Skip to main content

Help us improve the Digital Marketplace - send your feedback

FormusPro

ERP - Dynamics Business Central

Our ERP service uses Microsoft Dynamics 365 Business Central to manage finance, manufacturing, supply chain, sales, and operations in one cloud system. It replaces disconnected tools with real-time data, strong controls, and clear reporting, helping organisations run efficiently and scale with confidence.

Features

  • Cloud-based ERP accessible securely from anywhere, any device, anytime
  • Real-time financial reporting with drill-down visibility across all transactions
  • Integrated manufacturing planning, production orders, and shop floor control
  • End-to-end supply chain management covering purchasing, inventory, and logistics
  • Automated sales invoicing, order processing, and customer account management
  • Built-in budgeting, forecasting, and cash flow management tools
  • Role-based security controlling access, approvals, and segregation of duties
  • Seamless integration with Microsoft 365, Power Platform, and Azure services
  • Scalable configuration using standard functionality without unnecessary customisation
  • Audit-ready data with full traceability and compliance reporting built-in

Benefits

  • Improve financial control with real-time visibility and accurate decision making
  • Reduce manual processing through automation of finance manufacturing sales processes
  • Work from anywhere securely using cloud access across devices globally
  • Gain faster insights with real-time reporting dashboards and drill-down analysis
  • Streamline purchasing inventory and production planning in one system platform
  • Scale operations confidently without complex customisation or disruptive upgrades cycles
  • Improve collaboration using integrated workflows approvals and shared data models
  • Increase accuracy by maintaining a single trusted source of data
  • Support compliance with clear audit trails and role-based controls built-in
  • Reduce operational risk by standardising processes across the organisation consistently

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andrewmartin@formuspro.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 9 4 2 6 5 3 4 7 5 2 2 3 2 7

Contact

FormusPro Andrew Martin
Telephone: 01432345191
Email: andrewmartin@formuspro.com

About your service

Service categories

Applications

Enterprise resource management

  • Payroll management
  • Procurement
  • Order management and orchestration
  • Enterprise performance management
  • Project and portfolio management
  • Asset life-cycle management

Financial

  • Financial and Accounting Applications
  • Accounts Payable Applications
  • Accounts Receivable Applications
  • Treasury and Risk Management Applications
  • Travel and Expense Management Applications
  • Corporate Tax Management Applications

Human capital management

  • Core Human Resources Applications
  • Talent Management Applications
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Our service extends Microsoft Dynamics 365 Business Central across the full Microsoft stack including Microsoft 365, Power Platform, Azure, and Dynamics. It also integrates with many third-party platforms using FlexSync, our IP-owned integration product, enabling secure, scalable connectivity between Business Central and almost any external system.
Cloud deployment model
  • Public cloud
  • Hybrid cloud
Service constraints
No

The service is delivered as a fully managed cloud service. Infrastructure, updates, security, and availability are handled by Microsoft. Users access the service using supported web browsers and devices, with no specialist hardware requirements or local installation needed.
System requirements
  • Access through a standard web browser with secure internet connection
  • Use existing Microsoft login for simple and secure user access
  • Works across desktop laptop tablet and mobile devices
  • No software installation or specialist hardware required by users
  • Fully cloud managed with automatic updates and security handling

User support

Email or online ticketing support
Yes
Support response times
We provide email and online ticketing support during UK business hours.
Support tickets are acknowledged within one hour.
Response and resolution times depend on priority.
24/7 support is also available.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support levels

We provide flexible, tiered support for Microsoft Dynamics 365 Business Central, aligned to issue priority and business impact.

Standard Support
Included within Business Central Lite, Core, Core Advanced, Plus, and Pro packages.
Support is provided via email and online ticketing during UK business hours.
Tickets are acknowledged within one hour and managed using response-based SLAs.
Support is delivered by Microsoft-certified cloud support engineers.

Monthly support packages range from £500 to £3000, depending on system complexity and required coverage.

