards mandate AES‑256 for data‑at‑rest (with GCM preferred), use of validated KMS/HSMs, and at‑rest encryption for sensitive database fields and storage back‑ends (e.g., EBS with AWS KMS, LUKS‑based storage encryption).
• Role‑based access control (RBAC)
• Encrypted backups
• Formal encryption and key‑management policies (IS110/IS111) - Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
Data importing and exporting
- Data export approach
- Not relevant to the Bitdefender Service.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Security Data Lake / MDR / XDR telemetry
- Threat Intelligence (Operational TI Feeds)
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Security Data Lake / MDR / XDR telemetry
- Threat Intelligence (Operational TI Feeds)
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
"Bitdefender guarantees a 99.9% uptime SLA for the GravityZone Cloud management console, excluding planned maintenance windows that are communicated in advance. Endpoint protection continues to operate locally even if the console is temporarily unavailable.
For support availability, Bitdefender provides 24x7 technical support in English for business products, with standard target response-time SLAs of 2 hours (Severity 1 – Critical), 8 hours (Severity 2 – Major), 24 hours (Severity 3 – Minimal), and 48 hours (Severity 4 – Trivial). Higher service levels can be provided through optional Enterprise Premium Support packages under separate commercial terms.
Internally, Bitdefender’s Business Continuity Plan classifies GravityZone Cloud as a highly critical service with a very short recovery time objective, and uses redundant cloud infrastructure (e.g., GCP/AWS) and tested BC/DR processes to support the external availability commitments." - Approach to resilience
-
GravityZone Cloud is hosted on leading public cloud providers (primarily Google Cloud Platform and Amazon Web Services) using multi-region, highly available architectures. GravityZone management consoles are deployed in paired main/backup regions per geography (e.g., Germany/Netherlands for Europe; N. Virginia/South Carolina for Global; Singapore/Melbourne for APAC), leveraging tier‑1 datacenters, multiple availability zones, redundant networking, storage, and compute. Bitdefender offers a 99.9% uptime SLA for the GravityZone Cloud console (excluding planned maintenance), and availability and performance are continuously monitored.
Resilience is embedded at both the management and enforcement layers. The management plane (GravityZone console) is separated from the enforcement plane (endpoint and workload agents). Endpoint agents and security components (including Security Virtual Appliances, security servers for cloud workloads, and container security components) continue to enforce policies and provide full local protection even if the console is temporarily unreachable. In virtualized and cloud environments, centralized scanning services are deployed with built‑in high availability and load distribution; if a given scanning appliance or server becomes unavailable, agents automatically fail over to alternative appliances or revert to full local scanning, avoiding single points of failure.
Bitdefender’s internal Business Continuity Plan identifies GravityZone Cloud and related backend systems (licensing, update infrastructure, etc.). - Outage reporting
-
"Bitdefender reports service outages through a combination of public status pages and direct customer notifications.
For our cloud services, including GravityZone, we maintain a dedicated public status page (for example, status.gravityzone.bitdefender.com for GravityZone Cloud) where we publish real‑time information on service health, active incidents, and maintenance. When an outage or major service degradation is detected, an incident entry is created and updated on the status page with start time, scope (affected regions, products, and functions), symptoms, protection impact, and resolution details. After closure, a post‑incident summary is retained for transparency.
In parallel, administrators can receive notifications via in‑console messages and email. GravityZone includes a notifications framework that can alert designated admins about critical system or service events. During significant incidents, our Crisis/Incident Management processes ensure coordinated communication, and Customer Care keeps affected customers informed about impact and estimated recovery timelines.
Internally, outages are tracked and coordinated via our incident management tooling (Jira, dedicated outage channels, and runbooks), but externally, customers primarily see timely updates on the public status page and, where appropriate, targeted communications (for example, advisories or incident summaries) from Bitdefender."
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Users are authenticated to Bitdefender’s cloud services (e.g., GravityZone Control Center) using unique, individual accounts and strong, multi-factor–protected sign‑in over TLS.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Bitdefender solutions (including GravityZone and associated cloud and on‑premise services) operate under a formal, written Information Security Program governed by corporate information security policies and aligned with major industry standards and regulations (e.g., ISO/IEC 27001, SOC 2, HIPAA Security Rule, PCI‑DSS, NIST, CIS Controls, GDPR/NIS2).
