Ticketing
Ticketer’s ticketing service enables easy, fast, flexible fare payment for public transport. It lets passengers pay by cash, contactless, smartcard or mobile app, while operators manage fares and monitor services in real time through a cloud platform. We simplify ticketing, improving efficiency for operators and convenience for passengers.
Features
- Multiple Payment Options: Cash, contactless, ITSO smartcards and m-tickets
- Cloud-Based Management: Remote fare updates and real-time data transfer
- On-Vehicle Hardware: Electronic ticket machines and tap-on/tap-off readers
- Integration: Works with m-ticketing apps and contactless payment systems
Benefits
- For Passengers: Faster boarding, flexible payment choices and fair pricing
- For Operators: Reduced cash handling and real-time visibility
- For Operators: Easy fare updates and improved operational efficiency
- For Authorities: Accurate data for compliance and reporting
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 3 1 7 2 2 8 3 3 8 9 3 0 6 9
Contact
Ticketer
Kelly Hanna
Telephone: +44 7921 335840
Email: kelly.hanna@ticketer.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service requires hardware (electronic ticket machines or handheld devices) to operate and may experience planned maintenance windows that could temporarily affect availability.
- System requirements
- All system requirements are covered by the service provided
User support
- Email or online ticketing support
- Yes
- Support response times
-
For Severity Level 1 questions, responses will be within 15 minutes during working hours (8am-5pm Monday to Friday, excluding UK bank and other public holidays). For other questions, responses will be within 1 hour during working hours (8am-5pm Monday to Friday, excluding UK bank and other public holidays).
For questions received outside working hours, responses will be provided on the nearest working day. Customers have access to an emergency incident phone line for Severity Level 1 incidents. This is covered on a 24/7 basis. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
As part of our normal service offering (at no extra cost), we operate a tiered support model designed to ensure fast resolution and clear escalation paths. First Line Support serves as the initial point of contact for users, handling common issues such as password resets, account access, and basic troubleshooting. Their primary goal is to resolve straightforward problems quickly and efficiently, minimising disruption for end users. If an issue cannot be resolved at this level, it is escalated to the next tier.
Second Line Support provides deeper technical expertise for more complex problems that require advanced troubleshooting. This team investigates issues related to applications, systems, and configurations, often working closely with First Line Support to identify recurring problems and improve processes. They have the technical knowledge to resolve issues that go beyond basic fixes, ensuring continuity of service for critical systems.
For the most advanced challenges, we rely on Third Line Support, which consists of subject matter experts and developers. This team handles critical incidents, system bugs, and architecture-level issues that require specialised knowledge. They are responsible for root cause analysis and implementing permanent solutions, often collaborating with product teams or third parties to deliver long-term improvements. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Ticketer provides onboarding support, documentation and training sessions for new users.
Training needs are defined in a stakeholder management plan, with needs defined based on role:
IT technical staff receive a basic introduction to core functionality and portal reporting.
Business management staff receive a guide to the Insights hub, including all major reporting functionality.
Business users receive an introduction to the device and management portal, including a guide to basic business processes.
Super Users receive a full introduction to relevant elements of the device and portal functionality, including processes relevant to super-users (e.g. password resets, user set up etc.). - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Video
- End-of-contract data extraction
- Users can request data extraction through Customer Support. Upon request, Ticketer provides the data in an agreed format (e.g., CSV or XML) within a defined timeframe.
- End-of-contract process
-
Ticketer agrees an Exit Management Plan during contract negotiations at the beginning of a contract. Standard principles are:
i) Ticketer will continue to provide services and support up to an agreed exit date (with no change to standard costs).
ii) Each party will appoint an Exit Manager who will act as the key point of contact between the organisations in order to ensure a smooth and satisfactory exit (at no additional cost).
iii) Ticketer will ensure all data is deleted and/or stored in line with relevant data processing regulation (at no additional cost).
Only additional development or non-standard activity will be charged at additional cost. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Documentation is made available online or via email to support user access. Users also have access to Ticketer trainers for help and support as needed during implementation.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- None
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
Drivers: Use on-vehicle ETMs or handheld devices to issue tickets, process payments (cash, contactless, smartcard, mobile) and manage boarding.
Operators: Access the cloud back-office portal to configure fares, update ticket types, and monitor transactions in real time. - Accessibility standards
- None or don’t know
- Description of accessibility
-
The information is presented in ways users can perceive (such as ext alternatives for images, readable fonts).
User interfaces are navigable via keyboard.
Content and navigation is clear, predictable and intuitive. - Accessibility testing
- N/A
- API
- Yes
- What users can and can't do using the API
-
Fare API can allow third parties to access the fares set up in the Ticketer portal.
None of the other features are available via an API. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Our device software and portal are configuration-driven, allowing tailored setups to meet specific operational needs. Based on customer requirements, our Support teams can enable or disable different features and functionalities remotely through the Ticketer Portal’s admin interface. Customers do not have direct access to make these changes themselves, ensuring consistency, security and proper implementation.
Scaling
- Independence of resources
-
Our cloud-hosted solution is designed to handle high volumes of daily activity without compromising performance.
Vertical scaling allows us to enhance the capacity of existing infrastructure by increasing CPU, memory or storage resources. Horizontal scaling enables us to add instances or nodes, distributing load across the system during peak usage.
Technical teams monitor performance, storage utilisation and system health. Automated alerts and dashboards allow us to respond quickly to spikes in usage or data volume.
Intelligent data archiving processes optimise system performance, ensuring that active datasets remain lean while historical data is stored securely and accessible for reporting and compliance.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Sales Data: Number of tickets sold, revenue by payment type (cash, contactless, smartcard, mobile).
Fare Breakdown: Usage of different fare types and concessions.
