ERP - Dynamics Business Central
Our ERP service uses Microsoft Dynamics 365 Business Central to manage finance, manufacturing, supply chain, sales, and operations in one cloud system. It replaces disconnected tools with real-time data, strong controls, and clear reporting, helping organisations run efficiently and scale with confidence.
Features
- Cloud-based ERP accessible securely from anywhere, any device, anytime
- Real-time financial reporting with drill-down visibility across all transactions
- Integrated manufacturing planning, production orders, and shop floor control
- End-to-end supply chain management covering purchasing, inventory, and logistics
- Automated sales invoicing, order processing, and customer account management
- Built-in budgeting, forecasting, and cash flow management tools
- Role-based security controlling access, approvals, and segregation of duties
- Seamless integration with Microsoft 365, Power Platform, and Azure services
- Scalable configuration using standard functionality without unnecessary customisation
- Audit-ready data with full traceability and compliance reporting built-in
Benefits
- Improve financial control with real-time visibility and accurate decision making
- Reduce manual processing through automation of finance manufacturing sales processes
- Work from anywhere securely using cloud access across devices globally
- Gain faster insights with real-time reporting dashboards and drill-down analysis
- Streamline purchasing inventory and production planning in one system platform
- Scale operations confidently without complex customisation or disruptive upgrades cycles
- Improve collaboration using integrated workflows approvals and shared data models
- Increase accuracy by maintaining a single trusted source of data
- Support compliance with clear audit trails and role-based controls built-in
- Reduce operational risk by standardising processes across the organisation consistently
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 9 4 2 6 5 3 4 7 5 2 2 3 2 7
Contact
FormusPro
Andrew Martin
Telephone: 01432345191
Email: andrewmartin@formuspro.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Payroll management
- Procurement
- Order management and orchestration
- Enterprise performance management
- Project and portfolio management
- Asset life-cycle management
Financial
- Financial and Accounting Applications
- Accounts Payable Applications
- Accounts Receivable Applications
- Treasury and Risk Management Applications
- Travel and Expense Management Applications
- Corporate Tax Management Applications
Human capital management
- Core Human Resources Applications
- Talent Management Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Our service extends Microsoft Dynamics 365 Business Central across the full Microsoft stack including Microsoft 365, Power Platform, Azure, and Dynamics. It also integrates with many third-party platforms using FlexSync, our IP-owned integration product, enabling secure, scalable connectivity between Business Central and almost any external system.
- Cloud deployment model
-
- Public cloud
- Hybrid cloud
- Service constraints
-
No
The service is delivered as a fully managed cloud service. Infrastructure, updates, security, and availability are handled by Microsoft. Users access the service using supported web browsers and devices, with no specialist hardware requirements or local installation needed. - System requirements
-
- Access through a standard web browser with secure internet connection
- Use existing Microsoft login for simple and secure user access
- Works across desktop laptop tablet and mobile devices
- No software installation or specialist hardware required by users
- Fully cloud managed with automatic updates and security handling
User support
- Email or online ticketing support
- Yes
- Support response times
-
We provide email and online ticketing support during UK business hours.
Support tickets are acknowledged within one hour.
Response and resolution times depend on priority.
24/7 support is also available. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support levels
We provide flexible, tiered support for Microsoft Dynamics 365 Business Central, aligned to issue priority and business impact.
Standard Support
Included within Business Central Lite, Core, Core Advanced, Plus, and Pro packages.
Support is provided via email and online ticketing during UK business hours.
Tickets are acknowledged within one hour and managed using response-based SLAs.
Support is delivered by Microsoft-certified cloud support engineers.
Monthly support packages range from £500 to £3000, depending on system complexity and required coverage.
Enterprise Support
Designed for larger or more complex environments.
Includes priority handling, extended hours, and 24/7 cover for critical issues.
Named technical account manager provides escalation management, service reviews, and governance.
Enterprise support pricing starts from £3,5o0 per month.
Additional Options
Pay-as-you-go support is available at £175 per hour.
Optional add-ons include enhanced support coverage and additional superusers.
All support follows response-based SLAs, with priority levels from critical to low-impact queries. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We help users start using the service through a structured and supportive onboarding process.
Initial setup is carried out by experienced consultants who configure the service to agreed requirements and ensure secure access. Onboarding is typically delivered remotely, with onsite support available where required.
Users receive role-based training through live online sessions, supported by clear user documentation and walkthroughs. Training focuses on practical, day-to-day use to help users become productive quickly.
Administrators and power users receive additional guidance covering configuration, security, and integrations. Documentation is provided in digital format and can be reused for future users.
Following go-live, users have access to email and online ticketing support. Ongoing support, refresher training, and optimisation sessions are available to support adoption as needs evolve. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
We are transparent and firmly believe that customer data always remains the customer’s own. When a contract ends, users can extract their data using standard export tools and APIs, with data provided in commonly used formats suitable for migration or archiving.
