UK Sovereign Object Storage for Backup, Evidence and Long-Term Data Retention
A UK-sovereign object storage service providing secure, immutable storage for backup repositories, evidential data, medical imaging, and long-term data retention. The service supports public sector compliance, audit, ransomware resilience, and statutory retention requirements through UK-only data residency, Object Lock immutability, legal hold, and multi-tier retention policies.
Features
- Long-term data archive and cold storage
- Local authority statutory, planning, and records management data
- NHS imaging and clinical records archiving
- Police evidence, CCTV, and body-worn video retention and archiving
- Enterprise and SaaS backup repositories (BaaS)
- Cloud backup target repositories
Benefits
- Optional multi-site replication
- Scalable capacity on demand
- UK-only data residency
- Encryption at rest and in transit
- Multi-tier storage options for active and archive data
- Legal hold and configurable retention policies
- Object Lock immutability and air-gapped protection
- Optimised for backup, archive, and evidential workloads
- S3-compatible APIs
- UK-hosted, UK-sovereign object storage
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 0 2 2 4 7 1 2 8 8 1 8 9 8 6
Contact
CENTERPRISE INTERNATIONAL LIMITED
Tenders Team
Telephone: 01256 378 000
Email: tendersteam@centerprise.co.uk
About your service
- Service categories
-
PaaS
Data Management
- Data integration and intelligence
Service scope
- Service constraints
- The service operates from UK-based data centres to maintain data sovereignty and compliance. Planned maintenance is performed during agreed maintenance windows and may result in temporary, non-disruptive service degradation; advance notice is provided wherever possible. The service is designed for S3-compatible object storage workloads and is not intended for transactional block or file use cases. Customer access requires compatible APIs, supported network connectivity, and adherence to agreed security and authentication controls. Service availability and performance are subject to agreed SLAs, network connectivity, and customer configuration. No unsupported hardware dependencies are imposed on customers.
- System requirements
-
- Secure network connectivity to UK sovereign cloud service endpoints
- S3-compatible applications or backup software for object access
- Support for encrypted communications using standard TLS protocols
- Buyer-managed security controls on systems accessing the service
- Compatible identity and access management for object authentication
- No customer-owned hardware or infrastructure dependencies required
- Cloud deployment model
-
- Public cloud
- Hybrid cloud
User support
- Email or online ticketing support
- Yes
- Support response times
- These SLAs are applicable, but for out-of-business hours, telephone support should be used. Incident Response and Resolution Incident Management Priority 1 Priority 2 Priority 3 Priority 4 Response Time 15 Mins 30 Mins 30 Mins 30 Mins Target Resolution 4 Hrs 8 Hrs 16 Hrs. 5 Days
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Tiered, ITIL-aligned support is provided through a single UK-based Service Desk, ensuring consistent service delivery and clear escalation routes across all cloud services.
Standard Support provides access M-F, 08:00–18:00 (excluding UK public holidays). This includes incident logging and triage, service requests, first-line resolution, prioritisation, and escalation to specialist engineering teams where required.
Enhanced Support (optional) provides extended service hours, priority incident handling, and increased access to specialist cloud and platform engineers. This level includes proactive monitoring, accelerated escalation, and regular service review meetings to support operational assurance and continuous improvement.
Critical / 24×7 Support (optional) provides 24×7×365 incident response for business-critical services. This includes out-of-hours engineering cover, Major Incident Management, and senior technical oversight. This level is designed for regulated or mission-critical environments, including disaster recovery and resilience services.
Cost of support levels:
Standard Support is included within the core service price. Enhanced and Critical support levels are charged as additional managed service uplifts, priced at call-off based on service scope, support hours, and criticality.
