Bug Bounty Program: Security Penetration Testing and Vulnerability Disclosure Platform
Crowdsourced penetration testing through a managed Bug Bounty service connecting UK public sector organisations with vetted ethical hackers to surface and evaluate critical vulnerabilities. The platform enables continuous testing, outcome-based rewards, provides in-house triage and complies with government-backed security standards, including ISO 27001 and GDPR.
Features
- Continuous or time-bound security testing & live vulnerability reporting
- Global community of vetted whitehats, for maximum breadth/depth of skills
- Dedicated experts support customers throughout programs with continuous, high-quality triage.
- In-house reports, including bug reproduction & detailed analysis
- API & connectors integration - incl. Jira, GitHub and Slack
- Live dashboards & analytics for easy program & report tracking
- Self-generation of PDF, audit-ready, executive summaries, aligned to compliance requirements
- Secure teams collaboration workspace through highly granular access rights management
- VPN & User-Agent for clear visibility & control over programs
- Supports unlimited users, programs, with flexible and unlimited managed scopes
Benefits
- Time-to-detect reduction (= find vulnerabilities faster, as they emerge)
- Ongoing testing coverage (versus annual, time-bound) aligned to IT releases
- In-depth security through discovery of complex & critical vulnerabilities
- Testing controls: flexibility in terms of start, stop and pausing
- Testing of "exotic" tech stacks (not covered by traditional pentesters)
- Easy prioritisation of reports remediation based on actual risks
- Time-to-fix reduction through ticket creation or integration into existing tools
- Systematic vulnerabilities fix-check for security assurance
- Facilitated teams & cross-department collaboration – and ethical hackers
- Clear observability & easy reporting over testing & vulnerability management
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 3 9 4 8 4 7 2 3 8 3 8 2 2 9
Contact
Yes We Hack SAS
Sam Lowe
Telephone: 07342132662
Email: gcloud@yeswehack.com
About your service
- Service categories
-
Systems Infrastructure Software
Security
- Cloud native application protection platform
- Security analytics
- Governance, risk and compliance
Network security
- Active application security
Data security
- Information protection
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- YesWeHack does not operate regular planned maintenance or outage windows. Any scheduled maintenance expected to exceed 30 minutes is communicated to clients at least 24 hours in advance via email and the public status page. Support is not available at weekends.
- System requirements
-
- Browser versions – Modern browsers (Chrome, Edge, Firefox)
- Internet access – Active connection required.
User support
- Email or online ticketing support
- Yes
- Support response times
- Customer support is provided Monday to Friday, from 08:00 to 17:00 UK local time, through teams based in France, Singapore, and Canada. Each customer has a dedicated Customer Success Manager (CSM) as their main point of contact. However, urgent requests sent to csm@yeswehack.com can be handled by any available team member. Responses are typically provided within the same business day. While no formal SLAs are in place, standards are maintained through established processes and resourcing. In exceptional cases, an emergency contact route can be activated. Support is not available at weekends.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Support is included with all subscriptions and provides access to our secure online portal, during business hours (Monday–Friday, 8:00–18:00 UK time). All communications with ethical hackers (“hunters”) are accessible through individual hunter profiles in the portal.
A dedicated Customer Success Manager (CSM) is assigned to plan, build, and manage the testing programme, coordinate teams, and provide ongoing guidance.
A Triage Team also included, validates and prioritises submitted reports, ensuring only actionable findings are sent to your internal teams.
All interactions, findings, and remediation guidance are tracked in the portal with full audit history, ensuring clear visibility and accountability. Support is designed to integrate seamlessly with your internal teams, workflows, and compliance requirements. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
YesWeHack provides a structured onboarding process to ensure customers can deploy and manage their vulnerability disclosure or bug bounty programmes efficiently and securely.
Each new customer is supported by a dedicated Customer Success Manager (CSM) who guides them through setup, scope definition, and programme launch. The CSM works alongside the customer’s security and development teams to align the testing approach with organisational objectives, compliance requirements, and internal workflows.
