Skip to main content

Help us improve the Digital Marketplace - send your feedback

Power Framework

Power Framework PPM

Power Framework PPM uses Microsoft cloud services to deliver full capability for Project Portfolio Management. Built in the Microsoft Power Platform, it delivers collaboration, integration and automation for your PMO. It has full reporting and dashboards through Power BI, and Artificial Intelligence features supporting new ways of working in PPM.

Features

  • Supports full project life cycle, from idea to benefits realisation
  • Comprehensive financial controls at portfolio, programme and project level
  • Resource demand and capacity planning
  • Portfolio modelling capability to perform 'what if' analysis
  • Connects to most planning tools like Planner, Jira, DevOps, MS_Project
  • Manage risks, issues, benefits, variations, lessons learned
  • Rich reporting out of the box with Power BI
  • Easily create your own reports using data model provided
  • Automate approvals, alerts and integrations
  • Intregated AI features

Benefits

  • Provides visibility and governance across all your portfolios and teams
  • Inspires collaborative working through Microsoft Teams integration
  • Efficient Demand Management, Portfolio governance, Risk & Issue Management
  • Improved governance for both agile and traditional waterfall projects
  • Drives process maturity and efficient working
  • Supports pragmatic adoption of AI for PPM
  • Supports executive decision making and consistent project success

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gero.renker@programframework.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 5 6 2 4 7 5 8 1 7 1 2 0 6 2

Contact

Power Framework Gero Renker
Telephone: 020 39347205
Email: gero.renker@programframework.com

About your service

Service categories

Applications

Enterprise resource management

  • Project and portfolio management
Multi cloud support
No

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
Microsoft Power Apps
Cloud deployment model
Public cloud
Service constraints
None
System requirements
  • Power Apps
  • Power BI
  • Power Automate
  • Azure infrastructure
  • Optionally integrates with Teams, Planner, MS_Project, Jira, &others

User support

Email or online ticketing support
Yes
Support response times
Response to a support request on the online helpdesk system occurs within 30 minutes with an email reply with a ticket number.

Response times during normal business hours:

Severity 1 - Major functionality loss impacting many or all users - 4 business hours

Severity 2 - Minor functionality loss impacting few or no users - 16 business hours

Severity 3 - - No functionality loss impacting any users - 4 business days
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
EN 301 549
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We provide a single, comprehensive support level that is fully included with the solution at no additional cost.

Our support offering includes unlimited support requests via our online ticketing system (Zendesk), covering incidents, service requests, configuration queries, and general product guidance. Customers are not restricted by caps on tickets, users, or hours, ensuring predictable costs and consistent access to help when required.

Support is delivered by experienced cloud support engineers with in-depth knowledge of the solution and the Microsoft cloud platform. They provide functional and technical assistance, including troubleshooting, root cause analysis, and advice on best practice usage.

In addition to day-to-day support, each customer is assigned a named Account Manager. The Account Manager acts as the primary point of contact, providing service oversight, coordinating support activities, and supporting ongoing adoption, optimisation, and roadmap alignment. Where appropriate, the Account Manager works closely with our technical team to ensure customer requirements are understood and addressed effectively.

There are no tiered support levels and no additional charges for enhanced support, escalation, or account management. All customers receive the same high level of service as part of the standard solution.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Power Framework PPM provides a ready-to-go, fully functional solution for project and portfolio management. To ensure maximum value, we personalise the solution for your organisation’s processes, terminology, and information requirements.

Deployment Approach:

To start, we provision a dedicated environment for your organisation and enrol prototype users. We walk your core team through the solution, apply the first iteration of personalisation, migrate sample data, and present the prototype to stakeholders to capture feedback. A backlog of further customisation is documented to prepare for live deployment.

Build Up: We develop and test the backlog, covering additional data model customisation, project lifecycle stages, security roles, integrations, and reporting.

Roll Out & Knowledge Transfer: The solution is deployed into your Microsoft cloud tenant. We work with your team to review PPM processes and provide training, including solution administration and project management sessions delivered online. Recorded sessions are provided for reuse.

Adopt & Support: The solution is wrapped into a managed service for ongoing maintenance and user support. Customers are invited to join the Power Framework User Group to share best practice and provide input into the product roadmap.

