Secure Messaging
Stiona Secure Messaging is a cloud-hosted encrypted communication service enabling secure exchange of messages and documents with internal teams, organisations and public recipients. Supports multiple verification types, audit history, attachments and message threads. Fully managed with configurable retention and ISO27001-aligned controls, with integration available through APIs and UI components.
Features
- Secure encrypted messaging between public sector users and external recipients
- Supports four recipient types: authenticated, organisation, SMS, email.
- Recipients verified with external identity, organisation login or passcode.
- Admin portal for message management, monitoring and audit history.
- Recipients can reply; replies optionally disabled by configuration.
- Status tracking: Sent, Read, Response Submitted, Complete
- Attachment upload with configurable size and type restrictions.
- Multi-tenant isolation ensuring secure separation between organisations.
- Audit history covering all message access, delivery and actions.
- APIs enabling integration with other internal or tenant systems.
Benefits
- Enables secure communication with verified recipients across multiple channels.
- Removes reliance on unencrypted email, improving data protection compliance.
- Provides full audit trail for forensic and governance requirements.
- Facilitates structured two-way engagement, reducing operational handling effort.
- Improves traceability of decisions, improving service accountability and transparency.
- Reduces risk of misdirected information through controlled recipient verification.
- Supports fast response cycles, improving service delivery and user outcomes.
- Easily integrates with existing systems using secure API endpoints.
- Scales to support high-volume messaging with consistent performance.
- Fully managed service, reducing internal overhead and infrastructure burden.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 0 6 0 8 6 2 3 1 2 9 8 3 2 5
Contact
STIONA SOFTWARE LIMITED
Jason Malone
Telephone: 0044 7796174337
Email: sales@stiona.com
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
The Secure Messaging service is delivered as a cloud-native SaaS solution hosted in Microsoft Azure UK regions. As with all SaaS platforms, Azure availability and network connectivity represent standard technical dependencies. Azure platform maintenance or regional outage events may temporarily affect access, although resilience and monitoring minimise disruption.
Scheduled maintenance for Secure Messaging is notified in advance and arranged outside peak usage. The service requires only a supported web browser and has no dependency on specific operating systems, hardware or device types.
Beyond normal cloud platform dependencies, there are no constraints affecting adoption or daily use. - System requirements
-
- Table Internet Connection - Minimum 25Mbps download, 10Mbps upload
- Modern browser: Edge, Chrome, Safari, Firefox latest or minus one.
- Mobile app not required; service supports mobile browsers fully.
- Cookies permitted; used for secure session management and identity
- JavaScript enabled; required for secure authentication and messaging workflows.
- HTTPS required; TLS 1.2 or higher enforced for security.
- Email access required; recipients notified via secure message alerts
- SMS access required when using SMS verification authentication flow.
- No VPN required; connections optionally protected by organisational firewall.
- No additional software installation; entirely browser-based secure messaging.
User support
- Email or online ticketing support
- Yes
- Support response times
- Support for Secure Messaging is provided via the Stiona Managed Service from 08:00–18:00, Monday to Friday, with out-of-hours support available separately. SLA response times are: Priority 1 (Critical) – 30 mins, Priority 2 (High) – 1 hour, Priority 3 (Medium) – 2 hours, Priority 4 (Low) – 4 hours. Resolution times range from 4–12 hours for support issues, 8 hours–next release for defects, depending on priority. Response times reflect acknowledgement; resolution times reflect full or workaround resolution. SLAs can be tailored to meet specific buyer requirements.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Secure Messaging includes Standard Support via the Stiona Managed Service, available 08:00–18:00 Monday–Friday, with out-of-hours support available separately. Standard Support includes email/ticket assistance and knowledge base access at no additional cost. Premium Support (optional) provides 24/7 phone/email support, faster SLAs, and access to a dedicated Technical Account Manager or Cloud Support Engineer, with pricing agreed per contract. SLAs for all levels range by priority, from 30-minute response for critical issues to 4-hour response for low-priority requests, with resolution times from 4 hours to the next software release depending on issue type.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
We provide comprehensive online user documentation to help organisations get started with Secure Messaging, including step-by-step guidance for message configuration, authentication methods and recipient interactions. The service can typically be adopted rapidly without technical setup, and training needs are minimal.
Where required, additional on-boarding support is available at extra cost. This can include remote training sessions, administrator familiarisation walkthroughs, guidance on configuration choices, accessibility testing support, and assistance preparing communications and internal rollout plans. The service integrates easily with existing processes and requires no installation or specialist skills to begin use. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- All user data is stored in an Azure SQL database and can be extracted in several ways. As standard, we provide a complete CSV export of all customer data at the end of the contract at no additional cost. Service configuration can be exported as JSON at any time. Additional export formats or structured migration support can be provided on request, subject to Azure SQL capabilities and may incur extra cost. All data extractions are delivered securely and follow agreed timelines and data-retention requirements.
