Moodle Learning Management System (LMS) Development, Hosting, Maintenance, and Optional Support
SkillSet provides expert Moodle learning management system maintenance and support, including data backups, seamless updates, and UK-based assistance. Optimise your Moodle LMS experience, whether self-hosted or leveraging our secure infrastructure. Our ISO-certified practices ensure reliability and allow for custom API, plug-in, and code development to tailor your Moodle LMS solution.
Features
- Secure UK-based Moodle LMS development, hosting, support, maintenance and migration.
- Moodle LMS SaaS eliminates the requirement for in-house software management.
- ISO:27001, Cyber Essentials Plus and code scanning ensure Moodle security.
- Monitoring and reporting provide insights into your Moodle LMS usage.
- Access UK-based Moodle experts for timely support and problem resolution.
- Customise Moodle LMS design and branding to your organisation's identity.
- Use blended learning through Moodle's versatile features.
- Integrate Moodle with external systems including payments, authentication and HR.
- Moodle LMS offers multilingual support for global audiences including Welsh.
- Proven customer satisfaction, feedback reflects excellent quality, communication, and reliability.
Benefits
- Leverage open-source Moodle for a cost-effective learning management system.
- Optimise your Moodle investment with our hosting and expert support.
- Reduce Moodle LMS risks with proactive monitoring and support.
- 100% of Moodle learning management system customers recommend SkillSet.
- Customise your Moodle LMS with bespoke plug-in development.
- Leverage Moodle LMS plugins for additional features and integrations.
- Avoid vendor lock-in with complete Moodle data backups.
- Real-time Moodle reporting for use and progress tracking.
- 24*7*365 support available for Moodle LMS customers.
- No licence cost with a Moodle learning management system.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 9 0 6 6 2 5 9 1 9 2 0 6 7 8
Contact
SKILLSET LIMITED
Jemma Greener
Telephone: 01252810061
Email: contracts@skillset.co.uk
About your service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Core Human Resources Applications
- Talent Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No known constraints.
- System requirements
-
- Internet access
- Current web/mobile browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Priority 0/1 issues: we provide a response within 1 hour during business hours (8:30am-5:30pm, UK time excluding bank holidays), with restoration and resolution targets depending on priority. Priority 2/3 issues: response within 2 working days during business hours (8:30am-5:30pm, Mon-Fri excluding bank holidays). Resolution timeframes are detailed in Appendix A of our standard Ts and Cs. Weekend and 24/7 support is available at additional costs.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Web chat needs to be tested in the context in which it is deployed and we test with each individual client.
- Onsite support
- Yes, at extra cost
- Support levels
-
We offer three service levels for Moodle LMS hosting, maintenance, and support:
1. Standard Package: customer support available to nominated customer administrators during UK working days (08:30–17:30, excluding weekends and public holidays). Support is provided via email, telephone, and our Freshdesk Support Portal.
2. Premium Package: customer and end-user support available to all site users during UK working days (08:30–17:30, excluding weekends and public holidays), providing helpdesk assistance for login issues, navigation, and content access. Support is provided via email, telephone, and our Freshdesk Support Portal.
3. Out-of-Hours Support: customisable extended hours, including 24/7/365. This option is available with our Premium package and supports customers requiring continuous service or international coverage. Support is costed with our day rate of £575, according to expected usage and response requirements.
All requests are logged and tracked through Freshdesk, ensuring full visibility of response and resolution times. Support includes incident, problem, and event management; service monitoring; and configuration assistance.
A dedicated account manager and technical developer is assigned to all clients to oversee service performance, reporting, and strategic guidance. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- We prioritise a smooth user experience for both administrators and end-users. For administrators and managers, we provide tailored training options including on-site sessions, webinars, in-depth guides, and videos. These resources are customised to your specific Moodle setup, including any required templates or specifications. Moodle itself offers an intuitive design, making it accessible for most end-users without formal training. Additionally, we collaborate with you to develop user tours directly within Moodle. These tours offer step-by-step guidance through the system's key features or specific pages, aiding new users and aligning with your unique business processes. Users can access these tours at any time for a refresher. Our goal is to ensure a seamless onboarding experience for your team, empowering them to leverage Moodle effectively from the start.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- End-users can easily extract their personal data at any time (including the end of contract) using Moodle's built-in tools. This process can be automated or adjusted for manual intervention based on your preferences. Depending on your Moodle setup, users may also be able to directly download certificates and reports. At the end of the contract (or upon request), we'll provide you with a full backup of your Moodle site. This comprehensive backup includes all configuration, user data, and learning content, allowing you to replicate your Moodle site elsewhere or use it for historical reference. We can also provide reports to extract any specific data, including users, completions, course lists etc.
