ACS Cloud Application Services
ACS offers a complete range of SAAS Cloud Services & Collaborative Software, Support and modernization with a seamless transition and reliable support. ACS is an expert in Licence audits, deployment, and training, and customizes Cloud based solutions to suit organisation's needs.
Features
- Migration and Deployment: Assistance with migrations, deployments, and cloud adoption
- Co-Managed Support: Acting as an extension of client IT departments
- Robust Security: Data encryption, loss prevention, and compliance
- Technical Support: Standard technical support, productivity and security licence audits
- License Utilization
- Cloud Backup and Security: Ensuring data safety and regulatory compliance.
Benefits
- Enhanced Collaboration: Seamless integration with Microsoft Product sets
- Cost-Effective Licensing: Strategic license management for optimal utilization
- Data Safety: Cloud backup and security measures for data protection.
- Strategic Planning: Quarterly strategic planning and technological updates
- Strategic Engagement: ACS provides a strategic approach to Microsoft license
- Security-centric migration with data protection.
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 8 4 2 9 2 5 4 0 9 1 8 8 5 1
Contact
ACS TECHNOLOGY GROUP LTD
Ben Townend
Telephone: 01274 556091
Email: ben.townend@acsgroup.co.uk
About your service
- Service categories
-
Applications
Engineering
- Computer-Aided Design Applications
- Computer-Aided Engineering Applications
- Computer-Aided Manufacturing Applications
- Collaborative product data management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service is limited to Vendor subscriptions within the agreed scope and relies on the customer providing timely access, information, approvals and licences. Third‑party platforms and Microsoft service availability remain outside provider control. Optimisation and security actions require customer approval, with services delivered in line with agreed service hours, SLAs and shared compliance responsibilities.
- System requirements
-
- Supported operating systems
- User devices capable of accessing cloud‑hosted services
User support
- Email or online ticketing support
- Yes
- Support response times
- SLA's are dependent on service taken. 1 hour for Critical outages 4 Hour for Single user outages 8 Hours for small system changes The above are example of SLA offerings
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support services are provided on a time‑and‑materials basis at a standard professional services day rate of £1,200. This rate applies to migration, optimisation, remediation and operational support activities delivered remotely or on customer premises, where agreed. Services are delivered by suitably qualified engineers during standard business hours, excluding public holidays. All support activity is scoped, scheduled and agreed in advance with the customer. Work may include incident investigation, configuration changes, architectural design, security improvements and performance or cost optimisation. Support is provided on a reasonable endeavours basis and is dependent on the customer supplying timely access, information, approvals and licences. Partial days may be charged on a pro‑rata basis. Any requirement for specialist resources, expedited delivery or out‑of‑hours support is subject to separate agreement and may incur additional charges. Service delivery is governed by agreed service levels and does not include responsibility for third‑party services or platform availability.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
If Required
Onboarding begins with a formal initiation phase to confirm service scope, objectives and delivery approach. This includes agreement of supported subscriptions, workloads, service levels and any required customisations. The customer provides necessary documentation, access permissions and licensing information to enable service delivery. A discovery and assessment phase follows, during which the existing environment is reviewed to establish a baseline covering architecture, security, performance, cost and governance. Findings are documented and used to validate assumptions, identify risks and confirm priorities. Once discovery is complete, the service is configured in line with the agreed solution design. This may include setting up monitoring, security controls, access models, reporting and operational processes. Any required migrations or optimisation activities are planned and scheduled with minimal disruption. The onboarding process concludes with a transition to steady‑state service delivery. This includes confirmation of support channels, escalation paths, service levels and reporting arrangements. Knowledge transfer is provided where appropriate, ensuring the customer understands service operation and ongoing engagement processes. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- The Data is kept within the customers tenant and is not held by ACS
- End-of-contract process
- At the end of the contract, the service enters a structured offboarding phase to ensure a smooth and orderly transition. The supplier works with the customer to agree exit timelines, responsibilities and any handover requirements. Access to environments, documentation and operational information is maintained until the agreed contract end date. All customer data, configuration information, architecture documentation and service records created or maintained as part of the service are returned to the customer or a nominated third party, as requested. This includes reasonable assistance to support continuity of service and minimise disruption during transition. No additional charges are applied for the handover of customer information or standard service documentation. The supplier will revoke its administrative access at the end of the contract in line with customer instructions and security best practice. Any customer data held by the supplier is handled in accordance with contractual and data protection obligations, with confirmation provided where data deletion is requested. Following contract completion, no ongoing management or support is provided unless a new agreement is put in place.
