Winning a place on an NHS framework isn’t just about writing a strong bid. Before evaluators read a single word of your submission, they want evidence that your business meets a baseline of operational, financial, quality, and security standards. Getting those accreditations in order early is one of the most reliable ways to protect your bid from failing at the first hurdle. It’s also one of the clearest signals to procurement teams that your organisation is ready to deliver at scale.
This guide sets out the main requirements across each category, what’s changed recently, and what to prioritise if you’re planning ahead.
Framework agreements are the most common way of buying products and services across the NHS. They enable buyers to place orders without running a lengthy full tendering exercise, drawing from a predetermined list of accredited suppliers. That accreditation process is the gate. Without the right credentials in place, you won’t reach the evaluation stage, regardless of how strong your service offering is.
For procurements above threshold, suppliers must submit a standard selection questionnaire that assesses capability alongside financial and economic standing. Many of the mandatory criteria in that questionnaire are directly tied to the accreditations and certifications covered below. A pass/fail structure means there is no route around gaps, only through them.
| Category / Sector | Required Accreditations & Standards | Why It’s Mandatory / Impact |
|
All suppliers |
• ISO 9001 (Quality Management – UKAS accredited) • Carbon Reduction Plan (PPN 006) • Social Value Proposition (PPN 002) • Modern Slavery Assessment Tool (MSAT) |
These form the standard pass/fail threshold for almost all NHS framework Selection Questionnaires (SQs). |
|
Digital, SaaS & data |
• Cyber Essentials Plus (Enforced under PPN 014) • DSPT submission (With mandatory independent audit) • ISO 27001 (Information Security Management) |
Non-compliance or a lapsed DSPT status constitutes an immediate breach of contract and framework disqualification. |
| Clinical & care services |
• CQC registration • Robust clinical governance frameworks • Up-to-date safeguarding policies |
Legally required to deliver any patient-facing or regulated clinical care within the health service. |
| Physical goods, maintenance & works |
• MHRA registration • CE / UKCA Marking (as applicable) • CHAS, Constructionline, or SafeContractor |
Essential for NHS Supply Chain tenders, physical medical devices, or estate maintenance work. |
| Professional services & consultancy |
• Relevant professional body memberships • Professional indemnity insurance (typically £5m–£10m) |
Tailored thresholds are specified within each individual framework’s selection criteria. |
ISO 9001 (Quality Management) is the most commonly requested certification across NHS accredited frameworks. Many framework operators also require ISO 14001 (Environmental Management), and for any contract involving digital services, data handling, or system access, ISO 27001 (Information Security Management) is increasingly standard. For NHS, defence, and government contract work, UKAS-accredited certification is required. Procurement frameworks in these sectors will not accept non-UKAS-accredited certificates.
If you don’t yet hold these certifications, start the process well in advance. Total elapsed time from gap analysis to certificate is typically six to twelve months for an SME, though organisations with existing frameworks such as Cyber Essentials or a partial DSPT submission can move faster. Surveillance audits are also required on an ongoing basis, so factor annual costs into your compliance budget from the outset.
For any contract involving NHS systems, patient data, or digital services, Cyber Essentials has become a baseline requirement rather than a differentiator. Recent NHS cyber incidents have accelerated the focus on supply chain assurance, with NHS England and the National Cyber Security Centre reinforcing guidance on supply chain security throughout 2024 and 2025.
Individual NHS trusts and Integrated Care Boards set their own supplier cybersecurity requirements, meaning there is no blanket NHS-wide mandate, but the adoption of Cyber Essentials is accelerating. This is especially true for suppliers handling sensitive data or providing critical services. Software and SaaS vendors, IT support providers, and data processors should treat Cyber Essentials Plus as the de facto standard for NHS work.
Suppliers to the NHS who handle personal data or provide IT systems must now be certified under Cyber Essentials Plus, a requirement being enforced under PPN 014. This represents a significant shift in supplier expectations.
The DSPT is a mandatory annual self-assessment for any organisation that processes or accesses NHS health and care data. All organisations that have access to NHS patient data and systems must use this toolkit to provide assurance that they are practising good data security and that personal information is handled correctly.
For the 2025–2026 period, IT suppliers are required to complete a mandatory independent audit as part of their DSPT submission, with a deadline of 30 June 2026. If your DSPT submission lapses or falls below the required standard, this can constitute a breach of contract, with both commercial and reputational consequences. Full guidance on the toolkit and current requirements is available on the NHS England DSPT page.
Beyond the universal requirements, the accreditations you’ll need depend on the nature of your contract. For NHS Supply Chain tenders involving physical works or maintenance, construction-sector accreditations such as CHAS, Constructionline, or SafeContractor are typically mandatory at selection stage. Clinical or care service contracts will require CQC registration, clinical governance documentation, and evidence of current safeguarding policies. Medical device and consumables suppliers need MHRA registration alongside CE or UKCA marking, as applicable.