Enterprise Support
Designed for larger or more complex environments.
Includes priority handling, extended hours, and 24/7 cover for critical issues.
Named technical account manager provides escalation management, service reviews, and governance.
Enterprise support pricing starts from £3,5o0 per month.

Additional Options
Pay-as-you-go support is available at £175 per hour.
Optional add-ons include enhanced support coverage and additional superusers.

All support follows response-based SLAs, with priority levels from critical to low-impact queries.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We help users start using the service through a structured and supportive onboarding process.

Initial setup is carried out by experienced consultants who configure the service to agreed requirements and ensure secure access. Onboarding is typically delivered remotely, with onsite support available where required.

Users receive role-based training through live online sessions, supported by clear user documentation and walkthroughs. Training focuses on practical, day-to-day use to help users become productive quickly.

Administrators and power users receive additional guidance covering configuration, security, and integrations. Documentation is provided in digital format and can be reused for future users.

Following go-live, users have access to email and online ticketing support. Ongoing support, refresher training, and optimisation sessions are available to support adoption as needs evolve.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
We are transparent and firmly believe that customer data always remains the customer’s own. When a contract ends, users can extract their data using standard export tools and APIs, with data provided in commonly used formats suitable for migration or archiving.

We actively support customers with data extraction and migration where required, providing guidance and reasonable assistance to ensure data is transferred securely, accurately, and in line with agreed data retention and security policies.
End-of-contract process
At the end of the contract, we work with the customer to agree an orderly off-boarding process. This includes confirming timelines, access requirements, and data extraction or migration needs.

Access to the service continues until the agreed contract end date. During this period, customers can extract their data using standard tools and APIs. Guidance on data export is included as part of the service.

Additional assistance, such as hands-on support for data migration, bespoke exports, or extended access beyond the contract term, can be provided at additional cost on a time and materials basis.

Once data extraction is confirmed, access is removed in line with agreed security and data retention policies.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is accessible on mobile devices using responsive web access and Microsoft mobile apps.
Core tasks such as approvals, reviews, and data lookup are supported.
Advanced configuration, complex reporting, and administration are best performed on desktop.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed through a secure, web-based user interface provided by Microsoft Dynamics 365 Business Central. The interface is consistent across devices, integrates with Microsoft 365, and uses role-based navigation to support different user needs.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The service interface is provided by Microsoft Dynamics 365 Business Central and aligns to Microsoft’s accessibility standards. Microsoft conducts ongoing accessibility testing using assistive technologies such as screen readers, keyboard-only navigation, magnification tools, and high-contrast display modes.

During implementation and configuration, we ensure that accessibility features are preserved and not affected by role setup, extensions, or integrations. User acceptance testing includes validation of navigation, readability, and usability for different user roles. Where buyers identify specific accessibility needs, we work with them to review configurations and support reasonable adjustments using standard platform capabilities.
API
Yes
What users can and can't do using the API
Users can:

Connect using standard authentication and permissions (role-based access).

Read and write business data such as customers, suppliers, items, invoices, and journals.

Create and update transactions and master data to support integrations and automation.

Trigger workflows via connected services (for example Power Automate) where configured.

Onboard integrations by configuring API access, users, permissions, and endpoints.

Users can’t:

Bypass Business Central security, approvals, or audit controls through the API.

Change Microsoft-managed platform settings for the SaaS environment.

Reliably perform complex UI-only configuration through the API.

Limitations:

Available operations depend on the API set exposed and the user’s permissions.

Some configuration changes require admin access and may need UI steps.

Rate limits, throttling, and versioning apply under Microsoft’s API policies.

Certain extensions may expose additional endpoints, others may not.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Buyers can customise the service through configuration, role settings, extensions, and integrations using standard Microsoft Dynamics 365 Business Central capabilities, without modifying the underlying platform or affecting future upgrades.

