Microsoft CSP/NCE Licensing
This service provides public sector organisations with access to Microsoft’s cloud‑based SaaS applications through the New Commerce Experience (NCE) previously referred to as CSP. It enables organisations to procure, deploy, manage, and optimise Microsoft 365 and related cloud services with compliant, scalable subscription management, configuration guidance, and ongoing support.
Features
- Licensing procurement and management
- Subscription optimisation
- Configuration and governance guidance
- Security and compliance alignment
- Tenant level operational support
- Adoption and user enablement
- Reporting and usage insights
- Post deployment support
Benefits
- Supports secure, compliant adoption of Microsoft cloud services.
- Reduces administrative effort for licence and subscription management.
- Improves productivity through cloud‑first, secure collaboration tools.
- Enables cost control with optimised subscription management.
- Provides a secure platform aligned to public sector standards.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 1 8 5 9 3 3 1 3 8 6 2 4 6 8
Contact
SCG.WORLD LIMITED
Adrian Sota
Telephone: 07490713858
Email: sales@scg.world
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Team collaboration
Conferencing and virtual event
- Web Conferencing Applications
- Virtual Event Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- This service extends Microsoft 365, Entra ID, and related Microsoft cloud applications by providing enhanced licensing oversight, configuration governance, optimisation insights, and management tooling not included within the native Microsoft admin portals.
- Cloud deployment model
-
- Public cloud
- Hybrid cloud
- Service constraints
-
• Some support and consultancy elements may be delivered remotely.
• Certain Microsoft services may require prerequisite licences or tenants.
• Customer participation is required for configuration tasks, MFA enforcement, or user provisioning.
• Availability of specific products is subject to Microsoft’s NCE catalogue. - System requirements
-
- Modern web browser required (Chrome, Edge, Safari, Firefox).
- Stable internet connection required for platform access.
- JavaScript enabled for full UI functionality
- Cookies enabled for secure session handling
- Microsoft 365 tenant required for integration features.
- Admin consent needed for Microsoft Graph access.
- Entra ID permissions required for licence data access.
- HTTPS (TLS 1.2+) connection required.
- Access to platform and Microsoft identity endpoints required.
- Desktop or mobile browser compatible with latest versions.
User support
- Email or online ticketing support
- Yes
- Support response times
- Within standard business hours
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We completed basic accessibility testing with assistive tech users, including screen reader checks.
- Onsite support
- Yes, at extra cost
- Support levels
-
Typical tiers include:
• Tier 1: Initial triage, basic troubleshooting
• Tier 2: Technical support and configuration assistance
• Tier 3: Escalation to specialist engineers
• Tier 4: Vendor liaison (Microsoft) - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- We provide a simple onboarding process to help organisations start using the service. This includes initial setup guidance, tenant validation support, and documentation covering licence management, support routes, and key contacts. Optional online onboarding sessions are available to walk through Microsoft 365 administration and best‑practice configuration. Users can access support via email/ticketing or phone during onboarding, and additional guidance from a Technical Account Manager can be provided where required.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
Users can extract their data at any time before the contract ends using standard Microsoft 365 export tools. This includes downloading files directly from OneDrive and SharePoint, exporting mailboxes via Outlook or Microsoft 365 admin tools, and exporting configuration or usage reports where supported. All data remains under the customer’s control within their Microsoft 365 tenant.
If requested, we provide guidance on how to perform exports or access Microsoft’s built‑in data extraction capabilities. No proprietary formats or tools are required, and no data is held by us outside of the customer’s tenant. - End-of-contract process
-
At the end of the contract, the customer retains full control of all data stored within their Microsoft 365 tenant. Licences purchased under this service can either lapse naturally, be transferred to another Microsoft partner, or be renewed under a new agreement. Before licences expire, users may export their data using Microsoft’s standard tools and admin portals.
We provide basic guidance on data extraction and licence transition at no additional cost.
If the customer chooses to migrate to a different supplier, we support the transfer of the tenant and subscriptions in line with Microsoft CSP processes. Any additional consultancy, extended support, or hands‑on migration activity is available as an optional chargeable service. Once the contract ends, we cease administrative access and no data is held or stored by us outside the customer’s own Microsoft tenant. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile version offers the same functionality with a responsive layout.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The interface is a cloud‑hosted dashboard offering licence insights, configuration monitoring, reporting, and management tools through a clean, responsive web layout.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We performed screen reader and keyboard‑only testing to verify accessibility, ensuring correct focus order, readable labels, and fully operable navigation.
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Microsoft SaaS services delivered through the CSP/NCE model run on Microsoft’s globally distributed, multi‑tenant cloud platform. Each customer’s data and service performance are isolated through Microsoft’s underlying architecture, ensuring that demand from other organisations does not affect availability or performance. Capacity, scaling, and resource management are handled entirely by Microsoft, and the service benefits from automatic load balancing and elastic cloud resources. As a reseller, we do not host or operate the platform, and customers receive the same guaranteed performance levels defined by Microsoft’s service commitments.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide service usage metrics based on available Microsoft 365 reporting, including licence allocation and utilisation, active/inactive users, subscription status, and adoption insights for core workloads such as Teams, Exchange, SharePoint, and OneDrive. Additional metrics cover consumption trends, security and compliance activity (where applicable), and subscription optimisation opportunities. Metrics are provided through standard Microsoft admin centre reports or as periodic summaries on request.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Microsoft
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export their data at any time using Microsoft 365’s built‑in export and download tools. This includes exporting mailboxes, downloading files from SharePoint and OneDrive, and generating reports or configuration data through the Microsoft 365 admin portals. All data remains within the customer’s own tenant, and no proprietary tools are required. We can provide guidance on where to access these export options if needed.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- JSON
- XML
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
We provide Microsoft SaaS licensing under the CSP/NCE model. Service availability for the underlying Microsoft 365 cloud services is guaranteed by Microsoft and backed by financially supported Service Level Agreements (SLAs). Core Microsoft 365 services typically offer a monthly uptime commitment of 99.9% or higher.