Technical Account Management:
A named Technical Account Manager is available as an optional service. All support levels include access to certified cloud support engineers, with higher tiers providing greater access to senior specialists. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Centerprise provides a structured and low-risk onboarding process designed to ensure services are adopted quickly, securely, and with minimal operational disruption. Each engagement begins with a formal mobilisation phase, including a service kick-off, confirmation of scope, roles and responsibilities, and agreement of onboarding milestones aligned to customer timelines. A named service delivery contact coordinates onboarding and acts as the primary point of escalation. Customers are supported through a combination of clear documentation, guided configuration, and knowledge transfer. Where applicable, Centerprise provides live walkthroughs, remote or on-site workshops, recorded training sessions, and access to vendor-accredited learning resources. Training is tailored to operational and administrative users and focuses on day-to-day service use, recovery actions, and support processes. Prior to go-live, services are validated through testing and user acceptance to ensure the solution operates as expected. Once live, customers are fully onboarded to the Centerprise Service Desk, including access to ticketing, escalation routes, and agreed service levels. Post-transition reviews are conducted to confirm service stability and ensure customers are confident in operating and consuming the service.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- Centerprise supports secure, orderly, and auditable data extraction at contract end to ensure continuity and data integrity. As part of service exit planning, Centerprise works collaboratively with the customer to agree a documented exit strategy and data migration approach. This includes defining data scope, extraction methods, security controls, timelines, and responsibilities. Data can be exported using standard, non-proprietary formats supported by the underlying platforms and tools, ensuring compatibility with successor services or in-house environments. Where applicable, data extraction may be performed incrementally to reduce risk and operational impact. Transfers are monitored, validated, and subject to post-migration checks to confirm completeness and integrity. Secure delivery methods are used throughout, aligned to customer security and compliance requirements. Customers may self-extract data where the service supports customer-managed access, or request Centerprise-assisted extraction via the Service Desk. Any assisted extraction is delivered under controlled change and security processes. Data remains accessible for the duration of the agreed exit period. Following confirmation of successful extraction and formal service termination, remaining service data is securely deleted in line with contractual obligations and data protection requirements.
- End-of-contract process
- At contract end, Centerprise follows a defined service exit process to ensure a controlled and transparent transition. An exit plan is agreed in advance, covering service termination activities, data extraction, access removal, and service decommissioning. During the notice period, services continue to operate in line with contracted service levels unless otherwise agreed. Customers retain access to support and service documentation throughout this period. The standard contract price includes exit planning, coordination, and reasonable assistance to enable service cessation in an orderly manner. This includes stakeholder engagement, access to documentation, and support for standard data extraction using agreed methods. Additional costs may apply where customers request non-standard exit activities, such as bespoke migration tooling, accelerated timescales, extended data retention beyond contract end, specialist engineering effort, or physical data transfer media. Any such costs are agreed in advance through a transparent change control process. Following service termination, access is removed, integrations are decommissioned, and data is securely deleted once extraction is confirmed. A formal service closure confirmation can be provided on request.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Using the web interface
- The service is accessed via a combination of Centerprise’s Service Desk interface and product-specific self-service capabilities. Customers interact with the service through Centerprise’s secure client portal, email and telephone channels to raise incidents, service requests and restore requests, all delivered in line with agreed SLAs. For backup services, an optional self-service recovery portal is provided, enabling authorised users to perform granular restores of VMs and other data. Service reporting and operational communications are provided through agreed reporting mechanisms as part of the managed service including report access via an ITSM tool provided by Centerprise.
- Web interface accessibility standard
- WCAG 2.2 AA
- Web interface accessibility testing
- Autotask design, test and supply enhancements of assisted technologies as part of this interface and Veeam UI is similarly tested by them.
- API
- Yes
- What users can and can't do using the API
-
The sovereign object storage service exposes a standards-based object storage API, built on the S3-compatible API framework provided by Scality. This enables customers and authorised applications to integrate directly with the service using widely adopted tools, SDKs and automation frameworks.
Users can programmatically configure and manage data operations, including creating and accessing buckets, uploading and retrieving objects, applying metadata and tags, enforcing lifecycle policies, and managing object immutability features such as retention periods and legal holds (where enabled). The API supports integration into CI/CD pipelines, backup platforms, archiving workflows and data-driven applications.
Service setup via the API is focused on data plane configuration. Customers can authenticate using access keys issued by Centerprise and begin ingesting data immediately once a tenancy and namespace are provisioned. Ongoing changes, such as lifecycle rules, object lock settings and access controls, can be managed through API calls, subject to role-based permissions.
