Skip to main content

Help us improve the Digital Marketplace - send your feedback

JUICY MEDIA LIMITED

Applications - Concrete CMS

Open Source CMS Services design, build and support secure, accessible websites that are WCAG AA compliant as a minimal. We deliver content models, templates, workflows, integrations, hosting, and performance optimisation. Includes migration, training, documentation, and ongoing support for updates, security patching, enhancements, and incident response.

Features

  • Open source CMS implementation: with supported secure configuration.
  • Role-based editorial workflows with approvals, permissions, and audit logging.
  • Responsive, accessible themes and components aligned to WCAG requirements.
  • Content modelling with custom fields, templates, and reusable page blocks.
  • Secure remote admin access MFA, SSO options, and IP controls.
  • Performance optimisation using caching, CDN integration, and image optimisation.
  • SEO tooling: redirects, metadata rules, sitemaps, and structured data.
  • Integrations with forms, CRM, search, payments, and marketing platforms.
  • Automated updates, vulnerability monitoring, and scheduled security patching.
  • Analytics and reporting via dashboards, GA4/GTM, and event tracking.

Benefits

  • Publish and update content from multiple devices using browser-based editing.
  • Approve changes quickly with workflows, roles, and automated notifications.
  • Reuse page blocks to create new pages faster and consistently.
  • Schedule content updates in advance, reducing last-minute publishing pressure.
  • Find and manage content quickly with search, filters, and taxonomy.
  • Reduce errors with previews, validation, and version history rollback.
  • Improve accessibility with reusable compliant components and content guidance.
  • Track engagement instantly using dashboards and analytics event reporting.
  • Migrate content safely, preserving URLs, redirects, and SEO performance.
  • Maintain site security automatically with updates, monitoring, and alerts.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at adam.smethurst@juicymedia.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 4 7 1 2 0 5 7 0 2 5 5 4 5 8

Contact

JUICY MEDIA LIMITED Adam Smethurst
Telephone: 0161 464 9252
Email: adam.smethurst@juicymedia.co.uk

About your service

Service categories

Applications

Content workflow and management

  • Capture
  • Document
  • Media Services
  • Creative

Content services

  • Enterprise Content Management Applications
  • Content Sharing and Collaboration Applications

Persuasive content management

  • Website Software
  • Digital Asset Management Applications
  • Product Content Management Applications
  • Content Marketing Applications

Enterprise portals and digital workspaces

  • Multi-Audience Portals
  • Integrated Employee Workspaces
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Extends common hosting and cloud services (AWS, Azure, OVH), identity and access management (Microsoft Entra ID/SSO), analytics and tag management (GA4, GTM), search (OpenSearch/Elastic), email/newsletter platforms, CRM (Dynamics/HubSpot/Salesforce), forms/case management systems, payment gateways (Stripe/PayPal), CDN/WAF/security services (Cloudflare), and CI/CD tooling (GitHub/GitLab).
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
Planned maintenance windows are required for core CMS, plugin/module and infrastructure updates (typically out of hours). Support is limited to supported CMS versions and reputable plugins/modules; end-of-life components must be upgraded before we can provide full assurance. Some features (SSO, WAF/CDN, advanced search, newsletter integrations) depend on buyer licences and third-party availability. Performance outcomes depend on hosting capacity, content/media volumes, and traffic patterns. Migrations require access to source systems and data quality may affect timelines. Security controls such as IP allow-listing and MFA require compatible identity/network setup.
System requirements
  • Supported CMS versions, with maintained plugins/modules and dependencies.
  • Linux hosting with PHP, web server, and HTTPS/TLS enabled.
  • Managed database service: MySQL/MariaDB or PostgreSQL
  • Buyer-provided domain DNS access for records and SSL validation.
  • Secure admin access: VPN or IP allow-listing where required.
  • MFA/SSO requires compatible identity provider, e.g., Microsoft Entra ID.
  • Backup and monitoring enabled: snapshots, logs, uptime and alerts.
  • Outbound email service: SMTP provider or transactional email platform.
  • CDN/WAF optional: Cloudflare or equivalent security edge services.
  • Analytics licences: GA4/GTM access and consent management where needed.

User support

Email or online ticketing support
Yes
Support response times
We acknowledge support questions within 4 working hours (Monday–Friday, UK business hours). For live service-impacting incidents, we acknowledge within 1 hour and begin triage immediately. Weekend and bank holiday cover is available for P1/P2 incidents where an out-of-hours support option is in place; otherwise requests received weekends are handled from the next working day. We provide regular updates during incidents, including actions taken, workarounds, and expected next steps, and we can agree bespoke SLAs for critical services.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We’ve tested it with assistive technology users through moderated remote sessions and structured accessibility QA.

