Microsoft Online Services and Agreements
Select your tailored Microsoft agreement from the complete range of Microsoft online services and software, such as ESA, SCE, CSP, MPSA, SPLA, and Open or EES.
Solutions include Modern Work, Cloud Productivity, Security, Dynamics, Azure, Copilot AI, Exchange, Windows and SQL Server.
Features
- Office 365: Productivity, email, Teams, collaboration platform.
- Enterprise Mobility: MDM, cybersecurity solutions.
- Windows 10/11: Information protection, Windows Hello.
- Archive: Legal hold, data leakage protection.
- Compliance Tools: Rights management, information protection.
- Online Meetings: Web-conferencing, voice, video, phone system.
- Single Sign-On: Cloud access.
- Social Networking: Corporate, analytics, PowerBI.
- Data Security Posture Management for AI (DSPM for AI)
- Data Security Investigations (DSI)
Benefits
- Office 365: Productivity, email, Teams, collaboration platform.
- Enterprise Mobility: MDM, cybersecurity solutions.
- Windows 10/11: Information protection, Windows Hello.
- Archive: Legal hold, data leakage protection.
- Compliance Tools: Rights management, information protection.
- Online Meetings: Web-conferencing, voice, video, PSTN.
- Cloud App Protection: Visibility, control, security.
- Office applications: Word, Excel, PowerPoint, SharePoint.
- Compliance Support: Information protection, privacy, GDPR.
- Corporate Networking: Social, analytics, PowerBI.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 2 5 5 4 0 6 5 0 7 8 8 2 6 3
Contact
BYTES SOFTWARE SERVICES LIMITED
Richard Read
Telephone: 01372 418 500
Email: tenders@bytes.co.uk
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Team collaboration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Any component parts can be stepped up
- Cloud deployment model
- Public cloud
- Service constraints
- Microsoft admins can view the status of services and find out when maintenance is scheduled. Service health information is available at any time by signing in. https://learn.microsoft.com/en-us/office365/servicedescriptions/office-365-platform-service-description/service-health-and-continuity
- System requirements
-
- Microsoft 365: Fully hosted, managed SaaS; no on-premises infrastructure needed.
- Cost-effective: Eliminates additional IT infrastructure for Onboarding system support.
- Accessibility: Use on any web-enabled device with modern internet browsers.
- Browser Compatibility: Supports Internet Explorer, Edge, Chrome, Safari.
- Mobile Availability: Native apps for Android and iOS devices provided.
User support
- Email or online ticketing support
- Yes
- Support response times
- Response times vary based on support plan selected. For more information, visit: https://www.microsoft.com/en-us/microsoft-365/business/microsoft-365-for-business-support-options
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Microsoft is committed to developing technology that empowers everyone, including people with disabilities. Microsoft has a Disability Answer Desk where customers with disabilities get support with Microsoft Office, Windows, and other products. Microsoft also has Accessibility Conformance Reports (ACR) which describe how products and services support recognized global accessibility standards.
https://www.microsoft.com/en-us/Accessibility/disability-answer-desk
https://www.microsoft.com/en-us/accessibility/conformance-reports
https://learn.microsoft.com/en-us/windows/apps/design/accessibility/accessibility-testing - Onsite support
- Yes, at extra cost
- Support levels
-
Microsoft provides four (4) Modern Work support plan options. These include the following:
- STANDARD (included for all customers)
- BUSINESS ASSIST
- PROFESSIONAL DIRECT
- MICROSOFT UNIFIED
For more information, visit https://www.microsoft.com/en-us/microsoft-365/business/microsoft-365-for-business-support-options - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Microsoft provides all Modern Work customers with 24/7 self-help resources, including Microsoft Learn, training documentation, templates, and community support. For more information, visit:
- https://learn.microsoft.com/en-us/microsoft-365/
- https://support.microsoft.com/en-us/training
- https://adoption.microsoft.com/en-us/customer-hub/
- https://support.microsoft.com/en-us/modernworkplace - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
When the contract ends, your access to Modern Work services, applications, and customer data go through multiple stages before the subscription is fully turned off, or deleted:
1. Expired Stage (30 days): Users have normal access to Modern Work applications and files.
2. Disabled Stage (90 days): Data is accessible to admins only. Users can’t access applications. Admins can access the admin centre to buy and manage other subscriptions.
