Moodle LMS (Learning Management System)
Moodle LMS revolutionises organizational learning by leveraging the power of open-source technology. It offers advanced functionality for e-learning delivery, including competency management, training execution, course management, personal development, classroom coordination, and comprehensive reporting, all designed to enhance educational outcomes while reducing costs.
Features
- Track learning progress and compliance
- Personal development plans
- Manage team and role-based development
- Support knowledge sharing and social learning
- Delivery of structured eLearning and blended learning
- Integration with HR, ERP and CRM systems via APIs
- Offline learning via supported mobile applications
- Performance and competency management
- Access from any device with a modern web browser
- Reporting and dashboards for learning activity and completion
Benefits
- Map learning to job roles, teams, departments and organisational structures
- Access instructor-led, self-paced and virtual training in one platform
- Deliver learning consistently across desktop and mobile devices
- Integrate with existing enterprise platforms and identity providers
- Create and manage learning content and activities within the platform
- Assess learners using question banks, tracking scores and completion
- Define compliance requirements with clear audit trails
- Maintain current and historical learning records
- Support informal and social learning across teams
- Gain visibility of learning usage, progress and achievement
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 7 6 2 0 6 1 7 5 2 2 6 1 0 4
Contact
Synergy Learning
Jonathan McAlister
Telephone: +44 (0) 28 9042 2000
Email: jonathan.mcalister@synergy-learning.com
About your service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Core Human Resources Applications
- Talent Management Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- The service is delivered on supported LAMP-based environments and requires planned maintenance for platform updates, security patches and upgrades. Maintenance is scheduled in advance where possible. End-user access requires a modern web browser, with offline access supported via compatible mobile applications.
- System requirements
-
- Microsoft Edge
- Access to any modern web browser
User support
- Email or online ticketing support
- Yes
- Support response times
-
Our average response time is 1 hour 20 mins
No online ticketing responses are available at the weekend - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Synergy Learning provides second-line application support tailored to the needs of platform administrators and support teams. Support is available through fixed-hour or unlimited support packages, allowing organisations to select an option that aligns with their usage and budget.
All support requests are managed through an online helpdesk, which records interactions and enables authorised users to view ticket status, respond to queries, update priorities and review time logged against issues.
Support response times and communication methods are aligned to issue severity, ensuring higher-impact incidents are prioritised appropriately.
Each customer is assigned a dedicated account manager, with access to technical account management and cloud support engineers where required, supporting the ongoing operation and performance of hosted learning platforms. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Service implementation begins with structured onboarding, including remote or on-site consultancy and training as required. This ensures the platform is configured correctly and that administrators and key users are trained for their roles.
Onboarding is supported by experienced consultants and trainers, alongside online documentation and self-service guides to help users become familiar with the service. Platform administrators have access to the application support helpdesk via email and phone for ongoing assistance.
Additional training can be provided remotely or on-site to address specific use cases, workflows or changes in requirements as needed. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
At the end of the hosting and support contract, customers can request a full export of their data to support migration to another platform or provider. Synergy Learning provides access to customer data in standard formats, including:
* A database export
* Archived Moodle data directories, including course files and user uploads
On request, we also support the extraction of specific datasets using reporting tools, enabling delivery of user, activity and completion records in spreadsheet formats.
Once confirmation is received that all required data has been successfully transferred, customer data is securely removed from the hosting environment in line with agreed data retention and deletion processes. - End-of-contract process
-
End-of-contract process We provide the download of your site data, if under 5GB, as part of the contract. For any sites above 5GB a small charge will be applied to download your data locally, adding this to a portable storage device and securely sending this via courier.
For any transfers of sites via RSYNC an additional cost would be applicable for any additional time or transfers requested if this was required as part of a migration.
