Thales's Imperva Cloud Web Application Firewall (cWAF)
Imperva Cloud WAF protects websites and APIs from attacks like SQL injection, XSS, bots, DDoS, and offers protection against the OWASP top 10 threats. It uses machine learning, global threat intelligence, and flexible deployment options to block malicious traffic while ensuring performance, availability, and compliance for modern enterprises at scale.
Features
- Protects against OWASP WAF Top-10 threats, without impacting legitimate users
- Protects against OWASP Top-10 API threats, without impacting legitimate users
- Basic service mitigates 1000+ unique bot types over 14 categories
- Industry-leading AI-assisted advanced bot protection optionally available
- Consistently identified as a leader by multiple independent analyst reviews
- Provides critical infrastructural protection for large security-focused organizations globally
- Completely agnostic to application structure and payload size
- Single stack solution with all protection services in all PoPs.
- Multiple UK-based PoPs for traffic sovereignty isolation and resiliency
- Real-time reporting into dashboards with ML for contextual incident insights
Benefits
- Automatically protect applications from DDoS and OWASP Top 10 Threats
- Scalable cloud-based security without impacting application performance or adding latency.
- Real-time threat intelligence with contextual insights and AI explainability
- Centralized dashboard for simplified WAF management and policy automation capabilities
- High availability with 99.999% uptime through our global cloud infrastructure
- Managed ruleset by the Global Imperva SOC team
- 24/7 follow the sun support
- Accelerated time to value with simplified onboarding and terraform integrations
- Fast incident response through actionable alerts and contextual/forensic insights
- Protect applications whether they're cloud or on-prem.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 6 3 5 2 6 7 9 3 3 8 6 8 1 2
Contact
SOFTCAT PLC
Public Sector Tenders
Telephone: 01628 403403
Email: psitq@softcat.com
About your service
- Service categories
-
Systems Infrastructure Software
Security
- Cloud native application protection platform
- Endpoint security
- Security analytics
- Governance, risk and compliance
Identity and access management
- Access
- Privilege
Network security
- Trusted network access and protection
- Active application security
Data security
- Information protection
- Digital trust
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- No.
- System requirements
- Applications to be protected must be HTTP based
User support
- Email or online ticketing support
- Yes
- Support response times
-
Our support team has SLAs for tickets that are raised through our support portal.
SLAs are addressed beginning on page 5 of our Customer Support Guide, available here: https://docs.imperva.com/en-US/bundle/imperva-customer-support-guide/resource/imperva-customer-support-guide.pdf - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We offer four tiers of support and escalation. Tier 1 support handles initial support requests. Tier 2 support provides a higher level of expertise and product depth. Tier 3 escalations may involve consulting from our security operations team or network operations team. Tier 4 support includes our engineering and product development organizations. All support is facilitated by Imperva employees. In addition, we can provide, at an additional cost, operational support through a Technical Account Manager (TAM), who becomes familiar with your application and network implementation, internal processes, business and technical requirements, and change management procedures to help plan, deploy, and maintain your environment. Assigned TAMs are responsible for engaging our product development team members as needed. We also offer 24x7x365 technical support via phone, e-mail, and our Customer Support Portal. Our support organization is strategically deployed across the globe to ensure immediate and timely assistance for all Imperva products and solutions.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Imperva helps users onboard easily and efficiently to the platform through our well documented documentation portal and onboarding assistance provided by our Enterprise Services team, which is included in the cost. The user will also have access to online training seats and the Imperva community to further assist in the initial onboarding and ongoing management of the service.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Users can extract their data when the contract ends by utilizing the SIEM integration to extract security events and access logs. For configuration data, this can be extracted via Imperva API or Terraform integration.
- End-of-contract process
-
"As part of the contract, the end user will get the Imperva Cloud WAF with the aforementioned technical capabilities, but additional bandwidth and sites come at an additional cost, with sites and bandwidth being priced per unit. Total Bandwidth is calculated on clean bandwidth and on the 95 percentile, for additional detail, please see our documentation portal - https://docs-cybersec.thalesgroup.com/bundle/cloud-application-security/page/settings/account-bandwidth-calculation.htm
At the end of the contract, the service will be switched off, but prior to this point, the Thales renewals team would of been in touch with the user to discuss renewal options for the service. " - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The platform can adapt to display on any device.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The externally facing web interface offers users a self-service management portal with a homepage dashboard for quick visibility of protected assets. Through this portal, users can access services such as WAF (Dashboards, Policies), DDoS Protection, Advanced Bot Protection, Account Takeover Protection, Client-Side Protection, Attack Analytics, Reputation Intelligence, DDoS Protection for Networks, Individual IPs, and DNS. The portal enables configuration and monitoring, providing a single-pane-of-glass for managing security and operations. Users can interact via the UI, API calls, and Terraform, ensuring flexible management and integration options for various needs.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have conducted accessibility interface testing using a combination of evaluation methods and tools to ensure usability for users of assistive technology. Our evaluation methods include the use of screen readers, visual code inspection, manual interface and components analysis. For assistive technology specifically, we utilize VoiceOver on MacOS and test with the Chrome browser. Evaluation tools employed in our process include Equal Access Toolkit: Accessibility Checker, Axe DevTools extension for Chrome, Accessibility Insights for Web extension for Chrome and Edge Chromium, Colour Contrast Analyser from the Paciello Group, and the WCAG Contrast checker. Both automated and manual testing are performed to validate accessibility features.
