Informatica IDMC Cloud Data Integration and Engineering, Data Ingestion and Replication
Informatica's Cloud Data Integration service enables low code scalable data integration across cloud and on premise systems. It automates data engineering workflows and ingestion pipelines, supports real time and batch processing, and data quality, empowering businesses to transform data for analytics, applications, and decision making using cloud datalakes and warehouses.
Features
- Ingest data with high-performance ELT/ETL, data replication, change data capture
- Low-code advanced integration using cloud-based designer tool for developers, citizen-integrators
- Data replication wizards for ingesting databases, applications, files, streaming data
- Integrated data quality to profile, cleanse, standardise and enrich data
- AI-enabled intelligent structure discovery to handle structured and unstructured data
- AI-powered auto-scaling of big data compute resources and optimisation engine
- Multi-cloud support to optimise AWS, Azure, Google, Snowflake, Databricks workloads
- Integrated data catalogue to search, access and understand enterprise data
- Integrate data with ETL pushdown, Spark or managed serverless options
- 200+ application, database, warehouse, datalake, storage, messaging, SaaS, API connectors.
Benefits
- Accelerate migration and modernisation of on-premise workloads to Cloud
- Lower TCO with automated cost control and intelligent optimisation engine
- Single platform approach for integration reduces complexity of multiple tools
- Automate routine tasks with low-code/no-code tools, reducing time and resources
- Operationalise AI into business processes to eliminate data silo fragmentation.
- Visibility of workloads, auto-tuning to optimise and govern Cloud costs
- Enable citizen integrators to build, monitor enterprise-scale Integrations without coding
- Improve productivity with AI-powered recommendations for source datasets and transformations
- Streamlined DevOps and DataOps with serverless deployment for lower TCO
- Easily connect to databases, data lakes, on-premise and SaaS applications
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 9 2 5 8 9 3 1 9 2 9 6 8 3 7
Contact
Agile
Henrietta Malpass
Telephone: 07951 162448
Email: tenders@agile.co.uk
About your service
- Service categories
-
Application Development and Deployment
Data management
Database administration and development
- Database Replication
Data integration and intelligence
- Data Ingestion and Transformation Software
- Dynamic Data Movement Software
- Data Quality Software
- Data Access Infrastructure Software
- Composite Data Framework Software
- Data Archiving and Information LifD-Cycle Management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Informatica's Cloud services can be used standalone or as part of the Informatica Intelligent Data Management Cloud (IDMC) platform. E.g. you only consume the specific services required for Data Integration, API & Application Integration, Data Quality, Master Data Management, Data Governance & Catalog, Data Marketplace and Data Access Management.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- IDMC provides automated monthly patches and 3-4 upgrades a year. Customers are notified of upgrade schedules about 6 weeks in advance and receive details on what's in each new release. We also provide a sandbox (pre-release) environment for the customer to try out the new release. Production upgrades typically occur on weekends, lasting 2-4 hours depending on the Point of Delivery (PoD) and nature of the upgrade. The only customer installable component is the Secure Agent, used for data communications.
- System requirements
-
- Secure agent installed on 64-bit Windows or Linux.
- 4 CPU cores (logical processors) at least.
- RAM: Minimum 16GB, 32GB recommended.
- Disk Space: 250 GB total volume.
- Connectivity: Internet access for secure outbound communication (port 443).
User support
- Email or online ticketing support
- Yes
- Support response times
-
Premium Success offers unlimited advanced support services to meet complex business requirements. The Premium Success program delivers 24x7 web + telephone access to support staff globally for critical issues and provides access to resources to accelerate success.
Initial response P1 – 1 hour, P2 – 4 hours
Signature Select offers all the features of premium success and proactive support services for mission-critical deployments. It is recommended for large-scale enterprises where performance and latency are key. Benefits include 24x7 access for all issues and prioritised emergency bug fixes.
