Thinkproject Contracts (CEMAR)
Make contracts easy with Thinkproject Contracts, the market-leading contract management solution for NEC3, NEC4, JCT, FIDIC and other forms. Modern contracts are complex and expensive to administer. Thinkproject combines industry leading knowledge and expertise to make sophisticated contract management simple and free professionals time to focus on delivering their projects.
Features
- Marketing-leading solution, acknowledged contributor to NEC4 and ISO 27001,9001, 22301,CE+.
- Optional modules; connected mobile-field management, asset management, and document management.
- Collaborative environment, single truth of shared events, registers and reminders.
- Tailored workflows for all core NEC3, NEC4, JCT, FIDIC procedures.
- Complaint communications with clauses, appropriate verbs, defined terms and actions.
- User and process-orientated governance, delegated authorities, approvals and financial/time limits.
- Superuser wizards for-all-parties facilitate rapid-configuration of contracts, users and governance.
- Secure data, UK-based infrastructure, hourly back-ups, 2FA, APIs and Datawarehousing.
- Embedded Microsoft-PowerBI for real-time portfolio level Analytics and Reporting.
- Dedicated support ticketing-service, user guides, integrated eLearning & practice areas.
Benefits
- Reassurance through secure and rapid-to-deploy market-leading software.
- Simplifies management of sophisticated contracts. (NEC3, NEC4, FIDIC, JCT, etc)
- Achieves collaboration, promotes trust and supports cultural change.
- Embedded contract knowledge with intuitive, party and user based workflows.
- Reduces commercial risk through improved contract compliance.
- Autonomy through Superuser model (for-all-parties) with extensive help and support.
- Reminders, countdowns and alerts keep teams aware of outstanding actions.
- Extensive events log, communications archive and governance audit trail.
- Securely-stored contractual data, regularly backed-up with flexible, comprehensive access controls.
- Embedded Microsoft-PowerBI, critical to managing performance, behaviours and identifying trends.
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 6 7 9 4 7 8 5 6 4 0 8 9 7 1
Contact
THINKPROJECT UK LIMITED
Thomas Mayne
Telephone: 01452 547 140
Email: info.tpuk@thinkproject.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Project and portfolio management
- Asset life-cycle management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Hybrid cloud
- Service constraints
- Planned maintenance is broadcast to all Users during login and occurs outside of office hours. In-built support is available 24/7, including help articles and video tutorials, while our dedicated Help and Support team respond to calls and tickets raised during working hours.
- System requirements
-
- Internet Access
- Internet Browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is delivered via a dedicated ticketing service. We acknowledge and triage all requests promptly and provide a first response in line with our SLA, based on impact and urgency — typically within a few hours for high-priority incidents and within one business day for normal incidents. Response will be provided during the regular service business hours from Monday to Fridays (except public holidays)
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide two support levels:
1) Standard Support (included in subscription)
Users access a fully integrated online Help Centre (help articles, quick start guides and video tutorials) and can submit tickets via the portal. Requests are triaged by ticket type (incident / support request) and priority (Critical / High / Medium / Low). We provide SLA-aligned first-response based on that triage (e.g., Critical incidents within hours).
2) Enhanced Support (optional, extra cost)
For customers needing higher-touch service, we offer an enhanced support option at additional cost (quoted case-by-case based on scope/criticality). This can include a named service contact, agreed escalation path and regular service reviews, etc.
Technical Account Manager / Cloud Support Engineer
Not included by default; available as part of an optional additional cost service.
Separately from support, customers can engage our Professional Service team for a range of additional services (e.g. onboarding, configuration) and benefit from a dedicated Account Manager who leads regular business reviews and helps drive desired outcomes. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Our integrated solutions benefit from our real-life experience of the complexities of the AECO industry. With over 20 years of experience in the industry, our experts are on hand to advise you on how to get the most out of your projects. From best practice processes to data analysis, we offer full consultancy services that go beyond technical support.
We offer various implementation pathways to suit your unique needs. Our standard project implementation ensures a seamless integration of our solutions into your operations, our customised project implementation allows for a more tailored solution that aligns perfectly with your specific goals, or our Enterprise Strategic Implementation focuses on the holistic digital transformation of your processes throughout the asset lifecycle.
To ensure a successful rollout after implementation, our comprehensive eLearning, enablement, and support services will be the foundation, fostering a strong partnership and delivering the highest level of service and satisfaction for our valued clients. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Video Tutorials
- Help Articles
- Quick Start Guides
- ELearning Programme (powered by Thinkproject Academy)
- End-of-contract data extraction
- Administration Users (from any organisation including Client, Contractors and Consultants) may backup and download the communications archive for a contract at any time via the administration module, this comprises a structured zip folder by event type containing every PDF hard copy communication and associated attachments.
