Skip to main content

Help us improve the Digital Marketplace - send your feedback

ROADMAPPING TECHNOLOGY LIMITED

Nuclear Enterprise Innovation Management Software

Accolade SaaS enables effective management of the full innovation lifecycle to ensure execution remains aligned with strategic objectives, supported by nuclear-level governance.

Programme and project portfolios are optimised to maximise value and minimise risk based on available resources, resulting in better informed decision-making at all levels.

Features

  • Provides Governance, Assurance and Sanction Control for the Nuclear Industry
  • Enables faster and better‑informed decisions at all organisational levels
  • Ensures continual alignment of strategy with execution
  • Optimises portfolios across the enterprise
  • Manages the full innovation process
  • Creates real‑time dashboards to improve decision integrity
  • Manages gated processes and workflow to accelerate delivery
  • Produces intuitive roadmaps for medium‑ and long‑term planning
  • Incorporates best practices for Nuclear and Energy sectors
  • Data classification up to Official Sensitive(OS) and Sensitive Nuclear Information(SNI)

Benefits

  • More effective decisions to promote, pause or retire projects
  • Improved efficiency and enhanced benefit realisation tracking
  • Assurance that activities consistently support enterprise objectives
  • Maximised value within financial and resource constraints
  • Increased decision integrity through a single source of truth
  • Stronger governance through managed process decisions at every stage
  • Continuous alignment of R&D with development and strategic objectives
  • Adaptability to organisational and role changes
  • Clearer communication through stakeholder specific roadmap views
  • Seamless collaboration through Microsoft 365 and Teams integration

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at jon.holdback@roadmappingtechnology.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 2 6 5 0 2 3 2 5 1 3 4 0 2 8

Contact

ROADMAPPING TECHNOLOGY LIMITED Jon Holdback
Telephone: 01494 616006
Email: jon.holdback@roadmappingtechnology.com

About your service

Service categories

Application Development and Deployment

AI platforms

  • Search and knowledge discovery
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
Please see our Service Definition document for details of technical requirements
System requirements
  • Modern networked device / PC
  • Browser as defined in specifications section
  • Sufficient network bandwidth to access services

User support

Email or online ticketing support
Yes
Support response times
Operational questions are answered within 2 to 24 hours dependent on agreed criticality.
Standard support is provided form 9:00 to 17:00 on Monday to Friday excluding public holidays. Other options can be arranged as required.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Standard technical support is included in the SaaS license fees. Support can be arranged outside normal support hours at an additional cost. Additional support may be required to enable new features to be configured to clients needs. Support charges are based on our standard daily rates in the pricing document
A technical account manager is assigned to each client and is responsible for the level of client satisfaction.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
On-site training workshops are carried out with classes of up to 12 attendees run by one of our training consultants. Typically 1 day
"Train the trainer" sessions are encouraged so that ongoing training can be done in-house for new users.
On-line training is also available and may be more suitable if attendees are geographically dispersed.
User documentation is accessible from within the system.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Roadmapping Technology can provide extracts of the data in a variety of formats from an entire backup of the SQL database to an export format to be agreed with the customer, including but not limited to XML, CSV and ODF formats. Self-service reports can be used directly by the customer to extract data at any time limited only by the security profile of the user.
End-of-contract process
Roadmapping Technology will provide a copy of the client's data in a suitable format free of charge, or the client can extract this at any time.

If the client wishes we can also provide additional help and guidance to assist in moving this data to a new environment. This will be charged on our normal time and materials basis.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Interface layout optimised for mobile platforms with option to run desktop version as required
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
Specific user account role setting to allow Process Design rights
Accessibility standards
WCAG 2.2 A
Accessibility testing
Accolade’s Web API conforms to the Richardson Maturity Model Level 2. It is implemented with ASP.Net Web API 2.2 with attribute routing, and follows OData v3 conventions. JSON is the media type that is supported for request and response payloads.
API
Yes
What users can and can't do using the API
Accolade provides a fully functional web API covering a comprehensive set of functionality allowing efficient management of data and enabling interfacing to external data sources. There is also an Integration Engine which enables easy integration with most common applications.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Accolade provides a comprehensive configuration layer allowing it to be tailored to the individual business use cases of each customer. This configuration approach is far better than customisation as it does not involve modifying any of the core product components.
Trained users can customise the configuration, but only when they are given appropriate access rights. Alternatively, many customers consider it more efficient to use our resources to make changes.

