What is G-Cloud 15? A guide to buying cyber security services

G-Cloud 15 Buyers Guide

G-Cloud 15 is the latest version of the UK Government’s long-running procurement framework for cloud-based computing services. It gives public sector buyers an established route to cloud hosting, infrastructure and platform services, cloud software, software as a service and specialist support connected to the adoption, security, operation or transition of cloud services.

For organisations that do not work with government frameworks every day, the name can obscure what G-Cloud does. It is not a single government cloud, a technology platform or a cyber security accreditation but a commercial agreement between government and appointed suppliers. The agreement establishes the terms, service categories and procurement routes that eligible public sector bodies can use when buying services listed within the framework.

The benefit is that a buyer does not need to create an entirely new procurement structure for every cloud requirement. G-Cloud provides an existing contractual route, published supplier information and defined call-off procedures. The buyer must still understand its requirement, identify the correct lot, evaluate the relevant services and document why the selected procurement route and supplier meet its needs.

Logiq has been appointed to G-Cloud 15 under Lot 2a Infrastructure Software, Lot 2b Software as a Service and Lot 3 Cloud Support Services. These positions cover secure cloud platforms alongside the cloud-related cyber security, assurance, architecture, implementation and operational support that public sector programmes may need around them.

G-Cloud 15 at a glance

  • Framework: G-Cloud 15
  • Agreement reference: RM1557.15
  • Framework owner: Government Commercial Agency, formerly Crown Commercial Service
  • Legal basis: Procurement Act 2023
  • Core scope: cloud hosting, infrastructure and platform services, cloud software and cloud support services
  • Framework structure: five lots covering IaaS/PaaS, higher-assurance hosting, infrastructure software, SaaS and cloud support
  • Framework model: a four-year open framework, reopening after 18 and 36 months
  • Logiq’s award scope: Lot 2a Infrastructure Software, Lot 2b SaaS and Lot 3 Cloud Support Services
  • Authoritative buying information: the live G-Cloud 15 catalogue entries, service definitions, pricing, framework documents and current buyer guidance

Why was G-Cloud created?

The first G-Cloud framework launched in 2012 as part of a wider effort to change how government bought technology. Traditional public sector IT procurements could be lengthy, expensive and difficult for smaller suppliers to enter. Cloud services were also evolving more quickly than conventional long-term infrastructure contracts could comfortably accommodate.

G-Cloud was intended to make cloud procurement more accessible, repeatable and transparent. It created a catalogue-based route through which buyers could compare standardised service information, pricing and supplier terms. It also reduced barriers for small and medium-sized enterprises, giving public sector organisations access to a broader supplier market rather than relying only on the largest technology vendors and systems integrators.

The framework later became closely associated with the Government’s Cloud First policy, introduced in 2013, which required central government organisations to consider cloud solutions before other options for new technology decisions. The Digital Marketplace followed in 2014 as the online service through which G-Cloud and other digital frameworks could be searched and accessed.

Successive versions have updated the suppliers, services and commercial terms available to buyers. G-Cloud 15 represents a more substantial change than a routine catalogue refresh because it is being let under the Procurement Act 2023, uses a revised five-lot structure and introduces more extensive evaluation of suppliers and framework tenders.

What G-Cloud is

G-Cloud is a framework agreement. It creates a legally compliant route through which eligible buyers can place a call-off contract for services that fall within the framework scope. Appointment allows a supplier to offer the services included in its framework tender, but it does not mean that every service offered by that supplier outside G-Cloud is available through the agreement.

G-Cloud is also distinct from the digital platform used to access it. The framework contains the legal and commercial rules; the government platform provides the searchable service information and supports the buying process. References to the Digital Marketplace, Contract Award Service or Public Procurement Gateway describe parts of that access route, not a separate procurement framework.

Supplier appointment should not be treated as a blanket government endorsement, security accreditation or guarantee that a particular service is appropriate for every buyer. G-Cloud 15 introduces evaluation of price, quality, social value, technical ability and economic and financial standing, but the buyer remains responsible for assessing the service against its own functional, security, commercial, data-handling and operational requirements.

Who can use G-Cloud 15?

G-Cloud is designed for eligible UK public sector organisations and other bodies identified in the framework’s contract notice and customer list. This commonly includes central government departments and arm’s-length bodies, local authorities, NHS organisations, education bodies, police and other blue-light services, devolved administrations and a wide range of wider public sector organisations.

The buyer must confirm that its organisation is eligible to use the agreement and follow its own governance, delegated authority and procurement policies. Access to a framework does not remove the need for an approved business case, budget, information assurance, data protection review or any internal commercial controls that apply to the purchase.

