Skip to main content

Help us improve the Digital Marketplace - send your feedback

ORACLE CORPORATION UK LIMITED

Oracle Cloud Infrastructure (OCI) - Functions (Serverless)

Oracle Cloud Infrastructure (OCI) Functions is a serverless platform for running code without infrastructure management, enabling automatic scaling, event-driven execution, and Oracle Cloud Infrastructure service integration.

Features

  • Managed serverless platform, open-source Fn Project.
  • Auto-scaling, no server management.
  • Support for multiple runtimes: Java, Python, Node.js, Go, more.
  • Invoke via HTTP, events, SDKs; integrate with API Gateway.
  • VCN-native private endpoints and policy-based network access controls.
  • Tight integrations with Object Storage, Streaming, Events, and Notifications.
  • Secure secrets and config via OCI Vault and environment variables.
  • Per-execution metrics, logs, and tracing with Monitoring and Logging.
  • CI/CD friendly: buildpacks, Docker images, and registries (OCIR).
  • Granular IAM policies, compartments, and tagging for governance.

Benefits

  • Run code without managing servers, patching, or capacity planning.
  • Reduce costs with scale-to-zero and per-execution billing efficiency.
  • Accelerate development using familiar languages and lightweight functions.
  • Integrate quickly with OCI services to build event-driven workflows.
  • Enhance security using private networking, IAM, and Vault-managed secrets.
  • Improve reliability through automatic scaling and fault-tolerant architecture.
  • Speed delivery with CI/CD automation and container-based packaging.
  • Gain visibility with built-in metrics, logs, and distributed tracing.
  • Simplify operations for microservices and backend API use cases.
  • Enable agile experimentation with rapid deployment and rollback capabilities.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at uk-publicsector_gb@oracle.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 7 6 4 1 4 0 6 7 8 3 1 5 4 9

Contact

ORACLE CORPORATION UK LIMITED Kevin Brayne
Telephone: +44 (0) 7876 262525
Email: uk-publicsector_gb@oracle.com

About your service

Service categories

IaaS

IaaS Compute

  • Container and serverless engine compute

Service scope

Service constraints
The default memory limit for function execution is 60GB per availability domain. To increase this limit, submit a service-limit-increase request.

Payload Size: The maximum request and response payload size for a function is 6MB.

CIDR Block Conflicts: Functions may fail to connect to virtual machines in subnets with a CIDR block of 172.17.0.0/16 due to IP address conflicts.

Configuration Parameter Size: Custom configuration parameters are limited to a combined size of 4 KB.

Concurrency Limits: OCI Functions automatically scales to handle multiple concurrent function invocations, up to memory limit specified for your tenancy.

The service is subject to eligibility requirements.
System requirements
  • OCI account with proper service permissions
  • Sufficient quotas for Functions and related resources
  • Supported region for function deployment
  • VCN with correct subnet and security lists
  • Function CLI and OCI CLI installed
  • Docker installed for building and deploying
  • Runtime code supports required programming languages
  • IAM policies for function creation and deployment
  • Required licenses for third-party libraries or code
  • Customer responsible for code and API security
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud

User support

Email or online ticketing support
Yes
Support response times
Response times are dependent on the severity of the request, as well as the level of support package purchased.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
The extent to which an Oracle product is, prior to any customizations, capable of providing comparable access to individuals with disabilities consistent with the applicable provisions of the Architectural and Transportation Barriers Compliance Board standards set out in 36 CFR Part 1194 Appendix A ('Revised Section 508') effective as of January, 2018 and Web Content Accessibility Guidelines (WCAG) 2.1 level AA, or 2.2 level AA, is indicated exclusively by the dependencies, comments and exceptions noted on the applicable Accessibility Conformance Report (ACR) based on the Voluntary Product Accessibility Templates (VPAT) available at www.oracle.com/accessibility for each product, when they are used in accordance with Oracle's associated documents and other written information, and provided that any assistive technologies and any other products used with them properly interoperate with them. In the event that no ACR is available for a particular Oracle product, Oracle makes no representations regarding accessibility. Oracle Support customers with disabilities may use the online My Oracle Support or call Oracle Support at 1.800.223.1711 telecommunications relay service (TRS), reference https://www.fcc.gov/file/15195/download (PDF). Oracle cannot make commitments about future product directions, including plans to address accessibility. Product direction remains at the sole discretion of Oracle.
Web chat accessibility testing
By policy, Oracle will not advocate for any testing tool, product or assistive technology over other similar tools and technologies. Oracle is familiar with various testing tools including but not limited to Axe-core, Wave, Site Improve, Lighthouse Etc., and Oracle is likewise familiar with many assistive technologies including but not limited to JAWS, NVDA, Dragon Naturally Speaking, Zoom Text, Orca, Voice Over, and Talkback.
Onsite support
Yes, at extra cost
Support levels
Oracle Cloud Infrastructure (OCI) offers several support levels to fit customer needs. All customers receive Basic (Essential) Support at no additional charge, which includes access to online documentation, community resources, and automated troubleshooting tools. For enhanced assistance, the Premier Support level provides 24/7 technical support for critical issues, faster response times, and access to cloud specialists. The cost of Premier Support is based on the customer’s cloud service expenditure and is typically calculated as a percentage of the annual cloud contract—contact Oracle Sales for precise pricing.

For customers who require personalized, proactive assistance, Advanced Customer Support (ACS) services are available for an additional fee. ACS includes access to dedicated Technical Account Managers (TAMs) or Cloud Support Engineers who deliver tailored guidance, proactive monitoring, and best practice recommendations to optimize cloud environments and manage complex deployments.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Oracle offers a comprehensive suite of resources to assist users in effectively utilizing Oracle Cloud Infrastructure (OCI):

Documentation: The OCI Documentation provides detailed guides, tutorials, and best practices for deploying and managing cloud services.
Oracle University: Through Oracle University , users can access training courses, certifications, and learning paths tailored to various OCI services, enhancing their cloud proficiency.
Oracle LiveLabs: LiveLabs offers hands-on labs and workshops, enabling users to practice deploying and managing applications on OCI in a controlled environment.
Reference Architectures: The Oracle Architecture Center provides validated reference architectures, offering blueprints for building secure and scalable applications on OCI.
OCI QuickStart: The OCI QuickStart repository on GitHub contains automated deployment scripts and templates, facilitating rapid provisioning of OCI resources and services.
These resources collectively support users in learning, deploying, and optimizing their cloud solutions on OCI.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
When a contract with Oracle Cloud Infrastructure (OCI) ends, users are responsible for extracting their data before service termination. Data can be exported via the web console, CLI, or APIs to local systems or external storage. Users can download object storage contents, export compute instance data, databases, and backups as needed (Exporting Data Documentation ). Oracle does not typically transfer or extract user data on behalf of the customer.
End-of-contract process
After contract termination, Oracle follows established data retention and deletion policies, and access to data may be removed. Users should ensure all necessary data is extracted, validated, and securely stored prior to the end of their contract. Details on data extraction capabilities are described in the OCI documentation and terms of service.

At the end of an Oracle Cloud Infrastructure (OCI) contract, access to cloud resources and services is terminated according to Oracle’s offboarding process. Users must extract all required data before the contract ends, as data may be deleted and recovery is not guaranteed (Data Termination Policy ). Included in the contract price are the provisioned OCI services, technical support as specified in your plan, and usage within your Universal Credits or pay-as-you-go agreement. Additional costs may apply for premium support tiers, excess resource consumption beyond contract limits, Advanced Customer Support, data egress above included quotas, or third-party integrations. For detailed terms, included services, and optional add-ons, refer to your service agreement, the OCI documentation , and the Universal Credits Guide . It is the customer’s responsibility to manage, extract, and retain any critical data before contract termination.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
The extent to which an Oracle product is, prior to any customizations, capable of providing comparable access to individuals with disabilities consistent with the applicable provisions of the Architectural and Transportation Barriers Compliance Board standards set out in 36 CFR Part 1194 Appendix A ('Revised Section 508') effective as of January, 2018 and Web Content Accessibility Guidelines (WCAG) 2.1 level AA, or 2.2 level AA, is indicated exclusively by the dependencies, comments and exceptions noted on the applicable Accessibility Conformance Report (ACR) based on the Voluntary Product Accessibility Templates (VPAT) available at www.oracle.com/accessibility for each product, when they are used in accordance with Oracle's associated documents and other written information, and provided that any assistive technologies and any other products used with them properly interoperate with them. In the event that no ACR is available for a particular Oracle product, Oracle makes no representations regarding accessibility. Oracle Support customers with disabilities may use the online My Oracle Support or call Oracle Support at 1.800.223.1711 telecommunications relay service (TRS), reference https://www.fcc.gov/file/15195/download (PDF). Oracle cannot make commitments about future product directions, including plans to address accessibility. Product direction remains at the sole discretion of Oracle.

