SMART Planning Monitoring
SMART is a spatial/GIS recording, monitoring, analysis and reporting solution for housing monitoring, including Section 106, Employment, Sustainability and Transport, Biodiversity Net Gains (BNG), and configurable forward planning monitoring reports and trajectories.
SMART includes sophisticated reporting/GIS for Plots, Sites, Existing/Proposed-Residential and Non-Res, Open Space, Polygons, Geographical/Custom-GIS, Superseding, Open Space etc.
Features
- Full planning permission lifecycle
- Create sites and manage allocations inc. plots
- Facilitates monitoring reports and housing trajectories
- Manages existing/proposed res, non-res, policies, constraints, sustainability, power, transport
- Section 106 (S106), Site Build Estimates, SHLAA, Brownfield etc
- Algorithms for quality and accuracy including superseding
- Import data and integrate with GIS map servers/data
- GIS enabled for advanced GIS based reporting
- Per Permission Biodiversity Net Gain summary information recording and reporting
- Extensive analytics and reporting
Benefits
- Provides definitive forward planning monitoring view
- Expands information access and data sharing throughout the organisation
- Supports best practice and MHCLG guidance
- Streamlines administration creating synergies and efficiencies
- Improves monitoring processes and querying
- Reduces the burden of monitoring reports and tracjectories
- Extensive analytics and reporting
- Interfaces with existing systems for data exchange
- Designed with monitoring, analysis and reporting as central purpose
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 6 6 8 2 8 2 3 2 2 6 6 6 2 4
Contact
CDPSoft Limited
Keirron Goffe
Telephone: 07746 141547
Email: enquiry@cdpsoft.com
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Advanced and predictive analytics
- Location and geospatial data management and analytics
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- Supported browsers are the latest releases of Microsoft Edge, Chrome and Safari. We use reasonable endeavours to ensure the service is available 24/7 (excluding scheduled downtime or downtime due to prior user consent, user error, maintenance, nightly reboots, important security patches and regional network/power outages We use reasonable endeavours to meet a 99% uptime. The service window is 09:00 to 17:00 Monday to Friday excluding English Public Holidays. Support outside of the service window is not included. The Customer provides first-line support to end users. Planned server maintenance for five minutes every night and 2-hours once a month (at weekends).
- System requirements
-
- Modern computer with a minimum of 2GB of RAM.
- Stable internet connection over 10mbps download speed.
- Minimum browser, latest versions of Microsoft Edge, Chrome or Safari.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support calls are acknowledged within 1-2 hours.
Depending on the type of question and the priority, responses are normally within the same working day if received before 16.00 hours on a weekday (excluding Public Holidays). - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
All customers are provided with an account manager who is the key liaison for any non-support related matters. Additional professional services can be purchased at the day rate noted in our pricing for this listing.
The helpdesk is available from 09:00 to 17:00 Monday to Friday excluding English Public Holidays. Major Error; The entire software or a full module is prevented from being run. Serious Error; Failure of a major feature or serious performance degradation. We aim to respond within 4-hours, provide a temporary fix within 1 working day and a permanent fix within 5 working days. Other Error; Any other error that does not fall within the Major or Serious category. We aim to respond within 4-hours, provide a temporary fix within 5 working days and a permanent fix within 10 working days. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
SMART is an off the shelf Cloud solution hosted in the UK and requires little to no local IT resource for setting up which enables a rapid start-up time. SMART is usually integrated with the customer's GIS map server provider. Alternatively, GIS layers can be loaded at extra cost.
Buyers select the relevant Cloud components which determine the level of buyer resource required.
Component set-up times range from one to nine days, carried out remotely by our consultants. Further customisation can be included based on the day rate noted in our pricing for this listing.
A context-based online help facility allows the Customer to view help text or guidance notes against each major area and field group.
Remote training is available for up to five users at the day rate noted in our pricing for this listing.
