Skip to main content

Help us improve the Digital Marketplace - send your feedback

PEGASYSTEMS LIMITED

Pega Cloud including Pega Government Platform and Pega Customer Services

Pega is a low-code platform for AI-powered decisioning and workflow automation. We enable organisations to get work done using apps that are secure, scalable, governed, and maintainable. We offer solutions for business process management, digital process automation, and customer/citizen engagement. Pega Government Platform (PGP) is tailored to meeting governments’ needs.

Features

  • Dynamic case management platform with AI-driven process automation engine.
  • Omnichannel citizen engagement CRM with intelligent communication orchestration capabilities.
  • Model-driven low-code application platform for rapid government service delivery.
  • Enterprise API integration gateway with AI-powered connectivity and interoperability.
  • AI-Driven application configuration for enhanced citizen service delivery modernisation.
  • Intelligent workflow automation platform with AI-powered workforce optimisation capabilities.
  • Robotic process automation enabling end-to-end task orchestration and efficiency.
  • Real-time AI decisioning engine delivering contextual recommendations and insights.
  • Pega’s single-tenant hosting, but flexibility for cloud choice.
  • Software that writes your software. Patented ‘Build for Change’ technology.

Benefits

  • Rapidly modernise legacy government systems using intelligent low-code automation.
  • Maximised intelligent automation across fragmented systems using Pega’s Process Fabric™
  • Optimised end-to-end customer journeys experienced through AI and robotics.
  • Build applications 12X faster with low-code, accelerate digital service delivery.
  • Monitor performance KPIs and manage SLAs through real-time intelligent dashboards.
  • Deploy scalable applications conforming to GDS Design Principles and standards.
  • Easily integrates into legacy estates, orchestrating and exploiting existing investments.
  • Ability to deliver higher quality, lower cost, more reliable solutions.
  • Lower total ownership costs using proven low-code intelligent automation platform.
  • Proven, referenceable technology, successfully used by major government departments.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at rfpteam@pega.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 5 7 7 9 2 7 7 3 6 7 9 5 8 8

Contact

PEGASYSTEMS LIMITED Simon Haydn-Lee
Telephone: +44 (0) 7929 364629
Email: rfpteam@pega.com

About your service

Service categories

Applications

Customer relationship management

  • Marketing campaign management
  • Sales force productivity and management
  • Customer service
  • Contact centre
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Pega Live Data provides a data virtualization layer so you can quickly and easily define the data models required to build your applications and how they’re connected to any back-end systems. You can then access that data on-demand in your live application without re-configuring where the data is stored.
Cloud deployment model
Public cloud
Service constraints
Pega Cloud G-Cloud Customers can be deployed in the Amazon EU-Ireland / UK Region. Within this geographic zone, Pega Cloud environments are deployed into multiple availability zones. Environments also then have the following further resiliency services applied:
• Backups of all environments on an ongoing basis.
• Synchronous multi-availability zone database replication and load balancing delivering an RPO of approximately 1 minute and RTO of approximately 4 minutes.
Production environments are provided with a 99.95% availability SLA. For each customer Pega provides purpose-built infrastructure dedicated to that customer within a dedicated virtual private cloud.
System requirements
  • Modern HTML5 browsers supported; disable unsupported legacy Internet Explorer versions.
  • Outbound TLS 1.2+ internet access to Pega Cloud endpoints allowed.
  • Allowlist Pega IP ranges or establish site‑to‑site VPN for connectivity.
  • Identity provider supporting SAML 2.0 or OpenID Connect SSO integration.
  • Email SMTP relay configured for outbound notifications and password resets.
  • Secure firewall rules permitting required ports, protocols, corporate egress traffic.
  • Chosen cloud region meeting buyer’s data residency and compliance requirements.
  • Access management: named administrators and role‑based permissions governance processes established.
  • Integration endpoints reachable: REST APIs, SFTP, Kafka if required externally.
  • Application configuration and data management responsibilities agreed during service engagement.

User support

Email or online ticketing support
Yes
Support response times
User support is provided via email and ticketing through the Pega support portal. Response times are aligned to incident severity levels, with initial responses typically provided within defined targets ranging from one hour for critical incidents to next business day for low‑priority queries. Support is available 24x7, including weekends and public holidays, for critical and high‑severity incidents. For lower‑severity requests, responses during weekends may be limited, with full service resuming during standard business hours.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
No
Support levels
Support levels and costs:
Pega Cloud Subscriptions include Pega Premium Support as standard. Premium Support provides 24x7 access to Pega’s global support service for incident management, service requests, and operational assistance. Support is delivered via the Pega support portal and includes defined response targets aligned to incident severity.
Premium Support is included within the Pega Cloud subscription cost.

