OnePlan
OnePlan is a cloud-based portfolio, programme and project management platform that connects strategy to delivery. It consolidates planning, financial, resource and delivery data across existing tools, giving leaders clear visibility, stronger control and better decision-making, without forcing disruptive changes to established ways of working
Features
- Cloud-based strategic portfolio and delivery management platform
- Supports Agile, waterfall and hybrid delivery models
- Highly configurable structures, workflows and data fields
- Integrated financial planning and cost management
- Portfolio-level resource demand and capacity modelling
- Native Microsoft Project Desktop bi-directional integration
- Broad tool integrations via OneConnect integration engine
- Embedded Power BI reporting and analytics
- Role-based security and configurable access controls
- AI-enabled insights and decision support
Benefits
- Single source of truth across portfolios and projects
- Improved alignment between strategy and delivery
- Reduced disruption through integration with existing tools
- Better portfolio prioritisation and investment decisions
- Improved resource utilisation and capacity visibility
- More reliable, timely management information
- Reduced manual reporting and data consolidation
- Increased confidence through consistent governance
- Scalable solution supporting organisational change
- Secure platform aligned to public sector requirements
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 6 6 6 9 8 5 9 7 1 2 9 8 7 0
Contact
PROGRAM PLANNING PROFESSIONALS LIMITED
Mark Sorrell
Telephone: 020 7462 0100
Email: uk.info@migso-pcubed.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Project and portfolio management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- This is Software as a Service so there are limited service constraints. There are no hardware requirements, just an approved browser. Microsoft Excel is expected to data interchange and Power BI for reporting but these are recommended, not essential. Planned Maintenance is typically "silent" i.e. completed without any downtime. In the case of this being needed administrators are notified in advance, times are scheduled for lower use and it would be unusual for any downtime to last more than 5 or 10 minutes.
- System requirements
-
- Approved browser
- Microsoft Active Directory for secure connections
- A Microsoft 365 environment
User support
- Email or online ticketing support
- Yes
- Support response times
- There are agreed response times depending on the severity of the issue and whether Premium Support has been purchased. While the technical support team operate EST working hours (Mon-Fri) there are UK based resources which can be contacted for immediate issues and to see if ticket is required. Technical support is not available at the week-ends
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
There are 4 levels of severity defined (Urgent, High, Medium, Low) and these are client assessed. Response to support queries raised online are not charged.
Typically resolution of incidents is managed by email and / or chat conversations.
It is possible to purchase Premium Support which, apart from other benefits provides faster initial incident response times and video /remote access support.
It is unlikely on-site support would be required as this is a Software as a Service product. There is a UK based OnePlan team and if required they could be engaged on-site at additional cost.
It is also possible to gain additional support for deployments and post deployment support can be obtained via an associated PPM Deployment Service. The specific coverage for support e.g. access will be agreed on a client by client basis. Services for a range of PPM related skills can be provided - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
There are multiple options:
OnePlan provide full functionality training which can be remote or on-site
1. We can provide functionality and process training or functionality
2. training aligned to specific processes both remotely and on-site
3. There is full online documentation available
4.There is a OnePlan Academy which provide role or function based training via a series of focused videos.
In addition we would normally provide hypercare and drop-in sessions as part of our deployment service - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Project level data can be extracted via Microsoft Project directly and there are multiple points in the application for data to be exported out of the solution, typically in Excel formats
- End-of-contract process
-
At the end of a customer initiated conclusion all access will stop and it is assumed all data required will have been exported prior to that date. All data will be retained for a further 90 days and after this time will be permanently deleted.
If the contract is terminated by OnePlan, then they will notify customers sixty days in advance and deliver all back up and database files to the client and provide a functional environment for sixty days.
These are all standard terms and conditions and they are all viewable online here: https://oneplan.ai/terms/ - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
All onboarding documentation is available online for all users. It can be accessed directly, via links, or via one of the defined learning pathways.
Offboarding is not a core capability and relies on client specific processes being undertaken. This can be supported with additional documentation or workflows.
