CCS Vertical Application Solutions (RM6259) Application Support
A Crown Commercial Service framework for sector specific software applications and associated services for the public sector. It supports specialised line of business systems across government. Application vendors should apply for inclusion.
How Glaxtons wins CCS Vertical Application Solutions (RM6259) places
What CCS Vertical Application Solutions (RM6259) actually is
RM6259 is the Crown Commercial Service route for buying sector specific software applications and the services that surround them. Where a general cloud agreement handles commodity hosting and horizontal software, this category covers line of business systems built for a particular public sector function: case management, licensing, revenues and benefits, clinical and care systems, court and justice applications, education management, transport and highways systems and similar specialised platforms, together with implementation, integration, data migration and ongoing support.
Purchases are made by call-off from the agreement. Depending on the framework terms and the requirement, a buyer runs a further competition among appointed suppliers in the relevant category or makes a direct award against published catalogue terms where the specification is standard and the terms permit it. Because vertical applications tend to be long lived and expensive to replace, call-offs commonly bundle licensing, implementation, integration and multi year support into a single contract, which raises both the value and the evidential burden on the bidder.
Category and lot arrangements on technology agreements are revised frequently, and the boundary between this agreement and other CCS technology routes moves with each iteration. Do not build a go to market plan on a remembered lot structure. Check the current Crown Commercial Service agreement page for RM6259 and the contract notice on Find a Tender, which together set out the scope, the categories, the term, any extension options and which bodies are entitled to use it.
Who buys through it
Buyers are the organisations that run statutory services on specialised systems: local authorities running revenues, benefits, social care, planning and licensing; NHS bodies procuring clinical, patient administration and care coordination systems; police, fire and justice bodies buying case and incident management; central government departments running regulatory, grant or casework functions; and education, housing and transport bodies with sector specific platforms. Eligibility is defined in the contract notice on Find a Tender, which is the authoritative source if you need to confirm a particular buyer can use the route.
What they buy is rarely software alone. A typical requirement covers licences or subscription, configuration to the buyer's statutory process, integration with existing systems through defined interfaces, migration of live data from a legacy platform, training, and a support and development arrangement running for several years. Many competitions are replacements of ageing systems where the incumbent holds the data, so migration approach, cutover planning and the risk of service interruption during a statutory process carry as much weight in evaluation as product functionality.
How suppliers get on it
Appointment is by open competition advertised on Find a Tender and run through the Crown Commercial Service e-sourcing portal. There is a selection stage covering financial standing, exclusion grounds, insurance and technical capacity, and a technical stage covering the categories you are bidding, security, service management and pricing. Under the Procurement Act 2023 some agreements are established as open frameworks that reopen at defined points, so a closed competition may not be the end of the matter. Register for Find a Tender alerts against the agreement reference and monitor preliminary market engagement notices.
Security and assurance evidence is the long pole. Expect to need Cyber Essentials and, for most meaningful scope, Cyber Essentials Plus, and in practice ISO 27001 or a demonstrably equivalent information security management system. For anything touching health or care data, add the NHS Data Security and Protection Toolkit, the Digital Technology Assessment Criteria and, where the product influences clinical decisions, clinical safety documentation under DCB0129 with a named clinical safety officer. Accessibility conformance to WCAG at the level required by the Public Sector Bodies Accessibility Regulations 2018 is a hard requirement for citizen facing interfaces.
Then assemble the commercial and contractual evidence: your standard licensing and subscription model expressed in a form that maps to the framework pricing schedule, your position on data ownership, exit and portability, service levels with credits, and your approach to change control on a multi year support contract. Public buyers are alert to lock in after a decade of difficult legacy exits, so an exit and data extraction commitment stated plainly is a genuine advantage. If you want help translating a commercial product model into framework compliant pricing, call 020 3668 5488.
What actually scores
Evaluators score fit to the public sector process, not feature count. A response that lists modules scores poorly. A response that shows how the product handles the statutory workflow, the reporting the buyer must return to a regulator or department, the retention and disposal rules that apply to that record type, and the audit trail an inspector would ask for, scores well. Demonstrate that you understand the legislation the system serves, because buyers assume a supplier who does not mention it has not built for it.
