Websites
Custom WordPress websites designed for public sector organisations. Features include WCAG 2.2 AA accessibility compliance, responsive design, content management system, integrated analytics, secure UK hosting, two-factor authentication, and member areas. ISO 9001/27001 and Cyber Essentials Plus certified. Includes training, ongoing support, and regular maintenance.
Features
- WCAG 2.2 AA Accessibility Compliance
- Responsive Multi-Device Design
- WordPress Content Management System
- Two-Factor Authentication (2FA)
- Matomo Analytics Platform
- Secure UK Data Centre Hosting
- Member's Area Access Control
- Multi-Language Translation Facility -
- Content Update Reminder System -
Benefits
- Update website content easily using drag-and-drop blocks.
- Translate content instantly into over 100 languages.
- Maintain WCAG 2.2 AA accessibility compliance automatically at launch.
- Share sensitive documents securely via password-protected member areas.
- Send newsletters directly without requiring third-party email systems.
- Track performance through intuitive analytics showing visits and engagement.
- Access and manage your website from any device.
- Protect accounts with two-factor authentication reducing unauthorised access.
- Keep content current with automated email review reminders.
- Notify visitors immediately using customisable site-wide alert messages.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 1 1 7 6 9 1 5 2 9 0 8 9 4 3
Contact
PHEW DESIGN LIMITED
Matthew Burgess
Telephone: 01234779050
Email: accounts@phew.org.uk
About your service
- Service categories
-
Applications
Content workflow and management
Content services
- Enterprise Content Management Applications
- Content Sharing and Collaboration Applications
Persuasive content management
- Website Software
- Digital Asset Management Applications
- Product Content Management Applications
- Content Marketing Applications
- Video Platforms
- Digital Adoption Platform
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Planned maintenance occurs monthly outside business hours with two weeks' notice for any downtime. Support available during business hours (9am-5pm weekdays) with four-hour response SLA; out-of-hours support limited to critical infrastructure alerts. Initial training included for up to four administrator users; additional training incurs extra cost. Penetration testing conducted at client request and cost, not included annually. Twitter/X integration available at additional cost depending on traffic requirements. Newsletter functionality, microsite creation, and ongoing accessibility monitoring are optional paid features. Single Sign-On (SSO) not currently supported. Browser compatibility limited to modern browsers only.
- System requirements
-
- Modern web browser required: Chrome, Edge, Opera, or Firefox supported.
- Internet connection needed for cloud-based website access.
- JavaScript must be enabled in your browser.
- Cookies must be enabled for authentication purposes.
- TLS 1.2 or higher required for secure connections.
- Mobile devices require iOS, Android, or compatible system.
- Email account required for administrator notifications and alerts.
- Phone number needed for optional two-factor authentication.
- Minimum screen resolution recommended: 1024x768 pixels for admin.
- PDF reader required for viewing downloadable documents.
User support
- Email or online ticketing support
- Yes
- Support response times
- Phew guarantees a four-hour response time for all support queries raised during business hours (9am to 5pm, Monday to Friday excluding bank holidays). Support is accessible via telephone, email, and online ticketing system. Critical infrastructure issues are monitored 24/7 through automated alerting software, enabling immediate remedial action outside business hours. Planned maintenance occurs outside business hours to minimize disruption, with two weeks' notice provided. Weekend and out-of-hours support is limited to critical system failures only. Non-urgent queries submitted outside business hours receive responses on the next working day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Phew provides comprehensive support through a credit-based system included within the annual hosting fee. Support credits are purchased in advance and used on a per-minute basis during business hours (9am-5pm weekdays) with a four-hour response SLA.
Support channels include: telephone, email, online ticketing, and dedicated Account Manager access.
Credit-based support covers: technical troubleshooting, content management guidance, custom configuration assistance, and training for new administrators beyond initial implementation.
Included without using credits: critical system failures, security patches, framework updates, Virtual Clinics, Lunchtime Learning sessions, Account Manager reviews, and scheduled maintenance.
