Device / Endpoint management
Astaris provides device and endpoint management covering lifecycle, inventory & remote monitoring. The service supports Cyber Essentials, Cyber Essentials Plus, ISO27001 and PCI Compliance with analytics and reporting to provide visibility, audit assurance and SLA compliance.
Features
- Software & firmware patching and updating
- Threat detection and remediation
- Secure, fast and reliable devices
- Reporting and Analytics
- Lifecycle management with reporting
- Asset tracking and inventory
- Consistent user experience including when needing support
- WEEE Compliant disposal of end of life devices
- Support is wholly from a UK based team
- Enterprise grade printers from Xerox and Brother
Benefits
- Predictable costs & reliability
- Reliable endpoints backed with SLA
- Ease of access to UK based support
- Compliant for achieving Cyber Essentials (Plus)
- Compliant for achieving ISO27001 and ISO9001
- Compliant for achieving PCI DSS status
- Flexibility in deployment locations and timescales
- Reporting and analytics
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 7 9 6 6 6 8 4 1 5 7 2 9 7 5
Contact
TWO PEAS IN A POD LIMITED
Ivan Spencer-Phillips
Telephone: 01273359133
Email: tenders@astaris.co.uk
About the service
- Service categories
-
- Systems Infrastructure Software
- Endpoint management
- Output management
- Device Management
- Print Management
- Client endpoint management
- Unified Endpoint Management
- IoT Device Management Software
- PC Life-Cycle Management
- Output management
- Endpoint management
- Systems Infrastructure Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Microsoft Office 365 / InTune and / or Google Workspace.
Hardware vendor management solutions (eg. Brother BRAdmin tool for managing fleets of printers) - Cloud deployment model
- Public cloud
- Service constraints
-
Devices have to have manufacturer supported operating systems. ie. cannot be end of life.
Remote management / interaction with devices requires reasonable speed internet connectivity. - System requirements
-
- Reasonable internet connection speed
- Operating system must not be end of life
- Software must not be end of life
User support
- Email or online ticketing support
- Yes
- Support response times
-
Astaris ensures 24/7 technical resilience through a tiered SLA system. Our on-call engineers and management guarantee high availability during and outside office hours.
Managed Service Levels:
High (Critical): 1-hour response / guaranteed resolution within 4-hours
Medium (Standard): 4-hour response / guaranteed resolution within 8-hours
Low (General): 8-hour response / guaranteed resolution within 16-hours
Users can instantly escalate requests by including "URGENT" in email subjects. Failure to meet these targets entitles customers to Service Credits applied to the next monthly fee. This "Always-On" approach ensures Astaris remains fully accountable for your mission-critical uptime. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- AI chatbot
- Yes
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Astaris supports multiple charitable organisations who employ people with all sorts of assistive needs. Many of these users prefer to use email / web chat over phone conversations. Some of these users work with confidential data so find that secure web chat and a privacy screen on their laptop is strongly preferable to a telephone conversation in their crowded workspace.
- Onsite support
- Yes, at extra cost
- Support levels
-
Astaris delivers a comprehensive managed service for the deployment and management of cloud-based software, ensuring your organisation’s digital tools are optimised, secure, and resilient. We provide an end-to-end service that covers everything from initial architectural design and seamless data migration to proactive 24/7 technical oversight.
24/7 Real-Time Monitoring: Using advanced RMM tools, we track the health of servers and cloud services, resolving glitches before they impact your staff.
Automated Patch Management: We automate critical security updates across Windows, macOS, Linux, Android and iOS to eliminate vulnerabilities.
Predictive Maintenance: By analyzing trends like hardware wear or CPU spikes, we intervene early to prevent costly emergency downtime.
Managed Security Oversight: We proactively hunt for threats using SentinelOne AI and Cisco Umbrella, blocking emerging cyber risks at the source.
Strategic IT Reviews: Regular "Technology Alignment" audits ensure your IT strategy evolves alongside industry best practices and your business goals.
By leveraging industry-leading platforms, we ensure your cloud software environment is expertly configured to meet modern compliance standards while providing staff with the high-performance tools they need to work productively from any location.
