Skip to main content

Help us improve the Digital Marketplace - send your feedback

SOLNET

Managed Payment Services - Chargepoint Infrastructure

SolnetEV (CPMS) is an advanced platform for EV charge point operators, offering secure, compliant management of chargers. CPMS features a direct payment module and integrates with multiple payment providers, enabling efficient transaction processing, real-time tracking, reporting, and seamless revenue management, while ensuring uptime, control, and a superior driver experience.

Features

  • Centralised charge point monitoring and control
  • UK regulatory compliance and security

Benefits

  • Reduces downtime and costs through real-time remote charge point management
  • Ensures regulatory compliance, security, trust, and confidence for all users

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@solnetiot.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 2 9 5 3 3 5 5 7 8 7 9 0 9 9

Contact

SOLNET Syed Kazmi
Telephone: 01438419889
Email: info@solnetiot.com

About the service

Service categories

Applications

Enterprise resource management

Financial

  • Financial and Accounting Applications
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
Support is limited to approved hardware configurations, and service availability may be affected during planned maintenance windows.
System requirements
  • Internet connectivity, supported EV chargers, secure cloud access, web browser
  • Compatible hardware, stable power supply, SIM or ethernet networking required

User support

Email or online ticketing support
Yes
Support response times
We respond within one business day.
Weekend responses may take up to two business days.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We have tested web chat functionality with assistive technology users, including screen reader and keyboard-only users, to ensure accessibility, clear navigation, and effective communication in line with accessibility best practices.
Onsite support
Yes
Support levels
Support levels provided

Standard Support
Business-hours email and ticketing support, issue tracking, and updates.

Enhanced Support
Priority response, extended hours support, proactive monitoring, and incident management.

Premium Support
24/7 support, fastest response times, proactive system reviews, and escalation management.

Costs
Support costs vary by level and contract size and are provided on request.

Account management
Enhanced and Premium levels include access to a technical account manager or cloud support engineer.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
We support users in getting started through a combination of online training, comprehensive user documentation, and step-by-step setup guides. For larger deployments, we also offer onsite training sessions to help administrators and operators configure charge points, understand dashboards, and efficiently manage the service from day one.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of a contract, users can extract their data through secure export tools in the web interface or via the API. Data can be downloaded in standard formats (e.g., CSV, JSON) to ensure continuity, reporting, and migration to another system before the contract terminates.
End-of-contract process
End of Contract:
At the end of the contract, users retain access to their data for export, after which service access is deactivated. Any custom modules or features are removed unless a renewal or new contract is agreed.

Included in Price:

Access to the charge point management platform

Standard support and software updates

Use of approved charge point modules

Additional Costs:

Onsite training or extended support packages

Custom development or advanced integrations

Hardware upgrades or replacements beyond standard supported models
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile and desktop services offer the same core functionality, but with differences in interface and access:

Mobile: Optimized for touch screens, on-the-go monitoring, push notifications, and quick updates.

Desktop: Full dashboard view, advanced reporting, bulk management tools, and detailed analytics for in-depth operational control.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Yes, our service includes a web-based interface that allows charge point operators to monitor, manage, and control EV chargers, access reports, configure settings, and view real-time usage data. It is accessible via desktop and mobile devices for convenient, secure management.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We have conducted interface testing to ensure WCAG 2.2 AA compliance with users of assistive technology. This included testing with screen readers, keyboard-only navigation, and voice control tools to verify that all buttons, menus, forms, and notifications are accessible, clearly labeled, and fully operable without a mouse.
API
Yes
What users can and can't do using the API
API Capabilities and Limitations

What users can do:

Set up the service: Users can register new charge points, configure site details, and link accounts via the API.

Make changes: Users can update charge point settings, manage availability schedules, monitor usage data, and trigger remote diagnostics or resets.

Limitations:

Certain advanced features, such as firmware upgrades or hardware-specific configurations, can only be performed through the web interface.

Changes are restricted to supported hardware models and may be limited by user permissions.

Some bulk operations may have rate limits to ensure system stability.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Ustomisation of Service

What can be customised: Users can add management modules, configure charge point settings, adjust reporting dashboards, and tailor notifications.

How users can customise: Customisation is performed through the web interface or API, allowing selection and configuration of modules, scheduling preferences, and user roles.