Standard package includes: Knowledge Academy access with video tutorials and troubleshooting guides, monthly framework updates (scheduled outside business hours), 24/7 infrastructure monitoring, initial training for four administrators (two hours online, recorded), and accessibility conformance (WCAG 2.2 AA) at launch.
Optional paid services: onsite training, Accessibility as a Service with monthly Silktide reports, penetration testing, and bespoke feature development.
Monthly reports detail credit usage and tickets raised. The credit system encourages self-service for routine queries while ensuring technical expertise remains available when needed. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Phew provides comprehensive onboarding support to ensure smooth service adoption:
Initial Training:
Every implementation includes a dedicated two-hour online training session for up to four administrator users. Training is delivered by experienced trainers via video conference, tailored to your organisation's requirements and learning style. All sessions are recorded for future reference and refresher purposes. Optional onsite training available upon request at additional cost.
User Documentation:
Administrators receive full access to Phew's Knowledge Academy containing:
Step-by-step troubleshooting guides
Video tutorials and demonstrations
Best practice documentation
System user manuals
Ongoing Learning:
Phew provides regular complimentary learning opportunities including:
Virtual Clinics for specific topics
Lunchtime Learning sessions
Focus Groups for sharing experiences
New feature announcements displayed within the platform
Implementation Support:
A dedicated project team supports all implementation phases including platform configuration, comprehensive training on the configured system, and support during testing phases. Your assigned Account Manager remains available throughout your relationship with Phew.
Additional training sessions for new administrators or advanced features are available upon request to your Account Manager at extra cost. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- Other
- Other documentation formats
- Video
- End-of-contract data extraction
-
At Contract End:
• Full data export provided in Excel and PDF formats
• All delegate records, training history, certificates, evaluation data, and course information included
• Data export includes marketing consent status for GDPR compliance
• Reports can be filtered and downloaded by organisation grouping, event type, and date range
Data Ownership: All client data remains the property of the client throughout and after the contract. We provide 30 days' notice before contract end to ensure smooth data extraction. After contract termination, data is securely deleted in accordance with GDPR requirements. - End-of-contract process
- Included in Contract Price: Upon contract conclusion, Phew provides complete data extraction and transfer at no additional cost. All website content, documents, images, user accounts, member area materials, analytics data, and database records are securely extracted and transferred to the client or their nominated new supplier. Data is provided in formats suitable for migration to alternative systems. Transition Support: Phew works collaboratively with clients and incoming suppliers to ensure smooth transition. Technical documentation and system configurations are provided to facilitate handover. Your dedicated Account Manager coordinates the exit process, ensuring all contractual obligations are fulfilled. Data Deletion: Following successful data transfer and client confirmation of receipt, all data is permanently deleted from Phew servers and systems as per agreed data retention policies and GDPR requirements. Clients receive written confirmation of data deletion upon completion. Additional Costs: Extended transition support beyond standard data extraction may incur additional costs. If clients require Phew to maintain the website during an extended handover period beyond the contract end date, this would be charged at the standard annual hosting and support rate.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
There are no functional differences between mobile and desktop services. The Phew Website solution uses responsive design techniques with flexible grids, responsive images, and CSS media queries to provide identical functionality across all devices. The layout automatically adjusts based on screen size to ensure optimal user experience on desktops, laptops, tablets, and smartphones.
All features—including content management, document uploads, analytics access, newsletter management, and member area administration—are fully accessible from any device with a modern web browser and internet connection. Users can update and manage website content from anywhere, on any device, maintaining complete administrative control. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
The Phew Website service has multiple interfaces:
Administrator Dashboard/CMS Interface - WordPress-based content management system where administrators can:
Drag-and-drop content blocks
Manage documents
Access the "Broken Link Checker"
Send newsletters
Manage member areas and user permissions
View content update reminders
Configure site alerts
Analytics Interface - Matomo analytics platform for viewing:
Website performance reports
Visitor statistics
Popular pages
Document downloads
Device usage
Support Interface - Online ticketing system and Knowledge Academy access
Public-facing Website - The actual website that end users see and interact with - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
The platform is tested against WCAG 2.2 AA accessibility standards using automated accessibility testing via Silktide. This testing covers key areas such as keyboard accessibility, content structure, use of alternative text, and support for browser zoom and responsive layouts.
