Digital Accessibility Review and Remediation Services
Microlink provides three main areas of Digital Accessibility that includes Web accessibility, mobile accessibility, and PDF remediation. PDF remediation refers to ensuring the usability of PDF documents by disabled people. Alongside this we also offer Assistive Technology (AT) compatibility testing and scripting for the JAWS screen reader.
Features
- Ensures compliance to WCAG 2.2 A, AA, AAA and PDF/UA
- Manual tests which include reviews, remediation, and reporting
- Colour contrast, reading order, meaning of alternative text descriptions
- Use of Assistive Technology (AT) such as screen readers
- Automatic tests which include reviews, remediation, and reporting
- Use of automatic digital accessibility review tools, TPGi ARC Toolkit
- Minimise false positives and provide clear stakeholder friendly recommendations
- Use of an AI based platform to remediate PDFs
Benefits
- Provides both manual and automatic digital accessibility testing
- QA/recommendations ensure compliance and usability by disabled people
- Reviews determine priority for: short-, medium- and long-term gains
- Snapshot reviews determining the digital accessibility of common barriers
- Full review compliance to WCAG 2.2 A, AA, AAA
- May improve usability by disabled people of digital platforms
- One stop solution for web, mobile and PDF accessibility
- Social Value PDF remediation providing employment for young neurodivergent talent
- Adding metadata to PDFs and remediation of Microsoft documents
- Assistive Technology (AT) compatibility testing and JAWS scripting
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 0 9 0 3 7 5 7 7 4 0 3 4 5 3
Contact
MICROLINK PC (UK) LIMITED
Hazel Knights
Telephone: 02380240300
Email: sam@microlinkpc.com
About your service
- Service categories
-
Applications
Content workflow and management
- Document
- Media Services
Content services
- Enterprise Content Management Applications
- Content Sharing and Collaboration Applications
Persuasive content management
- Website Software
- Digital Adoption Platform
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No service constraints - the platform configures extensively and has multiple integration options.
- System requirements
- Late-release internet browser
User support
- Email or online ticketing support
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
The onsite support levels Microlink’s Digital Accessibility team provide a one-to-three-day physical site visit for consultancy that is followed with a short report of findings. Microlink provides digital accessibility onsite training, demonstrations and testing of onsite systems if required. This includes training documentation where required. We have extensive knowledge about the accessibility features available for different operating systems used onsite, from desktop/laptops and mobile devices. Microlink has expertise with assessing digital assets which includes eLearning platforms, such as a Learning Management System.
Our expert teams can also aid with determining suitable AT, and training on AT, such as the screen readers JAWS or NVDA that read aloud screen content to users who may be blind or visually impaired. We can also advise on the use of switch devices for those who may have mobility impairments or on appropriate software used on-site by neurodivergent employees. Our Digital Accessibility rate card is £1000 per day. We allocate members of our expert digital accessibility team based on the scale and/or volume of the project. Alongside this we also offer AT compatibility testing along with JAWS scripting. The compatibility testing is charge at £1000 per day and the JAWS scripting is charged at £1200. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Implementation is project-driven, starting with requirements gathering via web session or in-person, and then managed via project team between Microlink and the Buyer involving all relevant stakeholders. Onsite and online training is packaged as part of the project and tailored to specific requirements. Onboarding is delivered through a dedicated Onboarding Team. Training is delivered via webinars to build knowledge of how the system works and expand the Buyer's Disability Confidence in making use of the system.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Microsoft Office Documents (Word, PowerPoint, Excel)
- End-of-contract data extraction
- The project concludes with delivery to the client and works conclude as per the contract, no data extraction is required. No Personally Identifiable Information (PII) is captured during PDF remediation or web and mobile application accessibility reviews. For Web or mobile application accessibility the client provides us with a representative sample of web pages and/or screens for a mobile application. This enables us to script the project. Once agreed contractually we will then undertake a web and/or mobile application accessibility review (either snapshot/full) or remediation of all PDFs that are supplied.
