Skip to main content

Help us improve the Digital Marketplace - send your feedback

ROWDEN TECHNOLOGIES LTD.

Self-serve Portal

Rowden's Self-serve Portal allows any authorised users to deploy scalable, secure cloud applications effortlessly. Authorised users can tailor configurations, available services, and security via their team or ours. Manage, monitor, and scale with ease, benefiting from transparent, itemised billing and comprehensive yet intuitive administrative tools.

Features

  • Pre-configurable: Pre-configure secure cloud applications, ready to deploy
  • Scalability Built In: from 10s to 1000s of users automatically
  • Managed Security: customisable by user or Rowden experts
  • Persistent Monitoring: Offers round-the-clock logging and monitoring with archive options
  • Dashboards: Comprehensive user and administrator reporting
  • Observability: Real-time monitoring and metrics
  • FinOps: Transparent itemised billing system, per user or per service

Benefits

  • Usable: Simplifies cloud application deployment, direct with the end user
  • Secure: Enhances security with expert or in-house configurations
  • Scalable: Grows with organisational needs, no limitations
  • Reduces need for specialised cloud skills
  • Observable: Provides detailed oversight and operational control
  • FinOps: Streamlines financial operations and billing transparency
  • Effective resource and budget management
  • Improved administrative efficiency and resource allocation
  • Flexible: Offers robust scalability and optionality for all users

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@rowdentech.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 4 1 1 4 8 0 2 5 7 8 2 7 3 1

Contact

ROWDEN TECHNOLOGIES LTD. Sales Team
Telephone: +44 (0) 117 4285759
Email: sales@rowdentech.com

About your service

Service categories

PaaS

Application Development

  • Development languages, environments, and tools
  • Software construction components

Service scope

Service constraints
The service is optimised for modern Android devices running ATAK; iOS support is limited because iTAK lacks feature parity and offers more restrictive integration. Full functionality assumes some level of IP connectivity (internet, private WAN, 4G/5G, SATCOM or tactical bearer). Degraded and disconnected modes are supported, but federation, updates and remote management require periodic connectivity. Deployments into MOD or customer environments may depend on local approval for networking, identity and security services. Performance scales with the selected hosting tier and network quality, and very high concurrency may require dedicated tenancy. Only approved and signed third-party plugins or APKs are permitted.
System requirements
  • Modern Android devices capable of running ATAK.
  • Supported ATAK versions installed on buyer devices.
  • IP connectivity: internet, private WAN, 4G/5G, SATCOM.
  • Ability to install and update APKs on devices.
  • Camera and GPS enabled for situational awareness features.
  • QR-code scanning capability for Join Pack onboarding.
  • Web browser access for management portal administration.
  • Buyer-provided user identities, or access to SSO integration.
  • Network access to service endpoints via approved firewall rules.
  • Optional: MDM capability for fleet provisioning and enforcement.
Cloud deployment model
  • Public cloud
  • Private cloud

User support

Email or online ticketing support
Yes
Support response times
Response times are dependent on service level agreements as agreed with the buyer. Flexible response times can be provided allowing users to ensure support is available when needed, including for operational purpures
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Level 1 – Standard (included): Monday to Friday 09:00–17:00 (UK), excluding public holidays. Covers incident triage, service requests, platform operations, and user/portal support, with escalation to engineering when needed. A named Service Manager is available for agreed service governance. Included in the managed service price.
Level 2 – Extended (optional): Monday to Friday 07:00–19:00 (UK), excluding public holidays. Provides the same scope as Standard Support with faster response and support for operational changes during extended hours. Includes a named Service Manager where agreed. Priced per service agreement and SLA.
Level 3 – 24/7 (optional): 24/7 including UK public holidays. Delivers continuous incident response, operational recovery, on-call engineering escalation, and optional 24/7 monitoring and alerting. A dedicated Service Manager and on-call Cloud Support Engineer are available. Priced per service agreement and SLA.
Incident management and SLAs: Response and resolution targets are defined in the SLA. Incidents are prioritised as: P1 Critical (outage/security incident), P2 High (major degradation), P3 Medium (partial loss with workaround), P4 Low (minor issues/requests).
Account and technical support: Cloud Support Engineers are available for operations and incidents. Technical Account Managers and named resources can be added as options, scoped and priced to SLA requirements.
Support available to third parties
No