3. Deleted Stage: After the 90-day retention period ends, Microsoft disables the account and deletes the customer data.
During the term of an active subscription, a subscriber can access, extract, or delete customer data stored in Modern Work apps. For more information, visit https://learn.microsoft.com/en-us/microsoft-365/commerce/subscriptions/what-if-my-subscription-expires - End-of-contract process
-
Microsoft is governed by strict standards and follows specific processes for removing cloud customer data from systems under our control, overwriting storage resources before reuse, and purging or destroying decommissioned hardware. In our Online Service Terms, Microsoft contractually commits to specific processes when a customer leaves a cloud service or the subscription expires. This includes deleting customer data from systems under our control.
Please see Data Protection Addendum for full and up to date details about how Microsoft manages your data. https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA?lang=1
https://learn.microsoft.com/en-us/microsoft-365/commerce/subscriptions/what-if-my-subscription-expires?view=o365-worldwide - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Microsoft offers distinct experiences on mobile and desktop devices for Microsoft 365. On desktop, users access the full suite of features, while the mobile app provides a streamlined interface for essential tasks and allows for offline working when there isn't network connectivity.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Microsoft 365 can be managed via the M365 admin centre: https://learn.microsoft.com/en-us/microsoft-365/admin/?view=o365-worldwide
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Microsoft is committed to developing technology that empowers everyone, including people with disabilities. Microsoft has a Disability Answer Desk where customers with disabilities get support with Microsoft Office, Windows, and other products. Microsoft also has Accessibility Conformance Reports (ACR) which describe how products and services support recognized global accessibility standards.
https://www.microsoft.com/en-us/Accessibility/disability-answer-desk
https://www.microsoft.com/en-us/accessibility/conformance-reports
https://learn.microsoft.com/en-us/windows/apps/design/accessibility/accessibility-testing - API
- Yes
- What users can and can't do using the API
-
The Microsoft Graph API enables you to access data, intelligence, and insights from Microsoft applications. By integrating Modern Work with Graph API, developers can tap into user data and organizational information to enhance context-aware assistance from applications like Word, Excel, Teams, etc. Starting with users and groups at the core, Microsoft Graph forms a network of Modern Work services and features that manage, protect, and extract data to support a wide range of scenarios. Microsoft Graph lets you access this wealth of user data while always respecting proper authorization. For more information on Microsoft Graph's capabilities, services, and features, visit:
- https://learn.microsoft.com/en-us/graph/overview
- https://learn.microsoft.com/en-us/graph/overview-major-services
For information on Microsoft Graph limitations (throttling limits, service-specific limits, connection limits, schema limits, and availability), visit:
- https://learn.microsoft.com/en-us/graph/throttling-limits
- https://learn.microsoft.com/en-us/graph/connecting-external-content-api-limits
- https://learn.microsoft.com/en-us/graph/metered-api-overview
Microsoft Azure OpenAI also offers a suite of artificial intelligence (AI) services that can be seamlessly integrated with Modern Work to enhance its functionality. By leveraging services such as Azure Cognitive Services and Azure Machine Learning, developers can extend capabilities in areas such as code summarization, sentiment analysis of code reviews, and even predictive coding assistance based on historical patterns. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Modern Work customers can customize their services in various ways:
- The Microsoft 365 Admin Centre is a web-based portal where administrators can manage user accounts and settings for their organization. They can add or remove users, manage billing, reset passwords, and more.
- The Office Customization Tool allows administrators to customize the installation of Office by choosing which applications and languages are installed, how those applications should be updated, and application preferences.
- Users can personalize their Microsoft 365 experience by changing the theme, notifications, and other settings.
- The Microsoft 365 Developer Program provides a sandbox environment where developers can learn and experiment with Modern Work technologies.
- Developers can use the Microsoft Graph API to interact with data in Modern Work and build apps that integrate with Microsoft 365.