The API does not allow customers to modify control plane or infrastructure elements, such as physical storage configuration, replication topology, encryption key management, geographic placement, or underlying platform upgrades. These elements are intentionally restricted to maintain UK data sovereignty, security accreditation and service integrity, and are managed exclusively by Centerprise under the contracted service. - API automation tools
-
- Ansible
- Chef
- SaltStack
- Terraform
- Puppet
- Other
- Other API automation tools
-
- Automation tools or frameworks that supports S3 API
- S3 SDKs (for example, Python, Java, Go or backup platforms)
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- ODF
- Command line interface
- No
Scaling
- Independence of resources
- Our solution, using our sovereign Cloud storage, was recently designed and installed under strict sizing and stress tested parameters with guaranteed throughput (underwritten by vendor) sufficient to support all of our current customers as well as as accurate business growth forecasts based on historic and future growth expectations. Our network connectivity is designed for rapid scaling to meet growth across multiple channels.
- Usage notifications
- Yes
- Usage reporting
- Optimising consumption
- Yes
- Automatic scaling
- No
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- Network
- Number of active instances
- Other
- Other metrics
- Storage capacity usage and growth rates.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- Secure hardware handling, controlled media disposal, and managed lifecycle processes further protect data integrity and sovereignty.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Backup and recovery
- What’s backed up
-
- Provides durable object storage for backup data.
- Supports recovery through standard object read operations.
- Enables immutable backups using object lock.
- Supports long-term retention and archival recovery.
- Integrates with third-party backup and recovery platforms.
- Allows point-in-time recovery using object versioning.
- Supports API-driven restore and data retrieval.
- Enables secure off-site backup storage.
- Maintains data integrity through checksum verification.
- Supports disaster recovery architectures as a backup target.
- Backup controls
-
Users control what backups are performed through the backup, archive or application platforms that write data to the object storage service. These determine what data is protected, backup frequency, retention periods and recovery points, based on customer-defined policies and schedules.
The object storage service provides the secure backup target and enforces data protection controls such as immutability, object versioning and lifecycle policies. Different data sets can therefore be backed up on different schedules and retained for different durations, according to the backup or data management solution.
The service doesn't impose backup schedules itself, ensuring flexibility and compatibility. - Datacentre setup
- Single datacentre with multiple copies
- Scheduling backups
- Users schedule backups through a web interface
- Backup recovery
-
- Users can recover backups themselves, for example through a web interface
- Users contact the support team
- Backup and recovery
- Yes
- RPO/RTO
- Yes
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- Data in transit is protected using layered network security controls aligned to Cloud Security Principle 1. All data transfers use encrypted channels, with TLS 1.2 or higher enforced for API and object access. Where required, customers may connect using private connectivity or site-to-site IPsec VPNs, reducing exposure to public networks. Network traffic is restricted through firewall rules, access control lists and segmentation within the platform. Mutual authentication, role-based access controls and credential management are enforced to prevent unauthorised access. Continuous monitoring and logging are applied to network traffic to detect anomalies and maintain integrity and confidentiality of data in transit.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- Data within the service network is protected using defence-in-depth security controls aligned to Cloud Security Principle 1. All internal service communications are encrypted using TLS 1.2 or higher, including management, control and data plane traffic. Network segmentation and zoning are used to isolate workloads, storage nodes and management components, reducing lateral movement risk. Access is restricted through firewalls, security groups and least-privilege access controls. Administrative access is tightly controlled, logged and monitored. Internal traffic is continuously monitored for anomalous behaviour, and security controls are regularly reviewed to ensure the confidentiality and integrity of data in transit within the service network.
Availability and resilience
- Guaranteed availability
- The service is delivered from UK-based, carrier-neutral data centres, designed to support highly available, enterprise-grade cloud infrastructure. The underlying data centre environment targets 100% uptime for power and cooling, supported by resilient design, multiple power feeds, and continuous monitoring. The service is architected with redundant storage components and network connectivity. Platform throughput is underwritten to support sustained data transfer rates of up to 1.5 GB per second per storage environment, subject to service configuration and connectivity. The supplier provides a service availability target of 99.9% per calendar month, excluding scheduled maintenance and factors outside the supplier’s reasonable control, including upstream network providers and third-party platform dependencies. Planned maintenance is conducted during agreed maintenance windows and notified in advance where possible. If the guaranteed availability level is not met, service credits may be applied in accordance with the agreed call-off contract. Credits are calculated as a proportion of the monthly service charge for the affected service and represent the buyer’s sole remedy for availability failures under the service level agreement.