Scaling

Independence of resources
The service is delivered using Microsoft’s cloud platform, which is designed to isolate customer environments and manage resources at scale. Controls are in place to ensure that activity from one customer does not negatively impact others.

Capacity management, load balancing, throttling, and monitoring are handled at platform level, maintaining consistent performance and availability during periods of high demand.

Analytics

Service usage metrics
Yes
Metrics types
We provide service usage and operational metrics including availability, performance, capacity, error rates, and integration activity. Where supported by the underlying Microsoft platform, metrics also include user activity, system health, and resource consumption. These metrics help buyers monitor service performance, plan capacity, and support governance and reporting needs.
Reporting types
  • API access
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Microsoft, Insight Works, Factorial, Continia, and other Business Central add-ons.

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export data using built-in tools and APIs. We provide guidance where required.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • XML
  • Excel (XLSX)
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • XML
  • Excel (XLSX)

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is delivered using Microsoft Azure and is designed to align with Microsoft’s published cloud availability targets. The underlying platform provides a target monthly uptime of 99.9% or higher, depending on the specific Azure services in use.

Availability is measured on a monthly basis and relates to access to core ERP functionality.

Service levels

Target availability: 99.9%+ per calendar month

The service benefits from Azure’s built-in resilience, redundancy and monitoring

Planned maintenance is communicated in advance and scheduled to minimise business impact

Unplanned maintenance is undertaken only where required to maintain security or service stability

Service credits
Where service availability falls below Microsoft’s stated availability targets:

Any service credits are provided by Microsoft under its standard Azure SLA, not by us directly

Service credits are subject to Microsoft’s terms and conditions and are not guaranteed

We will support customers in raising and progressing any valid service credit claims with Microsoft

This reflects standard practice for services delivered on Microsoft’s cloud platform.
Approach to resilience
The service is hosted on Microsoft Azure and is designed using cloud-native resilience principles aligned to the government’s Cloud Security Principle 2: Asset protection and resilience.

Resilience is achieved through:

Deployment within Microsoft Azure datacentres that provide built-in physical security, redundancy and environmental controls

Use of redundant infrastructure components, including compute, storage and networking

Data protection through regular automated backups and point-in-time restore capabilities

Platform-level monitoring and alerting to detect and respond to service issues proactively

Azure datacentres are designed to tolerate component failure without service impact, with resilience built in at multiple layers of the platform.

Where required by a customer or regulator, more detailed architectural and datacentre resilience information can be provided on request, subject to appropriate confidentiality.

This approach ensures the service remains available, secure and recoverable in the event of infrastructure, software or operational failure.
Outage reporting
Service availability and outages are monitored continuously using Microsoft Azure platform monitoring and service health tooling.

Outages and service issues are reported through:

Microsoft Azure Service Health, which provides a public status dashboard covering Azure services and regions

Email notifications for relevant service incidents and planned maintenance, configurable per customer tenant

Direct customer communication from FormusPro for incidents impacting the service, including status updates and resolution progress

There is no separate public API for outage reporting beyond the Azure platform capabilities. Where required, incident reports and post-incident summaries can be provided to customers on request.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using Microsoft Entra ID with role-based access control. Administrative privileges are granted on a least-privilege basis and reviewed regularly. Multi-factor authentication is enforced for all privileged accounts. Access is logged and monitored, with audit trails retained for compliance and investigation. Support access is provided only to authorised personnel and limited to the minimum scope and duration required, using just-in-time access where applicable. Customer data access follows documented approval processes and contractual controls, aligned to Microsoft security and compliance frameworks.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Other
Description of management access authentication
Management access is authenticated using Microsoft Entra ID (Azure AD) with mandatory multi-factor authentication. Access is role-based using least-privilege principles and enforced through conditional access policies. Certificate-based authentication and secure TLS connections are used where applicable. Administrative access is restricted to authorised personnel only and is logged and monitored. Username and password authentication alone is not permitted for management access.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
Information security policies and processes
FormusPro follows a formal information security management framework aligned to ISO/IEC 27001 principles and Microsoft best practice.

