Drupal 10 CMS Content Management System (Drupal 11 CMS and Drupal 12 CMS Supported)
Drupal SaaS for UK public sector. UK-hosted Drupal CMS with full data sovereignty and no US cloud dependency. Our Drupal platform delivers Drupal content management, Drupal multisite hosting, and LocalGovDrupal for councils. Managed Drupal hosting for government organisations. Open source Drupal alternative to proprietary CMS.
Features
- Drupal CMS hosted entirely on UK infrastructure
- Drupal security patching within hours of advisory release
- Drupal multisite management for multiple web properties
- LocalGovDrupal distribution for council websites
- Drupal API-first architecture for headless deployments
Benefits
- Full data sovereignty with UK-only Drupal hosting
- Focus on content while we manage Drupal infrastructure
- Freedom from proprietary CMS vendor lock-in
- Accessible Drupal websites meeting public sector requirements
- Predictable Drupal costs with no per-user licensing fees
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 1 8 7 5 7 6 7 9 0 9 2 8 1 2
Contact
ENCIRCLE SOLUTIONS LIMITED
Darren Woods
Telephone: 08449910109
Email: dwoods@encircle.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
- Capture
- Document
- Media Services
- Creative
- EDiscovery and forensics
Content services
- Enterprise Content Management Applications
- Content Sharing and Collaboration Applications
Persuasive content management
- Website Software
- Digital Asset Management Applications
- Product Content Management Applications
- Content Marketing Applications
- Video Platforms
- Digital Adoption Platform
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Integrated Employee Workspaces
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- None.
- System requirements
- PHP 8.x
User support
- Email or online ticketing support
- Yes
- Support response times
- We aim to respond to questions immediately but always within 4 hours.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 A
- Web chat accessibility testing
-
Custom font sizes, high contrast options, screen reader compliant.
Keyboard Accessibility:-
Move focus to the next element [tab]
Move focus to the previous element [shift] [tab]
Move focus from messages* [up arrow] or [down arrow]
Move focus to the next section** [F6]
Move focus to the previous section*** [shift] [F6]
Take action or "click" on buttons [space]
Take action or "click" on links [enter]
Close windows, menus or the message field [escape]
*Using a screen reader, you may need to toggle the virtual cursor.
**If using in a browser, use .
***If using in a browser, use .
Reading messages
Press [F6] to move to the message window.
Press [up arrow] or [down arrow] to navigate between individual messages.
Or use any of these keys:
• [page up] or [page down] to move up or down.
• [home] to go to the oldest message.
• [end] to go to the most recent message.
• [space bar] to scroll through messages.
Interact with messages
Press [F6] to move to the message window.
Press [up arrow] or [down arrow] to navigate between messages.
When focused on a message, press [tab] to scroll through items.
Press [enter] to select. - Onsite support
- Yes
- Support levels
-
We aim to respond to questions immediately but always within 4 hours.
Standard working hours: Monday-Friday 9:00 to 17:30.
- P1 Critical (Service unavailable, or >70% users affected and no workaround): Immediate response, 1hr fix.
- P2 Major (Service degraded >30% users affected, difficult or no workaround available) : 1hr response, 2hr fix.
- P3 Medium (Component or module malfunction, simple workaround available) : 2hr response, 2hr fix.
- P4 Minor (Service request, feature enhancement, how to): 4hr response, 8hr fix.
NOTE: Weekends, public holidays and out of hours support available at additional cost. Elapsed times based on working hours.
All support levels included in pricing.
Technical Account Manager and regular Service Level Reviews. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We provide comprehensive onboarding support tailored to each organisation's requirements.
Training:
Remote training sessions via video conference, scheduled to suit staff availability
Onsite training available for larger deployments or complex implementations
Role-based training tracks: end users, administrators, and power users receive appropriate depth
Train-the-trainer sessions enabling organisations to onboard future staff independently
Documentation:
Access to extensive CiviCRM community documentation (docs.civicrm.org)
Organisation-specific user guides reflecting custom configuration
Quick-reference materials for common tasks
Video walkthroughs for key workflows
Onboarding process:
Dedicated implementation contact throughout setup
Data migration support including mapping, cleansing, and validation
Parallel running period where appropriate
Staged go-live with priority support during transition
Post-launch check-in sessions to address early questions
Self-service resources:
Sandbox/training environment for staff to practice without affecting live data
Access to CiviCRM community forums and knowledge base
Training can be delivered as part of initial implementation or purchased separately for staff changes and refresher sessions. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
CiviCRM is open-source software with no proprietary data lock-in. All data remains fully accessible and extractable throughout and beyond the contract period.
