AuditXYZ

Compliance Framework

G-Cloud Digital Marketplace Framework (G-Cloud)

G-Cloud is the UK government's digital marketplace for cloud services. This guide covers how to list services, compliance requirements, the procurement process, and tips for winning public sector contracts.

$5,000–$30,0001–3 monthsG-Cloud 14 (2024)
Issuing BodyUK Crown Commercial Service (CCS) / Government Digital Service (GDS)
First Published2012-02-01
Latest VersionG-Cloud 14 (2024)
Typical Cost$5,000–$30,000
Typical Timeline1–3 months
Audit RequiredNo
Audit FrequencyNo formal audit, but suppliers must self-certify against framework requirements. CCS may request evidence of compliance. Frameworks are refreshed approximately annually.
Geographyunited-kingdom

G-Cloud: UK Government Cloud Procurement Framework

G-Cloud is the UK government's framework agreement for procuring cloud services, hosted on the Digital Marketplace. It enables public sector organizations — from central government to local councils, NHS bodies, and emergency services — to find and buy cloud hosting, software, and support services through a streamlined procurement process. For cloud providers, G-Cloud listing provides access to the UK's substantial public sector IT spending.

What G-Cloud Is and Who Issues It

G-Cloud is a Crown Commercial Service (CCS) framework agreement. The CCS is an executive agency of the Cabinet Office that provides commercial and procurement services to the UK public sector, negotiating agreements that public sector buyers can use without conducting their own full procurement process. G-Cloud was first launched in 2012 to modernize public sector cloud procurement, which had previously been slow, expensive, and biased toward large incumbent suppliers.

The Government Digital Service (GDS) developed the technology platform — the Digital Marketplace — where suppliers list services and buyers search for them. GDS and CCS work together on framework policy, eligibility criteria, and governance. Individual iterations of the framework (G-Cloud 13, G-Cloud 14, and future versions) are refreshed approximately annually, opening for new supplier applications during defined application windows.

G-Cloud sits within the UK government's broader procurement legal framework, including the Public Contracts Regulations 2015 (PCR 2015) and, post-Brexit, the Procurement Act 2023. The framework structure allows public sector buyers to make direct awards to listed suppliers below applicable financial thresholds, significantly accelerating procurement timelines compared to running standalone tenders.

As of 2024, G-Cloud 14 is the live framework. Cumulative sales through G-Cloud have exceeded £10 billion since the programme launched, demonstrating its significance as a route to market for cloud suppliers across all sizes.

Who Should List on G-Cloud

G-Cloud is open to any supplier offering commercially available cloud services that meet the framework's eligibility requirements. The buyer base includes:

  • UK central government departments and agencies
  • Local authorities (councils) across England, Wales, Scotland, and Northern Ireland
  • NHS bodies including trusts, CCGs, and integrated care systems
  • Police forces and emergency services
  • Higher and further education institutions
  • Housing associations and other public-funded bodies

The UK government has an explicit target to award 33% of direct spend with SMEs, making G-Cloud particularly attractive for small and medium-sized suppliers who might otherwise struggle to access public sector contracts. The Direct Award mechanism — which allows buyers to select a supplier without a mini-competition for services within the framework — strongly favors well-documented, clearly priced services.

Suppliers who should consider G-Cloud listing include:

  • SaaS providers whose software serves use cases common in the public sector (case management, document management, HR, finance, citizen services)
  • IaaS and PaaS providers seeking to serve government hosting requirements
  • Managed service and cloud support providers helping government agencies migrate to or manage cloud environments
  • Niche specialist software providers with small market footprints that benefit from the reach of the Digital Marketplace

With over 6,000 suppliers and tens of thousands of services listed, the Digital Marketplace is a significant catalog. Standing out requires well-written service descriptions, clear pricing, and relevant certifications prominently displayed.

