Provision of Disclosure and Barring Service checks
A secure, cloud-based platform for conducting basic, standard and enhanced criminal record checks with associated services such as digital ID, right to work and social media checks. Ensuring compliance with safeguarding and employment law, our platform supports employers in making informed recruitment decisions, streamlines applicant verification and reduces administrative burdens.
Features
- Basic, standard and enhanced criminal DBS checks completed online securely
- Digital ID verification through mobile NFC scanning technology
- Verifies UK Right to Work eligibility using passport/share code
- Assesses available social media content, generating detailed traffic-light reports
- Restricts user access securely according to role/organisational permissions
- Monitors DBS progress in real-time through intuitive, live dashboards
- Records all user actions with timestamps for auditing/compliance
- Connects platform with customer systems for secure data exchange
- Secure access using desktop, tablet and mobile devices
- Verifies applicant eligibility and compliance to reduce errors/delays
Benefits
- Quickly complete DBS/ID/Right to Work applications
- Store applicant information securely in one location
- Track application status in real-time using dashboards
- Reduce errors and meet DBS legal/safeguarding obligations
- Digital ID checks using mobiles/NFC scanning
- Confirm applicant Right to Work before hiring
- Minimise paperwork and manual tracking with automated processes
- Restrict users to relevant data according to roles efficiently
- Export DBS results in CSV format, ID/social media/RTW in PDF
- Connect platform with existing customer systems for automated workflows
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 1 4 4 6 6 1 8 1 0 8 7 1 3 4
Contact
Care Check Ltd
Danielle Pinner
Telephone: 0333 777 8575
Email: tenders@carecheck.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Education
- Public Order and Safety
- Police
- Defence
- Social Security Administration
- Adult Social Care
- Children's Social Care
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Enabling submission/tracking of DBS, ID, Right to Work and social media checks, our service can be connected to customer HR/recruitment and onboarding systems via API. While it works alongside Applicant Tracking Systems (ATS), payroll and employee systems, any ATS integration must be completed by the ATS provider using our API.
- Cloud deployment model
- Public cloud
- Service constraints
-
Support is limited to Monday-to-Friday, 9am-5pm. Planned maintenance may result in temporary service unavailability.
Full application data is retained for six months, after which certain elements, such as the DBS results, are removed and the remaining data is archived in line with DBS Codes of Practice. If an application is withdrawn, data is cleansed immediately, leaving only basic information. All archived application data is removed after six years.
Digital ID/Right to Work checks require compatible mobile devices with NFC/camera functionality.
Once submitted to the DBS, applications cannot be amended and may be delayed due to external DBS/police audits. - System requirements
-
- Modern web browser, latest version recommended for platform compatibility
- Reliable internet connection to access cloud-based service securely
- User login credentials for authenticated platform access
- Mobile device with NFC capability for digital ID verification
- Front/rear cameras enabled for selfie/document capture
- Android 5.0 or later for digital ID/Right to Work
- IOS 7 or later for digital ID/Right to Work
- Email access for receiving applicant invitations/notifications
- Firefox browser not recommended for digital ID verification processes
User support
- Email or online ticketing support
- Yes
- Support response times
- Ensuring rapid assistance, we provide support via email, telephone and web chat, available Monday-Friday, 9am-5pm UK time. Evidencing our ability to respond swiftly and reducing waiting times, during November 2025, our customer service team answered calls on average within 1 minute and 25 seconds. However, we are aiming to reduce this to 30 seconds. Allowing users to resolve issues efficiently, we respond to emails within 1 working day. Providing real-time guidance, we also offer web chat. To minimise disruption for questions raised outside of standard working hours, we prioritise them at the start of the next working day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Improving response times and resolving queries efficiently, we provide web chat support during working hours, Monday to Friday, 9am to 5pm UK time. Ensuring easy access across devices, users can start a chat directly from the dashboard or support page without installing additional software or plugins. Outside staffed hours, a limited automated bot feature remains available 24/7 to provide basic guidance and route queries for follow up when the team is next available.
As our web chat is delivered through the LiveChat widget, accessibility testing for the chat component has been completed by LiveChat in line with the WCAG 2.2 AA standard. While we have not yet conducted additional in house testing with assistive technologies such as screen readers or alternative input devices, our support team provides personalised guidance via email, phone, chat and Teams to ensure users with accessibility needs can still access assistance.
