Sterling
Sterling is a SaaS platform for construction pre construction teams that enables resource based cost and carbon estimating. It combines 2D and 3D take off, structured estimating, forecasting and lifecycle analysis, allowing organisations to produce auditable, standards aligned cost and carbon outputs from a single, integrated system.
Features
- Resource based cost and carbon estimating
- Integrated 2D and 3D digital take off
- Centralised cost and carbon libraries
- Structured estimate and cost plan creation
- Integrated embodied carbon data sources
- Revision management and impact comparison
- Forecasting linked to project programmes
- Lifecycle cost and carbon analysis
- Secure cloud based access and permissions
- Open APIs for system integrations
Benefits
- Produce cost and carbon estimates in one process
- Improve accuracy through resource level data
- Reduce duplication across estimating workflows
- Increase confidence in reported outputs
- Support compliance with industry standards
- Identify cost and carbon impacts earlier
- Enable faster and more consistent estimating
- Improve collaboration across project teams
- Maintain a clear audit trail of decisions
- Scale easily without legacy software constraints
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 5 9 4 1 7 7 5 1 7 4 7 2 5 1
Contact
STERLING DCS LIMITED
James Hunter
Telephone: 01245808114
Email: james.hunter@sterling-dcs.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Procurement
- Project and portfolio management
- Asset life-cycle management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Sterling complements and extends common construction and enterprise platforms including document management, BIM authoring, cost management, scheduling, and carbon data services. It integrates with tools such as Microsoft SharePoint, Autodesk Construction Cloud, Procore, Primavera P6, Microsoft Project, and third party embodied carbon data providers.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- Sterling is delivered as a cloud based SaaS platform and requires a modern web browser and stable internet connection. Planned maintenance is carried out outside UK business hours wherever possible and is communicated in advance. Some advanced 3D take off workflows may require larger models to be optimised for performance. Support is provided for the supported browser versions and documented file formats only.
- System requirements
-
- A modern web browser such as Chrome, Edge, or Firefox
- A stable internet connection suitable for cloud applications
- A standard desktop or laptop computer with mouse input
- Sufficient bandwidth for viewing 2D drawings and 3D models
- User authentication via email and secure password credentials
User support
- Email or online ticketing support
- Yes
- Support response times
- Sterling provides support during UK business hours, Monday to Friday, excluding public holidays. Initial responses to support queries are typically provided within one UK business day. Requests received outside business hours or at weekends are logged automatically and responded to on the next business day. For critical issues impacting service availability, priority handling is applied in line with the agreed support terms and service level commitments.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Sterling has tested its web based support and help interfaces, including web chat components, against recognised accessibility standards. Testing has included keyboard only navigation, screen reader compatibility, focus management, and colour contrast checks. Feedback from accessibility testing has been used to improve usability and ensure that support interactions remain accessible to users with assistive technologies.
- Onsite support
- Yes
- Support levels
-
Sterling provides structured support levels designed to meet the needs of public sector and commercial customers.
Standard Support is included within the core subscription at no additional cost. It provides access to email based support during UK business hours, Monday to Friday, excluding public holidays. Issues are logged, tracked, and prioritised in line with service impact, with responses typically provided within one business day.
Enhanced Support is available as a paid add on. Pricing is agreed per customer based on user numbers and project complexity. Enhanced Support includes faster response targets, priority issue handling, and scheduled support reviews.
For larger or more complex deployments, Sterling can provide a named Technical Account Manager or Cloud Support Engineer. This service is priced separately and tailored to the customer’s requirements. It includes proactive system guidance, release briefings, and coordination of support and technical queries.
All support levels include access to online documentation and training resources. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Sterling provides a structured onboarding process to help users start using the service quickly and effectively.
New customers are supported through an initial kick off process to confirm objectives, data requirements, and user access. User accounts are set up securely, and administrators are guided through initial configuration including libraries, breakdown structures, and permissions.
Training is delivered through a combination of live online sessions and self service learning. Online training sessions are tailored to user roles such as estimators, commercial managers, and administrators. For larger deployments, onsite training can be provided by prior agreement.
Comprehensive user documentation is available through the Sterling support portal, including step by step guides, video tutorials, and best practice workflows. Ongoing support is available via email, with optional enhanced support services for customers requiring additional assistance.
This approach ensures users can adopt the platform confidently while aligning it to their existing processes and standards. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, users can extract their data directly from Sterling in a structured and usable format.