Support services provided:
Premium Support includes proactive monitoring of Pega Cloud environments, incident notification and resolution support, access to system health and environment status information, and operational guidance to support availability, performance, and reliability. Pega provides structured escalation, root‑cause analysis for major incidents, and regular service communications.

Technical account management:
Pega provides access to cloud support engineers as part of Premium Support. Where required, a Technical Account Manager (TAM) or named service contact can also be provided as an optional service, offering proactive service reviews, coordination, and strategic technical guidance.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide a comprehensive onboarding experience to help users start using our service quickly and effectively. Pega offers multiple options tailored to different learning styles and organizational needs:
• Online Training: Access to Pega Academy, a robust e-learning platform with self-paced courses, interactive exercises, and certifications for business users, developers, and administrators.
• Instructor-Led Training: Virtual and onsite sessions delivered by certified trainers, covering fundamentals, advanced configuration, and best practices.
• Blueprint Workshops: Collaborative design sessions using Pega Blueprint to capture objectives, map workflows, and accelerate solution design.
• User Documentation: Extensive online help, implementation guides, and knowledge articles available within the platform and via Pega Community.
• Onboarding Support: Guided setup, configuration assistance, and orientation sessions to familiarize users with key features and tools.
• In-Application Guidance: Contextual help, tooltips, and walkthroughs embedded in the platform to support real-time learning.
These resources ensure users can quickly configure applications, customize workflows, and leverage Pega’s low-code capabilities. Our approach combines structured learning, hands-on practice, and expert support to reduce time-to-value and empower organizations to achieve rapid adoption and success.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Clients have two options, the first of which is to extract the data from Pega’s working database. Pega’s cloud offering utilises a standard relational database making this a relatively simply task.

The second approach is to never hold such data in Pega in the first place. Where a client requires this approach Pega will support the use of data separation techniques to allow the client to maintain their data in a data store of their choice.
End-of-contract process
Pega Cloud will support the customer in removing their applications and data. This process will be completed within 14 days of contract termination.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Our solutions automatically render to fit to the size of screen of the device that they are being used on. They are built requiring no additional modifications. Our apps are 8 x quicker to deploy on mobile than Java Enterprise built applications.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service interface is accessed via a secure, web‑based portal provided as part of the Pega Cloud service. Users work with the service through intuitive role‑based dashboards, forms, and case views, accessible using standard web browsers without the need for local installation. The interface supports task management, case tracking, reporting, and collaboration, with access controlled through configurable user roles and permissions. Administrators use the same interface to manage users, monitor environments, and configure service settings. The interface is designed using inclusive design principles to ensure it is usable and effective for a wide range of user needs and working styles.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Extensive work has been performed with the Watson Institute in the USA to ensure the user interface can comply with the needs of the disabled.

Pega is committed to creating an accessible and inclusive experience for users of its platform and related applications. We continually strive towards improving our experience and adhering to the international standards created by the World Wide Web Consortium (W3C).
To help drive us towards an inclusive solution, we utilize the following measures:
• Leverage a third party to audit our applications and components, and conduct both automated and manual assessments.
• Provide an up-to-date Voluntary Product Application Template (VPAT) of our current state of conformance.
• Test our applications with assistive technology such as JAWS, ZoomText and Dragon Naturally Speaking.
Pega currently uses the WCAG 2.2 AA standards to evaluate our platform and out-of-the-box applications. These standards are being used to comply with requirements of Section 508, EN 301 549 and BITV.
API
Yes
What users can and can't do using the API
The Pega API allows users to trigger the execution of Pega rules from 3rd party applications and systems. Every capability of the Pega application platform is contained within rules and so clients have access to any capability that they have configured within their rule sets. In addition to an API, Pega rules can also be exposed as web services if a client finds that more convenient. In either case business login and functions contained within rules of all different types can be called from external 3rd party applications.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Pega solutions, built on the Pega Platform, provide extensive customization options to meet diverse business needs. What can be customised? Organizations can tailor case types, workflows, data models, user interfaces, decision logic, and integrations with external systems. Advanced features such as AI-driven decisioning and robotic automation can also be configured to align with business objectives.
How users can customise? Pega offers intuitive low-code tools and the innovative Pega Blueprint, which enables collaborative design through a shared visual model. Blueprint captures objectives, maps processes, and automatically generates documentation, ensuring transparency and accelerating delivery. Users can configure applications using guided templates, drag-and-drop components, and real-time previews without writing complex code. Integration with APIs and reusable components further simplifies customization.
Who can customise? Both business users and IT teams can participate in shaping solutions. Business stakeholders can define requirements and adjust workflows, while technical teams manage governance and advanced configurations. This collaborative approach reduces development cycles, improves accuracy, and enhances engagement across the enterprise.
By combining Blueprint, low-code configuration, and automated documentation, Pega empowers organizations to rapidly deliver tailored applications while maintaining flexibility, scalability, and compliance.