- End-of-contract process
-
At the end of the contract, all agreed deliverables—such as accessibility review reports, remediation outputs, or validation summaries—are handed over to the client in their final format. We also provide a brief close out meeting to confirm that the project objectives have been met, outline any remaining recommendations, and discuss potential next steps. Once the contract concludes, no further work is carried out unless a new agreement or purchase order (PO) is issued. The contract price includes all work necessary to complete the defined scope, such as conducting accessibility reviews of web or mobile applications to the required WCAG 2.2 conformance level (A, AA, or AAA), and delivering clear, actionable findings. This work is typically charged at a day rate of £1,000. For PDF remediation at scale, pricing is based on overall project volume and complexity; exact rates are provided in formal proposals but are not publicly disclosed. Low volume retail PDF remediation is handled through a simple PO rather than a formal contract.
Additional costs may apply if the scope expands—such as requests for extra rounds of testing, additional platforms, large scale document batches, or accelerated delivery timelines. Any such costs are agreed in advance before work proceeds. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The layout of the user interface adapts depending on the screen size utilised by the end user. Accordingly, it does not matter whether an end user is using a desktop or any other mobile device, be it tablet or smartphone.
The Portal uses bootstrap responsive design; function remains the same across device types. Differences would include layout only to ensure good user experience and follow best practices. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Both the digital accessibility and Retail PDF remediation web pages are available on the Microlink website which can be used by mainstream web browsers, such as Edge, Chrome and FireFox. The digital accessibility webpage provides contact details and information about the service. The Retail PDF remediation page also provides contact details for remediation at scale but also allows PDF documents to be uploaded directly.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Microlink has access to all assistive software. We use a full range of these applications to conduct accessibility testing on our systems and documentation within the Digital Accessibility department.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Our digital accessibility services enable clients to choose web, mobile or document formatting in isolation or in combination. For both web and mobile accessibility reviews the client specifies a representative sample of web or screen pages needing to be reviewed as they will know their content the best. Alongside this they will need to specify which level of compliance is required. For example, WCAG 2.2 A, AA, AAA, although AA is recommended.
Our reviews use an abridged or full version of the Web Content Accessibility Guideline Evaluation Methodology (WCAG-EM) report tool. This will include the selection of a 10% random sample from the client’s website or mobile application to comply with WCAG-EM requirements. We undertake testing on specified mainstream web browsers for both desktop/laptop and mobile platforms. Alongside this we undertake manual tests with AT, either native to the OS or third party. We also use automatic web accessibility evaluation tools such as Axe and PowerMapper in tandem with mobile testing tools such as Accessibility Scanner (Android). We offer both PDF and Microsoft (MS) document remediation, which includes the export from MS documents as a tagged PDF. Our clients can also choose if they require compatibility testing and JAWS scripting.
Scaling
- Independence of resources
- Microlink utilises and configures our environments within Microsoft Azure and has designed the service automatically to allocate additional resources depending on demand. Microlink also makes use of Azure’s Web Application Firewalls and monitoring tools to detect Distributed Denial of Service and respond appropriately.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- AccessibilityInsight AI platform and CalibrAI developed by codeMantra
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Microlink delivers remediated PDF files directly to the client in their preferred format. For smaller projects, files are typically sent via secure email or another agreed method. For large scale remediation projects, Microlink provides access to a dedicated SharePoint folder or secure FTP location, allowing clients to download files efficiently as batches are completed. This approach ensures smooth handling of high volume workloads while maintaining full security and traceability. All files are organised, labelled, and delivered in accordance with the client’s requirements, and Microlink confirms completion once all documents have been successfully uploaded or transferred.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- DOCX
- PPT
- XLSX
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- DOCX
- PPT
- XLSX
- Direct input via the PDF remediation webpage
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Service uptime >99% if there is planned maintenance that can affect this it is arranged in advance and usually done outside of operating hours. We scope for RPO 1 hour as we backup hourly and RTO 2 hours in disaster event.
- Approach to resilience
- The approach to resilience: the client’s data is processed in M365 cloud and thus is covered by Microsoft's cloud resilience capabilities. Resilience is underwritten by our service provider, Microsoft Azure. Azure provides independent availability zones (AZ) so if one fails the others remain operational currently our setup spans 2 or 3 different AZ depending on the resource and the fault tolerance requirements, geo-redundancy is planned but not yet available.
