JAGGAER Procure to Pay (P2P)
JAGGAER offers a comprehensive Procure-to-Pay (P2P) suite including Contracts, eProcurement (Guided Buying, Catalogues, Punch-outs, Request Forms, Shopping, Requisitions, Purchase Orders), Invoicing (Receipts, Accounts Payable), Inventory Management, and extensive supporting features plus optional integration with JAGGAER Source-to-Contract (S2C) for Sourcing & Supplier Management.
Features
- Integrated modules within the JAGGAER One platform
- Contract management, authoring, approvals and DocuSign or AdobeSign eSignature
- Easy and intuitive eCommerce shopping interface with Cart management
- Hosted Catalogues, L1 & L2 Punch-Outs and configurable Request forms
- Highly configurable Requisition, PO & Invoice workflows
- Efficient Receipting based on POs
- Automated Invoice 2/3-way matching and processing - manage by exception
- Solution integration with ERPs & 3rd party systems
- AWS UK and/or EU-hosted. ISO27001 certified services
- Integrated Sourcing & Supplier Management via JAGGAER S2C
Benefits
- Efficiently manage contract redlines, reviews and approvals
- Contract-based eProcurement to populate Catalogues with contracted items/pricing
- Easy, familiar online shopping experience for unlimited end-users
- Sourcing Request integration to JAGGAER S2C
- Flexible configurations to suit organisational processes, rules, and workflows
- Real-time graphical progress reporting of Requisition and PO workflows
- Visibility into all levels/types of purchasing across your organisation
- Supplier self-service eInvoicing, PO-flip and Invoice digitisation options
- Ensure goods/services are actually received before payment via 3-way matching
- AI Powered Innovation (ISO 42001 certified) supports Autonomous Commerce
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 2 4 6 9 5 7 8 3 4 3 8 5 8 4
Contact
BRAVOSOLUTION UK LIMITED
David Sharples
Telephone: +44 (0) 7825 843 903
Email: BSUKIN-Sales@jaggaer.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Procurement
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
JAGGAER's multi-tenant SaaS applications are delivered through a tried and tested infrastructure that has proven to be highly stable, scalable and secure. Customers choosing JAGGAER solutions do not need to invest any resources in additional Hardware/Software or IT staff to install, run, manage or upgrade the software solution, but still benefit from high standards of service in terms of security, availability and performance, and with no technical capacity constraints on resources.
From a software solution perspective, JAGGAER is not an on-premise solution and is delivered via the cloud. - System requirements
-
- Browser-based, hosted applications with no minimum OS specifications.
- Microsoft Edge (latest version with Windows) for PC
- Google Chrome (latest version) for PC
- Mozilla Firefox (latest version) for PC
- Safari 4.0 and higher for MacOS
- Mozilla Firefox (latest version) for MacOS
- Safari (latest version) for iPad
- Mobile apps require Android 4.0.3+ or 13.0+
- Contract Authoring App for Word add-in requires MS Word 2016+
User support
- Email or online ticketing support
- Yes
- Support response times
- Incidents are logged and tracked via a global incident tracking system within the JAGGAER GCC Portal. Our policy is to resolve any queries/issues as soon as possible following the receipt of a call. Generally, calls are resolved within that initial call. Any issue that cannot be resolved on the first call is immediately directed to the appropriate team for resolution. Outstanding customer support calls take priority over all other work within our operations team. Any issue not resolved within two hours is escalated through agreed escalation issue resolution protocols. The customer is updated on progress regularly. See https://www.jaggaer.com/jaggaer-one-terms-of-service
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- EN 301 549
- Web chat accessibility testing
-
JAGGAER is committed to supporting accessible digital experiences for all users. The core JAGGAER platform has undergone evaluation by independent third‑party accessibility specialists, including assessments using assistive technologies aligned with WCAG 2.2 Level A and AA requirements. These formal reviews are supported by an internal remediation program, regular accessibility audits, and ongoing enhancements incorporated throughout the product lifecycle.
Supplier users can access the chat channel 24/5 through the JAGGAER Support webpage. While the overall platform has been independently evaluated, the chat functionality itself has not been part of the third‑party testing scope yet. The chat component has undergone internal testing conducted by the implementation team, including reviews using the NVDA screen reader. These internal checks confirmed support for keyboard‑only navigation and compatibility with screen‑reader output with sufficient color contrast and scalable text, accessible form fields, appropriate error handling, and consistent page structure to support assistive technology behavior.
