Skip to main content

Help us improve the Digital Marketplace - send your feedback

Yes We Hack SAS

Bug Bounty Program: Security Penetration Testing and Vulnerability Disclosure Platform

Crowdsourced penetration testing through a managed Bug Bounty service connecting UK public sector organisations with vetted ethical hackers to surface and evaluate critical vulnerabilities. The platform enables continuous testing, outcome-based rewards, provides in-house triage and complies with government-backed security standards, including ISO 27001 and GDPR.

Features

  • Continuous or time-bound security testing & live vulnerability reporting
  • Global community of vetted whitehats, for maximum breadth/depth of skills
  • Dedicated experts support customers throughout programs with continuous, high-quality triage.
  • In-house reports, including bug reproduction & detailed analysis
  • API & connectors integration - incl. Jira, GitHub and Slack
  • Live dashboards & analytics for easy program & report tracking
  • Self-generation of PDF, audit-ready, executive summaries, aligned to compliance requirements
  • Secure teams collaboration workspace through highly granular access rights management
  • VPN & User-Agent for clear visibility & control over programs
  • Supports unlimited users, programs, with flexible and unlimited managed scopes

Benefits

  • Time-to-detect reduction (= find vulnerabilities faster, as they emerge)
  • Ongoing testing coverage (versus annual, time-bound) aligned to IT releases
  • In-depth security through discovery of complex & critical vulnerabilities
  • Testing controls: flexibility in terms of start, stop and pausing
  • Testing of "exotic" tech stacks (not covered by traditional pentesters)
  • Easy prioritisation of reports remediation based on actual risks
  • Time-to-fix reduction through ticket creation or integration into existing tools
  • Systematic vulnerabilities fix-check for security assurance
  • Facilitated teams & cross-department collaboration – and ethical hackers
  • Clear observability & easy reporting over testing & vulnerability management

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@yeswehack.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 3 9 4 8 4 7 2 3 8 3 8 2 2 9

Contact

Yes We Hack SAS Sam Lowe
Telephone: 07342132662
Email: gcloud@yeswehack.com

About your service

Service categories

Systems Infrastructure Software

Security

  • Cloud native application protection platform
  • Security analytics
  • Governance, risk and compliance

Network security

  • Active application security

Data security

  • Information protection
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
YesWeHack does not operate regular planned maintenance or outage windows. Any scheduled maintenance expected to exceed 30 minutes is communicated to clients at least 24 hours in advance via email and the public status page. Support is not available at weekends.
System requirements
  • Browser versions – Modern browsers (Chrome, Edge, Firefox)
  • Internet access – Active connection required.

