Skip to main content

Help us improve the Digital Marketplace - send your feedback

Nelson+ B.V.

Nelson+

Nelson+ is a configurable, cloud-based end-to-end data management and workflow platform for lung cancer screening programmes. It coordinates the full screening pathway including invitations, assessments, CT-scanning, reporting, results communication and referral. It can integrate with local clinical systems and external services such as AI-assisted image analysis and remote radiology reporting.

Features

  • Full screening workflow for NHS Lung Cancer Screening programmes
  • Standardised reporting and dashboards for NHS screening programmes
  • Flexible implementation options which can be integrated with Trust/NHS systems
  • Standardised reporting and dashboards for NHS screening programmes
  • Incidental Findings workflow included within screening management
  • Automated letter generation for all programme communications
  • Full participant tracking across the entire screening pathway
  • Capacity planning module with integrated appointment scheduling
  • Screening Review Meeting (SRM) Support
  • Configurable role-based access and two-factor user authentication support

Benefits

  • Streamlines and automates lung cancer screening workflows
  • Enables seamless technical integration and installation
  • Supports users with standard training and ongoing operational support
  • Simplifies learning process and platform usage via an intuitive UI
  • Meets NHS England reporting needs with customisable dashboards
  • Scales efficiently to manage large population screening programmes
  • Enables collaborative working across Trusts, ICBs and Cancer Alliances
  • Improves data quality through structured inputs and validations
  • Reduces manual tasks using automated letters and workflows
  • Enhances operational oversight with real-time activity visibility

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at compliance@nelson-plus.org. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 2 0 0 0 1 8 8 2 1 6 6 3 3 3

Contact

Nelson+ B.V. Nelson+ B.V.
Telephone: +31 (0) 50 211 03 48
Email: compliance@nelson-plus.org

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
No
System requirements
  • Supported on Chrome, Firefox, Safari and Edge
  • Works on laptop, PCs, tablets and mobile devices

User support

Email or online ticketing support
Yes
Support response times
Support requests are logged and triaged during business hours, Monday to Friday (excluding public holidays). Target response times are defined in the Service Level Agreement and are typically within 24–48 hours, depending on issue priority and severity. Requests received outside business hours, including weekends, are logged and reviewed on the next working day unless enhanced or out-of-hours support has been agreed separately.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We provide a full range of support for our customers. The central entry point for all customer questions and issues is our First Line Support Desk, a skilled helpdesk that supports customers with day-to-day functional queries, resolution of minor issues, and execution of monitoring tasks. The First Line Support Desk logs and tracks all customer requests (including incidents, defects, change requests and general queries) and ensures that agreed Service Level Agreements are met.

Where required, tickets are escalated to Second and Third Line Support, which provide deeper technical and platform expertise and investigate more complex issues. Where appropriate, configuration changes or fixes are applied to the system. Target response times are defined in the Service Level Agreement and are typically within 24–48 hours. Details of support levels, including response targets, service hours and any fixed support hours, are agreed per customer and documented in the Service Level Agreement.

Standard support is included within the service price and provides access to the Support Desk, escalation services, and a named Technical Account Manager. Support usage is reviewed periodically and, where sustained demand materially exceeds expectations, support levels may be adjusted by agreement, with applicable unit rates defined in the G-Cloud Pricing Document.
Support available to third parties
No

Onboarding and offboarding

Getting started
We provide online training sessions to introduce users to the Nelson+ platform, including demonstrations of core workflows and configuration options. Onsite training can be provided on request. Users receive access to training materials such as video tutorials, user guides and task specific tip sheets, and they are also provided with access to a test environment where they can safely practise using the system. The system also includes contextual help and guidance embedded within the interface to support day-to-day use.

During onboarding, support is provided for environment setup, user account creation and any required integrations. A dedicated contact is available during the onboarding period to support a smooth transition into live use.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
At the end of the contract, users can extract their data using defined export methods. The data extraction approach is agreed in advance with the customer to confirm the preferred transfer method, scope and formats, within the supported export options.