This approach ensures users can adopt the system quickly while maintaining flexibility for future growth.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
All customer data is stored entirely within the customer’s Microsoft cloud tenant, ensuring that the organisation retains full ownership and control at all times. This design simplifies data extraction at the end of the contract.

When the contract ends, customers can export their data directly from their environment using built-in Microsoft Power Platform tools and standard reporting/export features. This includes:

Exporting tables, records, and project data to Excel, CSV, or other supported formats

Exporting reports and dashboards via Power BI

Accessing document libraries and attachments stored in SharePoint or Dataverse

Using APIs (Dataverse OData/REST) to extract data programmatically if required

We provide guidance and documentation to support customers in performing these exports safely and efficiently. Additionally, our team can assist with end-of-contract data extraction planning, helping identify all data sources and ensuring a smooth handover.

Because the solution is deployed in the customer’s own Microsoft cloud tenant, there is no risk of data lock-in, and the organisation maintains full control over retention, backup, and migration of its data at all times.
End-of-contract process
At the end of the contract, we follow a structured offboarding process to ensure the customer retains full control of their data and can securely close the service. Because the solution is deployed in the customer’s own Microsoft cloud tenant, all data remains under their ownership throughout the contract.

Included in the price is:

Guidance to extract data from the environment using standard platform tools, APIs, and reporting features

Assistance with deletion of the solution environment once data extraction is complete

Advice and instructions for safe handover and continuity of operations

Any assistance beyond standard guidance—such as performing migrations, extensive custom data extraction, or complex transformation activities—is considered out-of-scope and may be billed separately.

This approach ensures customers can confidently conclude the contract, retain all critical information, and securely remove the environment. It balances providing end-of-contract support as part of the standard service while giving organisations flexibility to request additional assistance if needed.
Documentation accessibility standard
EN 301 549

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The desktop service provides the full feature set of the solution, including administration, configuration, reporting, and advanced data management capabilities. It is optimised for larger screens and keyboard-based interaction.

The mobile service is designed to support on-the-go access and focuses on key user tasks such as viewing information, updating records, submitting requests, and responding to notifications. It uses a responsive interface optimised for touch interaction and smaller screens.

While core functionality and data are consistent across platforms, some advanced configuration and reporting features are desktop-only to ensure usability and performance.
Service interface
Yes
User support accessibility
EN 301 549
Description of service interface
The service interface is a web-based user interface delivered using Microsoft Power Apps (model-driven apps). Users access the service through a standard modern web browser on desktop and mobile devices, with no local installation required.
The interface provides role-based access to portfolio management, project data, workflows, dashboards, and reporting. Navigation, forms, and views follow Microsoft’s Fluent UI patterns to ensure consistency and usability.
Administration and configuration are performed through the same secure interface by authorised users, supported by Microsoft Entra ID (Azure AD) authentication.
Accessibility standards
EN 301 549
Accessibility testing
Accessibility is primarily assured through the use of the Microsoft Power Platform, which undergoes extensive accessibility testing by Microsoft in line with EN 301 549 and WCAG 2.1 AA requirements. This includes testing with screen readers, keyboard-only navigation, colour contrast validation, and support for browser-based accessibility tools.
API
Yes
What users can and can't do using the API
The service provides an API through Microsoft Dataverse, which exposes secure, standards-based REST (OData) endpoints for all core data entities used by Power Framework PPM.

Using the API, authorised users and systems can:

Read and write portfolio, programme, project, resource, financial, and risk data

Create, update, and deactivate records

Integrate with external systems using standard authentication via Microsoft Entra ID

Automate setup and operational changes using Power Automate, Azure Logic Apps, or custom applications

Initial service provisioning (environment creation, licensing, and core security configuration) is performed through Microsoft Power Platform administration tools rather than directly via the API. Once provisioned, most functional configuration and data changes can be performed programmatically.

Limitations include:

Platform-level settings and security role definitions are restricted to administrators

Certain configuration elements are managed through the user interface to maintain governance and platform integrity

API usage is subject to Microsoft Power Platform service limits and throttling.
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Customisation and configuration of the service are performed during implementation in collaboration with the customer. Our team works closely with the customer to tailor workflows, forms, dashboards, notifications, and reports to their organisational processes, ensuring the solution meets their needs while maintaining best practice.

The core application and underlying data model are managed and maintained exclusively by us. This approach ensures ongoing supportability, maintainability, and compatibility with future upgrades, protecting the integrity of the platform.

