Skip to main content

Help us improve the Digital Marketplace - send your feedback

ANAPLAN LIMITED

Anaplan Planning Solution

Anaplan Supports UK public sector organisations to strengthen financial, supply chain and workforce planning with real-time forecasting, and performance insight. Anaplan can be delivered to all Public Bodies not limited to:

• Central Government
• NHS
• Local Authorities
• Arms Length Bodies
• Defence

Features

  • Real-Time Scenario Modelling
  • In-Memory Calculation Engine Hyperblock
  • Enterprise Forecasting & Reporting
  • Role-Based Dashboards and UX
  • Workflow and Colaboration Tools
  • Data Integration & APIs
  • Security & Governance Controls
  • Multi-Dimensional Modelling
  • AI and ML Capability
  • Long-Range Planning

Benefits

  • Link Finance, Supply Chain HR Operations in Single Platform
  • Create and compare multiple scenarios in real-time, demand shifts
  • Provide a single source of the truth
  • Design forward looking finance and workforce plans
  • No code platform enabling quick deployment and adoption
  • Deliver 100% spend to budget across all budgets
  • Support modelling of future budgeting needs informing strategic plans
  • Increased transparency and governance by centrally managing all assumptions
  • AI-Enhanced Forecasting to reduce bias in decision making
  • Enable visibility into outcomes from 1-Month to 10+ years

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at chris.ireson@anaplan.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 3 8 4 1 7 1 4 7 5 5 7 5 1 6

Contact

ANAPLAN LIMITED Chris Ireson
Telephone: +447765362254
Email: chris.ireson@anaplan.com

About your service

Service categories

Application Development and Deployment

AI platforms

AI life cycle

  • Data Labeling Software
  • AI Build Software
  • MLOps and Foundation Model Ops Software
  • Trustworthy AI Software

AI software services

  • Conversational AI Software Services
  • Generative AI Software Services
  • Anomaly Detection AI Software Services
  • Forecast AI Software Services
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
None
System requirements
  • Can run on any HTML5 compliant browser
  • Excel/Power Point Add-in requires Windows 8 or newer.
  • Does not require installation of any other software or plug-ins
  • Excel/Power Point Add-in requires Office 2013 or newer.

User support

Email or online ticketing support
Yes
Support response times
Email or online ticketing
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Anaplan's webchat facility enables users to speak directly with a support agent 24x7.
Web chat accessibility testing
None
Onsite support
Yes, at extra cost
Support levels
Anaplan offers two levels of support, both 24x7. The HyperCare packages take our standard platform support to the next level. These offerings combine model builder support, as well as a suite of proactive resources—to help promote adoption of the Anaplan applications. The standard support package offers: 24/7 platform support desk• Platform uptime and performance issue handling Single sign-on (SSO) setup support• and general platform inquiry support. The Hypercare offering includes: Priority queuing of support cases Quarterly end-user feedback interviews•. One-on-one model-builder support . Logging, reporting, and suggested prioritisation of end-user enhancement requests and defects. Bi-Annual application health check; covers usability assessment, performance testing, technical model health analysis, and report•. Monthly application performance reporting•. Daily application performance monitoring
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Anaplan clients are supported through a large Ecosystem of Anaplan Partners providing dedicated consultancy. In addition to on-site consultancy, clients are trained on all aspects of model building and become self sufficient by the end of the consultancy engagement. Additionally, Anaplan Partners run training courses to support the implementation and clients can get access to on-line courses, supporting documentation and access to a wealth of knowledge through the Anapedia within the Anaplan Community.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
During the thirty (30) day period following termination or expiration, Anaplan will grant a reasonable number of Authorised Users access to the Anaplan Service for the sole purpose of retrieving Client Data. Thereafter, Anaplan will delete Client’s account, including Client Data, from Anaplan’s site unless legally prohibited. These Authorised Users will be able to utilise Anaplan’s standard export functions to retrieve data.
End-of-contract process
At the end of the contract, Anaplan will deactivate the Client’s account. There is no additional charge for this process as we allow 30 days for the client to access their data.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Anaplan has received a formal accessibility audit which has given us a renewed VPAT. Our VPAT certification document assesses the Anaplan products against v2.1 of the Web Content Accessibility Guidelines (WCAG) providing an assessment against the most recent, published version of the guidelines, and those most appropriate for a rich, web-based application

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
You can operate various Anaplan features on a range of mobile devices. Anaplan is available for both IOS and Android. You can: Work with dashboards, with the exception of Dashboard Designer. Work with modules, with the exception of Blueprint mode and formula editing. Operate the Contents tab. Operate the Users area of the Settings tab, but not other settings
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
You can interact with the data in your models using Anaplan's RESTful API. This enables you to securely import and export data, as well as run actions through any programmatic way you desire. The API can be leveraged in any custom integration, allowing for a wide range of integration solutions to be implemented. Completing an integration using the Anaplan API is a technical process that will require significant action by an individual with programming experience.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can build their own models within Anaplan provided they have the appropriate builder licence rights

Scaling

Independence of resources
Anaplan models run in dedicated in-memory engines.