- End-of-contract process
- At the end of your contract, we'll provide you with a full backup of your Moodle site, including configuration, user data, and learning content. This backup is included for Standard and Premium maintenance packages, but an additional cost for Essential maintenance packages. Upon request, we can also securely archive your site using AWS (or a similar service) for potential restoration later. Restoration after the contract has ended will incur an additional cost. We'll provide source code for any custom plugins or code created for you. Further support, such as detailed specification documentation or assistance transitioning to a new supplier, is be available at an additional cost.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Moodle can be accessed via browser on desktop and mobile devices and has an official Moodle app. The desktop experience provides full functionality, including complete administration features and richer course layouts. On mobile, the interface is optimised for smaller screens, with simplified navigation and access to core learning activities; some advanced configuration and certain plugin features may be limited depending on your setup. Different versions of the mobile app are available with an annual fee and will be recharged at cost.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Moodle is a browser-based application that allows any user with an internet connection to log in and start learning immediately, with no software installation required. The interface provides a functional workspace consisting of a home page, personalised dashboard, intuitive course pages, and clear navigation menus.
Designed as a responsive web environment, it automatically adapts to any device - providing easy-to-use buttons for accessing materials, completing eLearning, and viewing progress. This flexible, user-friendly design supports online and blended learning by allowing educators to build engaging courses while giving learners a seamless, intuitive experience tailored to their needs. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Moodle's mobile app and browser application have been audited by Moodle HQ and achieved WCAG 2.1 Level AA accreditation. SkillSet understand that every Moodle site is unique due to customisations. Therefore, we will work with you to achieve the accessibility standard required (including achieved WCAG 2.2 Level AA) and prioritise pre-deployment accessibility testing for each client's site using assistive tools and test protocols. If your organisation has users who rely on assistive technologies, we're eager to collaborate with them directly to ensure optimal functionality. We've also partnered with clients and professional accessibility auditing companies for specific assessments with existing clients.
- API
- Yes
- What users can and can't do using the API
- SkillSet uses a REST API plugin to enable seamless and secure data exchange between your systems and Moodle, enhancing efficiency and automation. Users with the appropriate permissions can seamlessly integrate external systems with their Moodle LMS. We provide comprehensive documentation for standard Moodle APIs (https://docs.moodle.org/dev/Core_APIs) and define secure web service accounts to control access and tailor information for each integration. The API empowers users to automate various LMS actions like adding users, updating information, managing enrolments, tracking course completion, and manipulating grades. SkillSet also offers bespoke API integrations for custom data exchange, ensuring your systems receive the exact information needed and potentially streamlining complex processes, lowering the need for manual processes such as uploading spreadsheets of users or assigning user to groups. It's important to note that all APIs are governed by strict permissions and IP whitelisting, and standard APIs may not cover every niche scenario, potentially requiring custom development. Our team has extensive experience in Moodle integrations, including the use of third-party ETL services, and we're ready to provide the best solutions for your specific needs.
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Site administrators have full control over the site's appearance, allowing them to customise colours, fonts, and imagery to match your organisation’s branding. Users can also select their own colour schemes, including high-contrast options for accessibility. Site administrators can optimise navigation to prioritise core activities, ensuring a seamless user experience with minimal clicks. Teachers and managers can create, edit, and delete courses, activities, and programs. For certain plugins, managers have control over team structures and user options. Learners can participate in collaborative activities and create custom content either individually or in groups. Depending on the setup, site administrators may customise interfaces at the category, company, or user level. Learners have the flexibility to personalise their dashboards with widgets and adjust their notification preferences. With the appropriate training, users can access configurable reporting tools to generate insightful reports on system data. SkillSet offers custom plugin and functionality development (at additional cost) to extend Moodle's capabilities and address your organisation's unique requirements.
Scaling
- Independence of resources
- Our Moodle service is single-tenant and so each customer’s databases and web servers run on dedicated virtual machines in a separate security group. We understand use patterns with Moodle and will work with our clients to ensure that where we anticipate high use (such as launches of new course materials, mandatory training deadlines and large-scale scheduled online assessments) we can put additional resources in place. Our Moodle service can also be load-balanced and auto-scaled if required. This can save costs compared to sizing for rare worst-case scenarios.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We can build reports to show a range of usage metrics covering logins, user activity, time spent on the site etc. Reporting is entirely customisable and we work with clients to provide the information that they want.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Moodle HQ - https://moodle.com/about/
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- We use AWS for hosting and take advantage of their ability to encrypt data at rest for all elements of the service provided. Our protective monitoring processes include continuous vulnerability scanning and intrusion detection systems to identify potential compromises early.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users have two main ways to export their data. 1. End-users can easily request a copy of all their personal data directly from their Moodle profile. Once approved, they receive a text-format file. 2. For larger-scale data extractions, managers or other designated users can use reports to export user information in CSV format. These can be customised to include all required data.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- ODS
- XLS
- JSON
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- Data is always transmitted using TLS 1.2+ between servers. All data storage is on encrypted volumes. Access to the hosting environment is restricted to specific users, requires multi-factor authentication and is accessed via a VPN. We have worked with clients in different ways to provide additional data security between their network and our servers. Some clients do not make their Moodle instances accessible outside of their internal network, so we block all access and whitelist their outbound IP, and/or work with a VPN to provide access. Administration pages can specifically be whitelisted by IP.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We use the AWS Cloud Services due to its resilience and capacity. AWS commits to a monthly uptime of at least 99.95%. We offer varying levels of support, starting with UK business hours. We provide 24 hour support for business critical systems: this allows access to a member of our support staff at all times.