If Microsoft fails to meet these commitments, customers may be eligible for service credits in accordance with Microsoft’s SLA policies.
As a reseller, we support customers with incident management and escalation, but we do not operate the underlying cloud platform. Our responsibility is to ensure continuity of licensing, access to support channels, and timely escalation to Microsoft where required. Additional support SLAs may be provided through optional enhanced support packages. - Approach to resilience
-
This service is delivered using Microsoft’s globally distributed cloud platform, which is designed for high resilience and availability. Microsoft 365 services run across multiple geographically separated datacentres with built‑in redundancy, load balancing, automated failover, and continuous monitoring. Data is replicated across availability zones to ensure continuity in the event of hardware, network, or facility failure.
Resilience is further supported by Microsoft’s disaster recovery processes, 24/7 operational monitoring, and a multi‑layered engineering and support model. The platform is independently audited and certified to recognised standards such as ISO 27001, SOC 1/2, and CSA CCM.
As a CSP reseller, we do not operate the underlying infrastructure but ensure continuity of licensing and provide escalation routes to Microsoft. Additional support options are available on request. - Outage reporting
-
Outage reporting for this service is provided through Microsoft’s standard communication channels for Microsoft 365. Service health information, planned maintenance, and incident updates are published on the Microsoft 365 Service Health Dashboard, accessible to authorised administrators via the Microsoft 365 admin centre. Microsoft provides real‑time status updates, incident notifications, and post‑incident reports.
Administrators can also configure email alerts for service health events. Public service availability information is available on the Microsoft Status website for major incidents.
As a CSP reseller, we do not operate the underlying platform but support customers by monitoring service notifications, assisting with incident escalation, and providing updates when relevant. Additional enhanced communication options may be available through our support packages.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- We restrict access to management interfaces and support channels using role‑based access control, least‑privilege principles and MFA for all administrative accounts. Only authorised staff can access customer tenancy information or management portals. Support channels require authenticated user accounts, and sensitive actions are limited to designated technical staff. Access rights are reviewed regularly, and logs are monitored for unauthorised activity. No access is permitted without verified business need.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
We operate an Information Security Management System aligned to UK Government security expectations, Cyber Essentials, and ISO 27001 principles. Policies cover access control, secure configuration, data protection, vulnerability management, supplier assurance, and incident response. All staff receive mandatory security and data‑protection training and are vetted to BPSS or equivalent levels as required.
Security responsibilities sit with our leadership team, with oversight from our Security Lead and Data Protection Officer. Compliance is maintained through regular reviews, internal audits, and continuous monitoring of policy adherence. Access to customer environments is strictly role‑based, uses MFA, and follows least‑privilege controls.
We follow a structured incident‑management process covering identification, triage, investigation, containment, and customer notification where required. Risk management, business continuity procedures, and change‑control processes support secure service delivery.
When providing Microsoft CSP/NCE services, customers benefit from Microsoft’s certified security and compliance frameworks, while we ensure secure onboarding, governance alignment, and adherence to public‑sector standards throughout the lifecycle of the service. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We maintain a defined configuration and change‑management process. Service components are tracked throughout their lifecycle using documented configuration records, version control and audit trails. All changes follow a structured assessment that reviews security impact, dependencies, business risk and potential user disruption. Security‑related changes undergo enhanced review, including MFA, access, and compliance considerations. Approved changes are implemented using controlled procedures, with rollback plans and post‑change validation. Emergency changes follow an expedited but documented path. Microsoft SaaS platform changes are monitored and assessed for potential impact to customer environments.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We assess vulnerabilities through regular monitoring of vendor advisories, Microsoft Security Response Center (MSRC) feeds, NCSC threat alerts, CVE databases, and automated security notifications within Microsoft 365 and Azure. Potential threats are reviewed for relevance, impact and required actions. Where patches or configuration updates are required, we apply them as quickly as possible based on risk—critical issues are addressed immediately or within standard patch windows. We track remediation actions and validate successful deployment. Microsoft’s continuous SaaS platform updates further ensure underlying services remain secure and compliant.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We monitor for potential compromises using log reviews, Microsoft 365 Security Center alerts, identity‑risk notifications, and automated threat signals from Microsoft Defender services. When a potential compromise is identified, we follow a defined incident‑response process covering verification, containment, remediation and customer notification. Incidents are triaged immediately during business hours, with high‑severity issues acted on as a priority. All actions are documented and reviewed to prevent recurrence. Customers also benefit from Microsoft’s continuous protective monitoring across the underlying SaaS platform.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We operate a defined incident‑management process with predefined workflows for common events such as access issues, service disruption and security alerts. Users report incidents via our ticketing system or email, where they are logged, triaged and prioritised. High‑severity incidents are responded to immediately during business hours. We follow a structured process covering identification, containment, remediation and communication. Incident reports and updates are provided to customers through the ticketing portal or email, including root‑cause details where applicable. All incidents are documented and reviewed to prevent recurrence.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Certain Products have a 30-day evaluation or similar Trial available subject to Microsoft campaigns.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 3%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 6ddb32f3-8d59-4d61-98ef-99b7128d7640
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- D5161379-904c-42de-b85a-adbd834707ea
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-