- Approach to resilience
- The service is delivered from UK-based, carrier-neutral data centres, designed to support highly available, enterprise-grade cloud infrastructure. The underlying data centre environment targets 100% uptime for power and cooling, supported by resilient design, multiple power feeds, and continuous monitoring. The service is architected with redundant storage components and network connectivity. Platform throughput is underwritten to support sustained data transfer rates of up to 1.5 GB per second per storage environment, subject to service configuration and connectivity. The supplier provides a service availability target of 99.9% per calendar month, excluding scheduled maintenance and factors outside the supplier’s reasonable control, including upstream network providers and third-party platform dependencies. Planned maintenance is conducted during agreed maintenance windows and notified in advance where possible. If the guaranteed availability level is not met, service credits may be applied in accordance with the agreed call-off contract. Credits are calculated as a proportion of the monthly service charge for the affected service and represent the buyer’s sole remedy for availability failures under the service level agreement.
- Outage reporting
-
The service reports outages and service disruptions through a combination of proactive communications, automated notifications and service management processes. Customers are notified of service-impacting incidents via email alerts issued by the Centerprise Service Desk, ensuring timely awareness of incidents, updates on progress and confirmation of service restoration.
Automated notifications are generated for service-affecting events and major incidents, in line with agreed SLAs and incident management procedures. These notifications provide clear information on the nature of the incident, affected service components, expected impact and ongoing remediation actions. Where appropriate, follow-up communications and post-incident summaries are provided.
Operational visibility is supported through service reporting and review mechanisms, including incident history, SLA performance and service availability metrics, shared as part of regular service reviews or on request. An API is not exposed for outage notification, as incident communications are managed centrally to ensure accuracy, consistency and controlled messaging.
The service does not rely on a public-facing status dashboard. This approach avoids the disclosure of sensitive operational details while ensuring customers receive authoritative, timely and auditable communications directly from the service provider. Escalation paths are clearly defined to support critical incidents and major service disruptions.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Other
- Other user authentication
- Access to the object storage service by integrated platforms is authenticated using scoped, non-interactive access credentials generated per tenant and service. These credentials are bound to defined roles and permissions and are used exclusively over encrypted TLS connections. This model supports secure, API-driven access by backup and archive platforms such as Veeam, without the use of shared user accounts. Credentials can be rotated, revoked, and audited, and are restricted by policy to specific buckets, operations, and endpoints, enforcing least-privilege access and reducing exposure.
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access control aligned to least-privilege principles. Administrative access is limited to authorised personnel with job-role justification and is protected using multi-factor authentication. Management access is segregated between platform administration, service operations, and customer support functions. Support channels are accessed only through authenticated service desk systems, with permissions scoped to customer tenancy and service responsibility. Privileged actions are logged and auditable, with access reviewed regularly and removed promptly on role change or leaver events. Direct platform access by customers is limited to explicitly agreed, read-only or delegated functions where applicable.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Other
- Description of management access authentication
- Management access to the service is authenticated using centrally controlled, role-based privileged accounts that are individually assigned and approved. Access is time-bound where appropriate and granted only for operational or support purposes. Authentication is enforced through secure administrative identity controls integrated with the service management platform, ensuring that management actions are attributable to named individuals. All management sessions are established over encrypted channels and are subject to logging and monitoring. Privileged credentials are rotated in line with policy and revoked immediately upon role change or leaver events, ensuring continued alignment with least-privilege and strong accountability requirements.
- Devices users manage the service through
-
- Dedicated device on a segregated network (providers own provision)
- Dedicated device on a government network (for example PSN)
- Dedicated device over multiple services or networks
- Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus ADISA ICT Asset Recovery Standard 8.0 – DIAL 3 rated DataCentre specific: ISO 27001, SOC 1 Type 2 & SOC 2 Type 2 , PCI-DSS, HIPAA & PIPEDA: ISO 9001, 14001, 45001, 50001: -- Includes Data Centre.