User support

Email or online ticketing support
Yes
Support response times
Customer support is provided Monday to Friday, from 08:00 to 17:00 UK local time, through teams based in France, Singapore, and Canada. Each customer has a dedicated Customer Success Manager (CSM) as their main point of contact. However, urgent requests sent to csm@yeswehack.com can be handled by any available team member. Responses are typically provided within the same business day. While no formal SLAs are in place, standards are maintained through established processes and resourcing. In exceptional cases, an emergency contact route can be activated. Support is not available at weekends.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Support is included with all subscriptions and provides access to our secure online portal, during business hours (Monday–Friday, 8:00–18:00 UK time). All communications with ethical hackers (“hunters”) are accessible through individual hunter profiles in the portal.
A dedicated Customer Success Manager (CSM) is assigned to plan, build, and manage the testing programme, coordinate teams, and provide ongoing guidance.
A Triage Team also included, validates and prioritises submitted reports, ensuring only actionable findings are sent to your internal teams.
All interactions, findings, and remediation guidance are tracked in the portal with full audit history, ensuring clear visibility and accountability. Support is designed to integrate seamlessly with your internal teams, workflows, and compliance requirements.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
YesWeHack provides a structured onboarding process to ensure customers can deploy and manage their vulnerability disclosure or bug bounty programmes efficiently and securely.
Each new customer is supported by a dedicated Customer Success Manager (CSM) who guides them through setup, scope definition, and programme launch. The CSM works alongside the customer’s security and development teams to align the testing approach with organisational objectives, compliance requirements, and internal workflows.
Comprehensive online (teams/zoom) training and user documentation are provided, including step-by-step guides, best-practice templates, and instructional videos covering platform navigation, triage processes, and communication with ethical hackers. Live onboarding sessions and remote workshops are available for teams requiring deeper technical or operational guidance.
YesWeHack also supports integration setup with common tools (e.g., Jira, GitLab, GitHub) and helps configure automation via the API. Continuous support from the triage team and CSM ensures a smooth transition from onboarding to active programme management.
All onboarding materials are updated regularly to reflect platform enhancements and evolving security best practices.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
Powerpoint
End-of-contract data extraction
YesWeHack ensures that customers can securely extract all relevant data at the end of a contract. Customers have full access to export programme data, including vulnerability reports, remediation records, communications with ethical hackers, and audit logs, via the platform’s secure portal or API. Data can be exported in common readable formats to support internal record-keeping.
Using the API integration, you can integrate across your chosen internal bug tracker e.g. Jira / Service now etc.
A dedicated Customer Success Manager (CSM) assists with the extraction process, ensuring all necessary data is retrieved in a complete and organised manner. Where required, the triage team can provide support in consolidating historical reports and associated evidence.
End-of-contract process
At the end of a YesWeHack contract, customers are supported through a structured offboarding process to ensure secure closure and continuity. Included in the contract price is the complete extraction of all programme data, including vulnerability reports, remediation logs, communications with ethical hackers, and audit trails. Data can be exported via the secure portal or API in standard formats (CSV, JSON).

A dedicated Customer Success Manager (CSM) assists with the process, ensuring all data is accessible, organised, and any questions regarding historical reports or evidence are addressed. The triage team can provide support for consolidating and validating findings if required.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
YesWeHack’s service is accessible via mobile and desktop browsers. The mobile interface provides the core functionality, including viewing and acknowledging reports, accessing hunter communications, and monitoring remediation progress. Some advanced features, such as detailed analytics dashboards and bulk report management, are optimised for desktop use due to screen size and interaction complexity. Mobile access ensures on-the-go visibility and timely response to findings, while desktop remains the preferred environment for planning, configuration, and in-depth analysis. All interactions are secure and synchronized across devices in real time.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
YesWeHack provides a secure, web-based service interface accessible via desktop and mobile browsers. The interface offers a clear dashboard for managing programmes, tracking vulnerabilities, and communicating with ethical hackers. Users can view, triage, and prioritise reports, access remediation guidance, and generate audit-ready reports. Role-based access ensures users see only relevant data, while interactive analytics and visualisations help monitor trends and progress. The interface supports real-time updates, secure messaging, and integration with existing workflows and tools, providing a seamless experience for programme management and collaborative security testing.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
• Our service interface is designed and evaluated with accessibility in mind, following the WCAG 2.1 AA guidelines as our reference standard. Accessibility is considered from the early design stages through to development and qualification.
• In design, we rely on an accessible design system and use tools such as Stark for Figma to check color contrast and text legibility. During development, accessibility verification is progressively integrated into automated testing workflows.
• Manual checks are also performed regularly. These include keyboard navigation tests, especially on forms, to ensure usability without a mouse. For broader validation, we use tools like Lighthouse (Chrome) and the Firefox Accessibility Inspector to detect potential issues across the interface.
• Although we have not yet conducted user testing with assistive technologies, our current practices aim to make the platform accessible to users relying on screen readers and other assistive tools.
API
Yes
What users can and can't do using the API
Reports can be securely retrieved, filtered, and exported through the platform or API, with remediation statuses updated automatically for live synchronisation between YesWeHack and internal systems. Users can relay validated vulnerability reports directly into issue trackers or bug management tools, maintaining a single source of truth.