Preventative Maintenance £22.00 per device
See pricing document for full service details - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Users are onboarded with Astaris by either staging onsite training or remote training. On-site training consists of a qualified engineer attending site and going through the system and processes of the services we provide. If users do not want onsite training, there is the option to do remote training, which includes a group or 1-1 training session with a qualified engineer. Users are given a “How to Get Started“ document and are provided with information on where to go for support requests if needed. Any past issues users have are also ironed out in the onboarding phase, as this ensures users start our service with no past issues that have not been addressed. After the onboarding is complete, documentation about the customer is logged in our knowledge base system for future support, where our departments can refer to if needed.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- Documentation accessibility standard
- WCAG 2.2 AA
- End-of-contract data extraction
-
Strategy & Exit Planning: We work with the client to define an exit strategy. This includes identifying all data locations, service dependencies, and the final "termination" date to ensure a smooth transition without data loss.
Data Extraction & Portability: Astaris provides all customer-owned data in a structured, industry-standard format (ie. .PST for email or .CSV/.ZIP for files). We ensure that all data is portable and ready for migration to a new provider or an on-premises system.
Access & Identity Revocation: Once the migration is confirmed, we systematically revoke administrative access. This includes decommissioning relevant Microsoft Entra (Azure AD) identities, removing devices from Microsoft Intune, and disabling security agents like SentinelOne and Cisco Umbrella.
Security & Compliance Sanitization: To meet GDPR/Cyber Essentials standards, Astaris performs a secure "data wipe" of any cached information on our internal management systems. We provide a formal confirmation that all client data has been deleted from our infrastructure while the client retains the master copies.
Handover & Final Documentation: We provide a final documentation pack to the new provider or the client's internal team. This includes network diagrams, license schedules, and an inventory of assets to ensure the new team has everything they need, - End-of-contract process
-
Astaris ensures a secure, professional exit through a structured data offboarding process under G-Cloud 15. Our priority is maintaining your total data ownership while ensuring a transition with zero security gaps.
- Collaborative approach, providing your incoming provider with all necessary technical documentation and knowledge transfer to maintain operational integrity.
- Ensure transparency, no exit fees for data retrieval
- Engineering time is billed clearly according to our G-Cloud 15 SFIA Rate Card
- Guaranteed Data Sovereignty, ensuring your information remains under your 100% control until it is safely transferred and securely purged from our systems
- Your departure is as organized as your onboarding.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The main difference between mobile and desktop services is the user interface and layout. The interface or layout may appear differently depending on what device you are using to access the service. Our desktop service offers full functionality with no restrictions, whilst our mobile service is optimised for on-the-go users who need to use our service quickly and efficiently by having a simplified interface. Some features that you may not be able to see on mobile are analytics, custom filters and integrations.
- Service interface
- Yes
- Description of service interface
- The service interface is a self-service ticketing system which users can log, track and resolve users issues. Users have 2 ways of accessing our service interface: email our support address, where issues will be forwarded into our ticketing system or raise a new case via the web portal. The portal provides a centralised dashboard to view all your past/current tickets and the ability to access a knowledge base that provides basic how-tos. You can also live chat with engineers through this service interface if your issue is urgent.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Our service interface has been tested to ensure it is accessible for users who need to use assistive technology. Testing includes ensuring services are compatible with the following:
ADHD Friendly - Reduces distractions and creates a more focused experience.
Astigmatism - Optimised the page to reduce fuzziness and glare, alleviating strain on the eyes.
Blindness - Uses your device's screen reader and keyboard to navigate the service interface efficiently.
Colour blindness - Make it easier to discern and distinguish between colours.
Dyslexia Friendly - Enables features to improve readability.
Epilepsy Safe - Reduces motion and changes of appearance to prevent adverse reactions
For the Elderly - Makes the page clear and easy to read to help the elderly work without distractions.
Low Vision - Makes the interface accessible for a wide spectrum of low vision users by enhancing visual elements and improving legibility.
Motor Disabilities - Helps users navigate the interface efficiently using the keyboard and mouse.
