Skip to main content

Help us improve the Digital Marketplace - send your feedback

R.T.A. ASSOCIATES LIMITED

RTA OrderPro

RTA OrderPro is a hosted managed service for the creation and updating of a geodatabase for all types of Digital Traffic Regulation Orders (D-TRO's), all via a secure portal. Bolt on modules provide a cohesive suite of online services to manage DTROs end to end. A DTRO one stop shop.

Features

  • Managed service for D-TRO, D-MTO, off-street orders & Non TRO's
  • Interactive portals for easy data transfer and requests for change
  • Bespoke public consultation module. Bespoke public portal for current orders
  • Remedial works packages for procuring contractors
  • Remote access 24/7 supporting flexible working patterns and home workers
  • Cyber Essentials Plus certified and off site disaster recovery
  • Continual improvement by facilitating onsite reporting of remedial issues
  • Fully digitised TRO and MTO review module to TSRGD standards
  • 12 month rolling contract. No excessive tie in period
  • Human professional help desk, personal support during office hours

Benefits

  • Links to DfT D-TRO hub and National Parking Platform
  • Improves efficiencies and transparency within the client offices
  • Suite of online services to manage DTROs end to end.
  • Real time updates for CEOs, Admin and PCN processing teams
  • Provides professionally produced plans for consultation and order making
  • Reduced resource demand at client base. DTRO one stop shop.
  • Minimal training required. Simple system to understand and use.
  • Cost effective solution to help alleviate budget concerns
  • Helps to ensure conformity to relevant current national legislation
  • Unlimited licenced users and robust business continuity guaranteed

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at plowe@rtaassociates.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 6 5 5 3 4 9 7 3 9 5 8 2 2 5

Contact

R.T.A. ASSOCIATES LIMITED Peter Lowe
Telephone: 07900264137
Email: plowe@rtaassociates.co.uk

About your service

Service categories

Application Development and Deployment

Data management

Database administration and development

  • Database Administration
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
This is a managed service which does not require firewalls. Client retains responsibility for their entire website function and RTAA do not have any access to client IT systems. RTAA creates and maintains the geodatabase and the client uses as necessary. The service can update the client corporate GIS. Client chooses how the data is made public and in what format. The service simply builds, stores and manages all the background TRO and non TRO data to ensure consistency, transparency, professional outputs and a robust methodology. No constraints on size of data. GDPR issues are held within the clients configurations.
System requirements
  • Internet web browser
  • Authority to use client OS data licence

User support

Email or online ticketing support
Yes
Support response times
Mon to Friday, office hours 9am to 5pm. Initial response within 1 hour if total loss of service. Otherwise initial response within 3 hours.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Tier 0 Self- Service option via online help documentation. Included in the annual price

Tier 1 Basic help desk resolution & service desk delivery provided by RTAA. Included in the annual price

Tier 2 In-depth technical support provided by RTAA. Regarding RTA OrderPro only, Included in the annual price

Tier 3 Expert product and service support provided by RTAA. Regarding RTA OrderPro only, Included in the annual price

Tier 4 Outside support for problems not supported by RTAA. Costs to be agreed upfront with the client if external to RTA OrderPro.
Support available to third parties
No

Onboarding and offboarding

Getting started
Online training combined with documentation and verbal assistance as necessary. It is a simple to use service and can be taught in 20 minutes. No on site training required
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
Open format using the clients corporate GIS.
End-of-contract data extraction
The GIS data is provided at the end of the contract in whatever format the client requests (eg .shp or .tab). The latest accessible pdfs of the mapped tiles for their current legal orders are provided as well.
End-of-contract process
At the end of the contract the price includes for a full release of the clients data to the client in the format they choose to suit their corporate GIS system.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Mobile (field module): Focused on data capture and submission. On-site users can upload text-based observations, photographs and supporting information directly from site for review. Submissions are streamlined for touch input and variable connectivity, enabling quick capture and upload while working in the field.

Desktop (management portal): Provides the full management interface for review, approval and actioning of submissions. Desktop users access the complete dataset, reporting tools, approval workflows and configuration options not required by field users.

The mobile module complements the desktop service by enabling efficient on-site data collection, while approvals, processing and administrative actions are handled through the desktop.
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
Yes — OrderPro provides a web-based service interface.

*Users access the service through a secure web browser interface

*Includes a desktop management interface and a mobile-optimised field interface

*No local installation or specialist client software is required
Accessibility standards
WCAG 2.2 A
Accessibility testing
Interface testing was carried out through a structured beta-testing process with real users. Participants were guided through defined usability scenarios and asked to provide feedback on navigation, layout and accessibility.

Testing included use of built-in assistive technologies such as keyboard-only navigation, screen zoom, colour contrast tools and screen readers. Feedback was captured centrally, reviewed, and used to make iterative improvements to the user interface and form controls prior to wider release.
API
Yes
What users can and can't do using the API
The API provides read-only access to OrderPro data for authorised council clients. Users can set up access by requesting API credentials, which are issued and scoped to their organisation’s data.

Through the API, users can retrieve text-based mapping data and apply filters (for example by location or order type) in JSON or CSV format. Users cannot create, modify or delete data through the API, and cannot change service configuration or workflows. All data management, approvals and updates are performed through the web interface.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Yes. Limited customisation is available.

Buyers can customise branding elements within specific parts of the service, such as the public consultation module and council-facing pages. This includes use of council logos, colour schemes and council-specific wording.

Customisation is requested by authorised council administrators and applied by the supplier to ensure consistency, accessibility and security standards are maintained. Core service functionality, workflows and data structures are not customisable.