To improve compatibility, we continually monitor accessibility feedback from users and have plans to implement formal testing with assistive technologies, including screen readers in the future. - Onsite support
- Yes, at extra cost
- Support levels
-
Reducing downtime and improving operational efficiency, we provide customer support through:
• Phone
• Email
• Web chat
• WhatsApp
Our customer service team is available Monday to Friday 9am to 5pm. Emails are responded to on average within 1 working day and calls are typically answered within 1 minute 25 seconds, with a target to reduce this to 30 seconds.
Supporting seamless applicant processing, our standard support, included at no additional cost, covers account setup, application guidance and minor troubleshooting. Enabling independent problem solving for DBS, digital ID, Right to Work and social media checks, we also provide access to online guides, video tutorials, and manuals across desktop, tablet and mobile devices.
For more complex needs, optional support includes assistance with API integrations, reporting configuration and system customisation, which are included within the initial price.
Providing continuity and rapid escalation, customers can request a dedicated technical Account Manager. Ensuring seamless operations, the Account Manager checks in with the customer every month to identify any additional support. This is included at no extra cost. - Support available to third parties
- No
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Users can register their organisation by submitting basic information, including company name, address, registration number, contact details, account email and user information. Our team reviews the registration, performs a credit check if required and sets up the account, adding users and sending login credentials and a welcome pack.
To facilitate self-sufficiency, we provide online manuals, video tutorials and step-by-step guidance, ensuring users can navigate DBS, digital ID, Right to Work and social media checks independently. Helping administrators and HR teams become confident using the platform, we also provide optional online one-to-one or group training to explain workflows, compliance requirements and system functionality. All training and demonstrations are included within our pricing.
Ensuring organisations can quickly and confidently start using the service, we provide users with a dedicated Account Managers for ongoing guidance. Evidencing its benefits, the Account Manager can support the user with issues involving integration with HR or recruitment systems, setting up multi-branch access and configuring notifications or reports. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Ensuring smooth transition and continued access to information, users can extract their data at the end of the contract through the platform’s custom report function. Facilitating flexible data management, users can generate reports in CSV format, enabling seamless integration with their own systems for auditing, compliance, or record-keeping purposes.
Supporting transparency and regulatory adherence, we provide all applicant information completed within the last 6 months in full, including application forms, DBS results, digital ID, Right to Work and social media checks. This 6 month retention period is mandated by the DBS Codes of Practice. Maintaining privacy and compliance, after 6 months, data is partially cleansed to remove sensitive results while retaining essential identifiers such as name, date of birth, reference numbers and consent details. Providing long-term legal compliance, we remove fully anonymised or deleted records permanently removed from the system after 6 years in line with data protection requirements.
Reducing administrative effort, users can request bulk data extraction prior to termination, ensuring minimal disruption to ongoing processes or HR operations. Protecting sensitive information, extraction is secure and only authorised account users can access or download data. Any data owed on accounts may temporarily restrict access until payment is resolved. - End-of-contract process
-
Ensuring a smooth transition at contract end and included in the standard contract price, users can extract all applicant data via the platform’s custom report function, provided in CSV format for integration into other systems. Supporting compliance, we provide full data for applications completed within the last 6 months. In line with DBS Codes of Practice, any snapshot/personal data older than 6 months is partially retained.
Facilitating secure account management, users can close accounts, remove or reassign personnel and revoke access, ensuring only authorised individuals retain access. These actions are also included in the contract price. We will only restrict data downloads if the customer has an outstanding account balance.
Due to system limitations, we are unable to provide any additional custom reporting beyond the standard CSV export functionality. Any optional services outside the standard contract scope, such as extended support or bespoke operational assistance, are agreed separately and may incur additional cost. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Enabling rapid onboarding and efficient learning, users can access guides, video tutorials and online manuals from desktop, tablet, or mobile devices without additional software, included in the standard service. Supporting independent problem-solving, this documentation allows users to quickly complete DBS, digital ID, Right to Work and social media checks, reducing errors and administrative workload. Facilitating multi-branch management, guidance is tailored to user roles, helping administrators and branch staff follow correct procedures while maintaining compliance with DBS Codes of Practice.