What can be bought through G-Cloud 15?

G-Cloud 15 is organised into five lots. The lot is determined by the nature of the service being bought, rather than the buyer’s sector or the supplier’s general area of expertise.

G-Cloud 15 lotWhat it covers
Lot 1a: Infrastructure as a Service and Platform as a ServiceCloud hosting, compute, storage, networking, platform services and related infrastructure capabilities delivered at the standard framework security scope.
Lot 1b: IaaS and PaaS above OFFICIALInfrastructure and platform services designed for requirements above the OFFICIAL tier, subject to the specific scope and assurance requirements of the published service.
Lot 2a: Infrastructure Software (I-SaaS)Cloud-delivered infrastructure software, service-management software and enabling capabilities used to operate, integrate, secure or manage cloud environments.
Lot 2b: Software as a Service (SaaS)Cloud applications and application services delivered as software as a service, including productivity, collaboration, business and security applications.
Lot 3: Cloud Support Services (Additional Services)Professional and managed services that help buyers set up, maintain, secure, improve or transition to cloud software or hosting.

Logiq’s appointment covers Lots 2a, 2b and 3. It does not include the Lot 1 hosting categories. The live catalogue entry remains the authoritative source for deciding which Logiq service sits in each lot and what is included within that service.

What is different about G-Cloud 15?

G-Cloud 15 replaces G-Cloud 14, G-Cloud 14 Lot 4 and Cloud Compute 2. It updates both the market structure and the procurement model, reflecting the Procurement Act 2023 and the Government Commercial Agency’s intention to apply a more conventional framework evaluation at the scale required by G-Cloud.

ChangeWhat it means
Procurement Act 2023G-Cloud 15 uses the newer public procurement regime and a Public Sector Contract-based set of framework and call-off terms.
Four-year open frameworkThe framework is planned to run for four years and reopen to supplier applications after 18 and 36 months, allowing the market to refresh during its lifetime.
Five-lot structureHosting is divided between standard and above-OFFICIAL requirements, software is divided between infrastructure software and SaaS, and cloud support is consolidated into Lot 3.
More extensive evaluationFramework tenders are evaluated across price, quality and social value, with technical ability and economic and financial standing assessed as part of appointment.
New category taxonomyService categories are intended to align more closely with the current cloud market and improve the quality of searchable service information.
Call-offs with or without competitionAll lots provide routes that may allow an award without competition or require a competitive selection process, depending on the requirement and the framework conditions.
Longer call-off periodsFor Lots 2a, 2b and 3, the initial call-off period may be up to four years, with optional extensions of up to two further years where the framework terms and requirement allow.

How does buying through G-Cloud 15 work?

A framework reduces the work required to establish contractual terms and identify eligible suppliers, but it does not replace procurement judgement. The buying process should begin with the requirement, not with a supplier name or a product search.

The buyer should define the outcome, users, data, security requirements, integrations, operating model, service levels, support model, implementation needs and exit position. That information determines the relevant lot, the services that should be considered and whether the requirement can be satisfied by an existing published entry without changing its essential scope.

The buyer then uses the government platform and framework information to identify services that meet the requirement, assess their published scope and pricing, and apply the appropriate call-off procedure. The order form and applicable call-off schedules turn the framework service into a contract between the buyer and supplier, with any permitted buyer-specific requirements recorded within the framework rules.

When should you use G-Cloud 15?

G-Cloud 15 is most relevant where the core requirement is for a cloud service or for support that directly helps an organisation adopt, secure, operate, maintain or transition to cloud hosting or software.

  • You need cloud software or infrastructure software described by a published service entry.
  • You need cloud-related security, architecture, migration, assurance, testing, training or operational support.
  • The required outcome, users, data, environment, service levels and security needs can be described clearly enough to evaluate supplier fit.
  • The requirement can be contracted within the published framework scope and call-off terms.
  • You want to use established commercial terms and a defined framework award procedure rather than build a procurement route from the ground up.

G-Cloud 15 should not be treated as a general route for every cyber security requirement. Lot 3 support must remain connected to setting up, maintaining, securing or transitioning to cloud software or hosting. Standalone consultancy or operational work with no meaningful cloud connection may need a different agreement.

What kinds of cyber security services are available?

Cyber security can appear in G-Cloud 15 as software, as a managed operational capability or as professional support. The correct route depends on what the buyer is purchasing and how the service is described in the supplier’s published entry.

