Skip to main content

Help us improve the Digital Marketplace - send your feedback

CENTERPRISE INTERNATIONAL LIMITED

Azure Backup Service

Centerprise Microsoft Azure Backup delivers secure, policy-based protection for Azure workloads, ensuring rapid recovery from deletion, ransomware, and configuration errors. With immutable storage, granular restore, hybrid cloud efficiency, and automated resilience, the service safeguards critical data, strengthens compliance, and enables fast, reliable restoration across environments to maintain operational continuity.

Features

  • Automated, policy-based backups for Azure workloads and data.
  • Immutable storage using Azure Blob WORM technology.
  • Logical air-gapped backups are isolated from production environments.
  • Least privilege IAM and RBAC-controlled access.
  • Cost-optimised lifecycle management to object storage.
  • Hybrid and multi-cloud backup support.
  • Full instance and granular file-level recovery options.
  • Cross-region and cross-subscription recovery capability.
  • Native Cosmos DB and PostgreSQL backup orchestration.
  • Wizard-driven, self-service recovery workflows.

Benefits

  • Protects Azure data from ransomware, deletion, and corruption.
  • Ensures rapid recovery to maintain business continuity.
  • Strengthens security posture with immutable, isolated backups.
  • Reduces operational overhead through automated policies.
  • Lowers storage costs with lifecycle optimised retention.
  • Enhances compliance with secure, auditable backup processes.
  • Supports hybrid cloud resilience strategies.
  • Enables precise, minimal disruption restoration.
  • Improves recovery confidence with simplified workflows.
  • Accelerates onboarding for fast protection readiness.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tendersteam@centerprise.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 8 5 3 7 4 0 7 2 0 1 4 8 7 1

Contact

CENTERPRISE INTERNATIONAL LIMITED Tenders Team
Telephone: 01256 378 000
Email: tendersteam@centerprise.co.uk

About your service

Service categories

Systems Infrastructure Software

Security

  • Cloud native application protection platform
  • Endpoint security
  • Security analytics
  • Governance, risk and compliance

Identity and access management

  • Access
  • Privilege

Network security

  • Active application security

Data security

  • Information protection
  • Digital trust
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
The service offers sovereign Object Storage and Veeam software solutions which can standalone or act as part of a Veeam Suite of backup solutions.
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
The service operates within defined scope and support boundaries. Support is limited to backup, retention, and restoration of supported platform data and configurations and does not include application redesign, custom development, third-party integrations, end-user device support, or underlying platform administration. Platform licence costs are excluded unless explicitly agreed. Support is delivered during defined service hours, with response times aligned to the selected service tier. Planned maintenance of the backup service is scheduled and communicated in advance where applicable. The service is dependent on the availability, APIs, and change management processes of the underlying platform, which remain outside our direct control.
System requirements
  • Active subscription to the supported cloud platform
  • Appropriate administrative access for backup and recovery configuration
  • Secure authentication enabled for administrative access
  • Network connectivity to required cloud service endpoints
  • Platform permissions granted for data protection operations
  • Use of vendor-supported configurations and service versions

User support

Email or online ticketing support
Yes
Support response times
These SLAs are applicable, but out-of-business hours, telephone support should be used.

Incident Response and Resolution

Incident Management

Priority 1 Priority 2 Priority 3 Priority 4

Response Time 15 Mins 30 Mins 30 Mins 30 Mins

Target Resolution 4 Hrs 8 Hrs 16 Hrs. 5 Days
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Generally this service is a cloud to cloud service and does not require onsite support. If customers require onsite training for their personnel or if they have onsite Office legacy office accounts such as Exchange, we can provide onsite support when needed. We can provide a cloud support engineer or other.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Centerprise provides a structured and low-risk onboarding process designed to ensure services are adopted quickly, securely, and with minimal operational disruption.

Each engagement begins with a formal mobilisation phase, including a service kick-off, confirmation of scope, roles and responsibilities, and agreement of onboarding milestones aligned to customer timelines. A named service delivery contact coordinates onboarding and acts as the primary point of escalation.