Transaction Volume: Daily/weekly/monthly ticketing activity. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- Only authorised personnel are able to access the data.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Import and export of data is available either via the Ticketer Portal or the Insights Reporting Suite.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Excel
- Tmf
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- Data in transit is encrypted using either 3DES or AES. Sensitive data is hashed using SHA256 and transmitted via TLS v1.2.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Data in transit is encrypted using either 3DES or AES. Sensitive data is hashed using SHA256.
Availability and resilience
- Guaranteed availability
- We guarantee 99.5% availability for our solution.
- Approach to resilience
-
Our service is designed for resilience through Azure’s highly available and redundant infrastructure combined with our own proactive measures:
Azure Resilient Architecture: We leverage Microsoft Azure’s globally distributed datacentres, which provide built-in redundancy across power, networking and hardware. Azure offers automatic failover, geo-replication and disaster recovery capabilities to ensure continuity.
Proactive Monitoring & Scalability: Our platform is fully hosted on Azure and continuously monitored for performance and storage. We support both vertical and horizontal scaling to handle demand fluctuations and data growth.
Data Management: Proactive archiving processes maintain optimal size and performance.
Compliance & Security: Azure datacentres meet international standards (ISO 27001, SOC, etc.) and align with UK Government Cloud Security Principles. - Outage reporting
-
Customers are notified of outages through our incident management process.
We provide timely updates via email notifications and, where applicable, through our service status banner or customer communication channels. For significant incidents, we share details on impact, resolution steps and root cause analysis once the issue is resolved.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is restricted through Role-Based Access Control (RBAC), ensuring only authorised roles can access administrative functions.
All management access requires secure authentication with Multi-Factor Authentication (MFA). Support channels are limited to verified users and authenticated sessions, and sensitive actions are logged for auditing and compliance. - Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
PCI DSS
Cyber Essentials - Information security policies and processes
-
Ticketer operates a formal ISMS aligned to ISO/IEC 27001. Security governance is owned internally and built into day-to-day operations rather than treated as a separate function. Information security risks are identified, assessed and managed in line with business priorities, with regular review and oversight through management review, internal assurance activity and independent external audit. Security considerations are embedded into product development, supplier management and operational decision-making.
Ticketer maintains a defined set of information security policies and supporting processes aligned to ISO/IEC 27001 and relevant UK regulatory requirements. These cover areas such as risk management, access control, data classification and handling, secure development, supplier security, incident management and business continuity.
Policies are reviewed at least annually and when significant changes occur. All new joiners are required to confirm they have read and understood the relevant policies as part of onboarding and all staff receive appropriate information security awareness training as part of their role. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Configuration/change management processes follow industry best practices aligned with ITIL and ISO/IEC 27001. Formal procedures include:
Change Requests: All changes initiated through documented requests.
Impact & Risk Assessment: Changes are evaluated for potential effects on systems, security and operations.
Approval Workflow: Changes must be reviewed/approved by a Change Advisory Board or designated authority.
Implementation & Testing: Approved changes are implemented/tested in controlled environments before deployment.
Rollback Planning: Changes include a rollback plan to restore the previous state.
Logging & Audit: Changes are logged and subject to periodic audits.
Configuration Control: Version control is applied and changes tracked throughout their lifecycle. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Our vulnerability management process is proactive and aligned with industry best practices. It includes:
Regular Scanning: Automated tools perform scheduled vulnerability scans across systems and applications.
Risk Assessment & Prioritisation: Findings are assessed based on severity (CVSS scores), exploitability and business impact. Our internal policy includes clear KPIs around response times to vulnerabilities based on their severity and the system area impacted.
Remediation & Patch Management: High-risk vulnerabilities are addressed promptly through patches, configuration changes or compensating controls.
Verification: Post-remediation scans confirm issues are resolved.
Continuous Monitoring: Threat intelligence feeds and alerts are integrated to identify emerging vulnerabilities. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Our protective monitoring process combines infrastructure and application security scanning. We use Tenable Nessus for continuous vulnerability scanning of servers, networks and configurations, providing risk ratings and remediation guidance.
For software development, we integrate Veracode into our CI/CD pipeline to perform Static and Dynamic Application Security Testing, ensuring code-level vulnerabilities are identified and remediated early.
Findings from both tools are prioritised according to severity, business impact and KPIs defined in our vulnerability management policy (critical risks: <= 3; medium level: <=30 days). Each item is tracked through our security workflow and undergoes post-remediation verification to ensure compliance and minimise risk. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Incidents are reported via email, phone or Ticketer's online support system. All cases are logged in the support platform and triaged for severity and impact.
First-line support investigates using common incident guides and diagnostic logs. If the issue cannot be resolved promptly, it is escalated to second- or third-line support.
We apply fixes or workarounds to restore normal service as quickly as possible. Communication is maintained with customers/stakeholders via the ticketing system or email.
After resolution, the case is formally closed. For major incidents, Ticketer conducts a post-incident review to identify causes, document lessons and implement preventive measures. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 4%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Wednesday 24 September 2025
- What the ISO/IEC 27001 doesn’t cover
- The ISO 27001 scope includes all relevant systems and activities we operate, with no intentional exclusions. As standard, it does not extend to personal devices or third-party services outside our direct control, other than via supplier management.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Patronusec
- PCI DSS accreditation date
- Monday 31 March 2025
- What the PCI DSS doesn’t cover
-
Not covered:
Internal corporate networks (HR, finance, email, sharepoint)
Development or test environments not connected to cardholder data
Standalone systems with no access to card data
Only systems that store, process, or transmit cardholder data (or can impact their security) are covered. - Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E6bc8813-b417-4174-ab2d-2396769b6f28
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-