Delta eSourcing and Supply Chain
Delta eSourcing allows for the implementation of standing orders, low-value purchasing and the
full UK tendering process. Through complementary services such as Delta Market Analytics
and Delta Supply Chain, the Delta portfolio supports buyers through all stages of procurement,
from pre-market engagement through to tendering, evaluationm, contract management.
Features
- Publish direct to CDP/FTS, Contracts Finder and buyer portal
- Online PSQ/SQ (PQQ), RFI, RFP, RFT, Tender Box
- Supplier Share code integration with CDP through API
- Auto-score online questionnaires for online evaluation, side by side evaluation
- Register contracts, set reminders, record performance,track spend/change
- Fully branded Buyer Profile with contract noticeboard
- Custom portals with alerts, contracts and opportunities notice board
- Create project workspaces, assign internal/external roles and work collaboratively
- Database of more than 200,000 registered suppliers
- Buyer and supplier helpdesk service for all technical support
Benefits
- eSourcing and eTendering Compliant with UK legislation regulations
- Extensive pool of potential suppliers registered, create lists and invite
- Plan and execute complex procurement projects, multi-Lots
- Save time by auto-scoring online questionnaires, streamlining the evaluation
- One click supplier share code validation
- Repository of contract and supplier performance information
- Secure auditable activity log for organization and users
- Work collaboratively with other departments, shared service and buying organisations
- Assured confidentiality, integrity and availability
- Understand your own data, customise reports to your requirements
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 9 4 2 7 4 5 7 7 0 2 1 2 4 6
Contact
BIP SOLUTIONS LIMITED
Kevin Lewis
Telephone: 0141 270 7362
Email: commercial@bipsolutions.com
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Team collaboration
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- Our service, Delta eSourcing, is designed to provide a seamless and efficient procurement solution; the only constraint that buyers should be aware of to ensure optimal usage. Is that, our planned maintenance activities are scheduled to uphold our high service standards, and these are communicated well in advance to minimise disruption. We usually conduct these out with standard business hours. Regarding system requirements, there are no specific hardware configurations needed since Delta eSourcing is a cloud-based solution, but users must have stable internet access to utilise the platform effectively.
- System requirements
-
- Web Browser
- Stable Internet connection
- Multi-Factor Authentication (MFA)
User support
- Email or online ticketing support
- Yes
- Support response times
-
We prioritise fast, traceable communication throughout the procurement lifecycle. On weekdays, all queries are responded to within 24 hours, with weekend messages logged and addressed promptly on Monday.
Support options include:
• Telephone/Email: Monday–Friday, 8 am – 6 pm GMT.
• Live Chat: Monday–Friday, 9 am – 5 pm GMT, featuring full audit-compliant transcripts.
• 24/7 Webbot: Dedicated exclusively to MFA and password queries.
This structured approach, combining real-time helpdesk specialists and automated tracking, ensures all interactions are logged and managed efficiently, providing buyers and suppliers with reliable assistance during critical business hours. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
We take accessibility seriously and have ensured that our chosen web chat provider, Zendesk, aligns with our commitment to inclusive, user-centred service delivery. While Zendesk was not selected solely on the basis of its accessibility testing approach, this was an important factor in our decision, as Zendesk demonstrates a strong and continuous commitment to progress in this area.
Zendesk conducts automated, manual and real-user testing, including direct involvement from users who rely on assistive technologies such as screen readers, keyboard-only navigation and other adaptive tools. Zendesk’s accessibility programme includes:
• Regular research with agents, administrators and end users who rely on assistive technology, feeding this into product improvements.
• A dedicated Product Accessibility team oversees compliance, supported by “Accessibility Champions” embedded within frontend development teams.
• Commissioning third-party audits and tests against recognised standards, including WCAG 2.1 AA and EN 301 549.
• Accessibility feedback is incorporated at multiple stages, from design through to release, to continually improve usability for all users.
Zendesk acknowledges that accessibility is a continuously evolving area of importance for Delta eSourcing and is committed to active collaboration with assistive-technology users, supporting us to deliver an accessible, inclusive and compliant web chat experience for all. - Onsite support
- Yes, at extra cost
- Support levels
-
We provide a structured and reliable support service designed to meet operational needs efficiently and cost-effectively. Our support framework included as standard and complemented by robust client relationship management, strategic account oversight, and comprehensive system training
Standard support is included at no additional cost, providing access to our helpdesk via telephone, email and live chat (Monday–Friday, 08:00–18:00), alongside comprehensive online guides and FAQs.
