Zoho One – Integrated Digital Operations Platform for the Public Sector
Zoho One is a secure, cloud-based digital operations platform bringing together over 45 integrated business applications. It helps public sector organisations reduce system fragmentation, streamline workflows, and improve visibility across services including CRM, case management, finance, HR, collaboration, and reporting.
Features
- Integrated applications sharing a single data model across departments
- Configurable workflows supporting case management and internal service processes
- Secure, role-based access controls aligned to public sector governance
- Real-time reporting and dashboards across operational and performance data
- Cloud-based access supporting remote, hybrid and multi-site teams
- API-driven integration with existing systems and public sector platforms
- Low-code tools for building and adapting processes without redevelopment
- Centralised document management with version control and audit trails
- Built-in collaboration tools reducing reliance on disconnected third-party systems
- Scalable architecture supporting organisational change and service expansion
Benefits
- Reduce manual work by automating cross-departmental processes and approvals
- Improve service delivery through shared data and consistent case handling
- Increase operational visibility with real-time reporting across teams
- Support hybrid working with secure access from any location
- Simplify system estates by replacing multiple disconnected applications
- Adapt processes quickly without costly redevelopment or vendor dependency
- Improve accountability using role-based access and audit trails
- Enable better decision-making through reliable, joined-up management information
- Scale digital services as organisational needs and demand change
- Achieve better value for money through a single, integrated platform
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 3 8 2 4 3 3 4 9 5 6 2 9 9 4
Contact
ZOHO CORPORATION LIMITED
Corie Robinson
Telephone: +44 2038072092
Email: zohouk-gcloud@eu.zohocorp.com
About your service
- Service categories
-
Applications
Customer relationship management
- Marketing campaign management
- Digital commerce
- Sales force productivity and management
- Customer service
- Contact centre
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Only cloud-based deployment and no support for an on-premise setting.
- System requirements
-
- Stable internet connectivity Chrome
- Chrome - 10 and above
- Mozilla Firefox - 8 and above
- IE - 10 and above
- Safari - 5 and above
- Opera - 12.1 and above
User support
- Email or online ticketing support
- Yes
- Support response times
- We offer free technical support eight hours per workday, as well as Premium and Enterprise support tiers that make our experts available 24/5 and 24/7, respectively. The response time for Premium would be 3 hours and as of Enterprise would be 1 hour.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Zoho tests its web chat functionality as part of its broader accessibility assurance programme aligned with WCAG 2.2 AA. Testing includes validation of web chat interfaces with assistive technologies such as screen readers, keyboard-only navigation and screen magnification tools to ensure users can initiate, read and respond to chat interactions without barriers.
Testing activities focus on keyboard operability, logical focus order, accessible labelling, readable notifications, colour contrast and compatibility with commonly used assistive technologies. Automated accessibility testing tools are complemented by manual testing carried out by trained internal teams to identify issues that require human assessment.
Accessibility testing is incorporated into the development and quality assurance lifecycle for web-based features, including web chat, to ensure updates do not introduce regressions. Issues identified through testing or user feedback are logged, prioritised and remediated as part of ongoing product improvements.
While Zoho does not run customer-specific assistive technology trials for each deployment, accessibility validation is consistently applied across the platform to support inclusive use of web chat functionality for all users. - Onsite support
- Yes, at extra cost
- Support levels
-
Zoho One is supported through three clearly defined support levels, allowing organisations to select coverage aligned to service criticality and internal capability.
Classic Support (included)
Included at no additional cost with all Zoho One subscriptions. Provides technical support via email, phone and online ticketing during UK business hours (Monday to Friday). Suitable for non-critical operational use and standard technical queries.
Premium Support (optional)
Available at an additional cost of approximately 20% of the subscription value. Provides priority support with extended coverage 24 hours per day, Monday to Friday, across email, phone and live chat. Designed for organisations requiring faster response times and reduced operational risk.
Enterprise Support (optional)
Available at approximately 25% of the subscription value (minimum user thresholds apply). Provides 24/7 support coverage, priority escalation, and proactive assistance. Includes access to a Technical Account Manager or designated cloud support engineer, supporting incident management, escalation coordination and ongoing technical guidance.