- API
- Yes
- What users can and can't do using the API
- The user is able to deploy, configure, and manage the Imperva Cloud WAF through our available APIs and Terraform integration. Additional information is available through our documentation portal: https://docs-cybersec.thalesgroup.com/bundle/api-docs/page/api/api-overview.htm
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users can customize our service in several ways. They can configure customized response pages, including error responses, through the platform as described in the documentation. Policy Management enables users to centrally configure and manage settings, save them as policies, and apply those policies to multiple sites within an account. Policies can be created at the parent account level, made available to subaccounts, and set as default to automatically apply to new websites. At the website level, users can view, edit, apply, or remove policies. Imperva offers several policy types, each with specific configurable fields. Users can also customize which tasks and domains common users may modify. Customization is possible via multiple methods, including the user interface, API calls, and Terraform. Professional Services and certified partners are available to assist with deployments, configuration, tuning, upgrades, and custom integrations, tailoring installations to meet specific client needs. Advanced options are available for building custom security policies using the customer policy rule engine, allowing specialized adjustments for unique use cases.
Scaling
- Independence of resources
- We guarantee users are not affected by the demand other users place on our service by maintaining a fully scalable redundant platform with over 10 Tbps of on-demand scrubbing capacity and the ability to process 65 billion attack packets per second. Our global network is designed for robustness and resiliency, delivering premium performance and low latency. Controls are in place to prevent one client from compromising another in a resource pooled environment. Advanced caching and optimization techniques further ensure seamless user experiences during high traffic periods.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide comprehensive service metrics including performance (round-trip time, throughput, jitter) and availability (packet loss) for all Points of Presence (PoPs), as well as performance and availability between Imperva edge and customer origin servers. Traffic reports include metrics such as requests, response codes, page views, origin offload, browser and OS, with a 3-month data retention period. Cross-service line metrics are available via Attack Analytics within the management console.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller (no extras)
- Organisation whose services are being resold
- Thales
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can extract their data by utilizing the SIEM integration to extract security events and access logs. For configuration data, this can be extracted via Imperva API or Terraform integration.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- PDF, Excel (XLSX), HTML, JSON, XML, CEF, LEEF
- W3C log formats
- Data import formats
- Other
- Other data import formats
-
- JSON
- https://docs-cybersec.thalesgroup.com/bundle/api-docs/page/api/api-overview.htm
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We guarantee a 100% uptime SLA for Network DDoS protection when the origin is connected to 3 Imperva PoPs, and our network protection base plan includes 8 router connections for high availability. Imperva commits to a Network Infrastructure annual uptime of 99.999% and a Peripheral Infrastructure annual uptime of 99.95%. Our Always-on Services offer a 99.999% network uptime SLA and a 3-second mitigation SLA. If service levels are not met, remedies and refund procedures are detailed contractually. For application and disaster recovery scenarios, we maintain the highest level of availability through real-time monitoring, optimal load distribution, and automatic site failover. Service level agreements are supported and include mechanisms for monitoring and enforcing SLAs, such as 24x7x365 coverage, escalation procedures, and status updates through our Customer Support Guide. SLA documents are available with an NDA in place.
- Approach to resilience
- Our service is designed for resilience through a fully redundant architecture operating in active/active mode across multiple data centers worldwide, supporting a 99.999% uptime commitment. Each data center is strategically located and equipped with high-capacity infrastructure, leveraging advanced hardware and software to ensure maximum throughput and minimal latency. Cloud WAF security proxies are deployed in clusters within each PoP for high availability and resilience to DDoS attacks, with PoPs in each region backing each other up. Network configuration requires at least two data centers to serve any single customer at any time, minimizing the risk of downtime. Redundancy between data center PoPs enables automatic failover if infrastructure goes offline. For customer-managed environments, we implement a global load balancing design and support both on-premises and public cloud deployments without location restrictions. Additional planning for rolling power outages is unnecessary due to our resilient network and service design. Detailed data center specifications are available on request.
