Skip to main content

Help us improve the Digital Marketplace - send your feedback

BRITISH TELECOMMUNICATIONS LIMITED

BT UK Secure Cloud Max

BT’s Solution delivers secure, industry-compliant cloud platforms in the UK through dedicated or multi-tenant environments integrating compute, storage, networking, and cloud management. Fully managed by BT, the solution uses security vetted staff, secure tools, dual-DC architecture, and provides 99.99% annual availability in line with NCSC guidelines compliance.

Features

  • Dedicated or secure multi-tenant private cloud options
  • Air-gapped, dedicated management environment securing customer platforms
  • Policy-driven access controls for all workloads
  • Strict role-based access control guardrails
  • Dedicated SIEM with optional 24/7 Security Operations Centre
  • Fully aligned with highest NCSC guidance
  • Compliant with NCSC, DSP Toolkit, PCI standards
  • ISO 27001, ISO 9001, Cyber Essentials+ certified
  • Paired, resilient ARK datacentres across two UK regions
  • Automated, NCSC-compliant infrastructure with multiple security domains

Benefits

  • Securely manage platforms through an isolated, air-gapped environment for protection
  • Automatically enforce role-based access controls and workload policies across environments
  • Continuously monitor threats using integrated SIEM capabilities and dedicated SOC
  • Meets NCSC, PCI, and government compliance requirements for assured security
  • Accelerate cloud adoption using scalable templated deployments and flexible pricing
  • Resilient workloads across dual, highly available datacentres ensuring continuous service
  • Dedicated or multi-tenant private cloud options to meet organisational requirements
  • Protect data using encryption at rest and robust confidentiality controls
  • Compliant sovereign cloud operations through ITIL guardrails and automated governance
  • Maintain predictable costs enabling accurate budgeting throughout the service lifecycle

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ccsframeworks@bt.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 2 3 6 3 5 7 9 4 0 4 7 7 2 1

Contact

BRITISH TELECOMMUNICATIONS LIMITED Frameworks Team
Telephone: 0800 328 8077
Email: ccsframeworks@bt.com

About your service

Service categories

IaaS

IaaS Compute

Virtualised x86

  • General purpose
  • Compute optimised
  • Memory optimised

Service scope

Service constraints
BT operates this service as a fully managed solution. Occasional maintenance windows may be required and will be agreed through the service change control process. The platform follows BT architectural standards, with any deviations managed strictly via change control. All servers are hardened to agreed security baselines and protected behind managed firewalls; any firewall policy changes require formal security review and approval. The shared platform requires a minimum commitment of 10 VMs or 1 TB of storage. Custom VM SKU configurations are not supported, and only standardised vCPU and memory profiles can be provisioned to maintain consistency and compliance.
System requirements
  • Any application needs to be Vmware compatible
  • Certain applications need to be mutually agreed from monitoring perspective
  • Each environment is configured to meet customers specifications
  • BYO (Bring Your Own) licence available for customers
Cloud deployment model
Private cloud

User support

Email or online ticketing support
Yes
Support response times
Customers can raise support requests by email or through the secure portal, where all interactions are logged and managed within BT’s UKSSP Service Desk on ServiceNow. Proactive issues are automatically identified and prioritised, while customer raised tickets are triaged to ensure they reach the right teams quickly. High priority incidents are acknowledged in line with defined service timelines, keeping customers informed throughout. Every ticket is tracked end-to-end with SLA monitoring, regular updates, and clear resolution reporting. The service operates 24/7/365, ensuring customers always have access to support whenever required.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
No
Support levels
BT provides a structured, multitier support model designed to give customers the right level of expertise at every stage. Our Standard Support offering, defined in the SLA, includes Level 1, 2 and 3 support to ensure fast incident response, efficient triage, and access to deep technical skills when needed.

