MilestonePlanner
A cloud-native project management platform designed for public sector delivery. Facilitates complex milestone tracking, hybrid Agile/PRINCE2 governance, and real-time portfolio reporting. Securely collaborate across departments and teams with built-in audit trails, automated risk management (RAID), and delivery forecasting. Fully compliant with UK data residency and accessibility standards.
Features
- Real-time Milestone Tracking: Interactive timeline charts with automated RAG-status.
- Hybrid Governance Framework: Seamlessly switch between Agile and PRINCE2 approaches.
- Automated Dashboards: Instant reporting on project status and progress.
- Portfolio Management (PPM): Cross-project visibility for department-wide resource tracking.
- Centralised RAID Logs: Proactive Risk, Action, Issue, and Dependency management.
- Secure Stakeholder Collaboration: Role-based access (RBAC) with secure external sharing.
- Automated Audit Trails: History of changes for transparency and compliance.
- Interoperable API: Connects with Teams, Slack, and legacy ERP systems.
- Delivery Forecasting: Predictive analytics to identify milestone slippage.
- Mobile-First Design: Accessible and responsive for field-based project teams.
Benefits
- Increased Accountability: Clear milestone and task ownership reduces delivery delays.
- Simplified Collaboration: Share and track projects, workstreams and actions.
- Reduced Overhead: Automated reporting saves hours of manual data collection.
- Enhanced Security: UK-hosted data with Cyber Essentials Plus certification.
- Public Sector Compliance: Meets WCAG 2.2 AA accessibility requirements.
- Improved Decision Making: Real-time data visualisation for senior leadership.
- Scalable Growth: Flexible licensing from small teams to entire departments.
- Knowledge Transfer: Supports internal capability building via intuitive UI.
- Social Value Alignment: SME provider supporting employment and sustainability.
- Proven Reliability: 99.9% uptime SLA with dedicated UK-based support.
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 3 2 8 4 9 0 5 3 3 4 1 8 6 1
Contact
SOCIALOPTIC LTD
Caalie Ellis
Telephone: 0203 393 6591
Email: sales@socialoptic.com
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- No
- System requirements
-
- Working internet connection
- Supported browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 4hrs of receipt within office hours
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Tested using validation tools and manual testing
- Onsite support
- Yes, at extra cost
- Support levels
-
SocialOptic prides itself on providing friendly and effective customer service and support. Standard support hours are from 8am to 6pm Monday to Friday, excluding bank and public holidays. The service is available and monitored on a 24x7 basis, via the SocialOptic service assurance
infrastructure, and support requests can be raised electronically 24x7. The support service includes telephone, email, web-based and in-app support for all issues and queries. Calls are handled by our highly skilled staff, and call severity will be categorised under the following three levels: Severity 1 – Complete loss of service affecting multiple users. Response time <30 minutes. Severity 2 – Partial loss of service affecting a minority of users. Response time <60 minutes. Severity 3 – Issue affecting and individual user. Response time < 4 hours. We provide a named support contact for each
account, so that there is someone familiar with the particular use case, and able to answer questions within the organisational context. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
The on boarding process is managed according
to PRINCE 2 project management principles or
Agile, according to customer
preference. SocialOptic allocates a named
contact to provide support, who will work with
you to understand your objectives and
requirements, and build a milestone-based
project plan that will include the process for golive. SocialOptic provide user documentation that
assumes no prior experience, including a
"Getting started" guide. The platform is intuitive
and online/telephone training sessions are
conducted directly with users, supported with pdf
documentation. Post launch, the account team
are available to answer any questions or provide
support to ensure successful implementation of
the system. Optional tailored web-based or onsite training is available for groups. There is an
optional import service, to automate importing of
existing data, and our support staff are on hand
to help with questions. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- CSV export or via the API.
- End-of-contract process
-
Users can remove their own user accounts, or
accounts can be disabled (locked) via an administrator account. Users can export data as text CSV (comma separated variable) files, with
descriptive headers, prior to deleting their
account. Data is exported over a secure TLS
encrypted link, using a standard web browser.