Self-service extraction:
Built-in export tools for contacts, memberships, contributions, activities, and all other data entities
SearchKit enables custom data selections exported to CSV
Reporting tools generate exportable datasets
API access allows programmatic extraction in JSON format
Full database export:
Complete MySQL database dump provided on request
Standard, documented schema - no proprietary encoding
Compatible with any CiviCRM hosting environment (self-hosted, alternative provider, or on-premise)
Assisted migration:
We provide transition support including full data exports in agreed formats
Documentation of custom configuration, workflows, and extensions
Handover to incoming provider or internal team as required
Retention and deletion:
Data retained for agreed period post-contract to allow transition
Confirmed secure deletion and written certification on request
Compliant with GDPR data portability requirements
Buyers are never dependent on Encircle Solutions for ongoing access to their data - the open-source model guarantees full portability. - End-of-contract process
-
Included in the contract price:
Advance notice of contract end date and renewal options
Self-service data exports via CiviCRM's built-in tools (CSV, API access)
Standard database dump (MySQL format) on request
Continued service access during agreed notice period
Secure deletion of data and written confirmation upon request
Basic documentation of system configuration
Available at additional cost:
Extended transition period beyond standard notice
Assisted data migration to replacement provider or in-house systems
Data transformation into alternative formats (e.g., mapping to different CRM schema)
Handover meetings with incoming provider or internal IT team
Detailed technical documentation of custom development and integrations
Staff training for self-hosted operation
Parallel running of legacy and replacement systems
Process:
90 days before contract end: renewal discussion and transition planning
60 days: confirm exit requirements and any additional services needed
30 days: data exports completed, handover documentation provided
Contract end: service access terminated, hosting decommissioned
Post-contract: secure deletion completed, certification issued
No ongoing licence fees or penalties apply post-contract - open-source licensing ensures the buyer can continue using CiviCRM independently. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- None, both are responsive and provide the same functional scope.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- Web-based CRM interface accessible via standard browsers. Users manage constituent records, memberships, event registrations, donations, and communications through a responsive dashboard. Role-based access controls determine feature visibility. The interface includes search and reporting tools, bulk operations, and configurable workflows. Administrative users access system configuration, custom field management, and integration settings.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
-
CiviCRM is an open-source project with an active accessibility working group within the community. Accessibility improvements are contributed collaboratively, with community members conducting testing using screen readers (JAWS, NVDA, VoiceOver) and keyboard-only navigation. Core interface elements have been tested against WCAG guidelines through community sprints and issue tracking.
As a deployment partner, we implement CiviCRM using accessible themes and follow community accessibility guidelines for any customisations. We ensure custom fields and extensions maintain keyboard navigability and appropriate ARIA labelling. - API
- Yes
- What users can and can't do using the API
-
CiviCRM provides a comprehensive REST API (APIv4) enabling programmatic access to all core functionality.
Users can:
Create, read, update and delete contacts, organisations, and relationships
Manage memberships, subscriptions, and renewal workflows
Process contributions and payment records
Create and manage events, registrations, and participant data
Trigger and track bulk email campaigns
Generate reports and export data
Manage custom fields, option values, and system configuration
Integrate with external systems (websites, payment processors, marketing tools)
Limitations:
API access requires authentication via API key or OAuth credentials
Rate limiting may apply to prevent service degradation
Some administrative functions (system updates, extension installation) require direct admin access rather than API
Bulk operations on large datasets may require asynchronous processing
File uploads handled separately via dedicated endpoints
All API operations respect CiviCRM's permission system - users can only access data their role permits." - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
CiviCRM provides extensive no-code and low-code customisation tools enabling buyers to adapt the platform without developer involvement.
What can be customised:
Data model: custom fields, custom entities, and relationship types
User interface: dashboards, navigation menus, and screen layouts
Search and reporting: saved searches, custom reports, and data views
Forms: public-facing and internal data capture forms
Workflows: automated actions triggered by data changes or schedules
Communications: email templates, PDF layouts, and message workflows
How users customise:
SearchKit: drag-and-drop query builder for creating custom searches, listings, and tabular displays without SQL knowledge
FormBuilder: visual form designer for creating public and administrative forms with conditional logic, multi-step workflows, and field validation
CiviRules: business rules engine enabling automated workflows (e.g., "when membership expires, send reminder and create follow-up activity")
Profiles and custom data: administrative interface for extending the data model
Who can customise:
Administrative users with appropriate permissions can access all customisation tools. Role-based access controls allow organisations to delegate specific customisation capabilities (e.g., form creation) to departmental administrators while restricting system-wide configuration changes to senior administrators.
Scaling
- Independence of resources
-
Each customer receives a dedicated instance with isolated resources. Deployments are not shared-tenancy - each organisation has dedicated database, application container, and allocated compute resources.
This single-tenant architecture ensures one organisation's usage patterns (bulk mailings, large imports, reporting) cannot impact another's performance. All resources are deployed within a separate CSP Account.