At corporate level, Bitdefender maintains an Information Security Program Policy:
Security incident management is governed by the Bitdefender Security Incident Response Plan (IS051),
For GravityZone Cloud specifically, operational security processes include:
• SOC 2‑aligned controls for the multi‑tenant cloud platform, including encrypted storage of customer data on disks using AES‑256‑GCM with keys stored and periodically rotated in a cloud KMS.
• Additional application‑level encryption and hashing for sensitive data.
• Strict multi‑tenant segregation enforced in code and database queries, role‑based access control, and fine‑grained authorization checks on every console action.
• Formal user lifecycle and access management procedures for internal operators (Jira‑based request, approval, provisioning, de‑provisioning, and quarterly access reviews).
Across products, Bitdefender applies secure development and operational hardening practice. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
"Configuration management
Bitdefender maintains a formal System Configuration Management Policy that applies to all Bitdefender information systems and products.
For GravityZone specifically, configuration is implemented centrally and policy-based via the GravityZone Control Center. All endpoint/server protection settings (antimalware, firewall, device control, risk analytics, EDR/XDR, etc.) are defined in security policies and assigned to endpoints or groups.
In summary, configuration management is policy-driven, centralized and security-focused (with baselines, hardening and vulnerability management), while change management follows a documented, tool-supported lifecycle from request through assessment, implementation, testing, approval, controlled release, rollback planning and auditable documentation. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- "Bitdefender operates a layered protective monitoring model that combines continuous technical monitoring with formal internal processes for logging, analysis, and incident response.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Bitdefender operates a formal, documented Security Incident Management Policy and a Security Incident Response Plan (IS051), aligned with industry best practices. Incident management covers both internal Bitdefender information resources and, where applicable, customer environments under services such as Bitdefender MDR/MDR Plus.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Bitdefender operates a formal, documented Security Incident Management Policy and a Security Incident Response Plan (IS051), aligned with industry best practices. Incident management covers both internal Bitdefender information resources and, where applicable, customer environments under services such as Bitdefender MDR/MDR Plus.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
"The free trial runs for 30 days and typically includes:
EPP - Endpoint Protection
FDE - Full Disc Encryption
PATCH - Patch Management
SECURITY FOR STORAGE - Security for Storage
MTD - Mobile Threat Defense - Link to free trial
- Www.bitdefender.com/business/free-trials/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0.1%
- Between £250,000 and £500,000
- 0.2%
- Between £500,001 and £1,000,000
- 0.3%
- Between £1,000,001 and £2,500,000
- 0.4%
- Between £2,500,001 and £5,000,000
- 0.5%
- Over £5,000,001
- 0.6%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI Assurance UK Limited
- ISO/IEC 27001 accreditation date
- Thursday 21 January 2016
- What the ISO/IEC 27001 doesn’t cover
-
Our certificate applies to services including software licensing, hardware, software asset management (SAM), and IT consultancy. It covers these services when delivered to public sector, charities and housing associations, education, and corporate customers by our employees, systems, and business processes.
All activities outside of this scope are not covered by the certification. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI Assurance UK Limited
- ISO 9001 accreditation date
- Tuesday 23 November 2010
- What the ISO 9001 doesn’t cover
-
Our certificate applies to services including software licensing, hardware, software asset management (SAM), and IT consultancy. It covers these services when delivered to public sector, charities and housing associations, education, and corporate customers by our employees, systems, and business processes.
All activities outside of this scope are not covered by the certification. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Security Metrics via Self Certification
- PCI DSS accreditation date
- Wednesday 20 August 2025
- What the PCI DSS doesn’t cover
-
Our certificate applies to services including software licensing, hardware, software asset management (SAM), and IT consultancy. It covers these services when delivered to public sector, charities and housing associations, education, and corporate customers by our employees, systems, and business processes.
All activities outside of this scope are not covered by the certification. - Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 18c34a82-2bf3-4bf9-86c6-f489f07b37d6
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- F1e26d79-c268-4d22-a3d7-01e3f4c32c92
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-