Skip to main content

Help us improve the Digital Marketplace - send your feedback

SOFTCAT PLC

Oakland Data Platform Hosting

We design our client cloud architectures with open, accessible cloud technologies that are easy to maintain, extend and resource once our projects are completed. Our goal is to give you easily managed and extensible cloud infrastructures that will create the platform for continued digital transformation in your organisation.

Features

  • Tailored cloud architecture foreach client’s unique data platform needs.
  • Supports Azure, AWS, and open, accessible cloud technologies seamlessly
  • Rapid “Lighthouse Pilot” approach delivers immediate operational business value quickly.
  • End-to-end data engineering: design, build, migrate, and optimise data platforms.
  • Cross-functional team: data engineers, scientists, governance, and change management experts.
  • Agile delivery model ensures flexibility, adaptability, and continuous improvement throughout
  • No vendor lock-in; easy to maintain, extend, and resource.
  • Predictive analytics and AI/ML capabilities for advanced business insights
  • Transparent, collaborative“ one team” approach with full client inclusion
  • Proven methodology: Discover, Define, Plan, Execute, Adapt for success

Benefits

  • Solutions precisely matched to business goals, not generic or inflexible
  • Future-proofed platforms using latest, best-fit cloud and data technologies.
  • Fast time-to-value with pilots that demonstrate real business impact.
  • Reduced risk and cost through expert-led, proven delivery processes
  • Access to broad expertise, ensuring robust, scalable, and compliant solutions.
  • Adaptable to changing requirements, supporting ongoing business transformation
  • Avoids costly long-term contracts; empowers clients to self-manage platforms
  • Unlocks actionable insights with advanced analytics and machine learning
  • Builds internal capability and knowledge through open, collaborative delivery.
  • Continuous improvement ensures lasting value and measurable performance gains.

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at psitq@softcat.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 7 9 2 9 3 2 9 7 4 8 0 4 2 2

Contact

SOFTCAT PLC Public Sector Tenders
Telephone: 01628 403403
Email: psitq@softcat.com

About your service

Service categories

PaaS

Analytics and Business Intelligence

  • Business Intelligence
  • Advanced Predictive Analytics
  • Location and Geospatial data management and analytics

Service scope

Service constraints
Our service is tailored to client needs and leverages leading public cloud platforms (e.g., Azure, AWS). Constraints may include scheduled maintenance windows as defined by the underlying cloud provider, and support is limited to supported cloud hardware and configurations. Service availability and performance may depend on the client’s chosen cloud region and network connectivity. Customisation is subject to compatibility with standard cloud services. Any planned maintenance or service interruptions will be communicated in advance. No support for on-premises or unsupported legacy hardware
System requirements
  • Active Azure or AWS cloud subscription must be provided.
  • Secure network connection to cloud environment is required throughout
  • Buyer maintains all necessary software licences for deployed workloads
  • Supported operating systems: Windows Server, Linux distributions, cloud approved
  • Up-to-date anti-virus software required on all virtual machines
  • Identity and access management configured using cloud-native tools only
  • Data backup and disaster recovery configured per buyer’s requirements
  • Minimum internet bandwidth required for reliable platform access always
  • Compliance with data protection and security standards is buyer’s responsibility
  • No support for on-premises or unsupported legacy hardware/software
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud

User support

Email or online ticketing support
Yes
Support response times
Oakland provides both email and online ticketing support as part of our managed service offering. Clients can raise support requests via a dedicated email address or through our online ticketing portal, ensuring prompt and traceable resolution of issues. This support is included as standard, with no extra cost for core service users. Response times are different at weekends, with the majority being responded to during normal working hours.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
Oakland’s managed service provides a dedicated leadership team for each engagement, including a service manager(assigned for five or more resources), an account leader, and a director. This team oversees onboarding, demand planning, performance, and quality management. Support is delivered through: Proactive resource management and demand planning Rigorous quality management of deliverables Regular KPI reporting and service reviews Onboarding and training of resources to client standards All clients benefit from these support features as part of the managed service. The service is designed to scale with client needs, and rates can be structured as daily resource rates, fixed monthly fees, or team-based fees. A dedicated service manager acts as the main point of contact for larger engagements, ensuring consistent quality and alignment with client objectives.
Support available to third parties
No