Enhancing offline accessibility, we ensure that PDFs, training slides and custom report templates can be downloaded for reference without continuous internet access. Improving user support, we provide a dedicated Account Manager to supplement documentation. Supporting ongoing learning/support, the Account Manager provides personalised walkthroughs, answering questions and guiding users through technical processes when needed. Maintaining broad compatibility, content works with most screen readers, mobile devices and common browsers, allowing users to navigate and use documentation effectively.
Supporting offboarding, users can export data via the custom report function in CSV format for integration with other systems. Recent applications remain fully accessible, while older data is partially cleansed per DBS Codes of Practice. Access may be restricted if accounts are not settled.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Maximising flexibility/accessibility, our service works on both desktop and mobile devices, allowing users to manage DBS applications, digital ID, Right to Work and social media checks anywhere. Our service provides a consistent experience across desktop/mobiles, with users accessing the same dashboard and core functionality.
Enhancing accuracy, mobile devices are required for digital ID/Right to Work checks, as NFC scanning and live selfie capture cannot be performed on desktops. Desktop users benefit from easier navigation through the larger dashboard. While mobile users gain convenience for on-the-move verification. Ensuring a consistent experience, all progress/notifications and audit trails remain synchronised across platforms. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Improving recruitment efficiency and reducing administrative workload, our service interface is web-based and accessible on desktop and mobile devices. Allowing streamlined applicant management, users can submit and monitor DBS, digital ID, Right to Work and social media checks from one intuitive dashboard.
Enhancing compliance and oversight, the interface provides real-time progress tracking, automated notifications and full audit logs. Ensuring secure, role-based access, users only see relevant applicants and data. Supporting integration and reporting, administrators can export CSV files, connect via API and manage multiple branches or accounts, delivering a centralised, reliable and user-friendly recruitment workflow. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Our main system has been tested against the WCAG 2.2 AA standard to support accessibility and ensure the interface meets recognised guidelines for inclusive design. This testing covers the core web‑based platform, including navigation, form completion and dashboard interactions across desktop and mobile devices.
The interface has not been formally tested with screen readers, alternative input devices, or other assistive technologies. However, improving user support for those with accessibility challenges, the service provides email, phone, web chat assistance during standard working hours. This is supported by a dedicated Account Manager who will check in with users every month to ensure they do not require additional help/support.
Further supporting accessibility through a clean and responsive interface that functions across desktop/mobile platforms, we design our web-based system to minimise reliance on installed software. As such users can access dashboards, monitor progress and download reports without barriers. - API
- Yes
- What users can and can't do using the API
-
Enabling rapid onboarding, authorised customers can use the API to integrate their HR/recruitment systems within the platform. This allows the system to create applicant records, initiate DBS checks, digital ID verification, Right to Work checks and social media screening programmatically. Ensuring data is routed correctly from the outset, API access is provided securely in line with the customer’s organisational structure and permission model.
Supporting efficient operations, users can update applicant details prior to submission, retrieve real-time application statuses and monitor progress through the API. Where customers use the API only for initial actions, such as sending invites but complete ID checks and Section Y within the platform, the audit trail is recorded as normal. If a customer uses the API fully end to end, no audit trail is visible within the customer interface until the application is accessed by a Care Check employee.
Ensuring compliance with DBS rules/data protection requirements, applications cannot be amended once submitted to the DBS and eligibility criteria cannot be overridden via the API. Certain administrative actions, such as data deletion, must be processed by Care Check. API access requires credentials and functionality is limited by role-based permissions. AI-driven processing is not supported through the API. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Customisation is limited to template based configuration rather than full system branding. Customisation is available primarily through email templates, allowing organisations to tailor applicant communications. Improving workflow efficiency and user experience, customers can customise, invitations, notifications and reports to align with their organisation’s branding.
Enhancing administrative control, role-based access can be customised to ensure that users only see the data relevant to their branch or function. Ensuring compliance and safeguarding, head office administrators can manage multi-branch visibility, while branch users remain restricted to their own applicants. Allowing different billing arrangements for applicants and organisational-funded checks, customers can also set up split payment accounts.
Optimising reporting and analytics, users can create custom reports using pre-populated templates or define their own CSV exports to match organisational reporting requirements. Ensuring timely communication, notifications for application progress or queries can be tailored to specific email addresses or roles.
Customisation is primarily managed by the customer’s administrators or designated Account Managers, with guidance and support provided by our team during onboarding or via ongoing support. Enabling organisations to fully adapt the service to their internal processes and operational requirements without additional software or technical expertise, we provide all customisation at no extra cost.