We maintain documented policies covering, as a minimum:

Information security governance and risk management

Access control and identity management

Data classification, handling and retention

Secure system configuration and change management

Incident management and breach reporting

Supplier and third-party security assurance

Business continuity and disaster recovery

Reporting structure

Overall accountability for information security sits with a board-level sponsor, supported by senior operational leads responsible for day-to-day security management. Security risks, incidents, and compliance matters are escalated through defined governance routes and reviewed as part of management reporting.

Policy enforcement and assurance

Policies are embedded into operational processes and enforced through:

Role-based access controls and least-privilege principles

Mandatory onboarding and periodic security awareness training

Use of Microsoft security tooling across identity, endpoint, cloud and data platforms

Regular review of access rights and system configurations

Incident response procedures with defined escalation and communication paths

Compliance is monitored through internal reviews, supplier assurance processes, and reliance on Microsoft Azure’s independently certified security controls where services are hosted.

This approach ensures policies are consistently applied, monitored, and improved over time, with clear ownership and accountability
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
FormusPro tracks all service components throughout their lifecycle using controlled asset and configuration records, aligned to Microsoft Azure and Dynamics platform standards.

Changes are logged, reviewed and approved through defined change management processes. Each change is assessed for security, availability and data protection impact before implementation. Where relevant, changes are tested in non-production environments prior to release.

Access to make changes is restricted using role-based access controls and least-privilege principles. All changes are auditable and supported by Microsoft’s underlying platform change and release controls.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We operate a risk-based vulnerability management process aligned to Microsoft and industry best practice. Potential threats are identified using Microsoft security advisories, Azure Service Health, Microsoft Defender alerts, supplier notifications and internal monitoring. Risks are assessed for relevance and impact before action is taken.

Platform-level security patches are applied by Microsoft as part of the managed cloud service. Application and configuration updates under our control are prioritised by severity, with critical patches deployed promptly and typically within days. Threat intelligence is sourced from Microsoft advisories, Azure security notifications and ongoing operational reviews.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is delivered using Microsoft Azure and Dynamics 365 native security logging, monitoring and alerting, including audit logs, security alerts and service health notifications. Potential compromises are identified through automated alerts, log review and exception monitoring. Alerts are triaged by authorised staff and escalated via defined incident management procedures. Incidents are assessed promptly, with containment, remediation and root cause analysis undertaken as required. Critical security incidents are responded to immediately, with initial assessment typically within hours, followed by corrective actions and customer communication where applicable
Incident management type
Supplier-defined controls
Incident management approach
We operate defined incident management processes aligned to ITIL principles and our ISO/IEC 27001 and IASME-certified information security management system. Pre-defined procedures exist for common events including service outages, security incidents and data issues. Incidents can be reported via our service desk, email or agreed support channels. Incidents are logged, prioritised and managed through to resolution with clear ownership. Where required, we provide incident updates and post-incident reports outlining impact, root cause and corrective actions. Major incidents are escalated in line with severity thresholds and coordinated with Microsoft where platform services are involved.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
Yes
Connected networks
Other
Other public sector networks
  • None – accessed securely via standard internet connectivity
  • Microsoft public cloud connectivity

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
1%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
3%
Between £1,000,001 and £2,500,000
4%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Sancert Ltd
ISO/IEC 27001 accreditation date
Monday 10 February 2025
What the ISO/IEC 27001 doesn’t cover
Nothing specific was excluded from our certification.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Citation
ISO 9001 accreditation date
Sunday 8 October 2023
What the ISO 9001 doesn’t cover
Nothing specifically was excluded in the scope for ISO 9001.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
B5d64ed8-d805-47b9-8d6d-d5b8b7930150
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
0f73a075-a547-4fa1-a2bd-df536b1062d2
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andrewmartin@formuspro.com. Tell them what format you need. It will help if you say what assistive technology you use.