Scaling

Independence of resources
The virtual machine is hosted by Microsoft Azure. Resource of the system is monitored and automatic scaling is in place if required. We ask any customers who is having a problem to report it to us so we can investigate further.
Volume of work is dealt with by having a flexible workforce who can increase their hours as necessary, to suit their work life balance. The main demand is on setting up new clients which is controllable and negotiable with the Client. Once the service is up and running, updating a client will be covered under normal working practices.

Analytics

Service usage metrics
Yes
Metrics types
The service provides basic service usage metrics to buyers on request. Metrics include the number of registered users, user activity levels, and volumes of submitted and completed work packages. These metrics are intended to support operational oversight and service assurance rather than detailed analytics.
Reporting types
Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Data at rest is protected through platform-level encryption and strict access controls. All service data is encrypted at rest, including databases, file storage and backups. Physical access to storage media is managed by the cloud hosting provider through controlled data centre access and security monitoring aligned to recognised industry standards.

Logical access to stored data is restricted using role-based access controls. These measures are supported by Cyber Essentials Plus and Cyber Assurance-aligned controls to ensure appropriate protection of stored data.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Data Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users export their data through a built-in reporting and export tool within the OrderPro web interface. Authorised council users can filter live restriction data (for example by restriction type or location) using on-screen controls and view the results in an interactive table. The filtered dataset can then be exported directly using a dedicated export function. Exports are generated from the live dataset held within OrderPro and require no additional software or licences.
Data export formats
  • CSV
  • Other
Other data export formats
XLSX
Data import formats
  • ODF
  • Other
Other data import formats
  • PDF
  • Docx

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Within the hosting environment, different service components (for example the web application, application services and databases) are placed on separate internal network segments so they are not directly accessible from the internet. Communication between these components is restricted to required ports only and is encrypted using TLS.

For example, when the OrderPro application retrieves data from the database or GeoServer, the connection occurs over a private internal network using encrypted service-to-service communication, preventing unauthorised interception or lateral access.

Availability and resilience

Guaranteed availability
The service is designed to deliver 99.9% availability, measured on a monthly basis. Availability is monitored by the supplier as part of normal service operations.

Planned maintenance is excluded from availability calculations and is scheduled outside normal working hours where possible, with advance notice provided to users. Any service interruptions are investigated and addressed in line with the supplier’s incident management and service management processes.
Approach to resilience
The service is designed with resilience built into the hosting architecture. OrderPro is hosted on Microsoft Azure, using a production environment with redundancy and regular backups. A mirrored server is maintained and can be deployed in an alternative Azure region in the event of a major outage, allowing service restoration within approximately one hour.

Data is protected through frequent backups and off-site storage, and the hosting platform provides resilient datacentre facilities with power, cooling and physical security controls.
Outage reporting
Service outages are reported to users via email notifications. Where an outage or service degradation is identified, affected users are informed as soon as reasonably practicable, with follow-up updates provided if required.

The service does not currently provide a public status dashboard or outage reporting API.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using role-based access controls (RBAC). Council staff are granted access based on their role and responsibilities, ensuring they can only view or manage functions relevant to their position.

Administrative and support access is limited to authorised personnel and protected through authenticated user accounts. Access rights are reviewed periodically and adjusted when roles change or access is no longer required, in line with access control policies.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus
Cyber Assurance ISMS
Information security policies and processes
RTAA follows a documented set of information security policies covering areas such as access control, data protection, secure configuration, incident management, backup and business continuity. Overall accountability sits with the board, with day-to-day security oversight managed by the CISO (Chief Information Security Officer), who reports directly to the directors.

Policies are communicated to staff and contractors, supported by training and onboarding, and are required to be followed as part of normal working practices. Compliance is monitored through periodic reviews, risk assessments and security testing, with issues escalated through the defined reporting structure.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration and change management is governed by documented policies aligned to our Cyber Assurance controls. Service components are tracked through their lifecycle using asset and configuration records, covering deployment, change and retirement.

All changes are assessed prior to implementation for operational and security impact, including potential risks to data, availability and compliance. Changes are reviewed by the CISO and approved by senior management where required. Approved changes are implemented in a controlled manner and recorded, with outcomes fed back into risk and security reviews where relevant.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerability management is carried out using a risk-based approach. Potential threats are identified through regular vulnerability scanning, penetration testing and review of system configurations. Information on emerging threats is obtained from trusted sources including vendor security advisories, government guidance and industry alerts.

Identified vulnerabilities are assessed for impact and likelihood, prioritised accordingly, and remediated in line with risk. Security patches are deployed promptly, with critical updates applied as soon as practicable following testing, and all actions are recorded and reviewed as part of ongoing risk management.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is used to identify potential security compromises through review of system alerts, logs and monitoring outputs. Suspicious activity or indicators of compromise are reported immediately and assessed for severity and impact.

When a potential compromise is identified, the incident response process is initiated without delay, following defined procedures for containment, eradication and recovery. Incidents are prioritised based on risk, with critical incidents responded to as soon as practicable. Actions, communications and outcomes are documented, and post-incident reviews are carried out to improve controls and prevent recurrence.
Incident management type
Supplier-defined controls
Incident management approach
Incident management is handled through documented processes aligned to our Cyber Assurance controls. Pre-defined procedures exist for common security and service incidents, including assessment, containment, eradication and recovery.

Users report incidents via established support channels, including email and service contacts. Incidents are logged, prioritised by severity and managed by the incident response team. Where appropriate, incident updates and reports are provided to affected users, and post-incident reviews are carried out to identify lessons learned and improve controls.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
A test environment will be made available for a period of 4 weeks for Highway Authorities to assess suitablity to their needs.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
E1463144-c0f2-48fa-984e-29e6414ff388
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
IASME Cyber Assurance - 4ffda734-170f-4c39-8e26-7849414b919d

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at plowe@rtaassociates.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.