Data is provided as structured export files or transferred securely to a customer-nominated location, in line with the agreed offboarding arrangements. Where supported, data exports can also be delivered via existing interfaces.

All data extraction activities are carried out using secure transfer mechanisms and in accordance with applicable data protection and security controls, ensuring customers can retrieve their data in a usable format to support transition or archival requirements at contract end.
End-of-contract process
At the end of the contract, a structured offboarding process is followed. This includes agreeing timelines, confirming the data extraction approach and validating that all required data transfers have been completed.

Once the customer confirms receipt of their data, secure data deletion is carried out in accordance with defined data sanitisation procedures to ensure customer data is removed from active systems and storage in a manner that prevents retrieval. Where applicable, confirmation of data deletion can be provided.

Standard data extraction and secure deletion activities are included within the service price. Additional offboarding activities, such as extended access periods, non-standard extraction formats or specialist support, can be provided at additional cost where agreed.

Support remains available during the offboarding period to respond to queries and ensure completion of the agreed activities.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding and offboarding documentation is provided directly to customers in PDF format as part of the implementation and service delivery process. Documentation is structured clearly with headings and consistent formatting to support readability and can be accessed using standard PDF readers. Where required, documentation can be shared electronically with customer teams and stakeholders to support onboarding, operational use and service exit activities.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Nelson+ supports access on mobile and desktop devices. The functionalities are not restricted based on device type, while specific features are optimised for mobile use.
Desktop access is recommended for activities involving complex workflows or detailed data review, where larger screen size and multi-window navigation improve usability.
Service interface
No
User support accessibility
None or don’t know
API
No
Customisation available
Yes
Description of customisation
Nelson+ is designed to be configurable to align with each Buyer’s screening programme model and operational requirements. Customization can be achieved through either configuration or software development.
Authorised users can configure workflows, pathway steps, decision points, templates and dashboards within defined governance controls. This includes configuring participant pathways, communication templates, follow-up logic and reporting views to reflect local programme policies and clinical protocols.
Changes that go beyond standard configuration, such as new integrations, additional functional capabilities or broader platform changes, are requested by the Buyer and assessed by Nelson+ for feasibility, impact and alignment with the service model. Where agreed, such changes are delivered as enhancements through formal change management, scoped and approved by both parties, and provided on a chargeable basis as defined in the G-Cloud Pricing Document.

Scaling

Independence of resources
Nelson+ is a cloud native application. Its modular design enables scalability, allowing the service to adapt to varying demand through load balancing and horizontal scaling techniques.
The service can be deployed in most cloud service providers and is architected to operate within agreed capacity parameters, using standard cloud mechanisms to manage demand and support stable, predictable service delivery.

Analytics

Service usage metrics
Yes
Metrics types
Nelson+ provides operational metrics through built-in dashboards and reports. Metrics include participant volumes, pathway progress, appointment activity and operational performance indicators to support service oversight.

An anonymised reporting dataset is available for management and monitoring purposes and is refreshed on a scheduled basis. The platform also includes built-in views and reports that allow users to access key metrics on demand to support programme monitoring, capacity planning and reporting requirements.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Users can export data from Nelson+ in several ways depending on their role and requirements. End users may export selected datasets directly from the application where permitted. Full dataset exports are provided on request via the support team to ensure appropriate governance and data protection controls are applied.

Export methods, scope and formats are agreed with the customer on a case-by-case basis, taking into account the intended use of the data and applicable security requirements. All exports are performed using secure transfer mechanisms.
Data export formats
  • CSV
  • Other
Other data export formats
Structured export formats (where agreed)
Data import formats
  • CSV
  • Other
Other data import formats
Structured export formats (where agreed)

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Nelson+ provides a service availability target of up to 99.9%, measured over the agreed service period. Availability commitments, measurement methods and service hours are defined within the Service Level Agreement agreed with each customer.

