Skip to main content

Help us improve the Digital Marketplace - send your feedback

P3MO LTD

P3MO Platform

P3MO provides organisations the ability to visualise and manage their strategic objectives to deliver programme transformation and project change; bringing a fresh approach to managing complex challenges with a simple to implement and intuitive platform that provides instant value through increased collaboration, clarity and control to deliver strategic programme success.

Features

  • Portfolio, Programme and Project management data visibility
  • Exec overview, RAID, Objectives, Budget, Resourcing, Vendor, Planning,
  • Automated Project Intake
  • Automated Report Builder
  • Executive overview to Project Data detail in 3 clicks
  • Fully Customisable to align with customer terminology
  • Project Health management
  • Easy to implement and intuitive for a great user experience
  • Cloud hosted in Azure
  • Notifications and comments management

Benefits

  • Instant visibility of strategic initiatives
  • Deep dive into portfolio, programme and projects to manage progress
  • Identify issues and collaborate with colleagues to achieve success
  • Share comments and tag issues to drive impactful decisions
  • Reduce reporting time with Automated report Builder
  • Capture project requests and manage approval process with Project Intake
  • Improve team communication and collaboration, from Exec to Delivery
  • Clone projects for simple and fast project set up
  • Retain lessons learnt for future initiatives
  • Improve stakeholder confidence, with accurate real time information

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at legal@p3mo.io. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 0 4 8 2 3 8 8 4 1 2 4 0 5 7

Contact

P3MO LTD Martin Cullinane
Telephone: 07355091359
Email: legal@p3mo.io

About your service

Service categories

Applications

Enterprise resource management

  • Project and portfolio management
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
Currently only connected to our own Microsoft Azure Private cloud
System requirements
4Gig storage required if installing on desktop, NA for webapp

User support

Email or online ticketing support
Yes
Support response times
Support Hours: Automation: 24/7 - 365 ; Human contact: Mon – Fri 9-5
Channels: Automation (Bot), Email, Phone
Response Times:
Critical: 15mins - 1hr
High: 1-4 hrs
Medium: Same day or within 8 hrs
Low: 1-3 business days
Escalation Path:
T0 – Self-service (knowledge base or automated (bot))
T1 – Contact support and log ticket
T2 – Escalated to technical support, product team
T3 – Escalated to Engineering and architecture team
T4 – Escalated to Senior management/Incident Response
In parallel escalation is tracked by severity and time to resolve issue
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Our Web chat solution, is tested as part of our wider annual compliance processes including ISO27001, SOC2, Cyber Essentials Plus. Accessibility testing is provided by a 3rd party Professional testing provider. They provide a thorough review of accessibility requirements to support compliance to WACG 2.2 AA standards, as part of this process they use Microsoft's Accessibility testing tool, "Accessibility Insights for web"
Onsite support
Yes
Support levels
We provide a range of support options
- A knowledge hub, including videos and user guides
- An Automated (bot) solution
- A ticketing support service, with communication provided via email
- A option to speak with a support expert
- For technical escalation we provide in house 2nd and 3rd level support
- We provide a Customer Account Manager, who is available to the customers Super User community 24/7.

As part of our support service we offer ongoing training support for users throughout the term of the contract, to support new users joining and engaging with our platform.