Customers are supported through a combination of clear documentation, guided configuration, and knowledge transfer. Where applicable, Centerprise provides live walkthroughs, remote or on-site workshops, recorded training sessions, and access to vendor-accredited learning resources. Training is tailored to operational and administrative users and focuses on day-to-day service use, recovery actions, and support processes.

Prior to go-live, services are validated through testing and user acceptance to ensure the solution operates as expected. Once live, customers are fully onboarded to the Centerprise Service Desk, including access to ticketing, escalation routes, and agreed service levels.

Post-transition reviews are conducted to confirm service stability and ensure customers are confident in operating and consuming the service.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
Centerprise supports secure, orderly, and auditable data extraction at contract end to ensure continuity and data integrity.

As part of service exit planning, Centerprise works collaboratively with the customer to agree a documented exit strategy and data migration approach. This includes defining data scope, extraction methods, security controls, timelines, and responsibilities. Data can be exported using standard, non-proprietary formats supported by the underlying platforms and tools, ensuring compatibility with successor services or in-house environments.

Where applicable, data extraction may be performed incrementally to reduce risk and operational impact. Transfers are monitored, validated, and subject to post-migration checks to confirm completeness and integrity. Secure delivery methods are used throughout, aligned to customer security and compliance requirements.

Customers may self-extract data where the service supports customer-managed access, or request Centerprise-assisted extraction via the Service Desk. Any assisted extraction is delivered under controlled change and security processes.

Data remains accessible for the duration of the agreed exit period. Following confirmation of successful extraction and formal service termination, remaining service data is securely deleted in line with contractual obligations and data protection requirements.
End-of-contract process
At contract end, Centerprise follows a defined service exit process to ensure a controlled and transparent transition.

An exit plan is agreed in advance, covering service termination activities, data extraction, access removal, and service decommissioning. During the notice period, services continue to operate in line with contracted service levels unless otherwise agreed. Customers retain access to support and service documentation throughout this period.

The standard contract price includes exit planning, coordination, and reasonable assistance to enable service cessation in an orderly manner. This includes stakeholder engagement, access to documentation, and support for standard data extraction using agreed methods.

Additional costs may apply where customers request non-standard exit activities, such as bespoke migration tooling, accelerated timescales, extended data retention beyond contract end, specialist engineering effort, or physical data transfer media. Any such costs are agreed in advance through a transparent change control process.

Following service termination, access is removed, integrations are decommissioned, and data is securely deleted once extraction is confirmed. A formal service closure confirmation can be provided on request.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The management console is browser based and as such can be accessed via an optimised browser for the device being used -- mobile or desktop.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed via a combination of Centerprise’s Service Desk interface and product-specific self-service capabilities.

Customers interact with the service through Centerprise’s secure client portal, email and telephone channels to raise incidents, service requests and restore requests, all delivered in line with agreed SLAs.

For Microsoft 365 Backup, and ENTRA ID backup, an optional self-service recovery portal is provided, enabling authorised users to perform granular restores of Exchange, OneDrive and SharePoint data.

Service reporting and operational communications are provided through agreed reporting mechanisms as part of the managed service including report access via an ITSM tool provided by Centerprise.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Autotask design, test and supply enhancements of assisted technologies as part of this interface and Veeam UI is similarly tested by them.
API
Yes
What users can and can't do using the API
The solution provides REST-based APIs that enable programmatic interaction with Veeam Backup for Microsoft 365 and Veeam Backup & Replication environments. The APIs allow authorised users to integrate backup services with external systems, automate configuration tasks, and retrieve operational and reporting data.

Using the API, users can set up and configure elements of the service such as repositories, backup jobs, schedules, retention policies, and access controls, subject to role-based permissions. The API also supports making changes to existing configurations, including updating backup scopes, modifying schedules, triggering backup or restore operations, and querying job status and audit information.

The APIs are primarily intended for administrative and integration use rather than end-user interaction. Certain advanced configuration tasks, security-sensitive actions, and environment-level changes may require access through the management interface rather than the API. The APIs do not provide unrestricted system access and are constrained by authentication, authorisation, and platform safeguards to protect service integrity.