Initial response P1 – 30 mins., P2 – 2 hours - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 A
- Web chat accessibility testing
- The Informatica Communities / Network is partially WCAG 2.2 compliant at this time. We include the new AgentForce chat feature from Salesforce which is following WCAG standards. Salesforce ensures that its products, including Agentforce chat in the Support Cloud, meet the Web Content Accessibility Guidelines (WCAG) 2.2 standards. Salesforce has a dedicated accessibility support team that validates WCAG 2.2 AA compliance for out-of-the-box features in Sales, Service, and Industry Clouds. This team includes experts with certifications such as Salesforce Cloud Consultant/Developer, DHS Trusted Tester, and IAAP CPACC, WAS, or CPWA.
- Onsite support
- Yes, at extra cost
- Support levels
-
For Informatica projects, Agile provides professional services support, delivered through a flexible mix of onsite and remote services. Support resources work side-by-side with client teams where appropriate, while also providing remote assistance to ensure continuity, responsiveness, and cost efficiency.
Support covers day-to-day operational assistance, incident investigation, platform administration, integration and API development support, performance tuning, release activities, and knowledge transfer. The balance between onsite and remote support can be adjusted over time to reflect delivery phase, service criticality, and client preferences.
Agile can deliver support either through fixed support packages or flexible professional services engagements. Fixed packages provide a predictable level of support and cost, while more tailored engagements are delivered in line with Agile’s Lot 3 professional services rates, typically on a retained or time-and-materials basis. Pricing remains indicative at this stage and is shaped by scope, service hours, and resource mix.
A named Technical Account Manager can be provided as a single point of contact, supported by Informatica-certified consultants and cloud integration engineers. Agile also coordinates directly with Informatica vendor support for escalation and specialist input where required. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Informatica offers online documentation and free onboarding modules available at the Informatica Success Portal. Informatica University also offers a variety of training options to meet your needs.
Informatica University Offers Role-based training programs ensure your organisation gets the most out of its investment in Informatica products:
Learn at your own pace with Online/Self-Paced Training with hands-on Labs – accessible 24/7. Supplement your existing skill set or flexibly and efficiently ramp new team members.
Learn with your industry peers in live, public instructor led Virtual classes. Engage in chats discussion, access hands-on environments and leverage class materials for a traditional learning experience.
Dedicated instructor focused on your needs on Private classes. Conducted live at your location or virtually. Experience a traditional learning experience via a standard course or tailored to meet your requirements.
Training Subscriptions, Unlimited access to curated training for a full year. Collections of Informatica Instructor Led and Self-Paced courses with hands-on labs and Certifications to instil the knowledge and skills needed for success.
Professional Certifications. Prove your skills and knowledge. Gain prestigious recognition while bringing increased value to your organisation and your career. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Tooltips or descriptions used directly in the user interface.
- End-of-contract data extraction
- All customer data can be exported from the environment at any stage, including when the contract ends. All customer data hosted by Informatica can be completely purged when the contract ends. On discontinuing the contract with Informatica, no data is retained on our infrastructure. Informatica employs NIST 800-88 standards for secure data destruction. Informatica will wipe all customer data from Informatica storage locations and upon request provide a certificate of deletion to the customer within 60 days. A Records Management Policy and Data Retention Schedule are in place to direct required actions in this area.
- End-of-contract process
- The customer's licenses on the organisation to access the service are removed and no users can access the application. Also, on discontinuing the contract with Informatica, no data is retained on our infrastructure.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- Yes
- Compatible operating systems
-
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Informatica offers an easy to use, web-based interface that is designed for business and IT users. The graphical user interface design provides a consistent look and feel across all Data Integration, Data Governance, Data Marketplace, Master Data Management, Data Quality and Data Access Management services tailored to user roles; with integrated capabilities between these services.
Browser-based clients leverage the accessibility features within the browser and within the users' operating systems. The Data Integration solution offers a drag and drop user interface for easy development of no-code data processing processes e.g. containing Data Quality rules. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
The platform's user interface undergoes a comprehensive accessibility validation process conducted by specialists to ensure conformance with Web Content Accessibility Guidelines (WCAG) 2.2 Level AA standards.