Data is not typically changed during offboarding unless the service is being terminated.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Different views can be created to make reporting and viewing easier plus there is a specific mobile application targeted at work maangement
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The interface to the system is via an approved browser only
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service is aligned to WCAG requirements. All features are available online and views can be adjusted (text size, colour) to make access easier. Training is delivered by videos with both audio and script being available.
- Accessibility testing
- Not publicly available
- API
- Yes
- What users can and can't do using the API
-
There is the ability to create workflows using an API specifically for Microsoft Power Automate.
There is an OData API provided for reporting e.g., from Microsoft PowerBI.
In addition there is a full REST API that allows programs to create, amend and delete entities within the solution or execute standard application processes. This is a fully open API and is documented here: https://my.oneplan.ai/ApiHelp - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Dd
Scaling
- Independence of resources
- This is a cloud based and shared infrastructure service. Microsoft Azure will automatically scale for peaks to ensure consistency of performance but, as always, performance experienced by the user can be impacted by a number of other factors, including workstation performance and network issues.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- OnePlan
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
-
Data can be exported from multiple places within the solution. The specific export options will depend on the specific export but will always include Microsoft Excel and may include Microsoft Word and Excel.
The OData connection with Microsoft PowerBI provides a different channel to extract data i.e. to PowerBI and then, typically, to Microsoft Excel. - Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- .xlsx
- .mpp
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
-
OnePlan has SOC2 Type II Compliance which defines a minimal level of security for confidentiality, security and integrity.
All data is stored within the Microsoft Azure architecture which provides minimum 256 bit encryption and has many certifications including GDPR and EU Model Clause certification.
Regular penetration tests are conducted and results can be made available on request.
In addition to Microsoft backups, separate nightly backups are taken and stored in geo-located Microsoft Azure storage.
Availability and resilience
- Guaranteed availability
- OnePlan is expected to achieve a minimum of 99.95% availability, with backup, disaster recovery and resilience plans in place. Outside this SLA there are Service Credits applied to compensate
- Approach to resilience
- This data is available on request
- Outage reporting
- Outages both planned and un-planned are notified by email to registered owners of the solution. Planned outages can also be notified in the service itself
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- For interfaces access is controlled via an API key. Support users must have a valid account (and licence) and access is controlled via Role Based Authentication
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- No
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- W
- Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Any bug fix is implemented into OnePlan QA environment and tested thoroughly using standard regression testing before being pushed into Production. This includes security testing
All client environments use code from OnePlan’s cloud-based Production environment.
Microsoft conducts regular penetration testing to improve Azure security controls and processes. In addition, OnePlan performs our own penetration testing and code scans before and after every production update - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Every OnePlan service is monitored 24 hours a day, 7 days a week, 365 days a year using monitoring services provided by Microsoft Azure. The following services are monitored:
PING
Static HTTP
Processor and Memory Usage
Hard Disk Usage
If a test fails, OnePlan applies the following escalation:
Within 5 minutes during business hours, 8:00 a.m.-6:00 p.m. (PST) Monday to Friday or 30 minutes at other times
Azure uses integrated deployment systems to manage the distribution and installation of security updates for Microsoft software to help protect systems from unknown vulnerabilities - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Monitoring and logging: Centralized monitoring, correlation, and analysis systems manage the large amount of information generated by devices within the Azure environment, providing continuous visibility and timely alerts to the teams that manage the service. See Azure infrastructure monitoring.
Update management: Azure uses integrated deployment systems to manage the distribution and installation of security updates for Microsoft software to help protect systems from unknown vulnerabilities.
Antivirus: Azure software components must go through a virus scan before deployment.
Penetration testing: Microsoft conducts regular penetration testing to improve Azure security controls and processes. - Incident management type
- Supplier-defined controls
- Incident management approach
- Configuration, incident response and protective monitoring are all demonstrated in Microsoft’s compliance with the ISO-27001 information security standard.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- This is a full system, provided with one of a range of user selected configurations together with data to enable all features
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Saturday 18 May 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Monday 1 September 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5e375087-3e21-4292-b145-bf6e7d7a3997
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 6e23110e-84ce-4fb6-a1f9-bb4a4e727af0
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
-