Accessibility statements are published within the system, and accessibility is treated as an ongoing process. Regular reviews are carried out, with issues identified through testing addressed as part of continuous improvement to enhance accessibility for all users. - API
- No
- Customisation available
- Yes
- Description of customisation
-
What can be customised:
Administrators can customise website design including logos, colours, fonts, and branding elements. Page layouts are fully customisable using flexible content blocks arranged via drag-and-drop functionality. Content structure, navigation menus, categories, and taxonomies are fully configurable. Member area access controls can be customised with category-based permissions. Site-wide alert messages are customisable for specific or all pages. Newsletter templates and email communications are customisable. Analytics dashboard views can be configured to track specific metrics relevant to organizational needs.
How users customise:
Customisation occurs through the intuitive WordPress Content Management System interface. Administrators use drag-and-drop blocks to arrange page layouts without requiring technical expertise or coding knowledge. Design elements are managed through the admin dashboard. Content categories, user permissions, and site alerts are configured through simple form-based interfaces.
Who can customise:
Trained administrator users with appropriate access permissions can customise the service. Organisations typically train up to four administrators during initial implementation. Super Administrator roles can create microsites with differentiated branding. All customisation occurs without requiring Phew technical support, empowering administrators to maintain complete control over their website appearance and functionality.
Scaling
- Independence of resources
- Each client website operates as an isolated application with data separated by unique primary keys set at application load. Phew maintains 99.9% availability through 24/7 infrastructure monitoring with automated alerting for immediate remedial action. Our UK data centres provide Level 3 DDoS mitigation and robust hosting infrastructure designed to handle concurrent traffic across multiple client sites. Monthly maintenance and patch management ensure optimal software performance. Critical support processes enable rapid response to any performance issues. Rolling 30-day backups with monthly restoration testing ensure service continuity and data integrity for all clients.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Phew provides comprehensive service metrics through Matomo analytics platform. Metrics include website visitor numbers over specified periods, most popular pages, document downloads, device types used (desktop, tablet, mobile), browser types, geographic locations of visitors, and user engagement patterns. The administrator dashboard includes a Broken Link Checker that regularly reviews all content and reports broken links. Administrators can generate custom reports to track key performance indicators, monitor trends, and measure marketing campaign effectiveness. Monthly usage reports detailing support tickets raised are also available upon request, providing insights into system performance and user activity.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users contact their dedicated Phew Account Manager to request data export. Phew's technical team securely extracts all website content, documents, images, user accounts, member area materials, analytics data, and database records from the hosting environment. Data undergoes necessary transformations to ensure compatibility with standard formats. The extracted data is then securely transferred to the client or their nominated recipient via encrypted file transfer methods. Phew adheres to stringent data security standards throughout the export process to prevent data loss or compromise. Clients receive confirmation once all data has been successfully extracted and transferred.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
Other protection within supplier network
Data transfers within Phew's network occur via local connections on the same server between the application and database. As these are internal server connections that do not traverse external networks, they do not require additional encryption. The server infrastructure is hosted in secure UK data centres with Level 3 DDoS mitigation, 7 layers of physical security, strict access controls limited to authorised Phew personnel and hosting partner staff only, and 24/7 monitoring with surveillance systems and access logs.