Using the service

Web browser interface
Yes
Using the web interface
Users with appropriate permissions can perform various tasks using the Oracle Cloud Infrastructure (OCI) web interface, including:

Resource Management: Create, configure, and delete resources such as compute instances, databases, and networking components.
Monitoring and Analytics: Access dashboards and logs to monitor resource performance and usage metrics.
Security Configuration: Manage security settings, including Identity and Access Management (IAM) policies, user roles, and network security rules.
Billing and Cost Management: View billing information, set budgets, and analyze cost reports.

However, certain actions are restricted or not available through the web interface:

Advanced Configurations: Some complex configurations may require the use of the OCI Command Line Interface (CLI) or APIs.
Automated Scripting: Tasks requiring automation or scripting are better suited for the CLI or SDKs.
Third-Party Integrations: Integrating with external services or applications may necessitate API usage.
For detailed information on user capabilities and permissions, refer to the OCI Documentation.
Web interface accessibility standard
None or don’t know
How the web interface is accessible
The extent to which an Oracle product is, prior to any customizations, capable of providing comparable access to individuals with disabilities consistent with the applicable provisions of the Architectural and Transportation Barriers Compliance Board standards set out in 36 CFR Part 1194 Appendix A ('Revised Section 508') effective as of January, 2018 and Web Content Accessibility Guidelines (WCAG) 2.1 level AA, or 2.2 level AA, is indicated exclusively by the dependencies, comments and exceptions noted on the applicable Accessibility Conformance Report (ACR) based on the Voluntary Product Accessibility Templates (VPAT) available at www.oracle.com/accessibility for each product, when they are used in accordance with Oracle's associated documents and other written information, and provided that any assistive technologies and any other products used with them properly interoperate with them. In the event that no ACR is available for a particular Oracle product, Oracle makes no representations regarding accessibility. Oracle Support customers with disabilities may use the online My Oracle Support or call Oracle Support at 1.800.223.1711 telecommunications relay service (TRS), reference https://www.fcc.gov/file/15195/download (PDF). Oracle cannot make commitments about future product directions, including plans to address accessibility. Product direction remains at the sole discretion of Oracle.
Web interface accessibility testing
Oracle evaluates the OCI Functions (serverless) web interface using automated accessibility tools and manual assessments with assistive technologies, such as screen readers and keyboard-only navigation. User feedback from individuals with disabilities is considered to identify and address barriers, ensuring compliance with international accessibility standards and enhancing usability. These ongoing efforts reflect Oracle’s commitment to accessible and inclusive cloud services.
API
Yes
What users can and can't do using the API
OCI Functions (serverless) provides APIs for programmatic setup, deployment, and management of serverless functions. Users can set up the service by making authenticated API or SDK calls to create applications, deploy function code, configure triggers, and manage environment variables (Functions API Reference ). The API allows users to update, invoke, or delete functions; monitor execution status; and manage function-specific configurations and permissions.

However, API actions are governed by IAM policies, tenancy quotas, and supported regions. Some advanced features, such as setting up certain integrations, deep diagnostics, or new runtime options, may only be available via the OCI Console or after future API enhancements. The API does not support direct code editing (code must be built and deployed) or external scheduler setup inside the Functions API.

All actions must comply with OCI’s security and operational policies. For full details and the latest capabilities, consult the OCI Functions API documentation and Universal Credits Guide .
API automation tools
  • Ansible
  • Terraform
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
  • Other
Command line interface
Yes
Command line interface compatibility
Linux or Unix
Using the command line interface
The Oracle Command Line Interface (CLI) enables users to manage Oracle Functions by creating, deploying, and invoking serverless functions. Users can create applications, deploy functions using Docker images, and invoke them directly from the CLI. The CLI also supports listing and inspecting functions and applications.