Customers are also supported by a named Technical Designer or Lead Cloud Engineer who acts as their primary technical contact. This specialist understands the customer’s deployed solution in detail and works closely with customer teams to provide proactive guidance, continuity, and effective coordination across all support activities. Their role ensures smoother operations, faster issue resolution, and a more personalised support experience throughout the service lifecycle.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Following contract signature, BT begins onboarding with a kickoff meeting that introduces your account team, confirms key requirements, and outlines the onboarding approach and deliverables.
Throughout onboarding, BT provides structured implementation and knowledge transfer support. Once your solution design is agreed, we identify the training and documentation you need and deliver these through technical walkthroughs, online or remote sessions, and tailored user documentation. A dedicated Technical Designer or Lead Engineer works closely with your teams to gather solution details and provide clear, role specific guidance, ensuring your users understand how to operate the service confidently and effectively.
Training may include user guides, CBTs, knowledge articles, operations manual updates, demonstrations, or runbook walkthroughs.
As onboarding progresses, BT prepares a comprehensive Customer Handbook. This includes key contacts, roles and responsibilities, service details, service models, escalation paths, ITIL processes, security and compliance information, and how to provide feedback. The Handbook is issued at service handover, giving you a complete reference to help you use and manage the service with confidence.
You will also receive a demonstration of the secure UKSSP MyAccount portal, covering user setup, ticketing, documentation access, and how to raise requests, changes or incidents.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract, customers can extract their data using cloud-specific native tools, subject to BT’s approvals and security requirements. BT can provide project resources, at an additional cost, to assist in migrating workloads into or out of the platform. Upon request, BT may attach a portable device to the customer’s servers; the customer is responsible for providing security insurance for the device. Customers are fully responsible for transferring their data to their own site and for ensuring that personal data, sensitive personal data, and other sensitive information are protected, including through encryption.
End-of-contract process
At the end of the contract, customers can extract their data using cloud-specific native tools, subject to BT’s approvals and security requirements. BT can provide project resources, at an additional cost, to assist in migrating workloads into or out of the platform. Upon request, BT may attach a portable device to the customer’s servers; the customer is responsible for providing security insurance for the device. Customers are fully responsible for transferring their data to their own site and for ensuring that personal data, sensitive personal data, and other sensitive information are protected, including through encryption.

The notice period for non-renewal is 90 days before the end of the term, and the contract does not automatically renew unless mutually agreed. BT commits to planning, cooperating, and providing exit assistance in a timely manner to ensure a smooth transition of services with minimal disruption to the customer’s operations. Services will continue to be provided until the transfer is fully complete.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Using the web interface
BT delivers this service as a fully managed environment, ensuring your platform remains stable, secure and aligned to the certified design. All changes are controlled through BT’s governance processes, protecting the integrity of your environment and preventing unauthorised modifications.
Through BT’s secure UKSSP MyAccount portal, users can:
• Raise an Issue: Log a case to report any problems within their environment.
• Request Services: Submit service requests directly from the available catalogue.
• Track Tickets: Monitor progress and interact with the service desk on open cases.
• Access Knowledge Articles: View relevant guidance before raising a ticket.
• View Products and Install Base: Check details of subscribed services and deployed assets.
• Use Role Based Access: Ensure users and managers see cases appropriate to their permissions.
The portal provides a simple, transparent way to engage with BT’s service teams, helping you manage issues quickly, stay informed, and maintain full visibility of your service estate. It improves communication, speeds up resolution and gives you greater control over your day-to-day service experience.
Web interface accessibility standard
WCAG 2.2 AA
Web interface accessibility testing
At BT we are committed to digital inclusion. Our services are for everyone regardless of any differences. We are actively working towards increasing the accessibility and usability of all our online communications, by complying to level AA of the World Wide Web Consortium (W3C) Web Content Accessibility Guidelines 2.2 (WCAG) as a minimum.
API
No
Command line interface
No

