Pega Cloud including Pega Government Platform and Pega Customer Services
Pega is a low-code platform for AI-powered decisioning and workflow automation. We enable organisations to get work done using apps that are secure, scalable, governed, and maintainable. We offer solutions for business process management, digital process automation, and customer/citizen engagement. Pega Government Platform (PGP) is tailored to meeting governments’ needs.
Features
- Dynamic case management platform with AI-driven process automation engine.
- Omnichannel citizen engagement CRM with intelligent communication orchestration capabilities.
- Model-driven low-code application platform for rapid government service delivery.
- Enterprise API integration gateway with AI-powered connectivity and interoperability.
- AI-Driven application configuration for enhanced citizen service delivery modernisation.
- Intelligent workflow automation platform with AI-powered workforce optimisation capabilities.
- Robotic process automation enabling end-to-end task orchestration and efficiency.
- Real-time AI decisioning engine delivering contextual recommendations and insights.
- Pega’s single-tenant hosting, but flexibility for cloud choice.
- Software that writes your software. Patented ‘Build for Change’ technology.
Benefits
- Rapidly modernise legacy government systems using intelligent low-code automation.
- Maximised intelligent automation across fragmented systems using Pega’s Process Fabric™
- Optimised end-to-end customer journeys experienced through AI and robotics.
- Build applications 12X faster with low-code, accelerate digital service delivery.
- Monitor performance KPIs and manage SLAs through real-time intelligent dashboards.
- Deploy scalable applications conforming to GDS Design Principles and standards.
- Easily integrates into legacy estates, orchestrating and exploiting existing investments.
- Ability to deliver higher quality, lower cost, more reliable solutions.
- Lower total ownership costs using proven low-code intelligent automation platform.
- Proven, referenceable technology, successfully used by major government departments.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 7 1 4 8 0 2 4 4 7 6 2 0 4 2
Contact
PEGASYSTEMS LIMITED
Simon Haydn-Lee
Telephone: +44 (0) 7929 364629
Email: rfpteam@pega.com
About your service
- Service categories
-
Applications
Content workflow and management
- Capture
- Document
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Pega Live Data provides a data virtualization layer so you can quickly and easily define the data models required to build your applications and how they’re connected to any back-end systems. You can then access that data on-demand in your live application without re-configuring where the data is stored.
- Cloud deployment model
- Public cloud
- Service constraints
-
Pega Cloud G-Cloud Customers can be deployed in the Amazon EU-Ireland / UK Region. Within this geographic zone, Pega Cloud environments are deployed into multiple availability zones. Environments also then have the following further resiliency services applied:
• Backups of all environments on an ongoing basis.
• Synchronous multi-availability zone database replication and load balancing delivering an RPO of approximately 1 minute and RTO of approximately 4 minutes.
Production environments are provided with a 99.95% availability SLA. For each customer Pega provides purpose-built infrastructure dedicated to that customer within a dedicated virtual private cloud. - System requirements
-
- Modern HTML5 browsers supported; disable unsupported legacy Internet Explorer versions.
- Outbound TLS 1.2+ internet access to Pega Cloud endpoints allowed.
- Allowlist Pega IP ranges or establish site‑to‑site VPN for connectivity.
- Identity provider supporting SAML 2.0 or OpenID Connect SSO integration.
- Email SMTP relay configured for outbound notifications and password resets.
- Secure firewall rules permitting required ports, protocols, corporate egress traffic.
- Chosen cloud region meeting buyer’s data residency and compliance requirements.
- Access management: named administrators and role‑based permissions governance processes established.
- Integration endpoints reachable: REST APIs, SFTP, Kafka if required externally.
- Application configuration and data management responsibilities agreed during service engagement.
User support
- Email or online ticketing support
- Yes
- Support response times
- User support is provided via email and ticketing through the Pega support portal. Response times are aligned to incident severity levels, with initial responses typically provided within defined targets ranging from one hour for critical incidents to next business day for low‑priority queries. Support is available 24x7, including weekends and public holidays, for critical and high‑severity incidents. For lower‑severity requests, responses during weekends may be limited, with full service resuming during standard business hours.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Support levels and costs:
Pega Cloud Subscriptions include Pega Premium Support as standard. Premium Support provides 24x7 access to Pega’s global support service for incident management, service requests, and operational assistance. Support is delivered via the Pega support portal and includes defined response targets aligned to incident severity.
