Managed Payment Services - Chargepoint Infrastructure
SolnetEV (CPMS) is an advanced platform for EV charge point operators, offering secure, compliant management of chargers. CPMS features a direct payment module and integrates with multiple payment providers, enabling efficient transaction processing, real-time tracking, reporting, and seamless revenue management, while ensuring uptime, control, and a superior driver experience.
Features
- Centralised charge point monitoring and control
- UK regulatory compliance and security
Benefits
- Reduces downtime and costs through real-time remote charge point management
- Ensures regulatory compliance, security, trust, and confidence for all users
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 2 9 5 3 3 5 5 7 8 7 9 0 9 9
Contact
SOLNET
Syed Kazmi
Telephone: 01438419889
Email: info@solnetiot.com
About the service
- Service categories
-
Applications
Enterprise resource management
Financial
- Financial and Accounting Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- Support is limited to approved hardware configurations, and service availability may be affected during planned maintenance windows.
- System requirements
-
- Internet connectivity, supported EV chargers, secure cloud access, web browser
- Compatible hardware, stable power supply, SIM or ethernet networking required
User support
- Email or online ticketing support
- Yes
- Support response times
-
We respond within one business day.
Weekend responses may take up to two business days. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We have tested web chat functionality with assistive technology users, including screen reader and keyboard-only users, to ensure accessibility, clear navigation, and effective communication in line with accessibility best practices.
- Onsite support
- Yes
- Support levels
-
Support levels provided
Standard Support
Business-hours email and ticketing support, issue tracking, and updates.
Enhanced Support
Priority response, extended hours support, proactive monitoring, and incident management.
Premium Support
24/7 support, fastest response times, proactive system reviews, and escalation management.
Costs
Support costs vary by level and contract size and are provided on request.
Account management
Enhanced and Premium levels include access to a technical account manager or cloud support engineer. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- We support users in getting started through a combination of online training, comprehensive user documentation, and step-by-step setup guides. For larger deployments, we also offer onsite training sessions to help administrators and operators configure charge points, understand dashboards, and efficiently manage the service from day one.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At the end of a contract, users can extract their data through secure export tools in the web interface or via the API. Data can be downloaded in standard formats (e.g., CSV, JSON) to ensure continuity, reporting, and migration to another system before the contract terminates.
- End-of-contract process
-
End of Contract:
At the end of the contract, users retain access to their data for export, after which service access is deactivated. Any custom modules or features are removed unless a renewal or new contract is agreed.
Included in Price:
Access to the charge point management platform
Standard support and software updates
Use of approved charge point modules
Additional Costs:
Onsite training or extended support packages
Custom development or advanced integrations
Hardware upgrades or replacements beyond standard supported models - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The mobile and desktop services offer the same core functionality, but with differences in interface and access:
Mobile: Optimized for touch screens, on-the-go monitoring, push notifications, and quick updates.
Desktop: Full dashboard view, advanced reporting, bulk management tools, and detailed analytics for in-depth operational control. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Yes, our service includes a web-based interface that allows charge point operators to monitor, manage, and control EV chargers, access reports, configure settings, and view real-time usage data. It is accessible via desktop and mobile devices for convenient, secure management.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have conducted interface testing to ensure WCAG 2.2 AA compliance with users of assistive technology. This included testing with screen readers, keyboard-only navigation, and voice control tools to verify that all buttons, menus, forms, and notifications are accessible, clearly labeled, and fully operable without a mouse.
- API
- Yes
- What users can and can't do using the API
-
API Capabilities and Limitations
What users can do:
Set up the service: Users can register new charge points, configure site details, and link accounts via the API.
Make changes: Users can update charge point settings, manage availability schedules, monitor usage data, and trigger remote diagnostics or resets.
Limitations:
Certain advanced features, such as firmware upgrades or hardware-specific configurations, can only be performed through the web interface.
Changes are restricted to supported hardware models and may be limited by user permissions.
Some bulk operations may have rate limits to ensure system stability. - API documentation
- Yes
- API documentation formats
-
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Ustomisation of Service
What can be customised: Users can add management modules, configure charge point settings, adjust reporting dashboards, and tailor notifications.