- End-of-contract process
- There are no additional costs, Administration Users may backup and download the communications archive for a contract at any time.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Our onboarding and offboarding documentation is delivered through an online Help Centre and learning resources designed to be usable by a wide range of users. Content is provided in multiple formats, including written help articles, quick-start guides and video tutorials, so users can choose the format that best suits their needs. Written materials are structured with clear headings, step-by-step instructions and consistent terminology to support readability and navigation. Where processes are complex, we provide screenshots and practical examples to help users follow key workflows. Video content is organised into short, topic-based modules to aid comprehension and allow users to pause, replay and learn at their own pace.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Thinkproject Contracts (CEMAR) is compatible with tablets and smartphones. It can be accessed from a tablet device, and communications created, viewed, and sent. However, it is not responsive to screen size so functionality is limited on a smartphone.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Platform Services encapsulate a comprehensive suite of offerings designed to provide scalable, secure, and efficient cloud-based solutions for managing data and applications to enhancing collaboration, improving data accessibility, and facilitating the seamless integration of class leading applications. With features such as single sign-on, centralized API frameworks, and UI leading mobile applications, Platform Services streamline operations, reduce IT overhead, and promotes innovation by allowing users to leverage the latest technologies without the need for distributed solution landscape. Additionally, includes support and training resources, like academies, to ensure users can maximize the benefits of the platform environment.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Thinkproject is committed to making our services accessible for all users. We design and build our user interfaces with recognised accessibility principles in mind, referencing WCAG guidance during UI design and development. We support common accessibility needs through consistent layouts, clear navigation and usable form patterns, and we continually refine the interface through regular UI and code improvements. Users can also access assistance through multiple channels, including an integrated online Help Centre (articles, quick-start guides and video tutorials), ticket submission via the portal and a support hotline during UK business hours.
- Accessibility testing
- Accessibility is considered throughout our development and QA processes. We use automated accessibility checking tools, including WAVE (Web Accessibility Evaluation Tool) and IBM Equal Access Toolkit, to identify issues and inform prioritisation. Findings are logged and tracked as part of our ongoing product improvement process, helping ensure accessibility considerations are embedded into regular UI and code enhancements.
- API
- Yes
- What users can and can't do using the API
-
We provide an open API and management service, allowing clients to retrieve but also update information within Thinkproject Contracts (CEMAR) by a series of GET/PUT/POST/PATCH calls, covering all relevant data relating to contracts and events.
This allow communication and interaction with 3rd party services via a standard protocol, fostering interoperability and collaboration.
Thinkproject Contracts also offers a Data Share cloud service where direct access to all Client data is provided, alongside the Full Data Model, Data dictionary and example PBX files with in-app Analytics visualization - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The system is fully configurable by Administration Users with built in permissions so that any party, including Client, Contractor and Consultant organisations can configure and manage their users and contracts.
This enables project teams to be completely autonomous in the management of the system and enables the environment owner to devolve the Superuser duties across their supply chain.
Through intuitive setup wizards Administration Users can create new users, add or remove access across contracts and adjust the governance settings. In addition to this, the Administration Users can also create and edit contracts, framework templates, reporting structures and make bulk changes, i.e. add and update users, update/remove key personnel and approval settings across multiple contracts
Global permissions are available to enable the segregation of Administration rights to specific users, against specific contracts or at a hierarchical level, so that any organisation/user within the system can administer the users, contracts and settings relevant to them (i.e. all/any party under the contract).
Scaling
- Independence of resources
- Thinkproject Contracts (CEMAR) is hosted on a hybrid cloud platform combining both dedicated physical and virtual hosts. This affords flexibility and scalability allowing growth and demand requirements to be met dynamically. We perform regular performance testing and engage with specialist consultants to ensure that the system is optimised at all times.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Power BI is fully integrated into the application for analytics and reporting. This provides users a global view of contracts for portfolio level reporting, with rich drill down capability, interactive visualisations, alongside lots of immersive dashboards and reports, which provide metrics on risk, quality, cost, time and communications & behaviours. Key Performance Indicators evaluate how effectively contracts are being managed, highlighting strong areas and those that need improvement to allow the successful delivery projects. This real-time 360 degree view enables users to benchmark and track team, supplier and contract performance.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Exporting to Excel, Word, PDF and other formats is simple and convenient. All reports, registers and events can be downloaded by Users, both individually at a contract level or in aggregate across a project or portfolio of contracts.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- Excel
- JSON
- Word
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
- Any file formart apart from .EXE
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Our SLA defines a minimum contractual availability commitment. In practice, the service is monitored 24/7 and is operated as a high-availability cloud service. Availability is measured in line with the SLA (including standard exclusions such as planned maintenance within published maintenance windows). Any remedies (where applicable) are handled under the governing terms.