Scaling

Independence of resources
In order to guarantee users aren't affected by demands of other users, Pega Cloud is a single tenant environment.

Analytics

Service usage metrics
Yes
Metrics types
Pega provides out‑of‑the‑box dashboards and configurable reports via Report Creator, with real‑time views and scheduled distribution (PDF/Excel). Service metrics typically cover case and process performance (throughput, backlog, cycle times), SLA compliance (response and resolution targets), incident and exception volumes, and workload distribution. Usage‑related metrics include user and role activity, login frequency, assignments handled, and case actions performed, supporting operational oversight. Reports can be filtered by application, environment, role, and time window, enabling continuous service monitoring, governance, and performance management.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Pega Cloud provides multiple methods for data export, ensuring clients retain control and ownership of their data. Users can export operational data using Business Intelligence Exchange (BIX) in industry‑standard formats, with options for high‑volume extraction via Change Data Capture (CDC) or automated batch and real‑time workflows. Real‑time data streaming is supported using Kafka Data Sets, enabling integration with external or managed Kafka services. For ad‑hoc needs, users can export data to Excel via Insights and export case data and attachments using supported platform methods. This flexible approach supports operational, analytical, and integration use cases.
Data export formats
  • CSV
  • Other
Other data export formats
  • DOC
  • PDF
  • Excel
  • XML
  • JSON
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • XML
  • Excel
  • Other delimited text formats such as Tab separated values

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Pega Cloud Production Subscriptions provide a guaranteed availability level of 99.95% measured on a monthly basis, as defined in the Pega Cloud Service Level Agreement. Availability is calculated for the production environment and excludes agreed maintenance windows in line with the service terms.
If the guaranteed availability level is not met in a given month, customers are eligible for service credits, providing a financial remedy for service disruption. Service credits are calculated as a percentage of the monthly subscription fee and are applied in accordance with the agreed thresholds and claims process set out in the Pega Cloud service terms.
These service levels and associated remedies form part of Pega’s contractual commitments for its cloud services and support operational resilience, transparency, and assurance for users operating business‑critical services on Pega Cloud.
Approach to resilience
Available on request.
Outage reporting
The Pega Cloud Service Desk will communicate directly with any customers experiencing an outage via phone and E-Mail .

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Other user authentication
Authentication and authorisation of users is the responsibility of the customer. Pega supports multiple external identity providers as well as SSO.
Access restrictions in management interfaces and support channels
Pega operates on a 'best practice' basis operating in line with industry standard. Detail of this can be provided on request.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
Authentication and authorisation of users is the responsibility of the customer. Pega supports multiple external identity providers as well as SSO.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
  • Other
Other security governance standards
Pega Cloud has a Written Information Security Program (WISP) reviewed annually. The Pega Cloud WISP meets the requirements of NIST Special Publication 800-53, Revision 4. Pega is ISO/IEC 27001:2013 (“ISO 27001”) certified for information security management supporting infrastructure and services. Pega also holds a current Cyber Essentials Certificate.
Information security policies and processes
Pega Cloud has a Written Information Security Program (WISP) reviewed annually. The Pega Cloud WISP meets the requirements of NIST Special Publication 800-53, Revision 4. Pega is ISO/IEC 27001:2013 (“ISO 27001”) certified for information security management supporting infrastructure and services. Pega also holds a current Cyber Essentials Certificate.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Pega uses a controlled configuration and change management process that tracks all service components throughout their lifecycle using asset inventories and configuration baselines. All changes follow formal change control procedures, including impact analysis, peer review, automated testing, and approval gates. Security impact is assessed using risk-based evaluation, aligned to Pega’s secure development lifecycle and vulnerability management practices. Changes are deployed through standardised pipelines, with segregation of duties and full audit logging. Only authorised personnel can implement changes, and all modifications are monitored, documented, and traceable end‑to‑end.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Pega Cloud follows a structured vulnerability management process as part of its operational security controls. Potential threats are assessed through continuous monitoring, automated scanning, and risk‑based evaluation aligned to the service environment and data classification. Security patches and updates are deployed in accordance with defined change and release management processes, with prioritisation based on severity and impact, and expedited handling for high‑risk vulnerabilities. Intelligence on emerging threats is obtained from trusted sources, including internal security teams, cloud service providers, vendor advisories, and industry‑recognised vulnerability and threat intelligence feeds.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Pega Cloud operates protective monitoring processes to identify, assess, and respond to potential security compromises. Monitoring uses automated alerts, logging, and event analysis to detect anomalous activity, suspicious behaviour, and indicators of compromise across the service. When a potential compromise is identified, incidents are triaged, investigated, and remediated through defined security incident response procedures, including containment, escalation, and customer notification where required. Response times are prioritised based on incident severity, with rapid response and investigation for high‑risk security events, ensuring timely mitigation and service protection.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Pega Cloud operates defined incident management processes covering common operational and security events. Pre‑defined procedures are in place to ensure consistent triage, prioritisation, escalation, and resolution based on severity and impact. Users report incidents through the Pega support portal using email or ticket submission, with 24x7 availability for critical issues. Incidents are tracked through to resolution, with status updates provided during investigation. Following resolution, incident reports are made available, including details of root cause, impact, and corrective actions as appropriate, supporting transparency, assurance, and continuous service improvement.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
A free 30 day trial is available for Pega Platform and Customer Service. Pega Platform allows quick and easy building of applications via visual-driven rapid development with no coding using App Studio. With AI-guided interactions, Pega Customer Service can cut through service complexity for an improved overall customer experience.
Link to free trial
https://www.pega.com/products/try-now

