Skip to main content

Help us improve the Digital Marketplace - send your feedback

TTEC CONSULTING (UK) LIMITED

TTEC Digital Calabrio Workforce Management (WFM)

Calabrio Workforce Management empowers contact centres with intelligent automation, advanced forecasting, and flexible scheduling. It enhances employee engagement and operational efficiency, delivering seamless experiences for customers and agents across remote, on-site, or hybrid environments. Scalable and agile, it helps organisations adapt to evolving workforce needs.

Features

  • AI-powered forecasting for omni-channel contact centre environments
  • Intraday management with real-time adherence monitoring tools
  • Self-service scheduling, vacation bidding, and time-off management
  • Configurable dashboards for schedule and performance visibility
  • Automated schedule optimisation using machine learning algorithms
  • Integration with leading ACD and CRM platforms
  • Real-time alerts for staffing and call volume changes
  • Cloud-based scalability for seasonal or dynamic workforce needs
  • Historical and predictive reporting for workforce performance trends
  • Agent empowerment through mobile and web self-service tools

Benefits

  • Improves forecast accuracy, reducing costly overstaffing and overtime
  • Enhances employee engagement with flexible scheduling options
  • Boosts productivity through real-time adherence and performance insights
  • Supports compliance with labour laws and scheduling fairness
  • Reduces administrative workload via automated scheduling processes
  • Optimises staffing for digital and voice channels simultaneously
  • Improves customer experience by aligning resources to demand
  • Enables rapid intraday adjustments to meet service levels
  • Delivers actionable insights for strategic workforce planning
  • Scales easily to support growth and seasonal peaks

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@ttecdigital.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 3 8 5 2 4 3 7 9 3 2 8 2 6 6

Contact

TTEC CONSULTING (UK) LIMITED Wayne Kay
Telephone: 0113 5432620
Email: gcloud@ttecdigital.com

About your service

Service categories

Applications

Customer relationship management

  • Marketing campaign management
  • Digital commerce
  • Sales force productivity and management
  • Customer service
  • Contact centre

Advertising

  • Advertising Placement
  • Advertising Measurement
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Our service extends leading contact centre and CRM platforms, including NICE CXone, Microsoft Dynamics 365, Genesys Cloud and Amazon Connect. It integrates seamlessly via APIs and adapters, enabling real-time adherence, historical reporting, and schedule synchronisation for unified workforce management across omnichannel environments.
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
Planned maintenance occurs during agreed low-usage windows with prior notice. Service availability depends on stable internet connectivity and supported browsers (latest and previous versions). Performance may vary on outdated hardware or unsupported operating systems. Customer must ensure compliance with technical prerequisites, including API configurations. No offline mode; cloud access required.
System requirements
  • Windows Server 2019 or later operating system installed and licensed.
  • Microsoft SQL Server 2017 or newer database engine fully configured.
  • Latest Java Runtime Environment installed for application compatibility assurance.
  • Active Directory integration enabled for secure user authentication and management.
  • Minimum 16 GB RAM and quad-core processor for performance.
  • Reliable internet connection with minimum 10 Mbps bandwidth for operations.
  • Supported web browser: Chrome, Edge, or Firefox with latest updates.
  • Antivirus software installed and regularly updated on all virtual machines.
  • Valid SSL certificate for secure HTTPS communication between components.
  • Adequate disk space: 100 GB free for application and logs.

User support

Email or online ticketing support
Yes
Support response times
Service Priorities & Response Times:

P1 Emergency: Immediate contact, constant follow-up, 30 min response, hourly updates, 4-hour escalation, 24x7 coverage.
P2 High: Immediate contact via call or 4 hours via portal, daily follow-up, next business day contact, UK business hours.
P3 Medium: All types, 4-hour initial contact, 3 business days follow-up, next business day contact, UK business hours.
P4 Low: All types, 4-hour initial contact, 5 business days follow-up, next business day contact, UK business hours.
MACD: Completed within 2 business days, scheduled during business hours.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
1. Support Levels Provided
SurroundCX™ offers three support tiers: Essential, Plus, and Premium:
• Essential includes core monitoring, incident management, and standard platform support.
• Plus adds proactive health checks, configuration assistance, and enhanced reporting.
• Premium delivers strategic guidance, advanced analytics, priority case handling, and dedicated personnel.