We do not charge for additional levels of support as we believe strongly in user adoption being key principal for the success of a software solution
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
As part of onboarding we agree with each customer a clearly defined implementation process and plan. The plan includes each step of the onboarding journey including, identification of roles and responsibilities, actions and delivery dates, data identification and transfer, connectivity to customer systems (if required) and an agreed training plan. We provide training to customers in person or via online sessions. Training is to a customer designated super user community which normally includes designated Global Admin and Admin users. We also can support the wider user community training should this be required, including one to one sessions for Executive leadership colleagues. In addition we provide in-platform guidance and access to our knowledge hub consisting of videos and user guides for on-going user support throughout the duration of the customer contract
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of a contract we will be provide the customer with their data via a CSV file. Data can also be extracted via ppt & pdf via our report builder functionality. If a connection was established to a customer Datalake then data can be extracted via this option.
End-of-contract process
At the end of a contract and at no extra charge to the customer, we will provide a CSV file of all customer data to a customer designated email account. We will confirm that all data has been deleted and removed from our systems. We will request that the customer confirms receipt of their data CSV file and that they have been able to access the file successfully.
At the end of the contract all users will have access removed from the system.
The final user to be removed from the system will be the Customer Global Admin, who will be requested to confirm that all data and access has been removed in accordance with process.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
A clear and easy to use interface providing an
Executive overview of Portfolio, Programme and Projects.
Multiple modules providing the user the following functions: RAID, Objectives, Planning, Budget, Vendors, Resourcing, Project Intake, Lessons learnt.
Ability to drill down from Executive overview to project detail within 3 clicks
Notifications functionality for colleagues to share comments to increase collaboration
Build automated reports (in ppt or pdf) and distribute on a pre-set drumbeat
Fully customisable to align to customer specific terminology
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Our Platform is tested as part of our wider annual compliance processes including ISO27001, SOC2, Cyber Essentials Plus. Accessibility testing is provided by a 3rd party Professional testing provider. They provide a thorough review of accessibility requirements to ensure compliance with WACG 2.2 AA standards, as part of this process they use Microsoft's Accessibility testing tool, "Accessibility Insights for web"
API
No
Customisation available
Yes
Description of customisation
Customers - Global Admin can customise, terminology of labels across the platform to align with their in house terminology, metrics and colour. They can also set and adjust permissions for all users within their organisation
Customer - Admin, can customise permissions for the programmes and projects they are associated with
Customers - Users, can customise their own persona to view only relevant metrics for their role should they wish for a focussed view.

Scaling

Independence of resources
Each customer has their own dedicated environment, isolated from other customers. To scale we manage each environment separately through our private cloud auto scaling services as necessary to maintain service levels and guarantee minimal or no impact to customer user communities.

Analytics

Service usage metrics
Yes
Metrics types
We can provide Core availability metrics
Service uptime target ​Planned maintenance windows Performance and capacity
Response times
Capacity and scalability indicators
Reporting types
Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Physical access control, complying with another standard
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Data is held within the platform but the customer can use the automated report builder to provide ppt and pdf information and share this both in the system, via email and / or download. Should the customer wish to connect to their own Datalake or Sharedrive or 3rd party systems via an API this can be arranged as part of the implementation process, this may come at an additional cost depending on complexity of requirement.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Service Commitment
P3MO Ltd will use commercially reasonable efforts to make the Service available 99.9% of the time in any given calendar month, excluding scheduled maintenance and circumstances beyond our reasonable control

Uptime Commitment
The Service will be available 99.9% of the time during each monthly billing cycle, measured on a 24/7 basis.

Scheduled Maintenance
We may schedule maintenance with prior notice of at least 48 hours. Scheduled maintenance windows will not exceed 4 hours per month and will typically occur during low-usage hours.

Emergency Maintenance
In cases of emergency maintenance, we will provide as much notice as is practicable

Service Credits
If uptime falls below the stated commitment, you may be eligible for a Service Credit:
“Maximum Available Minutes” is the total accumulated minutes during a month period, excluding limitations (as defined in Section 5)

Downtime: The total accumulated minutes that are part of Maximum Available Minutes that have no Connectivity.

Uptime Percentage: Uptime Percentage is represented by the following formula:

Monthly Uptime %= (Maximum Available Minutes−Downtime) divided by Maximum Available Minutes X 100

