Compute Infrastructure (PaaS / IaaS) & Server Support - CoreGov
Core’s Compute Infrastructure service provides fully managed Windows Server and Azure IaaS environments, monitored and supported by our service desk. We handle incidents, changes and optimisation while Azure delivers scalable virtual machines for everything from small workloads to large, demanding data platforms—giving you a reliable, well‑managed infrastructure.
Features
- Proactive monitoring, alerting, and incident management through ITIL-aligned Service Desk.
- Windows Server administration: patching, vulnerability assessment, configuration and health checks.
- Azure IaaS management for VMs, storage, networks, security controls, automation.
- Advanced Azure networking options: ExpressRoute, Application Gateway, Firewall, Route Tables.
- Change management and releases with governance, approvals, and rollback planning.
- Monthly service reviews, KPI reporting, and continual improvement recommendations delivered.
- Secure, auditable access via Azure Lighthouse and GDAP delegated administration.
- Flexible support hours, including optional 24x7 coverage for critical workloads.
- Clear scope definition with documented exclusions, prerequisites, and customer responsibilities.
- Seamless onboarding, health checks, and guided offboarding with access removal.
Benefits
- Reduce operational burden; our experts run infrastructure reliably and transparently.
- Improve availability and performance through proactive monitoring, patching, and optimisation.
- Scale confidently with Azure virtual machines tailored to workload demands.
- Accelerate change safely using governed processes, approvals, and rollback readiness.
- Gain predictable operations via monthly reviews, KPIs, and improvement roadmaps.
- Enhance security posture with vulnerability management and auditable privileged access.
- Align costs to usage with per-server and percentage-based pricing models.
- Integrate seamlessly with internal teams for escalation or full outsourcing.
- Meet governance expectations using ISO 27001 operations and ITIL practices.
- Shorten time-to-value with rapid onboarding, clear prerequisites, and documentation support.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 0 2 8 4 5 9 1 8 2 6 4 6 1 6
Contact
CORE TECHNOLOGY SYSTEMS (U.K.) LIMITED
Paul Saer
Telephone: +44 (0) 207 626 0516
Email: tenders@core.co.uk
About your service
- Service categories
-
Systems Infrastructure Software
Physical and virtual computing
- Virtual client computing
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- All systems should be deployed in a highly available configuration to ensure patching and maintenance can be performed without service interruption. Support for Linux servers may require coordination with customer application teams to confirm compatibility after updates. The service also depends on secure delegated access via Azure Lighthouse and GDAP, valid licensing, and documented restore processes for incumbent backup tools. Support covers Windows Server and agreed Azure IaaS components only; application‑level support, onsite activity, major incident management and disaster recovery remain out of scope.
- System requirements
-
- Valid Microsoft licences required for all supported Windows Server workloads.
- Azure Lighthouse delegated access must be granted before service activation.
- GDAP permissions required to manage subscription-level Azure resources securely.
- Documented backup restore processes required for existing customer backup tools.
- Supported virtual machines must include active antivirus or endpoint protection.
- Network configuration must permit Core monitoring and management traffic flows.
- Conditional_Access policies must be configured prior to service desk support.
- On‑premise-servers require reliable connectivity for monitoring agents to operate.
- Linux server updates require customer application team validation post‑patching.
- Azure subscriptions must follow compliant governance policies and security standards.
User support
- Email or online ticketing support
- Yes
- Support response times
- Response times are dependent on the nature of the request. For Managed Services tickets, the response times for different request types are listed in the Service Description document.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Our webchat solution is configurable, allowing us to tailor the interface by enabling or disabling features for different clients. This can help simplify navigation for users who need a less cluttered interface. Security roles can be configured to limit or expand access to certain features, which can help create simpler experiences for users who might struggle with complex navigation. Users can submit tickets, access knowledge bases, and use service catalogues without direct staff interaction, which could benefit users who prefer asynchronous communication. Our platform also supports integrations with Teams, Slack, and chat applications, which may allow users to choose communication channels that work best for them.
- Web chat accessibility testing
- None
- Onsite support
- Yes, at extra cost
- Support levels
- Core run an ITIL aligned Service Desk and incident management approach. All service requests can be made directly to our 24/7 ServiceDesk function. First line or Second Line technical analyst or engineers engage with all service tickets until successfully closed. All customers can also engage with a named Account Manager and Customer Success Manager. Core typically structures Managed Services into modular SKUs, allowing customers to select the level of support they need - for example Service Desk, End User Compute, Microsoft365 Support, Infrastructure Support and Azure Managed Services. All of these SKU's are individually priced and pricing is referenced in the relevant Service Definition document
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- Our onboarding process begins with a structured discovery and health check of the customer’s environment, ensuring access, prerequisites, and configuration are in place. We guide customers through setup steps, including delegated access, monitoring deployment, and any required documentation. Users receive clear guidance on how to engage with our Service Desk, along with supporting materials and process documentation. We do not provide formal onsite or online end‑user training for this service, but we do ensure stakeholders understand how to log incidents, request changes, and work effectively with our team through clear onboarding communication and documentation.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- Users extract their data using their existing Azure or on‑premises tools, as all data remains in the customer’s environment. Core does not store or retain customer data within this service. At contract end, we remove delegated access and provide any necessary handover, but data extraction remains the customer’s responsibility.
