Skip to main content

Help us improve the Digital Marketplace - send your feedback

SmartyGrants UK

SmartyGrants

SmartyGrants is a cloud-based grants management system that streamlines the entire grants lifecycle - from application through assessment and contracting to reporting. Our secure, intuitive platform offers no-code form building and programme/round management, configurable workflows, and real-time data tracking, reducing administrative effort, ensuring compliance, and delivering reporting across funding programmes.

Features

  • Secure, scalable, cloud-based: ISO 27001 certified, UK hosted
  • End to end workflow automation: streamline application assessment, contracting, reporting
  • Configurable forms and workflows: no-code and customisable to programme needs
  • Integrated reporting and analytics: real time dashboards and exportable reports
  • Collaborative assessment tools: support multi reviewer scoring and defendable decisions
  • Applicant self service portal: accessible, user friendly and branded
  • Role based access control: ensure secure, auditable user permissions management
  • APIs: connect securely with finance, CRM and BI systems
  • Contacts management and mailouts functionality
  • Comprehensive audit trails: track all actions for accountability and compliance

Benefits

  • Reduce administration: automate tasks across grant lifecycle
  • Improve auditability: record and audit every action
  • Streamline funding delivery to get funds to recipients efficiently
  • Generate real time data insights and reports to improve performance
  • Enhance applicant experience through user friendly portal
  • Enforce consistent policies and enforcement of eligibility rules
  • Collaborate efficiently across onsite and offsite teams
  • Integrate effortlessly with finance, CRM etc systems with APIs
  • Ensure data security: protect sensitive information with certified infrastructure
  • Remove IT burden through cloud hosting, security and regular enhancements

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@smartygrants.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 8 4 8 7 5 5 3 7 1 0 5 5 8 9

Contact

SmartyGrants UK Vicky Coutts
Telephone: +44 7736 256 936
Email: sales@smartygrants.co.uk

About your service

Service categories

Applications

Production and operations

  • Other operations

Service industry and public sector operations

  • Healthcare
  • Education
  • Public Order and Safety
  • Police
  • Defence
  • Social Security Administration
  • Adult Social Care
  • Children's Social Care
  • Other
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
None, SmartyGrants is a web-based platform that operates 24x7 and is compatible with all major device types and browsers.
System requirements
Web Browser (including Chrome, Safari, Firefox, Opera, Edge)

User support

Email or online ticketing support
Yes
Support response times
1 business day
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
No
Support levels
Technical support is available to all customers (including administrators, as well as external applicants and assessors) as part of the Annual Access Fee (no additional charges).

Support hours are 9am to 5pm Monday to Friday (excluding public holidays) for ordinary email-based support, with phone-based support available for critical incidents. We respond to all requests within 8 business hours during our regular support window. A dedicated account manager is not part of our ordinary offering but can be provided as an add-on if required.

We also provide online training (via our Learning Management System) and documentation (via our Help Hub).

A standard support package is included with all subscriptions (no tiered pricing applies for standard support). Our standard offering includes technical support plus training webinars, applicant site design, self-service training resources, self-service help documentation and ongoing email support. Additional paid services - such as bespoke training, managed services, dedicated account management and premium features - are available on request.

SmartyGrants engages a managed service provider (MSP) to manage our production systems. Systems are monitored 24x7. We warrant that SmartyGrants will be available at least 99.9% of each calendar month. Please refer to our Support and Maintenance Policy for details and exclusions.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
The SmartyGrants onboarding experience has been tried and tested over more than 15 years by more than 830 customers.

New customers are assigned an Implementation Manager, who develops an implementation plan, informed by process mapping, that includes an outline of required activities, personnel, milestones and recommended training. The Implementation Manager coordinates liaison with other SmartyGrants teams (to facilitate skinning, migration, training, solution architecture etc), as well as overseeing account set-up, form building, report building, workflow set-up, testing, etc. They will guide the client towards launch of their first programme, and coordinated handover to the "BAU" team for ongoing support and training.

New users are trained in all aspects of core functionality to develop the necessary skills for effective use of SmartyGrants. The objective of the onboarding programme is to help users become confident, independent system users. SmartySkills, our self-paced online Learning Management System, provides immediate access to a self-guided, modular training experience, and one-on-one training is available as well.

Detailed documentation is available via our Help Hub.

Both SmartySkills and the Help Hub are available to all SmartyGrants UK customers as part of the Annual Access Fee. Implementation is costed to suit the needs of the customer.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract term we will make all customer data we hold available for downloading through SmartyGrants for a further 30 days. Ordinarily (and unless otherwise agreed) we will then permanently delete the customer data. Customers may ask us to retain all customer data in full for an additional period after that 30-day period. However, if we do so, it may be subject to additional fees and separate terms and conditions.

