Skip to main content

Help us improve the Digital Marketplace - send your feedback

CONDATIS GROUP LIMITED

Condatis Identity Infrastructure Service (iSaaS)

Condatis delivers secure, scalable identity infrastructure using Microsoft Azure and Entra. Our service enhances Zero Trust security, supports citizens and workforce access, integrates legacy systems, strengthens compliance, and provides managed support to improve cyber resilience, operational efficiency, and overall identity governance across public sector environments.

Features

  • Advanced identity and access management using Microsoft Entra technologies.
  • Zero Trust security framework with continuous verification and monitoring.
  • Custom connectors and extensions for legacy system integration.
  • Managed support with monitoring, optimisation, and incident response services.
  • Strategic advisory for identity strategy, compliance, and future capability planning.
  • Secure access for human, non‑human, workload, and AI identities.
  • Inclusive, accessible design aligned with WCAG 2.1 AA standards.
  • Integration using open standards including SAML, OAuth 2.0, OpenID Connect.
  • Migration planning with discovery, roadmap definition, testing, and hypercare.
  • Performance reporting including uptime, incident metrics, and SLA compliance.

Benefits

  • Strengthen security with Zero Trust verification for every access request.
  • Improve efficiency through streamlined identity processes and automation.
  • Enhance user journeys, seamless, secure access for citizens and staff.
  • Reduce organisational risk by meeting key regulatory compliance requirements.
  • Accelerate integration with standards‑based connections to legacy systems.
  • Increase cyber resilience through proactive monitoring and rapid incident response.
  • Support growth using scalable, cloud‑based identity infrastructure.
  • Improve governance with centralised identity lifecycle and access control.
  • Reduce internal workload with managed support and identity expertise.
  • Prepare for future needs with AI‑ready identity capabilities.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@condatis.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 3 5 8 7 9 4 3 8 6 9 0 0 5 6

Contact

CONDATIS GROUP LIMITED Chris Tate
Telephone: 0800 538 5533
Email: sales@condatis.com

About the service

Service categories

Systems Infrastructure Software

Security

  • Governance, risk and compliance

Identity and access management

  • Access
  • Privilege

Network security

  • Trusted network access and protection
  • Active application security

Data security

  • Information protection
  • Digital trust
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Our service extends Microsoft Entra identity and security technologies, enhancing capabilities across Entra ID, External ID, Verified ID, Governance, Protection, Private Access, Internet Access and Workload identities. It adds custom integration, strategy, and managed support while also operating independently as a standalone identity infrastructure service.
Cloud deployment model
Public cloud
Service constraints
The service is delivered on Microsoft Azure public cloud and is subject to Microsoft’s platform maintenance windows. Some legacy system integrations may require client‑side configuration or additional custom connectors. Service availability depends on internet or private network connectivity. Optional 24/7 support requires an enhanced support package. Penetration testing permissions follow Microsoft rules, and certain advisory or migration activities may require scheduled access to client environments.
System requirements
  • Microsoft Azure tenant for hosting identity infrastructure components.
  • Internet connectivity for accessing cloud‑based identity services.
  • Supported browsers for Entra‑based authentication experiences.
  • Client systems supporting SAML, OAuth, or OpenID Connect protocols.
  • Access to legacy systems requiring integration configuration.
  • Appropriate Microsoft Entra licensing for required identity capabilities.
  • Customer‑provided test environments for migration and validation activities.
  • Secure network configuration for private access integrations.
  • Administrative access to identity systems for setup activities.
  • Endpoints compliant with organisational security and configuration policies.

User support

Email or online ticketing support
Yes, at extra cost
Support response times
We provide an initial response within 30 minutes for critical issues, 1 hour for high‑priority queries, and within 4 business hours for standard requests. Weekend response times apply only where customers have a 24/7 support package; otherwise, support operates during UK business hours.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Standard (Mon–Fri, 9:00–17:00 UK): Email, ticketing, and phone support. Targets: Critical - initial response 30 minutes; High - 1 hour; Standard - 4 business hours. Includes incident management, basic change support, and monthly SLA reporting.
Enhanced 24/7: All Standard features plus out‑of‑hours incident cover, on‑call engineering, proactive alerting, and expedited escalations.
Premium Managed: All Enhanced features plus quarterly service reviews, optimisation backlogs, roadmap alignment, capacity/cost reviews, and service improvement plans.