For more information, visit:
- https://learn.microsoft.com/en-us/deployoffice/admincenter/overview-office-customization-tool
- https://learn.microsoft.com/en-us/microsoft-365/admin/setup/customize-your-organization-theme
- https://support.microsoft.com/en-us/office/personalize-your-microsoft-365-experience-eb34a21b-52fa-4fbf-a8d5-146132242985
Scaling
- Independence of resources
-
Microsoft employs a combination of proactive monitoring and efficient management to mitigate impacts of demand fluctuations.
Microsoft focuses on several areas of service management to minimize effects on users by demands on the service:
- Monitoring and Major Incident Management: knowing if users are impacted (regardless of root cause) and ensuring that the appropriate remediation occurs when users are impacted
- Evergreen Management: being prepared to absorb changes and derive business value from the ever-evolving service
- Service Desk and Normal Incident Management: supporting end-users, leveraging automation investments, and measuring call and escalation rates.
For more information, visit:
https://learn.microsoft.com/en-us/microsoft-365/community/maturity-model-microsoft365-servicing-microsoft365-service-change-management
https://techcommunity.microsoft.com/t5/microsoft-365-blog/modern-service-management-for-office-365/ba-p/52793
Analytics
- Service usage metrics
- Yes
- Metrics types
-
You can use dashboards in the Microsoft 365 admin centre to monitor service health. Monitoring increases observability and minimizes downtime through near real-time user telemetry data with enriched alerts in the Service Health dashboard.
Microsoft 365 usage analytics gives access to a prebuilt dashboard with a cross-product view of the last 12 months, containing many prebuilt reports. Each report provides specific usage insights. User-specific information is available for the last full calendar month.
Usage analytics contains Power BI reports.
Usage reporting can be accessed via Microsoft Graph API.
For more information, visit:
- https://learn.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-monitoring
- https://learn.microsoft.com/en-US/microsoft-365/admin/usage-analytics/usage-analytics
- https://learn.microsoft.com/en-US/microsoft-365/admin/usage-analytics/enable-usage-analytics
- https://learn.microsoft.com/en-us/graph/reportroot-concept-overview - Reporting types
-
- API access
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Microsoft
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Modern Work applications enable users to export their data in numerous ways.
For information on how Outlook users can export their data, visit https://support.microsoft.com/en-us/office/export-emails-contacts-and-calendar-items-to-outlook-using-a-pst-file-14252b52-3075-4e9b-be4e-ff9ef1068f91
For information on how Teams users can export their data, visit https://answers.microsoft.com/en-us/msteams/forum/all/how-to-download-data-and-activities-carried-out-on/0e21a9e5-71c8-4cdd-b817-a019dcd54592 - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Microsoft Excel (as a workbook or PivotTable report)
- Text-only (tab delimited)
- Comma-separated values (CSV)
- Extensible Markup Language (XML)
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- PST
- Application dependent: Word, Excel, PPT, PDF, image, video, audio.
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Please note that the following links are collectively a high-level overview, and the actual terms can be found in the specific SLA and refund policy documents:
• https://www.microsoft.com/licensing/docs/view/Service-Level-Agreements-SLA-for-Online-Services?lang=1&year=2023
• https://www.microsoft.com/licensing/docs/view/Service-Level-Agreements-SLA-for-Online-Services
• https://support.microsoft.com/en-us/account-billing/how-to-get-a-refund-on-a-microsoft-subscription-67dca30b-b323-44d5-acc2-e02f9902c472
• https://www.microsoft.com/en-us/store/b/returns
• https://learn.microsoft.com/en-us/answers/questions/1275102/ms-365-business-premium-service-level-agreement?page=1
• https://learn.microsoft.com/en-us/dynamics365/customer-service/use/overview-service-level-agreements
• https://learn.microsoft.com/en-us/training/modules/service-level-agreements/
• https://www.microsoft.com/licensing/servicelevelagreements%29 - Approach to resilience
-
Microsoft's datacentre setup is designed to be resilient and align with UK Government's 2nd Cloud Security Principle "Asset Protection and Resilience".
* Redundant Architecture: Microsoft online services achieve resilience through redundant architecture, which involves deploying multiple instances of a service on geographically and physically separate hardware. This provides increased fault-tolerance for Microsoft online services.
* Data Replication and Automated Integrity Checking: Data replication and automated integrity checking are part of Microsoft's strategy to ensure service resilience.
