Skip to main content

Help us improve the Digital Marketplace - send your feedback

CORE TECHNOLOGY SYSTEMS (U.K.) LIMITED

Compute Infrastructure (PaaS / IaaS) & Server Support - CoreGov

Core’s Compute Infrastructure service provides fully managed Windows Server and Azure IaaS environments, monitored and supported by our service desk. We handle incidents, changes and optimisation while Azure delivers scalable virtual machines for everything from small workloads to large, demanding data platforms—giving you a reliable, well‑managed infrastructure.

Features

  • Proactive monitoring, alerting, and incident management through ITIL-aligned Service Desk.
  • Windows Server administration: patching, vulnerability assessment, configuration and health checks.
  • Azure IaaS management for VMs, storage, networks, security controls, automation.
  • Advanced Azure networking options: ExpressRoute, Application Gateway, Firewall, Route Tables.
  • Change management and releases with governance, approvals, and rollback planning.
  • Monthly service reviews, KPI reporting, and continual improvement recommendations delivered.
  • Secure, auditable access via Azure Lighthouse and GDAP delegated administration.
  • Flexible support hours, including optional 24x7 coverage for critical workloads.
  • Clear scope definition with documented exclusions, prerequisites, and customer responsibilities.
  • Seamless onboarding, health checks, and guided offboarding with access removal.

Benefits

  • Reduce operational burden; our experts run infrastructure reliably and transparently.
  • Improve availability and performance through proactive monitoring, patching, and optimisation.
  • Scale confidently with Azure virtual machines tailored to workload demands.
  • Accelerate change safely using governed processes, approvals, and rollback readiness.
  • Gain predictable operations via monthly reviews, KPIs, and improvement roadmaps.
  • Enhance security posture with vulnerability management and auditable privileged access.
  • Align costs to usage with per-server and percentage-based pricing models.
  • Integrate seamlessly with internal teams for escalation or full outsourcing.
  • Meet governance expectations using ISO 27001 operations and ITIL practices.
  • Shorten time-to-value with rapid onboarding, clear prerequisites, and documentation support.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@core.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 0 2 8 4 5 9 1 8 2 6 4 6 1 6

Contact

CORE TECHNOLOGY SYSTEMS (U.K.) LIMITED Paul Saer
Telephone: +44 (0) 207 626 0516
Email: tenders@core.co.uk

About your service

Service categories

Systems Infrastructure Software

Physical and virtual computing

  • Virtual client computing
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
All systems should be deployed in a highly available configuration to ensure patching and maintenance can be performed without service interruption. Support for Linux servers may require coordination with customer application teams to confirm compatibility after updates. The service also depends on secure delegated access via Azure Lighthouse and GDAP, valid licensing, and documented restore processes for incumbent backup tools. Support covers Windows Server and agreed Azure IaaS components only; application‑level support, onsite activity, major incident management and disaster recovery remain out of scope.
System requirements
  • Valid Microsoft licences required for all supported Windows Server workloads.
  • Azure Lighthouse delegated access must be granted before service activation.
  • GDAP permissions required to manage subscription-level Azure resources securely.
  • Documented backup restore processes required for existing customer backup tools.
  • Supported virtual machines must include active antivirus or endpoint protection.
  • Network configuration must permit Core monitoring and management traffic flows.
  • Conditional_Access policies must be configured prior to service desk support.
  • On‑premise-servers require reliable connectivity for monitoring agents to operate.
  • Linux server updates require customer application team validation post‑patching.
  • Azure subscriptions must follow compliant governance policies and security standards.