Customers can configure the solution “around” the core application, for example by creating additional integrations, automations via Power Automate, custom Power BI reports, and extensions such as Copilot or other AI-enabled enhancements. These customisations allow organisations to extend the solution to meet specific reporting, automation, or operational needs without altering the underlying platform.

This approach provides a balance between flexibility and control: customers gain tailored functionality and enhanced value from integrations and automations, while we retain the ability to provide reliable, future-proof support and upgrades.

Scaling

Independence of resources
All customer environments are deployed in their own Microsoft cloud tenant, ensuring full isolation from other users. Resources such as storage, compute, and networking are provisioned and managed independently within that tenant, so activity from other organisations cannot impact performance, availability, or data integrity. The service leverages Microsoft’s enterprise-grade cloud infrastructure, including automatic scaling, redundancy, and monitoring, to maintain consistent performance under varying workloads. This design guarantees that each customer experiences reliable access and responsiveness regardless of the demand or usage patterns of other organisations using the platform.

Analytics

Service usage metrics
Yes
Metrics types
We provide service usage metrics through the platform’s reporting and dashboard features. This includes information on user activity, project updates, workflow progress, and system utilisation. Metrics are accessible via built-in dashboards, Power BI reports, and administrative views, enabling organisations to monitor adoption, engagement, and operational performance.
Reporting types
Real-time dashboards
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
All customer data is stored in Microsoft Dataverse, a secure, cloud-based data platform within the customer’s Microsoft cloud tenant. Dataverse provides structured storage for all tables, records, and attachments used by Power Framework PPM, ensuring full ownership and control. Users can export data directly using built-in tools, including table exports to Excel or CSV, Power BI reporting, and programmatic access via Dataverse APIs (OData/REST). We provide guidance and documentation to support these exports. This approach ensures customers can safely and efficiently extract their data in standard formats while maintaining full control over retention and use.
Data export formats
  • CSV
  • Other
Other data export formats
Excel
Data import formats
  • CSV
  • Other
Other data import formats
Excel

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is delivered using the Microsoft Power Platform and Azure, hosted within the customer’s own Microsoft cloud tenant. Availability is underpinned by Microsoft’s enterprise-grade cloud infrastructure, which provides built-in redundancy, monitoring, and resilience.
In the event that availability falls below the guaranteed level, customers may be eligible for service credits in line with Microsoft’s published SLA and service credit process.

Planned maintenance is managed by Microsoft and is communicated in advance where possible. Maintenance activities are designed to minimise disruption and are typically performed outside of core business hours.

This approach ensures customers benefit from a clearly defined, industry-standard availability commitment supported by a hyperscale cloud provider, with transparent remedies if service levels are not met.
Approach to resilience
The service is designed to be resilient by leveraging Microsoft Azure and the Power Platform, deployed within the customer’s own Microsoft cloud tenant. Resilience is provided through Microsoft’s globally distributed datacentre architecture, which includes built-in redundancy across compute, storage, and networking components.

Microsoft Azure datacentres use fault-tolerant infrastructure, automated monitoring, and self-healing capabilities to reduce the risk of service disruption. Data stored in Microsoft Dataverse is replicated within the region to protect against hardware failure, with backup and recovery services managed by Microsoft in line with published service commitments.

The platform supports planned maintenance, patching, and updates without customer intervention, and resilience is continuously tested by Microsoft through operational and security processes.

We complement this platform-level resilience with controlled solution design, release management, and monitoring to ensure stable operation and rapid response to incidents.

Further technical details on datacentre architecture, backup, and disaster recovery are available on request in line with Microsoft’s published security and resilience documentation.
Outage reporting
Service availability and outages are reported through Microsoft platform notifications: Microsoft provides a public service health dashboard via the Microsoft 365 and Azure Service Health portals, which report real-time status, incidents, and planned maintenance affecting Power Platform services. Customers can view current and historical incidents relevant to their tenant.

Microsoft also provides email alerts and notifications to tenant administrators for service incidents, degradation, and maintenance events. Where available, these notifications can be accessed programmatically via Microsoft service health APIs.