Onboarding and offboarding

Getting started
We help users start using the service through structured onboarding and clear operational guidance. We provide user documentation covering portal use, environment creation, user management, client onboarding, and common operational tasks. We provide guided remote onboarding sessions and optional online training for administrators and end users, including walk-throughs of typical deployment and usage workflows. Where required, we can deliver onsite training and operational handover workshops as an additional service. We also provide standard onboarding artefacts (e.g., Join Packs and QR enrolment workflows) to simplify client device setup and enable rapid adoption in both connected and deployed environments.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
When the contract ends, users can extract their data through the service portal and/or API using export functions provided for operational data and configuration artefacts. This includes exporting environment configuration, audit logs, approved plugins and application packages, and any operational datasets held within the service, in standard formats suitable for transfer to buyer-managed storage. We support an agreed offboarding process to confirm what data is required and ensure exports are completed securely. After contract termination, we do not retain user data unless the buyer explicitly requests a short-term retention period (up to 30 days) to support transition; data is then securely deleted in line with the service offboarding policy.
End-of-contract process
At the end of the contract, we will agree and execute a secure offboarding plan with the buyer. This includes confirming which environments and services will be decommissioned, supporting the buyer to export required data and configuration artefacts, and securely closing down all hosted services. User accounts and access permissions will be removed, and tenant resources will be deprovisioned to prevent further access. Unless the buyer requests a short-term retention period (up to 30 days) to support transition, all buyer data will be securely deleted or destroyed in line with the service offboarding policy and audit requirements.

Included in the contract price: standard offboarding support, data export assistance, secure decommissioning of environments, removal of user access, and confirmation of deletion.
Additional costs: any extended data retention (beyond the standard policy), bespoke data migration or transformation work, additional onsite support, or continued service operation beyond the contract end date.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Our onboarding and offboarding documentation is provided in accessible digital formats and follows recognised accessibility good practice. Documentation uses clear headings, consistent structure, and plain language to support screen readers and ease of navigation. Content is available in web-based and downloadable formats, supports browser zoom and text resizing without loss of readability, and avoids conveying meaning through colour alone. Diagrams and images include descriptive text or captions where appropriate, and links are labelled clearly. Documentation is designed to be usable with keyboard-only navigation and common assistive technologies, and we provide a contact route for users to request alternative formats or report accessibility issues.

Using the service

Web browser interface
Yes
Using the web interface
The service interface is a secure web-based portal that allows authorised users and administrators to create, manage and operate tactical environments through an intuitive self-service workflow. From the portal, users can deploy operationally ready TAK services (including TAK servers and supporting components), start/stop/restart environments, manage users and roles, and access configuration and onboarding artefacts (e.g., Join Packs and QR enrolment). The portal provides visibility of environment status, health, logging and monitoring dashboards, and supports controlled plugin and application distribution where enabled. Security is enforced through role-based access control (RBAC), strong authentication (including SSO/MFA options), audit logging, and encrypted communications; all actions are recorded for operational assurance and compliance.
Web interface accessibility standard
None or don’t know
How the web interface is accessible
The service is accessed through a web-based portal designed to be usable by a broad range of users, including those with accessibility needs. The interface follows recognised accessibility good practice and is designed to align with WCAG 2.1 AA principles, including clear navigation, consistent layout, meaningful headings and labels, and support for keyboard-only operation. The portal supports screen readers through semantic HTML and accessible form controls, provides sufficient colour contrast, and avoids relying on colour alone to convey meaning. Users can adjust browser zoom and text size without loss of functionality, and the service is designed to work across modern browsers and devices. Where interactive components are used, focus states and input validation messages are presented in an accessible way. The service does not currently provide full offline portal access; however, operational outputs (e.g., client onboarding artefacts) can be exported for use in disconnected environments.
Web interface accessibility testing
We have tested the service interface against recognised accessibility good practice, including checks for keyboard-only navigation, screen reader compatibility, and colour contrast compliance. Testing has included the use of common assistive technologies (e.g., screen readers and browser accessibility tools) to validate that key workflows such as authentication, environment creation, user management, and configuration actions can be completed without reliance on a mouse. Findings are captured and prioritised within our delivery backlog, and accessibility checks form part of our ongoing quality assurance and release process.
API
Yes
What users can and can't do using the API
Users can interact with the service through a secure, authenticated API to automate common administrative and operational tasks. Using the API, authorised users can provision environments from approved templates, start/stop/restart services, manage users and roles, retrieve configuration and onboarding artefacts, and query environment status, health and audit logs. The API can be used to integrate the service into buyer workflows (e.g., CI/CD pipelines, service management tools, or operational automation) and supports repeatable setup by applying version-controlled configuration and infrastructure definitions. Users cannot use the API to access underlying infrastructure directly, bypass portal controls, modify the managed baseline platform configuration, deploy unapproved software, or override security and policy restrictions. API usage is subject to role-based access control, tenant isolation, rate limiting, and audit logging; some actions may require elevated permissions or service-provider approval where they impact shared platform components or certified patterns.
API automation tools
  • Ansible
  • Terraform
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
Command line interface
No