2. Support Costs
Pricing is subscription-based and varies by tier, user volume, and service complexity. Exact costs are defined in individual contracts and service-level agreements.

3. Dedicated Support Personnel
Only Premium clients receive a dedicated Technical Account Manager for strategic oversight and a Cloud Support Engineer for technical troubleshooting and optimisation. Essential and Plus tiers rely on shared support resources.
Support available to third parties
No

Onboarding and offboarding

Getting started
We provide a structured enablement approach to ensure successful adoption of Calabrio WFM. Training is delivered through remote workshops over five days (three hours per day), accommodating up to 15 participants. These sessions include Business Requirements Discovery (BRD), hands-on configuration for scheduling and forecasting, and performance optimisation guidance.

Training is integrated into key implementation milestones, Discovery & Design, Execution, and User Acceptance Testing (UAT), to align with operational needs. Clients also gain access to the Calabrio Success Centre, offering self-service resources such as training materials, enablement guides, and roadmap documentation for ongoing learning.

For advanced requirements, we offer professional services and tailored workshops covering API integrations, custom configurations, and analytics. Additionally, Train-the-Trainer or End-User training can be delivered onsite or remotely, based on client preference.

This blended approach ensures flexibility, scalability, and continuous support for optimal platform utilisation.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
  • Swagger/OpenAPI specification for interactive API exploration
  • Postman collections for quick API testing and integration
  • Markdown files for lightweight developer documentation
  • JSON examples for API request and response payloads
  • YAML configuration samples for deployment and integration
  • Developer portal with searchable guides and tutorials
  • Knowledge base articles for troubleshooting and FAQs
  • Code snippets in multiple languages for API usage
  • Video tutorials for setup and feature demonstrations
  • Interactive sandbox environment for live API testing
End-of-contract data extraction
When the contract ends, users can extract their data through secure export options provided by Calabrio. Administrators can download all relevant data, including schedules, forecasts, reports, and historical interaction records, in standard formats such as CSV or XML. API endpoints are also available for automated data retrieval before service termination.

Calabrio ensures that data extraction is straightforward and does not require proprietary tools. Customers retain full control over timing and scope of exports, and support is available to assist with bulk downloads or structured exports. After extraction, data is removed from Calabrio systems in accordance with GDPR and contractual obligations.
End-of-contract process
At the end of the contract, Calabrio provides support for service termination and data extraction. Included in the contract price are secure data export options, account deactivation, and guidance on transitioning to alternative solutions. Customers can download all historical data in standard formats (CSV, XML) or use API endpoints for automated retrieval.

Additional costs may apply for extended access beyond the termination date, custom data transformation, or professional services such as migration assistance and bespoke reporting. After data extraction, Calabrio ensures complete removal of customer data from its systems in compliance with GDPR and contractual obligations.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile service focuses on quick, on-the-go functionality, allowing agents to view schedules, request time off, and manage shift changes easily. The desktop version provides full workforce management capabilities, including advanced forecasting, scheduling, reporting, and administrative tools. Mobile offers convenience and accessibility, while desktop delivers comprehensive control and analytics.
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
The TTEC Digital web-based customer self-service support portal is accessed through redemption of a secure invitation code sent directly to authorised personnel within the client business. Once registered, clients can open new support cases, and view existing support cases, priority, status, assigned contacts, case owners, date of creation and any updates provided by the TTEC Digital support engineering team.
Accessibility standards
EN 301 549
Accessibility testing
Calabrio has conducted accessibility testing to ensure usability for individuals relying on assistive technologies. The platform includes the Accessible Contact Evaluator (ACE), a screen-reader-friendly interface optimized for JAWS and compatible with other screen readers. ACE supports keyboard navigation and shortcuts, enabling evaluators with low vision to play and assess interactions effectively. Testing focused on compliance with WCAG standards, validating features such as semantic structure, ARIA roles, and alternative text for non-visual elements. Additionally, usability checks were performed to confirm smooth navigation, accurate playback controls, and filter functionality for screen reader users. These measures ensure an inclusive experience across desktop and mobile environments.
API
Yes
What users can and can't do using the API
Calabrio’s API enables users to integrate and configure core Workforce Management functions programmatically. Through the API, users can set up services by creating accounts, defining organisational structures, and importing schedules or forecasts. They can make changes such as updating agent profiles, modifying schedules, and retrieving performance data in real time.

