RTA OrderPro
RTA OrderPro is a hosted managed service for the creation and updating of a geodatabase for all types of Digital Traffic Regulation Orders (D-TRO's), all via a secure portal. Bolt on modules provide a cohesive suite of online services to manage DTROs end to end. A DTRO one stop shop.
Features
- Managed service for D-TRO, D-MTO, off-street orders & Non TRO's
- Interactive portals for easy data transfer and requests for change
- Bespoke public consultation module. Bespoke public portal for current orders
- Remedial works packages for procuring contractors
- Remote access 24/7 supporting flexible working patterns and home workers
- Cyber Essentials Plus certified and off site disaster recovery
- Continual improvement by facilitating onsite reporting of remedial issues
- Fully digitised TRO and MTO review module to TSRGD standards
- 12 month rolling contract. No excessive tie in period
- Human professional help desk, personal support during office hours
Benefits
- Links to DfT D-TRO hub and National Parking Platform
- Improves efficiencies and transparency within the client offices
- Suite of online services to manage DTROs end to end.
- Real time updates for CEOs, Admin and PCN processing teams
- Provides professionally produced plans for consultation and order making
- Reduced resource demand at client base. DTRO one stop shop.
- Minimal training required. Simple system to understand and use.
- Cost effective solution to help alleviate budget concerns
- Helps to ensure conformity to relevant current national legislation
- Unlimited licenced users and robust business continuity guaranteed
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 6 5 5 3 4 9 7 3 9 5 8 2 2 5
Contact
R.T.A. ASSOCIATES LIMITED
Peter Lowe
Telephone: 07900264137
Email: plowe@rtaassociates.co.uk
About your service
- Service categories
-
Application Development and Deployment
Data management
Database administration and development
- Database Administration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- This is a managed service which does not require firewalls. Client retains responsibility for their entire website function and RTAA do not have any access to client IT systems. RTAA creates and maintains the geodatabase and the client uses as necessary. The service can update the client corporate GIS. Client chooses how the data is made public and in what format. The service simply builds, stores and manages all the background TRO and non TRO data to ensure consistency, transparency, professional outputs and a robust methodology. No constraints on size of data. GDPR issues are held within the clients configurations.
- System requirements
-
- Internet web browser
- Authority to use client OS data licence
User support
- Email or online ticketing support
- Yes
- Support response times
- Mon to Friday, office hours 9am to 5pm. Initial response within 1 hour if total loss of service. Otherwise initial response within 3 hours.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Tier 0 Self- Service option via online help documentation. Included in the annual price
Tier 1 Basic help desk resolution & service desk delivery provided by RTAA. Included in the annual price
Tier 2 In-depth technical support provided by RTAA. Regarding RTA OrderPro only, Included in the annual price
Tier 3 Expert product and service support provided by RTAA. Regarding RTA OrderPro only, Included in the annual price
Tier 4 Outside support for problems not supported by RTAA. Costs to be agreed upfront with the client if external to RTA OrderPro. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Online training combined with documentation and verbal assistance as necessary. It is a simple to use service and can be taught in 20 minutes. No on site training required
- Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Open format using the clients corporate GIS.
- End-of-contract data extraction
- The GIS data is provided at the end of the contract in whatever format the client requests (eg .shp or .tab). The latest accessible pdfs of the mapped tiles for their current legal orders are provided as well.
- End-of-contract process
- At the end of the contract the price includes for a full release of the clients data to the client in the format they choose to suit their corporate GIS system.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Mobile (field module): Focused on data capture and submission. On-site users can upload text-based observations, photographs and supporting information directly from site for review. Submissions are streamlined for touch input and variable connectivity, enabling quick capture and upload while working in the field.
Desktop (management portal): Provides the full management interface for review, approval and actioning of submissions. Desktop users access the complete dataset, reporting tools, approval workflows and configuration options not required by field users.
The mobile module complements the desktop service by enabling efficient on-site data collection, while approvals, processing and administrative actions are handled through the desktop. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
-
Yes — OrderPro provides a web-based service interface.
*Users access the service through a secure web browser interface
*Includes a desktop management interface and a mobile-optimised field interface
*No local installation or specialist client software is required - Accessibility standards
- WCAG 2.2 A
- Accessibility testing
-
Interface testing was carried out through a structured beta-testing process with real users. Participants were guided through defined usability scenarios and asked to provide feedback on navigation, layout and accessibility.
Testing included use of built-in assistive technologies such as keyboard-only navigation, screen zoom, colour contrast tools and screen readers. Feedback was captured centrally, reviewed, and used to make iterative improvements to the user interface and form controls prior to wider release. - API
- Yes
- What users can and can't do using the API
-
The API provides read-only access to OrderPro data for authorised council clients. Users can set up access by requesting API credentials, which are issued and scoped to their organisation’s data.
Through the API, users can retrieve text-based mapping data and apply filters (for example by location or order type) in JSON or CSV format. Users cannot create, modify or delete data through the API, and cannot change service configuration or workflows. All data management, approvals and updates are performed through the web interface. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Yes. Limited customisation is available.
Buyers can customise branding elements within specific parts of the service, such as the public consultation module and council-facing pages. This includes use of council logos, colour schemes and council-specific wording.
Customisation is requested by authorised council administrators and applied by the supplier to ensure consistency, accessibility and security standards are maintained. Core service functionality, workflows and data structures are not customisable.
Scaling
- Independence of resources
-
The virtual machine is hosted by Microsoft Azure. Resource of the system is monitored and automatic scaling is in place if required. We ask any customers who is having a problem to report it to us so we can investigate further.