Scaling

Independence of resources
Through tenant isolation, resource management, and proactive capacity planning. Each buyer environment operates within a logically isolated tenancy, with dedicated configuration, access controls, and separate operational boundaries. Compute, storage, and network resources are allocated with defined capacities, quotas, and scaling limits to prevent “noisy‑neighbour” effects, while platform services enforce rate limits and workload scheduling to maintain stability. In shared delivery models, buyers can reserve baseline compute and storage capacity, with additional resources available on demand. Reservation levels and scaling parameters are agreed during service design, supported by continuous monitoring to maintain consistent performance.
Usage notifications
Yes
Usage reporting
Email
Optimising consumption
No
Automatic scaling
Yes

Analytics

Infrastructure or application metrics
Yes
Metrics types
  • CPU
  • Memory
  • Number of active instances
Reporting types
Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Backup and recovery

What’s backed up
  • User database – all user accounts, roles, groups, certificates, metadata.
  • Device identities, tags, certificates, trust and revocation states.
  • Access control – RBAC rules, permissions, mission and group policies.
  • Plugin manifest – enabled plugins, versions, configurations, compatibility metadata.
  • Mission data – mission definitions, participants, overlays, attachments, version history.
  • Server configuration.
  • Certificate authority - keys, issued certs, revocation lists, renewal records.
  • ETL/TDG rulesets – ingestion schemas, transformations, routing, enrichment logic.
Backup controls
Our approach provides continuous protection with an automated schedule. Core data is backed up hourly for the past 24 hours, daily for the past month, and weekly for all previous months, giving users a predictable and resilient history without requiring manual oversight. Users can still tailor what is included, choosing specific data types or applying alternative schedules where operational needs differ. This balance of automation and flexibility ensures critical information is always captured while allowing bespoke exclusions or retention rules. During contract setup, we work with customers to refine backup scope, scheduling, and retention to meet service and compliance requirements.
Datacentre setup
Multiple datacentres with disaster recovery
Scheduling backups
Supplier controls the whole backup schedule
Backup recovery
Users contact the support team
Backup and recovery
Yes
RPO/RTO
No

Data-in-transit protection

Data protection between buyer and supplier networks
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks
Using layered network and cryptographic controls, all traffic between client devices, buyer networks and service endpoints is encrypted in transit with industry‑standard protocols and strong certificate management. Network connectivity is restricted to approved ingress points, and administrative access is limited to controlled interfaces with multi‑factor authentication. Where required, we support secure VPN or private network options with segmentation to separate operational and management traffic. Continuous monitoring, intrusion detection where available, and full audit logging help identify and investigate anomalous activity. Data protection is strengthened through tenant isolation, role‑based access control, and least‑privilege policies to prevent unauthorised access across environments.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
We provide an availability commitment defined in the Service Level Agreement (SLA) agreed with the buyer. The service is designed for high availability through resilient architecture, monitored infrastructure, automated recovery, and operational support. Availability is measured monthly against the service’s core components (management portal, control plane, and hosted environments) excluding planned maintenance and events outside our reasonable control (e.g., buyer network outages, upstream carrier failures, force majeure).