As accessibility standards evolve, JAGGAER continues to incorporate improvements across design, development, and testing processes to maintain and enhance conformance. - Onsite support
- No
- Support levels
-
JAGGAER provides a full-service customer support model, which includes functional (administration and supplier functionality) and technical support for buyers and suppliers. JAGGAER Global Customer Care (GCC) provides all support needs post Go Live, and is available in different packages dependent on the current and predicted use that best fits customer requirements.
Global Support: 24x7 for Severity 1 cases; 24x5 (Monday-Friday) for Severity 2-4 cases.
1. Base: Suitable where customer provides their own support, no integrations.
2. Standard: Suitable where there are locally based administrators, standard integrations.
3. Premium: Suitable where the customer has multiple business units/portals, complex sourcing solutions, larger number of suppliers.
4. Premium+: Suitable where there are globally based administrators, utilising new functionality (dev partner), multiple ERP integrations, Support Account Manager requested by the customer.
Local Support: Federal Government/Public Sector: Business hours Monday-Friday only for all support cases, Severity 1-4.
5. Premium: Suitable where the customer has multiple business units/portals, complex sourcing solutions, larger number of suppliers.
6.. Premium+: Suitable where there are globally based administrators, utilising new functionality (dev partner), multiple ERP integrations, Support Account Manager requested by the customer.
JAGGAER's Terms of Service at https://www.jaggaer.com/jaggaer-one-terms-of-service/. Prices vary according to the package selected. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
JAGGAER's training offering is based on a tried and tested method that aims to determine the best approach for training customers and their users. Supporting the deployment of the JAGGAER solution to the customer's buyer community, the JAGGAER Professional Services team will work with them to define a learning and education program tailored to meet an organisations requirements, to build competence and confidence in using the toolkit, embed change successfully, and realise business benefits quickly. Our methodology focuses on understanding your organisational objectives and needs, identifying the skills needed to support those needs, then developing, measuring and sustaining those skills.
As part of a JAGGAER Implementation project, the team will perform an initial Training Impact Assessment. Depending on the outcomes of the Training Impact Assessment, there are several options available, including Standard Training Courses, Bespoke Training Courses, and Train-the-Trainer.
In addition, we provide access for all customers to educational resources within the solution, including:
Online Help - context-sensitive WebHelp, online, searchable, and accessible from every page of the solution.
JAGGAER Release Library - offering training videos and release notes on all three major JAGGAER releases per year.
JAGGAER University - provides online self-paced eLearning. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
In connection with any termination or expiration of the Agreement and upon customer’s written request, JAGGAER shall either (i) return client data to customer. Customer data shall be provided in XML format and at customer’s expense, at JAGGAER's standard hourly rates then in effect. Fees for return of customer data and transition assistance must be reasonable and consistent with the fees paid by customer during the term of the agreement for other services provided by JAGGAER or (ii) delete or render useless the customer data.
Client may also extract the data itself. For a period of thirty (30) days following termination or expiration of a Subscription (the “Retrieval Period”), Authorized Users may access the JAGGAER Applications solely for the purpose of extracting Client Data. - End-of-contract process
- JAGGAER's standard is that for a period of thirty (30) days following termination or expiration of a Subscription ("Retrieval Period"), Authorized Users may access the JAGGAER Applications solely for the purpose of extracting Client Data. If requested in writing by Client, during the Subscription Term and the Retrieval Period, JAGGAER will perform such data extraction from the JAGGAER Applications for Client, under a mutually agreed Statement of Work. After the Retrieval Period, Client will have no further access to Client Data in the JAGGAER Applications, JAGGAER shall have no further obligation to make Client Data available to Client, and subject to applicable law, JAGGAER may delete Client Data in the JAGGAER Applications.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Documentation is delivered through web-based platforms designed to support assistive technologies, keyboard-only navigation, and clear, consistent structure and language. While onboarding and offboarding materials do not have a standalone accessibility conformance statement, they are developed using the same accessibility standards, review processes and governance applied across JAGGAER’s services. Where required, JAGGAER will work with customers to review specific materials and address any accessibility needs identified, in line with UK public-sector accessibility requirements.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- JAGGAER One fully supports mobile for procurement and contracting operations, but the mobile app has some limitations: it does not support forms, analytics, reporting, sourcing, supplier management or dashboards. Tablets provide full functionality. The mobile application offers a limited feature set with a mobile-friendly front end and does not provide new or different features than the web browser application. JAGGAER Mobile allows users to process approvals, view attachments, add or view comments while approving documents, view accounting codes, identify other approvers, maximize procurement and accounts payable automation, and shop for products in the organisation's hosted catalogue.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
JAGGAER's service interface is a user-friendly, browser-based Software-as-a-Service (SaaS) platform delivered via the cloud to support seamless integration and efficient management of procurement processes through its robust API offerings and user-friendly portals. The interface aims to provide a "retail-like shopping experience" for general users while offering powerful, data-driven dashboards and configuration tools for administrators and procurement professionals. Key aspects of the interface include:
- Identity Management and Single Sign-On (SSO)
- Integration & APIs
- Provisioning and Activation
- User Interface
- System Landscape - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
JAGGAER solution design principles incorporate Accessibility into the User Experience (UX). Testing for accessibility is undertaken during development and prior to every product release. We also work with a third-party accessibility expert to audit our software and provide remediation guidance.
