Skip to main content

Help us improve the Digital Marketplace - send your feedback

Supply25

Supply Chain Risk, Assessment & Assurance Platform

UK based SaaS platform for supplier assurance and procurement due diligence. It helps public sector teams run compliance checks in areas such as cyber security, accessibility and data protection, track supplier responses, monitor contract risk and manage assessments in one system, replacing spreadsheets and emails with a clear, consistent process.

Features

  • Create standardised supplier assessments across multiple compliance areas (Cyber Security).
  • Deploy ready-made assessment templates for fast setup and use.
  • Contract management support
  • Share multiple supplier checks using a single secure link.
  • Track supplier responses and monitor completion progress in real time.
  • Automate reassessments across contracts to track supplier compliance over time.
  • Track supplier performance and monitor risk with live dashboards.
  • Visualise contracts & suppliers through supply chain mapping organisation-wide.
  • Generate audit-ready PDFs with Red-Amber-Green supplier risk scores.
  • Secure SaaS platform with MFA and role-based access for teams.

Benefits

  • Accelerate procurement readiness with pre-built supplier assessment templates.
  • Customise and automate risk assessments to fit your organisation’s needs.
  • Monitor ongoing compliance through automated reassessments and improvement plans.
  • Streamline supplier due diligence with standardised, reusable assessment workflows.
  • Gain real-time visibility into supplier risk with dashboards and alerts.
  • Spot compliance gaps early and act quickly to reduce exposure.
  • Simplify cross-department collaboration with one shared platform.
  • Make confident, data-driven decisions with actionable insights.
  • Save time on audit preparation with exportable, structured reports.
  • Strengthen supply chain resilience by identifying and mitigating emerging risks.

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at alexis@supply25.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 1 7 1 7 4 1 5 8 5 8 4 3 2 3

Contact

Supply25 Alexis Lui
Telephone: +447909335337
Email: alexis@supply25.com

About your service

Service categories

Applications

Enterprise resource management

  • Procurement
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Buyers require internet access and a modern web browser; no additional hardware or software is needed.
System requirements
  • Modern web browser (Chrome, Edge, Safari or Firefox).
  • Reliable internet connection for cloud-based access.
  • JavaScript must be enabled in the browser.
  • Firewall settings must allow access our services.

User support

Email or online ticketing support
Yes
Support response times
Support queries are submitted via the in-platform support form and automatically acknowledged. Response times vary by severity: Critical (P1) within 2 hours (24/7), High (P2) within 4 business hours, Medium (P3) within 1 business day, and Low (P4) within 2–4 business days. Out-of-hours support is available for P1 incidents only. Early triage may be initiated at Supply25’s discretion, especially for time-sensitive procurement activities. Resolution times are best-effort estimates and depend on issue complexity. Business hours are Monday to Friday, 09:00–17:30 (UK local time). Every effort is made to respond and resolve issues faster where possible.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Supply25 provides a single tier of premium support to all licensed Buying Organisations at no extra cost. This includes triage, investigation, and resolution of platform issues and user queries in line with defined priority levels, from P1 (Critical) to P4 (Low).

All support requests must be submitted via the in-platform support form, with automated acknowledgements and regular status updates provided. Users cannot assign ticket priorities, but Supply25 will assess and prioritise each request appropriately. Every effort is made to exceed minimum response times, particularly where issues affect procurement deadlines or supplier access.

A named technical support contact will be assigned to each Buying Organisation for continuity and familiarity.

Support is available Monday to Friday, 09:00–17:30 (UK local time). Critical incidents may be escalated outside business hours at Supply25’s discretion.
Support available to third parties
No

Onboarding and offboarding

Getting started
Supply25 offers a structured onboarding process to help users get started quickly and confidently. Each new Buying Organisation receives a tailored mobilisation session, led by a member of our team, to introduce key features and workflows. This includes setup of user accounts, organisation profiles, and any initial assessment packages.

We provide step-by-step online user guides, walkthrough videos, and downloadable reference materials to support independent learning. Users can access this content at any time via the platform.

Support is available throughout the onboarding period to answer questions or resolve issues. No onsite training is required, but live virtual sessions can be arranged where needed.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract, the Customer may request a data export as part of the standard offboarding process. A written request must be submitted within thirty (30) days after the Agreement terminates or expires. Upon receipt of a valid request, Supply25 will provide a reasonable export of Customer Data in a commonly used electronic format, limited to data ordinarily accessible to the Customer through the Services.