• Incident Management: Users can log issues via a service portal. They are then prioritised by severity and impact, and tracked with regular status updates. Post-incident reports include root-cause analysis and corrective actions.
• CRM & Account Management: A dedicated Client Relationship Manager coordinates system implementation, onboarding, migration and initial training. Strategic oversight is maintained through an Account Manager who provides quarterly reviews, sharing platform and compliance updates, commercial and system developments.
Training Services
To maximise system adoption and capability, we offer flexible training sessions, tailored to client requirements:
• Full Day (6 hours): £1,500 + VAT
• Half Day (3 hours): £750 + VAT.
Sessions cover core functionality and best practice. These can be delivered online or onsite (subject to additional travel and subsistence costs). - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Training is an integral part of the Delta implementation process. Initial training is provided to buyer administrators (super users) who then train other organisation staff. Additionally, Delta offers organisation-specific training through either onsite or online training sessions, either presentation style or ‘hands on’ with the trainer guiding users through the different modules using a sandbox environment. Users are provided with access to the sandbox environment – which mirrors the live platform and is updated alongside it – regardless of which training option they choose. This allows users to run example procurements, workflows and collaborations, enabling familiarity before running live procurements. The option of monthly webinar sessions caters for all users. These sessions can be run twice a month for each module and attendee numbers are unlimited. Delta will work with organisations to agree the best approach.
Ongoing support is provided by the Helpdesk, available by phone, email and live chat Monday-Friday 8am-6pm. The Helpdesk provides ongoing support and guidance to both buyers and suppliers using Delta. The Delta site also includes FAQs, help guides and access to scheduled webinars with industry leaders discussing topical procurement agendas and how Delta can facilitate procurement compliance and pathways through system process and workflows. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Training videos
- Implementation documents in Excel
- Word
- .CSV
- End-of-contract data extraction
-
Offboarding is carried out as a sub-project and a formal Impact Statement is provided. The cost of any managed data extraction project is based on volume and timescales of data to be extracted. Delta requires 60 days’ notice before contract expiry to set up a secure data exchange. Data can be provided in Oracle database format, structured XML, Microsoft Excel or .CSV, and any document types stored in the portal. Data will be returned in the format of the buyer’s choice. The buyer can also export all information from Delta before contract expiry. Data extraction is governed by Delta’s Data Exit Policy, which sets out a framework for handling of authority data following the end of an agreement for use of the Delta platform.
If the buyer has a data retention agreement, they can request the return of data at any time. In such cases, the data will be provided within 30 working days of the request. Any return of data will be subject to an impact assessment to determine the effort required and may be subject to a fee.
All actions will be governed by UK GDPR, our Information Security Management System (IS027001) and our Quality Management System (ISO9001). - End-of-contract process
-
Offboarding is carried out as a sub-project and a formal Impact Statement is provided. At the end of the contract, buyer access to the platform ends. Before this, buyers should choose between data retention or data extraction. Options:
Data retention – Offers read-only access to the portal. This is on by licence, costs £2,500+VAT/year per user and requires 30 days’ notice. If a retention agreement is in place, the authority may request data return at any time; delivery occurs within 60 working days, subject to an impact assessment and potential fees.
Self-service – The buyer can export their information from Delta before contract expiry.
Managed data extraction – This is charged for separately and the cost is based on volume and timescales of data to be extracted. Delta requires 60 days’ notice before the expiry of the contract to set up a secure data exchange.
Data extraction is governed by Delta’s Data Exit Policy, which sets out a framework for the handling of buyer data following contract expiry.
All actions are governed by the UK GDPR, our Information Security Management System (ISO270001) our Quality Management System protocols (ISO9001) and our Business Continuity Plan (designed in accordance with BS 25999). - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Mobile-friendly website means that is designed to work the exact same way across devices. This means that nothing changes or is unusable whether the user is on a computer or mobile device.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Delta eSourcing’s Helpdesk Portal allows users and administrators to log, track, and manage issues efficiently. It provides access to FAQs, knowledge bases, user guides, and contact by email, chat and phone.
The platform excels in API/System Integrations, enhancing interoperability with ERP and finance systems. Integration with DocuSign facilitates secure contract signing.
For administration, it includes user management, reporting dashboards, and audit logs. Modular design allows organisations to select modules and customise features to meet their needs. Delta features role-based interfaces for suppliers and buyers, promoting efficiency and transparency while supporting supplier engagement and compliance with the Procurement Act 2023. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Our approach to interface testing with users of assistive technology is comprehensive and aligns with established accessibility standards, ensuring that our web interfaces are usable by all, including those relying on assistive technologies.