* Compliance with UK G-Cloud: Every year, Microsoft prepares documentation and submits evidence to attest that its in-scope enterprise cloud services comply with the 14 Cloud Security Principles of G-Cloud. This gives potential G-Cloud customers an overview of its risk environment.
* ISO/IEC 27001 Certification: The compliance process relies on the ISO/IEC 27001 certification. A Government Digital Service (GDS) accreditor then performs several random checks on the Microsoft assertion statement, samples the evidence, and makes a determination of compliance.
* UK OFFICIAL Data: The appointment of Microsoft services to the Digital Marketplace means that UK government agencies and partners can use in-scope services to store and process UK OFFICIAL government data.
Please also see:
• https://learn.microsoft.com/en-us/compliance/assurance/assurance-resiliency-and-continuity
• https://learn.microsoft.com/en-us/compliance/regulatory/offering-g-cloud-uk
• https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-uk-g-cloud
• https://azure.microsoft.com/en-us/blog/trusted-cloud-security-privacy-compliance-resiliency-and-ip/
• https://azure.microsoft.com/en-us/blog/easing-compliance-for-uk-public-and-health-sectors-with-new-azure-blueprints/" - Outage reporting
-
Microsoft provides several ways to report service outages:
*Public Dashboard: Microsoft provides a public dashboard where users can view the health of their Microsoft services. The dashboard indicates any active service issue and links to the detailed Service Health page.
*API: Microsoft offers the Service Communications API, showing health status and posts about Microsoft cloud services.
*Email Alerts: Users can sign up for email notifications of incidents that affect their tenant and status changes for an active incident.
*Mobile Push Notifications: This allows users to learn about critical service issues right on their mobile device and act immediately to start mitigating any impact to their workloads.
*IT Service Management Tools: Microsoft recommends setting up Service Health alerts using the webhook or ITSM integration.
*Power BI Notifications: Power BI provides incident notification so you can optionally receive emails if there's a service disruption or degradation. A Power BI admin can enable notifications for service outages or incidents in the admin portal.
Please also see:
• https://learn.microsoft.com/en-us/microsoft-365/enterprise/view-service-health?view=o365-worldwide
• https://learn.microsoft.com/en-us/graph/service-communications-concept-overview
• https://learn.microsoft.com/en-us/azure/service-health/impacted-resources-outage
• https://learn.microsoft.com/en-us/azure/azure-monitor/app/sla-report
• portal.microsoft.com. https://portal.microsoft.com/servicestatus
• https://learn.microsoft.com/en-us/power-platform/admin/check-online-service-health
• https://learn.microsoft.com/en-us/power-bi/support/service-interruption-notifications
• https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/get-email-notifications-on-new-incidents-from-microsoft-365/ba-p/2012518
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
Using Microsoft Entra, Modern Work allows you to create or update dynamic groups based on defined rules. You can implement multifactor authentication and control device access based on group, team, or site sensitivity, as well as use sensitivity labels to protect content in Microsoft Teams, Microsoft 365 groups, and SharePoint sites.
You can manage sharing from specified domains, restrict sharing of content, and control team or group membership from specific domains. You can also prevent anonymous sharing and limit external sharing to specific people.
You can also block access entirely from unmanaged devices or allow limited, web-only access. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
Microsoft follows a comprehensive approach to information security policies and processes for its internal operations. Here's an overview:
*Microsoft Security Policy (MSP): Microsoft implements a comprehensive security governance program as part of the Microsoft Policy Framework.
*Business Unit Responsibility: Individual business units are responsible for specific implementations of Microsoft security policies.
*Alignment with Regulatory and Compliance Frameworks: Microsoft's security governance program is informed by and aligns with various regulatory and compliance frameworks.
*Policy Updates: Microsoft regularly updates its security policies and supporting documents to protect Microsoft systems and customers.
*Operational Security Practices: Microsoft Operational Security Assurance Practices aim to improve software security in a cloud-based infrastructure. These include training, multi-factor authentication, enforcing least privilege, protecting secrets, minimizing attack surface, encrypting data in-transit and at-rest, security monitoring, security update strategy, protecting against DDOS attacks, validating the configuration of web applications and sites, and penetration testing.