Who can customise: Only authorised administrators or account managers can make customisations to ensure security and compliance.

Scaling

Independence of resources
We guarantee users aren’t affected by others’ demand through rigorous stress testing. Our platform has been tested in multi-million user environments and under high-demand scenarios to ensure consistent performance, reliable uptime, and fast response times, even when multiple users are accessing or managing charge points simultaneously.

Analytics

Service usage metrics
Yes
Metrics types
Users can export performance metrics as part of their data, including KPIs for charger uptime, connectivity, service performance, and overall reliability. Metrics are accessible via the web interface or API, downloadable in standard formats (CSV/JSON) for reporting, analysis, or integration with other systems.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
Physical access control, complying with SSAE-18 / ISAE 3402
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Users can export their data using the web interface or the API. Data can be downloaded in standard formats such as CSV or JSON, allowing easy integration with other systems, reporting, or backup. Exports can include usage logs, transaction history, and configuration settings, with filters for date ranges or specific charge points.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • XML
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We guarantee 99.9% platform availability under normal operating conditions, backed by our Service Level Agreement (SLA). If availability falls below this threshold, users are eligible for service credits or refunds, calculated proportionally to the downtime experienced, ensuring accountability and maintaining trust in our service reliability.
Approach to resilience
Our service’s resilience strategy is built around industry best practices and proven architecture principles:

• Redundancy & Diversity

Critical components (compute, storage, network) exist in multiple independent instances to ensure failures in one do not impact overall service.

We architect for failure — components can fail without impacting live service availability.

• Isolation & Separation

Production, staging, and disaster recovery environments are logically and physically separated to reduce cross-environment impact and risk.

• Scalability & Elasticity

Services automatically scale to handle load spikes, helping maintain performance during traffic surges or degraded conditions.

• Data Protection

Data is replicated securely across locations; backups are maintained and regularly validated to ensure periodic restores are possible.
Outage reporting
Outage Reporting

Our service provides clear and timely outage reporting through automated monitoring and customer communication channels, ensuring transparency and rapid awareness of any service disruption.

The platform is continuously monitored using automated health checks across core services, APIs, and infrastructure components. When an issue is detected, alerts are generated in real time, incidents are logged, and severity levels are assigned to support prompt investigation and resolution.

A public service status dashboard is available to provide real-time visibility of overall platform availability, active incidents, and planned maintenance. Historical incident information is also retained to support transparency and service assurance. Where required, more detailed technical information can be made available on request.

Service status information can also be accessed via an API, allowing customers or partners to integrate outage and availability data into their own monitoring or reporting systems. The API is secured and rate-limited to ensure reliability and data protection.

In addition, email alerts are sent to nominated contacts for confirmed outages, significant service degradation, planned maintenance, and incident resolution updates. Communication is maintained throughout an incident, and post-incident summaries can be provided following major outages.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Other
Other user authentication
Access to the service is secured using OpenID Connect (OIDC) integrated with Microsoft Entra ID (Azure AD). Users authenticate via their Entra credentials, supporting single sign-on (SSO) and strong identity verification. Authentication tokens are issued by Entra and validated by the service before granting access. Role-based access controls ensure users can only access appropriate functionality and data. All authentication processes follow industry best practices, including token expiration, revocation, and encrypted transmission over TLS 1.3 to protect credentials and session integrity.
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is strictly controlled using role-based access controls (RBAC). Users are assigned roles with the minimum privileges required for their responsibilities. Administrative interfaces require multi-factor authentication (MFA) and are accessible only from approved devices or networks. Support channels are authenticated and monitored, with access limited to authorised personnel. All access attempts are logged and reviewed regularly. Changes to roles, privileges, or support access are subject to formal approval and periodic audit to ensure compliance with security policies and ISO/IEC 27001 standards.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Other
Description of management access authentication
Access to the service is secured using OpenID Connect (OIDC) integrated with Microsoft Entra ID (Azure AD). Users authenticate via their Entra credentials, supporting single sign-on (SSO) and strong identity verification. Authentication tokens are issued by Entra and validated by the service before granting access. Role-based access controls ensure users can only access appropriate functionality and data. All authentication processes follow industry best practices, including token expiration, revocation, and encrypted transmission over TLS 1.3 to protect credentials and session integrity.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Our organisation fully complies with ISO/IEC 27001 and operates a formal Information Security Management System (ISMS) covering people, processes, and technology. The ISMS is approved by senior management and is designed to protect the confidentiality, integrity, and availability of information assets.

We maintain a comprehensive suite of documented information security policies aligned with ISO 27001 Annex A controls. These include policies for risk management, access control, asset management, cryptography, secure development, incident management, business continuity, supplier security, and data protection. Policies are version-controlled, communicated to relevant staff, and reviewed regularly or following significant change.

Responsibility for information security sits with senior management and is supported by a designated Information Security Officer. Security risks, incidents, audit results, and compliance metrics are reported through defined management reporting lines and reviewed as part of formal management reviews.

Compliance with policies is ensured through mandatory staff security awareness and role-based training, least-privilege access controls, continuous monitoring and logging, and regular risk assessments. Internal audits are conducted to verify adherence to ISO 27001 requirements, and corrective actions are tracked to completion. Security incidents are formally recorded, investigated, and used to drive continual improvement of the ISMS.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
We operate formal configuration and change management processes aligned with ISO/IEC 27001. All service components are recorded in a central configuration management repository and tracked throughout their lifecycle, from deployment through change and retirement. Changes are requested, assessed, approved, implemented, and reviewed using a controlled change process. Each change is evaluated for potential security impact, including risks to confidentiality, integrity, and availability. Security reviews, testing, and rollback plans are required for material changes, ensuring service stability and ongoing compliance.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We operate a formal vulnerability management process aligned with ISO/IEC 27001. Potential threats are identified through vulnerability scanning, risk assessments, penetration testing, and code reviews. Vulnerabilities are assessed based on severity, exploitability, and impact, with remediation prioritised accordingly. Critical vulnerabilities are patched as a priority, typically within hours or days, while other issues follow defined timelines. Threat intelligence is sourced from vendor advisories, CVE databases, security bulletins, and automated security monitoring tools.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We operate continuous protective monitoring aligned with ISO/IEC 27001 to detect and respond to potential security compromises. Logs and system events are collected from all critical services and analysed for anomalies, suspicious activity, and policy violations. Potential compromises trigger automated alerts and are escalated to the security team for immediate investigation. Incidents are assessed, contained, and remediated according to severity, with critical events responded to within hours. Lessons learned are documented and fed back into our monitoring and incident response processes to strengthen ongoing security.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We operate a formal incident management process aligned with ISO/IEC 27001. Pre-defined procedures exist for common incidents, including system outages, security events, and data breaches. Users can report incidents via a dedicated support portal, email, or telephone, which are logged and tracked in our incident management system. Each incident is assessed, prioritised, and investigated promptly. Incident reports, including cause, impact, resolution, and lessons learned, are provided to affected users and stakeholders. Post-incident reviews inform continuous improvement of processes and controls.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
The free version provides basic EV charger management, mobile and web access, and charging history. Advanced features, analytics, automated scheduling, and priority support are not included. The service is available indefinitely.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0.5%
Between £500,001 and £1,000,000
0.75%
Between £1,000,001 and £2,500,000
1%
Between £2,500,001 and £5,000,000
1.25%
Over £5,000,001
1.5%

Standards and certifications

ISO/IEC 27001 certification
Yes
ISO/IEC 27001 accredited by
Alcumus ISOQAR Limited
ISO/IEC 27001 accreditation date
Friday 7 November 2025
What the ISO/IEC 27001 doesn’t cover
The ISMS covers all operational, technical, and support processes related to the delivery of our services
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
ISO 9001 certification accredited by
Alcumus ISOQAR Limited
ISO 9001 accreditation date
Friday 7 November 2025
What the ISO 9001 doesn’t cover
The ISMS covers all operational, technical, and support processes related to the delivery of our services
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
B6010d24-d0f6-45a4-9a3c-7898d0c60133
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
  • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
  • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
  • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
  • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
Mission: Make Britain a clean energy superpower

To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

  • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
Mission: Break down barriers to opportunity

By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

Policy Outcome 6: Employment and training: For those who face barriers to employment

  • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors

Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

  • Creation of outreach activities to create a pipeline of employees for the future contract delivery

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@solnetiot.com. Tell them what format you need. It will help if you say what assistive technology you use.