Skip to main content

Help us improve the Digital Marketplace - send your feedback

ZOHO CORPORATION LIMITED

ManageEngine Remote Access Plus Cloud - Remote troubleshooting and desktop support solution

Remote Access Plus is a secure and compliant enterprise remote support and troubleshooting platform designed for system administrators, IT help desk teams, and endpoint management professionals. It enables fast and reliable remote desktop access, remote control, and diagnostics to resolve issues, minimise downtime, and support distributed workforces at scale.

Features

  • Multiplatform support for Windows, macOS, Linux, and Android troubleshooting
  • Advanced system management tools with 12+ diagnostic and administrative utilities
  • Unattended remote access for offline, locked, or sleeping endpoints
  • Integrated voice, video, and text chat within remote sessions
  • Collaborative remote support with multi technician support and shared control
  • Remote power management with Wake on LAN and shutdown controls
  • Audit ready reporting with real time logs and video recordings
  • Enterprise grade security with AES 256 encryption and 2FA controls
  • Multi monitor visibility with seamless monitor switching during sessions
  • Native integrations with ServiceDesk Plus and leading help desk systems

Benefits

  • Multiplatform support reduces tool sprawl and unifies remote support operations.
  • Deep diagnostic access cuts MTTR dramatically and eliminates onsite troubleshooting.
  • Unattended access enables after hours maintenance without disrupting end users
  • Session chat improves clarity, reducing confusion and repeat support cycles
  • Collaborative troubleshooting boosts first call resolution for complex issues
  • Remote power actions lower energy usage and optimize operating costs
  • Audit ready reporting strengthens compliance and ensures technician accountability
  • Encrypted sessions prevent unauthorized access and safeguard sensitive data
  • Multi monitor viewing enhances diagnosis by shortening troubleshooting cycles
  • Help desk integration streamlines workflows and accelerates ticket resolution

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at zohouk-gcloud@eu.zohocorp.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 3 6 7 2 9 6 7 2 6 5 4 5 0 0

Contact

ZOHO CORPORATION LIMITED Corie Robinson
Telephone: +44 2038072092
Email: zohouk-gcloud@eu.zohocorp.com

About your service

Service categories

Applications

Collaborative

Conferencing and virtual event

  • Web Conferencing Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Remote Access Plus requires its agents to be installed in the managed end user machines. As a cloud solution, the service undergoes planned maintenance and enhancements from time to time which are intimated over various communication channels such as forum, email and product banner. Service updates are regularly posted in status.manageengine.uk or status.manageengine.eu where the user can find the detailed account of any planned/unplanned maintenance.
System requirements
  • Internet Connection
  • Browser
  • Mobile App
  • Distribution Server
  • A license is required to manage over 25 endpoints.

User support

Email or online ticketing support
Yes
Support response times
Severity Level - Acknowledgement Time
S1 – Major - Within 4 regional business hours
S2 – Moderate - Within 12 regional business hours
S3 – Low - Within 24 regional business hours Weekend Support is available for customers opting for Premium Support
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
The product includes an in-built chat feature that allows users to connect directly with a human support representative. In addition to in-product support, users can also initiate a web chat by visiting our website and clicking the support icon located at the bottom right, enabling them to request technical assistance, raise queries, or seek remote support.

During weekends and holidays, any chat that does not receive an immediate response is automatically converted into a support ticket within our ticketing portal to ensure timely follow-up. This approach ensures continuity of support, preserves customer confidence, and guarantees that issues are either resolved promptly through chat or escalated for further investigation when required. Overall, the chat system strengthens the customer experience and reflects our commitment to dependable, high-quality support.
Web chat accessibility testing
While specific documented testing with assistive technology users is underway, we are actively prioritising accessibility standards for our live chat widget. Our current focus centres on integrated features designed to enhance usability for all individuals.