However, the CLI does not provide interactive graphical interfaces or real-time monitoring dashboards. It requires users to input precise commands and parameters, which may have a steeper learning curve compared to the OCI Console.

To set up Oracle Functions, users install the Fn Project CLI, configure it with their OCI credentials, and execute commands to create applications and deploy functions. Changes are made by issuing specific commands to update configurations or redeploy functions.

The CLI is secured through authentication mechanisms, including API signing keys and IAM policies, ensuring that only authorized users can perform actions. Users must manage their credentials securely and adhere to OCI's security best practices to maintain a secure environment.

Scaling

Independence of resources
Oracle Cloud Infrastructure (OCI) isolates resources using dedicated compute shapes, virtual network segmentation, and enforced tenancy limits to prevent resource contention among users. Each tenant’s workloads run in isolated environments with guaranteed CPU, memory, and network allocations, ensuring consistent performance regardless of other users’ demand. OCI’s architecture uses physical and logical isolation to minimize “noisy neighbor” effects and enforces service quotas to protect against resource exhaustion.
Usage notifications
Yes
Usage reporting
  • API
  • Email
  • Other
Other usage reporting
In addition to API and email notifications, Oracle Cloud services provide usage alerts through the Oracle Cloud Console dashboard, where users can view real-time usage graphs, service limit statuses, and proactive banner warnings when approaching thresholds. Users can also configure custom alarms and dashboards to monitor quotas or consumption specifics and receive notifications through integrated third-party channels (such as PagerDuty, Slack, or ServiceNow) via Oracle’s Notifications service and webhooks. For account-wide quotas (including Universal Credits), summary alerts and recommendations for quota adjustments are displayed in the billing and usage interface. Oracle Support and account management teams may also contact users directly if sustained high usage or critical limits are detected, ensuring buyers have multiple, integrated channels to prevent unexpected service interruptions.
Optimising consumption
Yes
Automatic scaling
Yes

Analytics

Infrastructure or application metrics
Yes
Metrics types
  • CPU
  • Disk
  • HTTP request and response status
  • Memory
  • Network
  • Number of active instances
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Backup and recovery

What’s backed up
  • Function source code
  • Function configurations and environment variables
  • Application data from functions
  • Object Storage buckets for function data
  • API Gateway routing and access settings
  • Function execution logs
  • Performance and usage monitoring metrics
  • IAM policies for function access
  • Networking configurations for function connectivity
  • Dependencies (libraries, packages) used by functions
Backup controls
OCI Functions users control backups via the OCI Console, CLI, or APIs. They can manually create backups or configure automated backup policies for boot and block volumes, specifying frequencies (hourly, daily, weekly, or monthly) and retention periods. Users can apply different schedules for different volumes and resources as needed. Backup policies can be tailored to individual workloads for granular control.
Datacentre setup
Multiple datacentres with disaster recovery
Scheduling backups
Users schedule backups through a web interface
Backup recovery
  • Users can recover backups themselves, for example through a web interface
  • Users contact the support team
Backup and recovery
Yes
RPO/RTO
Yes

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Oracle Cloud Infrastructure (OCI) Functions (serverless) is designed to deliver high availability, backed by a formal Service Level Agreement (SLA). OCI guarantees a monthly uptime of at least 99.9% for the Functions service, ensuring users can deploy, manage, and invoke functions reliably. This SLA covers service accessibility and operational readiness, provided customers adhere to Oracle best practices for deployment, such as distributing functions across supported regions and monitoring usage.

If the guaranteed level of availability is not met, affected customers may be entitled to claim service credits. To initiate a claim, users must submit evidence of downtime or disruption as defined in the SLA policy, within the designated time frame. Approved credits are typically applied to future Oracle Cloud bills.