Premium Support is included within the Pega Cloud subscription cost.
Support services provided:
Premium Support includes proactive monitoring of Pega Cloud environments, incident notification and resolution support, access to system health and environment status information, and operational guidance to support availability, performance, and reliability. Pega provides structured escalation, root‑cause analysis for major incidents, and regular service communications.
Technical account management:
Pega provides access to cloud support engineers as part of Premium Support. Where required, a Technical Account Manager (TAM) or named service contact can also be provided as an optional service, offering proactive service reviews, coordination, and strategic technical guidance. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We provide a comprehensive onboarding experience to help users start using our service quickly and effectively. Pega offers multiple options tailored to different learning styles and organizational needs:
• Online Training: Access to Pega Academy, a robust e-learning platform with self-paced courses, interactive exercises, and certifications for business users, developers, and administrators.
• Instructor-Led Training: Virtual and onsite sessions delivered by certified trainers, covering fundamentals, advanced configuration, and best practices.
• Blueprint Workshops: Collaborative design sessions using Pega Blueprint to capture objectives, map workflows, and accelerate solution design.
• User Documentation: Extensive online help, implementation guides, and knowledge articles available within the platform and via Pega Community.
• Onboarding Support: Guided setup, configuration assistance, and orientation sessions to familiarize users with key features and tools.
• In-Application Guidance: Contextual help, tooltips, and walkthroughs embedded in the platform to support real-time learning.
These resources ensure users can quickly configure applications, customize workflows, and leverage Pega’s low-code capabilities. Our approach combines structured learning, hands-on practice, and expert support to reduce time-to-value and empower organizations to achieve rapid adoption and success. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Clients have two options, the first of which is to extract the data from Pega’s working database. Pega’s cloud offering utilises a standard relational database making this a relatively simply task.
The second approach is to never hold such data in Pega in the first place. Where a client requires this approach Pega will support the use of data separation techniques to allow the client to maintain their data in a data store of their choice. - End-of-contract process
- Pega Cloud will support the customer in removing their applications and data. This process will be completed within 14 days of contract termination.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Our solutions automatically render to fit to the size of screen of the device that they are being used on. They are built requiring no additional modifications. Our apps are 8 x quicker to deploy on mobile than Java Enterprise built applications.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service interface is accessed via a secure, web‑based portal provided as part of the Pega Cloud service. Users work with the service through intuitive role‑based dashboards, forms, and case views, accessible using standard web browsers without the need for local installation. The interface supports task management, case tracking, reporting, and collaboration, with access controlled through configurable user roles and permissions. Administrators use the same interface to manage users, monitor environments, and configure service settings. The interface is designed using inclusive design principles to ensure it is usable and effective for a wide range of user needs and working styles.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Extensive work has been performed with the Watson Institute in the USA to ensure the user interface can comply with the needs of the disabled.
Pega is committed to creating an accessible and inclusive experience for users of its platform and related applications. We continually strive towards improving our experience and adhering to the international standards created by the World Wide Web Consortium (W3C).
To help drive us towards an inclusive solution, we utilize the following measures:
• Leverage a third party to audit our applications and components, and conduct both automated and manual assessments.
• Provide an up-to-date Voluntary Product Application Template (VPAT) of our current state of conformance.
• Test our applications with assistive technology such as JAWS, ZoomText and Dragon Naturally Speaking.
Pega currently uses the WCAG 2.2 AA standards to evaluate our platform and out-of-the-box applications. These standards are being used to comply with requirements of Section 508, EN 301 549 and BITV. - API
- Yes
- What users can and can't do using the API
- The Pega API allows users to trigger the execution of Pega rules from 3rd party applications and systems. Every capability of the Pega application platform is contained within rules and so clients have access to any capability that they have configured within their rule sets. In addition to an API, Pega rules can also be exposed as web services if a client finds that more convenient. In either case business login and functions contained within rules of all different types can be called from external 3rd party applications.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Pega solutions, built on the Pega Platform, provide extensive customization options to meet diverse business needs. What can be customised? Organizations can tailor case types, workflows, data models, user interfaces, decision logic, and integrations with external systems. Advanced features such as AI-driven decisioning and robotic automation can also be configured to align with business objectives.
How users can customise? Pega offers intuitive low-code tools and the innovative Pega Blueprint, which enables collaborative design through a shared visual model. Blueprint captures objectives, maps processes, and automatically generates documentation, ensuring transparency and accelerating delivery. Users can configure applications using guided templates, drag-and-drop components, and real-time previews without writing complex code. Integration with APIs and reusable components further simplifies customization.