Testing for accessibility is conducted using a combination of assistive technologies (AT), manual assessments and automated test tools. The three approaches are used together to evaluate and support conformance with web accessibility:
Manual Assessment - conducted with a web browser and special plug-ins. often conducted alongside the automated assessment to qualify and identify issues that may come up or be missed.
Assistive Technology User Assessment - used to confirm that assistive technologies (ATs) such as screen readers can interact properly with the website and its content. Also provides HTML and CSS best practices to avoid attributes or values which cause compatibility issues with some ATs.
Automated Tool Assessment - The different techniques and assistive technology software and tools included in our testing suite include Colour Contrast Analyzer (CCA), VoiceOver and NVDA.
Tests consider ease of access for users with disabilities, most widely used browsers according to WebAIM metrics, and impact on system performance when AT integrates with the operating system. - API
- Yes
- What users can and can't do using the API
-
JAGGAER One Catalyze layer is a JAGGAER proprietary, native cross-platform middleware layer that provides integration capabilities to enable interoperability between JAGGAER Cloud services and external systems, making standard native interfaces and built-in connectors available to support the most common integration scenarios. Jaggaer Catalyze supports JAGGAER ONE cross-module orchestration and provides:
Cloud connectors to an unsurpassed ecosystem of partners for outcomes that no other solution provider can deliver, including out-of-the-box support for TrustWeaver, Thomson Reuters, D&B, EcoVadis, Bureau van Dijk, Achilles, ConnXus, DocuSign, Adobe, MasterCard and more.
Standard interfaces to customer systems and applications (for SSO, ERP connectivity, document exchange, etc.) via a comprehensive catalogue of REST APIs, with a detailed library of supporting documents describing the exposed interfaces and service descriptors.
Platform as a Service (PaaS) providing customer-specific developments for integrations to legacy systems, through certified JAGGAER Technical Partners. - API documentation
- Yes
- API documentation formats
-
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The solution is not customisable in the ‘traditional’ sense where customers can access the code and make changes specific to their needs and environment. Once the solution is set up by JAGGAER's Professional Services team, there are tools to help 'configure' it to the needs of your organisation, whereby changes made by your organisation will be within the parameters of the application.
The following areas are configurable nearly to the point of customisation:
• Application colour scheme (variable by department, role, and user)
• Application logo (variable by department, role, and user)
• User navigation can be set by the user to have their most common tasks appear in the main toolbar
• Field management tools allow you to change text and help contents to reflect your terminology.
• Custom fields can be added throughout the application for accounting codes, document types, and collecting organisation-specific data.
• Workflow interfaces allow you to manage and modify workflow rules as necessary.
• Supplier home page can be branded to your organisation.
Other configurable areas include email messaging, role design, attachment size limitations, date formats, number format, languages, and hundreds of other configurations.
Scaling
- Independence of resources
- JAGGAER is implemented within AWS, taking advantage of a global, scalable, reliable and secure environment. AWS follows an end-to-end approach to secure and harden their infrastructure including physical, operational and software measures. JAGGAER is designed to support tens of thousands of user IDs with typical usage patterns with a flexible architecture to add capacity as needed. AWS Internet service is horizontally scalable and utilises multiple carriers for highest levels of redundancy and availability. No bandwidth limits are imposed for connectivity. Application Load Balancer automatically scales to handle inbound requests. We monitor performance across the applications. See availability at https://www.jaggaer.com/jaggaer-one-terms-of-service/
Analytics
- Service usage metrics
- Yes
- Metrics types
-
JAGGAER Purchase-to-Pay provides comprehensive real-time reporting of usage metrics including:
Contract Lifecycle Management:
Contracts that Require Attention: Review Pending.
Contracts that Require Attention: Expiring Contracts Workload by Contract Manager.
Cycle Time Report: Contract Creation to Execution Obligations Across Contracts.
eProcurement: Purchasing Reports (by Purchase Order or Purchase Requisition), Cycle Time Reports, Site Usage Reports, Sort, Filter and Export Data Access Based on User Roles.
Accounts Payable: Invoice Source Report, Invoice Source by Supplier Report, Invoice Matching Report, Invoice Tolerance by Source Report, Early Payment Analysis Report, Cycle Time Report, Early Payment Discount Detail Report. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- EProcurement data can be extracted using a standard 'Export CSV' function for editing in Microsoft Excel. A full transactional data extract is available for any required date range. Data is extracted by Purchase Requisition or Purchase Order into Excel spreadsheets. Contract metadata, document, and attachment import/export are supported. Customers can import legacy contract metadata using spreadsheets and upload associated documents. Contract metadata can be exported into CSV and/or XML for reporting or integration to other legacy applications. Customers can export all contracts and associated documents individually or as a single PDF file.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLS
- XML
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XLS
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- JAGGAERs Amazon Virtual Private Cloud (VPC) is a virtual network defined by JAGGAER within the JAGGAER owned AWS accounts. It is logically isolated from other virtual networks in the AWS cloud and secured by the AWS service. Management and Production VPCs are interconnected with a VPC Peer service, which allows secure and controlled access between assets in each VPC. Direct access to the Management VPC can only be achieved by first establishing a VPN connection with MFA and then traversing the JAGGAER AWS Direct Connect, a leased private communication link between the JAGGAER network and JAGGAER’s associated AWS VPC’s.
Availability and resilience
- Guaranteed availability
- JAGGAER shall make all JAGGAER SaaS Applications available to the Client for at least ninety-nine and one half percent (99.5%) of the time (determined monthly on a calendar basis), seven (7) days a week, twenty-four (24) hours per day, not including any unavailability that (i) results from JAGGAER maintenance communicated in advance or (ii) results from the poor performance or, of failure of, internet service or other outside service, software or equipment not within the control of JAGGAER (“Service Level Availability”). JAGGAER test and pre-production environments are expressly excluded from this or any other service level commitment.
- Approach to resilience
- Our service is architected for high resilience through a highly available, load balanced configuration that minimizes the impact of the failure of a single server or service. All networking components, load balancers, web servers, application servers, and database servers are deployed in a redundant configuration. The database server cluster stores all client data for redundancy, and the database disk storage is configured using a redundant array of independent disks (RAID) with multiple data paths. Our production environment includes redundant application servers and a highly available DB2 database cluster (HADR) service, with each database server having separate storage, providing four protected online copies of customer data. Nightly online backups create two additional copies on separate storage. Main data storage and database systems are built with redundancy within a single data center and replicated to a secondary data center, supporting a Recovery Point Objective (RPO) of 1 hour. There are no critical single points of failure in our solution. Failover capabilities are included in our Software-as-a-Service (SaaS) offering.
- Outage reporting
- Outage reporting is via email alert to the customer nominated Support Contacts. Email communication continues until the issue is resolved, at which point a resolution email is sent. System availability historical data for up to six years for all JAGGAER solutions can be reviewed at https://www.jaggaer.com/trustcenter/uptime-report/
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- We authenticate users through single-sign-on (SSO) using any SAML 2.0 provider or LDAP server, including Active Directory. Our solution also supports username and encrypted password authentication. Once authenticated, a user’s access to features within the solution are restricted to those defined by his or her user role. JAGGAER employs a role-based access control (RBAC) model. User passwords are one way encrypted in the database using HMAC SHA-256 encryption with a 48-bit salt.
- Access restrictions in management interfaces and support channels
- We restrict access to management interfaces by permitting only key administrative personnel to possess physical and logical access to our production environment and sensitive data. All management interfaces to systems and components are restricted from access over any public network. Management access is restricted and only possible via a highly secure virtual private network (VPN) or the AWS console, both of which leverage MFA authentication and strong/complex passwords are used.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
ISO9001:2015 Quality Management
ISO22301:2019 Business Continuity Management
ISO/IEC 27017:2015 Code of practice for information security controls based on ISO/IEC 27002 for cloud services
ISO/IEC27018:2019 Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors
ISO/IEC42001:2023 Artificial intelligence
TypeI/TypeII SOC2 Reports
Cyber Essentials; CE+ - Information security policies and processes
- JAGGAER continually enhances the depth and breadth of our security policy in response to constantly evolving application features and technical standards. Over a decade of service delivery has provided JAGGAER with a solid foundation of 'real' experience to develop and fine-tune our security policies at the highest levels. We firmly believe that only a balanced combination of policies and technologies could effectively respond to the growing security requirements in delivering our services. The company has invested time and resources to ensure that appropriate policies are implemented, and suitable technologies are in place to deliver the most effective security protocols in the areas of Privacy, Authenticity, Integrity and Non-repudiation. JAGGAER has obtained relevant certifications from independent third parties, including leading international providers of services for risk management. Our applications are subject to regular independent penetration testing and review. JAGGAER also holds the integrated ISO 27001:2013 Information Security and ISO/IEC 22301:2012 Business Continuity Certifications, which together formally specify a management system to guarantee data security and business continuity.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- JAGGAER has implemented a documented process of Change Management aimed to ensure that only authorised changes to the services provided are allowed and that changes are managed in an effective and controlled manner. The third-party annual SOC examination includes a review of this process. Our change management process includes review and authorization of any critical administration activities. We have configuration management systems in place. Security control performance is validated by independent third parties per our SOC and ISO audits.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Application and infrastructure vulnerability scans are performed regularly using enterprise vulnerability management tools. All production systems are scanned with industry-leading vulnerability scanners externally on a monthly basis. A PCI approved scanning vendor (ASV) conducts monthly external vulnerability scans of the solution environment. Any detected high-risk vulnerabilities are remediated and re-testing is performed to ensure vulnerabilities are corrected. Vulnerability severity is based on the Common Vulnerability Scoring System Version (CVSS) and, in consultation with asset owners, may be modified based on internal or external circumstances which decrease or increase risk.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- JAGGAER uses several commercial monitoring systems and/or services to ensure the highest levels of performance and availability of the application. These monitoring systems are tied into a commercial notification and alerting system (PagerDuty), which allows JAGGAER to ensure that any issues are promptly and accurately relayed to JAGGAER infrastructure staff who can facilitate a timely and accurate problem resolution. This also provides escalation and prioritisation capabilities to ensure all notifications are responded to.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
We designed the data security architecture to incorporate industry-leading practices around encryption, access controls and data integrity for both in flight and at rest data following various NIST standards for systems in infrastructure and OWASP for software and application development. We established an Incident Response Policy and Customer Communication Process which includes a highly detailed set of processes for handling a security incident.
This process includes timely notification of affected customers and regular updates until the issue is resolved. Our incident response procedure clearly defines what constitutes an incident and provides a step-by-step process to follow when one occurs. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 15%
- Between £250,000 and £500,000
- 20%
- Between £500,001 and £1,000,000
- 25%
- Between £1,000,001 and £2,500,000
- 30%
- Between £2,500,001 and £5,000,000
- 40%
- Over £5,000,001
- 50%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- A-LIGN
- ISO/IEC 27001 accreditation date
- Thursday 2 June 2022
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- NQA
- ISO 9001 accreditation date
- Tuesday 17 May 2022
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- A-LIGN
- PCI DSS accreditation date
- Sunday 30 March 2025
- What the PCI DSS doesn’t cover
- Source-to Contract
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 08b7fc01-f864-4a15-bfc7-e74b418cc3dc
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 057865a0-a819-4f43-b9d3-5d4f994b00e8
- Other security certifications
- Yes
- Any other security certifications
-
- SOC 2 type II reports
- SOC 1 type II reports
- ISO/IEC 27017:2015
- ISO/IEC 27018:2019
- ISO 22301:2019 Business continuity management systems
- ISO/IEC 42001:2023 Artificial intelligence - Management system
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Plans for positive actions with community groups.
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-