Comprehensive online (teams/zoom) training and user documentation are provided, including step-by-step guides, best-practice templates, and instructional videos covering platform navigation, triage processes, and communication with ethical hackers. Live onboarding sessions and remote workshops are available for teams requiring deeper technical or operational guidance.
YesWeHack also supports integration setup with common tools (e.g., Jira, GitLab, GitHub) and helps configure automation via the API. Continuous support from the triage team and CSM ensures a smooth transition from onboarding to active programme management.
All onboarding materials are updated regularly to reflect platform enhancements and evolving security best practices. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Powerpoint
- End-of-contract data extraction
-
YesWeHack ensures that customers can securely extract all relevant data at the end of a contract. Customers have full access to export programme data, including vulnerability reports, remediation records, communications with ethical hackers, and audit logs, via the platform’s secure portal or API. Data can be exported in common readable formats to support internal record-keeping.
Using the API integration, you can integrate across your chosen internal bug tracker e.g. Jira / Service now etc.
A dedicated Customer Success Manager (CSM) assists with the extraction process, ensuring all necessary data is retrieved in a complete and organised manner. Where required, the triage team can provide support in consolidating historical reports and associated evidence. - End-of-contract process
-
At the end of a YesWeHack contract, customers are supported through a structured offboarding process to ensure secure closure and continuity. Included in the contract price is the complete extraction of all programme data, including vulnerability reports, remediation logs, communications with ethical hackers, and audit trails. Data can be exported via the secure portal or API in standard formats (CSV, JSON).
A dedicated Customer Success Manager (CSM) assists with the process, ensuring all data is accessible, organised, and any questions regarding historical reports or evidence are addressed. The triage team can provide support for consolidating and validating findings if required. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- YesWeHack’s service is accessible via mobile and desktop browsers. The mobile interface provides the core functionality, including viewing and acknowledging reports, accessing hunter communications, and monitoring remediation progress. Some advanced features, such as detailed analytics dashboards and bulk report management, are optimised for desktop use due to screen size and interaction complexity. Mobile access ensures on-the-go visibility and timely response to findings, while desktop remains the preferred environment for planning, configuration, and in-depth analysis. All interactions are secure and synchronized across devices in real time.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- YesWeHack provides a secure, web-based service interface accessible via desktop and mobile browsers. The interface offers a clear dashboard for managing programmes, tracking vulnerabilities, and communicating with ethical hackers. Users can view, triage, and prioritise reports, access remediation guidance, and generate audit-ready reports. Role-based access ensures users see only relevant data, while interactive analytics and visualisations help monitor trends and progress. The interface supports real-time updates, secure messaging, and integration with existing workflows and tools, providing a seamless experience for programme management and collaborative security testing.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
• Our service interface is designed and evaluated with accessibility in mind, following the WCAG 2.1 AA guidelines as our reference standard. Accessibility is considered from the early design stages through to development and qualification.
• In design, we rely on an accessible design system and use tools such as Stark for Figma to check color contrast and text legibility. During development, accessibility verification is progressively integrated into automated testing workflows.
• Manual checks are also performed regularly. These include keyboard navigation tests, especially on forms, to ensure usability without a mouse. For broader validation, we use tools like Lighthouse (Chrome) and the Firefox Accessibility Inspector to detect potential issues across the interface.
• Although we have not yet conducted user testing with assistive technologies, our current practices aim to make the platform accessible to users relying on screen readers and other assistive tools. - API
- Yes
- What users can and can't do using the API
-
Reports can be securely retrieved, filtered, and exported through the platform or API, with remediation statuses updated automatically for live synchronisation between YesWeHack and internal systems. Users can relay validated vulnerability reports directly into issue trackers or bug management tools, maintaining a single source of truth.