The daily rate for server engineers would be applicable to this. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is delivered through a responsive web interface, providing a consistent experience across desktop and mobile browsers. Most core learning features are available on mobile, with some administrative functions optimised for desktop use. Offline access is supported through the Moodle mobile application on iOS and Android devices, allowing learners to download and complete selected content without a network connection.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a standard web browser. Users are presented with features based on their assigned role, with additional functionality available to users with elevated permissions. Full administrator access is provided to enable complete configuration, management and operation of the service.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Synergy Learning has experience delivering projects for public sector organisations and supporting accessibility testing involving users with assistive needs. Accessibility considerations are reviewed during delivery and configuration, including alignment with GDS accessibility expectations where applicable, and issues identified are addressed as part of ongoing service improvement.
- API
- Yes
- What users can and can't do using the API
-
The platform provides a REST-based web services API that allows external systems to securely push and pull data and perform defined operations. API access is authenticated using tokens and is governed by user roles and capabilities.
Only actions explicitly enabled for a service and permitted by the associated user role can be performed. This includes activities such as user management, enrolments, course data, completion status and reporting. API users cannot perform actions beyond the permissions granted to their account.
Moodle LMS includes a wide range of core web service functions, with the option to extend functionality through custom services where required. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Moodle LMS is an open-source platform that can be deployed using standard functionality or customised to meet specific organisational requirements. Customisation options include:
* Configuration of platform settings through the administration interface
* User interface and experience changes through theming
* Development of additional features or functionality
* Integration with third-party systems using APIs
* Use of supported community or third-party plugins
Customers may carry out configuration and development using their own resources or engage Synergy Learning to provide these services. Where customisations or plugins are provided by third parties, they are subject to review for security, performance and compatibility before deployment.
Scaling
- Independence of resources
- The service can be delivered using either shared cloud or private cloud hosting, depending on customer requirements. For private cloud deployments, dedicated compute, storage and database resources are allocated to the customer’s service, isolating it from other environments. This reduces the impact of demand from other users and supports predictable performance.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Service metrics are provided in line with the agreed service levels within the contract. These include support response and resolution times, service availability and uptime, active user volumes, platform performance indicators and storage usage.
As a fully managed service, these metrics are monitored by Synergy Learning and used to support service management and continuous improvement. Additional metrics may be provided on request where they are available and appropriate to the service. - Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Moodle
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Users can export data using built-in reporting tools, with outputs available in common formats such as spreadsheet (CSV), PDF and OpenDocument. Reports can be configured to extract user, course and activity data as required.
Course content and configuration can also be exported using the platform’s backup and restore tools, producing MBZ files that can be migrated to compatible learning platforms. These export functions can be managed by authorised administrators without supplier involvement. - Data export formats
-
- CSV
- Other
- Other data export formats
- MBZ
- Data import formats
-
- CSV
- Other
- Other data import formats
- Txt
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
-
Synergy Learning provides a service availability target of 99.9%, measured over a monthly period, in line with the hosting agreement. Availability excludes planned maintenance and events outside the supplier’s reasonable control, such as upstream network failures, security incidents or force majeure events.
Where the availability target is not met, customers may request service credits or other remedies in accordance with the terms set out in the contract, including the option to terminate the service where applicable. - Approach to resilience
-
The service is designed with resilience built into the hosting architecture. The platform is hosted on virtualised cloud infrastructure with redundancy across compute, storage and networking components to reduce single points of failure.
Services can be deployed across multiple physical hosts with automated failover and load balancing to maintain availability in the event of component failure. Network resilience is supported through redundant connectivity and perimeter security controls.
Firewalls and security services are deployed in highly available configurations to protect the service and maintain continuity. Resilience, capacity and availability are continuously monitored as part of the managed hosting service.
Further technical detail on datacentre architecture and resilience controls is available on request. - Outage reporting
-
Customers are notified of service outages via support case/email in line with the service level agreement, including details of the issue and an estimated time to resolution where available. For prolonged or high-impact incidents, customers may also be contacted directly by their account manager by email or phone.
Following resolution, a written incident summary is provided outlining the cause, actions taken to restore service and any preventative measures identified.
The service does not provide a public status dashboard or outage reporting API. Outage communication is managed directly with customers.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to the service is controlled through role-based access permissions, applied at appropriate contexts within the platform. Roles define what users can view or manage, ensuring access is limited to functions and data relevant to their responsibilities. Additional restrictions can be applied through organisational structures and hierarchy where configured.