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
6.5%
Between £250,000 and £500,000
8%
Between £500,001 and £1,000,000
9%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
11%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Schellman & Company LLC
ISO/IEC 27001 accreditation date
Tuesday 26 November 2024
What the ISO/IEC 27001 doesn’t cover
The scope of the ISO/IEC 27001:2022 certification is limited to the information security management system (ISMS) supporting Pega Cloud Services, and includes the organizations, systems, and people directly involved in developing, deploying, maintaining, and monitoring Pega Cloud Services, in accordance with the statement of applicability, version 7.1, dated August 20, 2024, and aligned with control implementation guidance and additional control sets of ISO/IEC 27017:2015 and ISO/IEC 27018:2019. Pega Cloud Services includes Pega Software available via Pega Cloud Subscription and Pega Launchpad Subscription offerings hosted in Pega Cloud and consumed by clients, excluding Co-Browse.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI
ISO 9001 accreditation date
Tuesday 20 January 2026
What the ISO 9001 doesn’t cover
N/A - Pega's ISO certification covers all elements of Pega Cloud, including Cloud Engineering, Cloud Operations, Cloud Security and Global Client Support. It also includes back office functional departments that support service delivery, such as Sales, Legal (contracts), and People Management.
Quality management systems (QMS)
Yes
CSA STAR certification
Yes
CSA STAR accreditation date
Tuesday 26 November 2024
CSA STAR certification level
Level 2: CSA STAR Attestation
What the CSA STAR doesn’t cover
The STAR certification is assessed along with and aligned to the scope of the ISO/IEC 27001:2022 certification for the information security management system (ISMS) supporting Pega Cloud Services, which includes the organizations, systems, and people directly involved in developing, deploying, maintaining, and monitoring Pega Cloud Services, in accordance with the statement of applicability, version 7.1, dated August 20, 2024, and aligned with control implementation guidance and additional control sets of ISO/IEC 27017:2015 and ISO/IEC 27018:2019. Pega Cloud Services includes Pega Software available via Pega Cloud Subscription offerings hosted in Pega Cloud and consumed by clients, excluding Co-Browse.
PCI certification
Yes
Who accredited the PCI DSS certification
Wolf and Company
PCI DSS accreditation date
Thursday 22 August 2024
What the PCI DSS doesn’t cover
Scope: Pega Cloud AWS & GCP
Not Covered: Specific exclusions detailed in the Shared Responsibility Matrix
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
3e454509-6217-4475-8128-5f00b81c1e41
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
84c2eb2a-990e-42b6-925e-7bd4feffdc9f
Other security certifications
Yes
Any other security certifications
  • ISO 22301 (Business Continuity)
  • ISO 27017 (Cloud Security)
  • ISO 27018 (Cloud Privacy)
  • SOC 1
  • SOC 2 Type 2
  • HITRUST
  • FedRamp
  • IRAP
  • TISAX
  • C5 Type 1 & 2 (Cloud Computing Compliance Criteria Catalogue)

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at rfpteam@pega.com. Tell them what format you need. It will help if you say what assistive technology you use.