Where data migration is required we use our integrated proprietary migration tool and provide support from our technical consultants at the day rate noted in our pricing for this listing. - Service documentation
- No
- End-of-contract data extraction
-
At any time up until 30 days after the termination of the Agreement upon request and payment of the relevant charges, for preparing the data as detailed in the Pricing Document, we will prepare a copy of the Oracle database containing all data owned by the buyer (with proprietary stored procedures removed). We will provide the extract within 15 days of such request on a CD-ROM or other large data storage media.
The buyer is responsible for arranging secure collection or transfer of the data. Any other data migration assistance is chargeable at the day rate noted in the Pricing Document. - End-of-contract process
-
The minimum term for SMART is 36 months. Notice must be given 90 days before the end of each36-month term.
At any time up until 30 days after the termination of the Agreement upon request and payment of the relevant charges, for preparing the data as detailed in the Pricing Document, we will prepare a copy of the Oracle database containing all data owned by the buyer (with proprietary stored procedures removed). We will provide the extract within 15 days of such request on a CD-ROM or other large data storage media. The buyer is responsible for arranging secure collection or transfer of the data. Any other data migration assistance is chargeable at the day rate noted in our pricing for this listing
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed via a supported web browser. Supported browsers include the latest release of Microsoft Edge, Chrome and Safari.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The service is compliant with the above standard as far as is practicable to do so with a web-based service of this nature. No testing has been carried out on the current version.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
The system can be customised using custom fields and custom GIS within the system. This is at Site and Plot level.
The reporting suite also includes a full custom report module for users to create their own reports.
Scaling
- Independence of resources
-
SMART provides an optimally designed hosted environment underpinned by the following (neither of which are required to be purchased or maintained by the buyer): An Apache Tomcat Application Server running on a virtual machine in a private cloud, An Oracle database server.
Both are subjected to continuous proactive capacity monitoring and planning, ensuring that extra memory and disk space can be allocated dynamically and at short notice to match the resources required as usage of the solution increases.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Real-time management information is available through the fully integrated reporting tool.
Key Functions of the reporting tool: Extensive Standard Reports with Search Filters, Report Criteria, Custom Reports, Report Scheduling Engine, Report Distribution, Multiple output types including PDF, Word, Excel, CSV and XML, Master and Sub-Reports. - Reporting types
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
For data exporting, our integrated, purpose-built reporting tool can produce Excel, CSV and PDF reports from data held within the system. The reporting tool includes standard reports with filters, multiple output types and document data injectors. Buyers can build their own report templates using integrated reporting tool.
In addition to the above, customised batch jobs and additional report templates can be created by our technical consultants at the day rate noted in the pricing document. - Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Buyers shall normally be able to access the Hosting Service 24/7. We use all reasonable endeavours to ensure the service is available 24/7 (excluding scheduled downtime, downtime with prior user consent, downtime caused by user error, maintenance, nightly reboots, important security patches, regional network/ power outages). We use reasonable endeavours to meet a 99% uptime, measured as a full calendar month average. The service window is 09:00 to 17:00 Monday to Friday excluding English Public Holidays. Support outside of the service window is not included.
- Approach to resilience
-
SMART is designed to deliver 99% availability. The Cloud application is provided from a Tier III data centre.
A summary of the accreditation in place are, ISO 27001, Information Security, ISO 9001 for Quality Management, ISO 14001 for Environmental Management, BS OHSAS 18001 for Occupational Health and Safety.
Further information regarding our approach to resilience can be supplied on request. - Outage reporting
-
As a Cloud application, the availability of the hosted environment is fundamental to the continued use of the system.
We directly monitor all aspects of application performance and availability. The monitoring tools used are proactive and check application availability on a 24/7 basis and all errors generated during customer usage are automatically emailed directly to our help desk.
Our help desk issues email alerts and regular updates to the Customer’s agreed designated personnel until the service is restored.