Seizure Safe - Reduces motion and changes of appearance to prevent adverse reactions
Keyboard Navigation - Enabled motor-impaired users to use the interface using the keyboard Tab, Shift +Tab and Enter keys - User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Zoho Desk offers extensive end-to-end customisation for its ticketing interface:
Create custom fields to capture industry-specific data. Display only fields that are relevant to a department and specific workflows.
Dynamically show or hide fields and sections based on previous user input, reducing clutter and guiding agents through complex processes.
Default statuses (Open, On hold) can be modified, and custom statuses like "Waiting on Customer" can be added to reflect unique business processes. Priorities can also be customised with specific values.
Configure department-specific ticket IDs with custom prefixes, suffixes, and unique starting numbers to improve organisation and recognition.
Customise views with different display modes, color themes, and adjustable font sizes for better accessibility.
The customer-facing portal can be rebranded with company logos, favicons, and custom domain mapping. Advanced users can use HTML, CSS, and JavaScript editors to completely rebuild headers, footers, and page styling to match their main website.
Navigation tabs can be renamed, reordered, or hidden. Agents can create custom list views using up to 250 filters to organise tickets according to specific criteria.
Create buttons within the ticket detail page to trigger custom functions, execute workflows, or open external URLs with placeholder data from the ticket.
Scaling
- Independence of resources
- The management tools are hosted in public clouds from vendor specialists who soley look after the tools set hosting. These highly elastic and resilent clouds give extremely high uptime and reliability. Even if the management plane / cloud controller becomes temporarily unavailable, the customer systems they control continue to run and function without interruption or issue.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service desk / management system provides a wide variety of metrics that can be reported upon. These include: SLA & Overdue ticket compliance, volume of tickets, Response and resolution time monitoring, "customer happiness" scoring, ticket statuses, ticket sources (web, phone, chat etc), reopened tickets, failed, pending, applied and pending patches and many other similar metrics. As well as these standard reports in the ticketing tool, the underlying raw data can be automatically imported to a full analytics suite at no extra cost.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Multiple vendors including Cisco, Mimecast, Sentinel, NinjaOne, Xerox, Brother
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
-
To export data users follow a structured exit and extraction process:
Customer-owned data is provided in industry-standard formats, such as .PST for emails and .CSV or .ZIP for files.
Users work with the provider to identify all data locations and service dependencies before a set "termination" date to prevent loss.
Extracted data is prepared to be compatible with new service providers.
Once migration is confirmed, the provider revokes administrative access and performs a secure data wipe of cached information on their internal systems to ensure compliance.
Users receive a final handover pack containing network diagrams, license schedules, and asset inventories. - Data export formats
-
- CSV
- ODF
- Other
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
- Other import / export formats may be possible
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Astaris provides consistent availability during working hours and outside working hours as it is managed through a tiered SLA system. Helpdesk Management prioritises issues into the selected tier based on the impact to the customer's operations. High Priority: For critical issues, a guaranteed response within 1 hour and a guaranteed resolution within 4 hours. Medium Priority: For standard functional issues, a guaranteed response within 4 hours and a guaranteed resolution within 8 hours. Low Priority: For general inquiries or minor requests, a guaranteed response within 8 hours, with resolution guaranteed within 16 hours. Availability can be met outside of the office hours by calling our support line or emailing. Management is always available to work alongside the on-call engineer for out-of-hours work to ensure availability and SLA’s are met. SLA’s can be triggered by the end customer by inputting keywords like “URGENT” in the subject line. Management is then notified to assign a resource to prioritise and deal with the issue. Any breach of SLA will trigger service credits and an in depth collaborative investigation to ensure no repeat.
- Approach to resilience
- The SaaS items that Astaris supplies are resold 3rd party services (with additional support etc added by Astaris). The vendors are selected by Astaris for their reputation, size and reliability. All vendors are of “enterprise” grade with 1000’s of customers and have been established for 10+ years. This approach ensures that these vendors are highly experienced, well resourced and are able to instantly scale and expertly support their SaaS when needed. Where Astaris support is required then peaks in demand are dealt with triage & prioritisation of incoming requests, activation of additional personnel and SLA compliance.