Our web interfaces meet the Web Content Accessibility Guidelines (WCAG) 2.1 AA standard, which is critical in making digital content accessible to a broader audience, especially those with disabilities. This compliance assures that our services are accessible in terms of perceivable, operable, understandable and robust content. To ensure our interfaces work seamlessly with assistive technologies, we have conducted extensive testing with assistive technology users. This testing includes the use of screen readers, voice recognition software and other assistive devices. These tests help identify any barriers that users might face and allow us to make adjustments to enhance accessibility. Additionally, our user support services are designed to be accessible. For instance, our web chat support has been tested for accessibility, ensuring it can be used effectively by assistive technology users. The web chat is not automated by bots; instead, it is managed by a helpdesk representative, providing a more human touch in assisting users, with only standard queries on Multi Factor Authentication and passwords managed by the bot. - API
- Yes
- What users can and can't do using the API
-
Delta eSourcing features Open API functionality that allows buyers to extract tender and contract data, including contract management, supplier information and tender details, for integration with third-party systems. This is a one-way process; Delta can only provide data but cannot receive it from other systems. The API is designed for users to collect and transfer data independently. Authorised Delta users can access an API management screen to select specific data entities, such as contracts and suppliers, and generate an API key.
Additionally, Delta is integrated with the Central Digital Platform (CDP). Buyers must be registered on the CDP. At registration, buyers can generate an API key. This key must be added to the organisation’s Delta settings to publish notices on the CDP. Unique API Key Codes and PPONs identify each Public Authority on the CDP. This enhances automation when populating notices for publication to the CDP.
For suppliers, a unique API share code is provided by the CDP upon successful registration, enabling them to pull their information from the CDP into Delta when responding to tenders. This share code automatically populates details into the PSQ or any custom questionnaire set up by the buyer. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Delta eSourcing offers extensive customisation features that empower organisations to tailor the platform to their operational needs. It adapts to organisational structures and objectives, ensuring an optimised procurement experience.
User Roles
Delta has a structured permissions framework with five roles: Buyer Administrator, Supervisor, Registered User, Evaluator, and Auditor. This role-based access supports secure workflows and governance.
Branding and User Experience
Organisations can embed their corporate identity through branded homepages, personalised portals and URLs, enhancing user experience and supplier engagement through a consistent brand presence.
Integration and Automation
Delta's API capabilities enable seamless integration with internal systems, automating tasks and maintaining a unified procurement ecosystem.
Reporting and Dashboards
Customisable reporting tools allow users to tailor dashboards to display relevant metrics, supporting deeper data analysis and informed decision-making.
Market Analytics Customisation
Delta Market Analytics provides configurable market intelligence, facilitating market engagement and supplier identification.
Questionnaire and Template Customisation
Users can create and save customised questionnaire templates for different procurement stages, ensuring consistency and efficiency in tendering.
KPI Configuration
Users can design dynamic KPI forms and assign weightings, aligning measurable outcomes to organisational priorities.
Bespoke Fields
Users can create bespoke fields in the contract register, enhancing governance and efficiency in contract management.
Scaling
- Independence of resources
- Delta is designed to be used simultaneously by multiple users from multiple organisations at multiple sites. A single-organisation enterprise licence has a fair use assumption of 200 users, and the Delta platform currently hosts 500+ organisations. Each organisation is a separate tenant, so no organisation has access to or can affect another organisation’s use or data. Delta eSourcing is a web-based platform, ensuring compatibility across all major browsers and operating systems. It prioritises responsiveness, allowing for seamless access across various device types. Delta also has an automatic save and logout function, ensuring that inactive users do not remain online.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide comprehensive service usage metrics to our clients. Our service notifies users when usage approaches service limits, ensuring there are no unexpected disruptions. Notifications are sent via email, and displayed as banners within the application interface, keeping users informed in real-time and usage forms part of account management reviews. Our analytics service includes access to a range of infrastructure and application metrics, which are available upon request. These metrics encompass operating system performance, access logs and application performance indicators. Additionally we provide tailored, customisable reports, allowing clients to focus on the most relevant metrics to them.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Other
- Other data at rest protection approach
-
Our Approach: Aligned with industry best practices, complies with ISO 27001:2022, Cyber Essentials Plus.