Volume of work is dealt with by having a flexible workforce who can increase their hours as necessary, to suit their work life balance. The main demand is on setting up new clients which is controllable and negotiable with the Client. Once the service is up and running, updating a client will be covered under normal working practices.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides basic service usage metrics to buyers on request. Metrics include the number of registered users, user activity levels, and volumes of submitted and completed work packages. These metrics are intended to support operational oversight and service assurance rather than detailed analytics.
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
Data at rest is protected through platform-level encryption and strict access controls. All service data is encrypted at rest, including databases, file storage and backups. Physical access to storage media is managed by the cloud hosting provider through controlled data centre access and security monitoring aligned to recognised industry standards.
Logical access to stored data is restricted using role-based access controls. These measures are supported by Cyber Essentials Plus and Cyber Assurance-aligned controls to ensure appropriate protection of stored data. - Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users export their data through a built-in reporting and export tool within the OrderPro web interface. Authorised council users can filter live restriction data (for example by restriction type or location) using on-screen controls and view the results in an interactive table. The filtered dataset can then be exported directly using a dedicated export function. Exports are generated from the live dataset held within OrderPro and require no additional software or licences.
- Data export formats
-
- CSV
- Other
- Other data export formats
- XLSX
- Data import formats
-
- ODF
- Other
- Other data import formats
-
- Docx
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
Within the hosting environment, different service components (for example the web application, application services and databases) are placed on separate internal network segments so they are not directly accessible from the internet. Communication between these components is restricted to required ports only and is encrypted using TLS.
For example, when the OrderPro application retrieves data from the database or GeoServer, the connection occurs over a private internal network using encrypted service-to-service communication, preventing unauthorised interception or lateral access.
Availability and resilience
- Guaranteed availability
-
The service is designed to deliver 99.9% availability, measured on a monthly basis. Availability is monitored by the supplier as part of normal service operations.
Planned maintenance is excluded from availability calculations and is scheduled outside normal working hours where possible, with advance notice provided to users. Any service interruptions are investigated and addressed in line with the supplier’s incident management and service management processes. - Approach to resilience
-
The service is designed with resilience built into the hosting architecture. OrderPro is hosted on Microsoft Azure, using a production environment with redundancy and regular backups. A mirrored server is maintained and can be deployed in an alternative Azure region in the event of a major outage, allowing service restoration within approximately one hour.
Data is protected through frequent backups and off-site storage, and the hosting platform provides resilient datacentre facilities with power, cooling and physical security controls. - Outage reporting
-
Service outages are reported to users via email notifications. Where an outage or service degradation is identified, affected users are informed as soon as reasonably practicable, with follow-up updates provided if required.
The service does not currently provide a public status dashboard or outage reporting API.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is restricted using role-based access controls (RBAC). Council staff are granted access based on their role and responsibilities, ensuring they can only view or manage functions relevant to their position.
Administrative and support access is limited to authorised personnel and protected through authenticated user accounts. Access rights are reviewed periodically and adjusted when roles change or access is no longer required, in line with access control policies. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
-
Cyber Essentials Plus
Cyber Assurance ISMS - Information security policies and processes
-
RTAA follows a documented set of information security policies covering areas such as access control, data protection, secure configuration, incident management, backup and business continuity. Overall accountability sits with the board, with day-to-day security oversight managed by the CISO (Chief Information Security Officer), who reports directly to the directors.
Policies are communicated to staff and contractors, supported by training and onboarding, and are required to be followed as part of normal working practices. Compliance is monitored through periodic reviews, risk assessments and security testing, with issues escalated through the defined reporting structure. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Configuration and change management is governed by documented policies aligned to our Cyber Assurance controls. Service components are tracked through their lifecycle using asset and configuration records, covering deployment, change and retirement.
All changes are assessed prior to implementation for operational and security impact, including potential risks to data, availability and compliance. Changes are reviewed by the CISO and approved by senior management where required. Approved changes are implemented in a controlled manner and recorded, with outcomes fed back into risk and security reviews where relevant. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Vulnerability management is carried out using a risk-based approach. Potential threats are identified through regular vulnerability scanning, penetration testing and review of system configurations. Information on emerging threats is obtained from trusted sources including vendor security advisories, government guidance and industry alerts.
Identified vulnerabilities are assessed for impact and likelihood, prioritised accordingly, and remediated in line with risk. Security patches are deployed promptly, with critical updates applied as soon as practicable following testing, and all actions are recorded and reviewed as part of ongoing risk management. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Protective monitoring is used to identify potential security compromises through review of system alerts, logs and monitoring outputs. Suspicious activity or indicators of compromise are reported immediately and assessed for severity and impact.
When a potential compromise is identified, the incident response process is initiated without delay, following defined procedures for containment, eradication and recovery. Incidents are prioritised based on risk, with critical incidents responded to as soon as practicable. Actions, communications and outcomes are documented, and post-incident reviews are carried out to improve controls and prevent recurrence. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Incident management is handled through documented processes aligned to our Cyber Assurance controls. Pre-defined procedures exist for common security and service incidents, including assessment, containment, eradication and recovery.
Users report incidents via established support channels, including email and service contacts. Incidents are logged, prioritised by severity and managed by the incident response team. Where appropriate, incident updates and reports are provided to affected users, and post-incident reviews are carried out to identify lessons learned and improve controls. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- A test environment will be made available for a period of 4 weeks for Highway Authorities to assess suitablity to their needs.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E1463144-c0f2-48fa-984e-29e6414ff388
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
- IASME Cyber Assurance - 4ffda734-170f-4c39-8e26-7849414b919d
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-