YesWeHack’s secure REST API integrates seamlessly with CI/CD pipelines, ticketing systems (Jira, GitLab, GitHub), and internal dashboards, enabling automated workflows, continuous visibility of security findings, and faster collaboration between security and development teams. Users can set up the service by creating an API App (with name, domain, redirect URI) to obtain OAuth2 credentials or generate a Personal Access Token (PAT) if their role permits. Changes can be made by calling the platform’s REST endpoints (POST/PUT/PATCH/DELETE) using OAuth tokens or PATs, applying updates according to account and program permissions.
Limitations include role-based restrictions on PAT creation and certain actions, the need for correctly registered API Apps, and endpoint-specific permission and rate limits. Full configuration details and API usage examples are provided in the YesWeHack Help Centre. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
YesWeHack allows extensive customisation so organisations can tailor their security testing programmes to meet specific operational, compliance, and risk management needs.
Authorised administrators can customise programme settings, including scope definitions, testing environments, timelines, reward models, and vulnerability disclosure policies. Buyers can define rules of engagement, specify in-scope and out-of-scope assets, and adjust severity scoring to align with internal risk frameworks.
Through the management portal or API, users can configure integrations with third-party tools such as Jira, GitLab, GitHub, or ServiceNow, enabling automatic ticket creation and synchronised remediation tracking. Dashboards and reporting views can be personalised by role or team to display key metrics, trends, and programme performance.
Customisation privileges are limited to approved administrators and Customer Success Managers (CSMs), ensuring governance, consistency, and compliance. Ethical hackers (“hunters”) only interact within predefined programme parameters and cannot alter configurations.
Scaling
- Independence of resources
- YesWeHack ensures consistent service quality through dedicated resources and workload management. Each customer is supported by an assigned Customer Success Manager (CSM) who oversees programme planning and performance. The triage team operates with scalable capacity, ensuring reports are validated and prioritised without delay, even during peak activity. Work is distributed across qualified analysts to maintain turnaround times. Resource allocation is continuously monitored to prevent overload and ensure customers receive the same high standard of responsiveness, communication, and report quality regardless of overall platform demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- YesWeHack provides comprehensive metrics to help organisations measure and improve their security performance. Key service metrics include the number of vulnerabilities reported, validated, and resolved; average time to triage and remediate; vulnerability severity distribution; and programme participation rates. Custom dashboards display trends over time, team responsiveness, and overall risk reduction. Administrators can export metrics for internal reporting or integrate them with existing dashboards via API. Metrics support governance, compliance, and continuous improvement of security posture.
- Reporting types
-
- API access
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
Encryption algorithms used at rest:
• PHP defuse for application-level encryption (with AES-256-CTR) .
• vSphere virtual machine encryption on the SecNumCloud-qualified private IaaS (AES-256-XTS)
• Luks 2 for disk encryption on Linux servers and workstations (AES-256-XTS)
• Bitlocker for disk encryption on Windows workstations (AES-256-XTS), based on TPM+PIN
• Filevault 2 for disk encryption on MacOS workstations (AES-128-XTS)
• Proxmox backup encryption (based on AES-256 GCM)
Physical access control is ensured by our hosting providers - Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- YesWeHack allows users to export all programme data securely via the platform or API. Customers can retrieve vulnerability reports, remediation records, communications with ethical hackers, and audit logs in standard machine-readable formats (CSV, JSON). Exports can be filtered, sorted, and downloaded directly from the portal, or integrated into internal dashboards and ticketing systems via the API. A dedicated Customer Success Manager (CSM) supports the export process, ensuring completeness and accuracy. All exported data maintains integrity and is provided in a format suitable for audit, compliance, or migration purposes.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- CSV
- Via API
- JSON
- XLS
- Data import formats
-
- CSV
- Other
- Other data import formats
- API
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- Access to the web portal and API is exclusively via HTTPS. Cryptographic choices—including algorithms and parameters—follow state-of-the-art guidance from the French national cybersecurity agency (ANSSI) and widely adopted technologies, with updates monitored continuously. The ISMS defines encryption policies, covering levels, types, roles, responsibilities, and key management. Encryption is applied across the platform, internal network, and workstations: HTTPS (TLS ≥1.2) for web sessions, WireGuard for backbone tunnels, OpenVPN for employee VPNs, and OpenSSH for server access.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- YesWeHack protects data through layered encryption, network segmentation, and strict access control. All disks are encrypted, with keys securely managed internally. Data in transit is protected using TLS 1.2+ for web sessions and secure tunnels such as WireGuard, OpenVPN, and SSH for internal access. Firewalls and intrusion detection systems safeguard network boundaries. Administrative access is limited, authenticated, and logged. The Information Security Management System (ISMS) defines encryption, access, and monitoring policies aligned with ANSSI and ISO 27001 standards, ensuring confidentiality, integrity, and availability of customer data across all systems and environments.