Any outage is thoroughly investigated. A summary of findings, remedial actions and any lesson learned is shared with customers.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Interfaces and support channels Requests for support and changes are coordinated and managed through a specific and controlled channel. The buyer can designate named users who will be given user administration permissions and direct access to the help desk via email and phone line. An additional registration process is completed for users given access to the help desk.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- The Cloud application is provided from an ISO 27001 Information Security and ISO 9001 Quality Management Tier III data centre, including ISO 14001 for Environmental Management, ISO 45001 for Occupational Health & Safety. Both administrative offices and the data centre hold ISO 27001 certification. Administrative offices have Cyber Essentials. Certifications include Cyber Essentials Plus. Administrative office operations run under the ISO 27001 ISMS with Cyber Essentials controls. Compliance uses internal audits, management reviews, external assessments, staff training, and monitoring. Policies follow confidentiality, integrity, availability principles. Code adheres to OWASP. No customer data is stored outside of the ISO 27001 data centre. We have robust processes to ensure major issues within the hosting environment are resolved, including switching the database to a secondary hosting site to maintain continuity. Availability is continuously monitored. Our hosting provides 24/7 monitoring across all infrastructure layers, from firewalls to servers. Expert ISO27001-compliant Oracle database monitoring operates through dedicated processes running 24/7 at defined intervals. We monitor all aspects of application performance and availability. Best-in-class monitoring tools verify application availability on a 24/7 basis, including external checks outside the firewall, and all errors during customer usage are automatically routed to our Helpdesk for resolution.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
CDPSoft operates Project Management processes in accordance with PRINCE2. Our structured Project Management Methodology (CDP PMM) manages projects in a logical organised way, following defined steps. It consists of a set of distinctive management processes, covering the activities from setting off the project on the right track, controlling and managing the project’s progress, to completion of the project.
SMART is a customisable cloud solution and requires very little configuration. There is only one production version of SMART at any time, except during a rollout period for a new version. The underlying configuration is controlled by property settings and customisable options. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We use long-established processes that incorporate best practice for the technology stack. This is kept up-to-date by the diligence of a technical director, the DBA team (database), secure data hosting team (architecture) and Independent Security Consultancy (vulnerability and penetration testing). There are separate annual processes for independent external software threat assessment. In addition, every year a full external vulnerability assessment and penetration test is completed by a CREST approved third-party. The data centre team commission regular external independent IT Health Checks to identify potential vulnerabilities or areas for improvement.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- The hosted infrastructure is protected by hardware firewalls and full antivirus protection including host intrusion measures. Denial of Service (DoS) monitoring runs continuously and measures are taken automatically to deal with the threat (e.g. blocking of IP addresses) according to industry best practice. Host Intrusion Prevention (Host IPS) for Servers, monitors and blocks unwanted and suspect activity and threats. It utilises multiple methodologies, including signature and behavioural intrusion prevention, a system firewall, and application-blocking controls with automatic vulnerability shields and security content. 24/7 monitoring and alerting is in operation.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Ncidents are managed through automated alerting using Nagios, infrastructure alerting and a help desk. The majority of incidents are detected by Nagios which sends real-time alerts to our team. Incidents are typically resolved without end customers being aware of their occurrence. Standard working practices exist for incident types such as application errors, memory/CPU thresholds or security/network. The data centre also has layers of monitoring for security incidents, network connectivity and power. Users can report incidents to a help desk (email/telephone). Incidents are closed through normal help desk ticket procedures. Larger incidents have a written response signed off by senior management.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12.5%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO
- ISO/IEC 27001 accreditation date
- Tuesday 11 March 2025
- What the ISO/IEC 27001 doesn’t cover
- The ISO/IEC 27001 certification covers the full company scope as stated on the certificate.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- F7ecb1ec-25f8-4eb9-bfea-383279c2da4e
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 14001, Data Centre - issued October 2024 (LRQA)
- ISO 9001, Data Centre - issued October 2024 (LRQA)
- ISO 45001, Data Centre - issued October 2024 (LRQA)
- ISO/IEC 27001, Data Centre - issued October 2024 (LRQA)
- Cyber Essential Plus, Data Centre - issued November 2025
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-