Scaling
- Independence of resources
-
Enabling consistent performance for all users, our service uses role-based access and account separation, so each organisation’s data and workflows remain independent. Supporting operational efficiency, each customer’s data processing, application submissions and reporting run in dedicated environments or logically separated containers.
Maintaining efficiency, we control multi-branch access so that head office users can view all branches while branch users remain restricted to their own applicants. To ensure stability of the system, our service is hosted on a dedicated server provided by Matrix Security Watchdog, our System Provider.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Enabling organisations to monitor performance and compliance, our service provides real-time metrics on application progress, pending tasks, error rates, approvals and per-user and per-branch activity. Supporting operational efficiency, users can track application progress and pending tasks through live dashboards.
Facilitating accountability, the platform’s audit logs records all user and system actions, including which applications individual users have approved. These audit details are visible within the system but cannot be exported as part of a report. Metrics can be exported in CSV format or accessed via API for integration with HR and recruitment systems. - Reporting types
-
- API access
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Ensuring seamless operational continuity, users can export their data using the platform’s custom report function, which generates CSV files for integration with other systems.
Supporting efficient record-keeping and compliance, full data for applications completed within the last 6 months, including DBS results, digital ID, Right to Work and social media checks, is readily available.
Facilitating regulatory adherence, snapshot and personal data older than 6 months are partially retained in line with DBS Codes of Practice. Maintaining secure and controlled access, users can initiate exports independently through their dashboard. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Supporting operational continuity and high availability, we host all services on UK-based virtual servers with redundant infrastructure and automated failover across geographically separated data centres. Enabling rapid restoration, we backup data multiple times a day, with compressed copies stored in the same secure network zone. Furter allowing rapid recovery, file/OS-level snapshots are managed by the data centre’s virtualisation technology. Minimising disruption, this supports rapid restoration within our Recovery Time Objective (RTO) of 24 hours and Recovery Point Objective (RPO) of 1 hour.
Enabling rapid response to incidents, our system continuously tracks uptime and system health. Maintaining user confidence, we offer a Service Level Agreement (SLA) of 99% minimal uptime for the platform infrastructure.
Minimising impact, our team communicates scheduled maintenance windows at least 48 hours in advance. Keeping critical operations visible, we perform emergency maintenance outside peak hours wherever possible. Enhancing transparency and allowing rapid identification and resolution of issues to protect user workflows, Matrix Security Watchdog, our Service Provider continuously monitors the system’s health and uptime. - Approach to resilience
-
Ensuring continuous service delivery, our platform is fully cloud-hosted on virtual servers within UK-based data centres. Supporting compliance, all data handling aligns with UK data protection regulations, DBS Codes of Practice and internal policies advised by the DPO Centre.
Supporting operational continuity, critical data, schedules and user activity are securely stored in the cloud, accessible remotely by authorised personnel. Facilitating rapid recovery, backup procedures are automated and are conducted several times per day, with compressed files stored within the secure network zone and additional OS-level snapshots managed by the data centre’s virtualisation technology. In line with best practice, this enables system restoration within the defined recovery time objectives.
Enhancing operational confidence, network connectivity, power supplies and virtual server architecture are designed with redundancies to reduce single points of failure. Minimising disruption to users, we communicate scheduled maintenance in 48-hours advance and the system fails over automatically in the event of local outages.
Our Business Continuity Plan covers loss of premises, IT, data, services, staff, or cyberattack and is reviewed annually or after major incidents and is tested regularly. - Outage reporting
- Ensuring transparency and user confidence, our service provides timely notifications of any outages, helping organisations plan and minimise operational disruption. Supporting proactive management and allowing administrators to schedule tasks around service disruptions, we notify users of planned maintenance windows via email alerts at least 48 hours in advance. These notifications include clear details on expected start and end times, affected functionalities and estimated resolution. Supporting operational efficiency and reducing impact on active users, most planned outages are completed before 9am during the workday wherever possible. Minimising disruption during emergency maintenance, we issue notifications as quickly as possible through the same communication channels, keeping users informed in real time. Further mitigating disruption and supporting continuity, our customer service team is available to provide updates and guidance on affected services during any unplanned/planned outages or incidents. Enhancing accountability, users can request historical outage reports for audit and compliance purposes, providing evidence of service availability and operational resilience
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
To protect sensitive applicant/organisational data, we restrict access in management interfaces and support channels by implementing:
• Role-based access control: Users are assigned roles, ensuring they can only view/manage applicants relevant to their role
• Principle of least privilege: Permissions are limited to only the functions each user needs to perform their job
• Authenticated access: Secure login credentials are required for all platform interfaces. MFA is enabled by default for Care Check staff and can be activated on request for individual customer accounts
• Access monitoring/audit logs: All actions in management interfaces and support interactions are logged, providing traceability - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Care Check is Cyber Essential & Cyber Essentials Plus certified and the system which we use is ISO27001 certified.