Indicative pricing (GBP, per month; final pricing in Pricing Document)

Standard: £2,000 base, includes up to 20 tickets.
Enhanced 24/7: £5,000 base, priority incident handling included.
Premium Managed: £8,000 base, adds proactive optimisation and governance.
Pricing scales with environment complexity, user volumes, and integration breadth. Onboarding/hypercare and onsite activities are scoped and billed separately.

Roles provided

Cloud Support Engineer (CSE): Primary technical responder; investigates incidents, performs changes, maintains integrations and automations.
Technical Account Manager (TAM): Available on Premium; owns service governance, coordinates roadmaps, reviews SLA performance, and ensures alignment to business outcomes.
Service Manager (as required): Oversees major incidents, problem management, and continuous improvement.

Onsite support
Available by arrangement for workshops, migration cutovers, and complex troubleshooting; travel and expenses charged separately.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide a structured onboarding process to help users begin using the service quickly and confidently. This includes an initial kick‑off session to confirm goals, environments, access requirements, and implementation timelines. Users receive detailed onboarding documentation, including configuration guides, integration instructions, and best‑practice recommendations tailored to their environment.

We offer online training covering key features such as identity configuration, policy management, user journeys, and support processes. Additional onsite training can be provided where deeper technical enablement or collaborative workshops are required.

During setup, Condatis engineers assist with environment preparation, configuration of Microsoft Entra components, integration with existing systems, and validation testing. We also support user acceptance testing and provide knowledge‑transfer sessions to ensure administrators understand how to operate and maintain the service.

Early‑life hypercare support is available to help resolve issues quickly after go‑live and ensure a smooth transition to steady‑state operation.

Overall, users receive documentation, guided setup, training, and direct access to our support team to ensure a straightforward, well‑supported onboarding experience.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
  • Other
Other documentation formats
  • Word
  • Excel
End-of-contract data extraction
At the end of the contract, all customer data remains fully under the buyer’s control within their own Microsoft Azure and Microsoft Entra tenant. Users can extract their data at any time through native Microsoft tooling, including exporting configuration, logs, identity objects, policies, and integration settings directly from the Entra and Azure portals or via API.

If Condatis has deployed any custom components, connectors, or configuration assets, these are transferred to the buyer before contract end, along with supporting documentation. We assist with exporting relevant configuration, mapping files, and operational runbooks to ensure a smooth transition.

Buyers may also request a structured handover, including workshops or knowledge‑transfer sessions, to support migration to another supplier or internal team. After extraction is complete, Condatis removes any temporary data held in delivery environments in accordance with agreed data‑retention and sanitisation processes.

No additional charges apply for data extraction unless specialised support or onsite assistance is requested.
End-of-contract process
At the end of the contract, Condatis works with the buyer to ensure an orderly and secure transition. All identity data, configurations, policies, integrations, and logs remain within the buyer’s Microsoft Azure and Entra tenant, ensuring they retain full ownership and continued access. Buyers can extract data at any time using native Microsoft tools, API exports, or portal‑based downloads.

As part of the contract price, Condatis provides:
Guidance on data extraction
Handover of any configuration artefacts, runbooks, and documentation created during delivery
Secure removal of any temporary delivery data held by Condatis, following agreed sanitisation standards

If custom components, connectors, or integrations were developed, ownership is transferred to the buyer at no additional cost unless otherwise specified in a Statement of Work.

Additional cost may apply for:
Extended offboarding support
Onsite workshops or hands‑on migration assistance
Transition support to a new supplier or internal team
Complex reconfiguration or redevelopment outside the original scope

The service is designed so buyers can continue operating independently after contract end, with clear documentation and retained control of all identity infrastructure.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Users access the service through web‑based management interfaces provided by Microsoft Entra and Azure, enabling configuration, monitoring, reporting and identity lifecycle operations. Support is accessed through an online ticketing portal and email. Integration components use standards‑based APIs such as OAuth 2.0, SAML, and OpenID Connect. The interface is designed for simplicity, secure access, and compatibility with major operating systems and modern browsers.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The service leverages Microsoft Entra and Azure interfaces, which undergo continuous accessibility testing by Microsoft using a wide range of assistive technologies, including screen readers, keyboard‑only navigation, high‑contrast modes, and voice input tools. Condatis performs periodic accessibility reviews during implementation phases to ensure identity workflows remain usable with assistive technologies and comply with WCAG AA standards. This includes testing login, registration, verification, and support‑portal interactions using screen‑reader tools and browser‑based accessibility checkers.