YesWeHack’s secure REST API integrates seamlessly with CI/CD pipelines, ticketing systems (Jira, GitLab, GitHub), and internal dashboards, enabling automated workflows, continuous visibility of security findings, and faster collaboration between security and development teams. Users can set up the service by creating an API App (with name, domain, redirect URI) to obtain OAuth2 credentials or generate a Personal Access Token (PAT) if their role permits. Changes can be made by calling the platform’s REST endpoints (POST/PUT/PATCH/DELETE) using OAuth tokens or PATs, applying updates according to account and program permissions.

Limitations include role-based restrictions on PAT creation and certain actions, the need for correctly registered API Apps, and endpoint-specific permission and rate limits. Full configuration details and API usage examples are provided in the YesWeHack Help Centre.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
YesWeHack allows extensive customisation so organisations can tailor their security testing programmes to meet specific operational, compliance, and risk management needs.

Authorised administrators can customise programme settings, including scope definitions, testing environments, timelines, reward models, and vulnerability disclosure policies. Buyers can define rules of engagement, specify in-scope and out-of-scope assets, and adjust severity scoring to align with internal risk frameworks.

Through the management portal or API, users can configure integrations with third-party tools such as Jira, GitLab, GitHub, or ServiceNow, enabling automatic ticket creation and synchronised remediation tracking. Dashboards and reporting views can be personalised by role or team to display key metrics, trends, and programme performance.

Customisation privileges are limited to approved administrators and Customer Success Managers (CSMs), ensuring governance, consistency, and compliance. Ethical hackers (“hunters”) only interact within predefined programme parameters and cannot alter configurations.

Scaling

Independence of resources
YesWeHack ensures consistent service quality through dedicated resources and workload management. Each customer is supported by an assigned Customer Success Manager (CSM) who oversees programme planning and performance. The triage team operates with scalable capacity, ensuring reports are validated and prioritised without delay, even during peak activity. Work is distributed across qualified analysts to maintain turnaround times. Resource allocation is continuously monitored to prevent overload and ensure customers receive the same high standard of responsiveness, communication, and report quality regardless of overall platform demand.

Analytics

Service usage metrics
Yes
Metrics types
YesWeHack provides comprehensive metrics to help organisations measure and improve their security performance. Key service metrics include the number of vulnerabilities reported, validated, and resolved; average time to triage and remediate; vulnerability severity distribution; and programme participation rates. Custom dashboards display trends over time, team responsiveness, and overall risk reduction. Administrators can export metrics for internal reporting or integrate them with existing dashboards via API. Metrics support governance, compliance, and continuous improvement of security posture.
Reporting types
  • API access
  • Real-time dashboards
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Encryption algorithms used at rest:
•    PHP defuse for application-level encryption (with AES-256-CTR) .
•    vSphere virtual machine encryption on the SecNumCloud-qualified private IaaS (AES-256-XTS)
•    Luks 2 for disk encryption on Linux servers and workstations (AES-256-XTS)
•    Bitlocker for disk encryption on Windows workstations (AES-256-XTS), based on TPM+PIN
•    Filevault 2 for disk encryption on MacOS workstations (AES-128-XTS)
•    Proxmox backup encryption (based on AES-256 GCM)
Physical access control is ensured by our hosting providers
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
YesWeHack allows users to export all programme data securely via the platform or API. Customers can retrieve vulnerability reports, remediation records, communications with ethical hackers, and audit logs in standard machine-readable formats (CSV, JSON). Exports can be filtered, sorted, and downloaded directly from the portal, or integrated into internal dashboards and ticketing systems via the API. A dedicated Customer Success Manager (CSM) supports the export process, ensuring completeness and accuracy. All exported data maintains integrity and is provided in a format suitable for audit, compliance, or migration purposes.
Data export formats
  • CSV
  • Other
Other data export formats
  • CSV
  • Via API
  • JSON
  • XLS
  • PDF
Data import formats
  • CSV
  • Other
Other data import formats
API