For professional services firms such as consultancies, recruitment agencies, or training providers, relevant professional body membership is expected alongside professional indemnity insurance at the levels specified in each framework’s selection questionnaire. Check each framework’s requirements carefully rather than assuming a standard threshold applies.
This is an area of increasing weight in NHS procurement, and one that catches suppliers off guard. The NHS has adopted PPN 002 (taking account of Social Value) and PPN 006 (Carbon Reduction Plans), requiring suppliers to publish a carbon reduction plan and state their social value proposition as part of framework bids. These are not box-tick exercises. They are evaluated and increasingly weighted in framework awards. If your organisation does not yet have a published Carbon Reduction Plan, address this alongside your accreditation programme.
Most NHS frameworks set minimum insurance thresholds: public liability of £5m or £10m is common, and some contracts require product liability or professional indemnity in addition. Alongside this, expect financial viability checks: credit scoring, filed accounts, and in some cases a minimum annual turnover relative to contract value. Review these thresholds for each specific framework before submitting an expression of interest; mismatches at selection stage are a common and entirely avoidable reason for disqualification.
Accreditations open the door, but procurement teams also expect your governance documentation to be current, consistent, and clearly relevant to the contract in question. Equality and diversity, modern slavery, data protection, and environmental policies all need to align with NHS supplier compliance requirements. What’s more, they must reflect your actual business practices, not boilerplate text last reviewed several years ago.
As part of this, confirm that your organisation has completed the Modern Slavery Assessment Tool. Confirmation of completion forms part of the selection questionnaire for NHS Supply Chain tenders, with results used to establish supplier risk.
The right time to audit your compliance position is before a framework opens, not after. Most NHS frameworks use selection questionnaires that score mandatory criteria on a pass/fail basis, and there is no opportunity to remedy gaps once the window has closed. A structured review six to twelve months before your target frameworks re-procure gives you the time to address shortfalls without the pressure of an imminent deadline.
NHS England’s Framework Accreditation Programme, which requires NHS buyers to procure through accredited framework hosts, has also reshaped the landscape for suppliers since April 2024. This makes it worth understanding not just what accreditations you hold, but which frameworks are now the mandated routes to market for your category. More detail on this is available on the NHS England procurement page.
If you’re uncertain which frameworks apply to your sector or what their specific requirements look like, our healthcare framework and DPS support covers everything from market mapping through to full bid management.
Do I need every accreditation listed here before I can bid?
Not necessarily. The specific requirements vary by framework, contract type, and value. ISO 9001 and Cyber Essentials are the most commonly universal, but sector-specific requirements like MHRA registration or CQC registration only apply where relevant. The starting point is always the selection questionnaire for the specific framework you are targeting.
How long does it take to get ISO certified?
For most SMEs, the full journey from gap analysis to certificate takes between six and twelve months. If you have existing frameworks in place (Cyber Essentials, a partial DSPT submission) the process can move faster. Build certification timelines into your business development planning rather than treating them as something to tackle once a tender is live.
What is the DSPT and does it apply to my business?
The DSPT applies to NHS organisations, suppliers, social care providers, charities, and private sector organisations working with the NHS. This includes those handling health or care data, using NHS systems, or delivering services under an NHS contract. If any of those apply to you, the annual submission is mandatory, not optional.
Can I use Cyber Essentials instead of ISO 27001?
They serve overlapping but distinct purposes. Cyber Essentials covers five technical controls and is the government procurement baseline under PPN 014, while ISO 27001 is broader, covering governance, risk management, physical security, and technology. The evidence overlaps substantially, but one does not replace the other. For NHS contracts involving sensitive data or system access, you are likely to need both.
What happens if my accreditation lapses during a framework contract?
This is a contractual risk, not just a procurement one. Most framework agreements require suppliers to maintain the accreditations they held at award throughout the contract term. A lapse can trigger suspension or removal from the framework. Build renewal dates into your compliance calendar and treat them with the same urgency as the original application.
Where do I start if I’m new to NHS bidding?
Begin with a gap analysis against the requirements of the frameworks most relevant to your service area. Identify which accreditations you hold, which you are working towards, and which represent longer lead times. From there, build a compliance roadmap with realistic timelines, and make sure your governance documentation reflects where your business actually is, not where you’d like it to be.
Accreditation is the foundation, but it’s only part of what it takes to win. If you’re preparing for an NHS framework bid and want to make sure your submission is as strong as your compliance position, we can help.
Bidding works with healthcare suppliers at every stage, from identifying the right frameworks and understanding selection criteria, to writing and reviewing bids that score. Whether you’re bidding for the first time or looking to strengthen a track record of NHS wins, we bring the sector knowledge and bid writing expertise to give your submission the best possible chance.
Get in touch with the team today to discuss your next NHS bid.
Bidding Ltd © 2026