- Information security policies and processes
-
Centerprise International operates an Integrated Management System aligned with its Information Security Policies, establishing a consistent framework for protecting customer information across all sites and services, including Microsoft 365 Backup, Backup as a Service (BaaS), and Disaster Recovery as a Service (DRaaS). The policies defined under our ISO 27001 certification apply to all employees, contractors, suppliers, and relevant third parties, ensuring controlled and consistent handling of customer data.
ISO 27001 certification provides robust governance and accountability. Senior leadership, including the CEO, Group Quality Manager, Security Manager, Services Director, Board-level contact, and Data Protection Officer, review and approve all policies to ensure continued alignment with legal, regulatory, and contractual requirements. Clear responsibilities are defined for information security, risk management, access control, incident response, and data protection compliance. All users must follow security procedures and report suspected security incidents immediately.
Adherence is enforced through mandatory training, regular risk assessments, internal and external audits, and established incident response processes. Controls include data classification, acceptable use, technical safeguards, business continuity measures, and GDPR-aligned personal data handling, providing customers with strong assurance that their information is protected to a high standard.
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Configuration and change management is delivered through formal, documented processes to maintain security and service integrity. Service components, including infrastructure, platform software and configurations, are recorded and tracked throughout their lifecycle from provisioning to retirement.
All changes follow a controlled change management process, including impact assessment, approval, implementation and review. Security impact is explicitly assessed for each change, considering confidentiality, integrity and availability. Changes with potential security implications are subject to additional review/testing.
Changes are logged, auditable and subject to segregation of duties. Customer-impacting changes are planned, scheduled and communicated in advance where required to minimise risk and service disruption. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Vulnerability management is delivered through a structured, risk-based process designed to protect service confidentiality, integrity and availability. Potential threats are assessed using vulnerability scanning, vendor advisories and risk assessment processes to evaluate severity, exploitability and service impact. Patches and mitigations are prioritised based on criticality and deployed in accordance with defined patch management timelines, with urgent security updates expedited where required.
Threat intelligence is sourced from trusted vendors, platform suppliers, security advisories and industry best-practice sources. Changes are tested prior to deployment where appropriate, and all remediation activities are logged and auditable, ensuring accountability and continuous service improvement. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Protective monitoring is implemented through continuous monitoring of service platforms, infrastructure and network activity to detect potential security compromises. Logs, alerts and system events are analysed to identify anomalous behaviour, unauthorised access attempts or indicators of compromise. Monitoring outputs are reviewed by authorised operations/security personnel.
When a potential compromise is identified, predefined incident management procedures are invoked to assess impact, contain risk and initiate remediation. This includes escalation to specialist teams where required. Incidents are prioritised based on severity and business impact, with response times aligned to incident classification and SLAs. Actions are logged and reviewed to support auditability/continuous improvement. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Incident management is delivered through documented, pre-defined processes aligned to best practice. Standard procedures exist for common events, including service degradation, security incidents and data access issues, ensuring consistent/timely response.
Users report incidents via the Centerprise Service-Desk using email, telephone or the secure client portal. All incidents are logged, categorised and prioritised based on impact and urgency, with response and resolution managed in line with defined SLAs.
Updates are communicated to users throughout the lifecycle of the incident. Following resolution, incident reports and summaries can be provided, including root cause analysis for major incidents, supporting transparency and continuous service improvement. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- No
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
-
Our datacentres, delivered through the Vantage Data Centres campus in Wales (including CWL1 and Newport facilities), incorporate leading energy-efficient design and operational practices that align with the principles of the EU Code of Conduct for Energy Efficient Datacentres. The EU Code of Conduct is a voluntary framework that encourages operators to adopt best practices to reduce energy consumption and improve sustainability, including systematic measurement and optimisation of Power Usage Effectiveness (PUE) and broader resource-efficiency metrics.
