Skip to main content

Help us improve the Digital Marketplace - send your feedback

TTEC CONSULTING (UK) LIMITED

TTEC Digital Shelf Knowledge Management

TTEC Digital Shelf Knowledge Management centralises and organises product content, enriched by Content Intelligence that automates enrichment and flags gaps. It streamlines updates, improves collaboration, and ensures compliance, helping organisations deliver seamless customer experiences and optimise digital shelf performance.

Features

  • Centralised product content repository.
  • Real-time content updates.
  • Automated data validation.
  • Role-based access control.
  • API integration with e-commerce platforms.
  • Multi-language content support.
  • Version control and audit trails.
  • Cloud-based scalability.
  • Advanced search and filtering.
  • Compliance and governance tools.

Benefits

  • Publish accurate content across multiple channels.
  • Quickly update product details in real time.
  • Reduce manual errors through automated validation.
  • Improve collaboration with centralised content access.
  • Ensure compliance with governance controls.
  • Accelerate product launches with streamlined workflows.
  • Enhance customer experience through consistent information.
  • Manage multilingual content efficiently.
  • Access content securely from any location.
  • Simplify integration with existing e-commerce systems.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@ttecdigital.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 5 4 3 6 6 4 8 3 6 0 2 9 4 1

Contact

TTEC CONSULTING (UK) LIMITED Wayne Kay
Telephone: 0113 5432620
Email: gcloud@ttecdigital.com

About your service

Service categories

Applications

Customer relationship management

  • Marketing campaign management
  • Digital commerce
  • Sales force productivity and management
  • Customer service
  • Contact centre

Advertising

  • Advertising Placement
  • Advertising Measurement
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Shelf Knowledge Management can integrate with and extend enterprise collaboration and content platforms such as Microsoft SharePoint, Confluence, Salesforce Knowledge, and other systems via its Content Integration Layer (CIL). These integrations allow centralised knowledge access while maintaining synchronisation with existing tools and workflows.
Cloud deployment model
Public cloud
Service constraints
The service requires internet connectivity and supported browsers for access. Performance may vary based on network bandwidth. Planned maintenance windows are scheduled outside business hours where possible and communicated in advance. Integration depends on standard APIs; custom connectors may require additional effort. Service availability is subject to cloud provider uptime. No offline mode is supported.
System requirements
  • Modern web browser (Chrome, Edge, or Firefox latest version).
  • Stable internet connection (minimum 10 Mbps recommended).
  • Enabled JavaScript and cookies in browser settings.
  • Access to HTTPS for secure communication.
  • API credentials for integration with external platforms.
  • Minimum screen resolution of 1280x720 pixels.
  • Operating system supporting modern browsers (Windows, macOS, Linux).
  • Optional VPN for secure enterprise network access.
  • Cloud storage account for data synchronisation.
  • No additional software installation required (fully SaaS-based).

User support

Email or online ticketing support
Yes
Support response times
SurroundCX™ escalation tiers and response times:

P1 – Critical
Impact: Service outage or severe business disruption.
Response: Acknowledge within 15 minutes, 24/7 coverage.

P2 – High
Impact: Major functionality impaired, but workaround exists.
Response: Acknowledge within 30 minutes, during business hours.

P3 – Standard
Impact: Minor issue or general inquiry.
Response: Acknowledge by 10:00 AM next business day.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
1. Support Levels Provided:
SurroundCX™ offers three support tiers: Essential, Plus, and Premium:
• Essential includes core monitoring, incident management, and standard platform support.
• Plus adds proactive health checks, configuration assistance, and enhanced reporting.
• Premium delivers strategic guidance, advanced analytics, priority case handling, and dedicated personnel.

2. Support Costs:
Pricing is subscription-based and varies by tier, user volume, and service complexity. Exact costs are defined in individual contracts and service-level agreements.

