Nelson+
Nelson+ is a configurable, cloud-based end-to-end data management and workflow platform for lung cancer screening programmes. It coordinates the full screening pathway including invitations, assessments, CT-scanning, reporting, results communication and referral. It can integrate with local clinical systems and external services such as AI-assisted image analysis and remote radiology reporting.
Features
- Full screening workflow for NHS Lung Cancer Screening programmes
- Standardised reporting and dashboards for NHS screening programmes
- Flexible implementation options which can be integrated with Trust/NHS systems
- Standardised reporting and dashboards for NHS screening programmes
- Incidental Findings workflow included within screening management
- Automated letter generation for all programme communications
- Full participant tracking across the entire screening pathway
- Capacity planning module with integrated appointment scheduling
- Screening Review Meeting (SRM) Support
- Configurable role-based access and two-factor user authentication support
Benefits
- Streamlines and automates lung cancer screening workflows
- Enables seamless technical integration and installation
- Supports users with standard training and ongoing operational support
- Simplifies learning process and platform usage via an intuitive UI
- Meets NHS England reporting needs with customisable dashboards
- Scales efficiently to manage large population screening programmes
- Enables collaborative working across Trusts, ICBs and Cancer Alliances
- Improves data quality through structured inputs and validations
- Reduces manual tasks using automated letters and workflows
- Enhances operational oversight with real-time activity visibility
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 2 0 0 0 1 8 8 2 1 6 6 3 3 3
Contact
Nelson+ B.V.
Nelson+ B.V.
Telephone: +31 (0) 50 211 03 48
Email: compliance@nelson-plus.org
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- No
- System requirements
-
- Supported on Chrome, Firefox, Safari and Edge
- Works on laptop, PCs, tablets and mobile devices
User support
- Email or online ticketing support
- Yes
- Support response times
- Support requests are logged and triaged during business hours, Monday to Friday (excluding public holidays). Target response times are defined in the Service Level Agreement and are typically within 24–48 hours, depending on issue priority and severity. Requests received outside business hours, including weekends, are logged and reviewed on the next working day unless enhanced or out-of-hours support has been agreed separately.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide a full range of support for our customers. The central entry point for all customer questions and issues is our First Line Support Desk, a skilled helpdesk that supports customers with day-to-day functional queries, resolution of minor issues, and execution of monitoring tasks. The First Line Support Desk logs and tracks all customer requests (including incidents, defects, change requests and general queries) and ensures that agreed Service Level Agreements are met.
Where required, tickets are escalated to Second and Third Line Support, which provide deeper technical and platform expertise and investigate more complex issues. Where appropriate, configuration changes or fixes are applied to the system. Target response times are defined in the Service Level Agreement and are typically within 24–48 hours. Details of support levels, including response targets, service hours and any fixed support hours, are agreed per customer and documented in the Service Level Agreement.
Standard support is included within the service price and provides access to the Support Desk, escalation services, and a named Technical Account Manager. Support usage is reviewed periodically and, where sustained demand materially exceeds expectations, support levels may be adjusted by agreement, with applicable unit rates defined in the G-Cloud Pricing Document. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
We provide online training sessions to introduce users to the Nelson+ platform, including demonstrations of core workflows and configuration options. Onsite training can be provided on request. Users receive access to training materials such as video tutorials, user guides and task specific tip sheets, and they are also provided with access to a test environment where they can safely practise using the system. The system also includes contextual help and guidance embedded within the interface to support day-to-day use.
During onboarding, support is provided for environment setup, user account creation and any required integrations. A dedicated contact is available during the onboarding period to support a smooth transition into live use. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
At the end of the contract, users can extract their data using defined export methods. The data extraction approach is agreed in advance with the customer to confirm the preferred transfer method, scope and formats, within the supported export options.
Data is provided as structured export files or transferred securely to a customer-nominated location, in line with the agreed offboarding arrangements. Where supported, data exports can also be delivered via existing interfaces.
All data extraction activities are carried out using secure transfer mechanisms and in accordance with applicable data protection and security controls, ensuring customers can retrieve their data in a usable format to support transition or archival requirements at contract end. - End-of-contract process
-
At the end of the contract, a structured offboarding process is followed. This includes agreeing timelines, confirming the data extraction approach and validating that all required data transfers have been completed.
Once the customer confirms receipt of their data, secure data deletion is carried out in accordance with defined data sanitisation procedures to ensure customer data is removed from active systems and storage in a manner that prevents retrieval. Where applicable, confirmation of data deletion can be provided.
Standard data extraction and secure deletion activities are included within the service price. Additional offboarding activities, such as extended access periods, non-standard extraction formats or specialist support, can be provided at additional cost where agreed.
Support remains available during the offboarding period to respond to queries and ensure completion of the agreed activities. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding documentation is provided directly to customers in PDF format as part of the implementation and service delivery process. Documentation is structured clearly with headings and consistent formatting to support readability and can be accessed using standard PDF readers. Where required, documentation can be shared electronically with customer teams and stakeholders to support onboarding, operational use and service exit activities.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Nelson+ supports access on mobile and desktop devices. The functionalities are not restricted based on device type, while specific features are optimised for mobile use.
Desktop access is recommended for activities involving complex workflows or detailed data review, where larger screen size and multi-window navigation improve usability. - Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Nelson+ is designed to be configurable to align with each Buyer’s screening programme model and operational requirements. Customization can be achieved through either configuration or software development.
Authorised users can configure workflows, pathway steps, decision points, templates and dashboards within defined governance controls. This includes configuring participant pathways, communication templates, follow-up logic and reporting views to reflect local programme policies and clinical protocols.
