P3MO Platform
P3MO provides organisations the ability to visualise and manage their strategic objectives to deliver programme transformation and project change; bringing a fresh approach to managing complex challenges with a simple to implement and intuitive platform that provides instant value through increased collaboration, clarity and control to deliver strategic programme success.
Features
- Portfolio, Programme and Project management data visibility
- Exec overview, RAID, Objectives, Budget, Resourcing, Vendor, Planning,
- Automated Project Intake
- Automated Report Builder
- Executive overview to Project Data detail in 3 clicks
- Fully Customisable to align with customer terminology
- Project Health management
- Easy to implement and intuitive for a great user experience
- Cloud hosted in Azure
- Notifications and comments management
Benefits
- Instant visibility of strategic initiatives
- Deep dive into portfolio, programme and projects to manage progress
- Identify issues and collaborate with colleagues to achieve success
- Share comments and tag issues to drive impactful decisions
- Reduce reporting time with Automated report Builder
- Capture project requests and manage approval process with Project Intake
- Improve team communication and collaboration, from Exec to Delivery
- Clone projects for simple and fast project set up
- Retain lessons learnt for future initiatives
- Improve stakeholder confidence, with accurate real time information
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 0 4 8 2 3 8 8 4 1 2 4 0 5 7
Contact
P3MO LTD
Martin Cullinane
Telephone: 07355091359
Email: legal@p3mo.io
About your service
- Service categories
-
Applications
Enterprise resource management
- Project and portfolio management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- Currently only connected to our own Microsoft Azure Private cloud
- System requirements
- 4Gig storage required if installing on desktop, NA for webapp
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support Hours: Automation: 24/7 - 365 ; Human contact: Mon – Fri 9-5
Channels: Automation (Bot), Email, Phone
Response Times:
Critical: 15mins - 1hr
High: 1-4 hrs
Medium: Same day or within 8 hrs
Low: 1-3 business days
Escalation Path:
T0 – Self-service (knowledge base or automated (bot))
T1 – Contact support and log ticket
T2 – Escalated to technical support, product team
T3 – Escalated to Engineering and architecture team
T4 – Escalated to Senior management/Incident Response
In parallel escalation is tracked by severity and time to resolve issue - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Our Web chat solution, is tested as part of our wider annual compliance processes including ISO27001, SOC2, Cyber Essentials Plus. Accessibility testing is provided by a 3rd party Professional testing provider. They provide a thorough review of accessibility requirements to support compliance to WACG 2.2 AA standards, as part of this process they use Microsoft's Accessibility testing tool, "Accessibility Insights for web"
- Onsite support
- Yes
- Support levels
-
We provide a range of support options
- A knowledge hub, including videos and user guides
- An Automated (bot) solution
- A ticketing support service, with communication provided via email
- A option to speak with a support expert
- For technical escalation we provide in house 2nd and 3rd level support
- We provide a Customer Account Manager, who is available to the customers Super User community 24/7.
As part of our support service we offer ongoing training support for users throughout the term of the contract, to support new users joining and engaging with our platform.
We do not charge for additional levels of support as we believe strongly in user adoption being key principal for the success of a software solution - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- As part of onboarding we agree with each customer a clearly defined implementation process and plan. The plan includes each step of the onboarding journey including, identification of roles and responsibilities, actions and delivery dates, data identification and transfer, connectivity to customer systems (if required) and an agreed training plan. We provide training to customers in person or via online sessions. Training is to a customer designated super user community which normally includes designated Global Admin and Admin users. We also can support the wider user community training should this be required, including one to one sessions for Executive leadership colleagues. In addition we provide in-platform guidance and access to our knowledge hub consisting of videos and user guides for on-going user support throughout the duration of the customer contract
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At the end of a contract we will be provide the customer with their data via a CSV file. Data can also be extracted via ppt & pdf via our report builder functionality. If a connection was established to a customer Datalake then data can be extracted via this option.
- End-of-contract process
-
At the end of a contract and at no extra charge to the customer, we will provide a CSV file of all customer data to a customer designated email account. We will confirm that all data has been deleted and removed from our systems. We will request that the customer confirms receipt of their data CSV file and that they have been able to access the file successfully.
At the end of the contract all users will have access removed from the system.
The final user to be removed from the system will be the Customer Global Admin, who will be requested to confirm that all data and access has been removed in accordance with process. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
A clear and easy to use interface providing an
Executive overview of Portfolio, Programme and Projects.
Multiple modules providing the user the following functions: RAID, Objectives, Planning, Budget, Vendors, Resourcing, Project Intake, Lessons learnt.
Ability to drill down from Executive overview to project detail within 3 clicks
Notifications functionality for colleagues to share comments to increase collaboration
Build automated reports (in ppt or pdf) and distribute on a pre-set drumbeat
Fully customisable to align to customer specific terminology - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Our Platform is tested as part of our wider annual compliance processes including ISO27001, SOC2, Cyber Essentials Plus. Accessibility testing is provided by a 3rd party Professional testing provider. They provide a thorough review of accessibility requirements to ensure compliance with WACG 2.2 AA standards, as part of this process they use Microsoft's Accessibility testing tool, "Accessibility Insights for web"
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Customers - Global Admin can customise, terminology of labels across the platform to align with their in house terminology, metrics and colour. They can also set and adjust permissions for all users within their organisation
Customer - Admin, can customise permissions for the programmes and projects they are associated with
Customers - Users, can customise their own persona to view only relevant metrics for their role should they wish for a focussed view.
