Organisations supplying the NHS often assume there is a single “NHS security standard” they need to meet. There is not. NHS supplier assurance is a stack of separate, overlapping instruments some contractually mandatory, some risk-based, some entirely voluntary and the ISO standards that sit alongside them play different roles depending on which instrument you are looking at. Conflating the two, or assuming one certification substitutes for another, is one of the most common ways suppliers misjudge what they actually need. This article sets out the current NHS supplier assurance landscape in England and maps ISO/IEC 27001, ISO/IEC 27701, ISO 22301, ISO/IEC 20000-1 and ISO 9001 against it with precision, including where a standard is explicitly named in NHS guidance, and where it is genuinely useful but not an official requirement. CFE Certification is a UKAS and IAS-accredited certification body conducting audits against all five standards.
The NHS Supplier Assurance Landscape
Five instruments do most of the work. Understanding what each one actually requires and from whom matters more than knowing the acronyms.
The Data Security and Protection Toolkit (DSPT)
DSPT is the foundation. It is a mandatory self-assessment, formally recognised as an NHS Information Standard, for any organisation with access to NHS patient data or systems, including NHS trusts, integrated care boards, and any supplier or processor handling NHS patient information. Organisations are rated Standards Met, Approaching Standards, Standards Exceeded (Standards Met plus an active Cyber Essentials Plus certificate), or Standards Not Met, and the current cycle requires full conformance by 30 June 2026. DSPT completion is written into the NHS Standard Contract as a condition on providers, and DSPT’s own supplier due-diligence guidance (Guide 10, “Accountable Suppliers”) tells commissioning NHS organisations to expect their critical IT suppliers to hold a current, UKAS-accredited ISO/IEC 27001 certificate, scoped to the service actually delivered, alongside Cyber Essentials and Cyber Essentials Plus.
Cyber Essentials Plus and Procurement Policy Note 014
Cyber Essentials Plus became a firmer requirement for NHS and central government contracts under Procurement Policy Note 014, effective 24 February 2025. It applies on a risk basis to contracts involving personal data, OFFICIAL-classified information, or public service delivery rather than blanket across all NHS spend. The detail that trips suppliers up most often: ISO 27001 is not an accepted substitute for Cyber Essentials Plus. PPN 014 treats ISO 27001 as broader management-system assurance that does not, on its own, verify the five specific technical controls Cyber Essentials tests: boundary firewalls, secure configuration, access control, malware protection and patch management. A supplier can hold both, but one does not stand in for the other.
HSCN connectivity: a common misconception
It is often assumed that connecting to the Health and Social Care Network requires ISO 27001 certification. NHS England’s own connection-governance guidance says otherwise: DSPT completion is not even required to gain HSCN access, and ISO 27001 and Cyber Essentials Plus are recommended helpful demonstrations of security maturity rather than mandated for connecting organisations. The formal accreditation obligation sits with the Consumer Network Service Provider supplying the connection, not with every organisation that uses it.
DTAC is the clearest procurement gateway, naming ISO 27001
The Digital Technology Assessment Criteria (DTAC) is the mandatory-in-practice gateway for procuring digital health technologies, apps and clinical platforms, assessed across four sections: clinical safety, data protection, technical security, and interoperability. It is under the technical security section that ISO 27001 is explicitly named and evidenced suppliers upload their certificate directly as part of the assessment. Of all the NHS procurement touchpoints, this is the one where ISO 27001 is asked for by name, rather than implied through broader risk-management language.
The NHS Cyber Security Supply Chain Charter is voluntary, but increasingly active
Launched in May 2025, the Charter sets out eight expectations for IT suppliers to the NHS: keeping systems patched and in support; achieving and maintaining DSPT Standards Met; deploying multi-factor authentication; running 24/7 monitoring of critical infrastructure; maintaining immutable backups with tested business continuity plans; running board-level incident response exercises; reporting incidents promptly; and ensuring software complies with secure-by-design principles. NHS England is explicit that signing the Charter creates no contractual or commercial obligation. What has changed is enforcement posture: in January 2026, NHS England wrote to around 36,000 suppliers signalling a move from pure self-declaration toward direct, evidence-based engagement asking suppliers, particularly those delivering critical patient-care services, to discuss and evidence their controls against the Charter. It remains voluntary in form, but the direction of travel toward active verification is clear.
Emergency preparedness and business continuity expectations
Underneath the cyber-specific frameworks sits a longer-standing set of resilience obligations. NHS-funded organisations must comply with the NHS Core Standards for Emergency Preparedness, Resilience and Response (EPRR) and NHS England’s Business Continuity Management Toolkit, both grounded in the Civil Contingencies Act 2004 and delivered contractually through the NHS Standard Contract. These obligations sit primarily with NHS bodies themselves, but they shape what NHS organisations expect to see from suppliers whose outages would disrupt patient care tested recovery plans, not just backups that exist on paper.
How the Five Standards Map to NHS Supplier Requirements
With the landscape above in view, here is where each standard genuinely fits being precise about what is explicitly named in NHS guidance and what is complementary best practice.