Scaling

Independence of resources
BT’s Solution has two options i.e. Single Tenant (Dedicated) & Multi-Tenant (Shared). Where customers choose the shared instance, they have the choice between VMs having 4:1 or 1:1 contention against the underlying compute platform. In a shared compute infrastructure VMs are monitored and moved between hosts to ensure that there is sufficient resource available to provide the required compute, and for 1:1 VMs, the VMs on the host will not exceed the total host resources. This scenario also applies to dedicated compute to protect user VMs from user workloads in the same organisation.
Usage notifications
Yes
Usage reporting
Email
Optimising consumption
Yes
Automatic scaling
No

Analytics

Infrastructure or application metrics
Yes
Metrics types
  • CPU
  • Disk
  • HTTP request and response status
  • Memory
  • Network
  • Number of active instances
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Rackspace

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Backup and recovery

What’s backed up
  • Fully managed image-level backups for all customer virtual machines
  • Daily image-based backups using Changed Block Tracking
  • Production environment operating system instances
  • Customer-provided virtual appliances
  • Default or bespoke backup policies selectable during onboarding
  • Onsite backup retention for fourteen calendar days
  • Replicated backups to disaster recovery site
  • Full-disk restores from supplier-provided backup images
  • Optional extended retention via additional service order
  • File, database, application backups require customer-provided solutions
Backup controls
Backup policies and schedules are defined during service transition with changes managed via agreed change control process.
Datacentre setup
Multiple datacentres with disaster recovery
Scheduling backups
Users contact the support team to schedule backups
Backup recovery
Users contact the support team
Backup and recovery
Yes
RPO/RTO
Yes

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
BT’s Solution is offered in Dual DC architecture with a 99.99% availability measured on an annual basis. The Availability Service Level is measured as the availability of the Service.
Requests for Service Credits: You may submit one request for applicable Service Credits per calendar month, within 10 days of the month’s end in which a Severity Level 1 Incident occurred, providing details of the claim.
Failure to submit a request timely constitutes a waiver of any claim for that month. If a single Severity Level 1 Incident or connected series results in multiple Service Level failures, you may select one failure for which a Service Credit is awarded; no credit will be given for other failures from the same Incident.
Upon receipt of a valid request: BT will issue applicable Service Credits by invoice deduction within two billing cycles or, if no further invoices are due, pay within a reasonable period.
Approach to resilience
Available on request.
Outage reporting
BT’s Service Desk will provide outage reports through emails. Following a major incident, a customer may request an Incident Report from the BT’s Account team/ Service Delivery Manager. This report will be delivered via email and contains a summary of the events that occurred, along with a root cause analysis and preventative actions.

Identity and authentication

User authentication needed
Yes
User authentication
Multi-Factor Authentication (MFA)
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is controlled through platform security, role-based access control, and operational governance to enforce least privilege. The integration via Unify ensures authenticated data exchange, with incident bonds limited to a dedicated user account and securely shared credentials. RBAC restricts integration accounts to API-only access, scoped to essential tables and actions, while development and maintenance require authorized roles and approvals. Support is provided 24x7 by an UK onshore team, following defined access procedures, with role-specific access, auditable actions, and no direct access to integration credentials or secure bond configurations.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
Devices users manage the service through
Dedicated device on a segregated network (providers own provision)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
BT operates a UK Shared Service Platform (UKSSP) that is UK Government PSN certified (SRV_0030 Management Service) ensuring the service meets security, technical, and operational standards. In addition, SSP is in the process of becoming CE+ certified.
Subcontractor standards include: HITrust, ISO27017 and CE+
Information security policies and processes
The SSP security policy is defined in the PSN Security Handbook PSN.POL.4638. This is an internal document that refers to BT security standards and policies. All users undergo a formal onboarding and identity verification process ensuring access is role based, least privilege, and subject to periodic review and time bound revocation. Controls are defined in PSN.SEC.2507 SSP All Staff SyOps and embedded into operations then reinforced by mandatory security training for all personnel onboarded.
Acceptable Use and Protective Marking policies govern the handling and storage of information in accordance with classification. SSP’s hosting locations are subject to HMG sign-off, providing validated physical and environmental security.
Security governance is exercised through a local Security Board with defined terms of reference, risk ownership, and escalation routes. Engineering and Delivery teams operate under line management direction, however accountability for information security is independent of line management responsibility to ensure separation of duties.
Where required the SSP Security Architect interfaces into the BT Digital Security Lead who can feed into a monthly reporting pack for board level representation.