Onboarding and offboarding

Getting started
We support users in getting
started with our Data Platform
Hosting service through a
comprehensive onboarding
process. We provide detailed
user documentation, including
step-by-step guides for Azure,
AWS, and Google Cloud
Platform. Online training
sessions are available to
introduce key features,
management interfaces, and
best practices. For buyers
requiring additional support, we
offer remote onboarding
workshops and can arrange
onsite training upon request.
Our support team is available to
assist with initial setup,
configuration, and integration,
ensuring a smooth transition.
We also provide access to
FAQs, knowledge bases, and
community forums for ongoing
learning. All onboarding
materials are designed to be
accessible and tailored to the
buyer’s chosen cloud platform.
We work closely with buyers to
address specific requirements
and ensure their teams are
confident in using the service.
Continuous support is available
for troubleshooting and
optimisation as users become
familiar with the platform
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
At the end of the contract, users
retain full ownership of their
data and can extract it directly
using the standard tools
provided by Azure, AWS, or
Google Cloud Platform. Data
can be exported via the web
interface, command line
interface, or APIs, supporting
formats such as CSV, JSON, or
native database exports. Users
are responsible for initiating and
managing the extraction
process, including downloading
files, exporting databases, and
migrating backups. We provide
guidance and documentation to
assist with data extraction and
can offer support if required. No
proprietary formats or
restrictions are imposed—data
remains accessible in standard,
interoperable formats. After
contract termination, data will be
securely deleted from our
managed environments in
accordance with the buyer’s
requirements and applicable
data protection regulations.
Buyers should ensure all data is
extracted before the contract
end date to avoid loss of
access.
End-of-contract process
At the end of the contract, users
retain full access to their data
and can extract it using
standard tools provided by
Azure, AWS, or Google Cloud
Platform. Included in the
contract price are guidance documents for data extraction,
access to the platform until
contract expiry, and secure
deletion of data in accordance
with buyer requirements and
data protection regulations.
Basic support for data extraction
is also included. Additional costs
may apply for extended support,
bespoke extraction services, or
complex migrations requiring
significant technical assistance.
If users require onsite support,
custom scripting, or data
transformation beyond standard
export formats, these services
are chargeable. Any continued
access to the platform or
storage after contract expiry will
incur additional fees. Buyers are
responsible for ensuring all data
is extracted before the contract
end date to avoid loss of
access. We work closely with
buyers to ensure a smooth
transition and compliance with
all contractual and regulatory
obligations.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Using the web interface
Users can set up and manage the service via the web interfaces provided by leading public cloud platforms—Microsoft Azure Portal, AWS Console, and Google Cloud Console. Through these interfaces, users can provision compute and storage resources, configure networks, deploy data platform components, and manage access and security settings. Users can scale resources, update configurations, monitor usage, set up alerts, and manage backups directly through the web interface. The portals also provide dashboards for performance monitoring and cost management. However, some limitations apply. Advanced configurations, integrations, or automation may require use of command-line tools, APIs, or support from our team. Customisation is limited to features supported by Azure, AWS, or Google Cloud; unsupported legacy or on-premises systems cannot be managed through these web interfaces. Certain changes, such as major architectural redesigns or cross-region migrations, may require additional planning or support. Scheduled maintenance or updates by the cloud provider may temporarily restrict access to some features. Overall, the web interface offers a comprehensive, user-friendly environment for most management tasks, but some complex requirements may need alternative methods or additional support.
Web interface accessibility standard
WCAG 2.2 AA
Web interface accessibility testing
We test our web interface using standard accessibility tools and guidelines, including screen readers and keyboard navigation. Our service leverages the accessibility features of Azure, AWS, and Google Cloud web portals, which are regularly tested by their providers with assistive technology users. We review updates to ensure continued compatibility and support for users with disabilities. Where possible, we consult user feedback and incorporate improvements. We are committed to meeting recognised accessibility standards and will support buyers in addressing specific accessibility requirements.
API
Yes
What users can and can't do using the API
Users can set up and manage
the Data Platform Hosting
service programmatically via
APIs provided by Azure, AWS,
and Google Cloud Platform.
Through these APIs, users can
provision compute and storage
resources, configure networks,
deploy data platform
components, and automate
scaling and monitoring. APIs
enable integration with other
systems, support for
Infrastructure as Code (IaC),
and allow users to make
changes such as updating
configurations, managing
access controls, and scheduling
backups. However, some
limitations apply. API
functionality is restricted to
features supported by the
underlying cloud platform;
unsupported legacy or onpremises systems cannot be
managed via these APIs.
Certain advanced
configurations, cross-region
migrations, or complex
integrations may require
additional planning or support.
API usage is subject to the
permissions and quotas set by
the cloud provider and the
buyer’s account. Scheduled
maintenance or updates by the
cloud provider may temporarily
affect API availability. Buyers
must ensure secure API usage
and compliance with relevant
standards. Overall, the API offers powerful automation and
integration capabilities for most
management tasks, but some
specialist requirements may
need alternative methods or
support.
API automation tools
  • Ansible
  • Chef
  • OpenStack
  • SaltStack
  • Terraform
  • Puppet
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • ODF
  • PDF
Command line interface
Yes
Command line interface compatibility
  • Linux or Unix
  • Windows
  • MacOS
Using the command line interface
The Data Platform Hosting
service using the command line
interfaces provided by Azure
(Azure CLI), AWS (AWS CLI),
and Google Cloud Platform
(gcloud). Through the CLI, users can provision compute and
storage resources, configure
networks, deploy data platform
components, and automate
tasks using scripts. Users can
make changes such as scaling
resources, updating
configurations, managing
access controls, and monitoring
usage directly from the
command line. The CLI
supports integration with
automation tools and
Infrastructure as Code
workflows. However, some
limitations apply. The CLI is
restricted to features supported
by the underlying cloud
platform; unsupported legacy or
on-premises systems cannot be
managed via the CLI. Certain
advanced configurations, crossregion migrations, or complex
integrations may require
additional planning or support.
CLI usage is subject to
permissions and quotas set by
the cloud provider and the
buyer’s account. Scheduled
maintenance or updates by the
cloud provider may temporarily
affect CLI availability. Buyers
must ensure secure CLI usage
and compliance with relevant
standards. Overall, the CLI
offers powerful automation and
management capabilities, but
some specialist requirements
may need alternative methods
or support.

