Skip to main content

Help us improve the Digital Marketplace - send your feedback

TALKTALK BUSINESS DIRECT LIMITED

Zoom Unified Communications and Contact Centre

Zoom delivers easy, innovative, and intuitive communication, collaboration and contact capabilities in a single pane of glass solution. With extensive, market-leading features and impressive, effective AI as standard, it is an ideal Unified Communications as a Service (UCaaS) and Contact Centre as a Service (CCaaS) solution for businesses.

Features

  • Enterprise grade cloud telephony
  • Flexible collaboration tool
  • Multi device accessibility
  • Integrated AI at no extra cost
  • Omnichannel contact center solution that supports multiple channels seamlessly
  • Access multiple services via single pane of glass.
  • Workforce management (WFM) monitors queue activity in real-time
  • Extensive integration ecosystem
  • UK-based service and delivery team for network and communications

Benefits

  • Reliable communication supporting essential public services.
  • Seamless teamwork across distributed public sector teams.
  • Staff stay connected anywhere for uninterrupted service delivery.
  • Boosts productivity without increasing pressured public budgets.
  • Citizens contact services easily via preferred channels.
  • Simplifies operations and reduces IT management burden.
  • Optimises staffing to match fluctuating citizen demand.
  • Connects easily with existing public sector systems.
  • Local support reduces pressure on overstretched IT teams.

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andrew.stokes@talktalk.business. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 6 3 9 2 4 5 4 1 8 9 3 3 9 6

Contact

TALKTALK BUSINESS DIRECT LIMITED Andrew Stokes
Telephone: 07976911843
Email: andrew.stokes@talktalk.business

About your service

Service categories

Application Development and Deployment

Analytics and business intelligence

  • Business Intelligence
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
Service levels only apply when TalkTalk Business connectivity is used for locations where Zoom is deployed. Where third party connectivity is used, TTB cannot support SLAs

System Requirements: Users must have compatible devices, sufficient connectivity bandwidth, and the current software version to access full functionality.
End-user devices from multiple vendors are supported. Older handsets may not provide proprietary functionality when used with Zoom. A checker is available to help customers decide on the right choice of end-devices.
Network access: Firewalls, proxy servers, or web security gateway settings can block access to the service, so checking network configurations is important.
System requirements
  • Laptop hardware requirements for softphone
  • PoE requirements for IP phones
  • Internet connectivity at user location
  • WIFI or cellular availability for mobile users
  • Headsets required for contact centre users

User support

Email or online ticketing support
Yes
Support response times
Email and online tickets will be assessed on receipt and be placed into one of three priority queues by the service team:

P1: Critical Fault – loss of service. 4 clock-hours’ response, 24/7
P2: Partial loss of service. 8 clock hours
P3: Degradation of service. 48 clock hours

P1 faults will result in an immediate action plan with target resolution timescales agreed with the customer. All customer interactions will be managed though TalkTalk’s ticketing management system and customers kept up to date at all stages until resolution.

Response times will remain the same at weekend across P1-P3 faults.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes
Support levels
TalkTalk Business (TTB)’s service team manage faults through to conclusion. We provide the following service levels included within the overall service when taken up by the customer.

P1: Critical Fault – loss of service. 4 clock-hours’ response, 24/7
P2: Partial loss of service. 8 clock hours
P3: Degradation of service. 48 clock hours

Faults can be raised 24x7, 365. Each case will be allocated to a cloud support engineer who will investigate the issue and either resolve the fault directly or raise a ticket and track the support case with our suppliers. Tickets will be prioritised according to the severity of the fault reported, tracked and managed through our published fault management process.

All comms will be updated by our service team right up to the customer agreeing to close the ticket.

We can be contacted via:
In hours – Monday - Friday (excl. Bank Holidays) 8:30 to 17:15
Email: systemsupport@talktalkbusiness.co.uk
Phone: 0191 493 1120, option 1 or
0800 4661234, option 1 then 3
Out of hours:
Email: b2booh@talktalkbusiness.co.uk
Phone: 0800 5426753

All customers will be allocated a named Account Manager who will have a team of dedicated technical specialists that will support on any customer requirements.
Support available to third parties
No

Onboarding and offboarding

Getting started
We appoint a dedicated project coordinator, responsible for the delivery of the project.
The coordinator determines project stakeholders, contact details, design document and delivery steps. Project calls confirm timelines. We work through and document details around system data imports for users, call flows, groups. Porting documents and user guides.

The project design will determine the type of training your users require.
We offer on-site training, remote sessions, guides and user documentation, interactive self-paced learning or a mixture of all dependant on requirements.

