Managed Zero Trust Network Access (ZTNA)
SNO’s Managed Zero Trust Network Access (ZTNA) service provides secure, identity-driven access to applications and services without exposing the underlying network. Designed for organisations adopting cloud services, hybrid working and modern security architectures, it replaces traditional perimeter-based access with a zero-trust model, delivering a resilient, secure solution for any organisation.
Features
- Identity-driven access control for applications and services.
- Continuous device posture and user verification before access granted.
- Least-privilege, role-based access enforcement.
- Application-level segmentation preventing lateral movement.
- Centralised policy management and enforcement dashboard.
- Secure remote and hybrid workforce access.
- Integrated security controls during access workflow.
- Real-time monitoring, alerts, and automated risk response.
- Full lifecycle management of users, devices, and applications.
- Audit-ready reporting with compliance visibility.
Benefits
- Improve security by enforcing least-privilege, identity-based access.
- Reduce risk of lateral attacks across internal systems.
- Simplify remote access for hybrid and distributed workforce.
- Centralise policy management for consistent governance across organisation.
- Maintain compliance with auditable access logs and reporting.
- Quickly revoke or adjust access in real time.
- Enhance operational efficiency with automated access enforcement.
- Reduce network exposure while enabling cloud application adoption.
- Minimise administrative burden with fully managed ZTNA service.
- Increase resilience with always-on access and failover support.
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 3 7 1 0 5 5 1 6 4 0 7 7 2 1
Contact
SPECIALIST NETWORK OPERATIONS LIMITED
Russell Bristow
Telephone: 07970319563
Email: sales@sno.cloud
About your service
- Service categories
-
Systems Infrastructure Software
Security
Identity and access management
- Access
- Privilege
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- SNO's Managed ZTNA service can extend existing identity and access management systems, endpoint security platforms, network security tools and IT service management solutions. It integrates seamlessly with cloud applications, on-premises services and hybrid IT environments to enforce consistent access policies, continuous verification and secure, least-privilege application-level access.
- Cloud deployment model
- Hybrid cloud
- Service constraints
- SNO's Managed ZTNA service requires supported client software or devices to enforce access policies effectively. Integration with existing identity, endpoint or network platforms may require configuration based on the buyer’s environment. Planned maintenance or updates may occasionally result in brief service interruptions, communicated in advance. Access performance depends on network connectivity and device compliance. While the service is designed to support multi-cloud and hybrid environments, specific integrations or custom workflows may require scoping and agreement. Buyers should ensure their applications and user devices meet minimum requirements for secure access enforcement and continuous verification.
- System requirements
-
- Supported operating system on user devices (Windows, macOS, Linux).
- Compatible web browser for portal-based access and administration.
- Minimum hardware specifications for client software performance.
- Active identity and access management accounts for user authentication.
- Endpoint security or anti-virus installed on all user devices.
- Reliable internet or WAN connectivity for access and policy enforcement.
- Network ports and protocols open for ZTNA client communication.
- VPN or proxy configuration disabled if conflicting with ZTNA client.
- Administrative privileges on devices for initial client installation.
- Regular software updates applied for operating system and client.
User support
- Email or online ticketing support
- Yes
- Support response times
- We respond to support questions within 1 business hour during standard business hours, Monday to Friday. Outside of business hours and at weekends, responses are typically provided within 4 hours for standard requests. Critical or high-severity issues are monitored 24/7 and receive an initial response within 30 minutes, including weekends and public holidays.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We provide tiered support levels designed to meet different operational and business requirements. Standard Support is included in the service price and provides 24x7x365 monitoring, incident detection, alerting and response via email and ticketing. It includes access to our Security Operations Centre (SOC) and defined SLAs for incident acknowledgement and resolution. Enhanced Support is available at an additional cost and includes faster response SLAs, 24x7 phone support, priority incident handling and expanded reporting. Customers are assigned a named Technical Account Manager (TAM) who acts as the primary point of contact for service reviews, operational guidance and escalation management. Premium Support is offered at an additional cost and provides dedicated engineering engagement, proactive threat hunting, custom playbooks, regular security posture reviews and optional onsite support. Premium customers receive direct access to a named Cloud Support Engineer and senior security specialists. Pricing for enhanced and premium support tiers is based on service scope, environment size and SLA requirements and is agreed contractually.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We help users start using the Managed ZTNA service through a structured onboarding and training process. Each customer is provided with detailed user and administrator documentation, including step-by-step guides for installing clients, registering devices, accessing applications and managing sessions.
For administrators, we provide online training sessions covering policy configuration, role-based access management, reporting and integration with identity and endpoint security platforms. Onsite training can also be arranged for larger deployments or where additional guidance is required. Training materials include interactive guides, reference manuals and video tutorials to support different learning styles.