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Operational change management is a key ITIL practice in IT service management. It ensures all changes are assessed for risk and impact, reducing unplanned downtime and rework. A Forward Schedule of Change provides an overview of upcoming and ongoing changes to prevent conflicts. All changes should include pre- and post-implementation testing to mitigate potential security breaches. Changes may address vulnerabilities, such as OS upgrades, patching, or firewall adjustments. Updates to Configuration Items are reflected in the Configuration Management Database (CMDB), ensuring accurate, timely information for all items.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Vulnerability scans are performed on a quarterly basis at a minimum but can be run on-demand if required. Any vulnerabilities that may be identified will generate support tickets as part of the scan process. These tickets are alerted to the assigned Lead Engineer for management purposes and to ensure actions are carried out in a timely manner.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
The service employs sophisticated software-defined service instrumentation and monitoring that integrates at the component or server level, the data centre edge, our network backbone, Internet exchange sites and at the user level. This provides visibility when a service disruption is occurring and pinpointing its cause. Proactive monitoring continuously measures the performance of key subsystems of the services platform against the established boundaries for acceptable service performance and availability. When a threshold is reached, or an irregular event occurs, the monitoring system generates warnings so that operations staff can address the threshold or event.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
BT’s Services follows predefined ITIL-based processes for proactive and reactive incident management. It’s Secure Service Desk provides first-line support, logging incidents in ServiceNow and assisting customers. Incidents unresolved at first line are escalated to resolver teams for resolution. Customers can also access the MyAccount portal (BT's UKSSP Platform) to raise issues and track tickets. Based on customer request, BT delivers monthly reports to the customers for their IT estate hosted in BT’s Platform, ensuring transparency and efficient monitoring of customer environments.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Separation between users

Virtualisation technology used to keep applications and users sharing the same infrastructure apart
Yes
Who implements virtualisation
Supplier
Virtualisation technologies used
VMware
How shared infrastructure is kept separate
BT’s Solution have dedicated PoDs for different verticals, including Govt, Healthcare, Police, and Commercials, utilizing Virtual Data Centres (VDCs). BT provide Single Tenant & Multi-tenant infrastructure. On the multi-tenant platform, infrastructure is shared only among Government customers. Data is encrypted per customer at the storage level, while compute resources can be either shared or dedicated based on workload requirements. Logical network segregation is ensured through native hypervisor technologies. Customers can choose their preferred deployment model: fully shared, dedicated compute, dedicated compute with storage, or a fully dedicated platform.

Energy efficiency

Energy-efficient datacentres
Yes
Description of energy efficient datacentres
BT’s partner has committed to achieving net zero carbon emissions by 2045. This is five years ahead of the UN Paris Agreement on Climate Change ambition to limit the global warming of the planet to 1.5 degrees Celsius, compared to pre-industrial levels. They have begun the process of automating their large facilities with smart, energy-saving features that, so far, have resulted in a 2,000-kilogram reduction of C02 in the main office in UK, in Hayes. Theye have assembled a cross-functional team to define their ESG -related goals more clearly so they can better measure their impact in the future. They have also invested in and are deploying smart building automation systems in five locations globally and three data centres, both including London. These systems will drive reduced energy consumption in each of these locations, through building control systems that provide the ability to efficiently manage light, heat and cooling zones based on operational demand.