Where custom interfaces or extensions are developed, Condatis applies inclusive design practices, conducts accessibility validation with automated testing tools, and supports user acceptance testing that incorporates accessibility considerations. Feedback from users relying on assistive technologies is incorporated into iterative improvements.
API
Yes
What users can and can't do using the API
What users can do
Set up core identity flows by configuring standards‑based protocols (OAuth 2.0, OpenID Connect, SAML) against Microsoft Entra/Azure endpoints.
Integrate applications and legacy systems via RESTful APIs and Condatis extensions to enable authentication, authorisation, and lifecycle events.
Manage configuration, automate provisioning, and orchestrate migrations using documented endpoints and scripted workflows.

How users make changes
Update client/app registrations, redirect URIs, claims, and policies through Entra/Azure management APIs or the Condatis integration layer.
Adjust access policies and identity lifecycle rules via API‑driven configuration and deployment pipelines.

Limitations
Certain changes require appropriate directory permissions and role‑based access in the buyer’s tenant.
Legacy integrations may need custom connectors or client‑side configuration before API calls succeed.
Throughput and rate limits follow Microsoft platform constraints; penetration testing of APIs must follow Microsoft rules.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
What can be customised
Identity journeys: registration, sign‑in, MFA, recovery, verification steps.
Access policies: conditional access, risk policies, lifecycle and role‑based controls.
Integrations: custom connectors for legacy systems, claims mapping, attributes, schemas.
Branding and content: pages, emails, notifications, language/localisation.
Environments and operations: tenancy configuration, logging, monitoring, reporting, SLAs.

How users can customise
Configure Microsoft Entra and Azure settings via admin portals and management APIs.
Adjust policies, claims, and app registrations through scripted pipelines (IaC) or UI.
Deploy Condatis extensions/connectors to meet bespoke workflows and data mappings.
Provide feedback during discovery/UAT to refine user experience and accessibility.

Who can customise
Buyer administrators with appropriate directory roles (e.g., Global/Cloud App Administrator).
Condatis engineers under statement of work to implement advanced configurations, integrations, or custom components.
Third‑party partners authorised by the buyer for joint delivery or managed operations.

Note: Some changes (e.g., tenant‑wide policies, high‑risk configurations) require elevated permissions and change control. Optional customisation beyond standard configuration may be scoped and billed separately.

Scaling

Independence of resources
We isolate each customer’s environment using dedicated Azure subscriptions/resource groups, segregated identities, and role‑based access control. Workloads scale independently with autoscaling and per‑tenant quotas to prevent contention. Shared services use rate‑limiting and throttling to avoid “noisy neighbour” impact. Data stores, keys, and logs are logically separated per customer; dedicated instances can be provided for heightened isolation. Continuous monitoring and alerting detect saturation early, enabling proactive scaling or failover. SLAs apply per customer environment, not pooled across tenants.

Analytics

Service usage metrics
Yes
Metrics types
We provide metrics covering service availability, incident volumes, response and resolution times, SLA performance, authentication activity, and integration health. Monthly performance reports include uptime, ticket trends, policy or configuration changes, and any security‑relevant identity events. Additional metrics such as onboarding progress, migration status, and connector performance can be included where applicable. Customers may request enhanced reporting for governance or audit needs.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Data at rest is encrypted using Azure’s default encryption mechanisms, including AES‑256 and Microsoft‑managed keys, with the option to use customer‑managed keys. Identity data, logs, and configuration artefacts remain within the buyer‑selected Azure region and are isolated per tenant through role‑based access control and segregated resource groups. Sensitive information such as secrets, certificates, and tokens is stored securely in Azure Key Vault with tightly restricted access. All storage accounts enforce encryption, access policies, and continuous security monitoring to prevent unauthorised access or tampering.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data directly from their Microsoft Entra and Azure tenants using built‑in tools. This includes downloading configuration, logs, identity objects, policies, and audit records through the Azure and Entra portals. Data can also be exported via Microsoft Graph or REST APIs for automated or bulk extraction. If Condatis has deployed custom components, any configuration files, mappings, or integration artefacts are provided to the buyer for download. Condatis can assist with export activities during offboarding, but users retain full control of their data at all times.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • JSON: Exported via Microsoft Graph and REST API responses.
  • XML: Used for SAML metadata and some configuration exports.
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • JSON: Used for API‑based configuration and bulk identity imports.
  • XML: Supported for SAML metadata and configuration uploads.