Customer data is available for download via document or spreadsheet reports (snapshot reports, default reports and custom reports), Analytics exports (if this feature is available on the account at the end of the contract term), XMLs, PDFs and native file format for attached files.
End-of-contract process
At the end of the contract term, contracted services continue as normal until the end of the Annual Subscription Period. Upon notice of termination of the contract, we initiate a structured exiting/offboarding process with authorised customer representatives.

The exiting process comprises confirming and communicating schedules for data extraction (as per the end-of-contract data extraction process), deactivation of service, and data deletion in line with legal and contractual requirements. For 30 days after the expiry of the the Annual Subscription Period (or for an agreed additional period), we will provide support and guidance to authorised customer representatives regarding data extraction. This includes ongoing access to SmartyGrants staff and support resources and documentation to assist with data extraction, access to all customer data through the data extraction methods, and compliance with all relevant privacy and data-protection obligations.

We provide ordinary end-of-contract services, as described above, at no additional cost. Additional costs may apply to other services, such as the provision of customised data extracts or other forms of post-transition assistance.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Currently the system is accessible and usable on mobile browsers but does not provide mobile-responsive layout (ie may require scrolling etc). A new mobile-responsive Applicant Portal is under development anticipated for release late 2026 which will provide full functionality with mobile-friendly layout.
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
Browser based interface, with specific user portals for Grant Applicants and Grant Managers.
Accessibility standards
WCAG 2.2 A
Accessibility testing
We are committed to delivering a seamless and accessible experience for all users, including people with disabilities.

The SmartyGrants applicant site complies with the Web Content Accessibility Guidelines (WCAG) version 2.2 at Level A. Full mobile responsiveness is the only remaining requirement needed for us to meet Level AA under WCAG 2.2 – this is a key focus area of our applicant portal rebuild, which is due for completion end of 2026.

WCAG assessment is undertaken by Vision Australia.

Our Customer Support team is in constant contact with system users and we take into account and, wherever possible, action feedback and requests from users experiencing accessbility difficulties.
API
Yes
What users can and can't do using the API
API interfaces are available, including an Applications API (read/update grant application information), a Payments API (create/read/update payment information), a Contacts API (read contact), a Bulk Export API, and an OData API (data access for BI / data warehousing). A developer guide is provided to clients who opt to use APIs, and testing environments are available if required. User security restrictions are enforced in line with the user-defined access settings, and some rate limits apply.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
SmartyGrants is a highly flexible and configurable system that can be set up and managed by users in a large variety of ways. Users can, for example, build their own forms (including branching), design their own form fields, configure workflows, design and schedule/rerun reports, build dashboards, specify an outcomes schema, customise client-facing portal text and email text, and so on. Many other configuration options are available, allowing the vast majority of needs to be met without external assistance. SmartyGrants works closely with customers during implementation and beyond to help map requirements and processes to leverage existing out-of-the-box platform capabilities.

We are also able to work with customers to scope product enhancement/ configuration options, if required, to meet needs unmet by our out-of-the-box functionality. Most enhancements are released to all platform users after deployment. Custom development is carried out by SmartyGrants staff, and built within the core codebase, but can be driven by 'instance settings' to only apply to relevant account(s), meaning that it not degrade the ability of customers to keep receiving out-of-the-box upgrades and product enhancements.

Scaling

Independence of resources
SmartyGrants provides a 99.9% SLA, supported by 24x7 monitoring and alerting to detect and respond to any system degradation, with regular performance and load testing done at 50% above peak utilisation and ongoing tuning and capacity management. We also utilise an external "Virtual Waiting Room" for grant rounds expected to receive high volumes of traffic, and have DDoS protection and other security controls in place to detect and respond to suspicious or malicious activity that may impact the platform.

Analytics

Service usage metrics
Yes
Metrics types
System availability and performance data is available via status.smartygrants.co.uk. Notice of regular patch release and maintenance events are also provided through this site. Users can subscribe to receive updates. The response time shown on the Status Page is measured in milliseconds. Our in-built Analytics feature also provides rich Business Intelligence for business operational metrics which can be defined and configured by the user.
Reporting types
Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
User can self-configure Word, Excel, or PDF reports of data in the system, use the Bulk Export feature (via user interface or API) to export data and attachments, and/or use the OData API to extract data for use in BI / data warehousing applications. An automated weekly SFTP backup of all data and attachments is also available as an option.
Data export formats
Other
Other data export formats
  • XML
  • XLSX
  • DOCX
  • PDF
  • JSON
  • OData
Data import formats
Other
Other data import formats
  • Historical grant information migration, via our Managed Services team
  • File attachments of all major filetypes supported also