All support levels include access to online documentation, knowledge bases and remote troubleshooting tools. Support can be scaled up or down over time to reflect changing operational requirements. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
Zoho One provides a range of onboarding and learning resources to help users begin using the service effectively. All users have access to online documentation and guides, including detailed getting started content, admin setup guides and application FAQs. A central resource hub offers how-to articles, webinars, short “Zoho One Minutes” videos, and community forums to support learning at scale.
Organisations can also benefit from live webinars and scheduled online training sessions that cover core features, navigation and common workflows.
For deeper support, optional training and implementation services are available through Zoho’s partner network, including onsite or virtual training workshops, tailored sessions and consultancy to accelerate adoption. These sessions can cover setup, configuration, customisation and best practices aligned to an organisation’s specific needs.
Users can raise requests through the support portal for assistance with onboarding challenges, ensuring help is available if required during early use of the platform. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, users can extract their data using built-in export tools available within Zoho One applications. Data can be exported in commonly used formats such as CSV and Excel, enabling reuse in other systems. Many applications also support report-based exports and API access to retrieve structured data programmatically.
Data extraction is performed through the web-based interface by authorised users, subject to role-based permissions. Where required, APIs can be used to support bulk data extraction or integration with third-party data migration tools.
Users are responsible for initiating and managing data exports prior to service termination. Zoho provides documentation and support resources to guide users through the export process. Once the contract ends and any applicable retention period expires, customer data is deleted in accordance with Zoho’s data retention and deletion policies. - End-of-contract process
-
At the end of the contract term, access to Zoho One continues until the subscription expiry date. During this period, users can export their data using the standard data export tools available within the service. No automatic contract renewal occurs unless agreed by the customer.
The subscription price includes access to the Zoho One platform, standard product updates, security patches, and Classic Support as defined in the support section. There are no additional charges for routine maintenance, upgrades, or access to online documentation and self-service resources.
Optional services are available at additional cost and are not included in the standard subscription price. These may include enhanced support tiers (Premium or Enterprise Support), tailored training, onboarding assistance, implementation services, or consultancy delivered either remotely or onsite.
Following contract expiry and any applicable data retention period, customer data is securely deleted in accordance with Zoho’s data retention and deletion policies, unless the customer renews or extends the service. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Mobile applications are designed for end users and provide secure, role-based access to Zoho One applications while on the move. Users can view and update records, manage tasks and approvals, log activities, access dashboards, and receive notifications. Administrator-level configuration, advanced customisation, system setup and application administration are not available through the mobile apps and must be completed using the desktop browser interface. The desktop service provides full configuration, integration management and governance controls required for organisational administration.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Zoho One is accessed through a secure, web-based browser interface that provides a consistent experience across all included applications. Users access services through a central dashboard, with navigation based on role and permissions. The interface supports configurable menus, dashboards and workflows, allowing organisations to reflect their operating structure. Applications share a common design language and data model, reducing training effort and improving usability. The service supports modern web browsers and does not require local software installation. Mobile applications provide complementary access for end users where required.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Zoho One is developed in alignment with WCAG 2.2 AA accessibility guidelines. Zoho performs accessibility reviews across Zoho One applications using assistive technologies such as screen readers, keyboard-only navigation and screen magnification tools to validate usability of core workflows. Testing includes compatibility checks with commonly used assistive technologies and verification that interactive elements, focus order, colour contrast and labelling meet accessibility requirements. Zoho undertakes periodic accessibility audits and remediation activities as part of its ongoing accessibility compliance and product improvement programme.
- API
- Yes
- What users can and can't do using the API
-
Zoho One provides open REST APIs across many applications within the suite to support integration, data exchange and automation. Authorised users can perform actions such as creating, updating, retrieving and deleting records (subject to permissions), triggering workflows, synchronising data, and accessing reports and audit information where supported by the application.