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks
In addition to TLS 1.2+ and optional VPN connectivity, data exchanged between the buyer’s network and the service is protected through strict identity‑based access controls, Azure‑managed certificates, and encrypted endpoints. Private connectivity options such as Azure Private Link can be used to avoid exposure to the public internet. All APIs enforce strong authentication, conditional access, and least‑privilege permissions. Network traffic is monitored for anomalies, and Microsoft’s secure‑by‑design controls ensure continuous validation, threat detection, and protection against interception or tampering.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Data within the service environment is protected using Azure’s encrypted network fabric, role‑based access controls, segregated resource groups, and strict identity‑based authentication for all internal services. Internal traffic between components uses encrypted channels and managed certificates. Logs, keys, and secrets are isolated using Azure Key Vault with restricted access. Network security groups, firewalls, and continuous threat detection prevent unauthorised movement within the environment. Private Link can be used to keep traffic off the public internet entirely.

Availability and resilience

Guaranteed availability
We guarantee 99.9% monthly availability for core identity services delivered on Microsoft Azure and Microsoft Entra. Availability is measured per calendar month, excluding approved planned maintenance windows, force majeure, Microsoft platform incidents, and customer‑initiated changes. Services are continuously monitored, with automated alerting and monthly performance reporting showing uptime, incident timelines, and SLA compliance.

Planned maintenance is scheduled outside UK business hours where possible and notified in advance. Emergency maintenance is only used to mitigate critical risks and is communicated promptly.

If we fail to meet the guaranteed availability, service‑level remedies apply through the contract Call‑Off/Order Form. Remedies typically include service credits (or equivalent fee reductions) aligned to the measured shortfall, and may include extended hypercare or priority engineering at no additional cost. Specific credit structures are agreed with the buyer at contract award to match procurement preferences.

Our UK‑based team operates standard support (Mon–Fri, 09:00–17:00 UK) with optional 24×7 enhanced cover for incident response. Critical incidents receive an initial response within 30 minutes; high priority within 1 hour; standard within 4 business hours. Combined with Azure’s resilient platform, this approach ensures reliable operations and transparent remediation when targets are not met.
Approach to resilience
Our service is designed for resilience using Microsoft Azure’s highly available platform and best‑practice architecture. Each customer environment is isolated into dedicated subscriptions/resource groups with least‑privilege access. Core components are deployed across multiple availability zones (where supported) with load balancing, health probes, and automatic failover. Platform services use built‑in replication and geo‑redundant options where appropriate to protect against regional incidents.

Capacity is managed through autoscaling and throttling to prevent “noisy neighbour” effects, with proactive monitoring, alerting, and runbooks for rapid recovery. Configuration and infrastructure are defined as code, enabling consistent rebuilds and controlled change. Backups, exportable configurations, and documented recovery procedures support quick restoration and service continuity.

Network resilience includes encrypted endpoints, optional private connectivity, and layered controls (firewalls, NSGs, conditional access). Maintenance is performed during agreed windows to minimise user impact.

Detailed datacentre resilience information (power, cooling, physical security, audited certifications) is provided by Microsoft and is available on request if you require deeper, confidential detail.
Outage reporting
Our service uses Microsoft Azure and Microsoft Entra’s built‑in service‑health and incident‑reporting capabilities. Outages or service degradations are communicated to customers through multiple channels to ensure rapid awareness and coordinated response.

A public service‑health dashboard is available through the Azure Status and Microsoft Entra portals, allowing users to view live and historical incident information. Customers can also subscribe to email alerts for service‑health notifications, planned maintenance, or emerging platform issues. For organisations using management APIs, service‑health data can be accessed programmatically, allowing integration into internal monitoring tools or SIEM dashboards.