- End-of-contract process
- At the end of the contract, we provide a structured offboarding process to ensure a smooth transition. Included in the contract price are: export of customer data in an Azure SQL supported format, account closure, and revocation of access. Users retain full ownership of their data. Additional-cost services include assisted data migration, bespoke export formats, extended access beyond the contract end date, or support with transition to another supplier. All end-of-contract activities follow agreed security and data-retention requirements.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Secure Messaging is fully device-responsive and works consistently on desktop, laptop, tablet and mobile. All core messaging features are available on every device, including message viewing, status tracking, and replying (where enabled). The interface automatically adjusts to screen size for usability. Larger desktop screens make navigating rich message history and attachments more convenient, but there is no reduction in capability, authentication, or security enforcement when used on mobile.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Secure Messaging provides a REST-based API interface that enables secure integration with buyer applications. The API layer is logically separated into public endpoints for message submission and retrieval, and administrative endpoints for tenant configuration and audit access. All administrative APIs are protected and only accessible to authorised users.
The interface is designed to support transactional messaging workflows with encrypted transport, audit logging and granular access controls. This allows buyers to integrate secure document and message exchange into their existing systems while maintaining strict role separation, traceability and security. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Secure Messaging uses a shared component library that has been accessibility tested across multiple services using WAVE and NVDA screen reader tools. Testing covers component-level behaviours (navigation order, focus states, labels, and announcement patterns) and ensures consistent support for keyboard-only interaction.
These tested components are then assembled to form the Secure Messaging service, meaning accessibility testing benefits apply across configuration screens, message creation, recipient workflows and audit functions. Internal accessibility reviews inform refinements to improve clarity, responsiveness and assistive technology compatibility.
The service is scheduled for external accessibility testing early next year by specialist testers to validate compliance and identify further usability improvements. - API
- Yes
- What users can and can't do using the API
-
Secure Messaging has undergone accessibility testing as part of Stiona’s digital platform approach. The service is built from a shared library of UI components that have been accessibility tested and verified in other deployed services across government organisations. Internal testing has included the use of NVDA screen reader software, keyboard-only navigation, and automated checking using WAVE to identify contrast, structure and labelling issues. These checks ensure the interface provides clear focus states, navigable menu controls, consistent heading structure, and accessible messaging flows.
While Secure Messaging has not yet been individually externally audited, it will undergo third-party WCAG AA assessment as part of Stiona’s broader accessibility assurance programme early next year. Any findings from these independent tests will be incorporated into the component library and made available across all services that use it. This ensures accessibility improvements are cumulative, shared and continuously embedded into the Secure Messaging service design. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users of Secure Messaging can customise several aspects of the service to support organisational processes while maintaining secure, governed operation. Administrators can configure message templates, enable or disable reply functionality, define message retention periods, manage attachment types and configure permitted delivery verification options such as SMS, email or authenticated login. Administrators can also assign users to specific roles and manage user accounts, ensuring access aligns with organisational responsibilities. No direct changes to routing logic, role creation, security configuration or underlying platform infrastructure are permitted, maintaining predictable operation and consistent multi-tenant behaviour.
Customisation is completed through the administrative interface, where authorised users can update template wording, allow responses and set retention values. Configuration changes are applied immediately and do not require code deployment. Administrators can customise branding elements, including adding organisational name and logo for outbound communications, ensuring recipients recognise the sender and reducing phishing risk.
Users can request additional bespoke features beyond the standard functionality. These requests are reviewed through our change management process and delivered at additional cost. Typically, administrators or authorised representatives submit requests, collaborate to clarify requirements and approve release timing. Implementation is performed by Secure Messaging developers and deployed through controlled release processes.
Scaling
- Independence of resources
- The Secure Messaging service is hosted on Microsoft Azure, which provides isolation of resources through autoscaling, load balancing, and logically separated multi-tenant architecture. Each customer’s environment is allocated dedicated or appropriately partitioned compute, storage, and database resources, ensuring that performance is not affected by activity from other users. Azure’s automatic scaling adjusts capacity during peak demand, while monitoring and throttling controls prevent any single tenant from impacting others. This ensures consistent, reliable performance for all customers.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Secure Messaging provides service reporting aligned with our managed service framework. We supply quarterly service management reports including performance against agreed SLAs, service availability, planned and unplanned outages, incident volumes, severity levels, root cause resolutions, and service request volumes by type. Reports also summarise risks, issues, upcoming planned activities, and recommended service improvements.