Testing has included: keyboard-only navigation (tab order, focus visibility, escape/close behaviour), screen readers (NVDA and JAWS on Windows; VoiceOver on macOS and iOS; TalkBack on Android), screen magnification/high zoom, high-contrast modes, and speech input (for example Dragon). Typical tasks include opening chat, reading history, sending/receiving messages, handling attachments (if enabled), managing notifications, and returning to the page without losing context.

Findings are logged, prioritised, and retested after fixes. Common improvements we implement include correct labelling of fields/buttons, predictable focus management when chat opens/closes, accessible error messages, and ensuring new messages are announced via appropriate live-region behaviour without excessive repetition.
Onsite support
Yes
Support levels
We offer three support levels (priced as monthly retainers, with additional work charged at agreed G-Cloud day rates).

1) Essential Support (Standard) – £295/month Email/ticket support, business hours (Mon–Fri, 09:00–17:30 UK) Monthly security/core/plugin update window (staging-first) Target response: 1 business day (P2–P4), 4 business hours (P1)
2) Business Support (Enhanced) – £695/month Email/ticket + scheduled support calls Proactive monitoring (uptime, errors), performance checks, priority patching Target response: 4 business hours (P2–P4), 1 business hour (P1) Includes 4 hours development/support time per month (then £695/day pro-rata)
3) Mission-Critical Support (Premium SLA) – from £1,495/month 24/7 incident triage for critical issues (checkout/payment outages, security) On-call rota, hotfix releases, enhanced monitoring and alerting Target response: 15–30 minutes for P1, hourly updates until mitigated Includes 8 hours per month (then £695/day pro-rata) Cost notes Additional hours: £695/day (or £95/hour by agreement) Launch/campaign weekend cover: priced as a short-term add-on (e.g., £350/weekend standby + time used) Technical account manager / cloud support engineer Essential: assigned support lead (named primary contact) Business: named senior engineer + quarterly service review Premium: Technical Account Manager included (or can be added to other tiers), plus access to a Cloud/DevOps support engineer for hosting, WAF/CDN, backups, and resilience.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
We help users get started through a structured onboarding and handover approach:

Kick-off and discovery: confirm goals, users, content types, workflows, integrations, and accessibility needs.

Environment setup: configure CMS, roles/permissions, security (MFA/SSO options), and initial templates/blocks.

Content onboarding: migrate or create initial content, set up redirects, and validate information architecture.

Training: role-based editor and admin training delivered online as standard (recorded where appropriate). Onsite training can be provided if required.

Documentation: concise user guides, “how to” articles, and runbooks covering publishing, workflows, accessibility, and common tasks.

Support during adoption: floor-walking/office hours in early weeks, plus a service desk for questions and issue resolution.

Go-live support: launch checklist, content freeze plan, monitoring setup, and post-launch review to capture improvements.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
  • Other
Other documentation formats
Git
End-of-contract data extraction
At contract end, users can extract all service data in open, reusable formats.

For content, we provide full exports using platform-native tools (for example WordPress WXR/XML export and/or API export; Drupal database/content exports via JSON:API/REST or database dump). For media, we provide a complete copy of the uploads/files directory as an archive. For configuration and code (where supplier-managed), we provide the agreed theme/module/plugin code, deployment scripts, and environment configuration documentation (secrets excluded or handed over securely).

For hosting data, we provide database dumps (MySQL/MariaDB/PostgreSQL), backups/snapshots, and relevant logs/analytics exports where contractually permitted. Data is transferred via an agreed secure method (encrypted download link, SFTP, or buyer-provided storage bucket).

We support knowledge transfer with a handover pack and optional assisted migration to a new supplier/hosting. Following confirmation of successful extraction, we securely delete remaining copies in line with the agreed retention schedule and provide deletion confirmation if required.
End-of-contract process
At contract end we follow an agreed offboarding plan, typically covering:

Notice and exit planning: confirm end date, responsibilities, and timelines.

Final service review: outstanding issues, change freeze (if needed), and risk checks.

Data extraction and handover: export content, media, and databases; provide code/configuration pack (where supplier-managed) and admin runbooks.

Transition support: knowledge transfer sessions with the buyer/new supplier.

Decommissioning: disable access, revoke keys, and securely delete remaining data per retention policy, providing confirmation if required.

