Neyo - ServiceNow Cloud Platform Licensing
Neyo provides ServiceNow SaaS licensing for UK public‑sector organisations under G‑Cloud 15 Lot 2a, supplying subscriptions for ITSM, CSM, ITOM, ITAM, CMDB, SecOps and HRSD, coordinating provisioning with ServiceNow, and separating implementation, integration and ongoing support under Neyo’s Lot 3 Cloud Support services for end‑to‑end transformation.
Features
- ServiceNow SaaS licences for IT and business services.
- Secure browser and mobile access to ServiceNow.
- Fast instance provisioning and licence allocation.
- High‑availability SaaS platform with uptime SLAs.
- Real‑time dashboards and reporting for service performance.
- Role‑based access control and audit logging.
- Standard backups, replication and disaster‑recovery.
- Flexible scaling of users and modules.
Benefits
- Reduce time to access ServiceNow capabilities.
- Simplify procurement of ServiceNow licences via G‑Cloud.
- Eliminate need to host ServiceNow infrastructure.
- Improve service quality using proven ITSM tooling.
- Enable better decisions with real‑time insight.
- Strengthen security and compliance with certified controls.
- Reduce operational risk with resilient SaaS platform.
- Build scalable foundation for future ServiceNow enhancements
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 7 1 4 4 8 3 1 6 4 3 7 2 5 6
Contact
NEYO LTD
Chirag Karnik
Telephone: 02030516390
Email: tenders@neyoltd.com
About your service
- Service categories
-
Systems Infrastructure Software
System and service management
- IT operations management
- IT service management
IT automation and configuration management
- Workload management
- Datacentre system and application control
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Service is delivered on the ServiceNow public cloud and is subject to the vendor’s standard maintenance windows and SLAs. Service availability may be temporarily affected during planned or emergency maintenance. Buyers require reliable internet connectivity, supported browsers and compatible devices. Implementation, configuration, integrations and training are out of scope for this Lot 2a licensing service and must be purchased separately under Lot 3 Cloud Support.
- System requirements
-
- A modern web browser that supports HTML5 and JavaScript.
- Reliable internet connectivity with sufficient bandwidth
- A compatible operating system (Windows, macOS, Linux, iOS, Android)
- User must have appropriate ServiceNow software licences.
- Buyer-managed endpoint security and local network controls.
- An email address for notifications and authentication
User support
- Email or online ticketing support
- Yes
- Support response times
-
We provide email and online ticketing support for ordering, licensing, billing and account-related queries. During UK business hours (09:00–17:30, Monday to Friday, excluding public holidays), queries are typically acknowledged within one business day.
Technical support for the ServiceNow platform is provided directly by the software manufacturer under the relevant ServiceNow support agreement. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- For web chat support, ServiceNow provide an AI-driven self-service virtual agent (bot) that engages users first to resolve common issues, guide troubleshooting, and surface relevant knowledge articles. If the issue cannot be resolved, the conversation is seamlessly handed over to a live support operative with full context preserved, ensuring faster resolution and an improved user experience.
- Web chat accessibility testing
- We have not carried out independent testing of the web chat functionality with users of assistive technology. The web chat capability, including the AI-driven virtual agent, is provided and maintained by the software manufacturer as part of the ServiceNow cloud platform. Accessibility testing, conformance, and ongoing improvements for the platform’s web chat interface are the responsibility of the software manufacturer and are undertaken as part of their product development and assurance processes.
- Onsite support
- No
- Support levels
-
We provide support for cloud software licensing and subscription management through a single standard support level. This includes assistance with licence selection, ordering, renewals, subscription changes, billing queries, and general account management.
Support is provided during UK business hours (09:00–17:30, Monday to Friday, excluding public holidays) via email or an online ticketing channel. There is no additional cost for this licensing and account-related support, which is included as part of the service.
Technical support for the operation of the software platform itself is provided directly by the software manufacturer under the relevant vendor support agreement. Where required, we can assist customers by coordinating and escalating issues to the software provider.
This service does not include a dedicated technical account manager or cloud support engineer. Professional services, implementation, training, and managed support services are available separately under Cloud Support (Lot 3). - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
We help users get started by providing guidance and support throughout the ServiceNow licensing and onboarding process. This includes assistance with licence selection, ordering, subscription activation, and coordination with the software manufacturer to provision access to the ServiceNow platform. Once licences are active, users receive access to the ServiceNow cloud service, including the vendor-provided documentation, online help resources, and standard onboarding materials made available by the software manufacturer.
