Public Sector · QA
Testing, security and quality assurance.
Test scenarios from real use, regression, acceptance testing, plus security from permissions to audit trails.
When public bodies bring us in
- you're preparing a tender and need a supplier
- the project needs several disciplines at once
- an existing system needs extending or connecting
- a procedure needs digitalising from application to decision
- long-term support after handover is required
What this means for the contracting authority
- Traceability for every step of the procedure.
- Documentation that matches the tender requirements.
- One accountable partner even with several vendors.
- Acceptance testing against pre-agreed criteria.
- Support and development after handover.
Problem → solution
What we cover
- test plan and scenarios
- regression testing
- acceptance testing
- permissions and roles
- audit trails
- encryption and data retention
- a security review before launch
Testing before acceptance
Testing on a public project is not the last step before launch but a workstream of its own, with written scenarios and known criteria. Every important scenario has a defined input, an expected output, behaviour in edge cases and a condition under which it is accepted.
- functional testing against scenarios derived from the requirements
- regression testing on every release
- integration testing, including failure scenarios
- accessibility testing
- performance testing where it is a requirement
- a security review before go-live
- user acceptance testing with key users
- a defect log with severity and status
Security requirements
We treat security requirements as measurable requirements, not as a principle. Authentication, access rights, the audit trail, encryption, secret handling, dependency updates, backups and a tested restore are part of the design and part of acceptance.
- login, single sign-on and two-factor authentication where required
- role-based permissions and separation of duties
- an audit trail of access and changes
- environment hardening and access control
- vulnerability management and security updates
- backups, restore and a plan for outages
For deeper reviews we can bring cybersecurity specialists from the wider network into the project - for security architecture, penetration testing, vulnerability management, identity management and incident response.
Testing is not a phase before handover
When testing happens only at the end, faults are found when fixing them costs most and the deadline can no longer move. So testing runs alongside development, and the acceptance test confirms rather than discovers.
- automated tests for rules that must not break
- testing on the devices and browsers the client actually uses
- accessibility testing with a keyboard and screen reader
- a load test before a peak period
- an acceptance test against pre-agreed cases
Security you can demonstrate
Security requirements in tenders are often generic. In practice it helps to break them into things that can be checked and recorded.
- role-based access and revocation on departure
- encryption in transit and at rest for sensitive data
- a log of access to personal data
- keys and passwords managed outside the source code
- regular dependency updates
- a procedure for a security incident
How we run a public project
Requirements
Tender and technical requirements are translated into a delivery plan with milestones and responsibilities.
Project management
One contact, regular progress reporting and subcontractor coordination in one place.
Quality and security
Test scenarios, a security review and compliance with the client's requirements before acceptance.
Documentation
Technical and user documentation, instructions and training material.
Acceptance and SLA
Acceptance testing, handover and support with agreed response times.
Related work
FAQ
Do you help prepare tender documentation?
We can contribute to the technical part and clarifications, within public procurement rules.
Who manages the subcontractors?
We do. The client has one contact and one progress report.
What does post-handover support include?
Agreed response times, defect resolution and enhancements as agreed.
Related solutions
Sounds like your project?
Send us the project description, your existing system, the tender documents or the event date.