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks
Access to the web portal and API is exclusively via HTTPS. Cryptographic choices—including algorithms and parameters—follow state-of-the-art guidance from the French national cybersecurity agency (ANSSI) and widely adopted technologies, with updates monitored continuously. The ISMS defines encryption policies, covering levels, types, roles, responsibilities, and key management. Encryption is applied across the platform, internal network, and workstations: HTTPS (TLS ≥1.2) for web sessions, WireGuard for backbone tunnels, OpenVPN for employee VPNs, and OpenSSH for server access.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
YesWeHack protects data through layered encryption, network segmentation, and strict access control. All disks are encrypted, with keys securely managed internally. Data in transit is protected using TLS 1.2+ for web sessions and secure tunnels such as WireGuard, OpenVPN, and SSH for internal access. Firewalls and intrusion detection systems safeguard network boundaries. Administrative access is limited, authenticated, and logged. The Information Security Management System (ISMS) defines encryption, access, and monitoring policies aligned with ANSSI and ISO 27001 standards, ensuring confidentiality, integrity, and availability of customer data across all systems and environments.

Availability and resilience

Guaranteed availability
The YesWeHack platform is operational and accessible to customers 24 hours a day, 7 days a week, at least 99.7% of the time during a calendar year. Platform availability relies on OVHcloud private cloud solution in France which provides an SLA of 99.9% of availability.
Approach to resilience
YesWeHack is designed to ensure high availability and resilience across all services. Platform workloads run on SecNumCloud-qualified private cloud infrastructure, hosted in ISO 27001-certified European datacentres with robust DDoS protection. Critical servers are duplicated with load balancing or automatic failover to maintain service continuity in case of failure. Virtual machines and disks are encrypted, and system components are segregated across dedicated VMs and VLANs, limiting exposure.

A high-availability encrypted backbone network connects servers using WireGuard VPN tunnels with adaptive routing and failover capabilities. Access follows a zero-trust model, requiring individual authentication even within the internal network. Infrastructure is deployed via infrastructure-as-code and hardened following recognised security guidelines. All systems are monitored proactively, with logs collected and analysed via SIEM for rapid detection and response to incidents.

Application-level encryption ensures database and file-level data remains protected even in the event of a breach. Secure administration, automated patching, and continuous monitoring further reinforce resilience. Detailed information on datacentre architecture and resilience measures can be provided on request.
Outage reporting
YesWeHack minimises service disruption through formal incident and outage management processes. Our Incident Management Procedure assigns a lead incident manager (CISO, CTO, Head of IT, or Head of the Singapore office) based on incident type and impact, with a backup appointed for incidents lasting over eight hours.

For each incident, a management team is formed, including leads for IT infrastructure, development, customer success, legal, and external communications. Each lead coordinates their own team to ensure task allocation and clear information flow. For major incidents, a pyramidal structure supports uninterrupted operational work while maintaining streamlined communication. Dedicated channels help prevent overload during high-volume events.

Service performance is continuously monitored through Zabbix, Grafana, and BetterStack dashboards covering uptime, system performance, and capacity. Capacity reviews occur every six months with a 10% buffer to absorb unexpected demand. Critical systems are protected through redundant virtual machines, distributed backups, real-time database replication, and DDoS mitigation.

All production changes follow formal change management, including risk assessment, approvals, and controlled deployment via Infrastructure-as-Code and CI/CD pipelines. Historical logs and on-call rotations ensure rapid response and measurable performance. The platform’s status page is available at status.yeswehack.io, where users can subscribe to updates via email, RSS, or webhooks.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Other user authentication
Access to windows workstations as well as most services supporting SSO (either via SAML or LDAP) are based on a single nominative account provisioned in an active directory.  SSO authentication enforces MFA via push notification, which means users have to approve a notification popping on their smartphone (after entering password) to allow login. MFA specifically covers all systems handling sensitive data within the scope of our ISMS. Multi-factor authentication (TOTP) is available on our Bug Bounty platform for customer users and hunters.
Access restrictions in management interfaces and support channels
Access to Business Information is based upon the principle of least privilege - access to all systems, networks, services and information is forbidden, unless expressly permitted to individual users or groups of users. A user registration procedure for each system and service is mandatory and rights are assigned based on need-to-use and need-to-know principle. In addition, there is also a record of access tracking and authorization by name for each employee.
The YesWeHack administration portal is accessible only through VPN, and requires 2FA.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
YesWeHack follows a comprehensive Information Security Management System (ISMS) aligned with ISO/IEC 27001 and associated standards. The CISO leads security and privacy governance, coordinating with the executive committee, the Data Protection Officer, and departmental heads to ensure policies are applied. Day-to-day adherence is overseen by the CISO, CTO, and Head of IT.