We do not provide onsite training, platform configuration, implementation, or user training as part of this licensing service. Where required, implementation services, configuration support, training, and user enablement can be purchased separately under Cloud Support (Lot 3). - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, users can extract their data using the standard data export, reporting, and API capabilities provided directly within the ServiceNow cloud platform. Authorised customer users can export data in common formats (such as CSV or XML), subject to their roles, permissions, and licensed entitlements.
As a reseller, Neyo does not perform data extraction activities on the buyer’s behalf. We can provide guidance on available options and, where required, assist with coordination and escalation to ServiceNow for platform-level support. Data retention, deletion, and offboarding processes are governed by ServiceNow’s standard contractual terms and policies. - End-of-contract process
-
At the end of the contract, access to the ServiceNow cloud software subscriptions supplied under this service will end in line with the agreed contract terms and the software manufacturer’s standard offboarding process.
Prior to contract expiry, customers can use the platform’s standard reporting, export, and API capabilities to extract their data. Following contract termination, the ServiceNow instance is decommissioned in accordance with ServiceNow’s standard data retention, deletion, and security policies.
Neyo, as a reseller, supports the commercial close-out of the contract, including licence cessation and coordination with ServiceNow where required. Operational use of the platform and data handling are governed by the ServiceNow contractual framework. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Onboarding and offboarding documentation is provided primarily through web-based (HTML) and PDF formats supplied by the ServiceNow and supported by Neyo’s own service guidance where applicable. These documents are accessible using standard web browsers and PDF readers, support screen magnification and text resizing, and can be used with common assistive technologies depending on user settings and device capabilities.
Neyo has not carried out independent accessibility testing of onboarding or offboarding documentation. Accessibility features and compliance are managed by the software manufacturer as part of the cloud software platform and its associated documentation.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The cloud software platform can be accessed on mobile devices via a mobile-optimised web interface and, where applicable, vendor-provided mobile applications. The mobile experience is designed for common end-user tasks such as viewing records, approvals, notifications, and basic interactions.
The desktop version provides a fuller feature set and configuration capabilities intended for administrative and advanced use. Core data and functionality remain consistent across mobile and desktop access. - Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is accessed through a secure, web-based user interface provided by the software manufacturer. Users access the platform via a standard web browser to view and manage records, workflows, dashboards, and reports according to their role and permissions. The interface is responsive and can be accessed from desktop and mobile devices. Configuration and administration capabilities are available to authorised users within the platform.
- Accessibility standards
- None or don’t know
- Description of accessibility
- We have not carried out independent accessibility or assistive technology testing of the service interface. The user interface is provided and maintained by the software manufacturer as part of the cloud software platform. Any accessibility testing and compliance activities relating to the platform interface are undertaken by the software manufacturer.
- Accessibility testing
- We have not conducted independent interface testing with users of assistive technology. The service interface is provided and maintained by the software manufacturer as part of the cloud software platform. Accessibility testing and compliance activities relating to the platform interface are the responsibility of the software manufacturer.
- API
- Yes
- What users can and can't do using the API
-
The cloud software platform provides APIs that allow authorised users to integrate the service with other systems and applications. Using the APIs, users can programmatically access and manage data, automate workflows, and perform actions in line with their assigned permissions and the platform’s security model.
APIs can be used to read and update records, submit requests, and integrate with external tools, subject to role-based access controls and configuration. Initial service provisioning, licensing, and core platform configuration are not performed via the API and are managed through the platform’s standard administrative interfaces.
Use of the APIs is subject to vendor-defined limits, authentication requirements, and usage policies. The APIs do not allow changes beyond those permitted by the platform configuration or the customer’s licensed entitlements. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise the service using the configuration and administration capabilities provided within the cloud software platform. This includes configuring workflows, forms, fields, dashboards, reports, and user roles, subject to the features available under their licensed entitlements.
Customisation is carried out by authorised customer users using the platform’s standard configuration tools and interfaces. These activities do not require changes to the underlying software code and are performed within the boundaries defined by the software manufacturer.
The supplier does not perform customisation as part of this cloud software licensing service. Professional services such as configuration, development, integration, or advisory support are available separately under Cloud Support (Lot 3), where required.