Identity and authentication

User authentication needed
Yes
User authentication
Multi-Factor Authentication (MFA)
Access restrictions in management interfaces and support channels
The solution is deployed in the customer’s Microsoft cloud tenant, and access to solution administration and configuration is restricted to authorised administrators and power users using role-based security and Azure Active Directory authentication. Support requests via our Zendesk portal are also restricted to registered users, and internal support staff access is limited based on role.
Access restriction testing frequency
At least once a year
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We follow a structured set of information security policies and processes aligned with industry best practice and the security controls of the Microsoft cloud platform on which the service is delivered.

Our policies cover information security governance, access control, data protection, incident management, change management, supplier management, and business continuity. These policies are reviewed regularly and updated to reflect changes in risk, regulation, and platform capabilities.

Responsibility for information security sits with senior management, with clear accountability for policy ownership, implementation, and oversight. Operational responsibility is supported by defined roles covering service delivery, support, and technical administration.

Policy compliance is ensured through a combination of role-based access controls, documented procedures, staff training, and operational controls. Access to customer environments is restricted to authorised personnel and logged. Changes to the service are managed through controlled release and configuration processes.

We rely on Microsoft Azure and Power Platform security controls, including identity management, logging, monitoring, and threat detection, to enforce security at the infrastructure and platform level. Security incidents are managed through a documented incident response process, with escalation, investigation, and customer communication as required.

This layered approach ensures information security policies are consistently applied, monitored, and enforced across the service.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We operate documented configuration and change management processes aligned to operational security best practice. Service components are tracked throughout their lifecycle using controlled solution versions, environment records, and configuration documentation within the Microsoft Power Platform.

All changes are logged, reviewed, and approved before implementation. Changes are assessed for security, stability, and customer impact, including review of access controls, data handling, and integration points. Where appropriate, changes are developed and tested in non-production environments before release to production.

Core application changes are managed by us to ensure supportability and secure upgrades. Customer-specific configuration is delivered in a controlled and auditable manner.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We operate a proactive vulnerability management process to protect the service. Potential threats are assessed using Microsoft security advisories, CVE databases, and industry reports to evaluate impact and likelihood. Platform-level patches and security updates are applied automatically by Microsoft Azure and Power Platform, while solution-level updates are tested in non-production environments before deployment. Security patches and mitigations are prioritised based on risk to customer data, service availability, and compliance. This process, combined with continuous monitoring and controlled change management, ensures vulnerabilities are identified, assessed, and remediated promptly, maintaining the security and resilience of customer environments.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We operate protective monitoring using Microsoft Azure and Power Platform built-in logging, alerting, and anomaly detection. Potential compromises are identified through automated monitoring of user activity, system events, and unusual behaviour patterns. Alerts are reviewed by our support and operations teams, and suspected incidents are investigated promptly. Confirmed security events are escalated according to documented incident response procedures, with containment, mitigation, and communication actions applied as quickly as possible. We leverage platform-level notifications and our support processes to ensure rapid response, maintaining service integrity and protecting customer data in line with the UK government’s operational security principle.
Incident management type
Supplier-defined controls
Incident management approach
We operate pre-defined incident management processes for common service and security events, aligned with best practice. Users report incidents via our online support portal (Zendesk) or their named Account Manager. All incidents are logged, categorised, and prioritised, with prompt acknowledgement. Because customer data is hosted in the customer’s Microsoft cloud tenant, underlying platform incidents are managed in coordination with Microsoft. Customers receive regular updates and a final incident report detailing resolution, root cause, and recommended follow-up actions. This approach ensures transparency, traceability, and timely resolution while maintaining service continuity and data integrity.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Access to a standard sandbox environment for full evaluation of product features. Access will be provided on request and will be time-limited.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Citation
ISO/IEC 27001 accreditation date
Sunday 17 March 2024
What the ISO/IEC 27001 doesn’t cover
Does not cover infrastructure security, provided by Microsoft under their own ISO/IEC 27001-certified cloud services.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Citation
ISO 9001 accreditation date
Sunday 17 March 2024
What the ISO 9001 doesn’t cover
Not covering:
Underlying cloud infrastructure operations, which are provided by Microsoft.
Datacentre facilities and physical security, operated by Microsoft Azure.
Microsoft platform services (Azure, Power Platform, Dataverse, Entra ID), which are covered by Microsoft’s own ISO 9001 certifications.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
55c08bb8-5caa-4400-9a0b-d4bdcb8e3735
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gero.renker@programframework.com. Tell them what format you need. It will help if you say what assistive technology you use.