- Approach to resilience
- Our standard Moodle hosting prioritises swift recovery. Through nightly backups, we can restore your site to a new instance within 1 hour, minimising disruption. This approach balances resilience and cost-effectiveness for most clients. For clients whose LMS is mission-critical, we offer a fully resilient architecture. This includes load balancing, multiple web servers across AWS availability zones, distributed storage, and a resilient database solution. These ensure maximum uptime and seamless operation. This is designed and costed based on the client’s specification. We use AWS CloudWatch to monitor key metrics like CPU, storage, and memory. This allows us to detect potential issues early, proactively safeguarding your system's availability.
- Outage reporting
- AWS Cloudwatch monitors the hardware for any failure conditions or extended periods of excess load. The support team are notified when thresholds are breached. We also monitor the availability of all public web front-ends with a third party monitoring solution outside of AWS, again, immediate notifications to our support team. Currently, we do not have automatic notification of outages direct to client contacts via dashboard, or API. Customers would be notified by email.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- Moodle provides a number of authentication plugins to support ensuring the user is who they say they are. Integrations include, but are not limited to: OIDC, OAuth2, SAML, LDAP, Shibboleth, and SSO options for third party services such as Microsoft Azure AD, on-premises AD, Facebook, Google, LinkedIn, Joomla CMS and Wordpress CMS. Additional controls can be introduced including limiting retry attempts before enforced cooldown periods, IP whitelisting, anti-hammering policies, password strength, MFA and more.
- Access restrictions in management interfaces and support channels
- We prioritise secure access in management interfaces and support channels. User authentication methods can include username/password, MFA, and integration with external identity providers, all tailored to client needs. Moodle's robust role-based access control framework allows us to restrict configuration screens based on agreed user roles. Access to infrastructure management interfaces is strictly limited to authorised SkillSet personnel via VPN with multi factor authentication. Server command line/SFTP access utilises public key authentication. Our information security manager and technical director oversee permissions in accordance with our ISO 27001-accredited process, ensuring the highest security standards.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Our information security policy is provided to all staff and forms part of our ISO 27001 (2022) compliance. It covers, but is not limited to, any systems or data attached to the company’s computer or telephone networks, any systems supplied by the company, any communications sent to or from the company and any data that is owned by the company held on external systems. The company will ensure that: - information is always available to those who need it and there is no disruption to business. - confidentiality is not breached. - the integrity of information is maintained. - appropriate legal, regulatory and contractual clauses are complied with. - the management team continually improve security.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We hold ISO 27001 (2022) accreditation and manage configuration and changes through processes controlled by our quality management system. All source code is tracked within Git or Subversion as part of our continuous integration pipeline. Customers initiate changes following our formal Change Request process, and all changes undergo impact assessment and customer approval. Our approach to individual client instances allows us to make customer-specific changes without adversely affecting other clients, ensuring flexibility and tailored solutions.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We proactively assess potential threats through regular vulnerability scanning and penetration testing. We stay informed about security risks via trusted sources like the Moodle community, security bulletins, and our internal threat monitoring. We follow ISO 27001 processes for evaluating and deploying critical patches in a timely manner, with bi-monthly reviews ensuring all systems are protected. Results from penetration tests are applied across all our Moodle sites to strengthen security for everyone.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Our protective monitoring processes include continuous vulnerability scanning and intrusion detection systems to identify potential compromises early. If a potential compromise is detected, we immediately escalate the issue to our information security manager. Resolution procedures strictly adhere to our ISO 27001 approved process. We guarantee a response to all incidents within one working hour.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We follow an ISO 27001-approved process for incident management, ensuring structured and effective responses. Users can conveniently report incidents via email, phone, or a support ticket. We use predefined processes to streamline resolution. We provide customers with detailed incident reports, including response times, and discuss them during service review meetings. Our robust incident management approach is regularly assessed as part of our ISO 27001 certification.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7.5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Approachable Certification
- ISO/IEC 27001 accreditation date
- Wednesday 22 May 2024
- What the ISO/IEC 27001 doesn’t cover
- There are no material service activities delivered to customers that fall outside the certified scope.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Approachable Certification
- ISO 9001 accreditation date
- Wednesday 22 May 2024
- What the ISO 9001 doesn’t cover
- There are no material service activities delivered to customers that fall outside the certified scope.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 8860b958-116a-4b32-b205-014842ff5752
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- B38e3228-d2d5-451a-8a07-d0ba333558d9
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-