- Outage reporting
- Astaris publishes status updates for all the services that it supplies on an external / independent service (statuspal.io). This ensures that the reporting of outages of any system or service does not depend on any of those systems or services. This public dashboard service can be subscribed to for alerts by email, SMS and Chat (Slack, Teams, Google Chat and others). There is also an OpenAPI interface for the alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access has a “least required access” policy applied. User support channels used a secondary method of verification.e.g. If contact is by telephone, then is the user’s voice recognised AND are they calling from a number that is known to belong to that customer? If not, then contact is made with their line manager for confirmation of the request. Management interfaces are disabled by default and are restricted by: Multi factor authentication and strong password requirement Only authorised users who specifically request access Known IP addresses or specific countries allowlisting Disablement of accounts that have not been used in 90 days
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Software Security Code of Practice
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
- Each security product / component that Astaris uses / deploys to customer systems has a product specialist supported by vendor accreditation and training. These specialists report to the service desk manager to ensure that clear oversight exists across all the ecosystems and products. Internally and for customer systems Astaris puts in place clearly defined Acceptable Use Policies (AUP), well defined Access Control Policies based on “least required access” methodologies. Operational information security policies are covered by the Identity & Access Management process / workflow, the Vulnerability management process / workflow and the strict implementation of Change Management processes and approvals. All of these processes / ecosystems are wrapped in a Backup and Disaster recovery envelope that is managed independently of the processes / ecosystems that it contains. Astaris long experience of working to ensure information security means that the solutions, ecosystems, processes and practices are appropriate for businesses and are practical / useable for users so that they are easily able to comply with the requirements and not find them onerous or that it’s easier to find “shadow IT” methods to work around overly complicated processes and procedures.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Astaris approach to configuration and change management is best described as “cautious”. Changes are assessed for possible worst outcome impacts initially and then depending on the weighted risk score, suitable mitigation and prevention strategies are employed. These may include: peer review, whole system backups, applying to test bench systems first, out of hours deployment,
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Potential threats to our services are reviewed by checking automated vulnerability scans and advisories. Potential threats are evaluated for severity and impact on service to determine the risk they pose to our service.
Patches are deployed as soon as a risk assessment is completed with testing. It is pushed out typically within days and lower risk items are pushed to deployed via the maintenance window.
Threat information is passed from vendors who provide advisories, automated scanning tools and mailing lists. We also continuously monitor trusted cybersecurity sources like the National Cyber Security Centre. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Tools are used to proactively monitor, analyze, and detect potential compromises before they happen. Log analysis helps identify and correlate suspicious activity. A dedicated incident response team assesses, remediates, liaises with the customer, and documents actions, generating a report outlining the cause, fix, and preventive measures. Incidents are classified by severity and actioned according to response procedures, with detection, investigation, and containment typically initiated within minutes depending on severity.
- Incident management type
- Supplier-defined controls
- Post-quantum cryptography secure
- No
- Incident management approach
-
Each event will have a series of processes that will be followed. This includes identification, prioritisation, containment, investigation, remediation and a post-incident review.
Users can report incidents by calling our Helpdesk or raising a ticket via our service interface.
Incident reports are provided to customers via secure channels and will include a full post incident analysis with recommendations for prevention if not actioned already. Documents will include the event details, impact and actions taken by our team.
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1.5%
- Between £250,000 and £500,000
- 2.5%
- Between £500,001 and £1,000,000
- 5.0%
- Between £1,000,001 and £2,500,000
- 7.5%
- Between £2,500,001 and £5,000,000
- 15.0%
- Over £5,000,001
- 20.0%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- QAS International
- ISO/IEC 27001 accreditation date
- Monday 23 December 2024
- What the ISO/IEC 27001 doesn’t cover
- N/a
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- QAS International
- ISO 9001 accreditation date
- Monday 23 December 2024
- What the ISO 9001 doesn’t cover
- N/a
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 880e7b83-cea6-4ec3-82af-e86173ed75f7
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce