Cyber Essentials for NHS Suppliers and Healthcare Organisations
How Cyber Essentials, DSPT and NHS supplier assurance fit together. Check the current organisation profile, actual tender and clinical-system scope rather than assume a universal mandate.

Section 01
Cyber Essentials for NHS Suppliers and Healthcare Organisations
Cyber Essentials can sit alongside the Data Security and Protection Toolkit (DSPT) in NHS supplier assurance. Organisations accessing NHS patient data or systems must use the applicable DSPT route. CE requirements depend on the relevant procurement and organisation profile; there is no universal CE mandate for every healthcare supplier or GP practice.
This guide explains how CE, DSPT, and NHS supplier due diligence fit together, what the controls actually ask of a healthcare organisation or NHS supplier, and the sector-specific issues that most often come up during assessment.
Section 02
Who needs Cyber Essentials in healthcare
Four groups should check their applicable DSPT and procurement requirements:
NHS suppliers
Any organisation providing goods or services to the NHS where the engagement involves access to NHS systems or patient data. This covers medical equipment suppliers, clinical software vendors, IT service providers, locum and staffing agencies, private healthcare providers on AQP contracts, and professional services firms doing NHS consultancy.
Private healthcare providers
Private hospitals, diagnostic imaging providers, and specialist clinics that accept NHS-funded patients under Any Qualified Provider (AQP) arrangements, or that conduct due diligence to NHS commercial standards as part of commercial hospital group expectations.
Clinical research and pharma
CROs, pharmaceutical companies, and medtech firms that handle patient data, clinical trial data, or NHS-linked research records.
GP, dental, and primary care
GP practices, dental practices, and primary care networks. Check the current DSPT organisation profile and NHS England or commissioner terms; do not assume an independent Cyber Essentials mandate for every practice.
Section 03
How Cyber Essentials and DSPT fit together
DSPT is the NHS's own data security assessment framework. Every organisation that accesses NHS patient data, connects to the NHS network, or processes NHS-commissioned patient information must use the applicable DSPT assessment route. Submission, publication and outcome requirements follow the current organisation profile; not every route uses the same status labels.
DSPT requirements vary by reporting year and organisation profile, including CAF-aligned routes. Check the current NHS England DSPT guidance. This guide does not establish assertion 8.3.4 as a universal version 9 CE mapping. CE can support evidence but does not replace the applicable toolkit assessment.
The practical relationship:
- Cyber Essentials is the baseline cybersecurity certification
- DSPT is the broader data security framework; CE-related evidence and any Plus exemptions depend on the current organisation profile and reporting year
- Holding Cyber Essentials is not sufficient for DSPT on its own - DSPT covers information governance, training, incident response, and other domains CE does not touch
- DSPT "Standards Met" is usually not sufficient for NHS procurement frameworks on its own - many frameworks also ask for CE directly
The healthiest posture for most NHS suppliers is to hold both: CE for the technical baseline, DSPT for the full NHS data governance scope.
Section 04
What NHS procurement frameworks require
Read the current framework and call-off documents, whether the buyer uses NHS Shared Business Services, Crown Commercial Service or direct procurement. PPN 014 includes NHS bodies but requires relevant and proportionate cyber controls, with equivalent controls accepted under its provisions. It is not a blanket certification rule for every NHS-adjacent service. G-Cloud listing and individual call-off requirements differ.
National-system integrations may also have NHS England supplier assurance requirements. Confirm the responsible service and exact integration terms; references to NHS Digital describe the former organisation, now part of NHS England. Keep DSPT, certification and system-specific assurance as separate checks.
Section 05
What healthcare infrastructure looks like for CE purposes
A typical NHS-adjacent organisation runs some mix of:
- Microsoft 365 or Google Workspace for corporate email and productivity
- A clinical or patient management system (SystmOne, EMIS Web, Cerner, Epic, MAXIMS, or a private-sector equivalent)
- DSPT-linked platforms (NHSmail for communication with NHS colleagues)
- Integration with NHS Spine, e-Referral, or SCR
- On-premise clinical workstations (common in diagnostic imaging, pharmacy, labs)
- A VPN or MPLS link to NHS networks
- Medical devices connected to the network (imaging devices, lab analysers, pharmacy dispensing systems)
Clinical SaaS and vendor-managed systems can be in scope, alongside accessing endpoints, cloud configuration and identities. Document the shared-responsibility boundary; vendor management does not automatically remove a service from CE scope.
Section 06
Medical devices on the network
This is the Cyber Essentials question unique to healthcare. Connected medical devices (MRI scanners, lab analysers, pharmacy robots, pathology slide scanners) often run old operating systems - Windows 7, Windows XP, stripped-down Linux distributions - because the medical device regulations make patching them complex. The device manufacturer may not have released a security patch in years, even for known vulnerabilities.
The workable Cyber Essentials positions:
Position 1 - Sub-set exclusion
Medical devices are placed on an isolated network segment with no routing to the rest of the in-scope estate. User credentials on the device are entirely separate from corporate identity. The device has no direct internet access. Documented as an isolated clinical network sub-set in the questionnaire.