Who can customise? Both business users and IT teams can participate in shaping solutions. Business stakeholders can define requirements and adjust workflows, while technical teams manage governance and advanced configurations. This collaborative approach reduces development cycles, improves accuracy, and enhances engagement across the enterprise.
By combining Blueprint, low-code configuration, and automated documentation, Pega empowers organizations to rapidly deliver tailored applications while maintaining flexibility, scalability, and compliance.
Scaling
- Independence of resources
- In order to guarantee users aren't affected by demands of other users, Pega Cloud is a single tenant environment.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Pega provides out‑of‑the‑box dashboards and configurable reports via Report Creator, with real‑time views and scheduled distribution (PDF/Excel). Service metrics typically cover case and process performance (throughput, backlog, cycle times), SLA compliance (response and resolution targets), incident and exception volumes, and workload distribution. Usage‑related metrics include user and role activity, login frequency, assignments handled, and case actions performed, supporting operational oversight. Reports can be filtered by application, environment, role, and time window, enabling continuous service monitoring, governance, and performance management.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Pega Cloud provides multiple methods for data export, ensuring clients retain control and ownership of their data. Users can export operational data using Business Intelligence Exchange (BIX) in industry‑standard formats, with options for high‑volume extraction via Change Data Capture (CDC) or automated batch and real‑time workflows. Real‑time data streaming is supported using Kafka Data Sets, enabling integration with external or managed Kafka services. For ad‑hoc needs, users can export data to Excel via Insights and export case data and attachments using supported platform methods. This flexible approach supports operational, analytical, and integration use cases.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- DOC
- Excel
- XML
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- XML
- Excel
- Other delimited text formats such as Tab separated values
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Pega Cloud Production Subscriptions provide a guaranteed availability level of 99.95% measured on a monthly basis, as defined in the Pega Cloud Service Level Agreement. Availability is calculated for the production environment and excludes agreed maintenance windows in line with the service terms.
If the guaranteed availability level is not met in a given month, customers are eligible for service credits, providing a financial remedy for service disruption. Service credits are calculated as a percentage of the monthly subscription fee and are applied in accordance with the agreed thresholds and claims process set out in the Pega Cloud service terms.
These service levels and associated remedies form part of Pega’s contractual commitments for its cloud services and support operational resilience, transparency, and assurance for users operating business‑critical services on Pega Cloud. - Approach to resilience
- Available on request.
- Outage reporting
- The Pega Cloud Service Desk will communicate directly with any customers experiencing an outage via phone and E-Mail .
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- Authentication and authorisation of users is the responsibility of the customer. Pega supports multiple external identity providers as well as SSO.
- Access restrictions in management interfaces and support channels
- Pega operates on a 'best practice' basis operating in line with industry standard. Detail of this can be provided on request.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
- Authentication and authorisation of users is the responsibility of the customer. Pega supports multiple external identity providers as well as SSO.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
- Pega Cloud has a Written Information Security Program (WISP) reviewed annually. The Pega Cloud WISP meets the requirements of NIST Special Publication 800-53, Revision 4. Pega is ISO/IEC 27001:2013 (“ISO 27001”) certified for information security management supporting infrastructure and services. Pega also holds a current Cyber Essentials Certificate.