Scaling
- Independence of resources
- The service is delivered on the ServiceNow public cloud using a multi-tenant SaaS architecture designed to ensure logical separation of customer data, workloads, and configurations. ServiceNow manages capacity planning, resource allocation, and performance monitoring to ensure that demand from one customer does not adversely impact others. Platform resources are scaled dynamically, and service performance is governed by vendor-defined availability and performance SLAs. As a reseller, we rely on the software manufacturer’s cloud architecture and operational controls to provide consistent service levels for all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Service usage metrics are provided through the cloud software platform and made available to customers via built-in dashboards and reports. These include licence usage, active users, module consumption, transaction volumes, audit logs, and platform availability information, subject to licensed features and user permissions. Metrics enable customers to monitor adoption, usage trends, and compliance. The supplier does not independently generate or operate service metrics but facilitates access to the reporting and analytics capabilities provided by the software manufacturer as part of the SaaS platform.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller (no extras)
- Organisation whose services are being resold
- ServiceNow
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export their data using the standard data export, reporting, and API capabilities provided within the ServiceNow cloud platform. Authorised users can export records directly from lists and reports or via APIs, subject to role-based access controls and licensed entitlements. Data can be exported in common formats such as CSV, Excel-compatible files, or structured data through APIs. All exports are performed by the customer within their own ServiceNow instance. As a reseller, Neyo does not perform data extraction or migration activities as part of this service.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- Xml
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Availability of the ServiceNow cloud platform is governed by the software manufacturer’s standard SaaS service level agreements. ServiceNow operates a highly available, multi-tenant public cloud platform designed for resilience and continuity of service. The platform typically provides a monthly uptime target of 99.8% or higher, excluding scheduled maintenance, as defined in the applicable ServiceNow subscription and SLA documentation.
Availability is measured at the platform level and applies to user access through supported web browsers, mobile interfaces, and APIs. Planned maintenance is carried out during published maintenance windows and may result in temporary service unavailability. In exceptional circumstances, emergency maintenance may also be required to protect platform stability or security.
Where availability levels are not met, any service credits, refunds, or remedies are provided in accordance with ServiceNow’s published SLA terms and subscription agreement, rather than by the reseller. Neyo does not provide separate availability guarantees beyond those offered by the software manufacturer as part of this Lot 2a cloud software licensing service.
Neyo supports customers by coordinating communications with ServiceNow during availability incidents and assisting with escalation where required. Availability commitments for implementation, configuration, integration, or managed services are not included in this Lot2a service and are delivered separately underCloudSupport(Lot3). - Approach to resilience
-
The service is delivered using the ServiceNow public cloud platform, which is designed and operated for high resilience and availability. ServiceNow’s cloud architecture uses a multi-tenant, highly available design with redundancy across infrastructure components, including compute, storage, networking, and power. The platform is hosted in secure, professionally managed datacentres with resilient power, cooling, and physical security controls.
ServiceNow implements automated monitoring, fault detection, and recovery mechanisms to minimise service disruption and support rapid restoration in the event of component failure. Data is replicated and protected in line with the vendor’s documented backup, disaster recovery, and business continuity arrangements.
Planned maintenance activities are managed through defined maintenance windows to reduce operational impact. In exceptional circumstances, emergency maintenance may be required to preserve platform stability or security.
As a reseller, Neyo does not operate or manage the underlying datacentre infrastructure. Resilience of the hosting environment, platform architecture, and recovery processes is the responsibility of the software manufacturer and is governed by ServiceNow’s published service documentation and SLAs. Further technical details relating to datacentre resilience and architecture are available from the software manufacturer on request. - Outage reporting
-
Service availability and outages are reported through mechanisms provided by the ServiceNow cloud platform. ServiceNow operates a publicly accessible system status dashboard that provides real-time and historical information on platform availability, incidents, planned maintenance, and service performance by region.
During service incidents, ServiceNow issues notifications and updates through the status dashboard and registered communication channels. Customers can subscribe to email alerts to receive notifications about incidents, service degradations, and maintenance events affecting their ServiceNow instances.
ServiceNow also provides APIs that allow authorised users to programmatically access service status information and integrate availability data into internal monitoring, reporting, or incident management tools, subject to platform configuration and permissions.
As a reseller, Neyo does not operate the underlying platform or publish an independent outage dashboard. We support customers by monitoring vendor-published notifications and, where appropriate, relaying relevant outage information to customer contacts and assisting with communication and escalation to the software manufacturer.
Outage reporting, root cause analysis, and service restoration activities are governed by ServiceNow’s published incident management processes and service level agreements (SLAs).