Service Credit:
Uptime Percentage < 99.90% = Service Credit of 10%
Approach to resilience
Available on request
Outage reporting
We currently provide email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
P3MO determines the type and level of access to individual users based on the "principle of least privilege." This principle states that users are only granted the level of access absolutely required to perform their job functions and is dictated by P3MO business and security requirements. Permissions and access rights not expressly granted are by default, prohibited.
P3MO maintains consistent access controls and access rights is through (RBAC). Wherever feasible, rights and restrictions shall be allocated to groups. Individual user accounts granted additional permissions only with approval from the system owner or authorized party. All privileged access uses (MFA).
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Soc2 type II and Cyber Essentials Plus
Information security policies and processes
Information security policies include
- Information roles and responsibilities policy
- Information Security policy (AUP)
- ISMS Information security objectives plan
- ISMS Procedure for the control for documented information
- ISMS Information security management system (ISMS) policy
Reporting structure:
level 4 - CEO
level 3 - Board
level 2- Heads of function (HR- Operations- Compliance - Development - Sales)
level 1- All Employees
As part of our ISO27001 and additional compliance standards, compliance to these governance processes is monitored and maintained both internally on regular (weekly/monthly)ongoing basis as part of business as usual activates and independently audited on an annual basis by regulated, qualified approved auditors.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Our ISO27001 and Soc2 certification requires we follow an audited Change Management Policy/Process.
This includes a defined
Purpose: is to ensure that all changes to production environments are managed in a controlled and auditable manner, minimising the risk of disruption to services and maintaining system integrity and security.
Scope: This policy applies to all changes to production software, systems, and infrastructure. The process is managed through DevOps with governance reviews throughout the stages of change process.

Roles and Responsibilities
Change Categorisation: Normal Changes, Emergency Changes
Governance Review including: Risk Assessment and Rollback Planning, Release Management Process, Governance and Review Meetings
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We hold ISO27001, Soc2 type II and Cyber Essentials Plus certification, demonstrating a strong approach to security and good governance.
We have constant monitoring of vulnerabilities through the use of tools and processes.
Nucleus Security for vulnerability management, constantly reporting, scoring and recording mitigation of threats.
Qualys software is used for threat detection
Patches are deployed with severity service levels
Critical 30 Days
High 30 Days
Medium 60 Day
Low 90 Days
Informational As needed
In addition we use Vanta.com to add additional levels of vulnerability and compliance process management, to ensure standards are maintained within regulatory time frames.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Protective monitoring follows our ISO27001 and SOC2 Type II standards and includes multi layered threat detection:
Microsoft Defender for Cloud,
Microsoft Firewall IDS/IDPS,
Entra ID,
Azure SQL Database threat detection,
Microsoft Endpoint,
Microsoft Sentinel,
We follow our ISMS policy for response management which includes:
Event reported,
Triage and analysis,
Investigation,
Containment & neutralisation,
Recovery & remediation,
Hardening & improvements.
Time frames for response is in line with our operational security policy
Critical: Immediate notification to Exec, Immediate action to remediate,
High : Support ticket created manager, up to 30 days remediation,
Medium and Low: Support ticket created, 60-90 days remediation.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Our ISO27001 and Soc2 Type II compliance requirements ensure we have a defined and tested Incident management process.
Users report incidents to Email support@P3MO.io providing information or reports about the event or incident.
Management monitor and action according to the defined plan as summarised:
Event reported
Triage and analysis
Investigation
Containment & neutralization
Recovery & remediation
Hardening & Detection improvements
All reported security events, incidents, and response activities are documented and protected in our Sharepoint.
Communication is shared internally and externally via email in accordance with agreed terms and legal requirements.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
All functionality is included, there is a limited time period of one month.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
20%
Between £500,001 and £1,000,000
22.5%
Between £1,000,001 and £2,500,000
25%
Between £2,500,001 and £5,000,000
27.5%
Over £5,000,001
30%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Amtivo Group T/A British Assessment Bureau
ISO/IEC 27001 accreditation date
Tuesday 30 April 2024
What the ISO/IEC 27001 doesn’t cover
.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
F8beb20e-e612-48ad-b981-253b4c49afd7
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
3bbbb39f-9ae2-4bd8-bd09-0e31c81c6fd9
Other security certifications
Yes
Any other security certifications
SOC2 Type II

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at legal@p3mo.io. Tell them what format you need. It will help if you say what assistive technology you use.