Detailed SLA definitions—including covered and excluded incidents, credit calculations, and step-by-step claim procedures—are outlined in the OCI Service Level Agreements documentation and supported by the Universal Credits Guide . Customers should refer to their own service agreement and these published SLA documents to confirm specific terms, regional applicability, and the process for receiving compensation.
Approach to resilience
Oracle Cloud Infrastructure (OCI) is architected for high resilience through its global network of regions, each containing multiple fault domains and availability domains (datacentres). This design enables workloads to withstand hardware failures, power outages, or network disruptions without loss of service. Data is replicated across fault and availability domains, and disaster recovery options are available for critical workloads. Redundant power, cooling, and network connectivity further enhance resilience. Automated failover, backup, and recovery features support business continuity.
Outage reporting
Oracle Cloud Infrastructure (OCI) reports outages and service status through multiple channels:

Public dashboard: OCI provides a real-time Service Health Dashboard where customers can view current and historical service status and outages by region and service.
API: Users can monitor service status and resource health programmatically via OCI Monitoring APIs (Monitoring Overview ).
Email alerts: Customers can configure alarms and notifications to receive email alerts for specific events, resource conditions, or incidents affecting their tenancy (Notifications Documentation ).

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
Access restrictions in management interfaces and support channels
Access to OCI Functions (serverless) management interfaces is enforced through Oracle Identity and Access Management (IAM), with authenticated users assigned granular, least-privilege roles and policies to control who can view, deploy, or manage functions. Multi-factor authentication (MFA) can be enabled for added security. Support interactions also require authentication, and all activities are logged for auditing and compliance.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
Devices users manage the service through
  • Dedicated device on a segregated network (providers own provision)
  • Dedicated device over multiple services or networks
  • Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
  • Directly from any device which may also be used for normal business (for example web browsing or viewing external email)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
  • Other
Other security governance standards
Other security governance standards include:
SOC 1, SOC 2, SOC 3, PCI DSS, FedRAMP, ISO/IEC 27701, BSI C5, IRAP, ENS, HIPAA, HITRUST, and ISO 9001.
Information security policies and processes
Oracle follows a comprehensive set of information security policies and processes aligned with international standards such as ISO/IEC 27001, SOC, and CSA CCM. These policies cover areas including data protection, access control, incident management, physical security, and employee training. Oracle’s Chief Information Security Officer (CISO) leads the global security program, reporting to executive leadership and ensuring oversight of all security initiatives.

Policies are enforced through regular audits, continuous monitoring, compliance checks, and mandatory security training for staff. Oracle’s internal controls are routinely reviewed to maintain certification with industry standards. Any incidents or non-compliance are reported through defined escalation paths, with corrective actions taken as needed.

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Oracle uses rigorous configuration and change management processes, tracking all service components throughout their lifecycle via asset management systems. Changes are logged, reviewed, and tested before implementation, with potential security impacts assessed through formal risk assessments and security reviews. Automated tools and manual checks verify configuration integrity and compliance with security baselines. Changes are only deployed after approval and, if necessary, staged rollouts are performed to minimize risk.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Oracle’s vulnerability management process includes continuous monitoring, regular scanning, and threat assessment using internal expertise and industry threat intelligence feeds. Potential threats to services are evaluated through automated and manual vulnerability assessments. Security patches are prioritized and deployed promptly based on severity, with critical issues addressed as quickly as possible, often within Oracle’s published patching timelines. Oracle sources threat information from global security organizations, vendor alerts, and dedicated internal security teams.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Oracle employs continuous monitoring using automated security tools and advanced analytics to identify potential compromises, including suspicious activity, unauthorized access, or policy violations. When a potential compromise is detected, Oracle’s Security Operations Center (SOC) investigates immediately, leveraging incident response plans to contain, remediate, and report the incident. Incident response is prioritized based on severity, with rapid action for critical events, often initiating response within minutes.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Oracle has pre-defined incident management processes for common security and operational events, adhering to recognized standards. Users can report incidents through Oracle Support channels, including web portals and support tickets. Incidents are triaged, investigated, and remediated by Oracle’s dedicated incident response teams. Oracle provides affected customers with timely incident reports, status updates, and guidance as appropriate for the incident’s severity.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Separation between users

Virtualisation technology used to keep applications and users sharing the same infrastructure apart
Yes
Who implements virtualisation
Supplier
Virtualisation technologies used
KVM hypervisor
How shared infrastructure is kept separate
Oracle Cloud Infrastructure (OCI) ensures segregation of different organisations using a multi-tenant architecture with strong logical isolation. Each customer’s resources are separated by dedicated virtual networks (VCN), compartments, and enforced by robust Oracle Identity and Access Management (IAM) policies. Hypervisor- and hardware-level controls further isolate compute, storage, and networking. Security zones, data encryption, and per-tenant keys prevent cross-tenant data access. Regular compliance reviews validate the effectiveness of these controls.