Availability and resilience
- Guaranteed availability
- We maintain 99.9% availability for the website service, maintained through 24/7 critical infrastructure monitoring with automated alerting software enabling immediate remedial action. Our UK data centres provide Level 3 DDoS mitigation, 7 layers of physical security, and automated fail-over redundancies for utilities, services, and environmental controls. Scheduled Maintenance: Monthly maintenance is performed outside business hours (typically overnight/weekends) with two weeks' advance notice for any planned downtime. Maintenance schedules are designed to avoid service disruption, with activities planned to cause no loss of service where possible. Business Continuity: Rolling 28-day backup policy with restorable snapshots enabling full system restoration if required. Monthly in-person restoration testing simulates catastrophic events. Real-time monitoring tracks key metrics including up/down status, CPU/RAM/disk usage, backup presence, and scheduled job execution. Incident Response: Critical support processes enable immediate response to infrastructure alerts. All issues receive four-hour response during business hours (9am-5pm weekdays), with 24/7 monitoring for critical system failures. SLA Terms: Specific service level agreements including availability guarantees, response times, and remedies for non-compliance are documented in individual client contracts.
- Approach to resilience
-
Our service is designed with multiple resilience layers to ensure continuous availability and rapid recovery:
Infrastructure Resilience: Hosted in Telehouse South, a secure UK data centre with dual-redundant power feeds, 2N UPS configuration, and N+1 generator resilience. Infrastructure is delivered on scalable virtualised platforms with spare capacity, enabling rapid failover and removal of single points of failure.
The site benefits from diverse dark-fibre connectivity and multi-layer physical security including 24/7 guarding, biometric access control, CCTV, and perimeter intrusion detection. Operations align with ISO/IEC 27001, ISO 22301, and PCI-DSS standards.
Backup and Recovery: 28-day full file system and database backups stored in geographically separate data centres, isolated from production infrastructure. Backups are tested and can be restored to any server within 2 hours. Our backup system enables service restoration through an alternative provider if needed.
Proactive Monitoring: 24/7 real-time monitoring tracks system health, backup completion, and scheduled job execution. Automated alerts enable immediate response. Critical incidents receive immediate attention 24/7.
Data Protection: Strict client ID enforcement ensures customer separation. Encrypted backups provide additional protection.
Compliance: ISO 27001 certified and compliant with NCSC Cloud Security Principles. Recovery procedures are regularly tested. - Outage reporting
- Phew provides proactive outage notification through automated email alerts: Planned Maintenance: Clients receive two weeks' advance notice via email for any scheduled maintenance or planned downtime. Maintenance is performed outside business hours to minimise disruption. Unplanned Outages: Our 24/7 infrastructure monitoring system with automated alerting software detects system issues immediately. When critical incidents occur, clients are notified via email, and our critical support processes enable immediate remedial action. Support Communication: Clients can also contact their dedicated Account Manager or Phew support team (via telephone or email during business hours 9am-5pm weekdays) for real-time status updates on any service issues. All infrastructure notifications are logged and tracked to ensure prompt resolution and client communication.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is provided only to identified system administrators. Employee access for maintenance and support is restricted to authorised personnel with justified business need. Support is provided exclusively to designated administrators who have completed platform training.
All access is password-protected. WordPress enforces strong password policies through its password strength meter. Role-based access controls provide granular permission management.
User activity logging is optional and disabled by default. When enabled, retention periods are configurable. Server-level access logs are retained for 7 days. When activity logging is enabled, logged activities are continuously monitored to detect and respond to security incidents. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus (UK Government cyber security certification), ISO 9001 (Quality Management System), ISO 14001 (Environmental Management System), OWASP secure development standards, NCSC Cloud Security Principles, UK GDPR and Data Protection Act 2018 compliance, Government Security Classification Policy.
- Information security policies and processes
- Phew maintains comprehensive information security policies compliant with ISO 27001:2022 standards, covering all aspects of information security management for design, support, and hosting of digital services.Key Policies and Processes:Secure Development Policy: Development team follows documented secure coding practices aligned with OWASP standards, incorporating security considerations throughout the software development lifecycle.Access Control Policy: Username and password systems with pattern matching, minimum entropy calculations, time-limited password reset tokens, 20-attempt lockout protection, and IP-restricted server access with time-limited restrictions.Patch Management: Monthly maintenance programme with daily security patch alerts ensuring timely application of critical and high-risk vulnerability fixes.Vulnerability Management: Monthly vulnerability testing on operating system and network levels using AppCheck scanning tools. Regular penetration testing by CREST-accredited third parties for significant products.Business Continuity: Rolling 28-day backup policy with monthly restoration testing, documented disaster recovery procedures.Incident Management: Specific information security incidents management procedures compliant with data protection laws and ISO 27001 requirements.Governance Structure: Policies maintained as commercial intellectual property under restricted distribution. Regular internal reviews and external audits through ISO 27001 and Cyber Essentials Plus certification processes ensure ongoing compliance
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
All approved changes are tracked in our work tracking system throughout their lifetime. Changes are assessed for potential security impact during development lifecycle testing and QA process before deployment.
