Skip to main content

Help us improve the Digital Marketplace - send your feedback

CDS

Optimizely Content Management System

Optimizely is a digital experience platform (DXP) and web content management platform with powerful, market-leading software and high-availability, scalable cloud hosting. Optimizely is a SaaS platform offering ease of use and connectivity with other cloud services and systems.

Features

  • Optimizely's Elastic scaling to support traffic peaks and bursts
  • Based on latest Microsoft cloud technology, Azure Web Apps
  • Optimal performance via a content delivery network (CDN)
  • Separate environments for integration/test, pre-production and production
  • Best-of-breed services from vendors via connectors and add-ons
  • 24x7x365 global operations for Optimizely maintenance and support
  • Online reports for website and transaction performance
  • Proactive application monitoring and end-user experience monitoring
  • Data back-up and retention
  • DDOS mitigation

Benefits

  • Optimizely SLA guarantee on service availability
  • Unlimited number of Optimizely websites
  • Unlimited number of Optimizely CMS editors and administrators
  • Scaled packages available to suit your traffic and content needs
  • Includes Optimizely Search & Navigation enterprise search product
  • Lower total cost of ownership with a fully managed service
  • Single platform including commerce, CMS and campaign
  • Leader in Gartner Magic Quadrant (web content management and DXP)
  • CDS is ISO20000-certified Optimizely Premium Solution Partners

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@cds.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 0 4 8 0 2 5 7 6 3 5 6 8 4 7

Contact

CDS Jonathan Astin
Telephone: 07904570073
Email: bidteam@cds.co.uk

About your service

Service categories

Applications

Content workflow and management

  • Capture
  • Document
  • Creative

Content services

  • Enterprise Content Management Applications
  • Content Sharing and Collaboration Applications

Persuasive content management

  • Website Software
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Deployment is on public cloud.
System requirements
  • Content editing: IE11, Firefox latest, Google Chrome, latest
  • Optimizely provides all needed PaaS and SaaS services
  • Visual Studio. Optional Azure Dev Ops, Octopus Deploy, GitHub

User support

Email or online ticketing support
Yes
Support response times
24/7/365 support with 30 minute response on Priority 1
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
No
Support levels
All Optimizely Digital Experience Cloud Service contracts include 24/7/365 support and is not charged separately.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
CDS commissions the DXP service which provides the platform and tools we need to build your website. We undertake discovery, design and development processes appropriate to your requirements, through to full system testing. The approved solution is deployed to the production environment by Optimizely.
CDS provides tutor-led, on-site training for editors and administrators, and template user guides. Optimizely also provides certified training courses and online user documentation for the application.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
All documentation is available at www.optimizely.com
End-of-contract data extraction
Through request to CDS or the Optimizely Managed Service desk, a full back-up of the Optimizely database and accompanying binary assets can be provided. CDS can provide additional Exit Planning and Management services upon request.
End-of-contract process
Subject to 90 days' termination notice being provided, there is no additional cost for ending the contract after the original contract period. If the termination date requested is before the end of the contracted period, the remaining period must be paid for in order to terminate. CDS can provide Exit Planning and Management services to assist in the transition.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
End user applications are designed to support both desktop & mobile. The content creation / admin interfaces are usually used on desktop browsers, but can be used on tablets. A smartphone is generally too small of an interface for the purpose of easily creating / managing web content.
Service interface
Yes
User support accessibility
WCAG 2.2 AAA
Description of service interface
The user and administration interface for Optimizely is browser based and can be customised to meet the requirements of the user.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
None
API
Yes
What users can and can't do using the API
Anything is possible using Optimizely APIs. Primary APIs are provided for Content Creation / Management, Content Delivery, Search and Deployment
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
- Nearly the entire Optimizely suite can be extended / built on top of including all HTML presentation templates, authentication providers, site functionality and Optimizely editor functionality.
- Customisation takes place using .net languages such as C# or VB.net and also in Javascript. This work is done Visual Studio.
Anyone with access to the solution source code can customised. This is normally Optimizely implementation partners or clients with appropriate development skills who own the overall solution.

Scaling

Independence of resources
Each customer's Optimizely DXP implementation runs as a single tenant solution with its own dedicated set of resources that scale using public cloud infrastructure.

