Skip to content
Industry

Cyber Essentials for NHS Suppliers and Healthcare Organisations

How Cyber Essentials, DSPT and NHS supplier assurance fit together. Check the current organisation profile, actual tender and clinical-system scope rather than assume a universal mandate.

person walking on hallway in blue scrub suit

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

11 min read

Share

Section 01

Cyber Essentials for NHS Suppliers and Healthcare Organisations

Cyber Essentials can sit alongside the Data Security and Protection Toolkit (DSPT) in NHS supplier assurance. Organisations accessing NHS patient data or systems must use the applicable DSPT route. CE requirements depend on the relevant procurement and organisation profile; there is no universal CE mandate for every healthcare supplier or GP practice.

This guide explains how CE, DSPT, and NHS supplier due diligence fit together, what the controls actually ask of a healthcare organisation or NHS supplier, and the sector-specific issues that most often come up during assessment.

Section 02

Who needs Cyber Essentials in healthcare

Four groups should check their applicable DSPT and procurement requirements:

NHS suppliers

Any organisation providing goods or services to the NHS where the engagement involves access to NHS systems or patient data. This covers medical equipment suppliers, clinical software vendors, IT service providers, locum and staffing agencies, private healthcare providers on AQP contracts, and professional services firms doing NHS consultancy.

Private healthcare providers

Private hospitals, diagnostic imaging providers, and specialist clinics that accept NHS-funded patients under Any Qualified Provider (AQP) arrangements, or that conduct due diligence to NHS commercial standards as part of commercial hospital group expectations.

Clinical research and pharma

CROs, pharmaceutical companies, and medtech firms that handle patient data, clinical trial data, or NHS-linked research records.

GP, dental, and primary care

GP practices, dental practices, and primary care networks. Check the current DSPT organisation profile and NHS England or commissioner terms; do not assume an independent Cyber Essentials mandate for every practice.

Section 03

How Cyber Essentials and DSPT fit together

DSPT is the NHS's own data security assessment framework. Every organisation that accesses NHS patient data, connects to the NHS network, or processes NHS-commissioned patient information must use the applicable DSPT assessment route. Submission, publication and outcome requirements follow the current organisation profile; not every route uses the same status labels.

DSPT requirements vary by reporting year and organisation profile, including CAF-aligned routes. Check the current NHS England DSPT guidance. This guide does not establish assertion 8.3.4 as a universal version 9 CE mapping. CE can support evidence but does not replace the applicable toolkit assessment.

The practical relationship:

  • Cyber Essentials is the baseline cybersecurity certification
  • DSPT is the broader data security framework; CE-related evidence and any Plus exemptions depend on the current organisation profile and reporting year
  • Holding Cyber Essentials is not sufficient for DSPT on its own - DSPT covers information governance, training, incident response, and other domains CE does not touch
  • DSPT "Standards Met" is usually not sufficient for NHS procurement frameworks on its own - many frameworks also ask for CE directly

The healthiest posture for most NHS suppliers is to hold both: CE for the technical baseline, DSPT for the full NHS data governance scope.

Section 04

What NHS procurement frameworks require

Read the current framework and call-off documents, whether the buyer uses NHS Shared Business Services, Crown Commercial Service or direct procurement. PPN 014 includes NHS bodies but requires relevant and proportionate cyber controls, with equivalent controls accepted under its provisions. It is not a blanket certification rule for every NHS-adjacent service. G-Cloud listing and individual call-off requirements differ.

National-system integrations may also have NHS England supplier assurance requirements. Confirm the responsible service and exact integration terms; references to NHS Digital describe the former organisation, now part of NHS England. Keep DSPT, certification and system-specific assurance as separate checks.

Section 05

What healthcare infrastructure looks like for CE purposes

A typical NHS-adjacent organisation runs some mix of:

  • Microsoft 365 or Google Workspace for corporate email and productivity
  • A clinical or patient management system (SystmOne, EMIS Web, Cerner, Epic, MAXIMS, or a private-sector equivalent)
  • DSPT-linked platforms (NHSmail for communication with NHS colleagues)
  • Integration with NHS Spine, e-Referral, or SCR
  • On-premise clinical workstations (common in diagnostic imaging, pharmacy, labs)
  • A VPN or MPLS link to NHS networks
  • Medical devices connected to the network (imaging devices, lab analysers, pharmacy dispensing systems)

Clinical SaaS and vendor-managed systems can be in scope, alongside accessing endpoints, cloud configuration and identities. Document the shared-responsibility boundary; vendor management does not automatically remove a service from CE scope.

Section 06

Medical devices on the network

This is the Cyber Essentials question unique to healthcare. Connected medical devices (MRI scanners, lab analysers, pharmacy robots, pathology slide scanners) often run old operating systems - Windows 7, Windows XP, stripped-down Linux distributions - because the medical device regulations make patching them complex. The device manufacturer may not have released a security patch in years, even for known vulnerabilities.