Encryption and Data Security Measures: All data at rest encrypted using industry-standard AES 256-bit encryption, utilising a mix of encryption methods including LUKS, Oracle TDE, proprietary file encryption
Access and Physical Security Controls: PAC, airlocks, CCTV. Access rights adjusted within 24 hours for leavers.
Data Management and Resilience: Includes role- and permission-based access controls, comprehensive audit logging, real-time backups to secondary sites, cold storage.
Data Sanitisation and Disposal: Explicit overwriting of storage before reallocation, destruction of hardware containing data. Complies with CSA CCM v.30, CAS. - Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Delta eSourcing provides flexible, GDPR-compliant data export across all modules. Users can export data related to tender activities, contract records and procurement processes into formats including CSV, Excel, XML, PDF, HTML, and RTF, making data analysis outside the platform easy.
The platform supports both daily analysis and formal offboarding, ensuring data can be transitioned to future systems or retained for compliance. Navigation is supported by an intuitive interface and comprehensive user guides. Whether extracting specific datasets or the full contract register, the system ensures seamless data portability and legal compliance throughout the procurement lifecycle, enabling efficient data management and analysis. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- HTML
- RTF
- Open API
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Word (.doc, .docx)
- .txt files
- Images (.jpeg, .png)
- Spreadsheets (CSV, Excel, .ods)
- Compressed (.zip)
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
1. Encryption standards – Data in Transit TLS 1.3
Data at rest: Virtual encryption, encrypted VM disks, file-based encryption including Oracle TDE.
2. Access Controls and Identity Management: Strict role-/permission-based access controls. Multi-factor authentication.
3. Data Integrity and Monitoring: regular integrity checks, monitoring, audit logging.
4. Physical Security Measures: controlled physical access, PAC, airlocks, CCTV surveillance. Server rooms within secure areas.
5. Incident Management and Response: Formal breach incident management process aligned with ISO 27001:2022 ISMS and GDPR framework.
6. Data Retention and Disposal: Protocols for data archiving/deletion. Explicit overwriting of storage before reallocation; complete destruction of hardware containing data.
Availability and resilience
- Guaranteed availability
-
Our service is guaranteed at 99.9% availability, supported by robust infrastructure and comprehensive SLAs. Our SLAs outline key performance indicators, including availability metrics and response times, which are regularly monitored and reported. Our support structure is designed to ensure that any issues impacting availability are addressed swiftly.
We provide helpdesk support via telephone, email, and live chat from 08:30 to 17:30, Monday to Friday, ensuring direct access to our technical support team for prompt issue resolution.
Adhering to ISO 27001:2022 standards, our proactive monitoring and incident management protocols feature industry-leading response metrics for service-related issues:
• Incident Response: Initial response within 10 minutes; services are isolated immediately if a compromise is detected and then reviewed.
• Vulnerability Management: High and critical vulnerabilities are patched within 24 hours, with others classified by priority and addressed within two weeks.
• Security Patches: Critical patches are prioritised and implemented within 24 to 48 hours.
• Continuous Monitoring: Host-based and network-level alerts allow for real-time responses to pre-emptively resolve performance or security issues.
These structured workflows ensure we maintain high performance, transparency and system integrity while consistently meeting our SLA commitments. - Approach to resilience
- We ensure that application availability is at the heart of our offering so have built in resiliency throughout our network and infrastructure. We operate with multiple fibre lines into our primary datacentre to remove single points of failure, and we run local and DR-site backups daily—shadow copies during the day and a full backup each night. We also maintain a fully managed third-party disaster recovery site to ensure continuity if our primary service was ever impacted. We have full observability across our infrastructure, supported by proactive monitoring and alerting, allowing us to address issues before they affect service. Our operations are aligned to a 99.9% uptime target.
- Outage reporting
- Our service provides comprehensive outage reporting through multiple channels to ensure timely and effective communication with stakeholders. We employ several mechanisms to report outages: We provide immediate email alerts to users in the case of an outage. These alerts ensure that all affected stakeholders are informed promptly about any disruptions and the expected resolution timelines. As part of our Business Continuity Management (BCM) process, we have a defined communication plan that includes notifying staff, customers, and stakeholders about the status of any service disruptions, ensuring transparency and clarity during incidents. Our service is governed by ISO 27001:2022 standards, ensuring that our outage management and reporting processes meet high-security and operational standards. These reporting mechanisms are part of our commitment to maintaining a resilient and reliable service, supported by robust disaster recovery and business continuity plans. Our approach ensures that users remain informed and can plan accordingly in the event of an outage.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Our multi-layered security framework strictly controls access to management and support interfaces through several key pillars:
Identity Management: We enforce Role-Based Access Control (RBAC) and the Principle of Least Privilege, ensuring staff only access necessary functions.