Condatis provides direct notification for any incident affecting the customer’s configuration, integrations, or custom components. During major incidents, customers receive timely updates through our support channels, including status summaries, expected remediation timelines, and confirmation when services have been restored.

Post‑incident reports are available on request.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Other user authentication
Users authenticate through Microsoft Entra using strong, identity‑based controls. Supported methods include MFA, passwordless sign‑in, biometric options such as Face Check, public key authentication, and federated sign‑in via existing identity providers. Conditional Access enforces risk‑based checks, device posture, network location, and session controls. Non‑human identities - such as Workload IDs, Managed Identities, and Agent IDs - authenticate using certificates, secrets, or token‑based methods with scoped, role‑based permissions. Administrative and API access requires authenticated, authorised accounts, and optional VPN or private connectivity can further secure access paths.
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted through Microsoft Entra role‑based access control, enforcing least‑privilege permissions for administrators, engineers, and automated workloads. Strong authentication methods - including MFA, passwordless, biometrics, and Conditional Access - ensure only authorised users can access sensitive functions. Non‑human identities use scoped Workload IDs, certificates, or managed identities. Support channels require verified customer contacts; only named and authenticated individuals can raise or manage tickets. Sensitive actions (e.g., configuration changes, data requests) require elevated approval, audit logging, and identity verification before execution. This ensures controlled, traceable access across all operational and support processes.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Description of management access authentication
Role-based access control (RBAC): Access is limited to named administrative roles with least‑privilege permissions.
IP allow‑listing: Management interfaces are restricted to defined trusted locations.
Just-in-time (JIT) privileged access: Optional integration with Microsoft Entra Privileged Identity Management (PIM) for time‑bound admin elevation.

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials Plus, ISO 9001, GDPR, NIST 800‑88 secure data handling, SOC 1/2 (via Microsoft Azure), and Microsoft Secure Development Lifecycle practices.
Information security policies and processes
Condatis operates an ISO/IEC 27001‑certified Information Security Management System (ISMS) with board‑level accountability. Policies include: Information Security, Acceptable Use, Access Control, Secure Development, Vulnerability Management, Incident Management, Business Continuity, Supplier Management, Data Protection (GDPR), and Secure Disposal. Policies are reviewed at least annually, risk‑based, and aligned to Microsoft’s Secure Development Lifecycle.

Reporting structure: The board‑appointed security owner (e.g., CTPO/CISO) chairs the Security & Risk Committee. The ISMS Manager maintains policies, coordinates audits, and reports KPIs. Service Managers own operational controls. Engineers follow documented runbooks and change procedures (four‑eyes review, RBAC, segregation of duties).

How we ensure compliance:
Mandatory annual training, role‑based security awareness, and phishing simulations
Formal risk assessments and treatment plans; DPO input for privacy risks
Change management with CAB approval for high‑risk changes; IaC version control
Continuous monitoring, vulnerability scanning, and patch management SLAs
Supplier due diligence and contractual security requirements
Internal audits, management reviews, and corrective actions; external certification audits