- Outage reporting
-
"1. a public dashboard
3. email alerts
Imperva's network status is available through our dedicated site (https://status.imperva.com/), but email alerts are also available through the platform to monitor customer sites. "
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- User authentication for accessing the service is determined by the specific SaaS application and service type. We support multiple authentication mechanisms, including LDAP, OIDC, certificate-based authentication, and auth tokens. Authentication can be configured through local accounts, and two-factor authentication (2FA) is available as an optional layer. For web-based user interfaces, SSO via SAML and cloud-created accounts is supported. Additionally, role-based access control is managed through locally defined roles or externally defined AD groups, ensuring users are granted access only to the relevant portions of the solution based on their assigned roles.
- Access restrictions in management interfaces and support channels
- Access in management interfaces is restricted through a formal management process controlling allocation of access and passwords. Role-based access controls (RBAC) enable precise privilege management, allowing edit, view-only, or restricted access to specific objects. Multi-factor authentication (MFA) is enforced for login security. User access is regularly reviewed and managed via structured provisioning and deprovisioning processes. For support channels, all calls and emails must be submitted through official Imperva support channels to ensure proper tracking, assignment, and resolution of cases.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Imperva's governance standards comply with ISO 27001:2022, SOC 2 Type II, PCI DSS 4.0 Service Provider Level 1, GDPR, APEC PRP, and TRUSTe GDPR Validation. These certifications and validations confirm adherence to internationally recognized information security, privacy, and data protection standards.
- Information security policies and processes
- We follow a documented Information Security Policy that is reviewed and approved by executive management, supported by an Information Security Management System for managing security risks. Our policies include controls for testing and applying security patches, secure system development and testing, strong password policies with regular expiration, clear desk policy, secure disposal of client information, exit strategies for termination or decommissioning of client data and infrastructure, logging of key system events, regular independent review of system logs, audit reviews and monitoring, backup and testing of information, software and system images, and baseline security documentation for IoT protection. Outsourced system development activities adhere to the same robust controls as internal development. Our policies align with industry standards such as ISO 27001, and we maintain a full ISMS program. Compliance with security hardening standards is monitored through regular audits, assessments, and automated tools. The reporting structure involves executive management oversight, with independent functions conducting reviews and audits to ensure policy adherence and prompt remediation of deviations.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our configuration management program utilizes platforms such as SCCM for Windows, Jamf for macOS, Puppet and Salt for Linux, and centralized management consoles for network devices to track components throughout their lifecycle. All configuration and system changes are governed by a formal change management program, which includes risk assessment, impact analysis, approvals, testing, and rollback planning to ensure potential security impacts are evaluated. Change candidates are scored based on risk level and routed to the Change Approval Board for review.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability scanning and remediation is performed regularly. We also follow security trends and communicate with third party vendors regarding emerging vulnerabilities. When identified, vulnerabilities are managed according to the Threat and Vulnerability Management Policy and Standard.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We implement comprehensive protective monitoring through automated audit trails that reconstruct key events such as access to sensitive data, actions by privileged users, and invalid access attempts. Logs are reviewed daily in real time to identify potential compromises, with user identification, event type, date/time, and success/failure recorded for each event. Upon detection of a likely major security incident or data breach, our Incident Response Leader activates the Data Security Incident Response Team in consultation with Legal, ensuring rapid notification to impacted individuals, customers, regulators, and partners according to our DSIRP.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We have a documented (pre-defined) incident management process that requires employees, contractors, and third-party users to report potential incidents to the security team for initial investigation. Incidents may be escalated to the Crisis Management Team, which manages identification, containment, eradication, recovery, and communication coordination, including customer notifications. The Computer Emergency Response Team (CERT) operates according to established standards and records events in a ticketing tool, with a 4-hour SLA for containment recommendations. Impacted customers are notified within 24 hours of incident confirmation, and updates are provided until resolution. Incident reports are communicated to designated contacts as specified in service agreements.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- "30 day free trial of the Imperva Cloud WAF is available through the link provided (https://www.imperva.com/free-trial/), which includes our core Cloud WAF, DDoS, Bot Protection, CDN, and more, but won't include our more complex offering like our Advanced API Security, Advanced Bot Protecton, and Network DDoS.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Monday 8 April 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- NQA
- ISO 9001 accreditation date
- Monday 8 April 2024
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- SecurityMetrics
- PCI DSS accreditation date
- Friday 10 January 2025
- What the PCI DSS doesn’t cover
- N/A
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E9fd5f85-7cd1-4ff2-aba9-6f9f5f225b1b
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 181966c9-f0aa-42ed-9271-d1b111bdf43b
- Other security certifications
- Yes
- Any other security certifications
- Security Standards dependant on the vendor solution
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-