Implementation and migration credibility is where bids are won and lost. Buyers have been burned by overrun replacements of live statutory systems. They look for a phased plan with named roles, a data migration method covering profiling, cleansing, mapping, dry runs and reconciliation, a cutover plan with a rollback position, and evidence that you have done this before on a comparable dataset. Give durations, team composition and the client side effort required. A plan that assumes unrealistically light client involvement reads as inexperience and is marked down.
Security, data protection and accessibility are pass or fail in effect. Weak answers assert compliance. Strong answers give the certification, the scope statement of that certification, the hosting arrangement and data location, the position on subprocessors, how a data protection impact assessment is supported, penetration testing frequency and how findings are remediated, and an accessibility statement with a current audit and a plan for any non conformance. Where a control is not in place, saying so with a dated remediation plan scores better than a claim that does not survive the clarification round.
Support, roadmap and exit determine the long term score. Evaluators want service levels defined by severity with realistic response and resolution targets, a named escalation route, transparent roadmap governance including how public sector clients influence priorities, and a clear statement of what happens at the end: data returned in a documented format, assistance with transition to a successor supplier, and no charge structure that makes leaving impractical. Suppliers lose marks by treating exit as a contractual formality rather than answering it as an operational question.
Before you apply
- Cyber Essentials Plus, and ISO 27001 or a documented equivalent, with a scope statement covering the bid entity.
- An accessibility audit against the current WCAG level required, plus a published accessibility statement.
- Two or three comparable implementations with dates, data volumes, migration approach and referees who will confirm them.
- A pricing model that maps cleanly to a framework schedule, including licensing, implementation and multi year support.
- Documented exit and data portability terms you are willing to be held to for the life of a call-off.
CCS Vertical Application Solutions (RM6259) questions
How does this differ from a general cloud purchasing route?
A general cloud route is designed for commodity hosting, horizontal software and associated support, usually bought from a catalogue with light competition. A vertical applications route exists for sector specific line of business systems where the requirement is bound up with statutory process, integration and migration from an incumbent platform. The boundary between the two shifts as agreements are reissued, so confirm the current scope on the Crown Commercial Service pages rather than relying on an earlier understanding.
Do I need NHS specific assurance to bid?
Only if you are bidding scope that touches health or care data. Where you are, expect the Data Security and Protection Toolkit and the Digital Technology Assessment Criteria to be required, and clinical safety documentation under the applicable DCB standards where the product supports clinical decision making, including a named clinical safety officer. If you are bidding only non health categories, those requirements do not apply, but the general security and accessibility requirements still do.
Is a reseller or implementation partner eligible?
Agreements of this kind generally accommodate both software owners and partners who implement and support third party products, but the evidence expected differs and the framework documents set out how you must describe the relationship. If you rely on a vendor's product, expect questions about your authorisation, your access to product roadmap and escalation, and what happens to the client if the vendor relationship ends. Confirm eligibility rules in the current tender documents before committing bid effort.
How important is the pricing schedule at application stage?
It matters more than most software suppliers expect. The schedule usually sets ceiling rates and structures that govern later call-offs, and further competitions frequently weigh price alongside quality. Submitting a model built only around your largest deals leaves you uncompetitive on smaller authorities, while pitching low across the board erodes margin for years. Model the schedule against a realistic spread of buyer sizes and implementation complexity before you commit to it.
What most often costs suppliers marks in this category?
Answering as a product vendor rather than as a delivery partner. Buyers are replacing systems that run statutory services and cannot fail, so they mark implementation method, migration evidence, resourcing and exit at least as heavily as functionality. The second common loss is asserting security and accessibility compliance without the certification scope, audit dates and remediation detail behind it. For a structured review before submission, call 020 3668 5488.
Win Your Place on CCS Vertical Application Solutions (RM6259)
Competitive fixed fees. 93% win rate. Same-day response from a Glaxtons specialist.