This process combines automated scanning tools with manual, functional testing using a representative set of common assistive technologies. The manual validation includes testing with industry-standard screen readers such as JAWS and NVDA, as well as system-native tools like VoiceOver. The evaluation also covers screen magnification software and confirms that all interactive elements and workflows are fully operable using only keyboard commands. This testing protocol is applied to all primary user workflows, navigation patterns, and interactive components within the service interface.
This rigorous, multi-layered testing approach is designed to identify and remediate potential barriers, ensuring the platform provides a functional and equitable experience for users who rely on assistive technologies. - API
- Yes
- What users can and can't do using the API
-
The platform provides a comprehensive set of REST APIs, enabling programmatic control over most data management functions for automation and integration.
Through the API, users can perform a wide range of actions:
Automate administrative tasks, including the management of users, roles, permissions, and connections.
Manage the complete lifecycle of data management assets, such as creating, deploying, and deleting data integration mappings, taskflows, and data quality rules.
Control job execution by initiating, scheduling, and monitoring tasks, as well as retrieving detailed logs and performance statistics.
Interact with the data catalog to search for assets, access metadata and lineage, and manage business glossaries.
The API is designed to manage the platform's services and assets, not the underlying infrastructure. Therefore, users cannot use the API to provision the cloud infrastructure, perform the initial installation of the Secure Agent runtime environment, or modify the platform's core internal code.
This API-first design allows for seamless integration into CI/CD pipelines and custom enterprise workflows. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The platform offers extensive customisation capabilities across its user interface, data processing logic, and metadata management, all governed by a granular security model.
What can be customized: Users can personalize dashboards and create custom reports. Core data management assets, including data integration mappings, taskflows, data quality rules, and business logic, are fully customizable. The data catalog can also be extended with custom attributes, business glossaries, and data domains to fit organizational standards.
How users can customise: Customisation is primarily achieved through browser-based, low-code graphical interfaces featuring drag-and-drop designers and configuration wizards. For automation and integration, a comprehensive set of REST APIs allows for programmatic management of assets. A rich expression language is also available for defining complex logic.
Who can customise: The ability to customise is determined by a role-based access control system. Administrators manage system-level configurations and user permissions. Users with specific roles, such as 'Designer' or 'Data Steward', are granted privileges to create and modify assets relevant to their functions.
Scaling
- Independence of resources
-
Customer environments are logically segregated by tenant and prevent users and customers from accessing resources not assigned to them.
Services are provided in virtualised operational environments to customers ensure that customers are segregated via security management processes/controls.
Informatica continuously monitors service usage to project infrastructure needs to support availability commitments/requirements. Informatica maintains a capacity planning model to assess infrastructure usage and demands at least monthly, and usually more frequently. Additionally, the Informatica capacity planning model supports the planning of future demands to acquire and implement additional resources based upon current resources and forecasted requirements.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service offers a wide range of metrics that include job status and execution statistics. Dashboards and visualisations are included to quickly assess the status and usage of your running services and deployed assets and take appropriate corrective actions as necessary. For example, you can view analytics related to running and completed jobs, API calls, processes, connections, and licensing consumption.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Informatica
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
In addition to physical controls and encryption, the platform's hybrid architecture provides a primary layer of protection. Customer business data is not stored at rest in the cloud; it remains within the customer's network, processed by a local Secure Agent.
Within the multi-tenant service, each customer's metadata is logically segregated to prevent cross-tenant access. Furthermore, all sensitive credentials, such as connection passwords and keys, are encrypted at rest in a secure vaulting system. This multi-layered approach provides comprehensive protection for all data associated with the service. - Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Data is exported by using the built-in export capabilities from within the service user interface. Users can select from available output formats and also select which available data they wish to export.
