Skip to main content

Help us improve the Digital Marketplace - send your feedback

Ticketer

Ticketing

Ticketer’s ticketing service enables easy, fast, flexible fare payment for public transport. It lets passengers pay by cash, contactless, smartcard or mobile app, while operators manage fares and monitor services in real time through a cloud platform. We simplify ticketing, improving efficiency for operators and convenience for passengers.

Features

  • Multiple Payment Options: Cash, contactless, ITSO smartcards and m-tickets
  • Cloud-Based Management: Remote fare updates and real-time data transfer
  • On-Vehicle Hardware: Electronic ticket machines and tap-on/tap-off readers
  • Integration: Works with m-ticketing apps and contactless payment systems

Benefits

  • For Passengers: Faster boarding, flexible payment choices and fair pricing
  • For Operators: Reduced cash handling and real-time visibility
  • For Operators: Easy fare updates and improved operational efficiency
  • For Authorities: Accurate data for compliance and reporting

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at kelly.hanna@ticketer.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 3 1 7 2 2 8 3 3 8 9 3 0 6 9

Contact

Ticketer Kelly Hanna
Telephone: +44 7921 335840
Email: kelly.hanna@ticketer.co.uk

About your service

Service categories

Applications

Production and operations

  • Other operations

Service industry and public sector operations

  • Other
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The service requires hardware (electronic ticket machines or handheld devices) to operate and may experience planned maintenance windows that could temporarily affect availability.
System requirements
All system requirements are covered by the service provided

User support

Email or online ticketing support
Yes
Support response times
For Severity Level 1 questions, responses will be within 15 minutes during working hours (8am-5pm Monday to Friday, excluding UK bank and other public holidays). For other questions, responses will be within 1 hour during working hours (8am-5pm Monday to Friday, excluding UK bank and other public holidays).

For questions received outside working hours, responses will be provided on the nearest working day. Customers have access to an emergency incident phone line for Severity Level 1 incidents. This is covered on a 24/7 basis.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
EN 301 549
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
As part of our normal service offering (at no extra cost), we operate a tiered support model designed to ensure fast resolution and clear escalation paths. First Line Support serves as the initial point of contact for users, handling common issues such as password resets, account access, and basic troubleshooting. Their primary goal is to resolve straightforward problems quickly and efficiently, minimising disruption for end users. If an issue cannot be resolved at this level, it is escalated to the next tier.

Second Line Support provides deeper technical expertise for more complex problems that require advanced troubleshooting. This team investigates issues related to applications, systems, and configurations, often working closely with First Line Support to identify recurring problems and improve processes. They have the technical knowledge to resolve issues that go beyond basic fixes, ensuring continuity of service for critical systems.

For the most advanced challenges, we rely on Third Line Support, which consists of subject matter experts and developers. This team handles critical incidents, system bugs, and architecture-level issues that require specialised knowledge. They are responsible for root cause analysis and implementing permanent solutions, often collaborating with product teams or third parties to deliver long-term improvements.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Ticketer provides onboarding support, documentation and training sessions for new users.

Training needs are defined in a stakeholder management plan, with needs defined based on role:
IT technical staff receive a basic introduction to core functionality and portal reporting.
Business management staff receive a guide to the Insights hub, including all major reporting functionality.
Business users receive an introduction to the device and management portal, including a guide to basic business processes.
Super Users receive a full introduction to relevant elements of the device and portal functionality, including processes relevant to super-users (e.g. password resets, user set up etc.).
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
Video
End-of-contract data extraction
Users can request data extraction through Customer Support. Upon request, Ticketer provides the data in an agreed format (e.g., CSV or XML) within a defined timeframe.
End-of-contract process
Ticketer agrees an Exit Management Plan during contract negotiations at the beginning of a contract. Standard principles are:
i) Ticketer will continue to provide services and support up to an agreed exit date (with no change to standard costs).
ii) Each party will appoint an Exit Manager who will act as the key point of contact between the organisations in order to ensure a smooth and satisfactory exit (at no additional cost).
iii) Ticketer will ensure all data is deleted and/or stored in line with relevant data processing regulation (at no additional cost).