APIs cannot be used to bypass role-based access controls, modify system-level or organisation-wide configurations, change subscription or licensing settings, or perform administrative actions reserved for the web-based interface. API usage is governed by authentication requirements, application-specific rate limits, and the permissions assigned to the calling user, ensuring secure and controlled integration. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Zoho One can be customised to reflect an organisation’s processes, structures and reporting requirements across included applications. Customisation options vary by application but commonly include custom fields, page layouts, workflows, approval processes, dashboards, reports, user roles and permissions.
Authorised users can customise the service through the web-based administrative interface using configuration tools and low-code capabilities. This includes modifying data models, automating processes, creating custom views and reports, and tailoring user experiences without requiring code. Where required, APIs and scripting tools can be used to extend or integrate functionality, subject to application support.
Customisation is controlled through role-based access. Typically, system administrators or designated configuration users are responsible for making and governing changes. End users can personalise aspects such as dashboards, views and notifications within the permissions assigned to them. Core platform settings, security policies and subscription management are restricted to authorised administrative roles to maintain governance, auditability and system integrity.
Scaling
- Independence of resources
- Zoho One is delivered using a multi-tenant cloud architecture designed to scale automatically and manage demand across users. Resources are logically isolated between customers, and system capacity is monitored continuously to maintain consistent performance. Zoho applies traffic management, load balancing and capacity planning to prevent individual customers’ usage from adversely affecting others. Usage controls and application-level limits are in place to protect service stability and ensure fair use across the platform.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export their data using built-in export tools available within Zoho One applications. Authorised users can export data through the web-based interface in commonly used formats such as CSV or Excel. Report-based exports allow filtered or structured datasets to be extracted. APIs are also available for supported applications to enable programmatic data export or bulk extraction. All data export activities are governed by role-based access controls and user permissions. Documentation and support resources are provided to guide users through the export process.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- Other
- Other protection within supplier network
- Zoho protects data within its network using layered security controls. Data stored in Zoho data centres is encrypted at rest using strong encryption standards. Internal traffic between services, storage systems and disaster recovery sites is encrypted to prevent unauthorised access. Zoho operates fully controlled data centres with restricted physical access, continuous monitoring and dedicated security systems. Network protections include firewalls, intrusion detection and prevention, and segmentation to isolate sensitive components and limit lateral movement. Access to production systems is restricted to authorised personnel following strict authentication, logging and approval processes.
Availability and resilience
- Guaranteed availability
-
Zoho One is delivered using a resilient, distributed cloud infrastructure designed to support high availability and continuity of service. The platform uses redundancy, load balancing and continuous monitoring across its data centre environments to minimise service disruption and maintain consistent performance for users.
Zoho targets a high level of service availability, typically measured at 99.9% uptime, excluding scheduled maintenance and events outside Zoho’s reasonable control. Planned maintenance activities are communicated in advance where possible and are designed to minimise impact on users.
Service availability and historical uptime performance can be monitored through Zoho’s publicly available service status pages, providing transparency into platform health and incident resolution.
Standard Zoho One subscriptions do not include a contractual availability Service Level Agreement (SLA) with financial service credits or refunds if availability targets are not met. Where required, enhanced availability commitments, escalation paths or service credits may be agreed separately through bespoke contractual or support arrangements. This approach allows organisations to align availability commitments with the criticality of their use case and operational requirements. - Approach to resilience
-
Zoho One is designed with built-in resilience across its application, network and data layers. Application data is stored on resilient storage systems and replicated across geographically separate data centres. Data held in the primary data centre is replicated to a secondary site in near real time. In the event the primary site becomes unavailable, services can fail over to the secondary data centre, supporting continuity of operations with minimal disruption.
Zoho’s data centre environments use multiple independent internet service providers and incorporate redundant networking, compute and storage components to reduce single points of failure. Physical resilience controls include redundant power supplies, backup generators, environmental and temperature controls, and fire detection and suppression systems.
Zoho maintains documented Business Continuity and Disaster Recovery plans covering critical services, infrastructure management and customer support operations. These plans are reviewed and tested periodically to validate recovery procedures and ensure ongoing service resilience. Further information on datacentre locations, certifications and resilience controls can be provided on request. - Outage reporting
-
Zoho reports service outages and operational issues through multiple channels to ensure transparency and timely communication.
