Optimizely Content Management System
Optimizely is a digital experience platform (DXP) and web content management platform with powerful, market-leading software and high-availability, scalable cloud hosting. Optimizely is a SaaS platform offering ease of use and connectivity with other cloud services and systems.
Features
- Optimizely's Elastic scaling to support traffic peaks and bursts
- Based on latest Microsoft cloud technology, Azure Web Apps
- Optimal performance via a content delivery network (CDN)
- Separate environments for integration/test, pre-production and production
- Best-of-breed services from vendors via connectors and add-ons
- 24x7x365 global operations for Optimizely maintenance and support
- Online reports for website and transaction performance
- Proactive application monitoring and end-user experience monitoring
- Data back-up and retention
- DDOS mitigation
Benefits
- Optimizely SLA guarantee on service availability
- Unlimited number of Optimizely websites
- Unlimited number of Optimizely CMS editors and administrators
- Scaled packages available to suit your traffic and content needs
- Includes Optimizely Search & Navigation enterprise search product
- Lower total cost of ownership with a fully managed service
- Single platform including commerce, CMS and campaign
- Leader in Gartner Magic Quadrant (web content management and DXP)
- CDS is ISO20000-certified Optimizely Premium Solution Partners
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 0 4 8 0 2 5 7 6 3 5 6 8 4 7
Contact
CDS
Jonathan Astin
Telephone: 07904570073
Email: bidteam@cds.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
- Capture
- Document
- Creative
Content services
- Enterprise Content Management Applications
- Content Sharing and Collaboration Applications
Persuasive content management
- Website Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Deployment is on public cloud.
- System requirements
-
- Content editing: IE11, Firefox latest, Google Chrome, latest
- Optimizely provides all needed PaaS and SaaS services
- Visual Studio. Optional Azure Dev Ops, Octopus Deploy, GitHub
User support
- Email or online ticketing support
- Yes
- Support response times
- 24/7/365 support with 30 minute response on Priority 1
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- No
- Support levels
- All Optimizely Digital Experience Cloud Service contracts include 24/7/365 support and is not charged separately.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
CDS commissions the DXP service which provides the platform and tools we need to build your website. We undertake discovery, design and development processes appropriate to your requirements, through to full system testing. The approved solution is deployed to the production environment by Optimizely.
CDS provides tutor-led, on-site training for editors and administrators, and template user guides. Optimizely also provides certified training courses and online user documentation for the application. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- All documentation is available at www.optimizely.com
- End-of-contract data extraction
- Through request to CDS or the Optimizely Managed Service desk, a full back-up of the Optimizely database and accompanying binary assets can be provided. CDS can provide additional Exit Planning and Management services upon request.
- End-of-contract process
- Subject to 90 days' termination notice being provided, there is no additional cost for ending the contract after the original contract period. If the termination date requested is before the end of the contracted period, the remaining period must be paid for in order to terminate. CDS can provide Exit Planning and Management services to assist in the transition.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- End user applications are designed to support both desktop & mobile. The content creation / admin interfaces are usually used on desktop browsers, but can be used on tablets. A smartphone is generally too small of an interface for the purpose of easily creating / managing web content.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AAA
- Description of service interface
- The user and administration interface for Optimizely is browser based and can be customised to meet the requirements of the user.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- None
- API
- Yes
- What users can and can't do using the API
- Anything is possible using Optimizely APIs. Primary APIs are provided for Content Creation / Management, Content Delivery, Search and Deployment
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
- Nearly the entire Optimizely suite can be extended / built on top of including all HTML presentation templates, authentication providers, site functionality and Optimizely editor functionality.
- Customisation takes place using .net languages such as C# or VB.net and also in Javascript. This work is done Visual Studio.
Anyone with access to the solution source code can customised. This is normally Optimizely implementation partners or clients with appropriate development skills who own the overall solution.