Overall, the APIs support automation, orchestration, and integration while ensuring that core service governance and security controls remain enforced.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • ODF
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The backup service supports configuration-based customisation to meet organisational and regulatory requirements. Customisable elements include backup scope (for example Exchange, SharePoint, OneDrive and Teams), user and group selection, retention periods, storage location, immutability settings, and backup schedules.

Customisation is performed through secure management interfaces and documented APIs, allowing authorised users to apply configuration changes, update policies, and initiate restore operations within defined service boundaries. Where agreed, limited self-service restore functionality can be enabled to support operational efficiency.

Customisation is undertaken by authorised administrators using role-based access controls. End users do not directly configure backup policies but may be granted restricted restore permissions. All changes are logged for audit purposes. The service does not support bespoke development or unsupported platform modifications; customisation is limited to standard configuration options provided by Microsoft 365 and the backup platform.

Scaling

Independence of resources
Our solution, using our sovereign Cloud storage, was recently designed and installed under strict sizing and stress tested parameters with guaranteed throughput (underwritten by vendor) sufficient to support all of our current customers as well as as accurate business growth forecasts based on historic and future growth expectations. Our network connectivity is designed for rapid scaling to meet growth across multiple channels.

Analytics

Service usage metrics
Yes
Metrics types
Centerprise provides service metrics aligned to the nature of the service and agreed service levels. Metrics may include service availability, incident volumes, response and resolution performance, backup or protection success rates (where applicable), and service request activity. SLA achievement is tracked and reviewed as part of ongoing service management.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
Secure hardware handling, controlled media disposal, and managed lifecycle processes further protect data integrity and sovereignty.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users export their data through a secure, web-based restore interface provided as part of the service. Access is authenticated using supported identity and access controls. From the interface, users select the required service, data scope, and restore point, then export supported data and configurations in standard formats for download or re-import. No local software installation is required. Export operations are subject to platform permissions, retention policies, and applicable service limits. Where supported, data can also be restored directly back to the source platform or exported for audit, investigation, or compliance purposes.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • EML – Open RFC 822 email format
  • MSG – Outlook/Exchange item file
  • PST – Open mailbox container format for full‑mailbox exports
  • ICS – Calendar export format
  • VCF – Contact card format
  • DOCX, XLSX, PPTX – Open Office XML formats
  • PDF – Standard document format
  • ZIP – For folder‑level exports
  • Any original stored file type (e.g., CSV, JPEG, MP4, etc.)
Data import formats
  • CSV
  • Other
Other data import formats
Platform native export formats.

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks
Data in transit is protected using layered network security controls aligned to Cloud Security Principle 1. All data transfers use encrypted channels, with TLS 1.2 or higher enforced for API and object access. Where required, customers may connect using private connectivity or site-to-site IPsec VPNs, reducing exposure to public networks. Network traffic is restricted through firewall rules, access control lists and segmentation within the platform. Mutual authentication, role-based access controls and credential management are enforced to prevent unauthorised access. Continuous monitoring and logging are applied to network traffic to detect anomalies and maintain integrity and confidentiality of data in transit.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Data within the service network is protected using defence-in-depth security controls aligned to Cloud Security Principle 1. All internal service communications are encrypted using TLS 1.2 or higher, including management, control and data plane traffic. Network segmentation and zoning are used to isolate workloads, storage nodes and management components, reducing lateral movement risk. Access is restricted through firewalls, security groups and least-privilege access controls. Administrative access is tightly controlled, logged and monitored. Internal traffic is continuously monitored for anomalous behaviour, and security controls are regularly reviewed to ensure the confidentiality and integrity of data in transit within the service network.

Availability and resilience

Guaranteed availability
The service is delivered from UK-based, carrier-neutral data centres, designed to support highly available, enterprise-grade cloud infrastructure. The underlying data centre environment targets 100% uptime for power and cooling, supported by resilient design, multiple power feeds, and continuous monitoring.

The service is architected with redundant storage components and network connectivity. Platform throughput is underwritten to support sustained data transfer rates of up to 1.5 GB per second per storage environment, subject to service configuration and connectivity.

The supplier provides a service availability target of 99.9% per calendar month, excluding scheduled maintenance and factors outside the supplier’s reasonable control, including upstream network providers and third-party platform dependencies. Planned maintenance is conducted during agreed maintenance windows and notified in advance where possible.