- Approach to resilience
- Thinkproject Contracts (CEMAR) is provided as Software as a Service (SaaS) on a secure hybrid cloud environment affording high availability with N+1 redundancy. It is hosted in geographically separate locations across the UK, our Primary Hosting site, our Backup site, and our Disaster Recovery site. Further information available on request.
- Outage reporting
- Thinkproject shall post a message on the login page to warn Users, no later than one business day prior to any planned downtime.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces (cloud portals, admin consoles and databases) is restricted to named, authorised personnel only, approved under our internal vetting policies and granted least-privilege access. Access is protected using MFA/SSO where available, strong authentication, and role-based access controls, with privileged access tightly limited (e.g., designated DBAs). All administrative and support access is logged and monitored. Support channels are controlled through ticketing with identity verification; customer data is shared only when necessary, minimised and time-bound, and only with approved subprocessors vetted through our ISO 27001-certified supplier assurance process where required.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
ISO 9001:2015 (Quality Management System)
ISO 22301:2019 (Business Continuity Management)
UK SbD aligned; supports MOD CyDR expectations.
Cyber Essentials Plus (CE+)
Certificates with Scope available on request. - Information security policies and processes
- All security policies and processes are managed under our ISO 27001 certified Information Security Management System and are subject to recurring management meetings of the Information Security Board to review the ISMS.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- All development is carried out in accordance to our ISO 27001 information security management system. Azure DevOps is utilised across the in-house development team. Thinkproject engages external security consultants to penetration test the application to CHECK standard. Accredited to CESG / CREST and ISO 27001 standards, our security consultants are qualified to carry out penetration testing and IT Health Check services for HMG and private sector organisations. Penetration testing is carried out at least annually and at any major upgrade release.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We operate a structured vulnerability management process aligned to our ISO 27001 certified information security management system. We assess potential threats through layered protective controls and continuous monitoring, including security logging/alerting, regular vulnerability scanning of our applications and networks, and secure development practices (review and testing). We prioritise remediation based on risk and deploy patches through controlled change management and our release schedule. Critical vulnerabilities are handled as a priority and expedited where required. We maintain up-to-date threat intelligence through vendor security advisories, industry sources and vulnerability databases and findings from internal and external security testing and audits.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We use protective monitoring aligned to our ISO 27001 certified information security management system, through security logging, alerting and continuous monitoring of our cloud and application environments. Alerts are triaged using documented procedures and escalated for suspected security incidents. Where a potential compromise is identified, we investigate, contain and remediate (for example restricting access, isolating affected components and rotating credentials), and retain evidence for analysis. We respond based on impact and urgency, with high-severity security incidents prioritised for immediate action in line with our incident process.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate documented incident management processes aligned to our certified ISO 22301 and ISO/IEC 27001 management systems. We maintain pre-defined playbooks for common events (e.g., service degradation, outage and security incidents) covering triage, escalation, communications and restoration. Users report incidents via our online ticketing portal or support hotline during UK business hours. We provide status updates during incidents and, where appropriate, a written incident report after resolution summarising impact, timeline, cause and corrective actions.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- TÜV Rheinland Cert GmbH
- ISO/IEC 27001 accreditation date
- Wednesday 13 November 2024
- What the ISO/IEC 27001 doesn’t cover
-
Any products, services or processes outside the scope stated on the ISO/IEC 27001 certificate and below:
The business processes involved in the development and operation of the products CDE ENTERPRISE, THINKPROJECT CDE, VDC MANAGER, DOCUMENT & FIELD MANAGER, CDE INFRASTRUCTURE, COSTS, CONTRACTS, ASSET & WORK MANAGER and Thinkproject Platform. This includes processes for Operations, Professional Services, Product Management, Product Development, Quality Management, Marketing, Administration and Finance - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Bsi
- ISO 9001 accreditation date
- Wednesday 13 October 2010
- What the ISO 9001 doesn’t cover
-
ISO 9001:2015 is not asserted as applying to all Thinkproject products/services. It applies only to the Thinkproject Contracts (CEMAR) scope as displayed on the certificate. Thinkproject is currently reviewing the certified scope and therefore the scope at the time of contracting will be included in the relevant call off agreements.
All other products are out of scope unless explicitly stated on the certificate. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 94351f6d-b1f3-40c8-8b34-ff16d71e94ff
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 760c17bd-ced2-412e-8a38-e1a0fc426856
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 22301 (Business Continuity Management) - See certificate for scope.
- UK SbD aligned; supports MOD CyDR expectations
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-