Government
Government on infrastructure you own
Public sector data stays in UK jurisdiction. Procurement requirements are met by architecture, not by exemption. Audit trails are built in because they have to be.
UK public sector organisations operate under specific data residency requirements, procurement frameworks, and security baselines that many commercial infrastructure options were not designed to satisfy. G-Cloud and the Digital Marketplace exist precisely because standard commercial procurement routes do not work for public bodies. The infrastructure underneath needs to match.
The regulatory weight
The frameworks that govern public sector IT procurement and security are specific and current:
Cyber Essentials and Cyber Essentials Plus
NCSC-backed certification scheme. CE is mandatory for central government contracts involving handling personal data or providing certain technical products or services. CE Plus (with independent assessment) is required for higher-assurance contracts. Genitco's Cyber Essentials certification is in preparation; we design infrastructure that supports client CE/CE Plus compliance.
G-Cloud framework (currently G-Cloud 14)
The Crown Commercial Service procurement route for cloud-based services. Public bodies buying cloud infrastructure through G-Cloud require suppliers to be listed.
NCSC Cloud Security Principles
14 principles covering data-in-transit protection, asset protection, separation between users, governance framework, operational security, personnel security, and others. Public sector deployments are assessed against these.
NIS2 Directive
Applicable to public sector entities meeting scope thresholds. Incident reporting obligations, risk management requirements, and supply chain security requirements apply from October 2024.
We document how our architecture addresses the NCSC Cloud Security Principles as part of every public-sector engagement, from the start of the build rather than retrofitted afterwards.
Why sovereignty matters specifically here
Public procurement has a data residency obligation that is increasingly explicit. Government Security Classifications require that SECRET and above data is processed on infrastructure accredited for that classification, but even OFFICIAL data has residency expectations in many contracts. Infrastructure on US-headquartered hyperscalers is subject to US law, including potential law enforcement access under CLOUD Act provisions. That is a material consideration for public bodies handling sensitive constituent data.
Three practical issues arise. A public sector organisation using a hyperscaler for document management and collaboration may not have assessed whether that infrastructure meets the data residency requirements in its contracts. An AI deployment that processes data from internal systems creates a supply chain security question: who else can access the model and the data it processes? A digital service that depends on external uptime creates a resilience exposure that NCSC guidance requires to be documented and mitigated.
Public sector organisations are also subject to Freedom of Information and audit by the National Audit Office, the Cabinet Office, and their own internal audit functions. The audit trail that satisfies those requirements needs to live somewhere you fully control.
Three typical engagements
G-Cloud-ready deployments
Architecture and deployment of infrastructure that meets G-Cloud framework requirements, NCSC Cloud Security Principles, and UK data residency obligations. Designed to be listed under G-Cloud service lots for reuse across public sector buyers.
Public sector AI with audit trail
Self-hosted AI deployment for internal government workflows: document processing, policy research, citizen communication support. Full audit trail built in. No data transits external infrastructure. Built to G-Cloud and NCSC Cloud Security Principle requirements.
Procurement-ready architecture review
Assessment of current infrastructure against G-Cloud, Cyber Essentials, and NCSC Cloud Security Principle requirements ahead of a procurement exercise or contract renewal. Documented gap analysis and remediation plan.
Proof
Case studies in this sector are in preparation. Work in this area is ongoing; we will publish when client permission is confirmed.
Start here
Fixed scope. Fixed price. No day rates. We will map your current infrastructure against relevant government security frameworks on a 30-minute call and tell you exactly what the work involves.
Book a scoping call