Managed SD-WAN
Digital Space’s Managed SD-WAN powered by Cisco Meraki or Fortinet delivers a secure, cloud-managed SD-Branch solution for UK mid-market organisations, integrating full stack networking platforms to optimise application performance, enhance resilience, simplify operations, and provide 24x7 UK-based managed support with clear performance and security controls.
Features
- 24x7 UK based support
- Active / Active load balancing
- Application performance optimisation
- Centralised management
- Analytics & reporting
- VPN overlay
- SD-branch extending the management and reporting to LAN and Wifi
- NGFW with upgradable security enhancements
- Proactive vulnerability management and patching
- Co-management/self-service
Benefits
- Optimise application traffic and increase network performance
- Reduce operating costs through multiple underlay connectivity types
- Centralised, simplified management of SD-WAN/SD-Branch from a single dashboard
- Increased visibility of performance through cloud management dashboards
- Reduce security exposure with industry-leading edge security
- Reduced complexity and operational cost through 24x7 Network operations teams
- Reduce risk of downtime due to incorrect configurations
- Increased network operational lifecycle through patching and application optimisation
- Reduce security risks through platforms underpinned by industry-leading threat intelligence
- Easily improve security through feature bolt-ons rather than new deployments
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 7 9 8 8 9 8 0 3 1 5 7 2 4 2
Contact
Digital Space Managed Services Ltd
Afsheen Shaikh
Telephone: 0333 220 0222
Email: afsheen.shaikh@digitalspace.co.uk
About your service
- Service categories
-
Systems Infrastructure Software
Network
Network infrastructure software
- Network application delivery
- Software-defined networking (SDN)
Network management
- Network performance management (NPM)
- Network operations management (NOM)
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Hybrid cloud
- Service constraints
-
Digital Space’s SD-Networks are powered by Cisco and Fortinet technologies, features from other vendors are not supported.
Managed Service is based on a Service Desk to Service Desk model where the Customer’s IT team are the first point of contact for issues.
Emergency maintenance or critical vulnerability patches are rolled out with notice to customers only. - System requirements
-
- Proprietary hardware from either Cisco or Fortinet
- Security features are based on the licence type
User support
- Email or online ticketing support
- Yes
- Support response times
-
• We aim to triage all queries, regardless of priority, within two hours. This includes a target response time of 30 minutes. Target time for resolution (TTFR) varies according to priority: P1 – 24x7x365 support: TTFR is 4 hours, with updates every 30 minutes
• P2 – 24x7x365 support: TTFR is 8 hours, with updates every 4 hours
• P3 – business hours/weekdays (excluding bank holidays) only: TTFR is 24 hours, with updates provided once per working day
• P4 – business hours/weekdays (excluding bank holidays) only: TTFR is 48 hours, with updates provided once per working day - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
-
The Meraki Dashboard and FortiManager are browser-based management platforms designed to support accessibility best practice and are compatible with standard assistive technologies.
Formal accessibility conformance documentation (VPAT/ACR) is available from the vendors on request. Where required, the supplier supports reasonable adjustments and alternative methods of access in line with the Public Sector Bodies (websites and mobile applications) Accessibility Regulations 2018. - Web chat accessibility testing
- N/A
- Onsite support
- Yes, at extra cost
- Support levels
-
Our support comes in 3 Tiers and scopes:
• Respond – Incident, Event, Asset & Configuration and Critical Vulnerability Management
• Operate – All above plus, High Vulnerability, Problem, Change and Patch Management
• Assure – All above plus, Capacity, Availability Management and Customer Solution Architect
Pricing per Tier:
Respond
• Edge Firewall, Router or Switch - £9/Device per Month
• Broadband Modem - £2/Device per Month
• Hosted Firewalls or Hubs - £37.21/Appliance per Month
Operate:
• Unit pricing as per Respond with an additional central monthly charge of £2350
Assure:
• Unit pricing as per Respond with an additional central monthly charge of £7250 - Support available to third parties
- No
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
Our approach is structured, transparent, and aligned to public sector delivery standards, ensuring a smooth and low-risk transition into the service. We begin by working collaboratively with the customer to define the SD-WAN design, producing a clear and auditable Design Document that sets out the agreed technical architecture, scope, and acceptance criteria.
Dedicated technical specialists then deploy the SD-WAN devices alongside the cloud-hosted management, logging, and reporting platforms. The solution is implemented in line with the approved design, including all associated security, application, and connectivity policies, ensuring consistency, compliance, and operational readiness from day one.
Delivery is governed by experienced project management and coordination, providing clear ownership, structured milestones, and regular progress reporting. As part of this process, we produce a comprehensive Service Handbook to support ongoing operational use and governance.
Prior to service handover, we configure and perform high-level testing to validate that the solution meets the agreed acceptance criteria. Once testing is complete, secure access to the service is provided in accordance with the Design Document.
Where additional transition or onboarding support is required, this can be delivered flexibly under agreed time-and-materials arrangements, ensuring public sector customers receive the appropriate level of support without unnecessary cost or complexity. - Service documentation
- No
- End-of-contract data extraction
-
Users can export their own data directly from the Meraki Dashboard by using built-in reporting and analytics tools. Network, application and security data can be viewed in real time or historically, then exported in standard formats (such as CSV) via the dashboard or API for local analysis, reporting or audit purposes.