Changes that go beyond standard configuration, such as new integrations, additional functional capabilities or broader platform changes, are requested by the Buyer and assessed by Nelson+ for feasibility, impact and alignment with the service model. Where agreed, such changes are delivered as enhancements through formal change management, scoped and approved by both parties, and provided on a chargeable basis as defined in the G-Cloud Pricing Document.
Scaling
- Independence of resources
-
Nelson+ is a cloud native application. Its modular design enables scalability, allowing the service to adapt to varying demand through load balancing and horizontal scaling techniques.
The service can be deployed in most cloud service providers and is architected to operate within agreed capacity parameters, using standard cloud mechanisms to manage demand and support stable, predictable service delivery.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Nelson+ provides operational metrics through built-in dashboards and reports. Metrics include participant volumes, pathway progress, appointment activity and operational performance indicators to support service oversight.
An anonymised reporting dataset is available for management and monitoring purposes and is refreshed on a scheduled basis. The platform also includes built-in views and reports that allow users to access key metrics on demand to support programme monitoring, capacity planning and reporting requirements. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Users can export data from Nelson+ in several ways depending on their role and requirements. End users may export selected datasets directly from the application where permitted. Full dataset exports are provided on request via the support team to ensure appropriate governance and data protection controls are applied.
Export methods, scope and formats are agreed with the customer on a case-by-case basis, taking into account the intended use of the data and applicable security requirements. All exports are performed using secure transfer mechanisms. - Data export formats
-
- CSV
- Other
- Other data export formats
- Structured export formats (where agreed)
- Data import formats
-
- CSV
- Other
- Other data import formats
- Structured export formats (where agreed)
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Nelson+ provides a service availability target of up to 99.9%, measured over the agreed service period. Availability commitments, measurement methods and service hours are defined within the Service Level Agreement agreed with each customer.
Where availability levels are not met, service credits or other contractual remedies are applied in accordance with the terms of the agreed Service Level Agreement. - Approach to resilience
-
Nelson+ is built using a cloud-native architecture designed to provide resilience and fault tolerance. The service is hosted on cloud infrastructure configured with redundancy across multiple availability zones to reduce the risk of single points of failure.
Standard cloud resilience mechanisms, monitoring and alerting are used to maintain service continuity. Backup and recovery processes are in place to protect customer data and enable service restoration where required. Resilience controls are reviewed as part of operational and change management activities. - Outage reporting
-
Nelson+ uses automated monitoring to detect service disruptions or degraded performance. When an outage or significant incident is identified, the support team is alerted and investigates in line with incident management procedures.
Customers are informed of service outages through agreed communication channels, typically via email notifications. Updates are provided as appropriate until the issue is resolved, in accordance with the incident response and communication arrangements defined in the Service Level Agreement.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to the Nelson+ platform is controlled using role-based access control, ensuring users can only perform actions appropriate to their assigned roles and responsibilities. Authentication mechanisms include username and password credentials, with support for multi-factor authentication where configured.
Where required, identity federation with an existing identity provider may be supported by agreement. For specific integration scenarios, access can also be restricted through dedicated network connections. Authentication controls are applied consistently to ensure that only authorised users are able to access the platform. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Nelson+ follows documented information security policies and processes designed to protect the confidentiality, integrity and availability of information. These policies align with recognised security standards and applicable data protection legislation, including GDPR.
Security governance is overseen by a designated security lead with organisational authority, supported by defined roles and responsibilities across the organisation. Policies are communicated to staff and embedded within operational and development activities.
Compliance is supported through access controls, staff awareness activities, incident management procedures and regular review of security risks. Security matters are escalated through established reporting lines, and policies are reviewed periodically to maintain effectiveness. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Nelson+ operates defined configuration and change management processes to control changes across the platform. Configuration items and application components are version-controlled, with changes tracked throughout their lifecycle.
Proposed changes are assessed for functional and security impact prior to implementation. Changes are reviewed by peers before being merged, with security considerations taken into account. Developers receive security awareness training to reduce the risk of introducing insecure code.
Automated security and quality testing is performed prior to release to identify potential vulnerabilities and defects, and change activities are documented to support traceability and ongoing platform stability. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Nelson+ applies defined vulnerability management processes to identify, assess and address security risks affecting the platform. Vulnerability information is monitored from recognised sources, including public vulnerability databases such as CVE, supplier security advisories and cloud provider notifications.
Identified vulnerabilities are assessed based on severity, exploitability and potential impact. High-severity vulnerabilities are addressed within 15 days of identification, with remediation actions, including patching or mitigation, prioritised according to risk and implemented in line with internal change management procedures and operational considerations. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Nelson+ uses automated monitoring mechanisms to analyse application and network activity logs and identify potentially suspicious behaviour or unauthorised access attempts. Monitoring rules and alert thresholds are configured to support timely detection of security-relevant events.
When potential security events are detected, alerts are raised to authorised operators, who investigate and take appropriate action in accordance with defined incident management procedures. Response actions are initiated within 72 hours of detection in the worst-case scenario, with prioritisation based on risk and potential impact. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Nelson+ follows defined incident management procedures to respond to security and operational incidents. Common incident scenarios are documented and handled through established support and escalation processes.
Users report incidents by contacting the support team through agreed channels. Incidents are logged, investigated and managed according to priority and impact. Incident updates and reports are provided to customers in line with contractual and regulatory requirements. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Amtivo Group Limited T/A British Assessment Bureau Ltd.
- ISO 9001 accreditation date
- Thursday 11 December 2025
- What the ISO 9001 doesn’t cover
-
The certification applies to the quality management system governing service delivery, implementation, support, and operational processes.
Design and software development activities are covered within the ISO 9001 scope of the parent company. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- C95eb9db-8bb6-4ee8-9178-32ddc34e9559
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-