Key accessibility implementations include:
Mouseless Navigation: The widget is fully functional without a mouse. Users can navigate forward using Tab, backward with Shift-Tab, and make selections via the Enter key.
Visual Adaptability: To ensure visibility across various devices, the application supports zoom controls ranging from 80% to 125%. Users can also customize text readability by selecting small, medium, or large font sizes to suit their preferences.
Screen Reader Integration: As a text-only interface, the widget is compatible with screen reader extensions. This allows focused areas to be read aloud, ensuring content accessibility for visually impaired users.
Compliance has been verified through manual testing for navigation and readability. We remain committed to refining these features as we advance toward full accessibility compliance, ensuring a seamless communication experience for every user across our digital platform regardless of their specific navigation requirements and individual technological preferences throughout the entire user journey.
Onsite support
Yes, at extra cost
Support levels
ManageEngine Remote Access Plus offers two tiers of support: Classic and Premium. Classic support is included with a subscription license, and provides email and chat support, as well as access to online resources. Premium support offers additional benefits, such as a single point of contact--a dedicated technical account manager (TAM), faster turnaround times, and 24/7 phone support.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Remote Access Plus offers the following ways to get up and running:

1. In-product onboarding: In-product guidance and instructions that activate users and familiarise with the platform after signing in for the first time.

2. Paid Product Support: Apart from classic support, Remote Access Plus provides a dedicated team of solution engineers and product experts who help users to get started with configuring Remote Access Plus practices through a variety of paid programs.

3. Online documentation: Remote Access Plus Cloud provides in-depth help documentation that is hosted online which provides step by step guidance for administrators, technicians, and end-users.

4. Live Webinar: In addition to product documentation, Remote Access Plus hosts live sessions with product experts throughout the year wherein the users can register for webinars on the training page.

5. Dedicated Technical Account Managers: Remote Access Plus’s Technical account managers travel around the globe meeting customers in their offices for on-site health checks.

6. In-person events: Remote Access Plus also hosts user conferences to help train customers on the product capabilities with an option to avail a product associate certification.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
After the evaluation period , users will be prompted to move to the free edition of Remote Access Plus (maximum 25 endpoints). If user does not move within 3 months (after repeated follow-ups), user data will be archived and will be deleted from our internal records after 3 subsequent months.
A licensed user can terminate a contract by deleting their org within the application console during which the user is given the chance to download a copy of basic inventory data.
End-of-contract process
Once the contract period ends, in the absence of any renewal contract, the Remote Access Plus license is deprecated to the standard edition that is free to use up to 25 endpoints and 1 technician.
Upon termination of user account, user data gets deleted from the active database during the subsequent clean-up that occurs once every 6 months. The data deleted from the active database will be deleted from backups after 3 months. During the off-boarding process, we provide the option to export data and ensure that all sensitive information is securely transferred or deleted as per our privacy policy
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding and offboarding documentation can be accessed through our online help documentation provided the user has internet connectivity and access to a reliable browser application. Documentation can also be viewed via mobile interface and optimised for mobile view. Service interface does not override user’s individual display attributes (such as contrast and colour). Service interface does not have elements that flashes/blinks at high frequency.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • Other
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Technicians will be able to remotely access the console on their mobile devices (via a dedicated Android/iOS app) with minimal variations compared to the desktop experience when they are away from their desk. Navigation and user experience have been optimised for mobile view.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
IT admins/managers/analysts can access the product console (service interface) on browser-only platforms (for desktops) and iOS/Android app (for mobile devices).
Accessibility standards
None or don’t know
Description of accessibility
Access to the Remote Access Plus console is achieved through a simple login via major web browsers, including Google Chrome, Microsoft Edge, and Safari, using valid credentials. For mobile flexibility, applications are also available via Google Play Store and iOS App Store. We currently assure the UI focuses entirely on built-in accessibility features designed for inclusive use, including:

1) Full keyboard-only navigation using Tab, Shift, and Enter/Return.

3) Support for screen reader extensions and assistive technologies to enhance content accessibility.