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access controls and least-privilege principles. Administrative access to the ServiceNow platform is controlled by the software manufacturer and customer-defined roles within the platform. Neyo access is limited to authorised personnel involved in licensing, ordering, billing, and account management only. Access to supplier systems and support tools is protected by individual user accounts, strong authentication (including MFA where available), and audit logging. Support requests are managed through controlled email or ticketing channels, with access reviewed and revoked when no longer required.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Neyo aligns with the principles of the Software Security Code of Practice through governance controls, supplier assurance, and contractual obligations. The core cloud software platform is provided by ServiceNow, which operates a mature secure development lifecycle and security assurance framework. Neyo’s security governance focuses on supplier oversight, access control, incident management, and compliance with applicable contractual and regulatory requirements. While Neyo’s security governance is not currently certified to a formal standard, policies and controls are reviewed at board level and applied consistently across all services.
- Information security policies and processes
-
Neyo operates a formal Information Security Management System (ISMS) certified to ISO/IEC 27001, covering the governance, management, and continual improvement of information security across the organisation.
Our information security policies and processes include access control, risk management, incident management, asset management, business continuity, supplier security, and data protection.
Neyo also holds Cyber Essentials and Cyber Essentials Plus certification, demonstrating alignment with UK government cyber security requirements.
Security accountability sits with a named board-level director, with day-to-day operational responsibility managed by senior technical leadership. Policies are reviewed regularly and compliance is enforced through role-based access controls, least-privilege principles, staff security awareness training, and internal audits as part of the ISO/IEC 27001 management cycle.
For this Lot 2a cloud software service, Neyo acts as a reseller. Security of the underlying SaaS platform is provided and maintained by the software manufacturer, which operates its own independently certified security and compliance frameworks. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Neyo follows supplier-defined change management controls limited to licensing, subscription administration, renewals, and contractual account updates associated with this Lot 2a service. We do not perform any configuration, development, or operational changes to the ServiceNow SaaS platform. All platform configuration, software changes, releases, and security updates are managed exclusively by the software manufacturer under their standard change and release management processes. Neyo ensures that any licence or subscription changes are formally requested, approved, and recorded, with appropriate checks to ensure access entitlements and commercial records remain accurate and controlled.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability management for the cloud software platform is performed by the software manufacturer as part of their standard secure development, testing, and operational security processes. This includes continuous vulnerability monitoring, regular security testing, patching, and remediation in line with the vendor’s security policies. Neyo does not perform vulnerability scanning or remediation on the platform itself as part of this Lot 2a licensing service. For our reseller activities, we maintain appropriate internal security controls aligned to ISO/IEC 27001 to protect licensing, ordering, and account management processes, and we coordinate with the software manufacturer where required.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring for the cloud software platform is provided by the software manufacturer as part of their standard SaaS security operations. This includes centralised logging, security event monitoring, alerting, and incident response processes operated by the vendor. Neyo does not perform protective monitoring of the platform itself as part of this Lot 2a licensing service. For our reseller activities, we apply internal monitoring and access logging aligned to ISO/IEC 27001 to protect licensing, ordering, billing, and account management processes, and we coordinate with the software manufacturer where escalation is required.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Ncident management for the cloud software platform is provided by the software manufacturer as part of their standard SaaS security operations, including detection, investigation, containment, and remediation of security incidents. Neyo does not operate or manage the platform and therefore does not provide technical incident response under this Lot 2a licensing service. For reseller activities, Neyo follows supplier-defined incident management procedures aligned to ISO/IEC 27001 to manage security incidents related to licensing, ordering, billing, and account access, and coordinates escalation with the software manufacturer where required.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- ServiceNow provides free developer instances that can be requested directly from the ServiceNow developer programme. These instances are for personal learning and evaluation only. They are not production environments and exclude licensing, configuration, integrations, training, and support from Neyo.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Tuesday 22 April 2025
- What the ISO/IEC 27001 doesn’t cover
- Our ISO/IEC 27001 certification does not cover the underlying infrastructure, data centres, or cloud hosting platforms operated by third-party vendors such as public cloud providers or software publishers. It also does not extend to customer-owned environments, end-user devices, or systems and processes that are outside Neyo’s operational control. The certification applies to Neyo’s information security management system and the delivery of consultancy and IT solutions, and excludes any services, systems, or suppliers not explicitly included within the defined scope of certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 49786ab3-85b4-4f9f-a74c-656ef53a701f
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 573a22a1-1686-4eca-adfa-e420d7ffb77c
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-