If the guaranteed availability level is not met, service credits may be applied in accordance with the agreed call-off contract. Credits are calculated as a proportion of the monthly service charge for the affected service and represent the buyer’s sole remedy for availability failures under the service level agreement.
Approach to resilience
The service is delivered from UK-based, carrier-neutral data centres, designed to support highly available, enterprise-grade cloud infrastructure. The underlying data centre environment targets 100% uptime for power and cooling, supported by resilient design, multiple power feeds, and continuous monitoring.

The service is architected with redundant storage components and network connectivity. Platform throughput is underwritten to support sustained data transfer rates of up to 1.5 GB per second per storage environment, subject to service configuration and connectivity.

The supplier provides a service availability target of 99.9% per calendar month, excluding scheduled maintenance and factors outside the supplier’s reasonable control, including upstream network providers and third-party platform dependencies. Planned maintenance is conducted during agreed maintenance windows and notified in advance where possible.

If the guaranteed availability level is not met, service credits may be applied in accordance with the agreed call-off contract. Credits are calculated as a proportion of the monthly service charge for the affected service and represent the buyer’s sole remedy for availability failures under the service level agreement.
Outage reporting
The service reports outages and service disruptions through a combination of proactive communications, automated notifications and service management processes. Customers are notified of service-impacting incidents via email alerts issued by the Centerprise Service Desk, ensuring timely awareness of incidents, updates on progress and confirmation of service restoration. Automated notifications are generated for service-affecting events and major incidents, in line with agreed SLAs and incident management procedures. These notifications provide clear information on the nature of the incident, affected service components, expected impact and ongoing remediation actions. Where appropriate, follow-up communications and post-incident summaries are provided. Operational visibility is supported through service reporting and review mechanisms, including incident history, SLA performance and service availability metrics, shared as part of regular service reviews or on request. An API is not exposed for outage notification, as incident communications are managed centrally to ensure accuracy, consistency and controlled messaging. The service does not rely on a public-facing status dashboard. This approach avoids the disclosure of sensitive operational details while ensuring customers receive authoritative, timely and auditable communications directly from the service provider. Escalation paths are clearly defined to support critical incidents and major service disruptions.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Other
Other user authentication
Access to the service integrated platforms is authenticated using scoped, non-interactive access credentials generated per tenant and service. These credentials are bound to defined roles and permissions and are used exclusively over encrypted TLS connections. This model supports secure, API-driven access by backup and archive platforms such as Veeam, without the use of shared user accounts. Credentials can be rotated, revoked, and audited, and are restricted by policy to specific buckets, operations, and endpoints, enforcing least-privilege access and reducing exposure.
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using role-based access control aligned to least-privilege principles. Administrative access is limited to authorised personnel with job-role justification and is protected using multi-factor authentication. Management access is segregated between platform administration, service operations, and customer support functions. Support channels are accessed only through authenticated service desk systems, with permissions scoped to customer tenancy and service responsibility. Privileged actions are logged and auditable, with access reviewed regularly and removed promptly on role change or leaver events. Direct platform access by customers is limited to explicitly agreed, read-only or delegated functions where applicable.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Other
Description of management access authentication
Management access to the service is authenticated using centrally controlled, role-based privileged accounts that are individually assigned and approved. Access is time-bound where appropriate and granted only for operational or support purposes. Authentication is enforced through secure administrative identity controls integrated with the service management platform, ensuring that management actions are attributable to named individuals. All management sessions are established over encrypted channels and are subject to logging and monitoring. Privileged credentials are rotated in line with policy and revoked immediately upon role change or leaver events, ensuring continued alignment with least-privilege and strong accountability requirements.

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials Plus
ADISA ICT Asset Recovery Standard 8.0 – DIAL 3 rated

DataCentre specific: ISO 27001, SOC 1 Type 2 & SOC 2 Type 2,
PCI-DSS, HIPAA & PIPEDA:
ISO 9001, 14001, 45001, 50001:
Information security policies and processes
Centerprise International operates an Integrated Management System aligned with its Information Security Policies, establishing a consistent framework for protecting customer information across all sites and services, including Microsoft 365 Backup, Backup as a Service (BaaS), and Disaster Recovery as a Service (DRaaS). The policies defined under our ISO 27001 certification apply to all employees, contractors, suppliers, and relevant third parties, ensuring controlled and consistent handling of customer data.