Position 2 - Resolve unsupported in-scope software
Upgrade, replace or decommission software that fails CE support requirements. Restrictive firewall rules, logging and access controls can reduce risk but do not by themselves waive mandatory supported-software controls.
Position 3 - Plan replacement without claiming present compliance
A future replacement plan is useful risk management, but does not make a currently non-compliant device compliant. Confirm an approved scope exclusion or resolve the control gap before certification.
What does not work is ignoring the device entirely because "it is a medical device, it is not really IT". It is IT. It is on your network. It is in scope unless you have documented why it is not.
Section 07
NHSmail, Spine access, and the corporate identity boundary
Many NHS suppliers have NHSmail accounts for corresponding with NHS colleagues and may have Spine access for specific systems. These national services are now overseen through NHS England and their service providers; verify the current owner and shared responsibilities. They count as cloud services that your staff use to access NHS data.
For Cyber Essentials purposes, the relevant questions are:
- Are NHSmail accounts protected with MFA? (NHSmail has its own MFA approach; confirm your staff have it enabled per NHSmail policy.)
- Is NHSmail accessed from managed devices or personal devices? (BYOD questions apply here the same as anywhere.)
- Is your Spine access via named individual smart cards, not shared? (It usually is - smart cards are the NHS default - but confirm.)
Record the actual MFA, device and account configuration and current service requirements. A managed-device-only statement alone is not proof that all CE controls are met.
Section 08
The right-to-work and payroll overlap
Healthcare organisations, particularly locum and staffing agencies, handle the same intense right-to-work and payroll documentation that general recruitment agencies do - plus additional healthcare-specific data (DBS checks, NMC/GMC registration numbers, revalidation evidence, occupational health records). These records are personal data. Health information may be special-category data under UK GDPR Article 9; DBS criminal-offence information is governed separately by Article 10 and applicable UK law. Registration numbers and payroll records are not automatically special-category data. The CE questions about access control, MFA, and secure storage apply with extra emphasis.
Section 09
The five healthcare-specific failures I see
Medical devices missing from the questionnaire
Applicant answers as if the clinical network does not exist. First thing the assessor asks about.
NHSmail accessed from BYOD
Personal phones accessing NHSmail must meet the applicable in-scope CE controls and current NHSmail policy. MDM and conditional access can help enforce controls, but lack of MDM alone is not an automatic CE failure.
DSPT-aligned but not CE-aligned
Organisation has DSPT "Standards Met" but the underlying technical controls have drifted - MFA coverage is incomplete, patching is behind, leaver processes are inconsistent. DSPT does not always catch this at the granularity CE does.
Shared logins on the PMS
The practice management system has a shared "reception" login that ten receptionists use. Same issue as any shared account - fails user access control under v3.3.
Ancient Windows workstations at a branch
Main office is on Windows 11 but a satellite clinic still has two Windows 7 diagnostic PCs "because they run a specific piece of kit". Either isolate them properly (Position 1 above) or replace them.
Section 10
Practical path for an NHS supplier
If you are a small-to-medium NHS supplier aiming for CE:
1. Confirm your DSPT route and outcome. Use the current organisation profile and reporting year; not every route uses Standards Met. Check the buyer’s actual DSPT and certification requirements.
2. Enumerate every system that holds NHS-linked data. Include clinical systems, NHSmail, Spine, integrated platforms, and corporate systems that reference NHS data.
3. Check MFA coverage. Apply the current CE requirements to in-scope cloud services and other applicable access, and verify current NHSmail policy and shared responsibilities.
4. Isolate medical devices. If you run clinical hardware, declare the scope posture explicitly.
5. Enrol staff laptops in MDM. Intune or Jamf, with baseline security policies.
6. Submit. CE from £299.99 + VAT; most NHS suppliers fall into the small (10-49) or medium (50-249) tiers.
Section 11
Bottom line
Healthcare suppliers should check the exact buyer, data, DSPT profile and system-integration obligations. Current CE can demonstrate the technical baseline, but it is not a substitute for the broader DSPT and information-governance requirements.
Get the scope right, apply the current CE controls and establish which DSPT and certification requirements your buyer actually sets. These checks support assurance without claiming a universal dual-certification mandate.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Ready to get certified?
Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.
Related solutions
Continue exploring Fig Group
Related guides
Continue reading
Technical Guides
Cyber Essentials Tender Deadline Emergency: The 48-Hour Playbook
You have 48 hours until the tender closes and you have just discovered it requires Cyber Essentials. This is the hour-by-hour playbook I give to every organisation in this situation. It works more often than you might expect.
Read articleFrameworks
Cyber Essentials vs ISO 27001: which does your customer actually want?
Check the exact customer or tender requirement before choosing Cyber Essentials, Plus or ISO 27001. Compare their different assurance purposes and permitted evidence.
Read articleGuides
Cyber Essentials Reading: a practical certification guide
Reading technology and business-service suppliers should distinguish certification of their own organisation from assurance about the products they resell or the customer environments they support. Cyber Essentials can provide a recognised baseline, but its scope must be clear in a proposal or supplier response.
Read article

