TOPdesk - ITIL Enterprise Service Management Software (ITSM / ESM)
TOPdesk’s award-winning SaaS software helps organisations effectively manage their complete ITSM/ESM operation catering for IT Service Desks, Services Teams, straight through to fully fledged ESM or Shared Service Centres.
The standardised, user-friendly software helps optimise the quality of the organisation's overall service operation, for both customers and end-users.
Features
- ITIL verified for Service Management practices
- Native Artificial Intelligence to support AI-assisted working
- Easily configured no-code / low-code Workflows and Automation Engine
- RESTful API to facilitate standard and bespoke integrations
- Full CMDB and Asset Tracking Capabilities
- Continuously developed to provide modern look-and-feel and latest features
- Codeless designers for Service Catalogues and Self-Service Portal
- Dashboards for out-of-the-box and custom reporting
- Native Knowledge Base for end-users and agents
- Supported across any device, including iOS and Android apps.
Benefits
- Supplier guided implementation to embed best-practice
- Workflow and integration capabilities to embed automation
- Standardised Enterprise Service Management capabilities to increase collaboration
- Asset and SLA tracking to ensure compliance and timely resolutions
- Shift-left approach to free up time for service teams
- Supplier and contractor management for alignment with third-parties
- Demonstrable ROI through self-serve automation and process improvement
- Enabling compliance with regulations like GDPR and other security standards
- UK Support and hosting as standard
- Easily configured to provide future scalability
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 3 1 3 8 3 5 7 8 0 0 2 0 1 0
Contact
TOPDESK UK LIMITED
TOPdesk UK
Telephone: +44 (0)20 7803 4200
Email: info@topdesk.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Education
- Public Order and Safety
- Police
- Defence
- Social Security Administration
- Adult Social Care
- Children's Social Care
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
Scheduled maintenance tasks are performed at any time during the maintenance window, which is between 22:30 and 03:00 in your chosen time zone.
Updates to SaaS environments occur during the maintenance window, and usually result in around 5 minutes of unavailability. - System requirements
- Browser access - Edge, Chrome, Firefox, Safari
User support
- Email or online ticketing support
- Yes
- Support response times
-
For High Priority P1 tickets, the response time is 15 minutes and for Normal Priority tickets, the response time is 8 hours Monday-Friday.
An emergency SaaS team are available 24/7 for any high priority SaaS related tickets. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
-
Keyboard navigation: Users can navigate all services via the keyboard.
Screen reader support: Content is compatible with screen readers using ARIA live regions.
Alt attributes: Images within the widget are accompanied by descriptive alt text.
Text scalability: The widget content adapts to text magnification.
Clear focus indicators: Focused elements are visually distinct.
Device adaptability: The widget adjusts seamlessly to different device orientations. - Web chat accessibility testing
-
The widget supports keyboard navigation and screen readers. However, the use of iframes may cause navigation challenges in some browsers. This is a browser limitation and beyond our direct control.
- Onsite support
- Yes, at extra cost
- Support levels
-
TOPdesk’s standard support offers 24/7 access to the Customer Self-Service Portal, as well as telephone support which is available Monday-Friday 08:30 – 17:30.
As well as this, Support can be accessed via email and chat. Support is included as part of the annual subscription cost.
P1 - High Priority - 75% resolution within 120 minutes - 99% Resolution within 1 day.
P2 - Normal Priority - 75% resolution within 1 day - 95% resolution within 3 days.
Premium support, 24/5, is available on the Excellent package.
Customers are also assigned an Account Manager.
TOPdesk has an in-house SaaS team that deal with all SaaS queries, SaaS infrastructure is monitored 24/7. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
TOPdesk implementations are led by customer requirements and guided by TOPdesk’s expertise. Using the train the trainer approach, combined with the option of dedicated one to one or group training sessions, the consultant will work in partnership to map the desired processes into the solution using Best Practice techniques. At the end of the onboarding process, customers will be equipped with the knowledge to maintain and manage the solution independently with support on-hand when needed.
As well as training during the implementation, TOPdesk provides customers with access to resources such as manuals, guides, webinars, blogs, training videos and more.
Consultancy is available onsite or as remote sessions. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- Other
- Other documentation formats
- Video
- End-of-contract data extraction
-
We offer a default and easy way to retrieve data from our software. Customer databases and attachments can be downloaded at any time via TOPdesk environments by an authorised user.
After terminating a contract, we keep data for 30 days and remove it automatically after this period. To ensure that data is completely deleted, we have an automatic system with a built-in control mechanism for the deletion. We also have a monitoring system that actively scans folders, databases and live environments for data that should have been removed.