Infrastructure is provisioned with headroom for peak demand. Resource utilisation is monitored, and capacity adjusted proactively when thresholds are approached.
Scheduled heavy operations (bulk emails, large data processing) can be queued for off-peak execution if required, though isolated resources typically make this unnecessary
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide metrics covering application usage and infrastructure performance:
Web Analytics via Google Analytics or Matomo
Application metrics: Active users, login frequency, records created/modified, email volumes sent, storage utilisation, and API call volumes.
Infrastructure metrics: Service availability/uptime percentage, response times, scheduled maintenance windows, and incident reports.
Security metrics: Failed login attempts, permission changes, and data export activity for audit purposes.
Metrics are available through CiviCRM's built-in reporting for application usage, with infrastructure and availability metrics provided through regular service reviews and on-request reporting. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Sers export data through multiple self-service methods:
Search and export: Any search result can be exported directly to CSV via the Actions menu.
SearchKit: Custom queries with selected fields exported to CSV or displayed for copy/paste.
Reports: Built-in and custom reports exportable to CSV and PDF.
API: RESTful API enables programmatic data extraction in JSON format for integration with other systems.
Database access: On request, full MySQL database dumps provided for complete data portability.
All exports available to users with appropriate permissions - no vendor involvement required for routine data extraction - Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- Xlsx
- Xls
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Service Level Agreement:
We guarantee 99.9% availability, measured monthly, excluding scheduled maintenance windows.
Measurement:
Availability calculated as: ((total minutes − unplanned downtime) ÷ total minutes) × 100. Monitored via external uptime monitoring with measurements logged for reporting and SLA verification.
Scheduled maintenance:
Planned maintenance conducted during low-usage periods (typically weekends, early morning) with minimum 5 business days' notice. Scheduled maintenance does not count against availability calculations.
Emergency maintenance:
Critical security patches may require shorter notice but customers are informed as early as possible.
Service credits:
If monthly availability falls below guaranteed levels, service credits apply:
99.0% – 99.9%: 10% credit on monthly fee
95.0% – 99.0%: 25% credit on monthly fee
Below 95.0%: 50% credit on monthly fee
Credits applied to subsequent invoice upon request. Customers must report claims within 30 days of affected period.
Exclusions:
SLA excludes downtime caused by factors outside our control: customer-requested changes, third-party service failures, force majeure, or customer network/browser issues. - Approach to resilience
-
UK datacentre infrastructure:
Services hosted in UK datacentres with ISO 27001 certification and physical security controls including 24/7 monitoring, biometric access, and CCTV. Datacentres feature redundant power (UPS and generator backup), redundant cooling, and multiple network connectivity providers.
Application resilience:
Services deployed with automated health monitoring and restart capabilities. Database servers configured with redundancy to prevent single points of failure. Load balancing distributes traffic and enables rolling updates without downtime.
Backup and recovery:
Daily automated backups with encryption at rest. Backups retained for 30 days minimum. Backups stored in geographically separate UK location from primary service. Regular restore testing validates backup integrity.
Disaster recovery:
Documented disaster recovery procedures with defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO). Ability to restore services to alternative UK infrastructure if primary datacentre unavailable.
Monitoring and response:
24/7 automated monitoring of service health, performance, and security events. Alerting triggers immediate response for critical issues. Incident response procedures documented and tested.
Detailed resilience architecture documentation available on request under NDA for security-sensitive procurement requirements. - Outage reporting
-
Email alerts:
Designated customer contacts receive email notifications for service-affecting incidents. Notifications sent at incident detection, during significant updates, and at resolution. Post-incident summaries provided for major outages including root cause and preventive measures.
Direct communication:
For critical incidents, primary contacts may be notified by phone in addition to email. Customers can designate multiple contacts to receive outage notifications.
Support channels:
Customers can check service status and report suspected issues via our support ticketing system. Support team confirms whether issues are localised or service-wide and provides updates through the ticket.
Incident communication includes:
Initial notification with affected services and estimated impact
Regular updates during ongoing incidents (minimum hourly for major outages)
Resolution notification with confirmation of service restoration
Post-incident report for significant outages (root cause, timeline, remediation steps)
Public status dashboard:
[Include if you have one, e.g., "Public status page at status.example.com displays current service health and historical uptime." Otherwise, remove this section or note: "Status dashboard available on request for enterprise deployments."]
Planned maintenance communicated separately via email with minimum 5 business days' notice.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
-
Management interface access:
Server and infrastructure access restricted to authorised personnel only. SSH access requires key-based authentication - no password access. Administrative interfaces protected by multi-factor authentication and IP allowlisting where appropriate. Access rights reviewed quarterly and revoked immediately on role change or departure.