During onboarding, our team assists with user and device registration, policy setup and integration with existing IT systems. We provide support via our 24/7 Service Desk for any initial technical questions and our Service Delivery Managers guide administrators through best practices for policy enforcement, security monitoring and audit readiness.
Ongoing support includes access to knowledge bases, FAQs and scheduled reviews to ensure policies remain optimised and aligned with organisational needs. This approach ensures users quickly become confident in using the service, while administrators can efficiently manage secure, least-privilege access across all applications, devices and locations. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of a contract, users can extract their data from the Managed ZTNA service through secure, structured export processes. All user, device, application and access policy data is retrievable in standard, machine-readable formats such as CSV or JSON. Audit logs, reporting data and configuration information can also be exported to support compliance, record-keeping or migration to another service.
Our team works closely with the customer to plan and execute data extraction, ensuring integrity, completeness and security throughout the process. Data is delivered via encrypted transfer, secure download links, or integration with the customer’s existing IT systems, depending on the organisation’s preference and policies.
Following extraction, SNO securely deletes all remaining customer data from our systems in accordance with contractual obligations and data protection regulations. Documentation and guidance are provided to ensure customers can effectively access and interpret exported data.
This approach ensures a smooth transition at contract end, maintaining business continuity, compliance and audit readiness while protecting sensitive information throughout the process. - End-of-contract process
-
At the end of the contract, SNO works with the customer to ensure an orderly transition or termination of the Managed ZTNA service. This includes secure extraction of all user, device, application, policy and reporting data in standard formats, guidance on interpreting exported data and support for migration to another service if required. Following data extraction, all remaining customer data is securely deleted from SNO systems in line with contractual obligations and data protection regulations.
The contract price includes full access to the Managed ZTNA service for the agreed term, including design, deployment, configuration, policy management, monitoring, incident management, reporting and user support. It also covers end-of-contract data extraction, secure deletion and standard transition assistance.
Additional costs may apply for optional services such as onsite training, custom integrations with third-party platforms, extended data retention, emergency policy changes, or bespoke reporting beyond the standard service offering. All optional services are agreed in advance and priced separately to ensure transparency.
This approach ensures continuity, compliance and security throughout the lifecycle of the service, including contract conclusion, while clearly defining what is included and any optional costs. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile and desktop versions of SNO's Managed ZTNA service provide the same core functionality, including identity-driven access, continuous device verification and policy enforcement. Mobile clients are optimised for smaller screens and intermittent connectivity, supporting secure access on-the-go. Desktop clients offer broader administrative capabilities, integration with endpoint security and access to legacy or complex applications requiring full operating system support. Both platforms enforce least-privilege, application-level access and integrate with centralised policy management, reporting and audit workflows. Any differences are primarily in user interface and device-specific optimisations, while access control, security and compliance capabilities remain consistent across mobile and desktop.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- SNO's Managed ZTNA service provides a web-based interface for administrators and users. Administrators can configure and enforce access policies, monitor user activity, generate reports and manage incidents. Users access applications, manage sessions and receive notifications through a clean, intuitive interface. The interface supports role-based access, centralised policy visibility and audit-ready reporting. Both desktop and mobile versions provide consistent functionality, while optimisations for device type ensure usability and efficiency. The interface is designed to be simple, responsive and secure, allowing seamless operation across supported browsers and devices without compromising zero-trust enforcement.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have conducted structured accessibility testing using screen readers, keyboard navigation and voice control tools to ensure the interface is usable by individuals with disabilities. Key workflows, such as user authentication, application access, session management and administrative reporting, were tested with assistive technologies to identify barriers and improve navigation, focus order, and semantic HTML structure. Feedback from test users guided adjustments to colour contrast, tab navigation, form labelling and alert visibility. We perform periodic accessibility reviews as part of interface updates to maintain compliance with WCAG 2.2 AA standards. Any changes that impact accessibility are documented, and regression testing is conducted to confirm continued usability. Users with assistive technology receive the same secure, continuous verification and access controls as all other users, ensuring consistent security and functionality without compromising accessibility.
- API
- Yes
- What users can and can't do using the API
-
SNO's Managed ZTNA service API allows authorised users to programmatically manage access policies, users, devices and applications. Users can set up the service by onboarding new users and devices, defining role-based access policies and integrating with identity or endpoint management systems. Through the API, users can update access rules, revoke or grant permissions and retrieve activity logs and reporting data. Limitations include restricted access to core platform configurations and administrative settings, which are only configurable through the service interface by SNO administrators to maintain security and compliance. Certain high-impact changes, such as modifying default security policies or global enforcement rules, require approval and cannot be performed directly through the API.