At Vantage, sustainability and energy efficiency are core to campus design and operations. The Welsh facility is powered by 100% renewable energy for critical load, significantly reducing indirect emissions and aligning with the Code’s focus on energy-efficient power sourcing. Vantage’s global sustainability strategy includes a commitment to net zero operational carbon emissions by 2030, robust energy metering, ongoing PUE optimisation, closed-loop cooling systems that minimise water use, and continuous performance benchmarking against best practices.
These measures support energy consumption transparency, efficient use of power and cooling infrastructure, and adherence to recognised best practices consistent with the intent of the EU Code of Conduct to foster more energy-efficient and sustainable data centre facilities.
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We are able to offer up to 5 TB as a test facility for one month. Extensions to the size of data available for the test and the duration can be varied according to the size of the individual project.
Discount
- Provide your minimum discount applicable to your baseline prices
- 10%
Formula for calculating price of your services
- Formula for calculating price of your services
-
Which of the core deployment models you intend to offer
Public CloudPublic Cloud - Formula for calculating price of your services
- Total Cost
- The Total Cost for a buyer's call off requirement in a Public Cloud Deployment
- =
- Baseline Pricing
-
Centerprise International publishes baseline pricing for its cloud and managed services within a publicly accessible online service catalogue on the Centerprise website. This catalogue provides transparent, indicative pricing intended to support early-stage commercial evaluation and comparison by public sector buyers.
The published baseline prices represent standard list rates for commonly consumed service components and configurations. They are designed to provide buyers with a clear understanding of entry-level costs, charging units (for example, per TB, per user, or per month), and typical service constructs before any buyer-specific tailoring is applied. Pricing is presented in a consistent and auditable format to support framework compliance and procurement governance.
Where services are subject to volume-based consumption, forecast usage, or contract-specific requirements, the public catalogue pricing should be treated as a baseline reference. Final pricing is confirmed through the formal CCS procurement process and reflected in the framework pricing submission and call-off agreement, ensuring alignment with buyer requirements, service scope, and contract duration.
The public catalogue is maintained by Centerprise to ensure pricing remains current and reflective of the services offered, while allowing buyers to validate that baseline prices are openly published and accessible without registration or login. - Baseline Pricing - Web link
- https://cicontinuity.co.uk/g-cloud-15-pricing-table/
- -
- Minimum Discounting
- 10%
- +
- Onboarding Activity
- Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
- +
- Additional sources of cost
- Additional costs may arise where a buyer requires services beyond the baseline object storage offering. These can include increased committed capacity above the forecast baseline, enhanced support arrangements, bespoke security or networking configurations, private connectivity, or customer-specific onboarding complexity. Costs may also vary where buyers request additional management services, reporting, or non-standard operating hours support. Energy price fluctuations, regulatory-driven changes, or mandatory security updates may also impact operational costs; however, these are managed through contract governance and change control. All additional costs are transparently agreed in advance and documented through the call-off contract to maintain budgetary control.
- -
- Additional sources of cost reduction
- Cost reductions may be achieved through commitment-based pricing, where buyers commit to forecast capacity over a defined period, enabling more efficient resource planning. Longer contract terms may also enable improved pricing stability. Framework-level public sector discounts are applied consistently, and onboarding costs may be reduced or waived depending on service complexity and scale. Where buyers optimise data usage, retention policies, or storage tiers, this can further reduce ongoing costs. Any cost reductions are clearly reflected in the call-off pricing schedule and do not affect the agreed baseline unit price.
Mandatory certifications
- Mandatory certifications
-
Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure
Sole Control of the InfrastructureISO 9001 certification
ProvidedISO 14001 certification
ProvidedISO 27001 certification
ProvidedISO 20000-1 certification
ProvidedISO 27017 certification
ProvidedAre you bidding to provide services under Lot 1b or both Lot 1a and Lot 1b?
YesISO 27018 certification
Provided
Cyber Essentials
- Do you have a Cyber Essentials Plus certificate?
- Yes
- Cyber Essentials Plus certificate Number
- Ae2ef03f-bd6e-4405-9ace-237c365676d6
Non-mandatory Standards and certifications
- ISO 28000:2022 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Security Metrics
- PCI DSS accreditation date
- Wednesday 5 November 2025
- What the PCI DSS doesn’t cover
- N/A
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for positive actions with community groups.
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-