With FortiManager, users can export their data through centralised reporting and logging functions, typically via FortiAnalyzer integration. Authorised users can generate predefined or custom reports covering performance, traffic and security events, then export data in standard formats to support compliance reporting, forensic analysis and internal governance requirements. - End-of-contract process
-
At the end of the contract, the customer’s account team will provide insight into utilisation and have a discussion on continuation of existing service or have a transformation discussion if the existing solution is no longer suitable.
If a customer wishes to end the contact then a member of the DS Account Team in collaboration with the customer will scope an appropriate decommissioning plan aligned to the desired timescales. The decommissioning will be costed on a time and material basis. Digital Space will handover the administration to the customer and delete any relevant data from our internal systems.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Meraki Dashboard and FortiManager provide a common service interface that enables centralised, consistent management of the SD-WAN estate across all sites and environments.
Through a single, secure management interface, administrators can deploy and manage configuration templates, enforce network and security policies, and monitor device and link health in near real time.
The platforms support role-based access control, audit logging and policy versioning, helping to reduce operational risk and support governance requirements.
Centralised visibility of application performance, traffic flows and security events enables faster fault diagnosis, simplified change management and improved assurance of service performance and security outcomes. - Accessibility standards
- None or don’t know
- Description of accessibility
-
The Meraki Dashboard and FortiManager are browser-based management platforms designed to support accessibility best practice and are compatible with standard assistive technologies.
Formal accessibility conformance documentation (VPAT/ACR) is available from the vendors on request. Where required, the supplier supports reasonable adjustments and alternative methods of access in line with the Public Sector Bodies (websites and mobile applications) Accessibility Regulations 2018. - Accessibility testing
- N/A
- API
- Yes
- What users can and can't do using the API
-
Users can interact with the POPX Customer Ticketing API to integrate their systems with our service management platform to raise/track/update support cases. The API enables users to set up service interactions by authenticating (via Basic Authentication or OAuth) and creating cases using standardised endpoints. For case creation, users supply details such as short description, full description, impact, urgency, contact details and a correlation ID to link the case back to their own system.
Users can change cases through the API by updating permitted fields (for example description, impact or urgency), adding comments, attaching files (up to 10MB), and progressing cases through their lifecycle using defined “actions”. Case actions enforce service policies, ensuring mandatory information is provided before a case can move between states. Users can retrieve case details, list cases, view comment history and manage watchlists. Aditionally, users receive near real-time updates through webhooks when cases are created, updated, commented on, or when attachments change.
Users cannot directly set arbitrary case states (such as forcing a case to “Resolved”), cannot customise API endpoints or webhook payloads, and are restricted to predefined fields and actions. Access is role-based, and unauthorised operations are blocked to maintain service integrity and compliance. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Where self-service access to the SD-WAN solution is required, Digital Space will configure restricted, role-based access within either the Meraki dashboard or FortiManager, aligned to the customer’s governance and security policies. This controlled access enables authorised customer administrators to make defined, low-risk operational changes while maintaining overall service integrity and compliance.
Using the dashboard, users can manage URL or IP blacklisting and whitelisting to block or permit access to specific destinations in response to operational, security or safeguarding requirements. This allows rapid action to mitigate emerging threats or enable access to approved services without raising a change request.
Users can also carry out firewall policy modifications within agreed boundaries, such as adjusting existing rules to reflect changing business needs, while preventing unauthorised creation of high-risk policies.
In addition, the platforms enable application performance modification and prioritisation, allowing customers to adjust traffic handling for critical services. For example, priority can be increased for collaboration, clinical, or line-of-business applications to ensure consistent performance during periods of congestion, while lower-priority traffic is deprioritised.
All changes are logged and auditable, supporting public sector accountability, security assurance and operational transparency.
Scaling
- Independence of resources
-
Digital Space ensures users are not affected by demand from other customers by delivering Meraki and Fortinet SD-WAN services using logically segregated, per-customer environments.
Each customer’s SD-WAN is isolated through dedicated configurations, policies and security domains, preventing contention or policy overlap. Bandwidth management, application-aware routing and QoS ensure critical traffic is prioritised within each customer network.
Central platforms (Meraki Dashboard and FortiManager) are designed for multi-tenant scale and resilience, while continuous monitoring, capacity management and proactive alerting ensure platform performance remains consistent, predictable and unaffected by the activity of other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide the following metrics/information from the SD-WAN:
Performance including:
• Availability of the SD-WAN
• Availability of individual WAN interfaces across each location
• Packet loss, Latency and Jitter performance across WAN Links
• Packet loss, Latency and Jitter performance across Application SLAs
Utilisation including:
• Traffic distribution by application
• Top applications by category, use or source
• Top users
• Web categories
Security including:
• Application risk assessment providing risk score based on real application use.
• Top 10 – Malware, Botnets, Victims of Attack, Phishing.