The API supports secure authentication and offers endpoints for common administrative tasks, including shift adjustments and time-off requests. However, certain advanced configuration options, such as system-level settings, UI customisation, and feature enablement, must be performed through the main application interface. Bulk data uploads and complex forecasting adjustments may also require the desktop platform.

Overall, the API provides flexibility for operational updates and integrations but does not replace full administrative control available in the web interface.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
1. What can be customised:
Users can tailor their SandcastleCX™ environment to match specific CX use cases, technology platforms (e.g., Calabrio, Genesys, AWS, Microsoft, Salesforce and NiCE), integrations, and features such as voice routing, CRM connectors, bots, and reporting dashboards.

2. How users can customise:
Customisation is achieved through a guided, hands-on sandbox experience. TTEC Digital CX architects configure the environment based on client requirements, enabling iterative testing of workflows, integrations, and advanced capabilities. Optional add-ons like Learning and Performance Management or IP solutions can extend functionality.

3. Who can customise:
Authorised client stakeholders, typically CX leaders, IT teams, and solution architects, collaborate with TTEC Digital experts to define priorities and adjust configurations during the trial period.

Scaling

Independence of resources
Calabrio guarantees performance through a multi-tenant, cloud-native architecture with strict resource isolation. Each customer environment is logically separated, ensuring workloads do not impact others. Auto-scaling and load balancing maintain consistent service levels during peak demand. Continuous monitoring and proactive capacity management prevent performance degradation, delivering reliable uptime and responsiveness.

Analytics

Service usage metrics
Yes
Metrics types
Calabrio provides detailed service metrics to monitor performance and usage. Metrics include system uptime and availability, API response times, data processing speed, and user activity logs. Workforce-specific metrics cover schedule adherence, forecast accuracy, and agent performance indicators. Reports are accessible via dashboards and exportable in standard formats for analysis.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
TTEC Digital: Genesys, Microsoft, Google, Calabrio, Shelf, ServiceNow – ttecdigital.com/services

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
We protect data at rest using AES-256 encryption across all storage layers, including databases, backups, and file systems. Encryption keys are managed through secure key vaults with strict rotation and access controls. Data is further safeguarded by role-based access permissions, ensuring only authorized personnel can retrieve sensitive information. Storage systems are hardened with disk-level encryption, and redundant copies are maintained in secure, geographically distributed environments. Regular integrity checks, vulnerability scans, and compliance audits (ISO 27001, SOC 2) ensure ongoing protection. These measures collectively guarantee confidentiality and resilience for all stored data.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export their data through secure options provided by Calabrio. Administrators can download historical data, schedules, and reports in standard formats such as CSV or XML directly from the platform. Additionally, API endpoints allow automated data extraction for integration or bulk retrieval. Secure transfer methods (HTTPS or SFTP) are supported.
Data export formats
  • CSV
  • Other
Other data export formats
  • XML for structured data exchange and system integration
  • JSON for API-driven data retrieval and interoperability
  • YAML for configuration and structured export scenarios
  • TXT for plain text data representation and logs
  • Excel XLSX for tabular reporting and analysis
  • HTML for formatted reports and browser-based viewing
  • PDF for static archival and compliance documentation
  • SQL dump for database migration and backup purposes
  • Markdown for lightweight documentation and structured notes
  • ZIP archive for bulk export of multiple data files
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • XML for structured data and system integration
  • JSON for API-driven imports and interoperability
  • YAML for configuration and structured data uploads
  • TXT for plain text data and logs
  • Excel XLSX for tabular data and scheduling
  • HTML for formatted content and structured imports
  • PDF for static documents and compliance uploads
  • SQL dump for database migration and bulk data
  • Markdown for lightweight documentation and structured notes
  • ZIP archive for bulk upload of multiple files

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks
In addition to TLS 1.2 or above, Calabrio enforces HTTPS with strong cipher suites and mutual authentication options for secure communication. Data integrity is maintained through certificate-based validation and strict session management. Optional IPsec or TLS VPN tunnels can be configured for enhanced security. Legacy protocols are disabled to ensure compliance with NCSC standards.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
We safeguard data within our network using segmentation and encryption at rest. Sensitive information is stored in encrypted databases using AES-256, and keys are managed through secure vaults with strict rotation policies. Access is controlled via role-based permissions and enforced through multi-factor authentication. Network traffic is monitored by intrusion detection and prevention systems, while firewalls and micro-segmentation limit lateral movement. Regular vulnerability scans and penetration tests ensure compliance with ISO 27001 and SOC 2 standards. These layered controls maintain confidentiality, integrity, and availability across all internal systems.