Pricing

Discount for educational organisations
No
Free trial available
No

Discount

Provide your minimum discount applicable to your baseline prices
0%

Formula for calculating price of your services

Formula for calculating price of your services

Which of the core deployment models you intend to offer

Private Cloud

Private Cloud - Formula for calculating price of your services


Total Cost
The Total Cost for a buyer's call off requirement in a Private Cloud Deployment
=
Baseline Pricing
Buyers will find baseline unit pricing within the G-Cloud service listing pricing document(s) for “UK Secure Cloud Max – Fully Managed” (e.g., per VM per month, per vCPU/RAM per month, per TB per month, backup/retention, and any managed service components).

Total Call-Off Cost (Cloud) =
(Σ [Baseline unit price × quantity × term])
− (Minimum discount % × Σ [Baseline unit price × quantity × term])

The charges shows the Onboarding (one-off) OTC
Ongoing charges are in addition to this.
Although BT takes every effort to ensure the pricing published here aligns as closely as possible to the described scenarios, all prices are calculated against our standard Cloud service configuration. Any deviation from the standard offering—such as bespoke requirements, non-standard product variants, or customer-specific assumptions—may increase or reduce the overall costs.
-
Minimum Discounting
0%
+
Onboarding Activity
Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
+
Additional sources of cost
a) One-off professional services for discovery, solution design, project management, implementation planning, and service acceptance activities.
b) Migration and transition activities, including application/VM/data migration, cutover support, testing support, and legacy environment decommissioning (where not included in baseline onboarding).
c) Connectivity and network integration requirements, such as dedicated private connectivity, complex routing/firewall changes, integration to Buyer WAN/SD-WAN, PSN/HSCN/other Buyer connectivity patterns, or bespoke DNS/IPAM requirements.
d) Security and compliance requirements above the standard baseline, such as enhanced logging/SIEM integration, non-standard key management/HSM, bespoke security tooling, or additional assurance/audit activities requested by the Buyer.
e) Non-standard service configurations (beyond the published baseline), such as bespoke HA/DR design, higher availability targets, specialised performance profiles, or custom backup/retention policies.
f) Third-party software/licensing required for the Buyer’s workloads (for example operating system subscriptions, database licences, backup agents, security tooling), where these are not included in the baseline service price.
g) Out-of-hours or accelerated delivery requirements (where the Buyer requests delivery timescales beyond standard lead times).
-
Additional sources of cost reduction
1. Reduced quantities/consumption by the Buyer (for example fewer VMs, lower vCPU/RAM sizing, reduced

2. storage capacity, or lower backup retention), charged at the same baseline unit rates.

3. Selection of standard service patterns (standard VM profiles, standard landing zone, standard monitoring/backup policies) which reduces bespoke build and professional services effort.

4. Removal of optional services not required (for example bespoke integrations, enhanced security options, complex connectivity, migration services, or out-of-hours support), reducing one-off and/or recurring charges.

5. Optimisation activities (rightsizing, decommissioning unused resources, schedule-based shutdown for non-production, storage tiering where offered) which reduce monthly consumption-based charges.

6. Commercial reductions agreed at call-off (for example additional discretionary discount above the published minimum discount, where offered) and/or commitment-based pricing where applicable.

Mandatory certifications

Mandatory certifications

Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure

Reseller

Cloud service suppliers you intend to resell with evidence

Organisation 1

Organisation name

Rackspace Limited

Website address/upload for organisation

Website address

Website address

https://www.rackspace.com/en-gb/strategic-alliances/bt

ISO 9001 certification

Provided

ISO 27001 certification

Provided

ISO 20000-1 certification

Provided

Are you reliant on the Cloud Service Provider for some accreditations

Yes

Cyber Essentials

Do you have a Cyber Essentials Plus certificate?
Yes
Cyber Essentials Plus certificate Number
31cf450d-d8be-4c72-9251-45f5a9a4025a

Non-mandatory Standards and certifications

ISO 28000:2022 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ccsframeworks@bt.com. Tell them what format you need. It will help if you say what assistive technology you use.