Included in contract price: standard offboarding management, one full data export, handover pack, and up to an agreed amount of remote knowledge transfer (aligned to the support level/retainer).

Additional cost: complex migrations to a new platform, extended parallel running, bespoke export formats or additional extracts, on-site handover days, large data reprocessing/clean-up, and any third-party licence/hosting fees that sit with the buyer.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is browser-based and responsive on both desktop and mobile. Desktop provides the full editorial experience (bulk editing, complex page building, media management, user administration, and configuration). Mobile supports core tasks such as viewing content, making small edits, approving workflow items, moderating comments (if enabled), and publishing urgent updates. Some advanced admin functions may be simplified on smaller screens to maintain usability and reduce error risk (for example drag-and-drop layout editing and large media uploads). Accessibility and security controls (MFA/SSO) are consistent across devices.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service interface is a secure web-based CMS admin dashboard and optional user-facing components (for example forms, dashboards, or member areas). Editors manage pages, media, and structured content using templates and reusable blocks, with role-based permissions, workflow approvals, and audit logs. Administrators access configuration, users, integrations, and reporting. The interface supports responsive layouts, keyboard navigation, and assistive technologies, with MFA/SSO options and IP restrictions where required.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Where the CMS admin interface and bespoke front-end components are in scope, we test with assistive technology users via moderated remote sessions and structured accessibility QA.

Testing typically covers keyboard-only use (tab order, focus states, skip links, modal behaviour), screen readers (NVDA/JAWS on Windows; VoiceOver on macOS/iOS; TalkBack on Android), screen magnification and reflow at 200–400% zoom, high-contrast/forced-colours modes, and speech input (for example Dragon). We validate common user journeys such as logging in with MFA/SSO, creating/editing content using blocks/templates, uploading media, completing and reviewing forms, running approvals, searching/filtering content, and downloading files.

Issues are logged with reproducible steps, WCAG mapping, and severity, then fixed and retested with the same tools. Typical improvements include clearer labels and instructions, predictable focus management (especially in dialogs and block editors), accessible error messaging, and ensuring status updates are announced without disrupting user workflow.
API
Yes
What users can and can't do using the API
Users can use the CMS API's to read and write content (pages, posts, structured content types), manage media (upload and reference assets), and query taxonomies (categories/tags) to support headless builds, integrations, and migrations. With appropriate permissions, they can also trigger workflow-related changes (for example create drafts, update status, submit for approval) and pull operational data such as content lists and metadata for reporting.

Service setup through the API can include bootstrapping content, importing structured data, creating taxonomies, and seeding configuration that is exposed via approved endpoints. Day-to-day changes include creating/editing content, updating metadata, and publishing (subject to roles/workflows).

Limitations: we restrict or disable endpoints that would weaken security (for example user admin, plugin/module management, file execution, or unrestricted settings changes). Administrative setup (hosting, database, WAF/CDN, IAM/SSO, encryption, backups) is performed via infrastructure tooling rather than the CMS API. API access requires authenticated tokens, least-privilege roles, HTTPS, and rate limiting; some actions may be blocked in production to protect service integrity.
API documentation
Yes
API documentation formats
  • HTML
  • ODF
  • PDF
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Content and structure: content types, taxonomies, custom fields, page templates, reusable blocks/components, navigation and menus.

Look and feel: themes, design system components, layouts, branding, accessibility patterns.

Workflows and governance: approvals, editorial roles, permissions, audit logging, content states, notifications.

Integrations: forms, CRM, email/newsletters, search, payments, analytics/tagging, SSO/MFA.

Operational settings: caching/CDN rules, media optimisation, redirects/SEO rules, monitoring and reporting.

How users customise: primarily through the CMS admin interface (block/page editing, media library, menus, workflow actions). Administrators can configure settings and roles. More advanced changes (theme development, custom modules/plugins, integration work, infrastructure and security controls) are delivered via controlled code changes (Git), CI/CD, and agreed change management.

Who can customise:

Editors/Authors: content, media, page composition using approved blocks.

Approvers/Publishers: workflow decisions and publishing.

Admins: users, roles, configurations within agreed guardrails.

Supplier developers/DevOps: code, integrations, and hosting/security configuration.

Scaling

Independence of resources
We avoid “noisy neighbour” impacts by defaulting to buyer-dedicated (single-tenant) environments: separate hosting accounts/projects, VPC/network segmentation, databases, storage, caches, and monitoring/alerting per buyer. Capacity is sized per service with auto-scaling (where supported), resource limits, and rate limiting/WAF rules to prevent abuse.

