Skip to main content

Help us improve the Digital Marketplace - send your feedback

SOCIALOPTIC LTD

MilestonePlanner

A cloud-native project management platform designed for public sector delivery. Facilitates complex milestone tracking, hybrid Agile/PRINCE2 governance, and real-time portfolio reporting. Securely collaborate across departments and teams with built-in audit trails, automated risk management (RAID), and delivery forecasting. Fully compliant with UK data residency and accessibility standards.

Features

  • Real-time Milestone Tracking: Interactive timeline charts with automated RAG-status.
  • Hybrid Governance Framework: Seamlessly switch between Agile and PRINCE2 approaches.
  • Automated Dashboards: Instant reporting on project status and progress.
  • Portfolio Management (PPM): Cross-project visibility for department-wide resource tracking.
  • Centralised RAID Logs: Proactive Risk, Action, Issue, and Dependency management.
  • Secure Stakeholder Collaboration: Role-based access (RBAC) with secure external sharing.
  • Automated Audit Trails: History of changes for transparency and compliance.
  • Interoperable API: Connects with Teams, Slack, and legacy ERP systems.
  • Delivery Forecasting: Predictive analytics to identify milestone slippage.
  • Mobile-First Design: Accessible and responsive for field-based project teams.

Benefits

  • Increased Accountability: Clear milestone and task ownership reduces delivery delays.
  • Simplified Collaboration: Share and track projects, workstreams and actions.
  • Reduced Overhead: Automated reporting saves hours of manual data collection.
  • Enhanced Security: UK-hosted data with Cyber Essentials Plus certification.
  • Public Sector Compliance: Meets WCAG 2.2 AA accessibility requirements.
  • Improved Decision Making: Real-time data visualisation for senior leadership.
  • Scalable Growth: Flexible licensing from small teams to entire departments.
  • Knowledge Transfer: Supports internal capability building via intuitive UI.
  • Social Value Alignment: SME provider supporting employment and sustainability.
  • Proven Reliability: 99.9% uptime SLA with dedicated UK-based support.

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@socialoptic.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 3 2 8 4 9 0 5 3 3 4 1 8 6 1

Contact

SOCIALOPTIC LTD Caalie Ellis
Telephone: 0203 393 6591
Email: sales@socialoptic.com

About your service

Service categories

Applications

Collaborative

  • Team collaboration
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
No
System requirements
  • Working internet connection
  • Supported browser

User support

Email or online ticketing support
Yes
Support response times
Within 4hrs of receipt within office hours
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Tested using validation tools and manual testing
Onsite support
Yes, at extra cost
Support levels
SocialOptic prides itself on providing friendly and effective customer service and support. Standard support hours are from 8am to 6pm Monday to Friday, excluding bank and public holidays. The service is available and monitored on a 24x7 basis, via the SocialOptic service assurance
infrastructure, and support requests can be raised electronically 24x7. The support service includes telephone, email, web-based and in-app support for all issues and queries. Calls are handled by our highly skilled staff, and call severity will be categorised under the following three levels: Severity 1 – Complete loss of service affecting multiple users. Response time <30 minutes. Severity 2 – Partial loss of service affecting a minority of users. Response time <60 minutes. Severity 3 – Issue affecting and individual user. Response time < 4 hours. We provide a named support contact for each
account, so that there is someone familiar with the particular use case, and able to answer questions within the organisational context.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
The on boarding process is managed according
to PRINCE 2 project management principles or
Agile, according to customer
preference. SocialOptic allocates a named
contact to provide support, who will work with
you to understand your objectives and
requirements, and build a milestone-based
project plan that will include the process for golive. SocialOptic provide user documentation that
assumes no prior experience, including a
"Getting started" guide. The platform is intuitive
and online/telephone training sessions are
conducted directly with users, supported with pdf
documentation. Post launch, the account team
are available to answer any questions or provide
support to ensure successful implementation of
the system. Optional tailored web-based or onsite training is available for groups. There is an
optional import service, to automate importing of
existing data, and our support staff are on hand
to help with questions.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
CSV export or via the API.
End-of-contract process
Users can remove their own user accounts, or
accounts can be disabled (locked) via an administrator account. Users can export data as text CSV (comma separated variable) files, with
descriptive headers, prior to deleting their
account. Data is exported over a secure TLS
encrypted link, using a standard web browser.
Exporting of data is freely available via the web
interface. Data is also available via the REST API
(Application Programming Interface), in JSON
format. High volume requests may be rate
limited. Key data may also be exported in PDF
format, as reports. Our team are available to help
with off-boarding, and there is no charge for
exporting data. At the end-of-contract all user
accounts and user data will be removed from live
systems within 7 days, and expired from backups
by rotation, within 30 days.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Adapts to mobile screen size and input features.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
A fully featured and easy to use interface with built-in documentation.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Fully tested using both automated and manual
testing and feedback from a user panel of
assistive technology users. Testhing includes
desktop screenreader software including JAWS,
Dragon, VoiceOver, NonVisual Desktop Access
(NVDA) and ChromeVox.
API
Yes
What users can and can't do using the API
The API allows for creating and disabling user
accounts. SurveyOptic APIs allow users and
application developers to create, update and
delete items in SurveyOptic. APIs are secured
by API keys and protected by configuration. Both
REST and WebHook APIs are available. Users
can create and manage surveys, add and update
responses, access analytics and reports.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • ODF
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The look and feel, branding, fonts, prompts,
questions and reporting colour schemes can all
be customised. Customisation is configured via
the web-based editor. Any user with appropriate
user permissions can customise their instance or
survey.