- End-of-contract process
-
At the end of the contract, Core follows a well‑managed off‑boarding process to ensure a smooth and secure transition. We begin by removing all delegated administrative access, including Azure Lighthouse and GDAP permissions, and closing down monitoring, alerting, patching, and incident management activities. Service Desk access is withdrawn, and any open tickets are reviewed, handed over, or formally closed in agreement with the customer. We provide a clear handover of any relevant service documentation, configuration details, and operational information needed for the customer or their new supplier to continue managing their environment effectively.
Because all data resides entirely within the customer’s own Azure or on‑premises environment, Core does not host, transfer, or extract customer data as part of this service. Customers retain full control of their data at all times and can continue to use their own native tools, backup solutions, and access methods without Core involvement.
The standard contract price includes day‑to‑day incident management, change handling for in‑scope components, monitoring, patching, backup monitoring, vulnerability remediation, and monthly service reporting. Additional costs apply for professional services such as onboarding or off‑boarding support, large‑scale configuration changes, major upgrades, DR/BCP work, application‑level support, or any activities outside the defined service scope. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Our onboarding and offboarding documentation is provided in standard digital formats (DOCX and PDF). While these formats are widely compatible with common screen‑readers and assistive technologies, the documentation itself is not currently authored to a formal accessibility standard such as WCAG 2.1.
Alternative accessible formats (e.g., ODF, large‑print, Easy Read, HTML, audio) are not currently produced by default but may be made available on request.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
- Yes. Buyers can customise the service by selecting the specific infrastructure components, support levels, and optional Azure features they need. The service is modular and flexible, allowing organisations to tailor scope and responsibilities. Customisation is limited to Core’s standard managed‑service framework and does not include bespoke tooling or application‑level support.
Scaling
- Independence of resources
-
Our service does not run on a shared platform operated by Core, so demand from other customers cannot impact your service performance. All compute resources remain entirely within our Customers own Azure subscriptions or on‑premises environment. These resources are isolated, dedicated to your organisation, and governed by Microsoft’s underlying capacity and SLAs.
Core’s role is to monitor, manage, patch, and support your infrastructure. There is no contention for CPU, memory, storage, or network resources between different organisations. Any performance considerations relate solely to our Customers own environment, and we proactively monitor utilisation to help identify and address bottlenecks early.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Yes. We provide operational service reporting, including incident volumes, SLA performance, monitoring insights, patching and vulnerability metrics, and (where applicable) Azure platform consumption summaries. These metrics are delivered through monthly service reviews. We do not provide end‑user usage analytics or a customer‑facing metrics dashboard as part of this service.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Microsoft
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Not applicable - as regards this service
- Data sanitisation process
- No
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
-
This service does not store, process, or retain customer data within Core‑hosted systems. All data remains entirely within the customer’s own Azure or on‑premises environment. As a result, users export or retrieve their data using their existing native tools (such as Azure Portal, PowerShell, backup solutions, file system access, or database tools), exactly as they normally would.
Core has no involvement in extracting or transferring data because no data is ever moved into Core’s control. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- Other
- Other protection between networks
- This service does not transmit customer data between the buyer’s network and Core’s network. All data remains within the customer’s own Azure or on‑prem environment. Core connects securely via Azure Lighthouse and GDAP for administrative operations only, meaning no user data is transferred to or stored within Core systems.
- Data protection within supplier network
- Other
- Other protection within supplier network
- Not applicable for this service
Availability and resilience
- Guaranteed availability
- This service provides availability for our managed service operations, not the underlying infrastructure. Core guarantees availability of its Service Desk, monitoring and support functions during contracted service hours (typically 09:00–17:30 Monday–Friday, with optional 24×7 cover for critical incidents). We provide defined response and resolution SLAs for incidents and requests. Because infrastructure remains within the customer’s own Azure or on‑premises environment, we do not guarantee platform uptime and no service credits or refunds apply. Azure infrastructure availability is covered under Microsoft’s own SLAs.
- Approach to resilience
-
Our Compute Infrastructure (PaaS/IaaS) & Server Support service is built around operational resilience rather than hosting resilience, because all customer workloads reside in the buyer’s own Azure or on‑premises environment. Core ensures service continuity through a resilient support model that includes 24/7 monitoring of critical alerts, ITIL‑aligned incident and change processes, and the ability to escalate issues directly to Microsoft when required.
The underlying platform resilience — such as VM redundancy, storage replication, availability sets or zones, and network failover — is provided by Microsoft Azure or the customer’s own datacentre design. We work with the customer to align patching, monitoring, backup and access models to those resilience capabilities.