Energy efficiency

Energy-efficient datacentres
Yes
Description of energy efficient datacentres
Oracle datacentres adhere to the EU Code of Conduct for Energy Efficient Datacentres by implementing advanced energy management strategies, optimizing cooling and power usage, and regularly monitoring energy consumption. Oracle utilizes best practices such as energy-efficient hardware, hot/cold aisle containment, advanced cooling technologies, and optimized power distribution to reduce environmental impact. Data centre operations are subject to continuous improvement, focusing on maximizing Power Usage Effectiveness (PUE) and adopting renewable energy where possible. Oracle publicly reports on sustainability goals and data centre efficiency, aligning with industry standards and the EU Code of Conduct principles.

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Oracle Cloud Infrastructure (OCI) Functions is included in the Always Free tier. However, the Always Free tier has limitations compared to the paid service, such as reduced resource allocations and potential restrictions on concurrent executions. For detailed information on these limitations, please refer to the OCI documentation.
Link to free trial
https://www.oracle.com/cloud/free/

Discount

Provide your minimum discount applicable to your baseline prices
0%

Formula for calculating price of your services

Formula for calculating price of your services

Which of the core deployment models you intend to offer

Public Cloud

Public Cloud - Formula for calculating price of your services


Total Cost
The Total Cost for a buyer's call off requirement in a Public Cloud Deployment
=
Baseline Pricing
Base line pricing will be provided as part of our submission. You can also access a dynamic online price list (link provided)
Baseline Pricing - Web link
https://oracle.sharepoint.com/sites/External-g-cloud15_framework
-
Minimum Discounting
0%
+
Onboarding Activity
Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
+
Additional sources of cost
Cloud consumption costs are as per the baseline pricelist provided. Any additional services / implementation / support / consulting etc will be priced on request.
-
Additional sources of cost reduction
Volume based discounts may be available subject to eligibility requirements.

Mandatory certifications

Mandatory certifications

Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure

Sole Control of the Infrastructure

ISO 9001 certification

Provided

ISO 14001 certification

Provided

ISO 27001 certification

Provided

ISO 20000-1 certification

Provided

ISO 27017 certification

Provided

Are you bidding to provide services under Lot 1b or both Lot 1a and Lot 1b?

Yes

ISO 27018 certification

Provided

Cyber Essentials

Do you have a Cyber Essentials Plus certificate?
Yes
Cyber Essentials Plus certificate Number
9eaf816b-1b1a-49dd-a804-da81c5c21ed7

Non-mandatory Standards and certifications

ISO 28000:2022 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
Yes
CSA STAR accreditation date
Friday 31 May 2024
CSA STAR certification level
Level 2: CSA STAR Attestation
What the CSA STAR doesn’t cover
The CSA STAR certification applies to the core OCI infrastructure and standard cloud services. Customer-managed applications, custom integrations, or third-party services running on OCI may not be covered; refer to OCI compliance documentation for full scope.
PCI certification
Yes
Who accredited the PCI DSS certification
Accredited by a Qualified Security Assessor (QSA)
PCI DSS accreditation date
Wednesday 11 January 2023
What the PCI DSS doesn’t cover
Services not classified as PCI-in-scope by Oracle’s Attestation of Compliance (such as customer-managed configurations, third-party/non-Oracle SaaS, etc.) are excluded; refer to current AoC.
Other security certifications
Yes
Any other security certifications
  • ISO 27001
  • ISO 27701
  • SOC 1 Type II
  • SOC 2 Type II
  • SOC 3
  • FedRAMP (for government cloud regions)
  • IRAP (Australia)
  • ENS High (Spain)
  • BSI C5 (Germany)
  • HITRUST (Healthcare-specific

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Volunteering opportunities for staff
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Plans for positive actions with community groups.
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at uk-publicsector_gb@oracle.com. Tell them what format you need. It will help if you say what assistive technology you use.