Optional benefit realisation analytics include transaction volumes, efficiency savings from reuse, adoption and utilisation trends, and customer satisfaction insights. Benefit reporting is scoped and delivered at additional cost and can integrate into wider service governance or transformation programmes. - Reporting types
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Authorised users with appropriate roles can export Secure Messaging data using documented, secure APIs. The export capability allows retrieval of message metadata, message content, attachments, and message status information in structured formats suitable for integration with other systems or offline analysis.
All API access is authenticated and role-restricted to ensure that users can only export data belonging to their own tenant. Exported data can be consumed by downstream systems for reporting, audit, or archiving purposes, or stored securely by the customer in line with their own data handling policies. - Data export formats
- Other
- Other data export formats
- JSON
- Data import formats
- Other
- Other data import formats
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
The Stiona Digital Platform and the SecureMessaging service are hosted within Microsoft Azure UK regions and operates on a resilient, high-availability architecture. Services are deployed across multiple Azure availability zones, with active failover and geo-redundancy of database and file storage components. Continuous monitoring runs automated heartbeat tests and synthetic transactions; alerts are raised to the Stiona ServiceDesk and on-call engineers, enabling rapid response to any service-impacting events.
Stiona guarantees 98% availability during core business hours (08:00–18:00 Mon–Fri UK time) and 95% availability outside these hours. These availability commitments exclude planned and pre-notified maintenance windows. Monitoring covers
performance, connectivity, resilience events and degradation. Failover mechanisms are in place to reduce downtime and ensure continuity of service.
Backups of all customer data are taken daily and stored within geo-redundant Azure storage. Recovery Time Objective (RTO) is 4 hours and Recovery Point Objective (RPO) is 15 minutes, ensuring recovery with minimal data loss in the event of service disruption.
If availability commitments are not met over a calendar month, customers are eligible for service credits applied against the monthly subscription charge, calculated proportionately to the duration and impact of the outage. All service incidents are reviewed and root-cause analysis is performed where appropriate. - Approach to resilience
- The Stiona Platform and the FormFlow service are built for high resilience using dual-leg Microsoft Azure UK data centres, ensuring continuity during hardware, network, or site failures. It leverages Azure’s redundant compute, storage, and networking, with automated failover and backup processes. Planned annual BCDR testing with the customer can be provided at additional cost, alongside quarterly vulnerability scanning and continuous system patching to support secure operations. The FormFlow Product Roadmap Years 1–3 drives ongoing resilience improvements. These measures ensure customer data remain secure, available, and resilient under all foreseeable conditions. Further technical details on resilience and failover procedures are available on request.
- Outage reporting
-
The Secure Messaging service is continuously monitored through automated heartbeat checks and performance monitors operating within our hosting environment. In the event of a detected outage or service degradation, alerts are automatically generated and sent to the Support Desk as well as a configurable list of customer contacts via email and SMS. This ensures that incidents are identified promptly and communicated to relevant stakeholders without delay.
Planned maintenance windows and post-incident notifications are communicated in advance through the agreed customer communication channels. While a public dashboard or outage API is not currently provided, all incidents are logged, tracked and resolved through our standard incident management processes.
As part of our broader service governance, outage trends and availability summaries are reported within our quarterly service management reporting. These reports provide visibility of service performance, root causes of issues where applicable, and improvement actions undertaken.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to SecureMessaging management interfaces and support channels are tightly controlled through a central identity service supporting multiple authentication mechanisms, including two-factor authentication (2FA), identity federation with existing providers, and public key authentication (including TLS client certificates). Roles-based access control (RBAC) is used to assign permissions for application features. Public APIs are logically separated and secured with appropriate authentication and authorisation. For support, business users are onboarded to the Stiona Managed Service portal, which is SSL-protected and requires authenticated user accounts. Additional identity providers can be configured at an additional cost.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- The Stiona Digital Platform and the SecureMessaging service are managed in accordance with our ISO 27001 and ISO 9001 certified information security and quality management systems, and Cyber Essentials Plus compliance. We maintain formal information security policies and procedures covering access control, data protection, incident management, and risk assessment. Policies are enforced through regular training, audits, and monitoring, with adherence reported through our management structure, including designated Information Security and Compliance Officers. Non-compliance is addressed via documented corrective actions to ensure continual improvement and policy compliance.