Where any shared components are used (for example shared CI runners or managed monitoring), we apply quotas, workload isolation, and priority incident handling so one buyer’s demand cannot consume another’s critical resources. Continuous performance monitoring and capacity management trigger scaling or optimisation before users are affected.

Analytics

Service usage metrics
Yes
Metrics types
We provide metrics covering availability and uptime, performance (TTFB, page load times, Core Web Vitals), traffic and engagement (users, sessions, key events via GA4/GTM), content operations (publishing volumes, approvals, time-to-publish), reliability (error rates, 4xx/5xx trends), security (WAF blocks, authentication events, vulnerability/patch status), and infrastructure health (CPU, memory, storage, database utilisation). Metrics are delivered via dashboards and agreed periodic reports, with alerting for thresholds on critical services.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Degaussing

Data importing and exporting

Data export approach
Users can export data using CMS-native tools and/or APIs. For example WordPress, exports include WXR/XML for content and database/media extracts for complete portability. For example Drupal, exports can use JSON:API/REST for structured content and database/file archives for full transfer. Administrators can run exports directly, or we can provide assisted exports as part of support. Media is exported as a complete file archive, and databases are provided as standard SQL dumps. Where integrations exist (analytics, CRM, email), we support exporting via those platforms’ own export tools and APIs.
Data export formats
  • CSV
  • Other
Other data export formats
  • XML
  • JSON
  • SQL Dumps
Data import formats
  • CSV
  • Other
Other data import formats
  • XML
  • JSON
  • SQL Dump

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection between networks
L2TP
Radius
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection within supplier network
Wireguard
L2TP
Radius

Availability and resilience

Guaranteed availability
For production services hosted and managed by us, we guarantee monthly availability of:

99.5% (Standard)

99.9% (Enhanced/Critical)

Availability is measured per calendar month against the public service endpoint using automated monitoring (5-minute checks). Excluded: pre-agreed planned maintenance windows, buyer-caused issues (for example DNS changes or credential lockouts), third-party outages outside our control (for example upstream IAM/analytics providers), and force majeure.

Refunds/service credits: if we miss the guaranteed availability, we apply service credits to the next invoice, calculated against the monthly hosting/managed service charge (excluding third-party pass-through costs):

< SLA to 0.5% below: 5% credit

0.5%–1.0% below: 10% credit

>1.0% below: 20% credit

For critical services, we can agree higher SLAs and bespoke credits in the call-off contract.
Approach to resilience
Our Open Source CMS service is designed for resilience through layered architecture and operational controls. We deploy in resilient cloud datacentres with redundant power, cooling, and network connectivity (provider assurance details available on request). At platform level we use multi-AZ designs where appropriate: load-balanced web tier, separate managed database, and resilient object/file storage.

We implement automated, encrypted backups (database and media) with defined retention, and regularly test restores. Monitoring and alerting covers uptime, error rates, capacity, and security events, enabling rapid detection and response. We use infrastructure-as-code and version-controlled deployments to support repeatable recovery, plus staging environments for safe changes. Performance resilience is improved through caching, CDN integration, and rate limiting/WAF rules to protect against spikes and abuse. For higher criticality, we can add cross-region backups and disaster recovery runbooks with RTO/RPO targets agreed in the call-off contract.
Outage reporting
We report outages through multiple channels, depending on the support level and buyer preference:

Email alerts: automated notifications for incidents (P1/P2), degradation, and recovery confirmations to agreed distribution lists.

Service desk updates: ticket updates with timestamps, impact, actions taken, workaround, and next steps.

Real-time dashboard: a live monitoring dashboard (shared access or read-only link) showing availability, performance, and active incidents.

API (optional): where buyers need machine-readable status, we can expose incident/status data via a simple JSON endpoint or integrate with their tooling (for example Teams/Slack/webhooks).

Post-incident report: for major incidents we provide an incident report and lessons learned, including root cause, timeline, and preventive actions.

We also provide advance notices for planned maintenance, including expected impact and rollback plans.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Other user authentication
IP allow-listing and role-based access controls
Access restrictions in management interfaces and support channels
We restrict access using least-privilege roles and separate admin/editor accounts. CMS admin areas are protected with MFA and optional SSO, strong password policies, session timeouts, and account lockout controls. Administrative endpoints can be limited by IP allow-lists/VPN and protected with WAF rules. Support channels use authenticated service desk accounts with role-based permissions; sensitive actions require verified requestors and change approval. Access is reviewed periodically, removed promptly on leavers, and logged for audit. Privileged operations are performed via controlled CI/CD and infrastructure tooling, not shared credentials.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Description of management access authentication
IP allow-listing/bastion access, just-in-time privileged access, audited admin actions

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users receive audit information on a regular basis
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We follow a documented information security management approach aligned to ISO 27001 principles and UK GDPR. Our policies cover: access control and MFA, least-privilege permissions, secure configuration baselines, encryption, logging and protective monitoring, secure development (code review, dependency management), change and release management, vulnerability and patch management, incident response, backup and disaster recovery, supplier assurance, and data retention/disposal.