The Three Service Lots Explained

Lot 1 — Cloud Hosting Covers Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and related managed hosting services. Examples include virtual machine services, container hosting, object storage, database-as-a-service, and managed Kubernetes. Buyers use Lot 1 to find hosting for government applications, data processing infrastructure, and development environments.

Lot 2 — Cloud Software The largest lot by number of services. Covers Software as a Service (SaaS) across virtually every software category used in the public sector: productivity tools, collaboration platforms, financial management, HR systems, case management, CRM, analytics, security operations, and specialist vertical software. Lot 2 services must be cloud-native or cloud-hosted; on-premise software is not eligible.

Lot 3 — Cloud Support Covers professional services relating to cloud adoption and management: cloud strategy consulting, migration services, implementation and integration, training and adoption support, quality assurance and testing, service management, and cloud security advisory. Lot 3 services must be specifically in support of cloud services; general IT consulting is not eligible.

Service Listing Requirements

Each service listed on G-Cloud must be described through a standardized set of attributes that buyers use to evaluate and compare services. Key requirements include:

Service Description and Pricing A clear, accurate description of the service including what it does, who it is for, and what is and is not included. Pricing must be transparent, expressed on a per-unit or per-user basis, and published on the Digital Marketplace without requiring a sales conversation. The pricing model must be cloud-appropriate (consumption-based or subscription-based).

Data Handling and Security Suppliers must disclose how data is handled, protected, and stored. This includes data center locations and jurisdictions (UK-based, EU-based, or other), data encryption in transit and at rest, access controls and user authentication, data portability and export capabilities, and compliance with UK GDPR and the Data Protection Act 2018. Government buyers are particularly sensitive to data sovereignty — where data physically resides and which legal jurisdiction applies.

Security Characteristics Suppliers must complete a standardized security questionnaire covering network architecture, access management, personnel security, operational security, and incident management. Holding Cyber Essentials or Cyber Essentials Plus certification is not mandatory but is expected by most public sector buyers and should be prominently declared. ISO 27001 certification is similarly valued. Services handling personal data or sensitive government information may face additional scrutiny.

Data Center and Infrastructure Disclosure Specific disclosure of data center locations by country and cloud region, physical security arrangements, resilience and redundancy architecture, and the identity of any sub-processors or infrastructure partners.

Business Continuity and Backup How service continuity is maintained during failures, backup frequency and retention periods, recovery time objectives, and the process for restoring service following an outage.

SLAs and Support Commitments Service availability commitments (typically expressed as a percentage), performance metrics, support hours and response times, and the escalation path for service issues. Public sector buyers expect SLAs to be specific and enforceable.

The Application and Award Process

Supplier Application During a G-Cloud application window, suppliers apply through the Digital Marketplace. The application requires completion of a supplier declaration (company details, financial standing, insurance, GDPR compliance, modern slavery obligations) and service definitions for each service to be listed. Services are reviewed against eligibility criteria and published upon acceptance.

Buyer Procurement Public sector buyers search the Digital Marketplace by lot, category, and other attributes. For services within the direct award financial threshold (currently set by the procuring authority, typically under the Public Contracts Regulations threshold), buyers can directly award a contract without a competitive process. Above threshold, buyers run a mini-competition among listed suppliers in the relevant lot.

Contract Award G-Cloud uses standardized call-off terms developed by CCS. Buyers complete a call-off contract referencing the framework terms, the service definition, and any buyer-specific requirements. The call-off process is typically much faster than conventional procurement — days or weeks rather than months.

Framework Refresh G-Cloud is refreshed approximately annually. Existing suppliers must reapply for each new framework iteration to remain listed. New service categories and eligibility requirements may be introduced with each refresh, requiring suppliers to review and update their service definitions.

Costs and Timeline

ActivityTypical CostTimeline
Service definition writing (per service)$1,000 – $5,0001–2 weeks per service
Security questionnaire completion$500 – $2,0001 week
Cyber Essentials certification (recommended)$300 – $8001–2 weeks
ISO 27001 preparation (if not held)$20,000 – $80,0006–18 months
Overall application preparation$5,000 – $15,0004–8 weeks
Annual framework renewal$2,000 – $5,0002–4 weeks
G-Cloud listing feeFreeN/A

The primary investment is time — well-crafted service definitions require genuine effort to describe the service clearly, accurately, and in terms that public sector buyers will understand and trust.