If data has not already been downloaded, customers can contact TOPdesk Support to request a copy. Up to 30 days after terminating a contract, one of a customer’s nominated contacts can request your data through our Self-Service Portal. Upon this request, we will send the data as soon as possible through a secure connection. All data comes in a regular file format. - End-of-contract process
- At the end of a contract, customers can extract their data at no extra cost.
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The Self-Service Portal provides feature parity on a mobile device, as the solution is designed to be fully mobile responsive.
The back-end provides a clean and slimmed down feature-set, for example excluding configuration settings, and provides full feature parity for working on tasks associated with Incidents, Requests, Change and Operational (Maintenance) Activities. - Service interface
- Yes
- User support accessibility
- EN 301 549
- Description of service interface
- The system has been designed to be as user-friendly as possible with clean, simple GUIs, dynamic searching across the tool and clear overviews for reports and dashboards. Users can multitask in a tabbed interface with multiple cards open if desired. Both the Self-Service Portal (SSP) and Operator side of the tool have been designed with ease of use in mind and are icon driven to create a simple and fluid user experience. Each side of the tool can be configured, whether the layout and branding of the SSP or the shortcuts and visibility of information on the Operator side.
- Accessibility standards
- EN 301 549
- Accessibility testing
- Customer testing has been undertaken using real-life use case scenarios.
- API
- Yes
- What users can and can't do using the API
-
TOPdesk's API allows customers and third-parties to create links with the tool freely.
The API can create or amend data within the solution, with the various functionalities listed below.
TOPdesk provides documentation with examples of API queries at https://developers.topdesk.com.
Links to General areas of TOPdesk, the Knowledge Base, Reservations Management, Services, Change Management, Asset Management, Operations Management, Supporting Files, the Self-Service Portal and tasks are available in the ever-expanding examples. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
TOPdesk is effortlessly customisable using code-free designers and settings.
The Service Catalogue is fully configurable by adding custom tiles, providing customers with a user-specific catalogue of available services. Colours, branding and terminology are all chosen by the organisation, as well as visibility controls.
Templates for Assets are completely customisable too, ensuring an organisation can capture exactly the information needed, per Asset type. These templates are completely code-free and are designed using a drag-and-drop designer.
Additional custom widgets can be added to the operator’s homepage. Each operator can configure their homepage with specific widgets and shortcut icons. Operators can build, customise and schedule reports using all the available fields in the TOPdesk suite.
An unlimited number of custom alerts, categorisations, statuses and other information can be created in the tool. In addition to standard fields in the tool, 60 additional fields, within two additional tabs, for each functional card are available.
TOPdesk allows customisable permission controls which are set at person/group, categorisation and location levels, allowing administrators to limit, extend and tailor user functionality. This can be done by a user with the necessary permission controls.
Customers are free to create custom templates, forms, workflows and more, achieved using code-free designers.
Scaling
- Independence of resources
- Customer environments are isolated from other customers to ensure optimal available resources. TOPdesk also operates a fair-use policy to ensure environments are not affected.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Customers can request metrics from TOPdesk Support. Metrics that are commonly asked for by customers are Number of calls logged/ resolved, Frequent Callers and duration reports. SaaS uptime reports are also available and can be scheduled to be sent out. SaaS uptime reports measure the uptime in service window, outside of the service window and a 24/7 average.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Using native functionality, exporting data can be achieved using integrated reporting and overview functionalities, including XLS and CSV file formats. The API and OData feed can also be used to extract data, such as for further use with BI tools.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- .ics
- Any attachments
- .eml
- Data import formats
-
- CSV
- Other
- Other data import formats
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
TOPdesk aims for an uptime of 100%. For updated information on Availability and Continuity please visit https://page.topdesk.com/saas-information#availabilityandcontinuity.
Several measures ensure the availability of your TOPdesk SaaS environment:
- Our redundant infrastructure ensures that a failing part does not affect availability.
- TOPdesk is installed on virtual machines that can be instantly transferred to another server, should a server fail.
- The TOPdesk database has a primary and secondary database server, ensuring availability in case of a database server failure.
- Several proxy servers in a load balancing set-up ensure heavy traffic does not cause your TOPdesk environment to become unreachable.
- Automated deployment of servers from a CMDB ensures failing servers can be quickly recreated. - Approach to resilience
-
The TOPdesk SaaS infrastructure is built with resilience in mind. Failure of a component within the infrastructure is mostly unnoticeable by our customers. This provides the 24/7 standby team with the means to intervene before our customers notice any disruptions.