4) A user-friendly interface designed to be usable for individuals with motor, cognitive, or visual disabilities.
Accessibility testing
ManageEngine is working to reach WCAG accessibility standards for Remote Access Plus Cloud. We are yet to perform any interface testing with users of assistive technology.
API
Yes
What users can and can't do using the API
The Remote Access Plus API facilitates easy integration with the existing infrastructure using REST APIs. Users can perform various patching activities easily from a single console.

Prerequisites to use Remote Access Plus API:
Remote Access Plus REST API supports OAuth 2.0 protocol to authorize and authenticate API calls.
The steps to generate an OAuth token are as follows:
1. Generate <Client ID> and <Client Secret>
2. Authorization by generating the <grant token>
3. Generating <Access> and <Refresh Token>
4. Generate <Access Token> from <Refresh Token>

The available functionalities accessible through APIs are:
1. Scope of Management (SoM)
2. Tools (System Manager, Remote Shutdown, Wake on LAN, Announcement, System Tools)
3. Remote Control and Chat

In case the user has removed or regenerated the Auth Token, then the existing token will become invalid and cannot be used in API requests.
In case the user is deactivated, then all the Auth Tokens of the user's account will become invalid.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Administrators have the flexibility to personalise the look and feel of the console according to their preference. Administrators can configure user accounts, provide role-based access, reorganise menu bar, rebrand the console and generate customised reports based on inventory parameters. Further service level customisation can be qualified upon request to Support.

Scaling

Independence of resources
We have a distributed network of servers across the globe that ensures service uptime and efficient content delivery with minimal latency. Individual Customer data is logically separated within a database to ensure data security and privacy. Failover and load balancing systems are put in place for overall reliability and seamless resource utilisation.

Analytics

Service usage metrics
Yes
Metrics types
1) Users can view their license information (like endpoints used, expiry, add-ons utilized). 2) Users are offered Uptime/Downtime metrics ( % service availability over an year).
3) There is a provision of user communication for planned maintenance, downtime and RCA.
4) Status of remote shutdown/startup tasks (Wake on LAN/Remote Shutdown) are notified to the admins (if configured) via email and in-console alerts
5) Details of remote sessions (initiated/terminated/recorded) are notified to the admins (if configured) via email for audit and compliance purposes.
Reporting types
Real-time dashboards
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Sensitive customer data at rest is encrypted using 256-bit Advanced Encryption Standard (AES). The data that is encrypted at rest varies with the services you opt for. We own and maintain the keys using our in-house Key Management Service (KMS). We provide additional layers of security by encrypting the data encryption keys using master keys. The master keys and data encryption keys are physically separated and stored in different servers with limited access.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Remote Access Plus allows you to export reports as PDF, CSV, and XLSX. In addition, users can mask/remove any Personally Identifiable Information (PII) from their reports. These can be exported from the Reports section in the console. Also, individual reports for the functionalities can be exported from the respective views, i.e. Manual Deployment, Automate Patch Deployment, Test and Approve.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • XLSX
Data import formats
  • CSV
  • Other
Other data import formats
  • PDF
  • XLSX

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
All customer data transmitted to our servers over public networks is protected using strong encryption protocols. We mandate all connections to our servers use Transport Layer Security (TLS 1.2/1.3) encryption with strong ciphers, for all connections including web access,API access, our mobile apps, and IMAP/POP/SMTP email client access. Additionally for email, our services leverages opportunistic TLS by default. We have full support for Perfect Forward Secrecy (PFS) with encrypted connections, ensuring no previous communication be decrypted. We have enabled HTTP Strict Transport Security header (HSTS) to all web connections and we flag all our authentication cookies as secure.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
ManageEngine protects data within its network using layered security controls. Data stored in Zoho data centres is encrypted at rest using strong encryption standards. Internal traffic between services, storage systems and disaster recovery sites is encrypted to prevent unauthorised access. Manageengine operates fully controlled data centres with restricted physical access, continuous monitoring and dedicated security systems. Network protections include firewalls, intrusion detection and prevention, and segmentation to isolate sensitive components and limit lateral movement. Access to production systems is restricted to authorised personnel following strict authentication, logging and approval processes.