Availability and resilience
- Guaranteed availability
- The YesWeHack platform is operational and accessible to customers 24 hours a day, 7 days a week, at least 99.7% of the time during a calendar year. Platform availability relies on OVHcloud private cloud solution in France which provides an SLA of 99.9% of availability.
- Approach to resilience
-
YesWeHack is designed to ensure high availability and resilience across all services. Platform workloads run on SecNumCloud-qualified private cloud infrastructure, hosted in ISO 27001-certified European datacentres with robust DDoS protection. Critical servers are duplicated with load balancing or automatic failover to maintain service continuity in case of failure. Virtual machines and disks are encrypted, and system components are segregated across dedicated VMs and VLANs, limiting exposure.
A high-availability encrypted backbone network connects servers using WireGuard VPN tunnels with adaptive routing and failover capabilities. Access follows a zero-trust model, requiring individual authentication even within the internal network. Infrastructure is deployed via infrastructure-as-code and hardened following recognised security guidelines. All systems are monitored proactively, with logs collected and analysed via SIEM for rapid detection and response to incidents.
Application-level encryption ensures database and file-level data remains protected even in the event of a breach. Secure administration, automated patching, and continuous monitoring further reinforce resilience. Detailed information on datacentre architecture and resilience measures can be provided on request. - Outage reporting
-
YesWeHack minimises service disruption through formal incident and outage management processes. Our Incident Management Procedure assigns a lead incident manager (CISO, CTO, Head of IT, or Head of the Singapore office) based on incident type and impact, with a backup appointed for incidents lasting over eight hours.
For each incident, a management team is formed, including leads for IT infrastructure, development, customer success, legal, and external communications. Each lead coordinates their own team to ensure task allocation and clear information flow. For major incidents, a pyramidal structure supports uninterrupted operational work while maintaining streamlined communication. Dedicated channels help prevent overload during high-volume events.
Service performance is continuously monitored through Zabbix, Grafana, and BetterStack dashboards covering uptime, system performance, and capacity. Capacity reviews occur every six months with a 10% buffer to absorb unexpected demand. Critical systems are protected through redundant virtual machines, distributed backups, real-time database replication, and DDoS mitigation.
All production changes follow formal change management, including risk assessment, approvals, and controlled deployment via Infrastructure-as-Code and CI/CD pipelines. Historical logs and on-call rotations ensure rapid response and measurable performance. The platform’s status page is available at status.yeswehack.io, where users can subscribe to updates via email, RSS, or webhooks.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- Access to windows workstations as well as most services supporting SSO (either via SAML or LDAP) are based on a single nominative account provisioned in an active directory. SSO authentication enforces MFA via push notification, which means users have to approve a notification popping on their smartphone (after entering password) to allow login. MFA specifically covers all systems handling sensitive data within the scope of our ISMS. Multi-factor authentication (TOTP) is available on our Bug Bounty platform for customer users and hunters.
- Access restrictions in management interfaces and support channels
-
Access to Business Information is based upon the principle of least privilege - access to all systems, networks, services and information is forbidden, unless expressly permitted to individual users or groups of users. A user registration procedure for each system and service is mandatory and rights are assigned based on need-to-use and need-to-know principle. In addition, there is also a record of access tracking and authorization by name for each employee.