3. Dedicated Support Personnel:
Only Premium clients receive a dedicated Technical Account Manager for strategic oversight and a Cloud Support Engineer for technical troubleshooting and optimisation. Essential and Plus tiers rely on shared support resources.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide a comprehensive onboarding experience to help users start using the service quickly and effectively. Our support includes detailed online documentation with step-by-step setup guides, FAQs, and best practices for configuration and integration. Interactive tutorials and video walkthroughs are available for self-paced learning. We also offer live online training sessions for administrators and key users, covering essential topics such as content management, workflow setup, and reporting features. For organisations requiring deeper engagement, optional onsite training can be arranged. A dedicated support team is available via email and chat to assist with initial configuration and troubleshooting. Additionally, we provide access to a sandbox environment for technical teams to test integrations before moving to production. Regular updates, release notes, and a searchable knowledge base ensure users stay informed about new features and enhancements.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
  • Video tutorials
  • Interactive online guides
  • Knowledge base articles
  • API reference portal
  • Quick-start cheat sheets
  • Web-based FAQs
  • Release notes in markdown
  • Embedded help tooltips
  • Email onboarding packs
  • Training slide decks
End-of-contract data extraction
When the contract ends, users can extract all their data securely using multiple options. The service provides an export feature within the administrative console, allowing users to download content, metadata, and associated files in standard formats such as CSV, JSON, or XML. Bulk export tools enable retrieval of large datasets, including version history and multilingual content. For integrations, the REST API supports programmatic extraction of data, ensuring continuity for external systems. Webhooks can be leveraged to trigger final synchronisation before termination. All exports are delivered over encrypted channels (HTTPS) to maintain data security. Users are responsible for initiating the export before the termination date; post-contract access may be limited. Optional support is available to assist with data migration or provide custom export scripts for complex configurations. No proprietary lock-in applies, data remains in open, portable formats to facilitate transition to alternative platforms.
End-of-contract process
At the end of the contract, buyers retain access for a defined period to extract all data using built-in export tools or the API. Exports include product content, metadata, attachments, and version history in standard formats such as CSV, JSON, or XML. Secure HTTPS transfer ensures data protection during extraction. Included in the contract price are data export capabilities, user support for standard extraction, and access to documentation. Optional services, such as bespoke migration scripts, extended post-contract access, or professional assistance for complex integrations, are available at additional cost. After the extraction window closes, all remaining data is securely deleted in accordance with our retention and compliance policies. No proprietary lock-in applies, ensuring buyers can transition smoothly to alternative platforms.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile version offers full access to core features, including viewing, editing, and publishing product content. The interface is optimised for smaller screens with simplified navigation and responsive layouts. Some advanced administrative functions, such as bulk uploads and detailed analytics dashboards, are best experienced on desktop for ease of use. Notifications and quick updates are streamlined on mobile for on-the-go management.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service interface is a secure, web‑based dashboard accessible via modern browsers. It offers intuitive navigation with role‑based menus for managing product content, workflows, and user permissions. Key features include advanced search, real‑time content editing, version control, analytics reporting, and seamless integration with the Genesys Cloud Answer Assist widget for AI‑powered agent support. The interface supports drag‑and‑drop uploads, multilingual content management, and API configuration for external systems. Its responsive design ensures smooth use across desktop and mobile devices.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We conducted accessibility testing to ensure compatibility with assistive technologies. Testing included screen reader support using JAWS and NVDA to verify proper reading of navigation menus, form fields, and dynamic content. Keyboard-only navigation was validated to confirm that all interactive elements are operable without a mouse. We checked colour contrast ratios against WCAG 2.2 AA standards and ensured that text alternatives for images and icons were correctly implemented. Zoom and responsive design were tested on desktop and mobile browsers to confirm readability at 200% magnification. Additionally, we validated ARIA roles and labels for clarity in complex components such as dropdowns and modal dialogs. Feedback from users familiar with assistive tools helped refine focus order and error messaging for improved usability.
API
Yes
What users can and can't do using the API
How users can set up the service through the API:
- Request API client during onboarding and receive credentials.
- Configure OAuth2 token exchange; whitelist callback URLs if needed.
- Enable required scopes (content, metadata, workflow).
- Use sandbox environment to validate integrations before production.

How users can make changes through the API:
- Create, read, update, retire knowledge items and categories.
- Manage metadata, translations, attachments, and version history.
- Trigger workflow actions: submit, review, approve, publish, unpublish.
- Perform bulk import/export; subscribe to webhooks for change notifications.
- Admin (with permissions): assign users, roles, and access policies.