The API is secured with authentication and role-based access, ensuring users can only perform actions aligned with their permissions. All changes made via the API are logged and auditable for compliance purposes. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customise the Managed ZTNA service through configurable policies and workflows. Customisation includes application-specific access rules, role-based permissions, device posture checks, contextual access conditions (such as location or behaviour), alerting thresholds and reporting dashboards. Users can also integrate the service with existing identity, endpoint security, or IT service management platforms to align access workflows with organisational processes.
Customisation is performed through the service interface or via the API, depending on the task. Administrators can define and update access policies, assign roles, manage user and device onboarding/offboarding and configure alerts. Changes are logged and auditable to maintain compliance.
Who can customise is role-based: only authorised administrators or delegated policy managers can make changes to access rules or system integrations, while standard users can manage their own sessions, device registrations and multi-factor authentication settings within the limits of their permissions. All customisations are centrally enforced in real time, ensuring consistent zero-trust access across the organisation, while expert SNO support provides guidance and oversight to ensure secure and compliant configurations.
Scaling
- Independence of resources
- SNO's Managed ZTNA service is designed with a resilient, multi-tenant architecture that isolates user and organisational workloads. Resource allocation, session management and policy enforcement operate independently for each customer, ensuring no single user or organisation can impact others. Active-active underlay connections, load balancing and automated failover maintain consistent performance and availability. Capacity planning and continuous monitoring detect and mitigate potential congestion before it affects users. This approach guarantees predictable access, consistent policy enforcement and uninterrupted service regardless of demand from other users, supporting secure, reliable operations for all organisations.
Analytics
- Service usage metrics
- Yes
- Metrics types
- SNO provides metrics on access events, policy enforcement, user and device activity, authentication successes and failures, session duration, incident response times, SLA adherence and trend analysis. Metrics also cover policy changes, device posture compliance and reporting on anomalous behaviour or access violations. These metrics help organisations monitor security, ensure compliance, optimise access policies and maintain visibility into service performance.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Fortinet's ZTNA service
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data from the Managed ZTNA service via secure, structured export processes. This includes user accounts, devices, applications, access policies, audit logs and reporting data. Data can be exported in standard machine-readable formats such as CSV or JSON, either through the service interface, the API or via secure transfer provided by SNO. Exports are encrypted during transfer to ensure confidentiality and integrity. Guidance and documentation are provided to help users interpret the data. This approach ensures users retain full access to their information for compliance, audit or migration purposes.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
SNO's Managed ZTNA service is designed for high availability and resilience, with redundant access enforcement points, active-active WAN connectivity and automatic failover to ensure continuous access for users. We guarantee 99.9% service availability as part of our Service Level Agreement (SLA). This availability is measured across all access events and service components, ensuring users can reliably access applications without interruption.
In the event that availability falls below the SLA, customers are eligible for service credits or refunds proportionate to the duration and impact of the downtime, as defined in the SLA. All incidents are logged, tracked and reviewed, with root cause analysis provided for high-impact outages.
Availability is supported by continuous monitoring, capacity planning and proactive incident management. Planned maintenance is communicated in advance and scheduled to minimise disruption. Redundant architecture and automated failover mechanisms ensure that users’ access is maintained even during component failures, network interruptions or maintenance windows.
This approach ensures reliable, resilient and predictable access to applications while providing transparent accountability through SLAs and remediation for any shortfalls. - Approach to resilience
-
SNO's Managed ZTNA service is designed for resilience and continuity of operations, ensuring secure access to applications even in the event of infrastructure, network or component failures. The service is deployed across redundant, geographically dispersed data centres operated by certified third-party providers. These facilities comply with recognised security and resilience standards, including CSA CCM v4.0 and ISO/IEC 27001, ensuring both physical and environmental protections.
Access enforcement points, WAN connections and policy engines operate in an active-active configuration, allowing automatic failover if any component becomes unavailable. Load balancing, capacity planning and continuous monitoring ensure consistent performance, even during peak demand. Planned maintenance is scheduled with minimal disruption and users are notified in advance.
Critical data and configurations are replicated securely between data centres to prevent data loss and disaster recovery procedures are tested regularly to ensure rapid restoration of service. Incident response and business continuity plans are embedded within operational processes to maintain service levels and security controls during unexpected events.
Detailed resilience information, including architecture diagrams and recovery procedures, can be provided to customers on request. This approach aligns with the government’s 2nd cloud security principle, “Asset protection and resilience,” ensuring high availability, secure access and predictable operations. - Outage reporting
-
SNO's Managed ZTNA service provides transparent outage reporting to ensure customers are informed of any disruptions. All incidents are logged and tracked through SNO’s central Service Management platform.
Customers receive notifications through multiple channels depending on severity and impact:
1.) Email alerts for immediate notification of service-impacting incidents.
2.) Service Desk updates with incident status, expected resolution times, and post-incident analysis.
3.) Public-facing status dashboards may be provided to display ongoing service health and uptime trends.
4.) API access is available for integration with customer monitoring systems, allowing automated retrieval of incident and performance data.