Authorised administrators can export project data, including cost plans, estimates, resource libraries, carbon data, forecasts, lifecycle outputs, and associated metadata. Exports are provided in common open formats such as CSV, Excel, and PDF to support reuse, reporting, and archiving. Where applicable, model related data and take off outputs can also be exported in supported formats.
Sterling provides guidance on the available export options and the recommended approach to ensure completeness. Customers may request support assistance during the offboarding process to help validate that all required data has been successfully extracted.
Following contract termination and confirmation of data extraction, customer data is securely retained for a defined period in line with contractual terms and then permanently deleted in accordance with Sterling’s data retention and security policies. Customers retain full ownership of their data throughout the contract lifecycle. - End-of-contract process
-
At the end of the contract, Sterling follows a defined offboarding process to ensure a clear and secure conclusion of the service.
The contract price includes continued access to the platform until the contract end date, the ability for authorised users to export their data, and standard support during the offboarding period. Customers can extract all project and library data using built in export tools before access is removed.
Prior to contract expiry, Sterling will notify the customer and confirm the end date, data export options, and next steps. Once the contract ends, user access is disabled and the account enters a data retention period in line with contractual terms.
Additional services such as assisted data extraction, bespoke data formats, extended access beyond the contract end date, or consultancy support are available at an agreed additional cost. Following the retention period, all customer data is securely deleted in accordance with Sterling’s data protection and information security policies. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
Sterling provides secure, documented APIs that allow customers to integrate the service with their wider technology estate.
Users can use the API to set up and configure key elements of the service, including creating projects, managing user access, synchronising reference data, and connecting external systems such as document management, cost management, or reporting platforms. Authentication is handled using secure token based access.
The API allows users to make controlled changes to data held within Sterling, such as updating project metadata, synchronising cost structures, importing resource data, and retrieving cost and carbon outputs for reporting and analysis. All changes made via the API follow the same validation and permission rules as the user interface to maintain data integrity and auditability.
The API is designed for integration and automation rather than full user interaction. Some configuration and workflow activities must be completed through the Sterling user interface. Access to specific API endpoints may be restricted based on subscription level, security requirements, or customer agreement. Rate limiting and usage controls are applied to ensure platform stability and performance. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users can customise Sterling to align with their organisational standards and project requirements. Customisable elements include cost and carbon libraries, breakdown structures, resource definitions, calculation rules, reporting layouts, and user permissions. Customisation is carried out through the web based user interface using configuration tools and role based controls. Administrators and authorised power users can manage and apply custom settings across projects, ensuring consistency while allowing flexibility at project or organisational level.
Scaling
- Independence of resources
- Sterling is built on a scalable, multi tenant cloud architecture designed to isolate workloads and manage demand effectively. System resources are dynamically allocated based on usage, ensuring consistent performance as demand fluctuates. Monitoring and automated scaling controls are used to prevent individual users or organisations from impacting others. Regular performance testing and capacity planning are carried out to maintain service reliability as the user base grows.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Sterling provides a range of service metrics to support analysis and decision making. Metrics include cost and carbon totals, resource level breakdowns, rate analysis, variance between revisions, and forecast versus estimate comparisons. Users can track changes over time, compare scenarios, and report against recognised standards and structures. Metrics are available through on screen dashboards, structured reports, and data exports for use in external analytics and business intelligence tools.
- Reporting types
-
- API access
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users export data from Sterling using built in export tools available through the web based user interface. Authorised users can export cost, carbon, resource, forecast, and lifecycle data in common formats such as CSV, Excel, and PDF. Exports can be completed at project or portfolio level, ensuring data can be reused for reporting, analysis, or archiving outside the platform.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- Json
- Xml
- Data import formats
-
- CSV
- Other
- Other data import formats
- Excel
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Sterling is designed to provide high levels of availability through a resilient cloud based architecture.
The service is provided with a target availability of 99.9 percent measured on a monthly basis, excluding planned maintenance. Planned maintenance windows are scheduled outside UK business hours wherever possible and are communicated in advance.
Availability is monitored continuously, and incidents impacting service access are logged and managed in line with defined incident response procedures. In the event that the monthly availability falls below the guaranteed level, service credits may be applied in accordance with the agreed Service Level Agreement. Service credits are calculated as a percentage of the monthly subscription fee and are applied to future invoices rather than issued as cash refunds.
Full details of availability commitments, measurement methods, exclusions, and service credit thresholds are documented within Sterling’s SLA and contractual terms and are made available to customers on request. - Approach to resilience
-
Sterling is designed with resilience built into every layer of the service.
The platform is hosted within resilient UK and EU based cloud infrastructure, using multiple availability zones to reduce the risk of single points of failure. Core services are distributed across redundant components, allowing the platform to continue operating if individual services or nodes fail.