Core’s internal management systems, including monitoring and service desk platforms, are themselves designed with high availability and failover capabilities. Detailed information on our internal platform resilience and datacentre arrangements is available on request for due‑diligence purposes. - Outage reporting
- We report service outages directly to customers via email or agreed communication channels. There is no public dashboard or outage API, as we do not operate a shared platform. Any disruptions to our service operations are also captured and reviewed in monthly service reports.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Other
- Other user authentication
- Users do not need to authenticate to any Core-hosted system. All authentication happens within the buyer’s own environment using their existing identity platform (such as Azure AD). Core’s engineers authenticate via delegated access (Azure Lighthouse and GDAP) to perform management activities, but end‑users do not authenticate to the service itself.
- Access restrictions in management interfaces and support channels
- We restrict access using Azure Lighthouse and GDAP, ensuring Core engineers receive only least‑privilege, auditable access to the customer’s environment. Permissions are role‑based, time‑bounded, and removed at contract end. Only authorised customer contacts can request or approve changes through our Service Desk, and sensitive tasks require explicit validation. No management portals are exposed to end‑users, reducing risk and limiting access strictly to authenticated, approved personnel.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Other
- Description of management access authentication
-
We authenticate management access using Azure Lighthouse and GDAP (Granular Delegated Admin Privileges), which enforce secure, least‑privilege, role‑based access directly within the customer’s tenant. Core engineers authenticate using their corporate identities with enforced MFA, conditional access and audited RBAC roles. No shared credentials, VPNs or generic admin accounts are used.
Every privileged action taken by Core is logged inside the customer environment, providing full traceability. Access is regularly reviewed, and all delegated permissions are removed immediately at contract end.
Because this service does not expose a management portal or UI to end‑users, only authorised Core personnel ever access management interfaces.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Core operates a fully ISO 27001‑certified Information Security Management System (ISMS), supported by formal policies covering confidentiality, integrity, availability, access control, incident management, risk assessment, business continuity and supplier management. All employees receive mandatory security awareness training, with additional specialist training for staff in sensitive roles. Security responsibilities are defined in job descriptions and contracts, and policy breaches are managed under our disciplinary process.
The ISMS is overseen by a dedicated Information Security Steering Group chaired by the COO and supported by the CISO, IT Manager and senior risk specialists. Policies are reviewed at least annually and continuously improved through internal audits, external ISO 27001 surveillance audits, risk assessments and automated compliance monitoring. Staff are required to report security incidents or weaknesses immediately via documented procedures. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Core operates ITIL‑aligned configuration and change management processes, benchmarked at CMM Level 3–4. Configuration items are tracked throughout their lifecycle using customer CMDBs, Intune, Azure and ITSM tooling, ensuring accurate, continually updated records. All changes follow a formal ITIL process, including risk and security assessment, CAB review, client approval, and full auditability. Security impact is evaluated using Microsoft native tooling (Defender, Secure Score) to ensure no adverse effect on identity, access or service integrity. All changes are documented, traceable, and aligned with customer governance.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Core operates a proactive, ITIL‑aligned vulnerability management process. Threats are continuously assessed using Microsoft Defender, Secure Score, Azure Security Centre, Sentinel SIEM and weekly Nessus scans to identify vulnerabilities and misconfigurations. We deploy critical and security patches within 14 days in line with NCSC guidance, with accelerated deployment for zero‑day threats using automated Endpoint Manager and Azure Update Management workflows. Threat intelligence is sourced from Microsoft’s security ecosystem, Tenable CVE feeds, NCSC advisories and SIEM‑driven correlation, ensuring rapid awareness and remediation of emerging risks.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Core delivers continuous protective monitoring using Microsoft Sentinel SIEM, Defender for Endpoint/Servers, and Azure Defender to identify potential compromises through behavioural analytics, real‑time alerting, threat intelligence and proactive threat hunting. When a potential compromise is detected, alerts are triaged by our security operations processes, with automated containment actions (e.g. isolating devices, disabling accounts) and escalation to our engineers. Incident response follows predefined playbooks and documented communication paths. Core provides rapid response, with 24/7 monitoring and immediate triage, and P1 security incidents responded to within minutes via Sentinel‑driven alerting.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Core operates ITIL‑aligned incident management with predefined processes for common events, including a full Major Incident Management (MIM) workflow covering P1 and P2 incidents. Users report incidents via phone, email, or the self‑service portal, or incidents may be auto‑raised through monitoring. When an incident is logged, it is triaged, prioritised, and assigned, with automated notifications and, for P1s, initiation of a live bridging call and stakeholder communications. Response times follow strict SLAs, including 30‑minute response for P1 incidents. We issue formal incident reports for all major incidents.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau (part of the Amtivo Group)
- ISO/IEC 27001 accreditation date
- Thursday 27 February 2025
- What the ISO/IEC 27001 doesn’t cover
- Nothing
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ad9ffc7a-28e4-460b-bccb-fc914b3420df
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 13867168-d605-4ed3-9481-13e21f4ae9bc
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-