TTEC Digital Shelf Knowledge Management
TTEC Digital Shelf Knowledge Management centralises and organises product content, enriched by Content Intelligence that automates enrichment and flags gaps. It streamlines updates, improves collaboration, and ensures compliance, helping organisations deliver seamless customer experiences and optimise digital shelf performance.
Features
- Centralised product content repository.
- Real-time content updates.
- Automated data validation.
- Role-based access control.
- API integration with e-commerce platforms.
- Multi-language content support.
- Version control and audit trails.
- Cloud-based scalability.
- Advanced search and filtering.
- Compliance and governance tools.
Benefits
- Publish accurate content across multiple channels.
- Quickly update product details in real time.
- Reduce manual errors through automated validation.
- Improve collaboration with centralised content access.
- Ensure compliance with governance controls.
- Accelerate product launches with streamlined workflows.
- Enhance customer experience through consistent information.
- Manage multilingual content efficiently.
- Access content securely from any location.
- Simplify integration with existing e-commerce systems.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 5 4 3 6 6 4 8 3 6 0 2 9 4 1
Contact
TTEC CONSULTING (UK) LIMITED
Wayne Kay
Telephone: 0113 5432620
Email: gcloud@ttecdigital.com
About your service
- Service categories
-
Applications
Customer relationship management
- Marketing campaign management
- Digital commerce
- Sales force productivity and management
- Customer service
- Contact centre
Advertising
- Advertising Placement
- Advertising Measurement
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Shelf Knowledge Management can integrate with and extend enterprise collaboration and content platforms such as Microsoft SharePoint, Confluence, Salesforce Knowledge, and other systems via its Content Integration Layer (CIL). These integrations allow centralised knowledge access while maintaining synchronisation with existing tools and workflows.
- Cloud deployment model
- Public cloud
- Service constraints
- The service requires internet connectivity and supported browsers for access. Performance may vary based on network bandwidth. Planned maintenance windows are scheduled outside business hours where possible and communicated in advance. Integration depends on standard APIs; custom connectors may require additional effort. Service availability is subject to cloud provider uptime. No offline mode is supported.
- System requirements
-
- Modern web browser (Chrome, Edge, or Firefox latest version).
- Stable internet connection (minimum 10 Mbps recommended).
- Enabled JavaScript and cookies in browser settings.
- Access to HTTPS for secure communication.
- API credentials for integration with external platforms.
- Minimum screen resolution of 1280x720 pixels.
- Operating system supporting modern browsers (Windows, macOS, Linux).
- Optional VPN for secure enterprise network access.
- Cloud storage account for data synchronisation.
- No additional software installation required (fully SaaS-based).
User support
- Email or online ticketing support
- Yes
- Support response times
-
SurroundCX™ escalation tiers and response times:
P1 – Critical
Impact: Service outage or severe business disruption.
Response: Acknowledge within 15 minutes, 24/7 coverage.
P2 – High
Impact: Major functionality impaired, but workaround exists.
Response: Acknowledge within 30 minutes, during business hours.
P3 – Standard
Impact: Minor issue or general inquiry.
Response: Acknowledge by 10:00 AM next business day. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
1. Support Levels Provided:
SurroundCX™ offers three support tiers: Essential, Plus, and Premium:
• Essential includes core monitoring, incident management, and standard platform support.
• Plus adds proactive health checks, configuration assistance, and enhanced reporting.
• Premium delivers strategic guidance, advanced analytics, priority case handling, and dedicated personnel.
2. Support Costs:
Pricing is subscription-based and varies by tier, user volume, and service complexity. Exact costs are defined in individual contracts and service-level agreements.
3. Dedicated Support Personnel:
Only Premium clients receive a dedicated Technical Account Manager for strategic oversight and a Cloud Support Engineer for technical troubleshooting and optimisation. Essential and Plus tiers rely on shared support resources. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We provide a comprehensive onboarding experience to help users start using the service quickly and effectively. Our support includes detailed online documentation with step-by-step setup guides, FAQs, and best practices for configuration and integration. Interactive tutorials and video walkthroughs are available for self-paced learning. We also offer live online training sessions for administrators and key users, covering essential topics such as content management, workflow setup, and reporting features. For organisations requiring deeper engagement, optional onsite training can be arranged. A dedicated support team is available via email and chat to assist with initial configuration and troubleshooting. Additionally, we provide access to a sandbox environment for technical teams to test integrations before moving to production. Regular updates, release notes, and a searchable knowledge base ensure users stay informed about new features and enhancements.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Video tutorials
- Interactive online guides
- Knowledge base articles
- API reference portal
- Quick-start cheat sheets
- Web-based FAQs
- Release notes in markdown
- Embedded help tooltips
- Email onboarding packs
- Training slide decks
- End-of-contract data extraction
- When the contract ends, users can extract all their data securely using multiple options. The service provides an export feature within the administrative console, allowing users to download content, metadata, and associated files in standard formats such as CSV, JSON, or XML. Bulk export tools enable retrieval of large datasets, including version history and multilingual content. For integrations, the REST API supports programmatic extraction of data, ensuring continuity for external systems. Webhooks can be leveraged to trigger final synchronisation before termination. All exports are delivered over encrypted channels (HTTPS) to maintain data security. Users are responsible for initiating the export before the termination date; post-contract access may be limited. Optional support is available to assist with data migration or provide custom export scripts for complex configurations. No proprietary lock-in applies, data remains in open, portable formats to facilitate transition to alternative platforms.
- End-of-contract process
- At the end of the contract, buyers retain access for a defined period to extract all data using built-in export tools or the API. Exports include product content, metadata, attachments, and version history in standard formats such as CSV, JSON, or XML. Secure HTTPS transfer ensures data protection during extraction. Included in the contract price are data export capabilities, user support for standard extraction, and access to documentation. Optional services, such as bespoke migration scripts, extended post-contract access, or professional assistance for complex integrations, are available at additional cost. After the extraction window closes, all remaining data is securely deleted in accordance with our retention and compliance policies. No proprietary lock-in applies, ensuring buyers can transition smoothly to alternative platforms.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile version offers full access to core features, including viewing, editing, and publishing product content. The interface is optimised for smaller screens with simplified navigation and responsive layouts. Some advanced administrative functions, such as bulk uploads and detailed analytics dashboards, are best experienced on desktop for ease of use. Notifications and quick updates are streamlined on mobile for on-the-go management.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service interface is a secure, web‑based dashboard accessible via modern browsers. It offers intuitive navigation with role‑based menus for managing product content, workflows, and user permissions. Key features include advanced search, real‑time content editing, version control, analytics reporting, and seamless integration with the Genesys Cloud Answer Assist widget for AI‑powered agent support. The interface supports drag‑and‑drop uploads, multilingual content management, and API configuration for external systems. Its responsive design ensures smooth use across desktop and mobile devices.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We conducted accessibility testing to ensure compatibility with assistive technologies. Testing included screen reader support using JAWS and NVDA to verify proper reading of navigation menus, form fields, and dynamic content. Keyboard-only navigation was validated to confirm that all interactive elements are operable without a mouse. We checked colour contrast ratios against WCAG 2.2 AA standards and ensured that text alternatives for images and icons were correctly implemented. Zoom and responsive design were tested on desktop and mobile browsers to confirm readability at 200% magnification. Additionally, we validated ARIA roles and labels for clarity in complex components such as dropdowns and modal dialogs. Feedback from users familiar with assistive tools helped refine focus order and error messaging for improved usability.
- API
- Yes
- What users can and can't do using the API
-
How users can set up the service through the API:
- Request API client during onboarding and receive credentials.
- Configure OAuth2 token exchange; whitelist callback URLs if needed.
- Enable required scopes (content, metadata, workflow).
- Use sandbox environment to validate integrations before production.
How users can make changes through the API:
- Create, read, update, retire knowledge items and categories.
- Manage metadata, translations, attachments, and version history.
- Trigger workflow actions: submit, review, approve, publish, unpublish.
- Perform bulk import/export; subscribe to webhooks for change notifications.
- Admin (with permissions): assign users, roles, and access policies.
Limitations to setup or changes through the API:
- HTTPS required; requests must follow documented schemas and pagination.
- Rate and payload size limits apply; long‑running jobs are asynchronous.
- Hard delete is restricted; recovery actions require elevated approval.
- Custom workflow design and UI configuration occur in the admin console.
- Unsupported connectors may need professional services for enablement. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
1. What can be customised:
Users can tailor their SandcastleCX™ environment to match specific CX use cases, technology platforms (e.g., Genesys, AWS, Microsoft, Salesforce and NiCE), integrations, and features such as voice routing, CRM connectors, bots, and reporting dashboards.
2. How users can customise:
Customisation is achieved through a guided, hands-on sandbox experience. TTEC Digital CX architects configure the environment based on client requirements, enabling iterative testing of workflows, integrations, and advanced capabilities. Optional add-ons like Learning and Performance Management or IP solutions can extend functionality.
3. Who can customise:
Authorised client stakeholders, typically CX leaders, IT teams, and solution architects, collaborate with TTEC Digital experts to define priorities and adjust configurations during the trial period.
Scaling
- Independence of resources
- Shelf is built on a scalable, cloud-based architecture with auto-scaling capabilities. Resources are dynamically allocated to handle varying workloads, ensuring consistent performance regardless of demand. Load balancing and distributed infrastructure prevent bottlenecks, while continuous monitoring maintains optimal response times. This design guarantees that high usage by some users does not impact others, delivering reliable service availability and performance at all times.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Shelf provides detailed service usage metrics to help organisations monitor adoption and optimise performance. Metrics include the number of active users, content views, searches performed, and engagement trends over time. Administrators can track which assets are most accessed, identify knowledge gaps, and measure overall platform utilisation. Reports also include user activity by department or role, search success rates, and contribution statistics for content creators. These insights enable data-driven decisions to improve knowledge accessibility and ensure compliance with organisational goals.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- TTEC Digital: Genesys, Microsoft, NiCE, Google, Shelf, ServiceNow – ttecdigital.com/services
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data through the platform’s built-in export feature. This allows downloading in common formats such as CSV or Excel for easy integration with other systems. Exports can be applied to full datasets or filtered views, and administrators may schedule recurring exports. All data transfers are encrypted and logged to meet compliance and security standards.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- JSON – widely used for structured data exchange.
- XML – standard for hierarchical data representation.
- PDF/A – archival format for documents.
- HTML – for web content export.
- TXT – plain text for simple data.
- Markdown (MD) – lightweight text formatting.
- YAML – human-readable structured data.
- XLSX – spreadsheet format.
- RDF – semantic web data format.
- TSV – tab-separated values for tabular data.
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- JSON – structured data exchange.
- XML – hierarchical data representation.
- HTML – web content format.
- Markdown (MD) – lightweight text formatting.
- TXT – plain text files.
- TSV – tab-separated values
- YAML – human-readable structured data.
- RDF – semantic web data format.
- PDF/A – archival document format.
- XLSX – spreadsheet format.
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- Shelf enforces end-to-end encryption for all data in transit using HTTPS with TLS 1.2 or higher. In addition to standard TLS, the platform supports optional IPsec or TLS VPN gateways for enhanced security. Session integrity is maintained through strong cipher suites and perfect forward secrecy. All API calls and integrations use secure tokens over encrypted channels. Continuous monitoring and automated certificate management ensure compliance with NCSC guidelines. Legacy protocols are disabled, and strict transport security headers are applied to prevent downgrade attacks, guaranteeing robust protection between the buyer’s network and Shelf’s cloud infrastructure.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- Shelf protects data within its network using multiple layers of security. All internal communications are encrypted with TLS 1.2 or higher, and sensitive data is encrypted at rest using AES-256. Network segmentation isolates critical services, while strict role-based access controls prevent unauthorised access. Continuous monitoring and intrusion detection systems safeguard against threats. Additionally, secure VPN tunnels are used for internal integrations, and legacy protocols are disabled to maintain compliance with modern security standards. These measures ensure confidentiality, integrity, and resilience of data across the entire Shelf infrastructure.
Availability and resilience
- Guaranteed availability
-
Shelf Knowledge Management – Availability Commitment
The Shelf Knowledge Management Platform guarantees 99.9% availability each month, excluding periods of scheduled maintenance or factors outside the platform’s control, such as customer‑side connectivity, third‑party software issues, or force majeure events. This commitment is consistently defined across Shelf SOWs and licensing agreements, which specify that the Operational Percentage represents the proportion of the month during which the platform is not affected by an outage.
An outage is defined as any period in which the platform, or a portion of it, is unavailable for an identifiable number of minutes, provided it is reported within 48 hours via Shelf’s support channels (email or in‑app support).
Refund / Service Credit Mechanism:
If monthly availability falls below 99.9%, and all customer obligations have been met, the customer is entitled to service credits. For every 30 cumulative minutes of outage, the customer receives a pro‑rated credit equal to one day of their annual subscription fee, capped at one month of fees per calendar month.
This SLA ensures transparency, predictable service quality, and fair compensation should guaranteed availability not be met. - Approach to resilience
-
Service Resilience and Datacentre Design:
The Shelf Knowledge Management Platform is designed with resilience, continuity, and secure asset protection at its core, aligned to the UK Government’s Cloud Security Principle 2.
The service operates within a resilient, secure cloud architecture that incorporates automated, geographically redundant backups, ensuring continuity even in the event of a regional failure. All customer content, articles, documents, metadata, configuration, permissions, and taxonomies, is backed up regularly within Shelf’s cloud infrastructure and stored across geo‑redundant environments to protect against data loss and ensure rapid recovery.
Backups are encrypted in transit and at rest, undergo integrity checks, and support both full environment restores and granular item‑level recovery, enabling rapid restoration with minimal operational disruption.
While the underlying datacentre architecture is not published publicly for security reasons, full details of physical resilience, redundancy, failover design, and infrastructure safeguards can be provided on request under NDA.
This resilience model ensures the service can withstand outages, failures, and disruptive events while maintaining continuity, aligning to public‑sector expectations for secure, robust cloud delivery. - Outage reporting
-
Public Dashboard:
Shelf provides a public, real time operational status dashboard displaying service health, uptime over the last 90 days, component performance, authentication status, and API latency metrics. This enables customers to independently monitor service availability at any time. Customers can also subscribe directly through the dashboard for automated updates.
API Availability:
Shelf does not currently offer a public API dedicated to outage or service status reporting. The public dashboard remains the primary source of real time, machine readable service metrics.
Email Alerts:
Customers may opt in to receive automated outage and maintenance notifications by email. These alerts provide timely visibility of service-impacting events and align to the platform’s broader incident management processes.
Incident Management Communications:
In addition to automated notifications, TTEC Digital operates an internal incident management framework and coordinates escalations with Shelf. Customers are informed promptly through agreed communication channels whenever a confirmed outage occurs.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- We authenticate users through secure, multi-layered controls. Access begins with username and password validation, enforced by strong complexity and rotation policies. We support Multi-Factor Authentication (MFA) using one-time codes or authenticator apps to prevent unauthorised access. For enterprise customers, Single Sign-On (SSO) via SAML 2.0 or OAuth integrates with identity providers like Azure AD. All sessions use TLS encryption and token-based authentication to maintain confidentiality. Role-based access controls ensure users only access resources aligned with their permissions. These measures collectively provide strong identity assurance and compliance with ISO 27001 and SOC 2 standards.
- Access restrictions in management interfaces and support channels
-
Access Restrictions:
Administrative access is limited to authorised personnel using role-based permissions and least-privilege principles.
Authentication:
All access requires multi-factor authentication (MFA) and secure VPN connections for remote sessions.
Session Security:
Interfaces are protected by TLS encryption, session timeouts, and continuous monitoring for anomalies.
Support Channels:
Customer support interactions are authenticated, logged, and conducted through secure portals. Sensitive actions require identity verification and approval workflows.
These measures ensure only verified users can manage or support services securely. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
PCI DSS Level 1
SOC 2 Type 2
HIPAA
Cyber Essentials
Cyber Essentials Plus - Information security policies and processes
-
TTEC's Global Information Security (GIS) reports to the VP and Chief Security Officer. The GIS department is within TTEC’s Security, Resiliency and Governance organisation, reporting to TTEC's Chief Information Officer.
TTEC’s robust Global Privacy, Risk, Compliance, Network, and InfoSec programmes are based on the guiding principles of: Availability; Integrity; and Confidentiality. These principles are achieved through defined policies, industry controls, with infosec and privacy trainings, and through the governance structure within our corporate GIS, IT, Legal and Risk Executives.
TTEC’s policies/procedures comply with ISO 27002 compliance framework that standardise the following security elements:
•InfoSec Policy & Organisational Measures
•Asset/Data Classification
•Human Resource Security- Corrective Actions
•Physical/Environment Security
•Communication/Operation Management
•Access/Authentication/Password Management
•Data Encryption
•InfoSec Acquisition Development/Maintenance
•Endpoint Security
•Auditing, Logging, Monitoring
•Vulnerability, Penetration, Patch Management
•Network Security, Configuration Management
•Applications, SDLC, Change Management
•Incident Response Management
•Security, Fraud, Ethics Code Training- Accountability
•BCP/DR
•Global IT/Risk Management
•Regulatory Compliance
TTEC performs periodic and annual, internal, and external independent, third party, qualified, industry compliance audits of the TTEC organisational controls and technology environments. TTEC continues to achieve ongoing industry compliance accreditation with PCI DSS (SL-1), ISO 27001, SOC 2 Type II (SSAE 18), Cyber Essentials Basic & Plus, and more. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Component Tracking:
All service components are tracked throughout their lifecycle using a Configuration Management Database (CMDB). Each asset is assigned a unique identifier, with version history and dependencies recorded to maintain visibility and integrity.
Change Assessment:
Changes follow a formal Change Advisory Board (CAB) process. Every modification undergoes risk and security impact analysis, including vulnerability checks and compliance validation. Approved changes are implemented with rollback plans and logged for audit purposes. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Threat Assessment:
We continuously monitor for vulnerabilities using automated scanning tools and perform risk-based analysis to assess potential threats to services.
Patch Deployment:
Critical patches are deployed within 24 hours, while high and medium-risk updates follow defined SLAs to ensure timely remediation.
Threat Intelligence Sources:
We leverage vendor advisories, CVE databases, CSA alerts, and threat intelligence feeds from trusted security partners to stay ahead of emerging risks. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Identifying Potential Compromises:
We use SIEM tools and real-time log analysis to detect anomalies, unauthorised access attempts, and suspicious patterns. Alerts are generated for predefined indicators of compromise.
Responding to Potential Compromises:
Incidents trigger an automated containment workflow, followed by manual investigation. Actions include isolating affected systems, revoking credentials, and applying patches.
Response Time:
Our Security Operations Centre (SOC) operates 24/7, with initial response within 15 minutes of detection and full remediation initiated immediately per severity level. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Pre-Defined Processes:
We maintain documented playbooks for common incidents, including service outages, security breaches, and performance degradation. These processes ensure rapid, consistent response.
User Reporting:
Users can report incidents via 24/7 support channels, including a dedicated portal, email, and phone hotline. Automated alerts also trigger internal escalation.
Incident Reports:
We provide detailed post-incident reports outlining root cause, impact, and corrective actions. Reports are shared through secure channels and archived for compliance. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- SandcastleCX™ provides a secure, customised sandbox for testing and exploring CX technologies, including CCaaS, CRM, AI, and analytics. It offers expert guidance, platform validation, and flexible trial access at no cost for standard use cases. Ideal for innovation and proof-of-concept projects, enabling rapid evaluation without production risk.
- Link to free trial
- https://youtu.be/hNmqTiNkIx8?si=9cRF7IADXikWKBm7
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.2%
- Between £500,001 and £1,000,000
- 4.2%
- Between £1,000,001 and £2,500,000
- 6.2%
- Between £2,500,001 and £5,000,000
- 8.2%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Coalfire Certification, Inc.
- ISO/IEC 27001 accreditation date
- Thursday 21 August 2025
- What the ISO/IEC 27001 doesn’t cover
- Certification available on request.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- PCI Security Standards Council
- PCI DSS accreditation date
- Friday 28 November 2025
- What the PCI DSS doesn’t cover
- Certification available on request.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 2807b81c-9543-492c-805b-f1fd3347313f
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 613c9a41-2540-4e86-811e-d9808a365c26
- Other security certifications
- Yes
- Any other security certifications
-
- SOC 2, Type II
- HIPAA
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Content of the outreach activity is designed to suit the target cohort
-