Each outage report includes the incident description, affected services, resolution progress and root cause analysis for high-impact events. Lessons learned are documented and used to refine policies, access controls and resilience procedures.
This multi-channel reporting approach ensures that organisations have real-time visibility, maintain operational awareness and can respond appropriately during outages. It also supports audit readiness, compliance requirements and transparency for both internal stakeholders and external regulators.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is strictly controlled and role-based. Only authorised personnel, including Service Delivery Managers, Technical Account Managers and NOC engineers, are granted access, aligned with least-privilege principles. Authentication is enforced using multi-factor authentication (MFA) and identity federation where applicable. Administrative actions and support requests are logged, monitored and audited to ensure accountability and prevent unauthorised changes. Access policies are reviewed regularly and updated through formal change management procedures. Temporary or emergency access is granted only via documented approvals and automatically revoked after the task, ensuring secure and auditable management of the service.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
SNO follows a comprehensive set of information security policies and processes aligned with ISO/IEC 27001 and CSA CCM v4.0 standards. Policies cover access management, device posture enforcement, network and application security, incident response, change management, configuration management, data protection and user onboarding/offboarding.
The organisation maintains a structured reporting hierarchy: the Security Officer oversees adherence to policies, while Service Delivery Managers, Technical Account Managers and NOC Team Leads ensure operational compliance. All staff are trained on security policies and responsibilities are clearly defined, with escalation paths for incidents or policy breaches.
Compliance is enforced through automated monitoring, periodic audits and regular reviews. Policy adherence is tracked via the Service Management platform, which logs changes, incidents and access events. Deviations or security events trigger investigation, remediation and lessons-learned reviews, ensuring continuous improvement.
Formal change management and configuration management processes ensure all modifications to access policies, enforcement rules or system configurations are documented, assessed for risk and approved before implementation.
This structured approach ensures policies are consistently applied, security risks are mitigated and access remains secure and auditable, supporting both operational resilience and compliance with government and industry standards. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- SNO manages all service components through a formal configuration and change management framework. Each component, users, devices, applications, access policies is tracked throughout its lifecycle, with secure versioning and documentation. Changes are assessed for risk and potential security impact before approval, including operational, compliance and access implications. All modifications are logged, centrally managed and monitored for unauthorised changes. Post-implementation reviews and audits ensure policies remain effective and lessons learned are incorporated into continuous improvement. This approach guarantees secure, predictable, and auditable service operation, supporting operational security, compliance and resilience throughout the lifecycle of the Managed ZTNA service.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- SNO follows a structured vulnerability management process to protect the Managed ZTNA service. Potential threats are assessed through automated vulnerability scans, penetration testing and monitoring of security advisories from industry sources, government alerts and vendor notifications. Identified vulnerabilities are risk-assessed based on potential impact and likelihood. Patches and mitigations are deployed promptly according to severity, following formal change management procedures to ensure stability and compliance. Ongoing monitoring validates patch effectiveness and detects emerging threats. Lessons learned are fed back into policies and procedures to continuously improve the security posture and resilience of the service.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- SNO employs continuous protective monitoring across the Managed ZTNA service to detect potential compromises. Telemetry from user sessions, device posture checks, access events and policy enforcement is analysed in real time using automated alerts and anomaly detection. When a potential compromise is identified, alerts are immediately escalated to the NOC and Service Delivery teams, who investigate, contain and remediate the issue according to formal incident response procedures. High-severity incidents are responded to within 30 minutes, with full root cause analysis provided within seven days. Lessons learned are incorporated into policy updates and preventative controls.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- SNO follows pre-defined incident management processes aligned with ISO/IEC 27035:2011 and CSA CCM v4.0. Common events, such as access violations or service disruptions are handled through structured workflows with clear escalation paths. Users report incidents via the Service Desk, email or portal, providing a single point of contact. Each incident is logged, assigned to a Service Delivery Manager or NOC Team Lead and investigated promptly. Customers receive regular status updates during resolution and a full post-incident report, including root cause analysis and remedial actions. Lessons learned are incorporated into policies to prevent recurrence.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- 3Core2
- ISO/IEC 27001 accreditation date
- Thursday 18 July 2024
- What the ISO/IEC 27001 doesn’t cover
- Cover SNO Network Operations Centre in the UK only. Does not cover other parts of the business such as Finance, PMO, US NOC, Sales, Business Operations
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- 3Core2
- ISO 9001 accreditation date
- Wednesday 18 September 2024
- What the ISO 9001 doesn’t cover
- Cover SNO Network Operations Centre in the UK only. Does not cover other parts of the business such as Finance, PMO, US NOC, Sales, Business Operations
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 3acf591d-7c54-4ff6-976e-3754609672c6
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 14001:2015
- ISO 20000:2015
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-