G-Cloud 15 areaHow cyber security can fit
Lot 2a: Infrastructure Software (I-SaaS)Security infrastructure, service-management platforms, secure gateways, monitoring, orchestration, integration and other software used to manage or protect cloud environments.
Lot 2b: Software as a Service (SaaS)Secure collaboration, identity, data protection, security applications and other cloud applications delivered as a managed software service.
Lot 3: Cloud Support ServicesSecurity strategy, risk management, security architecture, incident management, audit, quality assurance, testing, migration support, managed cloud services and other cloud-related professional services.

The live catalogue entry is decisive. A supplier’s appointment to a lot does not automatically make every product, consultancy service or managed capability in its wider portfolio available through G-Cloud 15.

Can cyber security consultancy be bought through G-Cloud 15?

Yes, where the consultancy is cloud-related and sits within a published Lot 3 service. The G-Cloud 15 specification includes areas such as security strategy, security risk management, security design, security incident management, security audit, quality assurance and testing within the Cloud Support Services taxonomy.

This can support cloud security architecture, cloud risk assessment, assurance of cloud controls, migration security, Secure by Design activity for cloud programmes, cloud incident readiness and security testing. The connection to cloud software or hosting must be genuine and reflected in the scope of the service being bought.

Lot 3 can be procured independently of the software and hosting lots. It can also support a cloud service acquired outside G-Cloud 15, and the support supplier does not necessarily need to be the organisation providing the underlying cloud platform.

Can managed services be bought?

Yes, provided the managed service is included within the supplier’s published entry and remains within the lot scope. G-Cloud 15 includes Cloud Managed Services focused on the ongoing operation of cloud environments across hosted, on-premises and multicloud estates. The definition can include applications, infrastructure, business processes and embedded professional services where these form part of the cloud service.

Buyers should look beyond the phrase ‘managed service’. The service definition and call-off should make clear what is monitored and managed, operating hours, service levels, tooling, incident responsibilities, escalation routes, reporting, security boundaries, subcontractors and the division of responsibility between buyer, supplier and underlying cloud provider.

Can software and support be combined?

Yes. A requirement may combine a Lot 2 software service with implementation, migration, security architecture, assurance, training or ongoing support. Where permitted by the published entry and framework terms, relevant support may be included as an additional service around the software.

A buyer may also purchase Lot 3 support separately or from a different supplier. This allows an organisation, for example, to procure a secure cloud platform from one provider and engage a specialist cyber security consultancy to assess, migrate, assure or support the environment.

The buyer must still identify the correct catalogue entries and apply the appropriate award procedure. Services cannot be added informally where they are absent from the supplier’s framework scope or materially change the service that was tendered.

How are services awarded under G-Cloud 15?

G-Cloud 15 provides three potential call-off routes. The correct route depends on the framework conditions, the nature and complexity of the requirement and whether an objective selection mechanism can identify a service without further competition.

Call-off routeWhat it means in practice
Award Without CompetitionAvailable where the framework’s objective selection mechanism identifies a particular supplier, the published service meets the requirement and the call-off can be placed using terms already established by the framework.
Two Stage Competitive Selection ProcessThe buyer assesses conditions of participation, invites the remaining eligible suppliers to tender and evaluates their responses against the framework criteria.
Multi Stage Competitive Selection ProcessA modular competitive process for more complex requirements, using mandatory and optional stages set out in the buyer’s tender pack.

An award without competition is not an informal direct purchase. The buyer must follow the framework’s objective selection process, maintain an audit trail and be able to show why the selected service satisfies the requirement. Competitive routes require a clear Statement of Requirements, proportionate evaluation criteria and the notices and records required under the Procurement Act 2023.

What should buyers evaluate?

Framework appointment establishes a commercial route and confirms that the supplier passed the framework evaluation. It does not remove the need to assess the specific service, delivery model and evidence against the buyer’s environment.

Evidence to assessWhat good evidence looks like
Clear scope and lot fitThe service description should show what is included, what is excluded, how the service relates to cloud software or hosting, and which additional services or dependencies may be required.
Security and assurance evidenceCertifications, assured services, security architecture, control evidence and professional credentials should be relevant to the actual requirement. Cyber Essentials or Cyber Essentials Plus may be valuable evidence; for Lots 2a, 2b and 3 they are not universally mandatory at framework appointment, so buyers should specify the assurance they require.
Architecture and delivery capabilityThe supplier should be able to connect business requirements, cloud architecture, risk, controls, implementation and operational responsibilities.
Operational detailCheck service levels, support hours, monitoring, incident handling, reporting, business continuity, disaster recovery, patching, vulnerability management, data handling and exit arrangements.
Shared-responsibility modelThe service should state which controls belong to the buyer, the supplier, subcontractors and the underlying cloud provider, including how evidence and incidents are handled across those boundaries.
Experience in comparable environmentsEvidence from similar public sector, regulated or sensitive environments is more useful than broad capability claims.
Commercial transparencyReview published pricing, assumptions, dependencies, optional services, volume bands and any circumstances that could alter cost or delivery.
Implementation and exitAssess onboarding timescales, migration, acceptance criteria, data portability, knowledge transfer, termination support and the practical route away from the service at contract end.