How users can customise: Customisation is performed through the web interface or API, allowing selection and configuration of modules, scheduling preferences, and user roles.
Who can customise: Only authorised administrators or account managers can make customisations to ensure security and compliance.
Scaling
- Independence of resources
- We guarantee users aren’t affected by others’ demand through rigorous stress testing. Our platform has been tested in multi-million user environments and under high-demand scenarios to ensure consistent performance, reliable uptime, and fast response times, even when multiple users are accessing or managing charge points simultaneously.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Users can export performance metrics as part of their data, including KPIs for charger uptime, connectivity, service performance, and overall reliability. Metrics are accessible via the web interface or API, downloadable in standard formats (CSV/JSON) for reporting, analysis, or integration with other systems.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export their data using the web interface or the API. Data can be downloaded in standard formats such as CSV or JSON, allowing easy integration with other systems, reporting, or backup. Exports can include usage logs, transaction history, and configuration settings, with filters for date ranges or specific charge points.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- XML
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We guarantee 99.9% platform availability under normal operating conditions, backed by our Service Level Agreement (SLA). If availability falls below this threshold, users are eligible for service credits or refunds, calculated proportionally to the downtime experienced, ensuring accountability and maintaining trust in our service reliability.
- Approach to resilience
-
Our service’s resilience strategy is built around industry best practices and proven architecture principles:
• Redundancy & Diversity
Critical components (compute, storage, network) exist in multiple independent instances to ensure failures in one do not impact overall service.
We architect for failure — components can fail without impacting live service availability.
• Isolation & Separation
Production, staging, and disaster recovery environments are logically and physically separated to reduce cross-environment impact and risk.
• Scalability & Elasticity
Services automatically scale to handle load spikes, helping maintain performance during traffic surges or degraded conditions.
• Data Protection
Data is replicated securely across locations; backups are maintained and regularly validated to ensure periodic restores are possible. - Outage reporting
-
Outage Reporting
Our service provides clear and timely outage reporting through automated monitoring and customer communication channels, ensuring transparency and rapid awareness of any service disruption.
The platform is continuously monitored using automated health checks across core services, APIs, and infrastructure components. When an issue is detected, alerts are generated in real time, incidents are logged, and severity levels are assigned to support prompt investigation and resolution.
A public service status dashboard is available to provide real-time visibility of overall platform availability, active incidents, and planned maintenance. Historical incident information is also retained to support transparency and service assurance. Where required, more detailed technical information can be made available on request.
Service status information can also be accessed via an API, allowing customers or partners to integrate outage and availability data into their own monitoring or reporting systems. The API is secured and rate-limited to ensure reliability and data protection.
In addition, email alerts are sent to nominated contacts for confirmed outages, significant service degradation, planned maintenance, and incident resolution updates. Communication is maintained throughout an incident, and post-incident summaries can be provided following major outages.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Other
- Other user authentication
- Access to the service is secured using OpenID Connect (OIDC) integrated with Microsoft Entra ID (Azure AD). Users authenticate via their Entra credentials, supporting single sign-on (SSO) and strong identity verification. Authentication tokens are issued by Entra and validated by the service before granting access. Role-based access controls ensure users can only access appropriate functionality and data. All authentication processes follow industry best practices, including token expiration, revocation, and encrypted transmission over TLS 1.3 to protect credentials and session integrity.
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is strictly controlled using role-based access controls (RBAC). Users are assigned roles with the minimum privileges required for their responsibilities. Administrative interfaces require multi-factor authentication (MFA) and are accessible only from approved devices or networks. Support channels are authenticated and monitored, with access limited to authorised personnel. All access attempts are logged and reviewed regularly. Changes to roles, privileges, or support access are subject to formal approval and periodic audit to ensure compliance with security policies and ISO/IEC 27001 standards.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Other
- Description of management access authentication
- Access to the service is secured using OpenID Connect (OIDC) integrated with Microsoft Entra ID (Azure AD). Users authenticate via their Entra credentials, supporting single sign-on (SSO) and strong identity verification. Authentication tokens are issued by Entra and validated by the service before granting access. Role-based access controls ensure users can only access appropriate functionality and data. All authentication processes follow industry best practices, including token expiration, revocation, and encrypted transmission over TLS 1.3 to protect credentials and session integrity.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Our organisation fully complies with ISO/IEC 27001 and operates a formal Information Security Management System (ISMS) covering people, processes, and technology. The ISMS is approved by senior management and is designed to protect the confidentiality, integrity, and availability of information assets.