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
SmartyGrants provides a 99.9% uptime SLA, with service credits available in case of any breach.
Approach to resilience
SmartyGrants operates a high-availability configuration, with multiple nodes across multiple AWS Availability Zones (AZs), with balancing and automated failover. Data is stored in multi-AZ database, with real-time replication, automated failover, with additional protection of snapshots taken every 5 mins allowing restore with minimal data loss even in the most extreme (and unlikely) failure scenarios.
Outage reporting
Public dashboard - status.smartygrants.co.uk. Customers can subscribe to receive alerts about incidents and any upcoming planned outages.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Customer Administrators can configure users and roles/permissions for their instance/programs, which are enforced via all access channels (web interface, API, etc).
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
Information security policies and processes
SmartyGrants adheres to comprehensive information security policies and processes governed by its ISO/IEC 27001:2022-certified Information Security Management System (ISMS), and complies with Data Protection Act 2018 and UK GDPR, with documented policies and procedures governing personal data handling.

System Security Plan, Incident Response Plan, Business Continuity Plan, Disaster Recovery Plan, and Third Party Service Provider documents are availalble which outline the controls that protect customer data across system security, access management, incident handling, continuity planning, and supplier assurance.

Our internal Information Security Policy covers information classification, data protection, human resources security, acceptable use, access control, legal and regulatory compliance, incident management, and data retention and destruction. These policies are reviewed at least annually and whenever material changes occur.

The ISMS is overseen by the Chief Technology Officer, with dedicated roles for security governance, operational assurance and continuous improvement. Security risks are managed through a formal risk assessment and treatment process, recorded in a maintained risk register, and prioritised by likelihood and impact. Quarterly ISMS reviews and annual internal and external audits ensure ongoing compliance.

Secure development practices are embedded across the software development lifecycle, including security training, peer-review, and vulnerability management incorporating industry best practice and automated tooling.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
SmartyGrants applies a formal ISO/IEC 27001:2022-aligned Change Management Process for all system, software, infrastructure, configuration, third-party, and policy updates. Every change undergoes assessment, approval, testing, documentation, and security impact review. Code changes are peer-reviewed and supported by automated testing, while infrastructure changes use infrastructure-as-code and configuration management tools to ensure consistent, auditable AWS deployments. No changes are deployed directly to production outside the approved process. All components are documented, version-controlled, and tracked in a ticketing system with full audit trails for compliance, and regular ISMS reviews confirm ongoing security and proper maintenance.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
SmartyGrants operates a formal vulnerability and patch management process supported by automated scanning tools including CloudHealth by VMware, SonarQube, OWASP Dependency-Check, and Docker component scanning. Infrastructure and application vulnerabilities are identified, prioritised by criticality, remediated, and tracked through closure, with high-risk or zero-day issues patched outside normal schedules and compensating controls applied when needed. The Security team monitors government, industry, and vendor advisories, assessing threats for likelihood and impact and recording them in the risk register. Supplier security reviews, Business Continuity simulations, Disaster Recovery tests, and security impact assessments for all system changes help prevent and mitigate emerging risks.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
SmartyGrants is monitored 24×7, with on-call personnel responding immediately to alerts. Automated monitoring detects availability, performance, errors, unusual activity, and excessive or suspicious requests, which may trigger automatic IP blocking. Event, application, and web-server logs are retained for seven years, protected from tampering, ingested into AWS CloudWatch in near real time, and archived in a separate AWS account inaccessible to staff. When a potential compromise is detected, the Incident Response Plan is activated for rapid investigation, containment, credential regeneration, and remediation. Affected customers are notified promptly in line with regulatory requirements, and all incidents undergo documented post-incident review.
Incident management type
Supplier-defined controls
Incident management approach
SmartyGrants maintains predefined procedures for common incidents (including compromised credentials, suspicious logins, performance issues, and infrastructure faults) defining containment actions, communication steps, and escalation paths to ensure consistent, timely response. Incidents are logged, assessed immediately, and managed under the Incident Response Plan. Affected customers and, where relevant, authorities are notified as required by UK privacy and cybersecurity laws, and service disruptions are communicated through the SmartyGrants UK Status Page. Written incident reports may be issued after resolution. All incidents undergo post-incident review, and annual Business Continuity and Disaster Recovery testing validates and improves response processes.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We offer a free trial account that allows users to evaluate SmartyGrants. It includes access to all areas of the system, Help Hub documentation and training. Trial users are not permitted to send Mailouts, or receive applications. The trial lasts up to sixty days but can be extended.
Link to free trial
https://manage.smartygrants.co.uk/signup

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2.5%
Between £500,001 and £1,000,000
2.5%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Global Compliance Certification Pty Ltd
ISO/IEC 27001 accreditation date
Tuesday 25 July 2023
What the ISO/IEC 27001 doesn’t cover
The scope of this certification applies to SmartyGrants products and services, and relevant parts of Our Community’s business relied upon to support the operations of SmartyGrants
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
49a38118-8fe8-409b-bf9f-eea0afd67adc
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@smartygrants.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.