Only additional development or non-standard activity will be charged at additional cost.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Documentation is made available online or via email to support user access. Users also have access to Ticketer trainers for help and support as needed during implementation.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Drivers: Use on-vehicle ETMs or handheld devices to issue tickets, process payments (cash, contactless, smartcard, mobile) and manage boarding.

Operators: Access the cloud back-office portal to configure fares, update ticket types, and monitor transactions in real time.
Accessibility standards
None or don’t know
Description of accessibility
The information is presented in ways users can perceive (such as ext alternatives for images, readable fonts).
User interfaces are navigable via keyboard.
Content and navigation is clear, predictable and intuitive.
Accessibility testing
N/A
API
Yes
What users can and can't do using the API
Fare API can allow third parties to access the fares set up in the Ticketer portal.

None of the other features are available via an API.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Our device software and portal are configuration-driven, allowing tailored setups to meet specific operational needs. Based on customer requirements, our Support teams can enable or disable different features and functionalities remotely through the Ticketer Portal’s admin interface. Customers do not have direct access to make these changes themselves, ensuring consistency, security and proper implementation.

Scaling

Independence of resources
Our cloud-hosted solution is designed to handle high volumes of daily activity without compromising performance.

Vertical scaling allows us to enhance the capacity of existing infrastructure by increasing CPU, memory or storage resources. Horizontal scaling enables us to add instances or nodes, distributing load across the system during peak usage.

Technical teams monitor performance, storage utilisation and system health. Automated alerts and dashboards allow us to respond quickly to spikes in usage or data volume.

Intelligent data archiving processes optimise system performance, ensuring that active datasets remain lean while historical data is stored securely and accessible for reporting and compliance.

Analytics

Service usage metrics
Yes
Metrics types
Sales Data: Number of tickets sold, revenue by payment type (cash, contactless, smartcard, mobile).
Fare Breakdown: Usage of different fare types and concessions.
Transaction Volume: Daily/weekly/monthly ticketing activity.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
Only authorised personnel are able to access the data.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Data Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Import and export of data is available either via the Ticketer Portal or the Insights Reporting Suite.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • Excel
Data import formats
  • CSV
  • Other
Other data import formats
  • Excel
  • Tmf

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Data in transit is encrypted using either 3DES or AES. Sensitive data is hashed using SHA256 and transmitted via TLS v1.2.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Data in transit is encrypted using either 3DES or AES. Sensitive data is hashed using SHA256.

Availability and resilience

Guaranteed availability
We guarantee 99.5% availability for our solution.
Approach to resilience
Our service is designed for resilience through Azure’s highly available and redundant infrastructure combined with our own proactive measures:

Azure Resilient Architecture: We leverage Microsoft Azure’s globally distributed datacentres, which provide built-in redundancy across power, networking and hardware. Azure offers automatic failover, geo-replication and disaster recovery capabilities to ensure continuity.

Proactive Monitoring & Scalability: Our platform is fully hosted on Azure and continuously monitored for performance and storage. We support both vertical and horizontal scaling to handle demand fluctuations and data growth.

Data Management: Proactive archiving processes maintain optimal size and performance.

Compliance & Security: Azure datacentres meet international standards (ISO 27001, SOC, etc.) and align with UK Government Cloud Security Principles.
Outage reporting
Customers are notified of outages through our incident management process.

We provide timely updates via email notifications and, where applicable, through our service status banner or customer communication channels. For significant incidents, we share details on impact, resolution steps and root cause analysis once the issue is resolved.

Identity and authentication

User authentication needed
Yes
User authentication
Multi-Factor Authentication (MFA)
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted through Role-Based Access Control (RBAC), ensuring only authorised roles can access administrative functions.

All management access requires secure authentication with Multi-Factor Authentication (MFA). Support channels are limited to verified users and authenticated sessions, and sensitive actions are logged for auditing and compliance.
Access restriction testing frequency
At least once a year
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
No audit information available
Access to supplier activity audit information
No audit information available
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
PCI DSS
Cyber Essentials
Information security policies and processes
Ticketer operates a formal ISMS aligned to ISO/IEC 27001. Security governance is owned internally and built into day-to-day operations rather than treated as a separate function. Information security risks are identified, assessed and managed in line with business priorities, with regular review and oversight through management review, internal assurance activity and independent external audit. Security considerations are embedded into product development, supplier management and operational decision-making.