PSN CoCo (related, not overlapping): The Public Services Network Code of Connection is required for organizations connecting to the PSN, the government network used for secure data sharing. G-Cloud services that need to connect to or integrate with PSN-connected systems may require their supplier to hold a PSN CoCo compliance certificate. See the PSN CoCo guide.

ISO 27001 (30% overlap): ISO 27001 certification is not mandatory for G-Cloud listing but is expected by most public sector buyers for services handling sensitive data. The G-Cloud security questionnaire covers many ISO 27001 domains; certified suppliers complete it more efficiently and credibly. Certification provides a recognized, third-party-validated signal of security maturity.

Cyber Essentials (40% overlap): The UK government's own baseline cybersecurity scheme. Cyber Essentials (basic self-assessment) or Cyber Essentials Plus (independent assessment) certification is expected for most G-Cloud services and is mandatory for services handling certain types of government personal data. Certification costs as little as £300–£500 and typically takes 1–2 weeks, making it an excellent early investment for any supplier targeting the UK public sector.

How Automation Helps

Maintaining G-Cloud listing across multiple services, keeping compliance documentation current, and responding to buyer security questionnaires during procurement requires organized compliance management. LowerPlane supports multi-framework compliance programs including the UK security frameworks relevant to G-Cloud buyers — Cyber Essentials, ISO 27001, and UK GDPR — with evidence management and audit-ready documentation from $4,000 per year with a free tier. AuditXYZ users rate it 9.4/10. See best compliance automation platforms for a full comparison.

Frequently Asked Questions

How often is G-Cloud refreshed and what does this mean for existing suppliers? G-Cloud is refreshed approximately annually, typically with a new numbered iteration (G-Cloud 14, G-Cloud 15, etc.). Existing suppliers must reapply during the application window for each new iteration to continue appearing on the Digital Marketplace. Services listed on a previous iteration remain available during the transition but buyers' preference shifts to the current framework. Missing an application window means waiting until the next iteration.

Can non-UK companies list on G-Cloud? Yes. G-Cloud is open to suppliers of all nationalities, provided they can meet the framework's legal and compliance requirements — including UK GDPR compliance, UK insurance requirements, and the ability to enter contracts governed by English law. Many international technology companies list on G-Cloud to access the UK public sector market. Data residency is a key consideration: many public sector buyers prefer or require data to be held in the UK or EEA.

Is there a minimum contract value on G-Cloud? No minimum. G-Cloud supports low-value transactions as well as high-value contracts. Many public sector bodies use it for relatively small software subscriptions and individual service purchases. The lack of a minimum contract value, combined with the direct award mechanism, makes G-Cloud efficient for small, routine cloud purchases.

What certifications give the most competitive advantage on G-Cloud? Cyber Essentials Plus provides the strongest signal for most buyers — it is the UK government's own scheme and signals basic security hygiene. ISO 27001 certification is particularly valued for services handling sensitive data. UK GDPR accountability documentation (Records of Processing Activities, Data Protection Impact Assessments) demonstrates data protection compliance. For services targeting NHS buyers, DCB0129 and DCB0160 clinical safety standards may also be relevant.

How do buyers typically choose between similar services on G-Cloud? Buyers generally look for clear, accurate service descriptions that match their use case; transparent, competitive pricing; security certifications (Cyber Essentials, ISO 27001); references from comparable public sector organizations; and clear data residency and protection commitments. Services with vague descriptions, opaque pricing, or absent certifications are typically passed over in favor of better-documented alternatives, even when the underlying product may be equivalent.

Request a G-Cloud consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

Cyber EssentialsLow40%
ISO 27001Low30%

Get matched with a G-Cloud auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.