Typical availability targets are agreed based on the buyer’s operational needs (e.g., standard service availability during business hours, or enhanced availability for 24/7 operational use). Where the service does not meet the agreed availability target, the buyer will be eligible for service credits in line with the SLA. Service credits are applied as a proportion of the monthly service charge for the affected service component, scaled by the extent and duration of the availability breach. Refund and credit arrangements, including exclusions and claim processes, are defined within the contract and SLA.
Approach to resilience
Our service is designed for resilience through layered technical controls, automated recovery, and operational processes that reduce single points of failure. The platform is deployed using infrastructure-as-code and repeatable templates to enable rapid rebuild and consistent configuration across environments. Core services are designed to be highly available, with health checks, automated restart and self-healing mechanisms, and continuous monitoring to detect and respond to failures. Data is protected through regular backups, defined retention policies, and tested restore procedures, with encryption at rest and in transit.
Outage reporting
We report outages and service degradation through multiple channels, depending on the buyer’s preferences and agreed support model. We provide service status updates via a service desk and operational communications process, including direct notifications to buyer administrators and end users where required. Outages and incidents can also be reported through automated alerting (email notifications) and, where enabled, API-accessible service health/status endpoints for integration into buyer monitoring tools. For managed customers, we provide incident updates and resolution progress reports through the agreed incident management process, including severity classification, timestamps, and post-incident reporting where appropriate.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
Using layered security controls aligned to least privilege and zero trust principles. Management access is limited to administrators and engineers through role-based access control (RBAC) with multi-factor authentication (MFA), using IP allow-listing and network access policies. Administrative functions are separated from standard user functions, privileged actions require elevated permissions and are fully BAC where appropriate. Support channels are controlled through authenticated service desk access, verified contacts, and defined escalation paths, ensuring only approved buyer representatives can raise requests or authorise changes. All administrative and support interactions are logged, auditable, and access is regularly reviewed to maintain operational and security compliance.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
Devices users manage the service through
  • Dedicated device on a segregated network (providers own provision)
  • Dedicated device on a government network (for example PSN)
  • Dedicated device over multiple services or networks
  • Directly from any device which may also be used for normal business (for example web browsing or viewing external email)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Rowden operates a robust Information Security Management System (ISMS) aligned with ISO 27001 and Cyber Essentials Plus, ensuring confidentiality, integrity, and availability of all data. Governance is supported by leadership through the Rowden Management System (RMS), integrating security with quality and environmental standards.
Core policies include:

Information Security Policy: Covers encryption of sensitive data, secure handling of assets, and compliance with legal and contractual obligations.
Network Security Policy: Enforces multi-factor authentication, strict access controls, and timely patching of network devices.
Event Reporting Policy: Requires immediate reporting of incidents via designated channels, with escalation to senior management and regulators when necessary.

Processes underpinning these policies include role-based access control, documented incident response plans, and continuous audit and monitoring of systems and service providers. Regular risk assessments and a maintained Statement of Applicability ensure controls remain effective.
Rowden also holds ISO 9001, ISO 14001, and JOSCAR registration, demonstrating commitment to operational resilience and defence supply chain compliance. These measures collectively safeguard sensitive information and maintain trust with clients operating in high-security environments.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
In our vulnerability management process, we assess threats through diverse sources like threat intel feeds and vendor advisories. We promptly deploy patches, prioritising critical ones for immediate action, staging others to minimize disruptions. Information sources include official vendor announcements, CVE databases, and security forums, ensuring timely response to emerging threats.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
In our vulnerability management process, we assess threats through diverse sources like threat intel feeds and vendor advisories. We promptly deploy patches, prioritising critical ones for immediate action, staging others to minimize disruptions. Information sources include official vendor announcements, CVE databases, and security forums, ensuring timely response to emerging threats.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Our protective monitoring processes involve:
Identifying Potential Compromises: We use automated and manual tools to monitor network traffic, logs, and user activity for anomalies.
Response to Compromises: Upon detection, we follow defined procedures to manage the incident, where applicably escalating to our incident response team for investigation and containment.
Incident Response Time: We define RTOs and RPOs for systems within our environment, and have SLAs to manage incident response time from our SOC team.
Incident management type
Supplier-defined controls
Incident management approach
Our incident management processes include predefined procedures for common events, ensuring a systematic response. Users report incidents through email, online forms, or phone hotlines, promoting prompt resolution. Incident reports are generated post-resolution, detailing the event's timeline, impact, root cause analysis, remediation actions, and preventive measures. These reports enhance transparency and facilitate organisational learning.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Separation between users