Released logs are retained and online notification provided to administrators within the platform. Changes are designed to minimize service disruption. When downtime is required, formal prior notice is provided with scheduling during off-peak hours.
Monthly maintenance and update alerts are assessed on risk and deployed according to priority. Our ISO 27001-certified processes ensure systematic tracking of system status, location, and configuration of service components throughout their operational lifetime. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Threat Assessment: We identify, prioritise, and mitigate vulnerabilities through annual CREST-accredited penetration testing and monthly automated penetration reporting. Our 24/7 platform monitoring alerts on potential threats including brute force attacks and denial of service attempts.
Information Sources: Monthly maintenance and update alerts from infrastructure providers, CREST penetration test findings, and automated security monitoring provide continuous threat intelligence.
Patch Deployment: Identified vulnerabilities are assessed on risk and patches deployed according to severity. Automatic infrastructure notifications enable immediate remedial action via our critical support process. Security measures immediately restrict problematic IPs when threats detected.
All processes maintained under ISO 27001 certification. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Identifying Compromises: 24/7 monitoring reports potential compromises via dashboard and email alerts. Platform monitoring tracks traffic patterns and automatically identifies threats including brute force attacks and denial of service. Audit logs retained for 90 days enable prompt incident analysis.
Response Process: Incidents receive immediate action to maintain security. Security measures automatically restrict problematic IPs when threats detected. Communication plan activated internally and externally upon incident identification.
Response Time: Automated response for detected threats occurs immediately. Manual incidents receive prompt investigation with timely updates until resolution. Action taken to resolve and prevent reoccurrence. ISO 27001 certified processes. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Pre-defined Processes: ISO 27001-compliant incident management documented in our Secure Development Policy. Critical incident processes actively deployed for common events including service outages and security incidents. Unscheduled downtime triggers critical process with 24/7 response capability.
User Reporting: Users report incidents via email or telephone to our support team during business hours (9am-5pm). Platform includes alert system for administrators.
Incident Reports: Incident report created at identification. Client lead contacts receive timely updates via email and phone until resolution. Communication plan accommodates incident severity and stakeholder requirements. Monthly support reports are available detailing incidents and resolution times. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 1.5%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- ISOQAR
- ISO/IEC 27001 accreditation date
- Tuesday 30 June 2020
- What the ISO/IEC 27001 doesn’t cover
-
Annex A Control A.8.23 'Web Filtering' is excluded from our ISO/IEC 27001:2022 certification. We do not implement group web filtering policies due to the nature of web design work and the sensitive data on our systems. Risk mitigation is achieved through employees agreeing to Acceptable Use and Electronic Communications policies, which govern appropriate internet usage and data handling practices.
All other controls within ISO/IEC 27001:2022 Annex A are applicable and implemented within our Information Security Management System. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- ISOQAR
- ISO 9001 accreditation date
- Wednesday 11 July 2012
- What the ISO 9001 doesn’t cover
-
Clause 7.1.5.2 'Measurement Traceability' is excluded from our ISO 9001:2015 certification. We do not use any measuring or monitoring equipment that requires calibration or verification against standards traceable to international or national measurement standards. Our business operations do not involve physical measurements requiring this level of traceability.
All other clauses within ISO 9001:2015 are applicable and implemented within our Quality Management System. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 90fe9f0c-72fc-494f-b5d1-814904a1c5e7
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-