We will encourage users to install their new device wherever possible prior to bringing into service (BIS) so they can experience the new solution. This may be on their desktop via a softphone, mobile client or hardware, so users can then familiarise themselves with any new features. We can also phase the BIS by moving users in departments or clusters, which can ease a large transition to a new platform.

The key delivery factor will be for the user to feel comfortable and ensure minimum disruption.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
Word
End-of-contract data extraction
Customers can extract their data via application in-built tools, which have export and reporting features.

TTB can help customers understand how these tools can be used if required.
End-of-contract process
The contract will cover the licences and the elements in the Zoom price list together with agreed up-front and recurring professional service elements.

Once out of fixed-term contract all services will renew to a new term on the same period as the original. The customer will be given the option to amend service elements prior to renewal or state that they wish not to renew. If they choose not to renew, then the service will be decommissioned.

Decommission will involve the closure of any billing activity and removal of any service-specific data on our commissioning and billing systems. We will also raise a data deletion request with our supplier. Customers can initiate a right-to-be-forgotten request to remove data held on our customer database.

Customers should if required, extract their data via application tools, which have export and reporting features.

TTB can help customers understand how these tools can be used if required.
Current processes are documented on TalkTalk’s online support centre (https://supportcentre.talktalkbusiness.co.uk/).
Documentation accessibility standard
None or don’t know
How the documentation is accessible
This documentation can also be accessed via PDF, which allows users with disabilities or sensory impairment to access information through functions such as text to speech and font settings.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • Windows
  • Other
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The Zoom UC service is designed to work seamlessly between laptop and mobile. There are no differences in service; the interfaces are identical to ensure the best user experience and familiarity when switching devices.
Service interface
No
User support accessibility
None or don’t know
API
No
Customisation available
Yes
Description of customisation
Zoom offers a wide range of integrations with third-party applications to enhance collaboration, streamline workflows, and improve productivity.

Overview of Zoom Integrations

Zoom integrates with numerous applications and services, allowing users to enhance their video conferencing experience. These integrations can simplify scheduling, improve communication, and provide additional functionalities tailored to various business needs.

Scaling

Independence of resources
Zoom’s unique architecture allows quick and easily scaling to meet demand, ensuring users aren’t affected by the demand of other users. Zoom maintains redundant capacity in all aspects of its infrastructure to accommodate and meet peak usage requirements.

Zoom's proven infrastructure supports over 350-million daily users and billions of meeting minutes a month. The architecture is built to handle growing levels of activity, as Zoom's unified communications platform is architected from the ground up to address the most technologically difficult aspect of communications: video. Zoom's modern cloud architecture gives the platform its trademark reliability, quality, and scalability.

Analytics

Service usage metrics
Yes
Metrics types
The service lets customers choose metrics from the different Zoom applications.

Zoom inbuilt business Analytics call reporting tool can be used to run reports on their end users and get call data like average waiting time, longest calls, etc.

For example:

View meeting and webinar quality (MOS Score)

Drill down into meeting quality measurements

View Mean Opinion Score (MOS) by site or across all sites for both inbound and outbound calling.

View key performance data for call queues

View call queue activity and trends over a selected period.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Zoom communications

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Other
Other data at rest protection approach
Data at rest is encrypted. There is an access control policy. We also have a data security standard that details the requirements for classification, storage, use, processing and destruction of all data. The access control policy and data security standard are both internal documents, so we are unable to share them.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Customers have multiple methods for extracting their data from the applications themselves or via application tools, which have export and reporting features. E.g.

Exporting Meeting Recordings & Transcripts
• Cloud Recordings: Go to Recordings in the web portal, find the meeting, and click Download.
• Transcripts: Download the .vtt file from the cloud recordings page.
• Local Recordings: These are automatically saved to your local computer (usually in Documents/Zoom).
• Tool: You can use third-party tools like Zoom Easy Downloader (Chrome Extension) for quick downloading.

TTB can help customers understand how these tools can be used if required.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Communications are established using Transport Layer Security (TLS). Meeting, webinar and messaging content is encrypted using 256-bit Advanced Encryption Standard (AES), with optional end-to-end encryption.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
To protect data within the network, Zoom offers a range of authentication methods such as SAML, OAuth, and/or Password based which can be individually enabled/disabled for an account. Users authenticating with username and password can also enable two-factor authentication (2FA) as an additional layer of security to sign in.

Availability and resilience

Guaranteed availability
SLAs are addressed in Zoom's Master Services Agreement (MSA) and may include 99.9% uptime, excluding excused downtime (maintenance).

Zoom offers no service credits.
Approach to resilience
Zoom web services leverage AWS high availability infrastructure with multi-region configuration operating in Active/Standby mode. For realtime communications, Zoom leverages multiple Tier 1 data centers running in Active/Active mode.
Outage reporting
Zoom posts any general incident announcement and other announcements including scheduled maintenance, outages, updates, through the status page at status.zoom.us (public dashboard). For incidents affecting a specific customer, Zoom will notify the account owner and administrator(s) through email or as specified in fully executed agreement.