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- EN 301 549
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- If Microsoft service then it is designed to ensure that one customer’s usage does not adversely affect another’s service performance. Microsoft operates a multi‑tenant architecture with strict logical isolation at tenant, subscription and resource levels. Compute workloads are isolated using hypervisor‑based virtualisation, while storage and networking are segregated per subscription. Microsoft enforces resource quotas and capacity controls to prevent any single workload from monopolising shared infrastructure.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Microsoft , Adobe , Corel, Paralles
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
- Microsoft protects all customer data at rest by default using AES‑256 encryption across supported services, including storage, databases and virtual machine disks. Encryption is applied automatically as data is written to physical media and cannot be disabled for Azure Storage services. By default, encryption keys are securely managed by Microsoft. Where greater control is required, customers can use customer‑managed keys stored in Azure Key Vault to manage key access, rotation and lifecycle. For higher‑risk workloads, Microsoft also supports infrastructure‑level double encryption, providing defence‑in‑depth. Encryption at rest operates within Azure’s shared responsibility model, supporting recognised regulatory and security compliance requirements.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Data Erasure
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Not needed as stays within there tenant
- Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
- Other
- Other protection between networks
- Microsoft Applications used in web or Desktop application.
- Data protection within supplier network
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- The service is hosted on Microsoft 365 and benefits from Azure’s enterprise‑grade infrastructure and availability commitments. Microsoft Azure provides formal Service Level Agreements (SLAs) that define guaranteed levels of service availability, measured on a per‑month basis. For most Azure services, Microsoft guarantees a minimum availability of 99.9% per calendar month, equating to a maximum of approximately 43 minutes of unplanned downtime per month. Higher availability levels are achievable where services are architected in line with Microsoft best practices, for example by deploying resources across Availability Sets or Availability Zones. In such configurations, availability guarantees can increase to 99.95% or 99.99%, depending on the service and deployment model. Availability is monitored continuously by Microsoft and is supported by resilient datacentre design, redundant power and networking, proactive maintenance, and automated failover mechanisms. Planned maintenance is managed to minimise disruption and, where possible, performed without customer impact. If Microsoft fails to meet the applicable SLA for an Azure service, customers may be entitled to service credits in accordance with Microsoft’s published SLA terms. The service operates under a shared responsibility model, meaning availability guarantees apply where the service is configured and operated in line
- Approach to resilience
- The service is designed to be resilient and is hosted on Microsoft Cloud, which provides built‑in platform capabilities to support fault tolerance, high availability, and business continuity. Resilience is achieved through redundant infrastructure, geographic distribution, and automated recovery mechanisms. Microsoft regions are composed of multiple physically separate datacentres. Where supported, services are deployed across Availability Zones, which are independent locations within a region with separate power, cooling, and networking. This design ensures that a failure in a single datacentre or zone does not result in a service outage. Microsoft also supports fault domains and update domains, reducing the risk of correlated failures during hardware faults or planned maintenance. Many Microsoft services provide zone‑redundant or region‑redundant configurations, enabling automatic replication of data and services and supporting failover in the event of infrastructure disruption. Platform monitoring, health checks, and automated recovery processes are used to detect and respond to failures without manual intervention. Resilience is implemented in line with Microsoft’s Well‑Architected Framework and reliability guidance. The service operates under a shared responsibility model, meaning resilience is supported by both the Azure platform and service configuration. This approach enables the service to continue operating during component failures and recover quickly from unexpected incidents.