Availability and resilience

Guaranteed availability
Calabrio guarantees 99.9% service availability as part of its SLA, excluding scheduled maintenance windows. Availability is monitored continuously, and performance metrics are shared via dashboards and reports. If availability falls below the guaranteed level, customers are eligible for service credits as outlined in the contract. Credits are calculated based on the duration and severity of the outage and applied to future invoices.

Calabrio’s cloud-native architecture uses redundant systems, load balancing, and automatic failover to maintain uptime. Disaster recovery and high-availability measures ensure resilience across multiple data centres. These commitments align with ISO 27001 and industry best practices for reliability.
Approach to resilience
Calabrio WFM is engineered for reliability and continuous service delivery. The platform uses a cloud-native, multi-tier architecture with built-in redundancy across application, database, and storage layers. Automated failover and load balancing ensure uninterrupted operations during component failures or maintenance.

Data is replicated across multiple, geographically dispersed datacentres to protect against regional outages. Each datacentre is equipped with resilient power, cooling, and network infrastructure, and adheres to strict physical and logical security standards. Disaster recovery processes include frequent backups, tested restoration procedures, and defined RTO/RPO objectives to minimise disruption.

The environment is continuously monitored with proactive alerting and incident response to maintain service integrity. Detailed datacentre resilience information is available upon request to authorised parties.
Outage reporting
Public Dashboard:
Calabrio provides a real-time public status dashboard that displays system health, outage notifications, and maintenance schedules. Users can view current incidents and historical uptime metrics at any time.

API:
An API is available for customers to integrate outage and status information into their internal monitoring tools. This allows automated alerts and reporting within existing systems.

Email Alerts:
Designated contacts receive email notifications for critical incidents, planned maintenance, and service restoration updates. Alerts include incident details, estimated resolution times, and progress updates.

Additional Details:
Customers can subscribe to notifications and customise alert preferences. These measures ensure transparency and timely communication during service disruptions.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Other user authentication
We authenticate users through secure, multi-layered controls. Access begins with username and password validation, enforced by strong complexity and rotation policies. We support Multi-Factor Authentication (MFA) using one-time codes or authenticator apps to prevent unauthorized access. For enterprise customers, Single Sign-On (SSO) via SAML 2.0 or OAuth integrates with identity providers like Azure AD. All sessions use TLS encryption and token-based authentication to maintain confidentiality. Role-based access controls ensure users only access resources aligned with their permissions. These measures collectively provide strong identity assurance and compliance with ISO 27001 and SOC 2 standards.
Access restrictions in management interfaces and support channels
Access Restrictions:
Administrative access is limited to authorised personnel using role-based permissions and least-privilege principles.

Authentication:
All access requires multi-factor authentication (MFA) and secure VPN connections for remote sessions.

Session Security:
Interfaces are protected by TLS encryption, session timeouts, and continuous monitoring for anomalies.

Support Channels:
Customer support interactions are authenticated, logged, and conducted through secure portals. Sensitive actions require identity verification and approval workflows.
These measures ensure only verified users can manage or support services securely.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
PCI DSS Level 1
SOC 2 Type 2
HIPAA
Cyber Essentials
Cyber Essentials Plus
Information security policies and processes
TTEC's Global Information Security (GIS) reports to the VP and Chief Security Officer. The GIS department is within TTEC’s Security, Resiliency and Governance organisation, reporting to TTEC's Chief Information Officer.
TTEC’s robust Global Privacy, Risk, Compliance, Network, and InfoSec programmes are based on the guiding principles of: Availability; Integrity; and Confidentiality. These principles are achieved through defined policies, industry controls, with infosec and privacy trainings, and through the governance structure within our corporate GIS, IT, Legal and Risk Executives.
TTEC’s policies/procedures comply with ISO 27002 compliance framework that standardise the following security elements:

•InfoSec Policy & Organisational Measures
•Asset/Data Classification
•Human Resource Security- Corrective Actions
•Physical/Environment Security
•Communication/Operation Management
•Access/Authentication/Password Management
•Data Encryption
•InfoSec Acquisition Development/Maintenance
•Endpoint Security
•Auditing, Logging, Monitoring
•Vulnerability, Penetration, Patch Management
•Network Security, Configuration Management
•Applications, SDLC, Change Management
•Incident Response Management
•Security, Fraud, Ethics Code Training- Accountability
•BCP/DR
•Global IT/Risk Management
•Regulatory Compliance

TTEC performs periodic and annual, internal, and external independent, third party, qualified, industry compliance audits of the TTEC organisational controls and technology environments. TTEC continues to achieve ongoing industry compliance accreditation with PCI DSS (SL-1), ISO 27001, SOC 2 Type II (SSAE 18), Cyber Essentials Basic & Plus, and more.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Component Tracking:
All service components are tracked throughout their lifecycle using a Configuration Management Database (CMDB). Each asset is assigned a unique identifier, with version history and dependencies recorded to maintain visibility and integrity.

Change Assessment:
Changes follow a formal Change Advisory Board (CAB) process. Every modification undergoes risk and security impact analysis, including vulnerability checks and compliance validation. Approved changes are implemented with rollback plans and logged for audit purposes.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Threat Assessment:
We continuously monitor for vulnerabilities using automated scanning tools and perform risk-based analysis to assess potential threats to services.

Patch Deployment:
Critical patches are deployed within 24 hours, while high and medium-risk updates follow defined SLAs to ensure timely remediation.

Threat Intelligence Sources:
We leverage vendor advisories, CVE databases, CSA alerts, and threat intelligence feeds from trusted security partners to stay ahead of emerging risks.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Identifying Potential Compromises:
We use SIEM tools and real-time log analysis to detect anomalies, unauthorised access attempts, and suspicious patterns. Alerts are generated for predefined indicators of compromise.

Responding to Potential Compromises:
Incidents trigger an automated containment workflow, followed by manual investigation. Actions include isolating affected systems, revoking credentials, and applying patches.

Response Time:
Our Security Operations Centre (SOC) operates 24/7, with initial response within 15 minutes of detection and full remediation initiated immediately per severity level.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Pre-Defined Processes:
We maintain documented playbooks for common incidents, including service outages, security breaches, and performance degradation. These processes ensure rapid, consistent response.

User Reporting:
Users can report incidents via 24/7 support channels, including a dedicated portal, email, and phone hotline. Automated alerts also trigger internal escalation.

Incident Reports:
We provide detailed post-incident reports outlining root cause, impact, and corrective actions. Reports are shared through secure channels and archived for compliance.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
SandcastleCX™ provides a secure, customised sandbox for testing and exploring CX technologies, including CCaaS, CRM, AI, and analytics. It offers expert guidance, platform validation, and flexible trial access at no cost for standard use cases. Ideal for innovation and proof-of-concept projects, enabling rapid evaluation without production risk.
Link to free trial
https://youtu.be/hNmqTiNkIx8?si=9cRF7IADXikWKBm7

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2.2%
Between £500,001 and £1,000,000
4.2%
Between £1,000,001 and £2,500,000
6.2%
Between £2,500,001 and £5,000,000
8.2%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Coalfire Certification, Inc.
ISO/IEC 27001 accreditation date
Thursday 21 August 2025
What the ISO/IEC 27001 doesn’t cover
Certification available on request.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
PCI Security Standards Council
PCI DSS accreditation date
Friday 28 November 2025
What the PCI DSS doesn’t cover
Certification available on request.
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
2807b81c-9543-492c-805b-f1fd3347313f
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
613c9a41-2540-4e86-811e-d9808a365c26
Other security certifications
Yes
Any other security certifications
  • SOC 2, Type II
  • HIPAA

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Content of the outreach activity is designed to suit the target cohort

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@ttecdigital.com. Tell them what format you need. It will help if you say what assistive technology you use.