A public service status dashboard is available, showing the real-time operational status of Zoho services, including Zoho One and its underlying applications. The dashboard provides current status, incident updates and recent outage history, allowing users to independently verify service availability.
Zoho also supports email notifications for service incidents and planned maintenance. Users can subscribe to receive alerts when service status changes or when maintenance activities are scheduled, helping organisations proactively manage operational impact.
While Zoho does not currently provide a dedicated outage-reporting API, status information is publicly accessible and can be monitored using third-party status aggregation or alerting tools if required.
In addition, customers can raise or track incidents through Zoho’s support channels, where updates and guidance are provided during service disruptions affecting their environment.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Zoho restricts access to management interfaces and support environments through least-privilege and role-based permissions. Only authorised personnel may access production systems, and authentication requires strong passwords, multi-factor authentication and the use of hardened devices on a segregated administrative network. All administrative actions are logged and periodically audited. Support staff do not have direct access to customer data unless explicitly authorised for a specific support request. Any access is logged, monitored and governed by strict internal policies. These controls prevent unauthorised access and ensure management interfaces and support channels remain secure and controlled.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Other standards include ISO/IEC 27701, ISO/IEC 27017, ISO/IEC 27018, SOC 2 Type II, HIPAA-compliant controls for eligible services, and CSA STAR Level 1 certification. These frameworks cover privacy management, cloud security, protection of personal data, independent assurance reporting, and cloud control transparency.
- Information security policies and processes
-
Zoho maintains a comprehensive information security management programme aligned with ISO/IEC 27001, supported by additional standards including ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701 and SOC 2 Type II. This programme establishes the policies, procedures and technical controls used to protect customer data from unauthorised access, alteration, disclosure or loss.
Zoho’s documented policies cover areas such as access control, encryption, asset management, physical security, secure development, incident response, vulnerability management, supplier management and data privacy. Policies extend to employee responsibilities, acceptable use requirements and confidentiality obligations. These documents are communicated to staff during onboarding and reinforced through mandatory periodic training.
Information security governance is managed by Zoho’s central Security and Compliance team, which reports into senior leadership. Control owners are designated across engineering, operations, support and facilities teams, with responsibility for implementing and monitoring relevant controls. Zoho conducts internal reviews, technical monitoring, access audits and risk assessments to ensure policies are followed.
Policies are formally reviewed at least annually or whenever significant operational or regulatory changes occur. Compliance with Zoho’s information security policies is independently validated through recurring external audits for ISO and SOC certifications.
These processes ensure consistent alignment with industry best practices and regulatory expectations. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Zoho follows documented configuration and change management processes aligned with ISO/IEC 27001 and SOC 2 controls. Service components are recorded in configuration repositories where ownership, versions and lifecycle status are tracked. All changes are assessed for security and privacy impact, reviewed by appropriate approvers and implemented with defined rollback procedures. Audit logs are maintained for traceability. High-risk or service-affecting changes receive additional security review. Emergency changes follow an expedited but controlled workflow. Zoho notifies customers of changes that may materially affect their use of the service. These processes ensure controlled, secure and traceable updates to the platform.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Zoho operates a structured vulnerability management process using certified third-party scanners, internal security tools and periodic automated and manual penetration testing. Potential threats are identified through continuous monitoring, vulnerability feeds, public advisories, security mailing lists and industry threat-intelligence sources. When a vulnerability is detected, it is logged, assessed for severity and risk, and assigned to an owner. Critical vulnerabilities are prioritised for immediate remediation, and patches or mitigating controls are deployed as quickly as possible following validation. All remediation activity is tracked to closure, with verification performed by the security team to ensure the issue has been resolved.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Zoho monitors its services using centralised logging, automated alerting and continuous analysis of events across applications, network traffic and system activity. Logs include access, audit, administrator and security events, which are stored securely and monitored for anomalies such as unusual authentication behaviour or unauthorised access attempts. When a potential compromise is identified, alerts are escalated to the Security Incident Response Team for investigation. Incidents are assessed, contained and remediated according to severity, with high-risk events addressed immediately. Zoho follows documented incident response procedures and tracks each incident through to closure, including post-incident review.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Zoho maintains documented incident management procedures for common security, privacy and service events. Incidents are logged, categorised and handled by Zoho’s Security Incident Response Team using predefined investigation, containment and recovery workflows.