Support channel verification:
Support requests accepted only from pre-authorised customer contacts. Identity verified before discussing account details or making changes. Sensitive changes (user permissions, data access) require written authorisation from designated customer administrator.
Audit logging:
All administrative access and configuration changes logged with timestamps and user identification for audit trail. - Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Certified frameworks:
We maintain ISO 27001 certification, providing a comprehensive Information Security Management System (ISMS) covering risk assessment, access control, incident management, business continuity, and supplier relationships. Annual surveillance audits ensure ongoing compliance.
Cyber Essentials Plus certification validates technical controls including boundary firewalls, secure configuration, access control, malware protection, and patch management.
Key policies include:
Information Security Policy (overarching governance)
Access Control Policy (least privilege, role-based access)
Data Protection and Privacy Policy (GDPR compliance)
Acceptable Use Policy
Incident Response Policy
Business Continuity and Disaster Recovery Policy
Supplier Security Policy
Reporting structure:
Information security responsibility sits with senior management. Security incidents escalate to designated Information Security lead with board-level reporting for significant issues. Annual management review assesses ISMS effectiveness.
Ensuring compliance:
Staff security awareness training on induction and annually
Regular internal audits against ISO 27001 controls
External certification audits
Automated vulnerability scanning
Access reviews conducted quarterly
Incident logging and lessons-learned reviews
Policy documentation available on request for procurement due diligence. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Configuration tracking:
Infrastructure defined as code using Terraform, with server configurations managed through Ansible. All configurations stored in Git version control with full change history. Deployed components, versions, and dependencies tracked and reproducible from code.
Change management:
Changes submitted as pull requests, reviewed before merging. GitHub CI runs automated tests and validation. Changes categorised by risk - significant changes require approval before deployment. Emergency changes logged retrospectively.
Security assessment:
Changes assessed for security impact during review. Dependency updates checked against vulnerability databases. Security patches prioritised by severity. Changes tested in staging before production.
Rollback procedures documented for all deployments. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Threat intelligence sources:
NCSC advisories for UK-relevant threats. CiviCRM and Drupal security announcements. CVE databases and vendor notifications for infrastructure components.
Vulnerability assessment:
Snyk monitors code dependencies for known vulnerabilities. OpenVAS scans infrastructure for security weaknesses. OWASP ZAP tests web application security. CrowdStrike provides endpoint detection and response across all client devices, identifying threats in real-time. Scans run regularly and before releases.
Patch deployment:
Critical security patches deployed within 24-48 hours. High-severity within one week. Medium/low severity in scheduled maintenance. Emergency procedures allow rapid response.
Vulnerabilities logged, tracked to resolution, and verified post-patching. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Identifying compromises:
CrowdStrike endpoint detection and response (EDR) monitors all systems for malicious activity, behavioural anomalies, and indicators of compromise in real-time. Centralised logging aggregates authentication events, access patterns, and system changes. Automated alerts trigger on suspicious activity including failed login attempts, unusual data access, and unexpected configuration changes.
Incident response:
Alerts investigated immediately during business hours; critical alerts escalate to on-call staff out-of-hours. Confirmed incidents trigger documented response procedures: contain, investigate, remediate, recover.
Response times:
Critical security incidents acknowledged within 1 hour, initial response within 4 hours. Affected customers notified promptly with updates throughout resolution. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Pre-defined processes:
Documented runbooks for common incidents including service outages, security events, data issues, and performance degradation. Incidents classified by severity with defined response times and escalation paths. ISO 27001 incident management procedures followed.
Reporting incidents:
Users report incidents via support ticketing system (email or portal). Emergency contact available for critical issues. All incidents logged, assigned, and tracked to resolution with customer visibility of progress.
Incident reports:
Customers receive updates throughout incident lifecycle. Post-incident reports provided for significant events, including timeline, root cause analysis, impact assessment, and preventive measures. Reports delivered within 5 business days of resolution. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Police National Network (PNN)
- Joint Academic Network (JANET)
- Scottish Wide Area Network (SWAN)
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Full, time limited access to a trial environment.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 7%
- Between £500,001 and £1,000,000
- 9%
- Between £1,000,001 and £2,500,000
- 11%
- Between £2,500,001 and £5,000,000
- 13%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- UKAS
- ISO/IEC 27001 accreditation date
- Thursday 27 February 2025
- What the ISO/IEC 27001 doesn’t cover
- 7.1 .. 7,4 are all excluded. Physical data centre controls, as we do not manage or operate these.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- IAS
- ISO 9001 accreditation date
- Thursday 27 February 2025
- What the ISO 9001 doesn’t cover
- 7.1.5 Excluded
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 0dc8c09a-498f-436f-8c05-caa292c42268
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 01010093-95fc-4cf3-bcfd-a1d8dc879087
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-