Note that the following types of data are stored within the platform's cloud environment:
Design and Operational Metadata, Catalog Metadata, User and Security Information, and
System Logs. Customer business data is not stored in the system. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- XML
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XML
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- The Informatica Intelligent Data Management Cloud (IDMC) services are hosted in one of 20+ Point of Delivery (PoD) locations globally - on AWS, Azure, GCP and Oracle Cloud. A UK PoD is supported for organisations requiring data sovereignty. If the buyer's network uses a protective firewall, a list of IP addresses for accessing the IDMC services PoD need to be whitelisted, ensuring that the Informatica Cloud Secure Agent and related services can connect to Informatica's servers to perform all necessary tasks. All data transmissions with the buyer's network are securely encrypted using HTTPs with further options for PrivateLink support.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
Informatica's Cloud Services use TLS certificates with 2048/256-bit keys, SSH, and IPsec protocols for data transmission and remote access over public networks, and AES encryption for transmission and for protecting the database containing Customer Data or Metadata. Encryption for all Web-enabled transactions that require user authentication or transfer of Customer Data is accomplished using one of the following methods: (a) TLS v1.2, (b) Secure Shell (SSH), (c) Secure File transfer protocol (SFTP), (d) Virtual Private Network (VPN), (e) PrivateLink connection.
Metadata scanners follow security models consistent with the SaaS applications, databases, web services and other data sources they connect to.
Availability and resilience
- Guaranteed availability
-
The platform provides a financially backed Service Level Agreement (SLA) that guarantees a monthly uptime percentage of at least 99.9% for its core cloud services.
This high level of availability is achieved through a resilient, fault-tolerant architecture deployed across multiple, geographically isolated Availability Zones. The design includes redundancy for all critical components and automated failover to prevent service disruptions.
If the monthly uptime percentage drops below the guaranteed 99.9% in any given monthly billing cycle, customers are eligible to receive a service credit. The credit is applied to a future invoice and is calculated as a percentage of the monthly subscription fee for the affected service. The specific percentage of the credit typically increases based on the severity of the availability shortfall, providing a tiered compensation structure for service disruptions. To receive a credit, a customer must submit a claim in accordance with the process outlined in the SLA documentation. - Approach to resilience
-
The platform is engineered for high availability and resilience through a fault-tolerant architecture designed to prevent service disruptions and data loss.
The service's infrastructure is deployed across multiple, geographically separate Availability Zones within a cloud provider's region. All critical components of the platform, including application services and metadata repositories, are designed with redundancy and operate in an active-active or active-passive configuration across these zones. Customer metadata is synchronously replicated across the zones to ensure it remains available and consistent.
The system employs automated health checks and failover mechanisms. If a component or an entire Availability Zone becomes unavailable, traffic is automatically rerouted to healthy instances in another zone without manual intervention. This design minimises single points of failure and is built to maintain continuous operation. For data processing, customers can configure Secure Agent groups to provide high availability and failover for jobs running within their own network, complementing the resilience of the cloud-hosted control plane. - Outage reporting
-
The platform provides transparent and proactive communication regarding service availability and outages through a dedicated public status page and subscription-based alerts.
The service's approach to reporting outages includes the following:
Public dashboard: Yes, there is a publicly accessible status page. This dashboard provides real-time operational status for all platform services, organized by regional instance or "pod." It displays current service health, details of any ongoing incidents, post-mortems of past incidents, and information about upcoming scheduled maintenance windows.
Email alerts: Yes, users can subscribe to notifications directly from the status page. This allows them to receive proactive email alerts tailored to the specific services and regional pods that are relevant to their organization.
API: Yes, the status page offers programmatic access through webhooks. This allows customers to integrate real-time service status updates directly into their own internal monitoring tools, dashboards, or incident management systems for automated alerting and response.
This multi-faceted approach ensures that customers have multiple ways to stay informed about the operational health of the services they rely on.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to the platform's management interfaces is restricted through a granular Role-Based Access Control (RBAC) model. Administrators assign users to roles with specific privileges, enforcing the principle of least privilege and ensuring users can only access the functions and data necessary for their duties.
For support channels, access to the Global Customer Support portal requires authentication as a registered and authorized contact. Support personnel do not have standing access to customer environments or data. If access is required for troubleshooting, it must be explicitly and temporarily granted by the customer, ensuring full customer control. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
-
SOC 2, Type II
FedRAMP
HIPPA - Information security policies and processes
-
Security is delivered through a combined approach covering Agile’s service delivery and Informatica’s software platform.