Limitations to setup or changes through the API:
- HTTPS required; requests must follow documented schemas and pagination.
- Rate and payload size limits apply; long‑running jobs are asynchronous.
- Hard delete is restricted; recovery actions require elevated approval.
- Custom workflow design and UI configuration occur in the admin console.
- Unsupported connectors may need professional services for enablement.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
1. What can be customised:
Users can tailor their SandcastleCX™ environment to match specific CX use cases, technology platforms (e.g., Genesys, AWS, Microsoft, Salesforce and NiCE), integrations, and features such as voice routing, CRM connectors, bots, and reporting dashboards.

2. How users can customise:
Customisation is achieved through a guided, hands-on sandbox experience. TTEC Digital CX architects configure the environment based on client requirements, enabling iterative testing of workflows, integrations, and advanced capabilities. Optional add-ons like Learning and Performance Management or IP solutions can extend functionality.

3. Who can customise:
Authorised client stakeholders, typically CX leaders, IT teams, and solution architects, collaborate with TTEC Digital experts to define priorities and adjust configurations during the trial period.

Scaling

Independence of resources
Shelf is built on a scalable, cloud-based architecture with auto-scaling capabilities. Resources are dynamically allocated to handle varying workloads, ensuring consistent performance regardless of demand. Load balancing and distributed infrastructure prevent bottlenecks, while continuous monitoring maintains optimal response times. This design guarantees that high usage by some users does not impact others, delivering reliable service availability and performance at all times.

Analytics

Service usage metrics
Yes
Metrics types
Shelf provides detailed service usage metrics to help organisations monitor adoption and optimise performance. Metrics include the number of active users, content views, searches performed, and engagement trends over time. Administrators can track which assets are most accessed, identify knowledge gaps, and measure overall platform utilisation. Reports also include user activity by department or role, search success rates, and contribution statistics for content creators. These insights enable data-driven decisions to improve knowledge accessibility and ensure compliance with organisational goals.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
TTEC Digital: Genesys, Microsoft, NiCE, Google, Shelf, ServiceNow – ttecdigital.com/services

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Physical access control, complying with another standard
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export their data through the platform’s built-in export feature. This allows downloading in common formats such as CSV or Excel for easy integration with other systems. Exports can be applied to full datasets or filtered views, and administrators may schedule recurring exports. All data transfers are encrypted and logged to meet compliance and security standards.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • JSON – widely used for structured data exchange.
  • XML – standard for hierarchical data representation.
  • PDF/A – archival format for documents.
  • HTML – for web content export.
  • TXT – plain text for simple data.
  • Markdown (MD) – lightweight text formatting.
  • YAML – human-readable structured data.
  • XLSX – spreadsheet format.
  • RDF – semantic web data format.
  • TSV – tab-separated values for tabular data.
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • JSON – structured data exchange.
  • XML – hierarchical data representation.
  • HTML – web content format.
  • Markdown (MD) – lightweight text formatting.
  • TXT – plain text files.
  • TSV – tab-separated values
  • YAML – human-readable structured data.
  • RDF – semantic web data format.
  • PDF/A – archival document format.
  • XLSX – spreadsheet format.

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks
Shelf enforces end-to-end encryption for all data in transit using HTTPS with TLS 1.2 or higher. In addition to standard TLS, the platform supports optional IPsec or TLS VPN gateways for enhanced security. Session integrity is maintained through strong cipher suites and perfect forward secrecy. All API calls and integrations use secure tokens over encrypted channels. Continuous monitoring and automated certificate management ensure compliance with NCSC guidelines. Legacy protocols are disabled, and strict transport security headers are applied to prevent downgrade attacks, guaranteeing robust protection between the buyer’s network and Shelf’s cloud infrastructure.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Shelf protects data within its network using multiple layers of security. All internal communications are encrypted with TLS 1.2 or higher, and sensitive data is encrypted at rest using AES-256. Network segmentation isolates critical services, while strict role-based access controls prevent unauthorised access. Continuous monitoring and intrusion detection systems safeguard against threats. Additionally, secure VPN tunnels are used for internal integrations, and legacy protocols are disabled to maintain compliance with modern security standards. These measures ensure confidentiality, integrity, and resilience of data across the entire Shelf infrastructure.