Scaling

Independence of resources
Each user is handled in an independent process, with separately managed memory and processor resources. A resource scheduling algorithm limits the maximum resources allocated to a specific user thread, protecting other threads from resource starvation.

Analytics

Service usage metrics
Yes
Metrics types
Number of users Number of plans, workstreams
and milestones
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
NCSC approved service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
All user data is easily exportable in common and open formats including CSV export, RSS feed, calendar feed, PDF reports, and via APIs
Data export formats
  • CSV
  • Other
Other data export formats
  • RSS
  • PDF
  • XLXS
  • Calendar
  • APIs
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
SocialOptic has extensive operational
experience, and has been running Software as a
Service platforms for over 15 years. All systems
are monitored 24x7 and target a 99.999% availability level, by using redundant systems
with automated switch over. There are no
scheduled maintenance windows that are
excluded from the SLA, and SocialOptic operates
a "zero-downtime" methodology for system
updates. Should availability fall below the target
SLA, a support request can be raised to obtain a
pro rata refund for any outage over 30 minutes.
Availability is measured to the edge of the data
centre, and does not cover users' Internet Access
or third party remote systems.
Approach to resilience
Primary, secondary and tertiary facilities are
used, with redundant mirroring. Further details
available on request.
Outage reporting
Public status page

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
User credentials are used to secure
management interfaces and support channels
and provide strong authentication. All
communications make use of session level
encryption to protect confidentiality and integrity.
Access controls are subject to regular review, as
part of the overall security policy, and scanning
and penetration testing is used to increase
assurance.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
IASME and Cyber Essentials Plus
Information security policies and processes
Information Security is a board level
responsibility, and is a standing agenda item at
all board meetings. Security policies and
procedures are regularly reviewed. SocialOptic
meets the requirements of Cyber Essentials and
is IASME certified, operating the core controls of
the ISO27001 standard. We adhere to the model
of the Cabinet Office Security Policy Framework
and implement the CESG Cloud Security
Principles and the requirements of new GDPR
legislation. Change control systems are used throughout the service process, and regular
security scans are part of the release and
operate process.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
All components and system configurations are
managed through a version control system, with
a full audit log, and impact assessment process.
All newly developed software goes through a
code review, and is subject to vulnerability
scanning as part of the release process, both in
development and in the live environment.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
SocialOptic operates a distributed patch
management and monitoring system. All
operating system patches and enhancements
are automatically applied to production systems,
with an automated rollback where required. This
ensures that updates are applied in a regular,
timely manner, with the minimum impact to
service. SociaIOptic operates regular scans for
vulnerabilities and malware, together with log
auditing. SocialOptic subscribes to the relevant
advisory feeds for OS and major software
components and monitors emerging threats
through engagement with vendors, CERTS,
specialist groups and community partners.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
SocialOptic's protective monitoring process logs
all user session activity, backup status and
suspicious device boundary activity. Logs are
collected, analysed for potential compromises or
inappropriate use, and archived. Where incidents
are identified, the Incident Management Process
is followed, and remedial action taken, if
required.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
SocialOptic has a defined Incident Management
Process. This includes Incident identification,
Incident logging, Incident categorisation, Incident
prioritisation, Initial diagnosis and Escalation. It is
a closed loop process including resolution and
communication throughout the lifecycle of the
incident. Global incidents are reported via the
status page & public feeds, while individual user
incidents are communicated via the user's
preferred communications channel.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
UKAS
ISO/IEC 27001 accreditation date
Thursday 11 September 2025
What the ISO/IEC 27001 doesn’t cover
Nothing - Whole Organisation accreditation
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
UKAS
ISO 9001 accreditation date
Thursday 11 September 2025
What the ISO 9001 doesn’t cover
Nothing - Whole Organisation accreditation
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
0607c008-3452-44a7-9cdd-ebdcd62cdde5
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
A12a7e37-91c8-40b0-931c-2744cad6b901
Other security certifications
Yes
Any other security certifications
  • NHS Data Guardian
  • IASME Cyber Assurance

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@socialoptic.com. Tell them what format you need. It will help if you say what assistive technology you use.