Analytics

Service usage metrics
Yes
Metrics types
Anaplan provides an online summary of the service level over a defined period and can provide a more detailed report of performance over a specific historical period on request.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Physical access control, complying with CSA CCM v4.0
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Exports from Anaplan can be performed directly via the user interface or via standard or configurable integration methods. Exports can be completed in industry standard formats including Excel, CSV, TXT and PDF by appropriately authorised end users.
Data export formats
  • CSV
  • Other
Other data export formats
  • TXT
  • JSON
  • XLS XLSX Excel
Data import formats
  • CSV
  • Other
Other data import formats
  • XLS XLXS Excel
  • Txt
  • CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
SLA
Anaplan's Availability SLA is 99.5%.
This SLA is contractually referenced in the SaaS Subscription Agreement (SSA).
Approach to resilience
Backups, DR plans and documentation, restore testing, and DR testing are described and tested in several controls in Anaplan's SOC 2 Type 2 report.

Each primary data center is paired with a DR data center in the same geopolitical region. Backups are are written to the DR location multiple times per day.
Data at rest encrypted AES-256.
Outage reporting
Any outage or maintenance events are reported via a publicly available status webpage and dashboard.
Customers can also subscribe to receive an update whenever Anaplan creates, updates or resolves an incident. Users can select their preferred channel of communication for recieving updates such as Email, SMS, Slack, RSS feeds

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Anaplan restricts support channel access through customer-controlled permissions, multi-factor authentication, and strict least-privilege policies for staff.

Support access to customer workspaces or models requires explicit, time-limited approval from a designated Encryption Administrator or workspace admin.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users receive audit information on a regular basis
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
Information security policies and processes
Anaplan's ISMS/security program is certified to ISO27001:2022 standards.
● Cybersecurity engineering designs are NIST (National Institute of Standards and Technology) NCP (National Checklist Program) based.
● Code security standards follow OWASP and SANS.
● Encryption methods are TLS and AES.
● Anaplan uses an Agile-based SDLC methodology.
● Auditing follows AICPA SOC1 and SOC2 standards.
● Infrastructure is hardened based on CIS standards.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Configuration and change management in Anaplan is typically run as a product-style lifecycle covering design, build, test, release, and continuous improvement, underpinned by ALM, security and governance.

Anaplan follows industry-standard secure software development and release practices to minimise vulnerabilities in new features and patches.

Code changes go through structured development, testing, and staging environments, with security reviews and regression testing before release to customers.

The platform uses continuous monitoring and regular vulnerability scanning of infrastructure and applications, so security issues can be identified and remediated quickly.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Anaplan runs regular automated vulnerability scans against its infrastructure and web application layers using industry‑standard tools and benchmarks.

Identified vulnerabilities are addressed through controlled patch and change processes.

All platform hosts follow a regular patching and maintenance routine, and servers are managed via central automation to ensure consistent, hardened configurations across environments.​

Anaplan publishes a responsible vulnerability disclosure program, giving security researchers a defined channel and guidelines to report potential issues for investigation and fix.

Results feed into internal security teams who assess severity and impact, typically aligned to standard risk ratings (e.g. critical/high/medium/low) and relevant compliance requirements.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Anaplan uses a range of industry‑leading monitoring and alerting tools to watch hardware, software performance, networks, memory and disk usage, log files, and other key metrics across the platform.​

All core services (for example firewalls, routers, switches, operating systems, and application components) produce security logs that are centrally collected and monitored as part of a “defence in depth” security architecture.​Technical Operations personnel receive real‑time alerts when serious anomalies are detected.

Aspects of incidents response programmes are tested as part of regular SOC 2 Type 2 audits, providing independent assurance over how incidents are detected, handled and documented.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
For confirmed data breaches involving client data, Anaplan commits contractually to notify the customer promptly within a defined time window.​

The Data Processing Addendum states Anaplan will notify the client within 48 hours of confirmation of a personal data breach relating to the client’s personal data.​

Anaplan then provides ongoing information and cooperation to support the client’s own regulatory and incident‑management obligations.

Anaplan’s incident response is governed by its Information Security Management System (ISMS), which is aligned with ISO 27002 and event/incident standards such as ISO 27035 and CSA CCM.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
20%
Between £2,500,001 and £5,000,000
25%
Over £5,000,001
30%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Bay Mountain Security
ISO/IEC 27001 accreditation date
Sunday 3 August 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
Yes
CSA STAR accreditation date
Friday 27 April 2018
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
N/A
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
48b76500-bbb8-440e-a346-0784dda14c08
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
  • ISO 27017
  • ISO 27018
  • ISO 27701

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Measures for making facilities used in the delivery of the contract available for community groups, education or training
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at chris.ireson@anaplan.com. Tell them what format you need. It will help if you say what assistive technology you use.