We maintain a comprehensive suite of documented information security policies aligned with ISO 27001 Annex A controls. These include policies for risk management, access control, asset management, cryptography, secure development, incident management, business continuity, supplier security, and data protection. Policies are version-controlled, communicated to relevant staff, and reviewed regularly or following significant change.
Responsibility for information security sits with senior management and is supported by a designated Information Security Officer. Security risks, incidents, audit results, and compliance metrics are reported through defined management reporting lines and reviewed as part of formal management reviews.
Compliance with policies is ensured through mandatory staff security awareness and role-based training, least-privilege access controls, continuous monitoring and logging, and regular risk assessments. Internal audits are conducted to verify adherence to ISO 27001 requirements, and corrective actions are tracked to completion. Security incidents are formally recorded, investigated, and used to drive continual improvement of the ISMS. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- We operate formal configuration and change management processes aligned with ISO/IEC 27001. All service components are recorded in a central configuration management repository and tracked throughout their lifecycle, from deployment through change and retirement. Changes are requested, assessed, approved, implemented, and reviewed using a controlled change process. Each change is evaluated for potential security impact, including risks to confidentiality, integrity, and availability. Security reviews, testing, and rollback plans are required for material changes, ensuring service stability and ongoing compliance.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We operate a formal vulnerability management process aligned with ISO/IEC 27001. Potential threats are identified through vulnerability scanning, risk assessments, penetration testing, and code reviews. Vulnerabilities are assessed based on severity, exploitability, and impact, with remediation prioritised accordingly. Critical vulnerabilities are patched as a priority, typically within hours or days, while other issues follow defined timelines. Threat intelligence is sourced from vendor advisories, CVE databases, security bulletins, and automated security monitoring tools.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We operate continuous protective monitoring aligned with ISO/IEC 27001 to detect and respond to potential security compromises. Logs and system events are collected from all critical services and analysed for anomalies, suspicious activity, and policy violations. Potential compromises trigger automated alerts and are escalated to the security team for immediate investigation. Incidents are assessed, contained, and remediated according to severity, with critical events responded to within hours. Lessons learned are documented and fed back into our monitoring and incident response processes to strengthen ongoing security.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate a formal incident management process aligned with ISO/IEC 27001. Pre-defined procedures exist for common incidents, including system outages, security events, and data breaches. Users can report incidents via a dedicated support portal, email, or telephone, which are logged and tracked in our incident management system. Each incident is assessed, prioritised, and investigated promptly. Incident reports, including cause, impact, resolution, and lessons learned, are provided to affected users and stakeholders. Post-incident reviews inform continuous improvement of processes and controls.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- The free version provides basic EV charger management, mobile and web access, and charging history. Advanced features, analytics, automated scheduling, and priority support are not included. The service is available indefinitely.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0.5%
- Between £500,001 and £1,000,000
- 0.75%
- Between £1,000,001 and £2,500,000
- 1%
- Between £2,500,001 and £5,000,000
- 1.25%
- Over £5,000,001
- 1.5%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- Alcumus ISOQAR Limited
- ISO/IEC 27001 accreditation date
- Friday 7 November 2025
- What the ISO/IEC 27001 doesn’t cover
- The ISMS covers all operational, technical, and support processes related to the delivery of our services
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- Alcumus ISOQAR Limited
- ISO 9001 accreditation date
- Friday 7 November 2025
- What the ISO 9001 doesn’t cover
- The ISMS covers all operational, technical, and support processes related to the delivery of our services
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- B6010d24-d0f6-45a4-9a3c-7898d0c60133
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Creation of outreach activities to create a pipeline of employees for the future contract delivery