ISO 27001 certification provides robust governance and accountability. Senior leadership, including the CEO, Group Quality Manager, Security Manager, Services Director, Board-level contact, and Data Protection Officer, review and approve all policies to ensure continued alignment with legal, regulatory, and contractual requirements. Clear responsibilities are defined for information security, risk management, access control, incident response, and data protection compliance. All users must follow security procedures and report suspected security incidents immediately.

Adherence is enforced through mandatory training, regular risk assessments, internal and external audits, and established incident response processes. Controls include data classification, acceptable use, technical safeguards, business continuity measures, and GDPR-aligned personal data handling, providing customers with strong assurance that their information is protected to a high standard.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Configuration and change management is delivered through formal, documented processes to maintain security and service integrity. Service components, including infrastructure, platform software and configurations, are recorded and tracked throughout their lifecycle from provisioning to retirement. All changes follow a controlled change management process, including impact assessment, approval, implementation and review. Security impact is explicitly assessed for each change, considering confidentiality, integrity and availability. Changes with potential security implications are subject to additional review/testing. Changes are logged, auditable and subject to segregation of duties. Customer-impacting changes are planned, scheduled and communicated in advance where required to minimise risk and service disruption.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Vulnerability management is delivered through a structured, risk-based process designed to protect service confidentiality, integrity and availability. Potential threats are assessed using vulnerability scanning, vendor advisories and risk assessment processes to evaluate severity, exploitability and service impact. Patches and mitigations are prioritised based on criticality and deployed in accordance with defined patch management timelines, with urgent security updates expedited where required. Threat intelligence is sourced from trusted vendors, platform suppliers, security advisories and industry best-practice sources. Changes are tested prior to deployment where appropriate, and all remediation activities are logged and auditable, ensuring accountability and continuous service improvement.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Protective monitoring is implemented through continuous monitoring of service platforms, infrastructure and network activity to detect potential security compromises. Logs, alerts and system events are analysed to identify anomalous behaviour, unauthorised access attempts or indicators of compromise. Monitoring outputs are reviewed by authorised operations/security personnel. When a potential compromise is identified, predefined incident management procedures are invoked to assess impact, contain risk and initiate remediation. This includes escalation to specialist teams where required. Incidents are prioritised based on severity and business impact, with response times aligned to incident classification and SLAs. Actions are logged and reviewed to support auditability/continuous improvement.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Incident management is delivered through documented, pre-defined processes aligned to best practice. Standard procedures exist for common events, including service degradation, security incidents and data access issues, ensuring consistent/timely response. Users report incidents via the Centerprise Service-Desk using email, telephone or the secure client portal. All incidents are logged, categorised and prioritised based on impact and urgency, with response and resolution managed in line with defined SLAs. Updates are communicated to users throughout the lifecycle of the incident. Following resolution, incident reports and summaries can be provided, including root cause analysis for major incidents, supporting transparency and continuous service improvement.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
Yes
Connected networks
Other
Other public sector networks
PSPA (Welsh Public Sector)

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Centerprise can initially provide a demonstration of the platform and its functionality, including the ability to recover individual items or groups of data. A 30-day free trial can also be provided, including licensing, setup and secure Cloud data storage.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
4%
Between £1,000,001 and £2,500,000
6%
Between £2,500,001 and £5,000,000
8%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
ISOQAR
ISO/IEC 27001 accreditation date
Monday 10 June 2024
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
ISOQAR
ISO 9001 accreditation date
Thursday 20 April 2023
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
Security Metrics
PCI DSS accreditation date
Wednesday 5 November 2025
What the PCI DSS doesn’t cover
N/a
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
D96b5015-69ba-4b1e-98cd-f228d80ba12f
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
Ae2ef03f-bd6e-4405-9ace-237c365676d6
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Plans for positive actions with community groups.
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tendersteam@centerprise.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.