Availability and resilience

Guaranteed availability
ManageEngine guarantees an average monthly uptime of 99.9% for its Cloud solutions. The standard SLA covers monthly service availability. If the service falls below this threshold, customers may be eligible for service credits according to contract terms
Approach to resilience
Application data is stored on resilient storage that is replicated across data centers. Data in the primary DC is replicated in the secondary in near real time. In case of failure of the primary DC, secondary DC takes over and the operations are carried on smoothly with minimal or no loss of time. Both the centers are equipped with multiple ISPs.

We have power back-up, temperature control systems and fire-prevention systems as physical measures to ensure business continuity. These measures help us achieve resilience. In addition to the redundancy of data, we have a business continuity plan for our major operations such as support and infrastructure management.
Outage reporting
Planned maintenance will be notified through In-App banners & status pages and unplanned outages will be notified through status pages, blogs, forums and social media handles.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to production environments is maintained by a central directory and authenticated using a combination of strong passwords, two-factor authentication, and passphrase-protected SSH keys. Furthermore, we facilitate such access through a separate network with stricter rules and hardened devices. Additionally, we log all the operations and audit them periodically."
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Other standards include ISO/IEC 27701, ISO/IEC 27017, ISO/IEC 27018, SOC 2 Type II, HIPAA-compliant controls for eligible services, and CSA STAR Level 1 certification. These frameworks cover privacy management, cloud security, protection of personal data, independent assurance reporting, and cloud control transparency.
Information security policies and processes
ManageEngine has a dedicated Compliance team and they conduct internal risk assessments to confirm if the policies are followed. Zoho has an established governance framework that supports relevant aspects of information security with policies and standards (Endpoint Central is an offering from ManageEngine, which in turn is a division of Zoho). Roles and responsibilities for the governance of Information Security within Zoho are formally documented and communicated by the management. Zoho shall establish, implement, and maintain an information security program in accordance with the international standard ISO 27001 that includes technical and organizational security and physical measures as well as policies and procedures to protect customer data processed by Zoho against accidental loss, destruction or alteration, unauthorized disclosure or access, or unlawful destruction. Zoho maintains documented information security and data privacy policies and requirements, and communicates them periodically to those employees responsible for the design, implementation and maintenance of security and privacy controls.The policies are reviewed annually to keep them up-to-date. This policy gets verified during our third-party audits like ISO and SOC.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
ManageEngine has Change Management procedures in place that include the following but are not limited to all the changes to the organisation, applications, systems, people, technology, and processes, information processing facilities that affect information security/privacy. For every change, the security impact is analysed. We maintain Audit logs as evidence of all the changes. Fall-back procedures, including procedures and responsibilities for aborting and recovering from unsuccessful changes and unforeseen events, are documented and communicated. Zoho shall notify the customer of any changes that may affect the customer in an adverse manner.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
ManageEngine has a vulnerability management process that actively scans for security threats using a combination of certified third-party scanning and in-house tools with automated and manual penetration testing efforts. Our security team actively reviews inbound security reports and monitors public mailing lists, blog posts, and wikis to spot security incidents that might affect the company’s infrastructure.

Once we identify a vulnerability requiring remediation, it is logged, prioritised according to the severity, and assigned to an owner. We further identify the associated risks and track the vulnerability until it is closed by either patching the vulnerable systems or applying relevant controls.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
ManageEngine ensures to monitor and analyse information gathered from services, internal traffic in our network, and usage of devices and terminals. We record this information in the form of event logs, audit logs, fault logs, administrator logs, and operator logs. These logs are automatically monitored and analysed to a reasonable extent that helps us identify anomalies such as unusual activity in employees’ accounts or attempts to access customer data. We store these logs in a secure server isolated from full system access, to manage access control centrally and ensure availability.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
ManageEngine has a dedicated incident management team. We track and close the incidents with appropriate corrective actions. Whenever applicable, we will identify, collect, acquire, and provide users with necessary evidence in the form of application and audit logs regarding incidents applicable.
We respond to the security or privacy incidents you report to us through incidents@zohocorp.com with high priority. For general incidents, we will notify users through our blogs, forums, and social media. For incidents specific to an individual user or an organisation, we will notify the concerned party through the primary email of the Organisation administrator registered with us.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
ManageEngine provides a free fully functional 30-day free trial for our Services. This allows users to test features without any initial cost. Our products also include a free edition with limited capabilities after the 30-day free trial period.
Link to free trial
UK: https://www.manageengine.com/uk/remote-desktop-management/free-trial.html EU: https://www.manageengine.com/eu/remote-desktop-management/free-trial.html

