Konsolute ISO Compliance Accelerator: Automate and Simplify ISO Compliance for Microsoft 365
Our Microsoft 365 native solution automates ISO compliance and quality governance. This GDS-compliant system streamlines audits and self-assessment checklists for ISO 9001, 27001, and 45001. Leveraging your existing Microsoft 365, it ensures consistent standards and robust data sovereignty, replacing manual spreadsheets with automated, enterprise-grade quality management and real-time assurance
Features
- Automated compliance within existing Teams and SharePoint environments
- Rapid deployment of 9001, 27001, and 14001 frameworks
- Automated scheduling and execution of internal quality audits
- Secure management of policies, SOPs, and quality manuals
- Instant visibility into certification readiness and compliance gaps
- Systematic management of corrective and preventive actions
- Centralised, audit-ready storage for all compliance-related records
- Ensures documents remain valid with proactive expiry notifications
- High-accessibility design following government digital service standards
- Data stays within your secure UK-based Microsoft tenancy
Benefits
- Reach ISO standards faster with pre-built digital frameworks
- Lower costs by using existing Microsoft 365 licensing
- Maintain compliance throughout the year, not just pre-audit
- Replace fragile spreadsheets with robust, automated workflows
- Consistent standards across complex, multi-site public organisations
- Proactively identify failures before they impact service delivery
- Near real-time Power BI reporting for senior leadership assurance
- Familiar Microsoft tools require minimal staff training
- Inherits enterprise-grade protection from your Microsoft ecosystem
- Configurable architecture that adapts to changing international standards
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 7 6 4 8 0 7 6 9 4 9 7 8 4 8
Contact
KONSOLUTE LTD
Konsolute Government Procurement
Telephone: +44 20 8152 4102
Email: sales@konsolute.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Healthcare
- Education
- Public Order and Safety
- Police
- Defence
- Social Security Administration
- Adult Social Care
- Children's Social Care
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- N/A
- System requirements
-
- Microsoft 365 Tenant
- Modern web browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Our standard response times differ at weekends. Core support hours operate Monday to Friday from 08:30 to 18:00, during which priority incidents follow our defined SLA response targets. Weekend support is available; however, response times may be longer and follow an extended SLA window. Full weekend response times and escalation paths are detailed in our Service Definition.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AAA
- Web chat accessibility testing
- We use HaloITSM for our web-chat. HaloITSM provides full keyboard navigation, high-contrast modes, and has undergone assistive-technology user testing. The live-chat and self-service portal conform to WCAG 2.1 accessibility standards
- Onsite support
- Yes, at extra cost
- Support levels
- We provide tiered support tailored for public-sector requirements. Our service includes Level 1, Level 2, and Level 3 support. A named technical lead is assigned to oversee service quality and escalations. Support is available during core business hours, with extended and weekend response times operating under adjusted SLAs. Full response and resolution times are detailed in the Service Definition and are fully customisable
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- We provide a range of training and support options to help users adopt and use the service effectively. This includes online training sessions, recorded demonstrations, and comprehensive user documentation covering both end-user and administrative functions. Onsite training can be provided where required, subject to agreement and additional cost. All training materials are designed to support accessibility and are kept up to date as the service evolves.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Users can extract their data directly from their own Microsoft 365 tenancy, where the data resides. As the service uses customer-owned Microsoft 365 and Microsoft Entra ID environments, administrators retain full control of user data, attributes, and configuration. No customer data is held independently outside the customer’s tenancy. Any service-specific configuration can be exported in a standard, commonly used format, and data remains accessible to the customer throughout and after contract termination.
- End-of-contract process
-
The contract price includes access to the service, standard configuration, integration with Microsoft Teams and Microsoft 365, and ongoing service maintenance and updates. It also includes standard support during business hours and access to online training materials and user documentation.
Additional costs may apply for optional services such as onsite training, bespoke configuration or customisation, extended support hours, or other professional services requested by the customer. Any additional costs are agreed in advance and clearly defined before delivery. - Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- N/A
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AAA
- Description of service interface
- The service provides a web based user interface that integrates directly with Microsoft Teams and Microsoft 365. Users access the directory through familiar Microsoft interfaces, allowing them to search for people, view profiles, and communicate without leaving their existing tools. Administrators also have a dedicated interface for managing directory settings, categorisation, and access controls.
- Accessibility standards
- WCAG 2.2 AAA
- Accessibility testing
- Interface testing has been carried out to ensure the service is usable with common assistive technologies used across the public sector. The user interface is tested for compatibility with screen readers (including NVDA and JAWS), keyboard-only navigation, and browser zoom and reflow up to 400%. Testing also includes colour contrast checks and focus visibility to support users with visual impairments. Findings are reviewed and any accessibility issues identified are prioritised for remediation as part of ongoing service improvement and release cycle.
- API
- No
- Customisation available
- Yes
- Description of customisation
- Users can customise the service to meet organisational and operational requirements. Administrators can categorise and restrict external accounts, control cross-tenant visibility, and define access rules. The service allows organisations to add logos and customise colours to align with corporate branding. Administrators can choose which user attributes are synchronised from Microsoft Entra ID, which attributes end users are allowed to edit, and which attributes can be searched or queried by users. End users can also customise their directory views and use filters and search options to tailor how information is displayed within Microsoft Teams and Microsoft 365.