We actively support customers with data extraction and migration where required, providing guidance and reasonable assistance to ensure data is transferred securely, accurately, and in line with agreed data retention and security policies. - End-of-contract process
-
At the end of the contract, we work with the customer to agree an orderly off-boarding process. This includes confirming timelines, access requirements, and data extraction or migration needs.
Access to the service continues until the agreed contract end date. During this period, customers can extract their data using standard tools and APIs. Guidance on data export is included as part of the service.
Additional assistance, such as hands-on support for data migration, bespoke exports, or extended access beyond the contract term, can be provided at additional cost on a time and materials basis.
Once data extraction is confirmed, access is removed in line with agreed security and data retention policies. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The service is accessible on mobile devices using responsive web access and Microsoft mobile apps.
Core tasks such as approvals, reviews, and data lookup are supported.
Advanced configuration, complex reporting, and administration are best performed on desktop. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure, web-based user interface provided by Microsoft Dynamics 365 Business Central. The interface is consistent across devices, integrates with Microsoft 365, and uses role-based navigation to support different user needs.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
The service interface is provided by Microsoft Dynamics 365 Business Central and aligns to Microsoft’s accessibility standards. Microsoft conducts ongoing accessibility testing using assistive technologies such as screen readers, keyboard-only navigation, magnification tools, and high-contrast display modes.
During implementation and configuration, we ensure that accessibility features are preserved and not affected by role setup, extensions, or integrations. User acceptance testing includes validation of navigation, readability, and usability for different user roles. Where buyers identify specific accessibility needs, we work with them to review configurations and support reasonable adjustments using standard platform capabilities. - API
- Yes
- What users can and can't do using the API
-
Users can:
Connect using standard authentication and permissions (role-based access).
Read and write business data such as customers, suppliers, items, invoices, and journals.
Create and update transactions and master data to support integrations and automation.
Trigger workflows via connected services (for example Power Automate) where configured.
Onboard integrations by configuring API access, users, permissions, and endpoints.
Users can’t:
Bypass Business Central security, approvals, or audit controls through the API.
Change Microsoft-managed platform settings for the SaaS environment.
Reliably perform complex UI-only configuration through the API.
Limitations:
Available operations depend on the API set exposed and the user’s permissions.
Some configuration changes require admin access and may need UI steps.
Rate limits, throttling, and versioning apply under Microsoft’s API policies.
Certain extensions may expose additional endpoints, others may not. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Buyers can customise the service through configuration, role settings, extensions, and integrations using standard Microsoft Dynamics 365 Business Central capabilities, without modifying the underlying platform or affecting future upgrades.
Scaling
- Independence of resources
-
The service is delivered using Microsoft’s cloud platform, which is designed to isolate customer environments and manage resources at scale. Controls are in place to ensure that activity from one customer does not negatively impact others.
Capacity management, load balancing, throttling, and monitoring are handled at platform level, maintaining consistent performance and availability during periods of high demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide service usage and operational metrics including availability, performance, capacity, error rates, and integration activity. Where supported by the underlying Microsoft platform, metrics also include user activity, system health, and resource consumption. These metrics help buyers monitor service performance, plan capacity, and support governance and reporting needs.
- Reporting types
-
- API access
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Microsoft, Insight Works, Factorial, Continia, and other Business Central add-ons.
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export data using built-in tools and APIs. We provide guidance where required.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- XML
- Excel (XLSX)
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- XML
- Excel (XLSX)
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is delivered using Microsoft Azure and is designed to align with Microsoft’s published cloud availability targets. The underlying platform provides a target monthly uptime of 99.9% or higher, depending on the specific Azure services in use.
Availability is measured on a monthly basis and relates to access to core ERP functionality.
Service levels
Target availability: 99.9%+ per calendar month
The service benefits from Azure’s built-in resilience, redundancy and monitoring
Planned maintenance is communicated in advance and scheduled to minimise business impact
Unplanned maintenance is undertaken only where required to maintain security or service stability
Service credits
Where service availability falls below Microsoft’s stated availability targets:
Any service credits are provided by Microsoft under its standard Azure SLA, not by us directly
Service credits are subject to Microsoft’s terms and conditions and are not guaranteed
We will support customers in raising and progressing any valid service credit claims with Microsoft
This reflects standard practice for services delivered on Microsoft’s cloud platform. - Approach to resilience
-
The service is hosted on Microsoft Azure and is designed using cloud-native resilience principles aligned to the government’s Cloud Security Principle 2: Asset protection and resilience.
Resilience is achieved through:
Deployment within Microsoft Azure datacentres that provide built-in physical security, redundancy and environmental controls
Use of redundant infrastructure components, including compute, storage and networking
Data protection through regular automated backups and point-in-time restore capabilities
Platform-level monitoring and alerting to detect and respond to service issues proactively
Azure datacentres are designed to tolerate component failure without service impact, with resilience built in at multiple layers of the platform.
Where required by a customer or regulator, more detailed architectural and datacentre resilience information can be provided on request, subject to appropriate confidentiality.
This approach ensures the service remains available, secure and recoverable in the event of infrastructure, software or operational failure. - Outage reporting
-
Service availability and outages are monitored continuously using Microsoft Azure platform monitoring and service health tooling.