Exporting of data is freely available via the web
interface. Data is also available via the REST API
(Application Programming Interface), in JSON
format. High volume requests may be rate
limited. Key data may also be exported in PDF
format, as reports. Our team are available to help
with off-boarding, and there is no charge for
exporting data. At the end-of-contract all user
accounts and user data will be removed from live
systems within 7 days, and expired from backups
by rotation, within 30 days. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Adapts to mobile screen size and input features.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- A fully featured and easy to use interface with built-in documentation.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Fully tested using both automated and manual
testing and feedback from a user panel of
assistive technology users. Testhing includes
desktop screenreader software including JAWS,
Dragon, VoiceOver, NonVisual Desktop Access
(NVDA) and ChromeVox. - API
- Yes
- What users can and can't do using the API
-
The API allows for creating and disabling user
accounts. SurveyOptic APIs allow users and
application developers to create, update and
delete items in SurveyOptic. APIs are secured
by API keys and protected by configuration. Both
REST and WebHook APIs are available. Users
can create and manage surveys, add and update
responses, access analytics and reports. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- ODF
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The look and feel, branding, fonts, prompts,
questions and reporting colour schemes can all
be customised. Customisation is configured via
the web-based editor. Any user with appropriate
user permissions can customise their instance or
survey.
Scaling
- Independence of resources
- Each user is handled in an independent process, with separately managed memory and processor resources. A resource scheduling algorithm limits the maximum resources allocated to a specific user thread, protecting other threads from resource starvation.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Number of users Number of plans, workstreams
and milestones - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- All user data is easily exportable in common and open formats including CSV export, RSS feed, calendar feed, PDF reports, and via APIs
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- RSS
- XLXS
- Calendar
- APIs
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
SocialOptic has extensive operational
experience, and has been running Software as a
Service platforms for over 15 years. All systems
are monitored 24x7 and target a 99.999% availability level, by using redundant systems
with automated switch over. There are no
scheduled maintenance windows that are
excluded from the SLA, and SocialOptic operates
a "zero-downtime" methodology for system
updates. Should availability fall below the target
SLA, a support request can be raised to obtain a
pro rata refund for any outage over 30 minutes.
Availability is measured to the edge of the data
centre, and does not cover users' Internet Access
or third party remote systems. - Approach to resilience
-
Primary, secondary and tertiary facilities are
used, with redundant mirroring. Further details
available on request. - Outage reporting
- Public status page
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
User credentials are used to secure
management interfaces and support channels
and provide strong authentication. All
communications make use of session level
encryption to protect confidentiality and integrity.
Access controls are subject to regular review, as
part of the overall security policy, and scanning
and penetration testing is used to increase
assurance. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- IASME and Cyber Essentials Plus
- Information security policies and processes
-
Information Security is a board level
responsibility, and is a standing agenda item at
all board meetings. Security policies and
procedures are regularly reviewed. SocialOptic
meets the requirements of Cyber Essentials and
is IASME certified, operating the core controls of
the ISO27001 standard. We adhere to the model
of the Cabinet Office Security Policy Framework
and implement the CESG Cloud Security
Principles and the requirements of new GDPR
legislation. Change control systems are used throughout the service process, and regular
security scans are part of the release and
operate process. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
All components and system configurations are
managed through a version control system, with
a full audit log, and impact assessment process.
All newly developed software goes through a
code review, and is subject to vulnerability
scanning as part of the release process, both in
development and in the live environment. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
SocialOptic operates a distributed patch
management and monitoring system. All
operating system patches and enhancements
are automatically applied to production systems,
with an automated rollback where required. This
ensures that updates are applied in a regular,
timely manner, with the minimum impact to
service. SociaIOptic operates regular scans for
vulnerabilities and malware, together with log
auditing. SocialOptic subscribes to the relevant
advisory feeds for OS and major software
components and monitors emerging threats
through engagement with vendors, CERTS,
specialist groups and community partners. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
SocialOptic's protective monitoring process logs
all user session activity, backup status and
suspicious device boundary activity. Logs are
collected, analysed for potential compromises or
inappropriate use, and archived. Where incidents
are identified, the Incident Management Process
is followed, and remedial action taken, if
required. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
SocialOptic has a defined Incident Management
Process. This includes Incident identification,
Incident logging, Incident categorisation, Incident
prioritisation, Initial diagnosis and Escalation. It is
a closed loop process including resolution and
communication throughout the lifecycle of the
incident. Global incidents are reported via the
status page & public feeds, while individual user
incidents are communicated via the user's
preferred communications channel. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- UKAS
- ISO/IEC 27001 accreditation date
- Thursday 11 September 2025
- What the ISO/IEC 27001 doesn’t cover
- Nothing - Whole Organisation accreditation
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- UKAS
- ISO 9001 accreditation date
- Thursday 11 September 2025
- What the ISO 9001 doesn’t cover
- Nothing - Whole Organisation accreditation
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 0607c008-3452-44a7-9cdd-ebdcd62cdde5
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- A12a7e37-91c8-40b0-931c-2744cad6b901
- Other security certifications
- Yes
- Any other security certifications
-
- NHS Data Guardian
- IASME Cyber Assurance
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-