User support

Email or online ticketing support
Yes
Support response times
Response times are dependent on the nature of the request. For Managed Services tickets, the response times for different request types are listed in the Service Description document.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Our webchat solution is configurable, allowing us to tailor the interface by enabling or disabling features for different clients. This can help simplify navigation for users who need a less cluttered interface. Security roles can be configured to limit or expand access to certain features, which can help create simpler experiences for users who might struggle with complex navigation. Users can submit tickets, access knowledge bases, and use service catalogues without direct staff interaction, which could benefit users who prefer asynchronous communication. Our platform also supports integrations with Teams, Slack, and chat applications, which may allow users to choose communication channels that work best for them.
Web chat accessibility testing
None
Onsite support
Yes, at extra cost
Support levels
Core run an ITIL aligned Service Desk and incident management approach. All service requests can be made directly to our 24/7 ServiceDesk function. First line or Second Line technical analyst or engineers engage with all service tickets until successfully closed. All customers can also engage with a named Account Manager and Customer Success Manager. Core typically structures Managed Services into modular SKUs, allowing customers to select the level of support they need - for example Service Desk, End User Compute, Microsoft365 Support, Infrastructure Support and Azure Managed Services. All of these SKU's are individually priced and pricing is referenced in the relevant Service Definition document
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Our onboarding process begins with a structured discovery and health check of the customer’s environment, ensuring access, prerequisites, and configuration are in place. We guide customers through setup steps, including delegated access, monitoring deployment, and any required documentation. Users receive clear guidance on how to engage with our Service Desk, along with supporting materials and process documentation. We do not provide formal onsite or online end‑user training for this service, but we do ensure stakeholders understand how to log incidents, request changes, and work effectively with our team through clear onboarding communication and documentation.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
Users extract their data using their existing Azure or on‑premises tools, as all data remains in the customer’s environment. Core does not store or retain customer data within this service. At contract end, we remove delegated access and provide any necessary handover, but data extraction remains the customer’s responsibility.
End-of-contract process
At the end of the contract, Core follows a well‑managed off‑boarding process to ensure a smooth and secure transition. We begin by removing all delegated administrative access, including Azure Lighthouse and GDAP permissions, and closing down monitoring, alerting, patching, and incident management activities. Service Desk access is withdrawn, and any open tickets are reviewed, handed over, or formally closed in agreement with the customer. We provide a clear handover of any relevant service documentation, configuration details, and operational information needed for the customer or their new supplier to continue managing their environment effectively.
Because all data resides entirely within the customer’s own Azure or on‑premises environment, Core does not host, transfer, or extract customer data as part of this service. Customers retain full control of their data at all times and can continue to use their own native tools, backup solutions, and access methods without Core involvement.
The standard contract price includes day‑to‑day incident management, change handling for in‑scope components, monitoring, patching, backup monitoring, vulnerability remediation, and monthly service reporting. Additional costs apply for professional services such as onboarding or off‑boarding support, large‑scale configuration changes, major upgrades, DR/BCP work, application‑level support, or any activities outside the defined service scope.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Our onboarding and offboarding documentation is provided in standard digital formats (DOCX and PDF). While these formats are widely compatible with common screen‑readers and assistive technologies, the documentation itself is not currently authored to a formal accessibility standard such as WCAG 2.1.
Alternative accessible formats (e.g., ODF, large‑print, Easy Read, HTML, audio) are not currently produced by default but may be made available on request.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
None or don’t know
API
No
Customisation available
Yes
Description of customisation
Yes. Buyers can customise the service by selecting the specific infrastructure components, support levels, and optional Azure features they need. The service is modular and flexible, allowing organisations to tailor scope and responsibilities. Customisation is limited to Core’s standard managed‑service framework and does not include bespoke tooling or application‑level support.

Scaling

Independence of resources
Our service does not run on a shared platform operated by Core, so demand from other customers cannot impact your service performance. All compute resources remain entirely within our Customers own Azure subscriptions or on‑premises environment. These resources are isolated, dedicated to your organisation, and governed by Microsoft’s underlying capacity and SLAs.
Core’s role is to monitor, manage, patch, and support your infrastructure. There is no contention for CPU, memory, storage, or network resources between different organisations. Any performance considerations relate solely to our Customers own environment, and we proactively monitor utilisation to help identify and address bottlenecks early.

Analytics

Service usage metrics
Yes
Metrics types
Yes. We provide operational service reporting, including incident volumes, SLA performance, monitoring insights, patching and vulnerability metrics, and (where applicable) Azure platform consumption summaries. These metrics are delivered through monthly service reviews. We do not provide end‑user usage analytics or a customer‑facing metrics dashboard as part of this service.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Microsoft

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Not applicable - as regards this service
Data sanitisation process
No
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
This service does not store, process, or retain customer data within Core‑hosted systems. All data remains entirely within the customer’s own Azure or on‑premises environment. As a result, users export or retrieve their data using their existing native tools (such as Azure Portal, PowerShell, backup solutions, file system access, or database tools), exactly as they normally would.
Core has no involvement in extracting or transferring data because no data is ever moved into Core’s control.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
Other
Other protection between networks
This service does not transmit customer data between the buyer’s network and Core’s network. All data remains within the customer’s own Azure or on‑prem environment. Core connects securely via Azure Lighthouse and GDAP for administrative operations only, meaning no user data is transferred to or stored within Core systems.
Data protection within supplier network
Other
Other protection within supplier network
Not applicable for this service

Availability and resilience

Guaranteed availability
This service provides availability for our managed service operations, not the underlying infrastructure. Core guarantees availability of its Service Desk, monitoring and support functions during contracted service hours (typically 09:00–17:30 Monday–Friday, with optional 24×7 cover for critical incidents). We provide defined response and resolution SLAs for incidents and requests. Because infrastructure remains within the customer’s own Azure or on‑premises environment, we do not guarantee platform uptime and no service credits or refunds apply. Azure infrastructure availability is covered under Microsoft’s own SLAs.
Approach to resilience
Our Compute Infrastructure (PaaS/IaaS) & Server Support service is built around operational resilience rather than hosting resilience, because all customer workloads reside in the buyer’s own Azure or on‑premises environment. Core ensures service continuity through a resilient support model that includes 24/7 monitoring of critical alerts, ITIL‑aligned incident and change processes, and the ability to escalate issues directly to Microsoft when required.
The underlying platform resilience — such as VM redundancy, storage replication, availability sets or zones, and network failover — is provided by Microsoft Azure or the customer’s own datacentre design. We work with the customer to align patching, monitoring, backup and access models to those resilience capabilities.
Core’s internal management systems, including monitoring and service desk platforms, are themselves designed with high availability and failover capabilities. Detailed information on our internal platform resilience and datacentre arrangements is available on request for due‑diligence purposes.
Outage reporting
We report service outages directly to customers via email or agreed communication channels. There is no public dashboard or outage API, as we do not operate a shared platform. Any disruptions to our service operations are also captured and reviewed in monthly service reports.