The workable Cyber Essentials positions:

Position 1 - Sub-set exclusion

Medical devices are placed on an isolated network segment with no routing to the rest of the in-scope estate. User credentials on the device are entirely separate from corporate identity. The device has no direct internet access. Documented as an isolated clinical network sub-set in the questionnaire.

Position 2 - Resolve unsupported in-scope software

Upgrade, replace or decommission software that fails CE support requirements. Restrictive firewall rules, logging and access controls can reduce risk but do not by themselves waive mandatory supported-software controls.

Position 3 - Plan replacement without claiming present compliance

A future replacement plan is useful risk management, but does not make a currently non-compliant device compliant. Confirm an approved scope exclusion or resolve the control gap before certification.

What does not work is ignoring the device entirely because "it is a medical device, it is not really IT". It is IT. It is on your network. It is in scope unless you have documented why it is not.

Section 07

NHSmail, Spine access, and the corporate identity boundary

Many NHS suppliers have NHSmail accounts for corresponding with NHS colleagues and may have Spine access for specific systems. These national services are now overseen through NHS England and their service providers; verify the current owner and shared responsibilities. They count as cloud services that your staff use to access NHS data.

For Cyber Essentials purposes, the relevant questions are:

  • Are NHSmail accounts protected with MFA? (NHSmail has its own MFA approach; confirm your staff have it enabled per NHSmail policy.)
  • Is NHSmail accessed from managed devices or personal devices? (BYOD questions apply here the same as anywhere.)
  • Is your Spine access via named individual smart cards, not shared? (It usually is - smart cards are the NHS default - but confirm.)

Record the actual MFA, device and account configuration and current service requirements. A managed-device-only statement alone is not proof that all CE controls are met.

Section 08

The right-to-work and payroll overlap

Healthcare organisations, particularly locum and staffing agencies, handle the same intense right-to-work and payroll documentation that general recruitment agencies do - plus additional healthcare-specific data (DBS checks, NMC/GMC registration numbers, revalidation evidence, occupational health records). These records are personal data. Health information may be special-category data under UK GDPR Article 9; DBS criminal-offence information is governed separately by Article 10 and applicable UK law. Registration numbers and payroll records are not automatically special-category data. The CE questions about access control, MFA, and secure storage apply with extra emphasis.

Section 09

The five healthcare-specific failures I see

Medical devices missing from the questionnaire

Applicant answers as if the clinical network does not exist. First thing the assessor asks about.

NHSmail accessed from BYOD

Personal phones accessing NHSmail must meet the applicable in-scope CE controls and current NHSmail policy. MDM and conditional access can help enforce controls, but lack of MDM alone is not an automatic CE failure.

DSPT-aligned but not CE-aligned

Organisation has DSPT "Standards Met" but the underlying technical controls have drifted - MFA coverage is incomplete, patching is behind, leaver processes are inconsistent. DSPT does not always catch this at the granularity CE does.

Shared logins on the PMS

The practice management system has a shared "reception" login that ten receptionists use. Same issue as any shared account - fails user access control under v3.3.

Ancient Windows workstations at a branch

Main office is on Windows 11 but a satellite clinic still has two Windows 7 diagnostic PCs "because they run a specific piece of kit". Either isolate them properly (Position 1 above) or replace them.

Section 10

Practical path for an NHS supplier

If you are a small-to-medium NHS supplier aiming for CE:

1. Confirm your DSPT route and outcome. Use the current organisation profile and reporting year; not every route uses Standards Met. Check the buyer’s actual DSPT and certification requirements.

2. Enumerate every system that holds NHS-linked data. Include clinical systems, NHSmail, Spine, integrated platforms, and corporate systems that reference NHS data.

3. Check MFA coverage. Apply the current CE requirements to in-scope cloud services and other applicable access, and verify current NHSmail policy and shared responsibilities.

4. Isolate medical devices. If you run clinical hardware, declare the scope posture explicitly.

5. Enrol staff laptops in MDM. Intune or Jamf, with baseline security policies.

6. Submit. CE from £299.99 + VAT; most NHS suppliers fall into the small (10-49) or medium (50-249) tiers.

Section 11

Bottom line

Healthcare suppliers should check the exact buyer, data, DSPT profile and system-integration obligations. Current CE can demonstrate the technical baseline, but it is not a substitute for the broader DSPT and information-governance requirements.

Get the scope right, apply the current CE controls and establish which DSPT and certification requirements your buyer actually sets. These checks support assurance without claiming a universal dual-certification mandate.

Check your readiness | View pricing | Talk to an assessor

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Ready to get certified?

Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.