Outages and service issues are reported through:
Microsoft Azure Service Health, which provides a public status dashboard covering Azure services and regions
Email notifications for relevant service incidents and planned maintenance, configurable per customer tenant
Direct customer communication from FormusPro for incidents impacting the service, including status updates and resolution progress
There is no separate public API for outage reporting beyond the Azure platform capabilities. Where required, incident reports and post-incident summaries can be provided to customers on request.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using Microsoft Entra ID with role-based access control. Administrative privileges are granted on a least-privilege basis and reviewed regularly. Multi-factor authentication is enforced for all privileged accounts. Access is logged and monitored, with audit trails retained for compliance and investigation. Support access is provided only to authorised personnel and limited to the minimum scope and duration required, using just-in-time access where applicable. Customer data access follows documented approval processes and contractual controls, aligned to Microsoft security and compliance frameworks.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Other
- Description of management access authentication
- Management access is authenticated using Microsoft Entra ID (Azure AD) with mandatory multi-factor authentication. Access is role-based using least-privilege principles and enforced through conditional access policies. Certificate-based authentication and secure TLS connections are used where applicable. Administrative access is restricted to authorised personnel only and is logged and monitored. Username and password authentication alone is not permitted for management access.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
FormusPro follows a formal information security management framework aligned to ISO/IEC 27001 principles and Microsoft best practice.
We maintain documented policies covering, as a minimum:
Information security governance and risk management
Access control and identity management
Data classification, handling and retention
Secure system configuration and change management
Incident management and breach reporting
Supplier and third-party security assurance
Business continuity and disaster recovery
Reporting structure
Overall accountability for information security sits with a board-level sponsor, supported by senior operational leads responsible for day-to-day security management. Security risks, incidents, and compliance matters are escalated through defined governance routes and reviewed as part of management reporting.
Policy enforcement and assurance
Policies are embedded into operational processes and enforced through:
Role-based access controls and least-privilege principles
Mandatory onboarding and periodic security awareness training
Use of Microsoft security tooling across identity, endpoint, cloud and data platforms
Regular review of access rights and system configurations
Incident response procedures with defined escalation and communication paths
Compliance is monitored through internal reviews, supplier assurance processes, and reliance on Microsoft Azure’s independently certified security controls where services are hosted.
This approach ensures policies are consistently applied, monitored, and improved over time, with clear ownership and accountability - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
FormusPro tracks all service components throughout their lifecycle using controlled asset and configuration records, aligned to Microsoft Azure and Dynamics platform standards.
Changes are logged, reviewed and approved through defined change management processes. Each change is assessed for security, availability and data protection impact before implementation. Where relevant, changes are tested in non-production environments prior to release.
Access to make changes is restricted using role-based access controls and least-privilege principles. All changes are auditable and supported by Microsoft’s underlying platform change and release controls. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We operate a risk-based vulnerability management process aligned to Microsoft and industry best practice. Potential threats are identified using Microsoft security advisories, Azure Service Health, Microsoft Defender alerts, supplier notifications and internal monitoring. Risks are assessed for relevance and impact before action is taken.
Platform-level security patches are applied by Microsoft as part of the managed cloud service. Application and configuration updates under our control are prioritised by severity, with critical patches deployed promptly and typically within days. Threat intelligence is sourced from Microsoft advisories, Azure security notifications and ongoing operational reviews. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is delivered using Microsoft Azure and Dynamics 365 native security logging, monitoring and alerting, including audit logs, security alerts and service health notifications. Potential compromises are identified through automated alerts, log review and exception monitoring. Alerts are triaged by authorised staff and escalated via defined incident management procedures. Incidents are assessed promptly, with containment, remediation and root cause analysis undertaken as required. Critical security incidents are responded to immediately, with initial assessment typically within hours, followed by corrective actions and customer communication where applicable
- Incident management type
- Supplier-defined controls
- Incident management approach
- We operate defined incident management processes aligned to ITIL principles and our ISO/IEC 27001 and IASME-certified information security management system. Pre-defined procedures exist for common events including service outages, security incidents and data issues. Incidents can be reported via our service desk, email or agreed support channels. Incidents are logged, prioritised and managed through to resolution with clear ownership. Where required, we provide incident updates and post-incident reports outlining impact, root cause and corrective actions. Major incidents are escalated in line with severity thresholds and coordinated with Microsoft where platform services are involved.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Other
- Other public sector networks
-
- None – accessed securely via standard internet connectivity
- Microsoft public cloud connectivity
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 4%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Sancert Ltd
- ISO/IEC 27001 accreditation date
- Monday 10 February 2025
- What the ISO/IEC 27001 doesn’t cover
- Nothing specific was excluded from our certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation
- ISO 9001 accreditation date
- Sunday 8 October 2023
- What the ISO 9001 doesn’t cover
- Nothing specifically was excluded in the scope for ISO 9001.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- B5d64ed8-d805-47b9-8d6d-d5b8b7930150
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 0f73a075-a547-4fa1-a2bd-df536b1062d2
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-