Identity and authentication

User authentication needed
Yes
User authentication
Other
Other user authentication
Users do not need to authenticate to any Core-hosted system. All authentication happens within the buyer’s own environment using their existing identity platform (such as Azure AD). Core’s engineers authenticate via delegated access (Azure Lighthouse and GDAP) to perform management activities, but end‑users do not authenticate to the service itself.
Access restrictions in management interfaces and support channels
We restrict access using Azure Lighthouse and GDAP, ensuring Core engineers receive only least‑privilege, auditable access to the customer’s environment. Permissions are role‑based, time‑bounded, and removed at contract end. Only authorised customer contacts can request or approve changes through our Service Desk, and sensitive tasks require explicit validation. No management portals are exposed to end‑users, reducing risk and limiting access strictly to authenticated, approved personnel.
Access restriction testing frequency
At least once a year
Management access authentication
Other
Description of management access authentication
We authenticate management access using Azure Lighthouse and GDAP (Granular Delegated Admin Privileges), which enforce secure, least‑privilege, role‑based access directly within the customer’s tenant. Core engineers authenticate using their corporate identities with enforced MFA, conditional access and audited RBAC roles. No shared credentials, VPNs or generic admin accounts are used.
Every privileged action taken by Core is logged inside the customer environment, providing full traceability. Access is regularly reviewed, and all delegated permissions are removed immediately at contract end.
Because this service does not expose a management portal or UI to end‑users, only authorised Core personnel ever access management interfaces.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Core operates a fully ISO 27001‑certified Information Security Management System (ISMS), supported by formal policies covering confidentiality, integrity, availability, access control, incident management, risk assessment, business continuity and supplier management. All employees receive mandatory security awareness training, with additional specialist training for staff in sensitive roles. Security responsibilities are defined in job descriptions and contracts, and policy breaches are managed under our disciplinary process.
The ISMS is overseen by a dedicated Information Security Steering Group chaired by the COO and supported by the CISO, IT Manager and senior risk specialists. Policies are reviewed at least annually and continuously improved through internal audits, external ISO 27001 surveillance audits, risk assessments and automated compliance monitoring. Staff are required to report security incidents or weaknesses immediately via documented procedures.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Core operates ITIL‑aligned configuration and change management processes, benchmarked at CMM Level 3–4. Configuration items are tracked throughout their lifecycle using customer CMDBs, Intune, Azure and ITSM tooling, ensuring accurate, continually updated records. All changes follow a formal ITIL process, including risk and security assessment, CAB review, client approval, and full auditability. Security impact is evaluated using Microsoft native tooling (Defender, Secure Score) to ensure no adverse effect on identity, access or service integrity. All changes are documented, traceable, and aligned with customer governance.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Core operates a proactive, ITIL‑aligned vulnerability management process. Threats are continuously assessed using Microsoft Defender, Secure Score, Azure Security Centre, Sentinel SIEM and weekly Nessus scans to identify vulnerabilities and misconfigurations. We deploy critical and security patches within 14 days in line with NCSC guidance, with accelerated deployment for zero‑day threats using automated Endpoint Manager and Azure Update Management workflows. Threat intelligence is sourced from Microsoft’s security ecosystem, Tenable CVE feeds, NCSC advisories and SIEM‑driven correlation, ensuring rapid awareness and remediation of emerging risks.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Core delivers continuous protective monitoring using Microsoft Sentinel SIEM, Defender for Endpoint/Servers, and Azure Defender to identify potential compromises through behavioural analytics, real‑time alerting, threat intelligence and proactive threat hunting. When a potential compromise is detected, alerts are triaged by our security operations processes, with automated containment actions (e.g. isolating devices, disabling accounts) and escalation to our engineers. Incident response follows predefined playbooks and documented communication paths. Core provides rapid response, with 24/7 monitoring and immediate triage, and P1 security incidents responded to within minutes via Sentinel‑driven alerting.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Core operates ITIL‑aligned incident management with predefined processes for common events, including a full Major Incident Management (MIM) workflow covering P1 and P2 incidents. Users report incidents via phone, email, or the self‑service portal, or incidents may be auto‑raised through monitoring. When an incident is logged, it is triaged, prioritised, and assigned, with automated notifications and, for P1s, initiation of a live bridging call and stakeholder communications. Response times follow strict SLAs, including 30‑minute response for P1 incidents. We issue formal incident reports for all major incidents.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau (part of the Amtivo Group)
ISO/IEC 27001 accreditation date
Thursday 27 February 2025
What the ISO/IEC 27001 doesn’t cover
Nothing
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Ad9ffc7a-28e4-460b-bccb-fc914b3420df
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
13867168-d605-4ed3-9481-13e21f4ae9bc
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@core.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.