Identity and authentication

User authentication needed
Yes
User authentication
  • Public key authentication (including by TLS client certificate)
  • Other
Other user authentication
• 2-factor authentication
• Identity federation with existing provider (for example Google Apps)
• Username or password
Access restrictions in management interfaces and support channels
The Internal Network and Security Team has access and is responsible for user access management. The level of access is based on the principle of 'least privilege' and only those members of staff who need access will be granted it. We have a formal Joiners, Movers, Leavers (JML) process with role-based access governing the majority of applications and systems. Access is removed within 24hrs of an employee leaving the business. Recertification of user access is completed bi-annually.
Access restriction testing frequency
At least once a year
Management access authentication
  • Username or password
  • Other
Description of management access authentication
Management interfaces are accessed via username and password derived from integration via SSO or username and password. Interfaces are accessed based upon role-based access control (RBAC).

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
As part of the TTB Security Policy, we are using an internationally recognised security control framework (NIST) to assess our maturity, which is validated internally every 3 months and externally every 3 years by BSI. TTB is accredited for ISO 27001 and follows all security principles to preserve the confidentiality, integrity and availability of its data.

The Information Security Management System (ISMS) is a set of policies and procedures for systematically managing the security of TTB data. The goal of an ISMS is to minimise risk and ensure business continuity by proactively limiting the impact of a security incident. This provides the guiding principles and responsibilities necessary to safeguard the security of our information assets. Supporting policies, standards, procedures and processes all form part of the information security policies in place.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Zoom configuration are logged and tracked via the Zoom web portal. This involves setting up features across personal, group, and account levels via the web portal, while change management focuses on the process of implementing updates, managing user adoption, and controlling settings using admin controls, ensuring smooth transitions for features like security, meeting settings, Zoom Rooms, and Phone.

Zoom configuration and change management conforms to a recognised standard, for example, CSA CCM v3.0 or SSAE-16 / ISAE 3402.

Security impact will be assessed through a risk assessment and structured model to ensure all risks are captured and clearly identified.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Zoom has a formal Vulnerability Management Plan in place. Zoom performs monthly vulnerability and web application scanning using an external party (Qualys) to assess potential threats. Zoom has a monthly patch cadence, patching all applications, workstations, and servers (virtual or physical) with all current operating system, database, and application patches deployed in our computing environment according to a schedule predicated on the criticality of the patch. Maintenance/patching typically will have no service downtime.

Scan reports are reviewed by Security and technical teams (in PlatformX Communications) who track validated findings throughout remediation.
Protective monitoring type
Undisclosed
Protective monitoring approach
Zoom has monthly vulnerability and web application scans to identify potential compromises. Findings are reviewed and validated by its technical and engineering team. Vulnerability is rated on severity level and tracked using JIRA.

Where a compromise is identified, vulnerability fixes are released from Zoom's engineering team and follow Zoom's formal change management process for deployment to production. Zoom also has DDoS monitoring and Managed service in place. Affected traffic is diverted and filtered through a scrubbing centre. Zoom responds to incidents as defined within its SOC2 report available upon mutual NDA.

Response times: Priority 1 (Urgent): Target 1 Hour.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Customers can raises incidents with TTB via email or calling us.

If incidents are Zoom related:
When a potential incident/common event is detected, a defined incident management process is initiated by authorised personnel. Incidents are tracked through the application, which includes the corrective actions implemented.

Zoom communicates the incident response policy to internal and external users and instructs users to contact their supervisor and the information security representative if they become aware of a possible breach.

Communication will be sent out to the business detailing the issue via email. Periodic progress updates and resolution comms will be sent.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
1%
Between £500,001 and £1,000,000
2%
Between £1,000,001 and £2,500,000
3%
Between £2,500,001 and £5,000,000
4%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
ISOQAR
ISO/IEC 27001 accreditation date
Tuesday 27 January 2026
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Alcumus ISOQAR
ISO 9001 accreditation date
Monday 26 May 2025
What the ISO 9001 doesn’t cover
Exclusions:
8.3 Design and Development of products and services
7.1.5.2 Measurement traceability
Location: Gateshead
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
Viking Cloud
PCI DSS accreditation date
Monday 3 November 2025
What the PCI DSS doesn’t cover
None - The Non PCI is not covered by our certification, all PCI is covered under this certification.
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
41015739-ac20-4a9f-a558-edbab61126e0
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andrew.stokes@talktalk.business. Tell them what format you need. It will help if you say what assistive technology you use.