• Number of Intrusions and Attacks by type and count. - Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- FortiNet and Cisco Meraki
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
-
Users can export their own data directly from the Meraki Dashboard by using built-in reporting and analytics tools. Network, application and security data can be viewed in real time or historically, then exported in standard formats (such as CSV) via the dashboard or API for local analysis, reporting or audit purposes.
With FortiManager, users can export their data through centralised reporting and logging functions, typically via FortiAnalyzer integration. Authorised users can generate predefined or custom reports covering performance, traffic and security events, then export data in standard formats to support compliance reporting, forensic analysis and internal governance requirements. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Our SD-WAN service does not come with any guaranteed SLAs due to a dependency on the underlying connectivity chosen by the customer. However, if the management platforms are hosted in our data centres, then these will come with a 99.99% SLA though not supported by service credits as a management platform will not impact service.
- Approach to resilience
- Resiliency is implemented based on the customer’s appetite for risk, we can offer fully resilient architectures which provide hardware resiliency, diverse secondary and tertiary connectivity at each customer location or scale this to more traditional deployment with a single edge firewall with a secondary LTE/5G failover.
- Outage reporting
-
Events that impact the customer which are correlated as warnings or exceptions will be logged by Digital Space in our ITSM toolset in line with the thresholds shown in Managed Device Monitoring Thresholds policy.
In the case of events that generate an Incident, these will be acknowledged by an alert being raised via API into our ITSM creating a ticket with a unique reference. Once a ticket is created this is then visible via the Digital Space portal.
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
- All systems are built on the principle of minimum access given providing access to data and information at a license level. Policies and Training are given to ensure staff understand how to comply, including dedicated GDPR training. New starters and staff changing role are given access to systems they require to perform their job role by system owners upon appropriate authorisation.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Digital Space operates Information Security Management System (ISMS) in accordance with ISO 27001, providing the framework for all information security policies and processes.
We maintain policies and procedures aligned with the standard’s controls, covering critical areas including access control, cryptography, physical and environmental security, supplier relationships, incident response, business continuity, asset management and compliance obligations.
Key processes:
• Formal risk assessment and treatment reviewed in a monthly risk forum.
• Mandatory security awareness training for all staff, including phishing awareness simulations.
• Documented incident management and response procedures with post-incident learning.
• Regular internal management reviews, and independent external surveillance audits.
Our Head of Security has direct accountability for the ISMS and reports to the Head of Platforms, who in turn reports to the Chief Operating Officer (COO). This structure ensures security risks and decisions receive executive visibility and sponsorship.
Policy adherence is maintained through:
• Clear control ownership and accountability.
• Automated and manual monitoring of key controls.
• Control self-assessments and internal review programmes.
• Integration of security into change management, procurement and HR processes.
• Disciplinary measures for non-compliance.
This multi-layered approach, underpinned by ISO 27001 certification, ensures Digital Space maintains an effective information security governance process. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- The asset management system tracks location, support agreements, manufacturers warranties, and EOL dates. Operations process that are "Business as Usual" include disc swaps for both faulty and EOL changes. BAU processes are fixed and tested and require no further authorisation. Non-BAU changes require operations review and approval. Changes that are software releases must have multiple sign-offs, including from the Architecture, Operations and Support departments, to ensure full impact is considered and mitigated where appropriate, including security.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Digital Space receives vulnerability and patch notifications directly from partners as well as through monitoring of other external sources. Each notification is assessed and classified by our internal teams into critical, high, medium and low.
Digital Space will patch any critical and high vulnerabilities (CVSS 7.0+) announced by our vendor or security partners within 14 Days of a fix or workaround being made available.
Medium and Low vulnerabilities can be patched on a per request basis and may be chargeable based on scope and service entitlement agreed at time of contracting. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Digital Space provides 24x7x365 event monitoring and vulnerability management through its UK-based Network Operations Centre. Potential compromises are identified using continuous monitoring and alerting from enterprise monitoring platforms, security telemetry from SD-WAN and security devices, and vendor threat intelligence feeds.
Events are automatically triaged within ServiceNow ITSM to identify abnormal behaviour, performance degradation or security indicators. When a potential compromise is detected, incidents are prioritised, contained, and remediated in line with ITIL processes, including patching or emergency change where required. Critical incidents receive a response within 30 minutes, with defined escalation and resolution targets based on severity. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Incidents are proactively identified through our monitoring or raised directly by authorised customer representatives via the service portal or support desk. All incidents are formally logged, assigned a unique reference, and time-stamped with updates provided in line with priorities to ensure full traceability in line with our Incident process.
Incidents within the service scope are managed and resolved in line with agreed service levels, while any out-of-scope issues are identified and returned to the customer. For major, multi-customer incidents, a formal major incident process is invoked to ensure coordinated response, rapid service restoration and formal incident report. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR
- ISO/IEC 27001 accreditation date
- Thursday 10 April 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Alcumus ISOQAR
- ISO 9001 accreditation date
- Thursday 10 April 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 881ef178-c69f-40e4-b6f2-717688b3ef8a
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- D8592b31-0f5b-4b81-838c-bb45c83e9ab2
- Other security certifications
- Yes
- Any other security certifications
- ISO27017
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-