- Outage reporting
- The service reports outages using Microsoft Azure’s built‑in service health and incident reporting capabilities. Azure continuously monitors the health of its infrastructure and services and provides real‑time visibility of service issues through Azure Service Health and the public Azure Status Page. For widespread or significant incidents affecting multiple customers, regions, or services, Microsoft publishes updates on the Azure Status Page, which provides a global view of current and historical service issues. This page is updated in real time and includes incident status, affected regions, and post‑incident reviews where applicable. For customer‑specific or targeted issues, outage notifications are delivered through Azure Service Health within the Azure portal. This provides a personalised view of incidents, planned maintenance, and service advisories that may affect the service based on the deployed resources and regions. Notifications can be configured to alert service administrators via email, SMS, or integrated IT service management tools. During an incident, Microsoft provides ongoing updates until service is restored, followed by a post‑incident report where appropriate. This approach ensures timely, transparent communication of outages and supports effective incident response and stakeholder communication.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- Access to Microsoft 365 management interfaces and support channels is restricted using Microsoft Entra ID identity controls. Role‑Based Access Control ensures users are assigned only the permissions required for their role, following the principle of least privilege. Administrative access is limited to authorised personnel and protected using multi‑factor authentication. Conditional Access policies restrict access based on factors such as user role, device compliance, location, and sign‑in risk. Access to support portals and administrative tools is logged and monitored using Microsoft 365 audit and sign‑in logs, providing oversight and traceability of administrative and support activities.
- Access restriction testing frequency
- Less than once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- The organisation follows a documented set of information security policies and processes aligned with ISO/IEC 27001:2022. Policies are designed to protect the confidentiality, integrity, and availability of information and apply to all employees, contractors, and third parties. Core policies cover information security governance, access control, information classification and handling, incident management, application security, physical security, and the secure use of cloud services. Information security risks are identified and assessed on an ongoing basis. Appropriate controls are implemented to manage identified risks and their effectiveness is reviewed through regular internal audits and formal management reviews. Policies and procedures are reviewed at least annually, or sooner where required due to changes in risk, technology, or regulatory requirements. Staff receive information security awareness training and are required to comply with all relevant policies as part of their role. A reporting structure is in place. All users are required to report actual or suspected information security incidents promptly using defined reporting channels. Reported incidents are escalated to the designated incident owner and information security leads for investigation and response. Significant incidents, risk trends, and compliance matters are reported to senior management to ensure oversight, accountability, and continual improvement of the information security management system.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- The service uses structured configuration and change management processes aligned with Microsoft Azure best practices. Service configuration is controlled using standardised, documented settings and is reviewed regularly to prevent configuration drift. Changes are planned, risk‑assessed, and approved prior to implementation, with testing performed where appropriate to minimise service impact. Changes are implemented in a controlled manner and monitored to ensure successful deployment.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- The service follows a structured vulnerability management process aligned with Microsoft Azure security best practices. Vulnerabilities are identified through continuous assessment using Microsoft Defender for Cloud if client takes the service, which provides both agentless and agent‑based scanning of supported resources. Identified vulnerabilities are reviewed within the Azure security portal, prioritised based on severity and risk, and tracked until resolution. Remediation actions, such as applying patches or configuration changes, are implemented in a controlled manner and monitored for effectiveness. The process supports ongoing risk reduction, auditability, and compliance through continuous monitoring and reporting.
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- Protective monitoring is delivered using Microsoft 365 native security and audit capabilities. Microsoft Defender for Office 365 monitors email and collaboration services for malicious activity, generating alerts for threats such as phishing, malware, and suspicious user behaviour. Microsoft Entra ID sign‑in and audit logs provide continuous monitoring of user authentication and administrative actions. The unified Microsoft 365 audit log records user and admin activity across Exchange, SharePoint, OneDrive, and Teams. Security alerts and logs are reviewed by authorised personnel, with incidents investigated and escalated in line with documented incident management procedures.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The service operates a structured incident management process aligned with ITIL best practices using Autotask. Incidents are identified through monitoring, automated alerts, or user reports and are promptly logged, categorised, and prioritised based on impact and urgency. Appropriate technical teams investigate incidents to restore normal service as quickly as possible, with escalation applied where required. Progress is tracked throughout the incident lifecycle and relevant stakeholders are kept informed
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 1%
- Between £1,000,001 and £2,500,000
- 1%
- Between £2,500,001 and £5,000,000
- 1%
- Over £5,000,001
- 1%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Monday 15 July 2024
- What the ISO/IEC 27001 doesn’t cover
- N/a
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Tuesday 2 September 2025
- What the ISO 9001 doesn’t cover
- N/a
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Ade3587b-337c-4113-9179-8b25d272282f
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-