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- The Stiona Digital Platform and the Secure Messaging service follow ISO 27001 and ISO 9001–compliant configuration and change management processes. All components are tracked through their lifecycle, including software, infrastructure, and configuration items. Changes are assessed for security, operational, and data protection impacts, supporting customers in completing DPIAs where required. Updates aligned with the Product Roadmap are included in the service, while bespoke or early-requested changes incur additional cost. All changes are logged, tested in isolated environments, and deployed using controlled procedures. Post-deployment reviews and monitoring ensure changes perform as expected, maintaining secure, reliable, and auditable service operations.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- The Stiona Digital Platform and the SecureMessaging service follow a formal vulnerability management process aligned to ISO 27001 and CyberEssentials Plus. Potential threats to services are assessed through quarterly vulnerability scanning, risk assessment, and monitoring of threat intelligence sources, including Microsoft security advisories, CVE databases, and industry alerts. Identified vulnerabilities are prioritised based on risk and patched promptly, following controlled change management procedures. Critical security updates are applied as soon as possible, while less urgent updates are scheduled according to risk assessment. Post-patching verification ensures changes do not disrupt service. This approach ensures the service remains secure, resilient, and compliant.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- The Stiona Digital Platform and the Secure Messaging service implement continuous protective monitoring to identify potential compromises. Automated heartbeat tests track service health, with alerts sent via email and SMS to the Stiona support desk and configurable user contacts. Additional monitoring includes system logs, vulnerability scanning, and anomaly detection. When a potential compromise is identified, incidents are assessed immediately, and corrective actions are initiated according to ISO 27001–aligned incident response procedures. Critical incidents are addressed as a priority, with response times guided by defined SLAs, ensuring rapid mitigation and minimal impact on service availability and data integrity.
- Incident management type
- Supplier-defined controls
- Incident management approach
- SecureMessaging support follows ISO 27001–aligned incident management processes with pre-defined procedures for common events, including service disruptions, security alerts, and system faults. Users report incidents via multiple channels which trigger automated notifications and escalation workflows. SLA response times are Priority 1 (Critical) – 30 mins, Priority 2(High) – 1 hour, Priority 3 (Medium) – 2 hours, Priority 4(Low) – 4 hours, with resolution ranging from 4–12 hours for support issues and 8 hours–next release for defects. Post-incident reviews are conducted for high/critical incidents which produce reports summarising root cause, resolution, and preventative actions to ensure continuous improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 4%
- Between £1,000,001 and £2,500,000
- 6%
- Between £2,500,001 and £5,000,000
- 8%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Thursday 19 June 2025
- What the ISO/IEC 27001 doesn’t cover
-
Our ISO/IEC 27001 certification covers the design, development, hosting and support of the Stiona Digital Transformation Platform, which provides the common core technology, services and operational controls used to host the FormFlow solution. All services within scope operate within Microsoft Azure UK regions, supported by ISO/IEC 27001 certified underlying infrastructure, with Stiona applying additional layered security, governance and operational controls.
The certification applies to the secure operation of the platform, its shared components, resilience measures, data handling processes, and the management system used to govern these. FormFlow, when hosted on the Digital Transformation Platform, inherits these security controls.
As part of this declaration, the following are not covered by the certification scope:
>Customer-owned devices, IT infrastructure, identity stores or environments outside the Stiona platform.
>Customer-managed configuration or administration of their own users (e.g., identity provider policies or access governance).
>External third-party systems integrated with FormFlow (e.g., payment providers or data sources), unless they are independently certified.
>Customer-defined business processes that sit outside Stiona’s hosted platform control.
>Any deployment of FormFlow or platform services to customer-owned Azure subscriptions unless explicitly included under a separately agreed SoA extension.
This statement reflects the defined scope and SoA (version 2.2.0, dated 12/5/2025) - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- NQA
- ISO 9001 accreditation date
- Monday 8 December 2025
- What the ISO 9001 doesn’t cover
-
Stiona’s ISO 9001 certification covers the design, development, hosting and support of the Digital Transformation Platform, which provides a common core infrastructure of shared digital systems, technology and processes for government and private sector customers.
The ISO 9001 scope does not extend to customer-specific operational processes, business policies, or organisational procedures implemented by customers when using the platform. Responsibility for how customers configure workflows, manage user access, define retention policies, or operate their own business processes using the service remains with the customer.
The certification also does not cover third-party services, integrations, or external systems that customers may connect to the platform, including identity providers, notification services, or downstream applications not operated by Stiona. Availability, quality management, and service delivery for those external components sit outside the scope of Stiona’s ISO 9001 certification.
In addition, the certification does not cover bespoke professional services, consultancy, or optional additional services delivered outside the standard platform service, which are governed by separate contractual arrangements and delivery controls.
Customers remain responsible for ensuring their own compliance with applicable laws, policies, and organisational requirements when using the services. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 2de34373-dcc6-4d1a-9e8c-34dca505158d
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 4b695eb6-5888-4775-b3cf-ed2c49818143
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-