Commercial Playbook & Guidance · explained by eSourcing Data
The Digital, Data and Technology Playbook: what it requires, explained
The government playbook for sourcing digital, data and technology: 11 key policies, six priorities, legacy IT rules and what version 2 adds on AI.
Source document: The Digital, Data and Technology Playbook (June 2023)
The key facts
- Published in June 2023 as version 2, the playbook applies to all new DDaT projects and is mandated for central government departments and arm's length bodies on a comply or explain basis.
- The wider public sector is expected to take it into account, and compliance is driven through governance, Cabinet Office controls for projects over 20 million per transaction and the Treasury approvals process.
- The public sector was estimated to spend up to 46 billion on digital in 2022/23.
- The playbook contains 12 chapters, 11 key policies and six cross-cutting priorities, structured around the commercial lifecycle from preparation and planning to contract end.
- Key policies include publishing commercial pipelines a minimum of 18 months ahead, delivery model assessments with a Should Cost Model, cyber security assessment against the NCSC Cyber Assessment Framework, and resolution planning information from critical suppliers.
- All software should be kept up to date and in mainstream support for the duration of the contract, with early exit planning to prevent future legacy IT.
- Legacy IT is defined as systems and their component software and hardware outside vendor support, on extended support or on bespoke support arrangements.
- Version 2 adds new and refreshed content on innovation, agile delivery, AI and machine learning, cyber security, sustainability and intellectual property rights.
What the DDaT Playbook is and who must follow it
The Digital, Data and Technology Playbook is the government's guidance on sourcing and contracting for digital, data and technology projects and programmes. Published by the Cabinet Office in June 2023 as the second iteration, it follows the Sourcing, Consultancy and Construction Playbooks and shares their common backbone of key policies, adapted for the DDaT sector. With public sector digital spend estimated at up to 46 billion in 2022/23, its stated purpose is getting things right from the start, since early investment in setup is repaid many times over by avoiding costly mistakes later.
The playbook applies to all new DDaT projects. It is mandated for central government departments and arm's length bodies on a comply or explain basis, and the wider public sector is expected to take it into account. For central government, compliance is driven through departmental governance, central Cabinet Office controls for projects over 20 million per transaction, and the Treasury approvals process. It sits alongside the Green Book, the Five-Case Business Model and the Orange Book, and covers everything from online public services and large transactional business systems to back office systems and core infrastructure.
The 11 key policies
The playbook is built on a spine of 11 key policies. In preparation and planning: contracting authorities should publish commercial pipelines with sufficient detail a minimum of 18 months ahead, and ideally three to five years, so suppliers can prepare for demand; they should assess the health and capability of the market early, covering skills, capacity, barriers to entry and concentration; and they should run proportionate, evidence-based delivery model assessments to choose the right mix of insourcing and outsourcing, producing a Should Cost Model to understand whole life cost and value.
On security and resilience: projects must apply a robust and appropriate level of cyber security assessment during selection, informed by the NCSC's Cyber Assessment Framework, and embed those expectations into contracts. Suppliers of critical DDaT contracts are now required to provide resolution planning information, so government is prepared for the continuity risk posed by the insolvency of critical suppliers. The economic and financial standing of bidders is assessed at selection, including on frameworks for non-critical contracts, with ongoing financial monitoring informing risk management through the life of the project.
On delivery and contracting: where a service is delivered in a new way, authorities should test and learn through iteration; contracts should be structured to drive collaboration, allocate risk appropriately and align pricing and payment mechanisms with desired behaviours and outcomes; software should be open source where possible, with data shared through APIs conforming to Central Digital and Data Office technical and data standards and the Technology Code of Practice; all software should be kept up to date and in mainstream support for the contract duration, with early planning for contract end; and products and services should comply with environmental, economic and social sustainability obligations.