Analytics

Service usage metrics
Yes
Metrics types
Service level metrics
CMS activity, e.g. pages published
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Optimizely

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
No
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
Data can be exported directly from the database or an export can be run that downloads content as a compressed XML file.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
SLA for availability starts at 99.7% and moves to 99.9% depending on package. If availability falls below the Service(s) SLA, the Customer has the right to obtain a reduction on the monthly fee for the affected Service(s). The reduction shall correspond to ten (10) percent of the monthly fee for each interval of one (1) hour that the effective availability falls below the SLA for the affected Service(s). For example, if there are thirty (30) days in the month, and the SLA is 99.5% (716 out of 720 possible hours), should actual availability be only 715 hours, the monthly fee will be reduced 10%. The reduction is limited to the actual month when the agreed availability level has fallen short. This compensation shall be Customer’s sole remedy for interruption or delay in Service(s) supplied by Optimizely.
Approach to resilience
Optimizely Digitial Experience Cloud Platform services are primarily based on Microsoft Azure services and utilise other cloud services. Full details around resiliency are available on request.
Outage reporting
Email alerts, public dashboard, phone notification

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access management is enforced at different levels in the DXP-S. Optimizely's PaaS portal is used to administer and manage a client's DXP users. Only authorised Optimizely users with set permissions are allowed to manage the service, this is controlled via AzureAD; stings are also hard coded in the portal. Client developers or partners are allowed to access the DXP integration environment only; users must be requested. Customer editors can authenticate with the DXP via their own chosen federated security if they wish, Optimizely can also restrict access via set IP ranges if required.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Optimizely's ISMS is based on NIST Cybersecurity Framework and ISO 27001. Optimizely DXP is continuously certified to ISO 27001. Work is in progress to certify DXP to SSAE 18 SOC 2.
Information security policies and processes
Optimizely 's ISMS has management representative down commitment, with regards to the DXP this covers operations, Managed Services, IT, HR, Finance, Facilities, Legal, Product Management, Marketing and Sales. Annual training on Optimizely 's ISMS (and new starter training for new employees and contactors) is enforced via our LMS. All employees receive ISMS training to ensure that their responsibilities are understood and enforced across their duties.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Optimizely development teams follow an iterative software development Lifecycle regarding code changes. Optimizely performs web vulnerability scans that look for the OWASP top 10 vulnerabilities and use the OWASP references as a guide during development. We have a review process for all changes/releases to our software (weekly), restricted to select publishers (who have have been trained against our ISMS).

Microsoft Azure teams follow a formal Security Development Life-Cycle process for their services which Optimizely consume on our service. For more information, please review: https://www.microsoft.com/en-us/sdl/
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Optimizely DXP provides a WAF to stop attacks at the network edge, protecting your website from common threats and specialized attacks before they reach your service. Microsoft is also protected by an active IDS/IPS system, which uses a number of techniques to detect threats.

Microsoft and their Red Team regularly pen test the underlying infrastructure of DXC Service. The Optimizely platform is also subject to regular pen tests conducted by customers and partners.

If a threats are detected these will follow Optimizely’s incident management process and are escalated gaining the highest priority available.
Microsoft is responsible for patch management.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Optimizely DXP provides centralized monitoring and analysis for continuous visibility and timely alerts to the teams who manage the service. We have a number of set triggers and thresholds, benchmarked against typical consumption or behaviour on your website. If unanticipated performance behaviour is detected (for example repetitive behaviour, creating increased scale in the service) we have hooks to alert our service desk to look into the issue and block the traffic if necessary

Security incidents receive highest priority and clients are notified without undue delay.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
CDS operate a mature Incident and Service Request Management process, certified to the ISO 20000 standard. The process is operated by our Service Management tool, which is interactive and can be configured to support the ticket workflow and metrics agreed with customers. Customers can report and update incidents via our interactive portal, email and telephone. Though we operate a core Incident Management policy and process, these can be tailored within customers Service Level Agreements to support common incidents and events. We operate a separate Major Incident Management process, which can provide incident reports, post-mortems etc., when criteria are triggered.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
NQA
ISO/IEC 27001 accreditation date
Friday 5 November 2004
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
NQA
ISO 9001 accreditation date
Friday 18 May 2001
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
30590b83-9532-4856-b047-7e4d3cc128c9
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
107e4854-eda7-403a-81ce-1cb3b4cf4d6c
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Plans for positive actions with community groups.
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@cds.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.