Scaling

Independence of resources
We guarantee resource
independence by leveraging
Azure, AWS, and Google
Cloud’s multi-tenant
architecture, which isolates
each user’s resources.
Compute, storage, and network
allocations are logically
separated, preventing one
user’s demand from impacting
another’s performance.
Resource quotas, autoscaling,
and quality-of-service controls
further ensure consistent
service levels. Regular
monitoring and platform
safeguards maintain isolation
and reliability.
Usage notifications
Yes
Usage reporting
  • API
  • Email
  • SMS
Optimising consumption
Yes
Automatic scaling
Yes

Analytics

Infrastructure or application metrics
Yes
Metrics types
  • CPU
  • Disk
  • HTTP request and response status
  • Memory
  • Network
  • Number of active instances
  • Other
Other metrics
  • Custom metrics
  • Storage usage
  • Database performance
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Reseller (no extras)
Organisation whose services are being resold
Oakland

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Backup and recovery

Backup controls
Users can control backups
through the cloud platform’s
interface, CLI, or API. Different
resources—such as databases,
virtual machines, or storage—
can be backed up on separate
schedules, with custom
retention periods and backup frequency. Users can enable,
disable, or modify backup
policies for each resource
independently. Automated,
manual, and on-demand
backups are supported.
Advanced options, such as
incremental backups or georedundant storage, are available
depending on the platform. All
backup settings are fully
configurable by the user to meet
specific business or compliance
needs.
Datacentre setup
Multiple datacentres with disaster recovery
Scheduling backups
Users schedule backups through a web interface
Backup recovery
Users can recover backups themselves, for example through a web interface
Backup and recovery
Yes
RPO/RTO
Yes

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks
Mutual authentication,
continuous monitoring,
compliance audits
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Network segmentation,
firewalls, mutual authentication,
monitoring