Scaling
- Independence of resources
- Each customer has their own dedicated environment, isolated from other customers. To scale we manage each environment separately through our private cloud auto scaling services as necessary to maintain service levels and guarantee minimal or no impact to customer user communities.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We can provide Core availability metrics
Service uptime target Planned maintenance windows Performance and capacity
Response times
Capacity and scalability indicators
- Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Data is held within the platform but the customer can use the automated report builder to provide ppt and pdf information and share this both in the system, via email and / or download. Should the customer wish to connect to their own Datalake or Sharedrive or 3rd party systems via an API this can be arranged as part of the implementation process, this may come at an additional cost depending on complexity of requirement.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Service Commitment
P3MO Ltd will use commercially reasonable efforts to make the Service available 99.9% of the time in any given calendar month, excluding scheduled maintenance and circumstances beyond our reasonable control
Uptime Commitment
The Service will be available 99.9% of the time during each monthly billing cycle, measured on a 24/7 basis.
Scheduled Maintenance
We may schedule maintenance with prior notice of at least 48 hours. Scheduled maintenance windows will not exceed 4 hours per month and will typically occur during low-usage hours.
Emergency Maintenance
In cases of emergency maintenance, we will provide as much notice as is practicable
Service Credits
If uptime falls below the stated commitment, you may be eligible for a Service Credit:
“Maximum Available Minutes” is the total accumulated minutes during a month period, excluding limitations (as defined in Section 5)
Downtime: The total accumulated minutes that are part of Maximum Available Minutes that have no Connectivity.
Uptime Percentage: Uptime Percentage is represented by the following formula:
Monthly Uptime %= (Maximum Available Minutes−Downtime) divided by Maximum Available Minutes X 100
Service Credit:
Uptime Percentage < 99.90% = Service Credit of 10% - Approach to resilience
- Available on request
- Outage reporting
- We currently provide email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
P3MO determines the type and level of access to individual users based on the "principle of least privilege." This principle states that users are only granted the level of access absolutely required to perform their job functions and is dictated by P3MO business and security requirements. Permissions and access rights not expressly granted are by default, prohibited.
P3MO maintains consistent access controls and access rights is through (RBAC). Wherever feasible, rights and restrictions shall be allocated to groups. Individual user accounts granted additional permissions only with approval from the system owner or authorized party. All privileged access uses (MFA). - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Soc2 type II and Cyber Essentials Plus
- Information security policies and processes
-
Information security policies include
- Information roles and responsibilities policy
- Information Security policy (AUP)
- ISMS Information security objectives plan
- ISMS Procedure for the control for documented information
- ISMS Information security management system (ISMS) policy
Reporting structure:
level 4 - CEO
level 3 - Board
level 2- Heads of function (HR- Operations- Compliance - Development - Sales)
level 1- All Employees
As part of our ISO27001 and additional compliance standards, compliance to these governance processes is monitored and maintained both internally on regular (weekly/monthly)ongoing basis as part of business as usual activates and independently audited on an annual basis by regulated, qualified approved auditors. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Our ISO27001 and Soc2 certification requires we follow an audited Change Management Policy/Process.
This includes a defined
Purpose: is to ensure that all changes to production environments are managed in a controlled and auditable manner, minimising the risk of disruption to services and maintaining system integrity and security.
Scope: This policy applies to all changes to production software, systems, and infrastructure. The process is managed through DevOps with governance reviews throughout the stages of change process.
Roles and Responsibilities
Change Categorisation: Normal Changes, Emergency Changes
Governance Review including: Risk Assessment and Rollback Planning, Release Management Process, Governance and Review Meetings - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
We hold ISO27001, Soc2 type II and Cyber Essentials Plus certification, demonstrating a strong approach to security and good governance.
We have constant monitoring of vulnerabilities through the use of tools and processes.
Nucleus Security for vulnerability management, constantly reporting, scoring and recording mitigation of threats.
Qualys software is used for threat detection
Patches are deployed with severity service levels
Critical 30 Days
High 30 Days
Medium 60 Day
Low 90 Days
Informational As needed
In addition we use Vanta.com to add additional levels of vulnerability and compliance process management, to ensure standards are maintained within regulatory time frames. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Protective monitoring follows our ISO27001 and SOC2 Type II standards and includes multi layered threat detection:
Microsoft Defender for Cloud,
Microsoft Firewall IDS/IDPS,
Entra ID,
Azure SQL Database threat detection,
Microsoft Endpoint,
Microsoft Sentinel,
We follow our ISMS policy for response management which includes:
Event reported,
Triage and analysis,
Investigation,
Containment & neutralisation,
Recovery & remediation,
Hardening & improvements.
Time frames for response is in line with our operational security policy
Critical: Immediate notification to Exec, Immediate action to remediate,
High : Support ticket created manager, up to 30 days remediation,
Medium and Low: Support ticket created, 60-90 days remediation. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Our ISO27001 and Soc2 Type II compliance requirements ensure we have a defined and tested Incident management process.
Users report incidents to Email support@P3MO.io providing information or reports about the event or incident.
Management monitor and action according to the defined plan as summarised:
Event reported
Triage and analysis
Investigation
Containment & neutralization
Recovery & remediation
Hardening & Detection improvements
All reported security events, incidents, and response activities are documented and protected in our Sharepoint.
Communication is shared internally and externally via email in accordance with agreed terms and legal requirements. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- All functionality is included, there is a limited time period of one month.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 20%
- Between £500,001 and £1,000,000
- 22.5%
- Between £1,000,001 and £2,500,000
- 25%
- Between £2,500,001 and £5,000,000
- 27.5%
- Over £5,000,001
- 30%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Amtivo Group T/A British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Tuesday 30 April 2024
- What the ISO/IEC 27001 doesn’t cover
- .
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- F8beb20e-e612-48ad-b981-253b4c49afd7
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 3bbbb39f-9ae2-4bd8-bd09-0e31c81c6fd9
- Other security certifications
- Yes
- Any other security certifications
- SOC2 Type II
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-