ISO/IEC 27001 the most consistently referenced standard
ISO 27001 appears more often in NHS supplier guidance than any other standard on this list: named in DSPT’s supplier due-diligence guidance, explicitly evidenced in DTAC’s technical security section, and recommended for HSCN-connected organisations. What it is not is a substitute for Cyber Essentials Plus where PPN 014 requires it, and it is not itself a mandatory gate for HSCN connectivity. Positioned accurately, ISO 27001 is the ISMS backbone that underpins the technical assertions DSPT and DTAC ask suppliers to evidence necessary context for those frameworks, not a replacement for them.
ISO/IEC 27701 is a strong fit for DSPT’s data protection assertions
No NHS document names ISO 27701 specifically, so it should not be presented as an official requirement. What it does do well is operationalise exactly the data-protection commitments DSPT already demands: lawful basis, data protection impact assessments, data subject rights, records of processing, breach notification and international transfer safeguards, alongside the processor obligations, sub-processor controls, audit rights, and DPIA cooperation that DSPT’s own supplier contract-clause guidance sets out. For suppliers processing NHS patient data under UK GDPR, a certified privacy information management system built on ISO 27701 gives a structured, auditable way to evidence those DSPT assertions, even though no NHS framework asks for the certificate by name.
ISO 22301 maps closely to a named Charter expectation
ISO 22301 is not cited by number in NHS guidance, but the NHS Cyber Security Supply Chain Charter asks, in plain terms, for exactly what it certifies: immutable backups and tested business continuity plans. NHS England’s own Business Continuity Management Toolkit and EPRR Framework reflect the same expectation at the level of NHS bodies themselves. For an IT or managed service supplier, a certified business continuity management system is a direct, evidence-based way to demonstrate the tested not merely documented recovery capability the Charter describes, and it speaks directly to the supplier-resilience concerns that recent NHS supply chain incidents have sharpened.
ISO/IEC 20000-1 complementary to NHS service expectations
ISO/IEC 20000-1 does not appear by name in DSPT, DTAC, PPN 014, the Charter or HSCN guidance. It should be presented candidly as complementary best practice rather than an NHS requirement. That said, NHS IT and managed service suppliers’ service desks, hosting providers, application management, and HSCN-connected network providers operate under the service-level, incident-management and availability expectations implicit in the NHS Standard Contract’s service conditions. ISO/IEC 20000-1 is the internationally recognised standard for exactly that discipline, and a certified service management system gives suppliers a structured way to demonstrate it, even where no NHS document specifically asks for the certificate.
ISO 9001 the clearest, most concrete NHS mandate of the five
Of all five standards, ISO 9001 has the most direct and dated official NHS requirement. NHS Supply Chain now requires ISO 9001 or ISO 13485 certification, issued by a UKAS-accredited body (or another IAF member), for suppliers bidding on framework agreements launched or renewed from February 2025 onward with valid certificate evidence covering all relevant products, services and subcontracted activities. NHS Supply Chain holds ISO 9001 itself, so the requirement reflects a standard the buying organisation already applies to its own operations. For suppliers on NHS Supply Chain frameworks specifically, this is not a “nice to have” it is a named, current procurement condition.
Recent Developments Worth Tracking
- January 2026: NHS England wrote to roughly 36,000 suppliers moving the voluntary Cyber Security Supply Chain Charter toward direct, evidence-based engagement rather than self-declaration alone.
- December 2025: DXS International, a supplier of GP practice software used by around 2,000 practices, suffered a ransomware attack a reminder that supply chain risk extends well beyond hospital pathology services into primary care software.
- March 2025: The ICO finalised a £3.07 million fine against Advanced (OneAdvanced) following its 2022 ransomware attack, which disrupted NHS 111 and other services, a concrete illustration of the regulatory exposure behind weak supplier-side security and continuity management.
- February 2025: Procurement Policy Note 014 took effect, tightening Cyber Essentials requirements for NHS and central government contracts, and NHS Supply Chain’s ISO 9001/ISO 13485 requirement for framework suppliers began applying to new and renewed agreements.
NHS supplier assurance is not a single checklist but a layered set of requirements, each with a different legal weight and a distinct relationship to the ISO standards that underpin it. ISO 27001 and ISO 9001 are the two standards with the clearest, most concrete footholds in official NHS guidance, one evidenced as recommended assurance across DSPT, DTAC and HSCN, the other as a direct procurement condition on NHS Supply Chain frameworks.
ISO 27701, ISO 22301, and ISO/IEC 20000-1 are not named requirements, but each maps closely onto specific, real expectations that NHS bodies already set out: data protection assertions, tested business continuity, and service management discipline, respectively. Suppliers who understand precisely which is which are better placed to invest in the right certification for the right reason. CFE Certification conducts UKAS- and IAS-accredited audits against ISO 27001, ISO 27701, ISO 22301, ISO/IEC 20000-1 and ISO 9001, including combined audits for organisations holding more than one certification.