Six cross-cutting priorities
Six priorities flow through every chapter. First, an outcome-based approach: focusing on outcomes for the public rather than specific solutions, using agile ways of working to test, iterate and improve. Second, avoiding and remediating legacy IT, which the playbook defines as systems and their component software and hardware outside vendor support, on extended support or on bespoke support arrangements, and describes as a burden with significant impact on cyber and national security, operational resilience and value for money.
Third, cyber security that is secure by design, with departments assessing resilience against the appropriate government profile under the NCSC Cyber Assessment Framework in line with GovAssure and the Government Cyber Security Policy Framework. Fourth, enabling innovation as a means to better outcomes, tied closely to risk appetite. Fifth, driving sustainability by using public buying power, building on the Social Value model. Sixth, levelling the playing field for SMEs and voluntary, community and social enterprises, which the playbook credits with leading much of the sector's innovation.
What version 2 adds: AI, cloud and the mixed model
Version 2 refreshes the playbook for a fast moving sector, with new and refined content on innovation, agile delivery, AI and machine learning, cyber security, sustainability and intellectual property rights. It also signals a strategic shift: moving away from procuring big projects towards products and services architected and owned in house and continuously improved, with government acting as service integrator and using market expertise to supplement agile teams.
The AI guidance is notably practical. Buyers should be clear whether they are procuring the model, the algorithm or the data set, since value, intellectual property and post-award management differ for each. AI is increasingly embedded in services that are not sold as AI, so market engagement should establish whether it sits in the service or supply chain, and generative AI's plausible but probabilistic output demands awareness of bias. The playbook also connects cloud models to market health, mapping how SaaS, PaaS and IaaS each open routes for SMEs to serve government. A procurement reform note flags that the Procurement Bill, then before Parliament, would expand pipeline publication duties and remove barriers for SMEs such as demands for audited accounts and contract-specific insurance before award.
How eSourcing Data helps
Several of the playbook's policies are, in practice, demands on procurement infrastructure. Publishing meaningful commercial pipelines, advertising opportunities, evidencing evaluation and keeping records through the commercial lifecycle all require systems rather than spreadsheets. eSourcing Data gives contracting authorities a single platform where pipeline planning, notices, evaluation and contract records live together, with the audit trail that comply or explain regimes and approval gates expect.
The playbook's emphasis on supplier relationships and financial standing maps directly onto the platform's supplier management capability: supplier information, performance records and contract data held in one place support both selection decisions and the ongoing monitoring the playbook calls for during delivery.
For the wider public sector bodies expected to take the playbook into account, proportionality matters. eSourcing Data supports below-threshold workflows alongside major procurements, so smaller authorities can apply the same disciplines of transparent pipelines, structured evaluation and documented decisions at a scale that fits their programmes, without overclaiming: the strategic choices the playbook demands remain with the buyer, but the evidence behind them can be systematised.
What to do about it
- 1Publish and maintain a commercial pipeline for DDaT work looking at least 18 months ahead, and ideally three to five years.
- 2Run a market health and capability assessment early in preparation and planning, sized to the procurement.
- 3Complete a delivery model assessment with a Should Cost Model before committing to insourcing, outsourcing or a mixed model.
- 4Build cyber security assessment against the NCSC Cyber Assessment Framework into selection and embed the expectations in the contract.
- 5Contract for currency: require software to stay in mainstream support for the contract term and plan exit and transition from the start.
- 6Check whether AI sits anywhere in the service or supply chain, and be explicit about whether you are buying the model, the algorithm or the data set.
- 7Require resolution planning information from suppliers of critical DDaT contracts and keep monitoring their financial standing.
Put this into practice on the platform
eSourcing Data runs compliant notices, evaluation, supplier management and audit trails out of the box, so meeting this guidance is the workflow, not extra work.
This explainer summarises and interprets an official document for general information; it is not legal advice. Contains public sector information licensed under the Open Government Licence v3.0. Nothing here implies endorsement of eSourcing Data by any government body.