The export is intended to be suitable for audit, reporting, and internal record-keeping purposes. It does not include internal system metadata, audit logs, derived analytics, scoring logic, or platform configuration data that is not exposed to users during normal service use.

After the export window has closed, or once any agreed export has been completed, Customer access to the Services is removed and Customer Data is deleted or anonymised in accordance with the Agreement, the Data Processing Schedule, and applicable law.
End-of-contract process
The Agreement may terminate at the end of the contract term or earlier where either party gives at least thirty (30) days’ written notice in accordance with the Agreement. Access to the Services continues until the effective termination or expiry date, unless suspended earlier under the contract.

On termination or expiry, Supply25 will deactivate user accounts and revoke access to the Platform as part of the standard offboarding process. This process, which is included in the contract price, also covers deletion or anonymisation of Customer Data in line with the Agreement, the Data Processing Schedule, and applicable data protection law.

Where the Customer requests a data export within the permitted timeframe, Supply25 will provide a reasonable export of Customer Data in a commonly used electronic format. A standard export within normal service scope is included in the contract price.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Supply25 provides a user-friendly web interface accessible through modern browsers. The platform offers intuitive dashboards, navigation menus, and interactive tools for managing supplier assessments, tracking progress, and generating reports. Users can create and share assessments, view supplier submissions, and monitor supply chain risks using filters, visualisations, and exports. Access is role-based, with permissions tailored to user responsibilities. No additional software installation is required.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Supply25 has been tested in collaboration with the Scottish Government to ensure it is accessible to users who rely on assistive technologies. As part of this process, Scottish Government digital accessibility specialists carried out structured testing using tools such as screen readers, keyboard-only navigation and browser-based accessibility features. These tests assessed key user journeys, including completing assessments, reviewing submissions and navigating the platform interface.

The platform has been designed in line with WCAG 2.2 AA principles, with particular focus on clear page structure, logical tab order, semantic HTML and ensuring that interactive elements are compatible with assistive technologies. Findings from accessibility testing were incorporated into iterative improvements to enhance usability and compliance.

Accessibility remains an ongoing area of focus within Supply25’s development cycle, and further updates will continue to be informed by good practice and feedback from public sector users.
API
No
Customisation available
No

Scaling

Independence of resources
Supply25 uses a cloud-native, serverless architecture that scales automatically with demand. This means performance remains consistent, even during periods of high activity. Each organisation’s data and usage are handled independently, so one user’s activity won’t affect another. Our infrastructure is designed for resilience, speed, and reliable performance at scale.

Analytics

Service usage metrics
Yes
Metrics types
Supply25 provides platform usage metrics to help buying organisations monitor internal adoption and engagement. Metrics include user logins, assessment package creation, supplier invitations, assessment completions, reassessment activity, and the use of improvement plans. Usage can be segmented by user, department, or timeframe. These insights are available via in-platform dashboards and can support assurance, training needs analysis, and audit readiness.
Reporting types
Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
Less than once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Data exports are handled by the Supply25 team on request. At the end of the contract, users can request exports of supplier responses, assessment outcomes, and audit records. These will be provided in standard formats such as CSV or Excel, within an agreed timeframe.
Data export formats
CSV
Data import formats
Other
Other data import formats
We don't support uploads.

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Supply25 guarantees 99.9% platform availability, measured quarterly, excluding planned maintenance and external disruptions. Uptime covers access to core functions like logging in, completing assessments, and managing submissions. Downtime is defined as service-wide outages lasting over three minutes. Service Credits may be issued at Supply25’s discretion if availability falls below target or critical incidents breach response thresholds. These credits are capped and applied to renewal invoices. Availability is continuously monitored using automated systems. While SLAs define minimum expectations, every effort is made to exceed these and resolve issues quickly—especially those impacting time-sensitive procurement activities.
Approach to resilience
Supply25 is hosted in the AWS cloud using a serverless microservices architecture designed for resilience and scalability. Critical services are distributed across multiple Availability Zones (AZs) within the UK region to ensure high availability and fault tolerance.

Stateless backend services automatically scale based on demand and are redeployed via infrastructure-as-code for consistency and rapid recovery. All data is stored in encrypted AWS-managed services (e.g. DynamoDB, S3), with automatic redundancy and point-in-time recovery enabled where applicable.