Where does Logiq fit?

Logiq is appointed to G-Cloud 15 across Lot 2a Infrastructure Software, Lot 2b Software as a Service and Lot 3 Cloud Support Services. The breadth of the award connects secure cloud software with the consultancy, engineering, assurance and operational support that public sector programmes often require around it.

Secure platforms and cloud software

Across its Lot 2 portfolio, Logiq has included secure cloud capabilities designed for organisations working with sensitive information. The live government catalogue will provide the final service names, lot mapping, scope, pricing and service documentation.

  • DISX – a managed secure collaboration environment supporting Microsoft 365, Teams, SharePoint, secure email, endpoint controls and connectivity options for government and defence collaboration.
  • Secure Internet Gateway – policy-controlled access incorporating filtering, threat prevention and centralised traffic monitoring.
  • Secure Printer Management – controlled and auditable printing to approved devices and networks.
  • Secure Artificial Intelligence – a customer-controlled AI environment designed to protect sensitive information and support data sovereignty.
  • Secure Ingest Systems – multi-engine malware scanning and content sanitisation for files entering secure or isolated environments..

Cloud-related cyber security and assurance

Logiq’s Lot 3 portfolio covers cloud-related support from early strategy and architecture through delivery, assurance and operation.

Logiq capabilityRelevant awarded scope
Cyber security and assuranceNCSC-assured Risk Management, Security Architecture and Audit and Review; cloud security assessments; policy, governance, security strategy and improvement.
Secure by Design, CAF and GovAssureSecure by Design delivery, training and assessments; CAF-aligned risk management, gap analysis, evidence mapping, assurance review support and remediation planning.
Operational technology and ICSOT audit, risk management, process mapping, secure architecture, lifecycle security, incident exercises and cyber-safety integration where cloud and hybrid services form part of the environment.
Technical programme supportBusiness analysis, portfolio and programme management, systems engineering, product ownership, agile delivery and technical coordination for cloud and secure digital programmes.
Data, analytics and business intelligenceData analytics, Power BI and Power Apps, business intelligence, data governance and decision-support capabilities for cloud-enabled services.
Architecture, ServiceNow and solution deliveryEnterprise, technical, security and data architecture; ServiceNow implementation, configuration, upgrade, monitoring and support; cloud-ready solution design.
Cloud migration and secure implementationCloud migration planning and transition, secure cloud infrastructure, public cloud configuration, Secure AI implementation and secure collaborative working environments.
Managed and ongoing supportSecure managed services, monitoring and maintenance, ISO/IEC 20000-aligned service management, security-cleared support desk capability and through-life support.

Why the breadth matters

Many public sector cloud requirements do not end with the purchase of a software licence. Security requirements need to be established, architectures designed, risks managed, users and data migrated, services operated and assurance evidence maintained throughout the contract.

Logiq’s G-Cloud 15 portfolio supports that wider lifecycle: secure platforms where a managed capability is required, and specialist cloud support where the buyer needs independent advice, delivery assistance, assurance or ongoing operation. Relevant credentials and experience include:

How to begin

A buyer should begin by defining the outcome and the operating context before searching the catalogue. Once the relevant service entries are identified, the published scope, pricing and dependencies can be tested against the requirement and the appropriate call-off route selected.

  • the service or operational outcome required
  • the existing cloud, on-premises or hybrid environment
  • the users, partner organisations and locations involved
  • the sensitivity, classification and handling requirements of the information
  • integration, identity, connectivity and migration dependencies
  • the required assurance, monitoring, support and service-management model
  • implementation timescales, acceptance criteria and exit requirements
  • the procurement timetable and likely call-off procedure

How we can help

Logiq can explain the scope of its G-Cloud 15 entries and help buyers determine which secure software, consultancy or support services are relevant to a defined cloud requirement. Early engagement can clarify service boundaries, dependencies, assurance needs and the catalogue information required for evaluation.

Our role can extend from initial cloud security and architecture advice through implementation, migration, assurance and ongoing managed support. The buyer remains responsible for its procurement strategy and award decision, but a clearer technical and security requirement makes it easier to identify the correct lot, service entry and call-off route.