Users can report security or privacy incidents directly via email, where they receive high-priority attention. Other service-related issues can be raised through standard support channels.
When an incident affects a customer, Zoho provides notifications and a summary reports outlining the event, impact and corrective actions. Broad service incidents are communicated through service announcements, status pages or community channels.
Post-incident reviews help prevent recurrence. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Zoho One provides a free, time-limited trial allowing organisations to evaluate the full suite of applications. The trial includes core functionality for configuration and testing but excludes enhanced support and service level guarantees. The trial typically lasts 30 days, after which a paid subscription is required.
- Link to free trial
- https://www.zoho.com/one/signup.html
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Wednesday 3 September 2025
- What the ISO/IEC 27001 doesn’t cover
-
ISO/IEC 27001 certifies our Information Security Management System (ISMS) and confirms that we have appropriate governance, controls, and continual improvement processes in place to manage information security risks within the defined scope of certification.
The certification does not certify individual products or specific technical features in isolation. Instead, it applies to the management framework, policies, processes, and controls that govern how information security is implemented and operated across our in-scope services.
Activities, systems, or services outside the formally defined ISMS scope are not covered by the ISO/IEC 27001 certification. This may include third-party services or infrastructure not operated or controlled by us, or internal systems not directly involved in the delivery of certified services.
ISO/IEC 27001 also does not replace or automatically include other standards (such as ISO/IEC 27017 or ISO/IEC 27018 - Which Zoho Corporation has obtained both certifications), which address cloud-specific controls and protection of personally identifiable information and are assessed separately where applicable. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Thursday 23 March 2023
- What the ISO 9001 doesn’t cover
-
ISO 9001:2015 certifies our Quality Management System (QMS) and confirms that we have defined, implemented, and continually improved processes to ensure consistent service delivery within the certified scope.
The certification does not certify individual products, features, or technical performance in isolation. It focuses on the management framework for quality rather than guaranteeing specific service outcomes, configurations, or performance levels for individual services.
Activities, systems, or services outside the formally defined QMS scope are not covered by the ISO 9001 certification. This may include third-party services, customer-managed configurations, or internal processes not directly involved in the delivery and support of in-scope services.
ISO 9001 also does not address information security, privacy, or data protection controls, which are covered separately under standards such as ISO/IEC 27001 and related certifications. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Monday 4 August 2025
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
-
Zoho’s listing in the CSA Security, Trust & Assurance Registry (STAR) is based on a STAR Level 1 Self-Assessment, which documents how our cloud security controls align with the Cloud Security Alliance Cloud Controls Matrix (CCM).
The STAR self-assessment applies to the security control framework and governance practices for our cloud services. It does not certify individual products, specific service configurations, or customer-managed settings in isolation.
Activities or services outside the scope of the published STAR self-assessment, including customer-controlled configurations, integrations with third-party services, or infrastructure not operated or controlled by Zoho, are not covered.
CSA STAR also does not replace other standards covering information security, privacy, or quality management, which are addressed separately through certifications such as ISO/IEC 27001 and related standards.
In summary, CSA STAR provides transparency into our cloud security controls within scope, but not independent certification or coverage of out-of-scope services or configurations. - PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Df4a2fb2-58c7-428b-b622-0d1dbd68ae22
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 061e91c4-e56a-4f0c-a09c-66fea8d9c587
- Other security certifications
- Yes
- Any other security certifications
-
- ISO/IEC 27017 (Cloud Security Controls)
- ISO/IEC 27018 (Protection of PII in public cloud)
- ISO/IEC 27701 (Privacy Information Management / PIMS)
- SOC 2 Type II
- CSA STAR (Level 1 Self-Assessment)
- Data Security and Protection Toolkit (DSPT)
- GDPR
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-