Cerina Professional Services: Implementation, Clinical Safety & Interoperability
Cerina provides Professional Services under G-Cloud Lot 2b (Cloud Support) to support the deployment, configuration, interoperability, integration, evaluation and optimisation of the Cerina cloud service. These services are delivered only in connection with the Cerina platform and are not offered as standalone consultancy.
Features
- Pathway design workshop with clinical and operational leads
- Assessment & Conversational Flow Configuration
- Escalation, safeguarding and signposting mapping
- Multilingual configuration and validation
- Interoperability review of local systems and data flows
- Definition of data fields, formats and exchange approach
- Data-sharing agreement drafting and negotiation support
- Clinical safety documentation support (DCB0129, DCB0160) and DPIA
- DTAC, DSPT and safety assurance evidence preparation
- Technical documentation and handover for local teams
Benefits
- Faster deployment through reuse of existing assessments and logic
- Reduced compliance risk with Clinical Safety Officer and DPO cover
- Fewer information governance blockers to go-live
- DTAC, DPIA and DCB evidence produced without external consultancy
- Multilingual configuration supports equity and inclusion obligations
- Interoperability delivered without bespoke integration cost
- Local teams equipped to operate the service independently
- Data-sharing agreements templated and negotiated with receiving services
- Safeguarding pathways aligned to local escalation routes from day one
- Configuration aligned to commissioner reporting and KPI requirements
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 0 8 3 4 9 0 0 8 7 0 1 1 0 8
Contact
NOSUFFERING LIMITED
Prasannajeet Mane
Telephone: 07404717777
Email: prasannajeet.mane@cerina.co
About your service
- Service categories
-
Application Development and Deployment
Software quality and life cycle
- Software change, configuration and process management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
Planned maintenance is carried out periodically to apply updates, security patches, and improvements. Where possible, maintenance is scheduled outside UK business hours, and customers are notified in advance of any planned service disruption.
The service requires a stable internet connection and is supported on current and commonly used versions of mobile operating systems. Support for older or end-of-life mobile operating system versions may be limited.
Updates to the mobile application are distributed via standard app store mechanisms and may be subject to platform approval processes.
Support is provided remotely and during UK business hours unless otherwise agreed at call-off. - System requirements
- No additional software, plugins, or specialist hardware required
User support
- Email or online ticketing support
- Yes
- Support response times
- 2 working days.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Accessibility has been considered through internal testing and the use of recognised accessibility guidance, including manual checks such as keyboard-only navigation, focus management, screen reader behaviour, colour contrast, and text resizing within the web chat interface.
Accessibility considerations are incorporated into ongoing development, and any issues identified through internal testing or user feedback are prioritised for remediation. More structured accessibility testing, including testing with assistive technology users, is planned as the service continues to evolve. - Onsite support
- Yes, at extra cost
- Support levels
-
Standard support (included)
Email-based support during UK business hours (Monday to Friday, excluding public holidays)
Incident logging and triage
Bug fixes and service-related queries
Access to product updates and documentation
Typical response times aligned to issue severity (e.g. critical incidents prioritised)
Cost:
Included in the standard service subscription
Enhanced support (optional)
Priority email support with faster response times
Scheduled support check-ins where required
Support for integration and configuration queries
Escalation management for incidents
Cost:
Charged as an additional annual or monthly fee (priced on request depending on scope and customer requirements)
Technical account management / cloud support
A dedicated technical account manager (TAM) is not provided as standard
For customers requiring enhanced support, a named technical contact can be assigned to coordinate support, manage escalations, and act as a primary liaison
Support is delivered by experienced technical staff familiar with the service and its hosting environment
Important clarifications (this protects you)
Support is provided remotely
No on-site support is included unless separately agreed
Service levels and response times can be agreed at call-off
All support is delivered in line with agreed data protection and security controls - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Users are supported to start using the service through a combination of in-app guidance, digital onboarding, and user documentation.
The mobile application includes guided onboarding to help users understand core features and how to use the service.
Supporting documentation and guidance can be provided digitally to organisational customers, and support is available via email during UK business hours to assist with setup and usage queries.
No on-site training is required, and the service is designed to be intuitive and self-guided for end users.
Administrative users can be supported with remote setup guidance where required.
Onsite and remote demonstrations can be provided on request. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
At the end of the contract, organisational customers can request extraction of their data by contacting the support team.
Data can be securely exported in a commonly used, machine-readable format and provided to the customer via a secure transfer method, subject to appropriate identity verification and data protection controls.
Following confirmation of successful data extraction and in line with contractual and data protection requirements, data is securely deleted from the service within agreed timescales. - End-of-contract process
-
At the end of the contract term, access to the service is disabled in line with the agreed contract end date.
Organisational customers may request extraction of their data prior to or at contract termination by contacting the support team. Data is securely exported in a commonly used, machine-readable format and provided via a secure transfer method, subject to appropriate identity verification and data protection controls.
Following confirmation that data extraction has been completed, customer data is securely deleted from the service in line with contractual terms, data protection requirements, and documented retention policies.
Where applicable, reasonable off-boarding support is provided remotely to support an orderly contract exit. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Interoperability & Data Enablement
Multi-Pathway Extension
Assessment & Conversational Flow
Pathway Design & Translation
Scaling
- Independence of resources
-
The service is hosted within a scalable cloud environment designed to support multiple customers concurrently. Resources are logically separated and managed to ensure that activity from one customer does not adversely impact others.