Availability and resilience

Guaranteed availability
Oakland guarantees a minimum
service availability of 99.9% for
its IAAS and PAAS application
support services, measured
monthly. This equates to a
maximum allowable downtime
of less than 44 minutes per
month, excluding planned
maintenance windows and force
majeure events. Service Level
Agreements (SLAs) are in place
to ensure high availability and
rapid incident response. For
example, Severity 1 (critical)
incidents have a target
resolution time of 8 hours, with
lower severity issues resolved
within 1–5 working days. The
underlying cloud platform SLAs
(e.g., Microsoft Azure, AWS,
Google Cloud) are also passed
through to the client, ensuring
robust platform-level
guarantees. If the guaranteed
availability is not met, users are
eligible for service credits or
partial refunds, calculated as a
percentage of the monthly
service fee for the affected
period. The exact credit/refund
mechanism is defined in the
contract and is triggered
automatically upon verification
of an SLA breach. Outage
reporting and monthly
performance summaries are
provided to all clients. This
approach ensures transparency,
accountability, and fair
compensation for any service
disruption.
Approach to resilience
Oakland’s IAAS and PAAS
services are architected for high
resilience, minimising risk of downtime and data loss. Our
cloud platforms leverage
multiple geographically
separated datacentres, ensuring
redundancy and failover
capability. Data and workloads
are replicated across availability
zones, so if one datacentre
experiences an outage, services
automatically fail over to
another, maintaining continuity.
Critical components—such as
storage, compute, and
networking—are deployed in a
highly available configuration,
with automated health
monitoring and self-healing
mechanisms. Regular backup
schedules and disaster recovery
plans are in place, with recovery
point and time objectives
tailored to client needs. Network
connectivity is resilient, using
redundant links and load
balancing to prevent single
points of failure. Security
controls and monitoring are
active across all layers,
ensuring rapid detection and
response to incidents. This
multi-layered approach ensures
that Oakland’s services remain
available and performant, even
in the event of hardware failure,
network disruption, or other
unforeseen events.
Outage reporting
Oakland’s IAAS and PAAS
services provide transparent
outage reporting to ensure
clients are promptly informed of
any service disruptions. Public
Dashboard: A real-time status
dashboard is available online,
displaying current service
health, ongoing incidents, and historical uptime data. This
dashboard is accessible to all
clients and stakeholders. API
Access: Clients can integrate
with our status API to receive
automated updates on service
availability and incident status,
enabling custom monitoring and
alerting within their own
systems. Email Alerts: In the
event of an outage or major
incident, affected users receive
immediate email notifications
detailing the nature of the issue,
expected resolution times, and
ongoing updates until service is
restored. Monthly outage
summaries and performance
reports are also provided,
ensuring full transparency and
accountability. This multichannel approach ensures
clients are always informed and
can respond appropriately to
any service disruption.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
We enforce strict access
controls aligned with CSA CCM
v4.0. Role-Based Access
Control (RBAC) applies least
privilege roles with Azure AD
group assignments. Conditional
Access policies mandate MFA,
restrict by IP ranges, and
require device compliance.
Privileged Identity Management
(PIM) provides Just-In-Time
access with approval workflows.
Network security includes
NSGs, firewalls, and Azure
Bastion for secure VM access,
while unused interfaces and
legacy protocols are disabled.
Support channels integrate SSO
with MFA, tiered access, and
encrypted communication.
Remote sessions require
approval and are recorded for
audit. All activities are logged,
monitored, and reviewed
regularly under Zero Trust
principles
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
Devices users manage the service through
  • Dedicated device on a segregated network (providers own provision)
  • Dedicated device on a government network (for example PSN)
  • Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)

Audit information for users

Access to user activity audit information
Users receive audit information on a regular basis
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users receive audit information on a regular basis
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Oakland operates a
comprehensive Information
Security Policy Pack,
comprising over 120 individual
policies covering all aspects of
security management, including
access control, information
classification, incident
management, remote working,
data backup, cryptography, and
change management. These
policies are aligned with ISO
27001 and industry best
practice, and are accessible to
all employees via an online
platform, where staff must read
and acknowledge each policy.
Reporting Structure: The boardlevel commitment to information
security is set out in the
organisational Information
Security Policy. Each policy has
a designated owner responsible
for ensuring it is
understandable, pragmatic,
enforceable, and regularly
reviewed (at least annually).
Policy changes require
management approval and are
communicated to all relevant
personnel. The Management
Review Board (Ops Group),
including the Information
Security Officer (ISO) and Data
Protection Officer (DPO),
oversees compliance, incident
management, and reporting to
authorities where required.
Ensuring Compliance:
Mandatory annual policy reading and training for all staff,
tracked via the online platform.
Internal and external audits are
conducted regularly to verify
adherence. Incidents and
weaknesses are logged and
managed through a formal
Security Incident Management
Track, with statistics and
reporting used to identify risks
and drive continual
improvement.