All employees integrate security and privacy into projects from inception, with risk assessments documented throughout the lifecycle. Segregation of duties ensures sensitive actions are approved and executed by separate personnel. Access control is enforced via role-based permissions, SSO with multifactor authentication, and regular rights reviews.

YesWeHack maintains detailed policies on asset management, secure development, operations, human resources, supplier security, and business continuity. Security awareness is reinforced through regular training, communications, and exercises such as phishing campaigns. Incident management procedures allow rapid detection, response, and reporting of security events, including GDPR compliance.

Compliance, monitoring, and continual improvement are ensured via audits, performance metrics, and ongoing threat intelligence, while public bug bounty programs contribute to proactive vulnerability identification. External contacts with authorities and industry associations support up-to-date best practices and threat awareness.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
YesWeHack manages configuration and changes via a structured GitLab-based change management process, where all proposals are logged, assessed for security and privacy impacts, approved by IT leads, and tested before implementation. Infrastructure-as-Code (IaC) ensures consistent, hardened configurations across environments, tracked in version control to detect drift and facilitate recovery. Changes affecting production or security-critical systems require peer validation and managerial approval. Backups, monitoring, and logging support traceability throughout each component’s lifecycle. Vulnerabilities and patches are continuously monitored, assessed, and integrated into change requests to maintain secure, resilient, and compliant operations.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
YesWeHack operates a proactive vulnerability management process. Potential threats are continuously monitored through antimalware alerts, CERT-FR advisories, security mailing lists, and Attack Surface Management (ASM) tools integrated with CVE alerting. When a vulnerability is identified, a GitLab issue is created within 24 hours for risk assessment by the IT team or CISO. High-risk vulnerabilities are prioritized and patched through the formal change management process. Open-source components are regularly reviewed to ensure they remain supported and free from known vulnerabilities, with end-of-support reviews conducted every six months to maintain a secure, up-to-date infrastructure.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Workstation security are monitored with an EDR solution.
The IT infrastructure is monitored through centralized logs in a SIEM.
Response to security events is carried out through the incident management procedure, annexed to the ISMS. The procedure defines a classification of incidents, which determines the urgency of corrective actions.
Incident management type
Undisclosed
Incident management approach
YesWeHack maintains a comprehensive protective monitoring and incident management process. All potential compromises are reported to a central contact security@yeswehack.com and assessed by the incident manager. Events are classified and handled according to severity, with containment and remediation actions triggered immediately. In the event of a significant incident or data breach, affected customers and authorities are notified within 72 hours, in line with GDPR and NIS2 requirements. Continuous monitoring, regular incident response exercises, and “lessons learned” reviews ensure rapid detection, effective response, and ongoing improvement of security operations and threat management capabilities.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
3.0%
Between £250,000 and £500,000
5.0%
Between £500,001 and £1,000,000
7.0%
Between £1,000,001 and £2,500,000
9.0%
Between £2,500,001 and £5,000,000
10.0%
Over £5,000,001
12.0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Laboratoire national de métrologie et d’essais
ISO/IEC 27001 accreditation date
Monday 21 July 2025
What the ISO/IEC 27001 doesn’t cover
Services that are not delivered through the YesWeHack platform, organizational units and assets that are not involved in building and delivering the service/platform (eg. Finance, Marketing, Sales) and locations outside our main office premises in France and Singapore.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Eb04b7c7-9aee-4523-9c7c-b6c3932a559a
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
Yes
Any other security certifications
  • CREST membership
  • Cybervadis certificate

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@yeswehack.com. Tell them what format you need. It will help if you say what assistive technology you use.