Scaling
- Independence of resources
- The service is designed so that each customer operates within their own Microsoft 365 and Microsoft Entra ID tenancy, ensuring logical separation of data and usage. As a result, user activity and demand from other customers cannot impact performance or availability. The service uses Microsoft’s cloud infrastructure, which provides built-in scalability, resilience, and resource management to handle varying workloads. Monitoring and capacity management processes are in place to ensure consistent performance for all users.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users export their data directly from their own Microsoft 365 tenancy, where all data is stored. Administrators can use standard Microsoft 365 and Microsoft Entra ID tools to export user attributes and directory information in commonly used formats. Any service-specific configuration data can also be exported through the administrative interface or agreed export process. This ensures customers retain full control of their data and can reuse or migrate it as required.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
The service is available in line with the availability of Microsoft 365 and on which it depends. We aim to provide a high level of availability consistent with Microsoft’s published service commitments. The service is designed to be accessible 24 hours a day, 7 days a week, excluding planned maintenance, which is communicated to customers in advance where possible.
Availability is monitored continuously, and service levels are reviewed against agreed targets. Where availability falls below the agreed service levels due to issues within the supplier-managed components of the service, service credits may be applied in line with the contract terms. Any service credits or refunds are calculated proportionately based on the duration and impact of the service disruption, as defined in the service level agreement. - Approach to resilience
- The service is designed for resilience by leveraging the built-in reliability of Microsoft 365 services. It operates on Microsoft’s cloud platform, which provides high availability, geographic redundancy, automated failover, and continuous monitoring. The service uses scalable, stateless components where possible, reducing single points of failure and enabling rapid recovery. Regular updates, monitoring, and proactive incident management processes are in place to maintain service continuity and minimise disruption to users.
- Outage reporting
- Where an outage relates to Microsoft 365 service, customers are also able to view detailed incident information and status updates through the Microsoft 365 Service Health Dashboard. Post-incident communications can be provided where required, including details of impact, resolution, and any corrective actions taken.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Other
- Other user authentication
- Users are authenticated using their organisation’s Microsoft 365 identity through Microsoft Entra ID. The service relies on Microsoft’s secure authentication mechanisms, including single sign-on (SSO) and support for multi-factor authentication where enabled by the customer. Access is controlled using role-based permissions and conditional access policies defined within the customer’s Entra ID tenancy, ensuring that only authorised users can access the service and its administrative functions.
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted through role-based access control managed by the application. The application defines administrative and management roles, and only authorised users assigned to these roles can access configuration and management functions. Authentication uses Microsoft 365 single sign-on and supports multi-factor authentication and conditional access policies where configured by the customer.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Other
- Description of management access authentication
- Management access to the service is authenticated using Microsoft 365 identities through Microsoft Entra ID. The service uses single sign-on (SSO) and relies on the customer’s Entra ID authentication policies, including multi-factor authentication and conditional access where enabled. Management access is further controlled by application-defined administrative roles, ensuring that only authorised users assigned to those roles can access management and configuration interfaces. All management access is logged for audit purposes.
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
- We follow formal information security policies and processes designed to protect customer data and ensure confidentiality, integrity, and availability. These include policies for access control, data protection, incident management, vulnerability management, and change control. Security processes are aligned with recognised standards such as Cyber Essentials and applicable UK data protection legislation. Regular reviews, risk assessments, and staff security training are carried out to ensure policies remain effective and are consistently applied across the service.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Configuration and change management are managed through controlled, documented processes. Service configuration is defined and approved before deployment, with changes made by authorised personnel only. All changes follow a formal change management process that includes impact assessment, testing, approval, and rollback planning where appropriate. Changes are scheduled to minimise disruption to users and, where relevant, customers are notified in advance. Configuration settings are version controlled and reviewed regularly to ensure consistency, security, and service stability.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Our vulnerability management process is designed to identify, assess, and remediate security risks in a timely and controlled manner. It includes regular vulnerability scanning, dependency and platform updates, and monitoring of security advisories from Microsoft and other relevant suppliers. Identified vulnerabilities are risk-assessed, prioritised based on severity and potential impact, and addressed according to defined remediation timescales. Patches and fixes are tested before deployment and applied through the formal change management process. The process is reviewed regularly to ensure it remains effective and aligned with recognised security best practices.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Our protective monitoring approach is designed to detect, analyse, and respond to security events in a timely manner. The service uses monitoring and logging capabilities provided by Microsoft 365 and Microsoft Entra ID, including audit logs, access logs, and security alerts. These are reviewed to identify unusual or unauthorised activity. Alerts are investigated in line with incident management procedures, and appropriate actions are taken to contain and remediate any issues. Monitoring processes are reviewed regularly to ensure they remain effective and aligned with security best practices and public-sector requirements.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Our incident management process is designed to ensure security and service incidents are identified, managed, and resolved promptly. Incidents can be detected through monitoring alerts, user reports, or supplier notifications. Each incident is logged, categorised, and prioritised based on impact and severity. Clear escalation paths are in place to ensure timely response and resolution. Customers are kept informed of significant incidents, including progress updates and resolution details. Following resolution, incidents are reviewed to identify root causes and implement corrective actions to reduce the likelihood of recurrence.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Yes, a trial version of the service is available. The trial provides access to all features for a period of 30 days. The trial period can be extended on request, subject to agreement.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 7.5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 12.5%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 633ce8e3-0f5c-48f9-af17-f3957b2b8652
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- D1a9172f-0bae-4b4d-ab05-d755e385dd8b
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-