- Outage reporting
- Any outage is reported by dynamic email alerting. Outage alerts are sent to pre-registered user(s) at the client by the Microlink IT support desk. The service itself is monitored via external services every minute and alerts are sent to IT staff immediately if an issue is detected.
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
- We implement comprehensive access control policies, defining and restricting who can access data based on their role and the necessity of access. These policies are enforced through robust authentication and authorisation mechanisms, including multi-factor authentication and the principle of least privilege. Regular audits and compliance checks are conducted to ensure that logical segregation controls are effectively implemented and maintained. These audits also help identify potential vulnerabilities and enforce continuous improvement in our security posture. Continuous monitoring and logging of access and activities related to client data help in detecting and responding to potential security incidents promptly.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Other
- Description of management access authentication
-
Internal users are authenticated via EntraID (the IdP) and Auth0 (the SSO provider) in this case our IdP manages the identities and enforces our policies of password complexity and MFA.
For External users a one-size-fits-all solution it is not possible as some will not have SSO available or use different IdP’s. If they choose not to use SSO, we offer the option of password and username with recommendation they use an MFA as well such as an OTP authenticator, the responsibility is delegated to them as it is their account.
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Microlink is ISO 27001:2022 certified and maintains information security policies accordingly. This includes the Business Management System Manual, which details the scope, the objectives, the responsibilities and the risk rating and management, as well as the mobile device policy, clear desk, access, teleworking and encryption management policy. Several other policies are also in force, including Change and Release procedure, document retention policy, incident management procedure, information classification and handling policy and the physical security policy. Finally, Microlink maintains a detailed Risk Register for logging of events and triggering any preventative/remedial measures. There is a documented escalation path from operator level right through to our board with dynamic stakeholder alerting at each level. All of these policies and procedures are subject to independent external review at least once a year, and also the subject of annual audit by many of our corporate clients.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Microlink utilises an internal proprietary change management system and tracks all changes across Microlink. This system ensures that the change and justification for the change and impacted areas including potential security impacts are recorded. Once a change has been defined the system facilitates getting approval signed by all the owners of the impacted areas. Once a review is approved by a member of the Executive Board it is implemented on a staging environment for review and once it meets acceptance criteria, it is deployed to production.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Hrough Microsoft Azure we have a number of systems in place including automated container vulnerability scanning, monthly patching of servers, and penetration testing of the service. We apply security patches as soon as they are available. Our approach focuses on maintaining system integrity through timely updates and monitoring rather than structured threat modelling
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Microlink utilises testing tools - static application security, dynamic application security, and human led testing comprising manual security tests and penetration testing to identify potential compromises. When discovered, the compromise is recorded, and impact measured so it can be categorised appropriately: Info/None, Low, Medium, High, Critical.
We aim to respond to incidents quickly based on severity/impact. Our process includes immediate acknowledgment upon detection and prioritisation according to our internal incident management workflow. While we do not commit to fixed SLAs, our goal is to begin investigation promptly and apply fixes as soon as practical to minimise disruption. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Microlink utilises an incident management system, that allows any staff to report and record incidents as and when they occur. This process ensures appropriate recording and remediation of incidents is performed. Incidents are actively monitored and allow Microlink to record new controls and risks within our risk register. Incidents that affect our buyers are communicated directly to the buyer from the buyer’s Account Manager. Escalation Based on Severity. Low: Logged for reference, monitored for patterns, closed after documentation.
Medium: Assigned to the security team for investigation and remediation.
High: Immediate escalation to the IT Teams, management, and possibly legal/compliance teams. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 7.5%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Wednesday 9 July 2025
- What the ISO/IEC 27001 doesn’t cover
- Due to the nature of the services we provided, data masking or anonymisation is not possible, so it is not covered by our certification. We can provide a redacted version of our SOA for ISO27001 showing all the sections covered.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- NQA
- ISO 9001 accreditation date
- Monday 18 December 2023
- What the ISO 9001 doesn’t cover
- Nothing. Everything is covered.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 3646e13c-d7dc-42b3-a7ed-07a5814cc080
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 80f895cd-7070-464a-98f1-307a7c616c2f
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-