Reporting structure: overall accountability sits with senior leadership (Technical Director/InfoSec Lead). Day-to-day controls are operated by nominated service owners and DevOps, with clear escalation routes to the InfoSec Lead for incidents and risk decisions.

How we ensure policies are followed: mandatory onboarding and annual security training; documented SOPs/runbooks; peer review and approval gates for changes; periodic access reviews; vulnerability scanning and remediation tracking; audit trails in ticketing/version control; regular backup/restore tests; and scheduled management reviews of risks, incidents, and improvements.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We operate documented configuration and change management controls aligned to ISO 27001 operational security practices and ITIL-style change processes.

We track service components across their lifecycle using an asset register, CMDB-style records, and version control (Git), infrastructure-as-code, and configuration. Changes are raised via tickets, scoped, risk-rated, and approved before implementation. Security impact is assessed by checking data exposure, access control, dependency risk (CVE review), and alignment to secure baselines. Changes are tested in non-production, deployed via CI/CD with peer review, and include rollback plans. We maintain audit trails (tickets, commits, approvals) and post-change validation, updating documentation and asset-records after release.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We assess threats through continuous monitoring of CMS core and dependency vulnerabilities, attack surface reviews, and log/WAF alerting. Vulnerabilities are triaged by severity, exploitability, and exposure (internet-facing, privileged paths, data sensitivity), then prioritised in a tracked remediation backlog. Patch deployment targets: critical within 24–72 hours, high within 5–10 working days, medium/low in scheduled maintenance windows. We use staged testing, backups, and rollback plans before production release. Intelligence sources include vendor advisories (e.g.. WordPress/Drupal), NCSC guidance, CVE/NVD feeds, hosting provider notices, and security tooling alerts.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use documented protective monitoring controls aligned to NCSC guidance and ISO 27001 practices.
We identify potential compromise through centralised logging (CMS, OS, WAF/CDN), alerting on suspicious authentication, privilege changes, file integrity, abnormal traffic, and malware indicators, plus vulnerability and uptime monitoring. Alerts create incidents in the service desk and trigger triage to confirm scope, preserve evidence, and contain (block IPs, disable-accounts, isolate hosts, rotate keys). We eradicate by patching, removing malicious code, restoring from clean backups, and validating integrity before reopening. Response targets: P1 acknowledged within 1 hour (or 30 minutes with 24/7 cover) and containment actions started immediately.
Incident management type
Supplier-defined controls
Incident management approach
We operate a documented incident process with playbooks for common events (availability outage, suspected compromise, credential loss, malware, data leak, DDoS). Users report incidents via service desk email/portal and (for critical cover) an on-call phone/escalation route. Incidents are logged, prioritised (P1–P4), triaged, contained, resolved, and reviewed, with regular status updates. For significant incidents we provide an incident report including timeline, impact, root cause, actions taken, evidence summary, customer actions required, and preventative improvements. Post-incident reviews are tracked to closure through change management.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
We offer a free, time-limited demo environment for WordPress, Drupal or Umbraco. It includes limited admin access to explore user roles, page editing, navigation management, and typical publishing workflows. It does not include bespoke design/build, integrations, migrations, hosting setup, security hardening. Demo content is illustrative only.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
6%
Between £500,001 and £1,000,000
7%
Between £1,000,001 and £2,500,000
8%
Between £2,500,001 and £5,000,000
9%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Alcumus ISOQAR
ISO/IEC 27001 accreditation date
Friday 24 November 2023
What the ISO/IEC 27001 doesn’t cover
The utilisation of subcontractors and external development
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Alcumus ISOQAR
ISO 9001 accreditation date
Friday 24 November 2023
What the ISO 9001 doesn’t cover
The utilisation of subcontractors and external development
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Bf061249-c353-4996-85f2-7ce28422febe
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
A902c814-0ada-44b9-8010-4e221fcdb65f
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
    • Plans for positive actions with community groups.
    • Measures for making facilities used in the delivery of the contract available for community groups, education or training
    • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
    • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at adam.smethurst@juicymedia.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.