The underlying infrastructure uses capacity management, monitoring, and autoscaling controls to manage demand and maintain consistent performance. Service performance is monitored, and capacity is adjusted as required to respond to changes in usage.
This approach helps ensure that users experience a consistent level of service regardless of demand generated by other users.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Data is securely extracted in a commonly used, machine-readable format and provided via a secure transfer method, subject to appropriate identity verification and data protection controls.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is designed to be highly available and is hosted within a resilient cloud environment.
The service targets 99.5% availability, measured on a monthly basis, excluding planned maintenance. Planned maintenance is scheduled in advance where possible and customers are notified ahead of any expected disruption.
Availability is monitored, and incidents affecting service availability are prioritised for resolution. - Approach to resilience
-
The service is hosted within a resilient cloud environment designed to support high availability and fault tolerance. The underlying infrastructure uses redundant components and managed cloud services to reduce single points of failure.
Data is hosted in geographically resilient data centre locations operated by the cloud service provider. The provider is responsible for physical security, power, cooling, and network resilience, and operates multiple data centres to support service continuity.
The service is designed to recover from component or infrastructure failures through automated monitoring and recovery mechanisms. Regular backups are performed, and tested recovery processes are in place to support service restoration if required.
Detailed information about the underlying data centre configuration and resilience measures can be provided on request. - Outage reporting
-
Service outages and significant incidents are communicated to organisational customers via email notifications.
Where appropriate, updates are provided during an incident and a follow-up summary can be shared once the issue is resolved.
The service does not currently provide a public status dashboard or outage reporting API.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is restricted to authorised personnel only. Access is granted on a least-privilege basis according to job role and is reviewed regularly.
Administrative access is protected through strong authentication controls and logging. Support channels are access-controlled, and customer data is only accessed where required to provide support and with appropriate authorisation.
Access rights are removed promptly when staff roles change or employment ends, and access activity is monitored as part of ongoing security controls. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
The service is operated in accordance with an ISO/IEC 27001 certified information security management system (ISMS).
Information security policies and processes are defined, documented, and maintained as part of the ISMS, covering areas such as access control, data protection, incident management, risk management, supplier security, and business continuity.
Responsibility for information security is clearly defined within the organisation. Senior management retains overall accountability for information security, with day-to-day oversight delegated to nominated security and operational leads.
Compliance with information security policies is ensured through a combination of staff training, documented procedures, risk assessments, internal audits, and management review. Policies and controls are reviewed regularly and updated as required to address changes in risk, technology, or regulatory requirements.
Information security incidents are reported, assessed, and managed in line with documented incident management procedures. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Service components, including application code, configuration items, and supporting infrastructure, are tracked using version control and configuration management practices. Changes are recorded, versioned, and traceable from development through testing and deployment, supporting accountability and auditability.
Proposed changes are assessed prior to implementation to evaluate potential impacts on security, clinical safety, data protection, and service availability. This includes risk and impact assessment in line with documented change management procedures established through compliance with DCB0129 and UKCA Medical Device Class I requirements.
Changes are reviewed, tested and approved before deployment. Post-change monitoring is performed to confirm successful implementation. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
The organisation operates a defined vulnerability management process as part of its information security controls. Potential threats are identified through risk assessments, monitoring of service components and dependencies, and review of relevant security advisories. Identified vulnerabilities are assessed for severity and potential impact on security, safety, data protection, and service availability.
Patches are prioritised based on risk, with high-severity issues addressed as a priority following assessment and testing, and lower-risk issues scheduled into planned release cycles. Information on emerging threats is obtained from cloud service provider notifications, software supplier advisories, and recognised vulnerability databases. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
The service uses protective monitoring to identify potential security compromises through logging, monitoring, and alerting of system and application activity. Alerts are reviewed to detect unusual or suspicious behaviour that may indicate a security incident.
When a potential compromise is identified, it is assessed promptly in line with documented incident management procedures, and appropriate containment, remediation, and escalation actions are taken.
Security incidents are prioritised based on severity, with high-risk incidents responded to as a priority to minimise impact and support timely resolution. - Incident management type
- Supplier-defined controls
- Incident management approach
-
The organisation operates documented incident management processes to handle security and service incidents. Pre-defined procedures are in place for common incident types to support consistent and timely response.
Users and organisational customers can report incidents by contacting the support team via email. Reported incidents are logged, assessed, and prioritised based on severity and potential impact.
Incident updates are provided to customers via email where appropriate, and a summary report can be shared following resolution to support transparency and service improvement. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 19%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 22%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Tuesday 15 April 2025
- What the ISO/IEC 27001 doesn’t cover
-
The ISO/IEC 27001 certification applies to the scope defined in the organisation’s Information Security Management System (ISMS).
Activities and systems outside the certified scope, such as third-party services not directly operated or controlled by the organisation, are not covered by the certification. Physical security of cloud data centres is managed by the cloud service provider and is outside the organisation’s direct ISO 27001 scope.
Any non-production environments or business functions not included in the ISMS scope are also outside certification coverage. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 03ba57fd-0223-4de8-bf33-8f114e5fb2bf
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
-