Incidents: Defined triage and escalation (critical: 30‑minute initial response), root‑cause analysis, and post‑incident reviews. Business continuity: Tested playbooks for backup, recovery, and service restoration. Evidence of control effectiveness and audit trails are available to customers on request.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We manage configuration as code with version control, immutable releases, and environment‑specific parameters. Every component (infrastructure, integrations, policies, runbooks) has an owner, CMDB entry, and lifecycle status (dev/test/prod, in‑support, end‑of‑life). Changes follow a documented workflow: request → impact/risk assessment → peer review (four‑eyes) → CAB approval for high‑risk items → change window → automated deployment → verification. Security impact is assessed using threat modelling, dependency checks, vulnerability scanning, and segregation‑of‑duties controls. Rollback plans and monitoring are mandatory. All actions are logged, auditable, and reviewed in post‑implementation reviews to drive continuous improvement.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We operate a risk‑based vulnerability management process within our ISO 27001 ISMS. Threats are assessed through continuous infrastructure scanning, dependency analysis, threat modelling, and configuration‑drift monitoring. Patching follows severity SLAs: Critical within 72 hours, High within 7 days, Medium within 30 days, and Low in planned release cycles, with emergency CAB for urgent fixes. Remediation is tracked through our ticketing system with verification scans. Threat intelligence is sourced from vendor advisories, Microsoft Security updates, CVE/CVSS feeds, OWASP, NCSC alerts, and industry mailing lists to prioritise risks and apply compensating controls where required.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use layered monitoring across Azure, Entra, and service components, capturing authentication, policy, configuration, and integration logs. Potential compromises are identified through anomaly detection, alert rules, threat‑intelligence correlation, and integrity checks. When a potential compromise is detected, incidents are triaged immediately, with rapid containment through access revocation, policy enforcement, or isolating affected components. Response times follow our SLAs: Critical - 30 minutes, High - 1 hour, Standard - 4 business hours. All incidents undergo root‑cause analysis, remediation, and post‑incident review, with continuous tuning of alerts and runbooks to improve detection accuracy and reduce false positives.
Incident management type
Supplier-defined controls
Incident management approach
We operate a defined incident management process within our ISO 27001 ISMS. Pre‑defined runbooks exist for common events such as authentication failures, service degradation, misconfiguration, and integration errors. Users report incidents through our ticketing portal, email, or phone, with triage based on severity. Critical incidents receive a 30‑minute initial response; High within 1 hour; Standard within 4 business hours. During an incident, customers receive timely updates via their chosen communication channel. Formal incident reports, including root‑cause analysis and remediation actions, are provided after resolution, and post‑incident reviews drive continuous improvement.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Standards and certifications

ISO/IEC 27001 certification
Yes
ISO/IEC 27001 accredited by
Centre for Assessment
ISO/IEC 27001 accreditation date
Wednesday 24 April 2024
What the ISO/IEC 27001 doesn’t cover
Out of scope for the Condatis ISO 27001:2022 certificate:
- Any office locations other than Edinburgh
- Business activities not related to digital identity and access management
- Customer‑owned or customer‑hosted environments
- Third‑party systems or services not included in Condatis’ ISMS
- Products/platforms not developed or supported by Condatis
- Any controls or activities excluded in Statement of Applicability v2
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
ISO 9001 certification accredited by
Centre for Assessment
ISO 9001 accreditation date
Wednesday 24 April 2024
What the ISO 9001 doesn’t cover
The following activities and areas are not covered by Condatis’ ISO 9001:2015 certification:
- Activities outside the provision of digital identity & access management solutions
- Non‑IAM consultancy, products, or service lines
- Sales, marketing, finance, HR, legal, and executive corporate functions
- Any office locations other than the Edinburgh HQ
- Customer‑hosted or customer‑managed environments
- Third‑party systems not included in Condatis’ Quality Management System
- Any activities excluded within Condatis’ internal Quality Manual/QMS scope
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
Bfa164bc-3281-4172-8320-4754934cded4
Cyber essentials plus
Yes
Cyber Essentials Plus Certificate Number
Fc2b79db-abcd-4e57-9095-972b3119da7b
Other security certifications
No

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
  • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
  • Plans to engage the contract workforce in deciding the most important workplace issues to address
  • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
  • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
  • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
  • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
  • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
  • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Volunteering opportunities for staff
  • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
  • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling

Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

  • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering

Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

  • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
  • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
  • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
  • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
  • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
  • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
  • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
  • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Plans for positive actions with community groups.
  • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
  • Plans to respond flexibly and adapt approaches to community engagement and initiatives
  • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
Mission: Make Britain a clean energy superpower

To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

  • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
Mission: Break down barriers to opportunity

By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

Policy Outcome 6: Employment and training: For those who face barriers to employment

  • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
  • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
  • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
  • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
  • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
  • Working conditions which promote an inclusive working environment and promote retention and progression
  • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition

Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

  • Understanding of the issues affecting the development of new skills by target cohort
  • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
  • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
  • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Understanding of issues relating to entering the contract workforce
  • Creation of outreach activities to create a pipeline of employees for the future contract delivery
  • Content of the outreach activity is designed to suit the target cohort
  • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
Mission: Build an NHS fit for the future

That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

  • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
  • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
  • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
  • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@condatis.com. Tell them what format you need. It will help if you say what assistive technology you use.