*Reporting Structure: Microsoft reports financial performance based on the following segments: Productivity and Business Processes, Intelligent Cloud, and More Personal Computing.
*Ensuring Policies are Followed: Microsoft ensures security policies are followed by implementing them consistently.
Please also see:
• https://learn.microsoft.com/en-us/compliance/assurance/assurance-governance
• https://www.microsoft.com/en-us/securityengineering/osa/practices
• https://www.microsoft.com/investor/reports/ar23/index.html
• https://learn.microsoft.com/en-us/sql/reporting-services/reporting-services-concepts-ssrs?view=sql-server-ver16
• https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/mdo-sec-ops-guide?view=o365-worldwide - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Modern Work enforces change management procedures for code and non-code changes to maintain security posture.
Service teams utilize ticketing or source control tools to document approval and track changes. Changes are deployed through Microsoft’s Secure Development Lifecycle (SDL), including Critical security review and approval checkpoints. Service teams discuss and document proposed changes.
Baseline configurations are established during deployment. Any deviations are tracked and managed, with automated tools monitoring and enforcing consistency. Configuration changes are assessed for impact on security, functionality, and availability. Risk assessments consider potential vulnerabilities introduced by configuration drift. Regular audits verify adherence to baseline configurations.
https://learn.microsoft.com/en-us/compliance/assurance/assurance-microsoft-365-change-management - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
The Microsoft Detection and Response Team actively looks for cyberthreats using a tiered data collection model which provides information about known threats, attack patterns, and indicators of suspicious or anomalous activity.
Microsoft can download updates from source if the updates is not available in a distribution point, within ~3 hours of security updates release.
Microsoft aggregates data to gather threat information, including first-party threat intelligence feeds (honeypots, malicious IP addresses, botnets, malware detonation feeds). Also SIEM and XDR solutions.
Please also see:
• https://www.microsoft.com/en-us/security/blog/2022/09/08/part-1-the-art-and-science-of-threat-hunting/
• https://learn.microsoft.com/en-us/microsoft-365/security/defender/criteria?view=o365-worldwide
• https://learn.microsoft.com/en-us/windows/deployment/windows-autopatch/overview/windows-autopatch-deployment-guide - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Active monitoring tools include the Microsoft Monitoring Agent and System Centre Operations Manager.
Azure continuously monitors and detects risk, even when devices aren’t connected to the network. Adaptive machine learning algorithms detect anomalies that might indicate an identity is compromised. Azure security has defined requirements for active monitoring.
Microsoft implements a security incident management process to facilitate a coordinated response to incidents. Microsoft conducts thorough investigations examining the risky users and Azure Monitor activity logs to confirm the compromise and contain the exposure immediately.
The Initial Response Time varies with the support plan and Business Impact: https://azure.microsoft.com/en-us/support/plans/response/ - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
To effectively respond to security incidents, Microsoft employs a federated security incident response model. The Security Response team provides centralized security expertise and incident response guidance.
Responsibilities for security incident response are shared between the Security Response team and each service team.
Our incident response strategy, based on NIST 800-61:
- Preparation: tools, processes, competencies, and readiness
- Detection and analysis: activity to detect a security incident in a production environment
- Containment, eradication, recovery: actions taken to contain the security incident based on prior analysis done
- Post-incident activity: post-mortem analysis performed after the recovery of a security incident - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Police National Network (PNN)
- Joint Academic Network (JANET)
- Scottish Wide Area Network (SWAN)
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Information on free trials can be found on https://www.microsoft.com/en-gb/microsoft-365/try
- Link to free trial
- https://www.microsoft.com/en-gb/microsoft-365/try
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO Certification Ltd
- ISO/IEC 27001 accreditation date
- Wednesday 5 March 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Peers Quality Assurance Ltd
- ISO 9001 accreditation date
- Wednesday 1 November 2023
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- SecurityMetrics
- PCI DSS accreditation date
- Thursday 23 October 2025
- What the PCI DSS doesn’t cover
- N/A
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 3990f676-b304-42c4-9776-0869f2d32229
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 21e94cf4-cda7-4d3a-8343-71e6363aef69
- Other security certifications
- Yes
- Any other security certifications
- IASME Cyber Assurance L2
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-