EntServ UK Ltd part of the DXC Technologies Group

DXC Technology Platform as a Service (SAP)

DXC Platform as a Service for SAP is a consumption-based service available on virtual private or public clouds that supports the full SAP IT stack (infrastructure through the application layer). It leverages the latest in automation to provide faster delivery of SAP services and flexibility to respond to workload changes.


  • Provides full stack of managed cloud services for SAP applications
  • Scale up/scale down and provisioning of SAP resources
  • "always on” capability that meets critical SAP business application requirements
  • Enterprise-class support included as standard at all service level agreements
  • Built upon industry standards (IT4IT, ITIL3)
  • A consumption-based managed cloud service
  • Dedicated and shared instances in the UK and the EU
  • Resilience options available


  • Lower total cost of ownership
  • Highly secure, enterprise-class managed PaaS
  • Minimises capital outlays, increases efficiency and productivity
  • Flexible, consumption-based cloud model; lower infrastructure support costs
  • Scales up/down to meet your demand in a cost-effective manner
  • Reduce time to perform common SAP application operational processes
  • providing on-demand high availability service with superior operational security


£839 per virtual machine per month

Service documents

G-Cloud 10


EntServ UK Ltd part of the DXC Technologies Group

DXC Frameworks Team

+44 (0)560 303 4826


Service scope

Service scope
Service constraints No
System requirements Disclosed upon application

User support

User support
Email or online ticketing support Email or online ticketing
Support response times Based on criticality, immediate for P1 issues.
User can manage status and priority of support tickets Yes
Online ticketing support accessibility None or don’t know
Phone support Yes
Phone support availability 24 hours, 7 days a week
Web chat support No
Onsite support Yes, at extra cost
Support levels DXC will provide enterprise level support.
Support available to third parties Yes

Onboarding and offboarding

Onboarding and offboarding
Getting started DXC will provide a comprehensive package of technology and account support to help new customers onboard to the service.
Service documentation Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction Users can recover their data via the WAN or by export to removable hard drive.
End-of-contract process DXC provide notice of impending end of contract period. User can then recover data by a variety of means. DXC close services at end of contract, data is retained post contract until user confirms data has been recovered, all storage is then wiped using Mil Std processes.

Using the service

Using the service
Web browser interface Yes
Using the web interface Users and Service Managers can access a full range of provisioning and service management and monitoring capabilities.
Web interface accessibility standard None or don’t know
How the web interface is accessible Disclosed upon application.
Web interface accessibility testing Disclosed upon application.
Command line interface No


Scaling available Yes
Scaling type Manual
Independence of resources Constraints are in place to ensure resources are not over-exploited by individual users. Dedicated resources can be selected where required.
Usage notifications Yes
Usage reporting Email


Infrastructure or application metrics Yes
Metrics types
  • CPU
  • Disk
  • Memory
  • Network
  • Number of active instances
Reporting types
  • Regular reports
  • Reports on request


Supplier type Not a reseller

Staff security

Staff security
Staff security clearance Conforms to BS7858:2012
Government security clearance Up to Security Clearance (SC)

Asset protection

Asset protection
Knowledge of data storage and processing locations Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • EU-US Privacy Shield agreement locations
User control over data storage and processing locations Yes
Datacentre security standards Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency At least once a year
Penetration testing approach ‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v3.0
  • Encryption of all physical media
Data sanitisation process Yes
Data sanitisation type Explicit overwriting of storage before reallocation
Equipment disposal approach Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Backup and recovery

Backup and recovery
Backup and recovery Yes
What’s backed up
  • Databases
  • Directories
  • Files
  • Virtual machines
Backup controls The user interface permits selection of files and directories for backup and the schedule for backup (daily, weekly etc)
Datacentre setup Multiple datacentres with disaster recovery
Scheduling backups Users schedule backups through a web interface
Backup recovery Users can recover backups themselves, for example through a web interface

Data-in-transit protection

Data-in-transit protection
Data protection between buyer and supplier networks TLS (version 1.2 or above)
Data protection within supplier network TLS (version 1.2 or above)

Availability and resilience

Availability and resilience
Guaranteed availability Resilience configurations offering server availability up to 99.999% are available.
Approach to resilience DXC offers a range of standard single and dual DC resilience configurations to provide users with a range of resilience SLAs.
Outage reporting Depending on criticality outage reporting may be via email or phone.

Identity and authentication

Identity and authentication
User authentication Public key authentication (including by TLS client certificate)
Access restrictions in management interfaces and support channels Management access is from a dedicated network via two levels of authentication. Device level controls ensure management access is restricted to control functions and excludes for instance access to client data.
Access restriction testing frequency At least once a year
Management access authentication Public key authentication (including by TLS client certificate)
Devices users manage the service through Dedicated device on a segregated network (providers own provision)

Audit information for users

Audit information for users
Access to user activity audit information Users receive audit information on a regular basis
How long user audit data is stored for At least 12 months
Access to supplier activity audit information Users receive audit information on a regular basis
How long supplier audit data is stored for At least 12 months
How long system logs are stored for At least 12 months

Standards and certifications

Standards and certifications
ISO/IEC 27001 certification Yes
Who accredited the ISO/IEC 27001 BSI
ISO/IEC 27001 accreditation date 23/09/2015
What the ISO/IEC 27001 doesn’t cover N/A
ISO 28000:2007 certification No
CSA STAR certification Yes
CSA STAR accreditation date 29/11/2016
CSA STAR certification level Level 3: CSA STAR Certification
What the CSA STAR doesn’t cover N/A
PCI certification No
Other security certifications Yes
Any other security certifications
  • FedRAMP

Security governance

Security governance
Named board-level person responsible for service security Yes
Security governance certified Yes
Security governance standards ISO/IEC 27001
Information security policies and processes DXC information security policies and processes are accredited to ISO 27001 and comply with National Laws and Industry Policies where applicable.

Operational security

Operational security
Configuration and change management standard Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Configuration and change management approach Configuration and Change Management conducted to ITIL Standards.
Vulnerability management type Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach Vulnerability and Patch Management are delivered in line with specific policies which are verified as part of the CSA Star and ISO27001 certifications.
Protective monitoring type Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach Protective Monitoring is provided in line with GPG13 requirements.
Incident management type Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach Incident Management follows documented Security Incident Management Policies and Process which are verified as part of the ISO27001 and CSA Star Certifications.

Secure development

Secure development
Approach to secure software development best practice Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Separation between users

Separation between users
Virtualisation technology used to keep applications and users sharing the same infrastructure apart Yes
Who implements virtualisation Supplier
Virtualisation technologies used VMware
How shared infrastructure is kept separate Disclosed upon application.

Energy efficiency

Energy efficiency
Energy-efficient datacentres Yes


Price £839 per virtual machine per month
Discount for educational organisations No
Free trial available No


Pricing document View uploaded document
Skills Framework for the Information Age rate card View uploaded document
Service definition document View uploaded document
Terms and conditions document View uploaded document
Return to top ↑