- Information security policies and processes
- Pega Cloud has a Written Information Security Program (WISP) reviewed annually. The Pega Cloud WISP meets the requirements of NIST Special Publication 800-53, Revision 4. Pega is ISO/IEC 27001:2013 (“ISO 27001”) certified for information security management supporting infrastructure and services. Pega also holds a current Cyber Essentials Certificate.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Pega uses a controlled configuration and change management process that tracks all service components throughout their lifecycle using asset inventories and configuration baselines. All changes follow formal change control procedures, including impact analysis, peer review, automated testing, and approval gates. Security impact is assessed using risk-based evaluation, aligned to Pega’s secure development lifecycle and vulnerability management practices. Changes are deployed through standardised pipelines, with segregation of duties and full audit logging. Only authorised personnel can implement changes, and all modifications are monitored, documented, and traceable end‑to‑end.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Pega Cloud follows a structured vulnerability management process as part of its operational security controls. Potential threats are assessed through continuous monitoring, automated scanning, and risk‑based evaluation aligned to the service environment and data classification. Security patches and updates are deployed in accordance with defined change and release management processes, with prioritisation based on severity and impact, and expedited handling for high‑risk vulnerabilities. Intelligence on emerging threats is obtained from trusted sources, including internal security teams, cloud service providers, vendor advisories, and industry‑recognised vulnerability and threat intelligence feeds.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Pega Cloud operates protective monitoring processes to identify, assess, and respond to potential security compromises. Monitoring uses automated alerts, logging, and event analysis to detect anomalous activity, suspicious behaviour, and indicators of compromise across the service. When a potential compromise is identified, incidents are triaged, investigated, and remediated through defined security incident response procedures, including containment, escalation, and customer notification where required. Response times are prioritised based on incident severity, with rapid response and investigation for high‑risk security events, ensuring timely mitigation and service protection.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Pega Cloud operates defined incident management processes covering common operational and security events. Pre‑defined procedures are in place to ensure consistent triage, prioritisation, escalation, and resolution based on severity and impact. Users report incidents through the Pega support portal using email or ticket submission, with 24x7 availability for critical issues. Incidents are tracked through to resolution, with status updates provided during investigation. Following resolution, incident reports are made available, including details of root cause, impact, and corrective actions as appropriate, supporting transparency, assurance, and continuous service improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- A free 30 day trial is available for Pega Platform and Customer Service. Pega Platform allows quick and easy building of applications via visual-driven rapid development with no coding using App Studio. With AI-guided interactions, Pega Customer Service can cut through service complexity for an improved overall customer experience.
- Link to free trial
- https://www.pega.com/products/try-now
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 6.5%
- Between £250,000 and £500,000
- 8%
- Between £500,001 and £1,000,000
- 9%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 11%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Schellman & Company LLC
- ISO/IEC 27001 accreditation date
- Tuesday 26 November 2024
- What the ISO/IEC 27001 doesn’t cover
- The scope of the ISO/IEC 27001:2022 certification is limited to the information security management system (ISMS) supporting Pega Cloud Services, and includes the organizations, systems, and people directly involved in developing, deploying, maintaining, and monitoring Pega Cloud Services, in accordance with the statement of applicability, version 7.1, dated August 20, 2024, and aligned with control implementation guidance and additional control sets of ISO/IEC 27017:2015 and ISO/IEC 27018:2019. Pega Cloud Services includes Pega Software available via Pega Cloud Subscription and Pega Launchpad Subscription offerings hosted in Pega Cloud and consumed by clients, excluding Co-Browse.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Tuesday 20 January 2026
- What the ISO 9001 doesn’t cover
- N/A - Pega's ISO certification covers all elements of Pega Cloud, including Cloud Engineering, Cloud Operations, Cloud Security and Global Client Support. It also includes back office functional departments that support service delivery, such as Sales, Legal (contracts), and People Management.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Tuesday 26 November 2024
- CSA STAR certification level
- Level 2: CSA STAR Attestation
- What the CSA STAR doesn’t cover
- The STAR certification is assessed along with and aligned to the scope of the ISO/IEC 27001:2022 certification for the information security management system (ISMS) supporting Pega Cloud Services, which includes the organizations, systems, and people directly involved in developing, deploying, maintaining, and monitoring Pega Cloud Services, in accordance with the statement of applicability, version 7.1, dated August 20, 2024, and aligned with control implementation guidance and additional control sets of ISO/IEC 27017:2015 and ISO/IEC 27018:2019. Pega Cloud Services includes Pega Software available via Pega Cloud Subscription offerings hosted in Pega Cloud and consumed by clients, excluding Co-Browse.
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Wolf and Company
- PCI DSS accreditation date
- Thursday 22 August 2024
- What the PCI DSS doesn’t cover
-
Scope: Pega Cloud AWS & GCP
Not Covered: Specific exclusions detailed in the Shared Responsibility Matrix - Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 3e454509-6217-4475-8128-5f00b81c1e41
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 84c2eb2a-990e-42b6-925e-7bd4feffdc9f
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 22301 (Business Continuity)
- ISO 27017 (Cloud Security)
- ISO 27018 (Cloud Privacy)
- SOC 1
- SOC 2 Type 2
- HITRUST
- FedRamp
- IRAP
- TISAX
- C5 Type 1 & 2 (Cloud Computing Compliance Criteria Catalogue)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-