Continuous monitoring and automated alerting help identify issues early. In the event of service disruption, Supply25 can restore functionality from resilient infrastructure without relying on manual intervention. Recovery procedures are documented and regularly reviewed as part of our Business Continuity and Disaster Recovery (BCDR) planning.
Outage reporting
Outage reporting is managed through proactive monitoring and alerting systems that continuously track the health of key services and infrastructure. In the event of an outage or performance degradation, automated alerts are triggered to the Supply25 engineering team for immediate investigation and resolution. A public-facing health check page is available on the Supply25 website, allowing users to confirm basic service availability at any time. This page indicates the operational status of core platform components but does not display incident history or real-time updates. Supply25 does not operate a public status page at this time. Outage summaries or incident reviews may be shared directly with affected clients upon request, depending on the severity and impact of the event.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is tightly controlled using named user accounts, enforced multi-factor authentication (MFA), and strict role-based permissions. Only authorised personnel with a business need can access administrative tooling, and privileges are assigned following the principle of least privilege. Support functions are limited to designated team members, with no broad or anonymous access permitted. All administrative access is logged and periodically reviewed. No access is granted by default, and escalation requests follow internal approval processes. These measures help ensure secure operations and minimise the risk of unauthorised changes or data exposure.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
Supply25 operates a clear set of information security policies aligned with UK GDPR and Cyber Essentials Plus certification. These cover data access, encryption, user account management, device security, and incident response.

All policies are reviewed regularly and shared with relevant staff as part of onboarding and ongoing training. Access to systems and data is based on the principle of least privilege, ensuring users only have access to what they need. Key systems maintain audit logs to support accountability and traceability.

The Chief Technology Officer (CTO) is responsible for maintaining and enforcing security policies, including change control and internal reviews. All platform changes are subject to code review and tested prior to deployment. External data sharing is controlled and permitted only through secure, pre-agreed mechanisms.

Supply25 makes ongoing improvements to its security processes and technical controls as the platform evolves and scales.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Supply25 follows structured configuration and change management processes. All infrastructure is managed using infrastructure-as-code (IaC), enabling version control, change tracking, and repeatable deployments. Changes to application code and infrastructure are peer-reviewed, tested in staging environments, and subject to approval before production release. Components are tracked through their lifecycle via Git-based repositories. Security impact is assessed during planning and code review stages, with a focus on least privilege and secure-by-default configurations. Critical changes are logged, and rollback mechanisms are in place to ensure stability. Regular reviews ensure alignment with evolving security best practices.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Supply25 follows a pragmatic, risk-based approach to vulnerability management. Security updates for third-party libraries, cloud services, and infrastructure are reviewed during regular development cycles. Patches are prioritised based on severity and applied promptly when vulnerabilities could affect data security, platform stability, or user access. All changes are deployed through a controlled CI/CD process following internal peer review. Supply25 periodically reviews its processes to improve response times and reduce exposure to emerging risks.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Supply25 applies layered protective monitoring to detect suspicious activity and potential compromise. Key platform events, such as authentication, system errors, and access patterns, are logged and reviewed periodically. Automated alerts notify designated personnel of abnormal activity to support rapid triage. Confirmed incidents follow our defined escalation path, with critical (P1) issues responded to within 2 hours, including out-of-hours coverage. Monitoring practices are reviewed regularly to ensure continued effectiveness, and enhancements are implemented as the service scales. Users are notified if any incident poses a risk to their data or service availability.
Incident management type
Supplier-defined controls
Incident management approach
Supply25 operates a defined incident management process with pre-established workflows for common events such as service degradation, access issues, or data-related concerns. Users report incidents through a support form within the platform, where submissions are triaged by severity. Priority 1 and 2 incidents trigger structured response procedures, with incident reports issued upon request. These reports include root cause analysis, timelines, and corrective actions. Lower-priority issues may be resolved without formal reporting. Real-time monitoring and internal logging enable proactive detection and resolution. Incident response is reviewed regularly to ensure resilience and continuity in support of procurement-critical activities.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Supply25 may offer a limited-time trial at its discretion to help buyers explore core features and assess suitability before entering a Call-Off Contract. The trial provides access to a reduced version of the service for evaluation only and is not for live procurement use. Terms are confirmed in writing.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
465d4c06-0996-4b08-9a04-439a1cdd4d9d
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
4542bc22-d7ff-4224-a3ea-545e2bb123b4
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Ensuring new workers are informed of their right to join a trade union
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at alexis@supply25.com. Tell them what format you need. It will help if you say what assistive technology you use.