Availability and resilience

Guaranteed availability
Shelf Knowledge Management – Availability Commitment
The Shelf Knowledge Management Platform guarantees 99.9% availability each month, excluding periods of scheduled maintenance or factors outside the platform’s control, such as customer‑side connectivity, third‑party software issues, or force majeure events. This commitment is consistently defined across Shelf SOWs and licensing agreements, which specify that the Operational Percentage represents the proportion of the month during which the platform is not affected by an outage.

An outage is defined as any period in which the platform, or a portion of it, is unavailable for an identifiable number of minutes, provided it is reported within 48 hours via Shelf’s support channels (email or in‑app support).

Refund / Service Credit Mechanism:
If monthly availability falls below 99.9%, and all customer obligations have been met, the customer is entitled to service credits. For every 30 cumulative minutes of outage, the customer receives a pro‑rated credit equal to one day of their annual subscription fee, capped at one month of fees per calendar month.

This SLA ensures transparency, predictable service quality, and fair compensation should guaranteed availability not be met.
Approach to resilience
Service Resilience and Datacentre Design:
The Shelf Knowledge Management Platform is designed with resilience, continuity, and secure asset protection at its core, aligned to the UK Government’s Cloud Security Principle 2.

The service operates within a resilient, secure cloud architecture that incorporates automated, geographically redundant backups, ensuring continuity even in the event of a regional failure. All customer content, articles, documents, metadata, configuration, permissions, and taxonomies, is backed up regularly within Shelf’s cloud infrastructure and stored across geo‑redundant environments to protect against data loss and ensure rapid recovery.

Backups are encrypted in transit and at rest, undergo integrity checks, and support both full environment restores and granular item‑level recovery, enabling rapid restoration with minimal operational disruption.

While the underlying datacentre architecture is not published publicly for security reasons, full details of physical resilience, redundancy, failover design, and infrastructure safeguards can be provided on request under NDA.

This resilience model ensures the service can withstand outages, failures, and disruptive events while maintaining continuity, aligning to public‑sector expectations for secure, robust cloud delivery.
Outage reporting
Public Dashboard:
Shelf provides a public, real time operational status dashboard displaying service health, uptime over the last 90 days, component performance, authentication status, and API latency metrics. This enables customers to independently monitor service availability at any time. Customers can also subscribe directly through the dashboard for automated updates.

API Availability:
Shelf does not currently offer a public API dedicated to outage or service status reporting. The public dashboard remains the primary source of real time, machine readable service metrics.

Email Alerts:
Customers may opt in to receive automated outage and maintenance notifications by email. These alerts provide timely visibility of service-impacting events and align to the platform’s broader incident management processes.

Incident Management Communications:
In addition to automated notifications, TTEC Digital operates an internal incident management framework and coordinates escalations with Shelf. Customers are informed promptly through agreed communication channels whenever a confirmed outage occurs.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Other user authentication
We authenticate users through secure, multi-layered controls. Access begins with username and password validation, enforced by strong complexity and rotation policies. We support Multi-Factor Authentication (MFA) using one-time codes or authenticator apps to prevent unauthorised access. For enterprise customers, Single Sign-On (SSO) via SAML 2.0 or OAuth integrates with identity providers like Azure AD. All sessions use TLS encryption and token-based authentication to maintain confidentiality. Role-based access controls ensure users only access resources aligned with their permissions. These measures collectively provide strong identity assurance and compliance with ISO 27001 and SOC 2 standards.
Access restrictions in management interfaces and support channels
Access Restrictions:
Administrative access is limited to authorised personnel using role-based permissions and least-privilege principles.

Authentication:
All access requires multi-factor authentication (MFA) and secure VPN connections for remote sessions.

Session Security:
Interfaces are protected by TLS encryption, session timeouts, and continuous monitoring for anomalies.

Support Channels:
Customer support interactions are authenticated, logged, and conducted through secure portals. Sensitive actions require identity verification and approval workflows.
These measures ensure only verified users can manage or support services securely.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
PCI DSS Level 1
SOC 2 Type 2
HIPAA
Cyber Essentials
Cyber Essentials Plus
Information security policies and processes
TTEC's Global Information Security (GIS) reports to the VP and Chief Security Officer. The GIS department is within TTEC’s Security, Resiliency and Governance organisation, reporting to TTEC's Chief Information Officer.
TTEC’s robust Global Privacy, Risk, Compliance, Network, and InfoSec programmes are based on the guiding principles of: Availability; Integrity; and Confidentiality. These principles are achieved through defined policies, industry controls, with infosec and privacy trainings, and through the governance structure within our corporate GIS, IT, Legal and Risk Executives.
TTEC’s policies/procedures comply with ISO 27002 compliance framework that standardise the following security elements:

•InfoSec Policy & Organisational Measures
•Asset/Data Classification
•Human Resource Security- Corrective Actions
•Physical/Environment Security
•Communication/Operation Management
•Access/Authentication/Password Management
•Data Encryption
•InfoSec Acquisition Development/Maintenance
•Endpoint Security
•Auditing, Logging, Monitoring
•Vulnerability, Penetration, Patch Management
•Network Security, Configuration Management
•Applications, SDLC, Change Management
•Incident Response Management
•Security, Fraud, Ethics Code Training- Accountability
•BCP/DR
•Global IT/Risk Management
•Regulatory Compliance

TTEC performs periodic and annual, internal, and external independent, third party, qualified, industry compliance audits of the TTEC organisational controls and technology environments. TTEC continues to achieve ongoing industry compliance accreditation with PCI DSS (SL-1), ISO 27001, SOC 2 Type II (SSAE 18), Cyber Essentials Basic & Plus, and more.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Component Tracking:
All service components are tracked throughout their lifecycle using a Configuration Management Database (CMDB). Each asset is assigned a unique identifier, with version history and dependencies recorded to maintain visibility and integrity.

Change Assessment:
Changes follow a formal Change Advisory Board (CAB) process. Every modification undergoes risk and security impact analysis, including vulnerability checks and compliance validation. Approved changes are implemented with rollback plans and logged for audit purposes.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Threat Assessment:
We continuously monitor for vulnerabilities using automated scanning tools and perform risk-based analysis to assess potential threats to services.

Patch Deployment:
Critical patches are deployed within 24 hours, while high and medium-risk updates follow defined SLAs to ensure timely remediation.

Threat Intelligence Sources:
We leverage vendor advisories, CVE databases, CSA alerts, and threat intelligence feeds from trusted security partners to stay ahead of emerging risks.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Identifying Potential Compromises:
We use SIEM tools and real-time log analysis to detect anomalies, unauthorised access attempts, and suspicious patterns. Alerts are generated for predefined indicators of compromise.

Responding to Potential Compromises:
Incidents trigger an automated containment workflow, followed by manual investigation. Actions include isolating affected systems, revoking credentials, and applying patches.

Response Time:
Our Security Operations Centre (SOC) operates 24/7, with initial response within 15 minutes of detection and full remediation initiated immediately per severity level.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Pre-Defined Processes:
We maintain documented playbooks for common incidents, including service outages, security breaches, and performance degradation. These processes ensure rapid, consistent response.

User Reporting:
Users can report incidents via 24/7 support channels, including a dedicated portal, email, and phone hotline. Automated alerts also trigger internal escalation.

Incident Reports:
We provide detailed post-incident reports outlining root cause, impact, and corrective actions. Reports are shared through secure channels and archived for compliance.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
SandcastleCX™ provides a secure, customised sandbox for testing and exploring CX technologies, including CCaaS, CRM, AI, and analytics. It offers expert guidance, platform validation, and flexible trial access at no cost for standard use cases. Ideal for innovation and proof-of-concept projects, enabling rapid evaluation without production risk.
Link to free trial
https://youtu.be/hNmqTiNkIx8?si=9cRF7IADXikWKBm7

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2.2%
Between £500,001 and £1,000,000
4.2%
Between £1,000,001 and £2,500,000
6.2%
Between £2,500,001 and £5,000,000
8.2%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Coalfire Certification, Inc.
ISO/IEC 27001 accreditation date
Thursday 21 August 2025
What the ISO/IEC 27001 doesn’t cover
Certification available on request.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
PCI Security Standards Council
PCI DSS accreditation date
Friday 28 November 2025
What the PCI DSS doesn’t cover
Certification available on request.
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
2807b81c-9543-492c-805b-f1fd3347313f
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
613c9a41-2540-4e86-811e-d9808a365c26
Other security certifications
Yes
Any other security certifications
  • SOC 2, Type II
  • HIPAA

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Content of the outreach activity is designed to suit the target cohort

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@ttecdigital.com. Tell them what format you need. It will help if you say what assistive technology you use.