Access to support channels is restricted to authorised users nominated at contract initiation. Only approved users, identified by name and email address, are permitted to raise and manage support requests. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Synergy Learning operates documented information security policies and processes designed to protect customer data and systems. These are aligned with UK GDPR and current data protection legislation and are reviewed regularly to ensure continued relevance and effectiveness.
Information security responsibilities are clearly defined. Overall accountability sits with senior management, with operational responsibility delegated to technical and service leads. All staff are required to follow security policies as part of their employment conditions.
Security policies are embedded into staff onboarding and ongoing training, particularly for staff with access to customer systems or data. This includes access control, data handling, acceptable use, incident reporting and secure working practices.
Compliance with policies is supported through role-based access controls, documented procedures and regular internal review. Any suspected security incidents are reported through defined escalation routes and managed in line with established incident management processes. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All code and configuration changes are tracked through their lifecycle using a central Git-based version control system. A nominated Release Manager coordinates testing, release notes and controlled deployments across environments. Proposed changes are reviewed and assessed for security, performance and operational impact prior to release.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
The service is operated on supported operating system and platform versions, using Long Term Support releases where available. Security updates and patches are applied on a regular, scheduled basis, with accelerated patching where critical vulnerabilities are identified.
Potential threats are assessed by the relevant technical owners to determine risk, impact and priority, with appropriate mitigation actions agreed and implemented.
Information on vulnerabilities is sourced from trusted channels, including vendor security advisories, partner notifications and official product and platform security bulletins. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
The service is subject to continuous monitoring to identify potential security incidents or service anomalies. Monitoring operates 24/7 and includes availability, network access, system performance and resource utilisation indicators such as CPU, disk usage, load and bandwidth.
Potential compromises or abnormal activity are investigated by the technical team to assess impact and risk. Where a security incident is suspected/confirmed, defined incident response procedures are followed to contain, remediate and recover the service.
Incidents are responded to promptly based on severity. Customers are informed without undue delay via agreed communication channels, with account managers involved for higher-impact or prolonged incidents. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Synergy Learning operates incident management processes for common service and security events. These processes include documented escalation paths, response actions and communication steps based on incident severity.
Users report incidents through the application support helpdesk, where all tickets are logged, tracked and managed centrally. All actions and communications recorded within the ticketing system with visibility of ticket status through the support dashboard.
For significant incidents, including those impacting service levels or lasting beyond agreed thresholds, an incident report is provided to the customer. This outlines the nature of the incident, actions taken, resolution and any follow-up or preventative measures identified. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- A fully functional trial is available for up to 30 days, allowing evaluation of core platform features. Data export is not included and all trial data is deleted at the end of the period. A standard demo environment with generic access is also available.
- Link to free trial
- https://moodle.demo.synergy-learning.com
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Friday 19 April 2024
- What the ISO/IEC 27001 doesn’t cover
-
The certification does not extend to customer-owned systems or infrastructure that are hosted, managed or administered entirely outside of Synergy Learning’s control. This includes customer-hosted LMS environments where we are not responsible for the underlying hosting, operating system, network, or security configuration beyond any specifically agreed application-level support.
It also does not cover third-party platforms, services or infrastructure that are not operated by Synergy Learning, except where those suppliers are formally assessed and managed within our ISMS supplier and risk management processes. While we work with a range of trusted partners and vendors, responsibility for their independent environments remains with those providers.
End-user devices, local networks and internal IT environments operated by customers are outside the scope of our certification, as these are managed directly by the customer and sit beyond our operational control.
Finally, the certification does not apply to business activities unrelated to the delivery, hosting, development and support of learning platforms and associated services as defined within our registered ISMS scope.
Where customer-hosted or third-party services are involved, information security responsibilities are clearly defined contractually and managed through documented controls, supplier assessments and shared responsibility models. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 3a7d426b-b4e2-4588-91b5-5728ca3d66e8
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
-