- Hardware includes industry standard redundancy on all critical components, such as power supplies, storage devices and network components.
- Hosting services include redundant power circuits with UPS and independent data paths to main internet exchange points.
- Virtualisation technology provides failover functionality on multiple levels, taking away downtime in case of system maintenance or replacement.
- Database and file storage mirroring provides instant failover capabilities without data loss or downtime in case of database server failure. - Outage reporting
-
TOPdesk has a 24/7 monitoring system on all TOPdesk SaaS environments and servers. The monitoring system verifies health metrics for every TOPdesk environment, like the (internal and external) availability, database connection, and search index availability. Servers are also tested on relevant metrics, like availability, CPU usage, memory usage, and available disk space.
Should the monitoring system detect a problem, TOPdesk operators are immediately notified. During the night, a 24/7 standby shift ensures issues are quickly resolved.
Issues affecting multiple TOPdesk environments are published on our status page (status.topdesk.com) and via the Self-Service Portal. You can also verify the monitoring results on our portal, and (if desired) immediately schedule follow-up actions like a restart of your TOPdesk environment, or submit a ticket for our Support team.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to the TOPdesk's software is granted on a 'need to have' basis and is linked to personal network accounts which are linked to permission groups in Active Directory. From within TOPdesk, extensive permission groups and filters are used to ensure users only see the information they are authorised to.
In addition, password, lockout and Single Sign-On policies are pushed to all TOPdesk domain users using a group policy. - Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- SOC2
- Information security policies and processes
- TOPdesk has an internally published Information Security Policy governed by the COBIT framework. Regular security awareness training is carried out internally. Information security is evaluated twice a year. Before employees are allowed access to TOPdesk SaaS systems, additional training and a certificate of conduct is required (e.g. DBS checks). Training includes (but is not limited to) security responsibilities and procedures for handling customer data.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- TOPdesk's Change Advisory Board examines and evaluates any new Requests for Change that are raised internally. Whilst evaluating, there are several grounds on which decisions are based: budget allocation, the potential risks involved in changing services and the effort required. The process' objectives are: to ensure changes in IT are dealt with in a structured and controlled manner, to implement the necessary changes in such a way that disturbances/deviations from the service level are minimal and to determine the effect a Change can have on service delivery.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Possible threats identified by:
- Periodic internal security assessment sessions
- Input from external penetration and vulnerability testing partners.
- Encouraging customers to perform independent testing and sharing results with us
- During development using input from sources like OWASP lists
- Automated patch process which ensures recent patch levels, mitigating known vulnerabilities automatically
Patches deployed as quickly as possible and are included in the annual subscription. Given that TOPdesk's development process follows Continuous Deployment, rolling software back to a previous version is fast and it is simple to rectify bugs that are noticed (as small releases are performed frequently). - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Potential threats to services are detected using daily Penetration Tests and by recognising Security Incidents (such as Incidents raised concerning exploits, cross-site-scripting, security leaks, unauthorised access, confidential information being made available to unauthorised users or if a virus scanner has given an alert on a file in a TOPdesk installation). These Incidents are treated with the highest priority and will be communicated to affected customers via a communication strategy determined by TOPdesk's Head of Support as soon as possible (within 15 minutes).
- Incident management type
- Supplier-defined controls
- Incident management approach
- Within TOPdesk's Incident Management process, a pre-defined Incident Process flow exists for common first and second line Incidents. Users can report Incidents through telephone (Monday - Friday during business hours), email or via our Support Portal (24/7/365). Incident types, statuses, durations and target dates, priorities and what would be registered as a 'Major Incident' are all defined within the Incident Management process. Incidents are defined as: questions, malfunctions, bugs, Service Requests and product feedback. Incident reports are available on request by contacting our Support team.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We offer a 30-day trial of our system free of charge with no credit card required. This trial provides an Enterprise version of our system with all modules and functionalities included.
- Link to free trial
- Www.topdesk.com/en/try-online/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 10%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Schellman Compliance, LLC (Schellman)
- ISO/IEC 27001 accreditation date
- Tuesday 11 November 2025
- What the ISO/IEC 27001 doesn’t cover
- TOPdesk's datacentre hosting partner, Microsoft, is certified for its Azure datacentres.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 4027da00-eec0-4cb5-a004-3fc3ebf96bf1
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
- SOC Type 2 Assurance Report
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Introducing transparency to pay and reward processes
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-