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Oakland tracks all service
components throughout their
lifecycle using asset registers
and configuration management
records. Each change is
formally requested, riskassessed (including security
impact), approved by
management, and logged with
full audit trails. Changes are
implemented in scheduled
windows, tested, and validated
before and after deployment.
Any security implications are
reviewed by the Information Security Officer, and all changes
are subject to regular audit and
continuous improvement. This
ensures traceability,
accountability, and robust
protection for client
environments
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Oakland proactively monitors for
vulnerabilities using automated
tools and regular security
reviews. Threat intelligence is
sourced from vendor advisories,
government alerts (e.g., NCSC),
and industry feeds. All potential
threats are risk-assessed for
impact and urgency. Critical
patches are deployed within 24
hours of release; other updates
follow a scheduled change
process. The Information
Security Officer oversees
remediation, and all actions are
logged and audited to ensure
compliance and continuous
improvement
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Oakland uses automated
monitoring tools and manual
reviews to detect suspicious
activity and potential
compromises. Alerts are
generated for anomalies,
unauthorised access, or policy
violations. On detection, the
Information Security Officer
leads an immediate
investigation, containing and
remediating threats within
hours. All incidents are logged,
analysed, and reported, with
lessons learned used to
strengthen future monitoring
and response.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Oakland has pre-defined
incident management
processes for common events,
including data breaches and
service outages. Users report
incidents via email or the online
ticketing system. Each incident
is logged, categorised, and
investigated promptly by the
Information Security Officer.
Incident reports, including root
cause analysis and remedial
actions, are provided to affected
users and stakeholders within
agreed timeframes. Lessons
learned are used to improve
future response and prevention.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Separation between users

Virtualisation technology used to keep applications and users sharing the same infrastructure apart
Yes
Who implements virtualisation
Supplier
Virtualisation technologies used
Other
Other virtualisation technology used
Proprietary and cloud-native
containerisation technologies
(e.g., Azure Container
Instances, AWS ECS/EKS,
Google Kubernetes Engine) for
further logical separation
How shared infrastructure is kept separate
Oakland, as the supplier,
implements and manages the
virtualisation technology. Logical
separation is enforced using
hypervisors, containers, and
virtual networks. Each
organisation’s workloads are
isolated at the compute,
storage, and network layers,
with strict access controls and
monitoring. This prevents
unauthorised access or data
leakage between tenants,
ensuring robust separation even
on shared physical
infrastructure.

Energy efficiency

Energy-efficient datacentres
Yes
Description of energy efficient datacentres
Our cloud services are delivered
via leading providers (e.g.,
Microsoft Azure, AWS, Google
Cloud), whose datacentres are
certified participants in the EU
Code of Conduct. These
facilities implement best practices for energy efficiency,
including: Advanced cooling
systems and optimised airflow
management Use of renewable
energy sources and power
usage effectiveness (PUE)
monitoring Virtualisation and
workload consolidation to
maximise hardware utilisation
Regular energy audits and
reporting to ensure compliance
with EU standards Continuous
improvement programmes
targeting reduced carbon
footprint and energy
consumption By leveraging
these certified datacentres,
Oakland ensures that all client
workloads benefit from
sustainable, energy-efficient
infrastructure, supporting both
environmental and operational
goals. Documentation of
compliance is available on
request.