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Wednesday 3 September 2025
What the ISO/IEC 27001 doesn’t cover
ISO/IEC 27001 certifies our Information Security Management System (ISMS) and confirms that we have appropriate governance, controls, and continual improvement processes in place to manage information security risks within the defined scope of certification.

The certification does not certify individual products or specific technical features in isolation. Instead, it applies to the management framework, policies, processes, and controls that govern how information security is implemented and operated across our in-scope services.

Activities, systems, or services outside the formally defined ISMS scope are not covered by the ISO/IEC 27001 certification. This may include third-party services or infrastructure not operated or controlled by us, or internal systems not directly involved in the delivery of certified services.

ISO/IEC 27001 also does not replace or automatically include other standards (such as ISO/IEC 27017 or ISO/IEC 27018 - Which Zoho Corporation has obtained both certifications), which address cloud-specific controls and protection of personally identifiable information and are assessed separately where applicable.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI
ISO 9001 accreditation date
Thursday 23 March 2023
What the ISO 9001 doesn’t cover
ISO 9001:2015 certifies our Quality Management System (QMS) and confirms that we have defined, implemented, and continually improved processes to ensure consistent service delivery within the certified scope.

The certification does not certify individual products, features, or technical performance in isolation. It focuses on the management framework for quality rather than guaranteeing specific service outcomes, configurations, or performance levels for individual services.

Activities, systems, or services outside the formally defined QMS scope are not covered by the ISO 9001 certification. This may include third-party services, customer-managed configurations, or internal processes not directly involved in the delivery and support of in-scope services.

ISO 9001 also does not address information security, privacy, or data protection controls, which are covered separately under standards such as ISO/IEC 27001 and related certifications.
Quality management systems (QMS)
Yes
CSA STAR certification
Yes
CSA STAR accreditation date
Monday 4 August 2025
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
Zoho’s listing in the CSA Security, Trust & Assurance Registry (STAR) is based on a STAR Level 1 Self-Assessment, which documents how our cloud security controls align with the Cloud Security Alliance Cloud Controls Matrix (CCM).

The STAR self-assessment applies to the security control framework and governance practices for our cloud services. It does not certify individual products, specific service configurations, or customer-managed settings in isolation.

Activities or services outside the scope of the published STAR self-assessment, including customer-controlled configurations, integrations with third-party services, or infrastructure not operated or controlled by Zoho, are not covered.

CSA STAR also does not replace other standards covering information security, privacy, or quality management, which are addressed separately through certifications such as ISO/IEC 27001 and related standards.

In summary, CSA STAR provides transparency into our cloud security controls within scope, but not independent certification or coverage of out-of-scope services or configurations.
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Df4a2fb2-58c7-428b-b622-0d1dbd68ae22
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
061e91c4-e56a-4f0c-a09c-66fea8d9c587
Other security certifications
Yes
Any other security certifications
  • ISO/IEC 27017 (Cloud Security Controls)
  • ISO/IEC 27018 (Protection of PII in public cloud)
  • ISO/IEC 27701 (Privacy Information Management / PIMS)
  • SOC 2 Type II
  • CSA STAR (Level 1 Self-Assessment)
  • Data Security and Protection Toolkit (DSPT)
  • GDPR

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at zohouk-gcloud@eu.zohocorp.com. Tell them what format you need. It will help if you say what assistive technology you use.