Scaling

Independence of resources
Environments are scoped with the customer during initial planning phases and are tested against specification during the implementation phases. Any subsequent changes to the customers usage requirements are scoped as required and changes in the provision of service are scheduled with the customer. Environments are additionally monitored allowing for any anomalies to be identified and investigated. Environments are highly scalable allowing for the largest of implementations.

Analytics

Service usage metrics
Yes
Metrics types
Usage metrics are captured at application, hosting environment and support system levels and can be reported on by defining a set of required metrics with the customer
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Wellspring for application software and Claritas Solutions for cloud hosting

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Comprehensive self-service reporting, including online report and chart creation, custom report creation, style templates and intelligent extract fields, and integration with Microsoft Office documents to create 'smart' documents driven from Accolade data. Extensive API allows expert users to create their own bespoke exports as required.
Data export formats
  • CSV
  • Other
Other data export formats
  • XML
  • PDF
  • JPG
  • PNG
  • TXT
  • DOCX
  • XLSX
  • PPTX
  • Any additional formats required via the API
Data import formats
  • CSV
  • Other
Other data import formats
  • XML
  • PDF
  • JPG
  • PNG
  • TXT
  • DOCX
  • XLSX
  • PPTX
  • Any additional data formats via the API

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection between networks
We understand that some clients’ data requires specific protection and as such where required "alternative security products" can be installed within the environment.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)

Availability and resilience

Guaranteed availability
99.95%. Excludes planned and emergency maintenance.
Approach to resilience
We only use “Tier 3” data centres, which are considered the gold standard for cloud storage. A Tier 3 (or Level 3) data centre is a location with redundant and dual-powered servers, storage, network links, and other IT components. It is one of the most commonly used data centre tiers, where IT components are powered with multiple, active and independent sources of power and cooling resources.

For Private Cloud a number of options enable you to build resilience into your applications. We offer Private Cloud Compute from two geographically distinct sites, both located in the UK and separated by over 100km for excellent geo-diversity.
Outage reporting
A public dashboard - both bespoke and standard is available
An API - porting data into the clients' SIEM product
Email alerts - alerting specific individuals or groups
SMS - message to defined individuals within the organisation

Outages are identified as Planned maintenance, Emergency maintenance, and platform issues. In addition, the designated Technical Account Manager will proactively contact customers as appropriate.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
For the management of the environment will always authenticate the identity of the user by validating known phone numbers and asking them for specific characters within their pre-agreed memorable word.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
Information security policies and processes
Development, implementation, support and hosting services are implemented according to the information security controls defined in the ISO/IEC 27001 standard
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
We operate our change and config management service in line with the ITIL 4.0 Approach. All CIs, are recorded and monitored through their lifecycle via our ITSM tooling so that all changes made to a particular CI can be tracked, seen and understood within the context of the full environment.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We have a documented vulnerability management policy and process, which have been implemented, maintained and assessed in accordance with the guidance from ITIL v.3 and the current ISO20000 and ISO27001 standards.

We run continual vulnerability scanning across the environment, ensuring that if any vulnerabilities are identified that they cannot be leveraged from the outside world,

Patching takes place on a weekly basis, however, if urgent or critical patches are released they will be issued outside of the weekly cycle.

We monitor and are subscribed to a variety of channels in order to monitor current and emerging threats.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We work with a partner to deliver an independent monitoring solution, ensuring that they give an independent view of what is going on within the environment.

Monitoring tools are deployed across the environment and monitored on a 24/7/365 basis.

Response times can be built to the client's specific SLAs but we would usually expect to be responding to a security incident within the first few minutes of a compromise being identified.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We have a documented incident management policy and process, which have been implemented, maintained and assessed in accordance with the guidance from ITIL v.3 and the current ISO20000 and ISO27001 standards.

Users may report incidents in a variety of ways (phone/email or integration into your organisation's ITSM tool).

Depending on the severity of the incident, reports will be provided in a variety of ways. General user interaction will be provided directly. High priority incidents (P1) will have a report produced and issued to client management.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Amtivo Group Limited
ISO/IEC 27001 accreditation date
Friday 13 June 2025
What the ISO/IEC 27001 doesn’t cover
Business functions not associated with hosted services
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
F04a7c0f-1028-4c99-8225-757b026e4c3d
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at jon.holdback@roadmappingtechnology.com. Tell them what format you need. It will help if you say what assistive technology you use.