The YesWeHack administration portal is accessible only through VPN, and requires 2FA. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
YesWeHack follows a comprehensive Information Security Management System (ISMS) aligned with ISO/IEC 27001 and associated standards. The CISO leads security and privacy governance, coordinating with the executive committee, the Data Protection Officer, and departmental heads to ensure policies are applied. Day-to-day adherence is overseen by the CISO, CTO, and Head of IT.
All employees integrate security and privacy into projects from inception, with risk assessments documented throughout the lifecycle. Segregation of duties ensures sensitive actions are approved and executed by separate personnel. Access control is enforced via role-based permissions, SSO with multifactor authentication, and regular rights reviews.
YesWeHack maintains detailed policies on asset management, secure development, operations, human resources, supplier security, and business continuity. Security awareness is reinforced through regular training, communications, and exercises such as phishing campaigns. Incident management procedures allow rapid detection, response, and reporting of security events, including GDPR compliance.
Compliance, monitoring, and continual improvement are ensured via audits, performance metrics, and ongoing threat intelligence, while public bug bounty programs contribute to proactive vulnerability identification. External contacts with authorities and industry associations support up-to-date best practices and threat awareness. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- YesWeHack manages configuration and changes via a structured GitLab-based change management process, where all proposals are logged, assessed for security and privacy impacts, approved by IT leads, and tested before implementation. Infrastructure-as-Code (IaC) ensures consistent, hardened configurations across environments, tracked in version control to detect drift and facilitate recovery. Changes affecting production or security-critical systems require peer validation and managerial approval. Backups, monitoring, and logging support traceability throughout each component’s lifecycle. Vulnerabilities and patches are continuously monitored, assessed, and integrated into change requests to maintain secure, resilient, and compliant operations.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- YesWeHack operates a proactive vulnerability management process. Potential threats are continuously monitored through antimalware alerts, CERT-FR advisories, security mailing lists, and Attack Surface Management (ASM) tools integrated with CVE alerting. When a vulnerability is identified, a GitLab issue is created within 24 hours for risk assessment by the IT team or CISO. High-risk vulnerabilities are prioritized and patched through the formal change management process. Open-source components are regularly reviewed to ensure they remain supported and free from known vulnerabilities, with end-of-support reviews conducted every six months to maintain a secure, up-to-date infrastructure.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Workstation security are monitored with an EDR solution.
The IT infrastructure is monitored through centralized logs in a SIEM.
Response to security events is carried out through the incident management procedure, annexed to the ISMS. The procedure defines a classification of incidents, which determines the urgency of corrective actions. - Incident management type
- Undisclosed
- Incident management approach
- YesWeHack maintains a comprehensive protective monitoring and incident management process. All potential compromises are reported to a central contact security@yeswehack.com and assessed by the incident manager. Events are classified and handled according to severity, with containment and remediation actions triggered immediately. In the event of a significant incident or data breach, affected customers and authorities are notified within 72 hours, in line with GDPR and NIS2 requirements. Continuous monitoring, regular incident response exercises, and “lessons learned” reviews ensure rapid detection, effective response, and ongoing improvement of security operations and threat management capabilities.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 3.0%
- Between £250,000 and £500,000
- 5.0%
- Between £500,001 and £1,000,000
- 7.0%
- Between £1,000,001 and £2,500,000
- 9.0%
- Between £2,500,001 and £5,000,000
- 10.0%
- Over £5,000,001
- 12.0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Laboratoire national de métrologie et d’essais
- ISO/IEC 27001 accreditation date
- Monday 21 July 2025
- What the ISO/IEC 27001 doesn’t cover
- Services that are not delivered through the YesWeHack platform, organizational units and assets that are not involved in building and delivering the service/platform (eg. Finance, Marketing, Sales) and locations outside our main office premises in France and Singapore.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Eb04b7c7-9aee-4523-9c7c-b6c3932a559a
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
-
- CREST membership
- Cybervadis certificate
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-