- Information security policies and processes
-
Ensuring robust protection of customer data, our System Provider, Matrix Security Watchdog, is fully ISO 27001 certified. While we do not currently hold ISO27001, we will be applying for this accreditation following the submission and we are Cyber Essentials Plus accredited. This is supported by a suite of information security policies. These include a Data Protection Policy, Information Security Policy, Data Processing Agreement, Data Retention Policy, Data Breach Policy and an Appropriate Use Policy. As part of our robust approach, we implement:
• Redundant UK data centres, with automated backups several times a day and OS-level screenshots to protect against hardware failure
• Recovery Time Objective (RTO) of 24 hours and Recovery Point Objective (RPO) of 1 hour to restore critical systems rapidly
• Business Continuity Plan covering loss of premises, IT staff or cyber attacks which is reviewed annually and tested regularly
• Mandatory staff compliance training to ensure policies are followed and compliant with UK regulations
• Role based controls to enforce secure data access and appropriate data access
• An audit trail of system access and data usage, which can be used by both us and the customer to see who has accessed, amended or approved applications - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Maintaining service availability and compliance, we track all platform components, including virtual servers, applications and sub-processor integrations, throughout their full lifecycle, from deployment to decommissioning. Assigning responsibility, Matrix Service Watchdog, our Service Provider Team is accountable for maintaining an up-to-date change management processes. Aligned with ISO27001 and Cyber Essentials Plus, we assess all proposed changes for security, operational and regulatory impact before implementation. Matrix Service Watchdog approves of any emergency changes which are subject to immediate post-implementation review. Ensuring traceability and accountability, we log all configurations changes within our Service Provider’s Information Security Management System.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Ensuring service integrity, we identify/assess potential threats to our platform, including virtual servers, applications and sub-processor integrations. To minimise exposure, Matrix Security Watchdog, our Service Provider is accountable for monitoring vulnerabilities and assessing based on risk, impact and likelihood. Enabling remediation, we source threat intelligence from the National Cyber Security Centre, the Cloud Security Alliance and the Centre for Internet Security (CIS). Patches are tested in a controlled environment and deployed according to risk-based priorities, following documented change management procedures. To maintain traceability, all vulnerability assessments, patches and configuration changes are logged within our Service Provider's Information Security Management System.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Protecting user data and maintaining operational continuity, our platform continuously monitors all virtual servers, applications and sub-processor integrations to detect potential compromises. Minimising disruption and safeguarding service integrity, we rapidly contain threats through early identification of anomalies. Prioritising incidents based on severity, our Matrix Security Watchdog, our Service Provider is accountable for investigating alerts and implementing corrective actions immediately. Supporting regulatory compliance, accountability and post-incident review, we log all activity and responses in our internal file structure, following discussions with our Product Manager.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Ensuring rapid response and continuity, our incident management processes are designed to minimise service disruption and protect user data. Enabling consistent and efficient responses, we maintain pre-defined procedures for incidents, including system outages, data access issues and security events. Users can report incidents via email, phone or web chat with guidance provided on criticality and required details. Maintaining transparency, all incidents are logged and tracked in our internal file structure, including all investigation outcomes. Supporting continuous improvement, following resolutions, we provide users with incident reports outlining the cause, impact, corrective actions and lessons learned.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0.1%
- Between £500,001 and £1,000,000
- 0.1%
- Between £1,000,001 and £2,500,000
- 0.2%
- Between £2,500,001 and £5,000,000
- 0.4%
- Over £5,000,001
- 0.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 95a4feb0-5b8d-4232-a1e1-d797f9410871
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 1a567776-484a-4020-90aa-5c7e5b148f3f
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-