Scaling
- Independence of resources
- Each customer's Optimizely DXP implementation runs as a single tenant solution with its own dedicated set of resources that scale using public cloud infrastructure.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Service level metrics
CMS activity, e.g. pages published - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Optimizely
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- No
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Data can be exported directly from the database or an export can be run that downloads content as a compressed XML file.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- SLA for availability starts at 99.7% and moves to 99.9% depending on package. If availability falls below the Service(s) SLA, the Customer has the right to obtain a reduction on the monthly fee for the affected Service(s). The reduction shall correspond to ten (10) percent of the monthly fee for each interval of one (1) hour that the effective availability falls below the SLA for the affected Service(s). For example, if there are thirty (30) days in the month, and the SLA is 99.5% (716 out of 720 possible hours), should actual availability be only 715 hours, the monthly fee will be reduced 10%. The reduction is limited to the actual month when the agreed availability level has fallen short. This compensation shall be Customer’s sole remedy for interruption or delay in Service(s) supplied by Optimizely.
- Approach to resilience
- Optimizely Digitial Experience Cloud Platform services are primarily based on Microsoft Azure services and utilise other cloud services. Full details around resiliency are available on request.
- Outage reporting
- Email alerts, public dashboard, phone notification
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access management is enforced at different levels in the DXP-S. Optimizely's PaaS portal is used to administer and manage a client's DXP users. Only authorised Optimizely users with set permissions are allowed to manage the service, this is controlled via AzureAD; stings are also hard coded in the portal. Client developers or partners are allowed to access the DXP integration environment only; users must be requested. Customer editors can authenticate with the DXP via their own chosen federated security if they wish, Optimizely can also restrict access via set IP ranges if required.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Optimizely's ISMS is based on NIST Cybersecurity Framework and ISO 27001. Optimizely DXP is continuously certified to ISO 27001. Work is in progress to certify DXP to SSAE 18 SOC 2.
- Information security policies and processes
- Optimizely 's ISMS has management representative down commitment, with regards to the DXP this covers operations, Managed Services, IT, HR, Finance, Facilities, Legal, Product Management, Marketing and Sales. Annual training on Optimizely 's ISMS (and new starter training for new employees and contactors) is enforced via our LMS. All employees receive ISMS training to ensure that their responsibilities are understood and enforced across their duties.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Optimizely development teams follow an iterative software development Lifecycle regarding code changes. Optimizely performs web vulnerability scans that look for the OWASP top 10 vulnerabilities and use the OWASP references as a guide during development. We have a review process for all changes/releases to our software (weekly), restricted to select publishers (who have have been trained against our ISMS).
Microsoft Azure teams follow a formal Security Development Life-Cycle process for their services which Optimizely consume on our service. For more information, please review: https://www.microsoft.com/en-us/sdl/ - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Optimizely DXP provides a WAF to stop attacks at the network edge, protecting your website from common threats and specialized attacks before they reach your service. Microsoft is also protected by an active IDS/IPS system, which uses a number of techniques to detect threats.
Microsoft and their Red Team regularly pen test the underlying infrastructure of DXC Service. The Optimizely platform is also subject to regular pen tests conducted by customers and partners.
If a threats are detected these will follow Optimizely’s incident management process and are escalated gaining the highest priority available.
Microsoft is responsible for patch management. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Optimizely DXP provides centralized monitoring and analysis for continuous visibility and timely alerts to the teams who manage the service. We have a number of set triggers and thresholds, benchmarked against typical consumption or behaviour on your website. If unanticipated performance behaviour is detected (for example repetitive behaviour, creating increased scale in the service) we have hooks to alert our service desk to look into the issue and block the traffic if necessary
Security incidents receive highest priority and clients are notified without undue delay. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- CDS operate a mature Incident and Service Request Management process, certified to the ISO 20000 standard. The process is operated by our Service Management tool, which is interactive and can be configured to support the ticket workflow and metrics agreed with customers. Customers can report and update incidents via our interactive portal, email and telephone. Though we operate a core Incident Management policy and process, these can be tailored within customers Service Level Agreements to support common incidents and events. We operate a separate Major Incident Management process, which can provide incident reports, post-mortems etc., when criteria are triggered.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Friday 5 November 2004
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- NQA
- ISO 9001 accreditation date
- Friday 18 May 2001
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 30590b83-9532-4856-b047-7e4d3cc128c9
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 107e4854-eda7-403a-81ce-1cb3b4cf4d6c
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Plans for positive actions with community groups.
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-