Virtualisation technology used to keep applications and users sharing the same infrastructure apart
Yes
Who implements virtualisation
Third-party
Third-party virtualisation provider
AWS, Google, MS Azure
How shared infrastructure is kept separate
Cloud providers ensure organisations sharing the same infrastructure remain isolated through layered security controls. Virtualisation and containerisation enforce strong separation of compute, memory, and storage. Software-defined networking prevents traffic from crossing between tenants unless explicitly allowed. Identity and access management provides strict logical boundaries, ensuring only authorised users and systems access resources. All data is encrypted at rest and in transit, with cryptographic wiping when resources are recycled. Control-plane APIs apply authenticated, per-tenant isolation for all operations. Independent audits and compliance frameworks validate that these technical and procedural controls maintain strict tenant separation across shared cloud environments.

Energy efficiency

Energy-efficient datacentres
Yes
Description of energy efficient datacentres
The cloud infrastructure in Europe is hosted on modern, hyperscale data centres designed to maximise energy efficiency and minimise environmental impact. These facilities use advanced virtualisation, high-efficiency servers, and optimised cooling systems to reduce overall power consumption. Continuous monitoring of power usage and data-centre performance supports improvements in both operational efficiency and sustainability.
Energy usage is reduced through automated workload scaling, modern hardware refresh cycles, and efficient network and storage architectures. The provider implements low Power Usage Effectiveness (PUE) designs, employs renewable energy where available, and follows best practices for responsible water use and heat-recovery systems.
Operational processes also reflect the Code’s intent: equipment is maintained to energy-efficient standards, unused capacity is optimised, and data-centre layouts and airflow management follow industry best practice. Security and resilience requirements are met without compromising efficiency.
Although participation in the EU Code of Conduct is voluntary, the architectural and operational approach taken by our cloud provider aligns with its principles: efficient facility design, responsible energy management, low-impact cooling, renewable energy adoption, and continuous improvement of operational efficiency.

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Rowden will support the user to define what they want to trial before providing a 2 week free to use trial. All data generated by the user will be available for export if required.
Link to free trial
N/A

Discount

Provide your minimum discount applicable to your baseline prices
2%

Formula for calculating price of your services

Formula for calculating price of your services

Which of the core deployment models you intend to offer

Private Cloud

Private Cloud - Formula for calculating price of your services


Total Cost
The Total Cost for a buyer's call off requirement in a Private Cloud Deployment
=
Baseline Pricing
In our uploaded pricing documents
-
Minimum Discounting
2%
+
Onboarding Activity
Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
+
Additional sources of cost
N/A
-
Additional sources of cost reduction
N/A

Mandatory certifications

Mandatory certifications

Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure

Sole Control of the Infrastructure

ISO 9001 certification

Provided

ISO 14001 certification

Provided

ISO 27001 certification

Provided

ISO 20000-1 certification

Provided

ISO 27017 certification

Provided

Are you bidding to provide services under Lot 1b or both Lot 1a and Lot 1b?

Yes

ISO 27018 certification

Provided

Cyber Essentials

Do you have a Cyber Essentials Plus certificate?
Yes
Cyber Essentials Plus certificate Number
3442e527-13f4-4ef6-b092-5f114ab88ee4

Non-mandatory Standards and certifications

ISO 28000:2022 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
    • Plans for positive actions with community groups.
    • Measures for making facilities used in the delivery of the contract available for community groups, education or training
    • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
    • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@rowdentech.com. Tell them what format you need. It will help if you say what assistive technology you use.