From a services perspective, Agile operates a risk-based Information Security Management System (ISMS) aligned to ISO/IEC 27001. The ISMS is governed with Board oversight and clear accountability across the organisation, including senior service sponsorship, formal governance, technical security management, and data protection oversight. Agile’s security controls cover risk assessment and treatment, access control (least-privilege, joiner/mover/leaver processes and regular reviews), encryption, secure development, supplier assurance, business continuity and incident management, and data breach notification. Policies are embedded through mandatory training, controlled documentation, monitoring, internal audits, management reviews, and corrective-action tracking. All staff are required to report security incidents or weaknesses promptly.
From a software vendor perspective, Informatica operates a comprehensive information security programme supported by an ISO/IEC 27001-certified ISMS, overseen by a Chief Information Security Officer (CISO). Security is integrated throughout Informatica’s Secure Software Development Lifecycle, including threat modelling, secure coding practices, and automated and manual testing such as independent penetration testing. The platform is subject to continuous vulnerability scanning, strict access controls with multi-factor authentication, and a tested incident response process. Controls are independently validated through external assurance, including SOC 2 Type II audits. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
The platform's configuration and change management processes are formally documented and audited under frameworks such as SOC 2 and ISO 27001.
All service components are tracked in a configuration management system throughout their lifecycle, from initial provisioning to final decommissioning.
Every proposed change to the production environment requires a formal change request. This process includes a mandatory security impact assessment conducted by the security team to identify and mitigate potential risks. Changes are only approved for deployment after successful testing and review, ensuring the continued stability and security of the service. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Informatica constantly scans its environment for recent publicized vulnerabilities that could affect its product offering to customers. Comprehensive vulnerability scans are performed monthly. Informatica's Patch management policy is a part of our configuration management policy. Patch management processes is in place to regularly and routinely update enterprise systems, applications, and network-connected devices. For Informatica's Cloud Solutions: Please refer to Informatica's Patching policy.
Informatica Enterprise Patching Standard: All critical and high vendor security patches are applied within thirty (30) days of the release date. All medium-rated security patches are applied within ninety (90) days of the release date. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
The platform employs a 24/7 protective monitoring program to safeguard the environment.
Potential compromises are identified through a combination of intrusion detection systems (IDS), security information and event management (SIEM) tools, and continuous analysis of system logs for anomalous activity. When a potential compromise is detected, an alert is triaged by the 24/7 security operations team. If validated, the formal Incident Response Plan is activated, which includes containment, eradication, and recovery steps. This process is designed for a timely response to all security incidents, initiating containment procedures immediately upon confirmation of a threat. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
The platform operates a formal incident management process governed by a documented Incident Response Plan.
This plan includes pre-defined procedures for responding to common security and operational events to ensure a consistent and timely response. Users report potential incidents by opening a support case through the Global Customer Support portal. Following the resolution of a significant incident, a post-mortem report is provided to affected customers. This report details the root cause, the actions taken to resolve the issue, and the measures implemented to prevent recurrence. These reports may be communicated directly or posted on the public status page. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- This includes some - but not all - of the Cloud Integration services, as well as the use of a Secure Agent to download, install and trial for 30 days. Trials of other IDMC services, can be provided on a case-by-case basis.
- Link to free trial
- https://www.informatica.com/trials.html
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 7%
- Between £250,000 and £500,000
- 11%
- Between £500,001 and £1,000,000
- 19%
- Between £1,000,001 and £2,500,000
- 29%
- Between £2,500,001 and £5,000,000
- 32%
- Over £5,000,001
- 34%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Thursday 8 January 2026
- What the ISO/IEC 27001 doesn’t cover
- Anything outside of The provision of data solutions and data management in accordance with the Statement of Applicability v1.4 23/06/2024. It doesn’t include solutions delivered by third parties or instances where we’re onboarded into client environments.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 422335d9-b0a0-4e1b-9ee8-d60349d0e15a
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 00129dda-1c1e-462f-bebc-c69ff3e67b57
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-