Where availability levels are not met, service credits or other contractual remedies are applied in accordance with the terms of the agreed Service Level Agreement.
Approach to resilience
Nelson+ is built using a cloud-native architecture designed to provide resilience and fault tolerance. The service is hosted on cloud infrastructure configured with redundancy across multiple availability zones to reduce the risk of single points of failure.

Standard cloud resilience mechanisms, monitoring and alerting are used to maintain service continuity. Backup and recovery processes are in place to protect customer data and enable service restoration where required. Resilience controls are reviewed as part of operational and change management activities.
Outage reporting
Nelson+ uses automated monitoring to detect service disruptions or degraded performance. When an outage or significant incident is identified, the support team is alerted and investigates in line with incident management procedures.

Customers are informed of service outages through agreed communication channels, typically via email notifications. Updates are provided as appropriate until the issue is resolved, in accordance with the incident response and communication arrangements defined in the Service Level Agreement.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Access to the Nelson+ platform is controlled using role-based access control, ensuring users can only perform actions appropriate to their assigned roles and responsibilities. Authentication mechanisms include username and password credentials, with support for multi-factor authentication where configured.

Where required, identity federation with an existing identity provider may be supported by agreement. For specific integration scenarios, access can also be restricted through dedicated network connections. Authentication controls are applied consistently to ensure that only authorised users are able to access the platform.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Nelson+ follows documented information security policies and processes designed to protect the confidentiality, integrity and availability of information. These policies align with recognised security standards and applicable data protection legislation, including GDPR.

Security governance is overseen by a designated security lead with organisational authority, supported by defined roles and responsibilities across the organisation. Policies are communicated to staff and embedded within operational and development activities.

Compliance is supported through access controls, staff awareness activities, incident management procedures and regular review of security risks. Security matters are escalated through established reporting lines, and policies are reviewed periodically to maintain effectiveness.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Nelson+ operates defined configuration and change management processes to control changes across the platform. Configuration items and application components are version-controlled, with changes tracked throughout their lifecycle.

Proposed changes are assessed for functional and security impact prior to implementation. Changes are reviewed by peers before being merged, with security considerations taken into account. Developers receive security awareness training to reduce the risk of introducing insecure code.

Automated security and quality testing is performed prior to release to identify potential vulnerabilities and defects, and change activities are documented to support traceability and ongoing platform stability.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Nelson+ applies defined vulnerability management processes to identify, assess and address security risks affecting the platform. Vulnerability information is monitored from recognised sources, including public vulnerability databases such as CVE, supplier security advisories and cloud provider notifications.

Identified vulnerabilities are assessed based on severity, exploitability and potential impact. High-severity vulnerabilities are addressed within 15 days of identification, with remediation actions, including patching or mitigation, prioritised according to risk and implemented in line with internal change management procedures and operational considerations.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Nelson+ uses automated monitoring mechanisms to analyse application and network activity logs and identify potentially suspicious behaviour or unauthorised access attempts. Monitoring rules and alert thresholds are configured to support timely detection of security-relevant events.

When potential security events are detected, alerts are raised to authorised operators, who investigate and take appropriate action in accordance with defined incident management procedures. Response actions are initiated within 72 hours of detection in the worst-case scenario, with prioritisation based on risk and potential impact.
Incident management type
Supplier-defined controls
Incident management approach
Nelson+ follows defined incident management procedures to respond to security and operational incidents. Common incident scenarios are documented and handled through established support and escalation processes.

Users report incidents by contacting the support team through agreed channels. Incidents are logged, investigated and managed according to priority and impact. Incident updates and reports are provided to customers in line with contractual and regulatory requirements.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Amtivo Group Limited T/A British Assessment Bureau Ltd.
ISO 9001 accreditation date
Thursday 11 December 2025
What the ISO 9001 doesn’t cover
The certification applies to the quality management system governing service delivery, implementation, support, and operational processes.

Design and software development activities are covered within the ISO 9001 scope of the parent company.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
C95eb9db-8bb6-4ee8-9178-32ddc34e9559
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at compliance@nelson-plus.org. Tell them what format you need. It will help if you say what assistive technology you use.