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount

Provide your minimum discount applicable to your baseline prices
0%

Formula for calculating price of your services

Formula for calculating price of your services

Which of the core deployment models you intend to offer

  • Public Cloud
  • Private Cloud

Public Cloud - Formula for calculating price of your services


Total Cost
The Total Cost for a buyer's call off requirement in a Public Cloud Deployment
=
Baseline Pricing
Baseline pricing will provided as per the the vendors publicly available catalogue where available and included in the individual G-Cloud catalogue entries, examples include:

https://calculator.aws/#/

https://azure.microsoft.com/en-gb/pricing/calculator/

https://cloud.google.com/products/calculator
Baseline Pricing - Web link
https://calculator.aws/#/
-
Minimum Discounting
0%
+
Onboarding Activity
Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
+
Additional sources of cost
Sources of costs that may relate to buyer's purchasing services under G-Cloud include:
- CPI or other inflationary increase
- Resource required for contract commencement, which is dependant on the size and requirement from the customer
- Increase supply chain costs to Softcat
- Vendor programmatic changes which affect discounts and purchases prices
- additional features / customisation required
- special considerations such as security

Our vendors pricing follows various models such as reoccurring subscription and consumption models, which have various charging models (usage, user) and are priced differently. Additional sources of cost depend on the model customers are purchasing from.
-
Additional sources of cost reduction
There are a variety of different cost reduction sources Softcat can leverage for Buyers under G-Cloud 15, these include:
- Vendor discount programmes
- Reserved Instances
- Savings Plans
- OGVA
- MACC
- GCP PPA
- Volume and Bundling Discounts
- Contract Length Discounts
- Licensing Optimisation efforts
- Contract flexibility, minimising unused software costs.

Private Cloud - Formula for calculating price of your services


Total Cost
The Total Cost for a buyer's call off requirement in a Private Cloud Deployment
=
Baseline Pricing
Baseline pricing will provided as per the the vendors publicly available catalogue where available and included in the individual G-Cloud catalogue entries, examples include:

https://calculator.aws/#/

https://azure.microsoft.com/en-gb/pricing/calculator/

https://cloud.google.com/products/calculator
-
Minimum Discounting
0%
+
Onboarding Activity
Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
+
Additional sources of cost
Sources of costs that may relate to buyer's purchasing services under G-Cloud include:
- CPI or other inflationary increase
- Resource required for contract commencement, which is dependant on the size and requirement from the customer
- Increase supply chain costs to Softcat
- Vendor programmatic changes which affect discounts and purchases prices
- additional features / customisation required
- special considerations such as security

Our vendors pricing follows various models such as reoccurring subscription and consumption models, which have various charging models (usage, user) and are priced differently. Additional sources of cost depend on the model customers are purchasing from.
-
Additional sources of cost reduction
There are a variety of different cost reduction sources Softcat can leverage for Buyers under G-Cloud 15, these include:
- Vendor discount programmes
- Reserved Instances
- Savings Plans
- OGVA
- MACC
- GCP PPA
- Volume and Bundling Discounts
- Contract Length Discounts
- Licensing Optimisation efforts
- Contract flexibility, minimising unused software costs.

Mandatory certifications

Mandatory certifications

Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure

Reseller

Cloud service suppliers you intend to resell with evidence

Organisation 1

Organisation name

Microsoft

Website address/upload for organisation

Website address

Website address

https://marketplace.microsoft.com/en-GB/marketplace/partner-dir/c3d431f1-3e02-4c62-a825-79cd8f9e2053/overview

Organisation 2

Organisation name

AWS

Website address/upload for organisation

Website address

Website address

https://partners.amazonaws.com/search/partners/?keyword=Softcat%20plc

Organisation 3

Organisation name

Salesforce

Website address/upload for organisation

Upload

Upload

Provided

Organisation 4

Organisation name

IBM

Website address/upload for organisation

Upload

Upload

Provided

ISO 9001 certification

Provided

ISO 27001 certification

Provided

ISO 20000-1 certification

Provided

Are you reliant on the Cloud Service Provider for some accreditations

Yes

Cyber Essentials

Do you have a Cyber Essentials Plus certificate?
Yes
Cyber Essentials Plus certificate Number
181966c9-f0aa-42ed-9271-d1b111bdf43b

Non-mandatory Standards and certifications

ISO 28000:2022 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
SecurityMetrics
PCI DSS accreditation date
Friday 10 January 2025
What the PCI DSS doesn’t cover
N/A
Other security certifications
Yes
Any other security certifications
  • ISO 27001
  • Security Standards dependant on the vendor solution

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at psitq@softcat.com. Tell them what format you need. It will help if you say what assistive technology you use.