Ticketer maintains a defined set of information security policies and supporting processes aligned to ISO/IEC 27001 and relevant UK regulatory requirements. These cover areas such as risk management, access control, data classification and handling, secure development, supplier security, incident management and business continuity.

Policies are reviewed at least annually and when significant changes occur. All new joiners are required to confirm they have read and understood the relevant policies as part of onboarding and all staff receive appropriate information security awareness training as part of their role.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Configuration/change management processes follow industry best practices aligned with ITIL and ISO/IEC 27001. Formal procedures include:

Change Requests: All changes initiated through documented requests.

Impact & Risk Assessment: Changes are evaluated for potential effects on systems, security and operations.

Approval Workflow: Changes must be reviewed/approved by a Change Advisory Board or designated authority.

Implementation & Testing: Approved changes are implemented/tested in controlled environments before deployment.

Rollback Planning: Changes include a rollback plan to restore the previous state.

Logging & Audit: Changes are logged and subject to periodic audits.

Configuration Control: Version control is applied and changes tracked throughout their lifecycle.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Our vulnerability management process is proactive and aligned with industry best practices. It includes:

Regular Scanning: Automated tools perform scheduled vulnerability scans across systems and applications.

Risk Assessment & Prioritisation: Findings are assessed based on severity (CVSS scores), exploitability and business impact. Our internal policy includes clear KPIs around response times to vulnerabilities based on their severity and the system area impacted.

Remediation & Patch Management: High-risk vulnerabilities are addressed promptly through patches, configuration changes or compensating controls.

Verification: Post-remediation scans confirm issues are resolved.

Continuous Monitoring: Threat intelligence feeds and alerts are integrated to identify emerging vulnerabilities.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Our protective monitoring process combines infrastructure and application security scanning. We use Tenable Nessus for continuous vulnerability scanning of servers, networks and configurations, providing risk ratings and remediation guidance.

For software development, we integrate Veracode into our CI/CD pipeline to perform Static and Dynamic Application Security Testing, ensuring code-level vulnerabilities are identified and remediated early.

Findings from both tools are prioritised according to severity, business impact and KPIs defined in our vulnerability management policy (critical risks: <= 3; medium level: <=30 days). Each item is tracked through our security workflow and undergoes post-remediation verification to ensure compliance and minimise risk.
Incident management type
Supplier-defined controls
Incident management approach
Incidents are reported via email, phone or Ticketer's online support system. All cases are logged in the support platform and triaged for severity and impact.

First-line support investigates using common incident guides and diagnostic logs. If the issue cannot be resolved promptly, it is escalated to second- or third-line support.

We apply fixes or workarounds to restore normal service as quickly as possible. Communication is maintained with customers/stakeholders via the ticketing system or email.

After resolution, the case is formally closed. For major incidents, Ticketer conducts a post-incident review to identify causes, document lessons and implement preventive measures.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
1%
Between £500,001 and £1,000,000
2%
Between £1,000,001 and £2,500,000
3%
Between £2,500,001 and £5,000,000
4%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Wednesday 24 September 2025
What the ISO/IEC 27001 doesn’t cover
The ISO 27001 scope includes all relevant systems and activities we operate, with no intentional exclusions. As standard, it does not extend to personal devices or third-party services outside our direct control, other than via supplier management.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
Patronusec
PCI DSS accreditation date
Monday 31 March 2025
What the PCI DSS doesn’t cover
Not covered:
Internal corporate networks (HR, finance, email, sharepoint)
Development or test environments not connected to cardholder data
Standalone systems with no access to card data
Only systems that store, process, or transmit cardholder data (or can impact their security) are covered.
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
E6bc8813-b417-4174-ab2d-2396769b6f28
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at kelly.hanna@ticketer.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.