Authentication & Connectivity: Mandatory Multi-Factor Authentication (MFA) via Microsoft, combined with VPNs and IP allow-listing, prevents unauthorized entry.
Visibility: All activities are logged and monitored, providing full traceability for audits and transparency.
Continuous Improvement: Regular penetration testing and configuration audits proactively identify and mitigate vulnerabilities.
These protocols ensure a secure, compliant, and highly resilient operational environment. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus and QMS9001
- Information security policies and processes
- Our organisation's governance standards are rigorously aligned with several internationally recognised standards to ensure comprehensive security and operational excellence. Primarily, our security governance is certified to the ISO/IEC 27001 standard, which ensures that our information security management systems are robust and reliable. Additionally, we comply with the Cyber Essentials Plus scheme, which provides a foundational level of IT security assurance against common online threats. Furthermore, our governance framework is complemented by adherence to other critical standards, such as Cyber Essentials Plus, which further enhances our cyber security posture through rigorous testing and validation processes. We also maintain compliance with the CSA CCM v3.0 for physical access control measures, ensuring that our data centres are secured with multiple layers of protection. This comprehensive approach ensures that our governance standards not only meet but exceed the expectations of our clients and partners, providing them with assurance of our capability to protect and manage sensitive information securely and efficiently.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Our configuration and change management processes ensure service integrity using a CMDB and asset register as the single source of truth. All physical and virtual components are tracked across primary and disaster recovery sites, with regular reconciliations to meet ISO 27001 standards.
Changes undergo systematic security impact assessments before implementation to mitigate evolving risks. This is supported by automated daily vulnerability scanning and annual independent CREST-accredited penetration testing. By integrating lifecycle tracking with rigorous security reviews, we maintain high operational standards and ensure every modification is documented, assessed, and compliant. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Our organisation adheres to a robust vulnerability management process that is aligned with best industry practices and government guidelines. We comply with the ISO/IEC 27001 standard, ensuring that all processes are systematically documented, implemented, and reviewed. Our vulnerability management framework is comprehensive and designed to identify, assess, and mitigate potential threats to our services.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Our organisation’s robust protective monitoring process utilises threat intelligence and ongoing vulnerability scans to continuously monitor for potential threats. Our systems are aligned with ISO 27001:2022 standards, ensuring adherence to best practices in operational security. Host-based monitoring and alerting systems are deployed across our network to detect anomalies and potential compromises in real-time. Integrating comprehensive threat detection and rapid response protocols ensures the integrity and security of our services, maintaining compliance with key operational security principles. Our commitment to regular testing and updating of our incident response capabilities underpins our proactive stance in safeguarding against potential security breaches.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
Our ISO 27001:2022-aligned incident management framework ensures swift, transparent responses to security events. Key features include:
Structured Protocols: Pre-defined, annually tested processes cover detection, triage, and resolution for critical incidents.
Rapid Support: A 24/7 support team monitors reporting channels, targeting a 10-minute response time for initial acknowledgments.
Comprehensive Reporting: Post-incident analyses and real-time updates are provided via the Delta platform, supporting multiple export formats.
Governance: A risk-based approach ensures regulatory compliance, including timely notifications to authorities like the ICO.
This robust framework prioritizes operational security and consistent stakeholder communication. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We offer a sandpit environment that is used for both demonstration and training, this environment mirrors the live functionally, post adoption clients have access to this for the duration of their contract. This also allows prospective buyers an opportunity to try the user interface and workflows pre-adoption.
- Link to free trial
- https://demo.delta-esourcing.com/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Friday 25 April 2008
- What the ISO/IEC 27001 doesn’t cover
- Client-Specific Customisations: While we maintain high security standards across all custom developments, any bespoke client-specific solutions that are not centrally managed or maintained directly by us may not be covered under our ISO/IEC 27001 certification. Nevertheless, we ensure that all customisations adhere to best practice security protocols, and we conduct thorough security assessments where applicable.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- NQA
- ISO 9001 accreditation date
- Friday 3 September 2004
- What the ISO 9001 doesn’t cover
- Payment Card Industry Data Security: Our quality management certification does not include specific protocols for Payment Card Industry Data Security (PCI DSS). Therefore, any requirements related to PCI DSS would need separate consideration as we do not hold this certification.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- D1c4c1ff-3f95-417b-becd-572c46558991
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-