Data is stored using resilient storage services with automatic replication and regular backups. Backups are encrypted, monitored, and tested to ensure data can be restored in the event of an incident. System health is continuously monitored, with automated alerts and failover processes in place to support rapid recovery.
The underlying datacentre infrastructure provides physical security, power redundancy, network resilience, and environmental controls in line with recognised industry standards. Detailed information on hosting locations, datacentre certifications, and resilience controls can be provided to customers on request.
This approach aligns with the UK Government’s cloud security principles for asset protection and resilience. - Outage reporting
-
Sterling uses a clear and transparent approach to outage reporting and service communications.
Service availability is monitored continuously, and any outages or service degradation events are identified automatically. Customers are informed of confirmed incidents through direct email notifications to nominated contacts, providing details of the issue, expected impact, and progress updates until resolution.
Sterling does not currently provide a public status dashboard or outage reporting API. However, incident information, post incident summaries, and root cause updates are shared with affected customers as part of the incident management process.
Planned maintenance notifications are communicated in advance via email, including details of timing, expected impact, and any actions required by users. Customers with enhanced support arrangements receive prioritised communications and, where applicable, direct contact from the support team.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to Sterling management interfaces and support channels is restricted using role based access controls. Users authenticate using unique usernames and strong passwords, with multi factor authentication supported for additional security. Single sign on is available to integrate with customer identity providers where required. Administrative access is limited to authorised personnel only, and permissions are granted based on least privilege. Support channels verify user identity before discussing or accessing account information.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Sterling follows a structured security governance framework aligned to ISO 27001 principles. Information security policies, risk management processes, and controls are defined, documented, and reviewed regularly. Access controls, data protection measures, and incident management procedures are embedded across the organisation. Security responsibilities are clearly assigned, and staff receive regular security awareness training. Compliance, risk, and security posture are reviewed as part of ongoing governance to ensure the service remains secure and resilient.
- Information security policies and processes
-
Sterling operates a comprehensive set of information security policies and processes aligned with ISO 27001 principles and recognised industry best practice.
These policies cover areas including access control, data protection, incident management, business continuity, risk assessment, supplier management, and secure development. Policies are documented, version controlled, and reviewed on a regular basis to ensure they remain current and effective.
Information security governance is overseen by senior management, with clear reporting lines to executive leadership. Responsibility for implementing and maintaining security controls is assigned across technical, operational, and management teams.
Compliance with security policies is enforced through technical controls, documented procedures, and regular monitoring. Secure configuration standards, logging, and audit trails are used to identify and investigate potential issues. Staff receive security awareness training as part of onboarding and on an ongoing basis. Any security incidents are managed through a defined incident response process, including investigation, reporting, and corrective actions to prevent recurrence. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Sterling follows controlled configuration and change management processes aligned with secure SaaS delivery practices. Service components are versioned, documented, and tracked throughout their lifecycle using managed repositories and deployment pipelines. Changes are proposed, reviewed, and approved through defined workflows. Each change is assessed for functional and security impact, including dependency checks and risk evaluation. Security related changes are reviewed by senior technical staff before release. Changes are tested in non production environments prior to deployment and are logged for audit purposes.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Sterling operates an active vulnerability management process aligned with industry best practice. Potential threats are assessed through regular security reviews, dependency scanning, and monitoring of platform components. Information on emerging vulnerabilities is obtained from trusted sources including vendor security advisories, cloud provider alerts, and recognised vulnerability databases. Patches and updates are prioritised based on risk and severity, with critical security fixes deployed as soon as practicable, and typically within defined SLA targets. All updates are tested prior to release to minimise operational risk.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Sterling uses protective monitoring to identify and respond to potential security incidents. System logs, access activity, and service events are continuously monitored to detect unusual behaviour or indicators of compromise. Automated alerts highlight potential issues for investigation. When a potential compromise is identified, the incident response process is initiated, including containment, assessment, and remediation. Security incidents are prioritised based on risk, with critical incidents investigated and responded to immediately and in line with defined incident response procedures.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Sterling follows defined incident management processes to ensure incidents are handled consistently and effectively. Pre defined procedures exist for common events such as service outages, security incidents, and performance degradation. Users report incidents through the support email channel, where tickets are logged and prioritised. Incidents are investigated, tracked, and resolved in line with severity. Incident updates and post incident reports are provided to affected customers via email, including details of impact, resolution, and any corrective actions taken.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2.5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 33474567-5fb6-43ca-ae82-aa22a688cbda
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-