30 March 2026

Cyber Essentials Plus and information security for health and MedTech suppliers

Cyber security requirements can look straightforward in NHS procurement. A tender asks for Cyber Essentials or Cyber Essentials Plus, the supplier checks whether a certificate is in place, and the issue can seem largely administrative. In reality, health and MedTech suppliers are often dealing with a wider set of assurance requirements that go beyond a single certification.

Suppliers assume that one certificate will answer every security question in the bid. Buyers are usually trying to establish something more practical than that. They want to know whether the supplier’s controls are proportionate to the risk and robust enough for a healthcare setting.

Where Cyber Essentials Plus fits

Cyber Essentials Plus is not an NHS-specific standard, but it is becoming more visible in NHS and wider public sector procurement.

In line with the government’s current Cyber Essentials procurement policy, evidence of holding Cyber Essentials or Cyber Essentials Plus certification, or equivalent, is required before contract award for in-scope procurements. Suppliers must recertify every 12 months to remain valid. Where a supplier is relying on an equivalent rather than the certificate itself, independent third-party verification is required to demonstrate Cyber Essentials Plus requirements have been met.

NHS Supply Chain, meanwhile, has gone further in spelling out what this means in practice for its suppliers. All suppliers in scope of Procurement Policy Note 014 must demonstrate compliance with Cyber Essentials Plus, or that they meet the criteria. It specifically says this applies where NHS Supply Chain personal data is handled or processed, or where IT or digital products and services are supplied.

That matters because many health and MedTech contracts involve patient data, hosted systems or connected devices. This brings technical security firmly into scope. Even where the product itself is not a software platform, the wider service model may still involve patient data, hosted systems, remote access, connected devices or supplier-side support arrangements that bring technical security into scope.

For suppliers still learning the main NHS procurement routes and platforms, cyber requirements can be one of the clearest signs that NHS bidding is rarely just about price and specification.

Why suppliers often get caught out

One reason this area causes problems is that suppliers tend to focus on the headline requirement and miss the surrounding detail.

A certificate on its own does not necessarily answer questions about scope. Buyers may want to know which legal entity the certification covers, whether it includes the relevant environment, whether subcontractors are in scope and whether the controls line up with the service being procured. By default, Cyber Essentials applies to the legal entity providing the goods or services. Contracting authorities should check the scope of the certificate where third-party information sharing is involved.

Timing is another issue. Suppliers sometimes assume they can sort certification out after bid submission if they are shortlisted. For in-scope procurements, the policy position is more demanding than that. The evidence is required before contract award, and expired certification is treated as uncertified unless there is a risk-based decision and the supplier can still demonstrate the appropriate certification or equivalent before data is passed.

The other difficulty is that Cyber Essentials Plus is often only one part of the assurance picture. A health technology supplier may meet that requirement and still face further scrutiny on product security, testing evidence, data processing or NHS-specific assurance routes. The wider assessment may also involve:

Why health and MedTech suppliers should think more broadly

This is where NHS procurement diverges significantly from standard public sector cyber requirements. It is also where health and MedTech suppliers most often find themselves underprepared.

If the product is a software-based digital health technology, DTAC may come into play. The NHS uses DTAC to assure digital health technology products across clinical safety, data protection, technical security, interoperability, usability and accessibility.

Within DTAC itself, where a product handles sensitive or personal information, or involves certain technical products and services, Cyber Essentials certification is required. Suppliers must also evidence vulnerability, load and penetration testing.

That means a MedTech supplier should not assume that Cyber Essentials Plus on its own closes the issue. A buyer may still expect to see how product testing is carried out, who conducted it and how often it happens. For connected products, platforms or software-enabled services, that supporting evidence can be just as important as the certificate itself.

Where the Data Security and Protection Toolkit fits

The Data Security and Protection Toolkit adds another layer. The DSPT says all organisations that have access to NHS patient data and systems must use the toolkit to provide assurance that they are practising good data security and handling personal information correctly.

The toolkit also allows organisations to record a Cyber Essentials Plus certification in their profile. Where an organisation achieves “Standards Met” and has a current Cyber Essentials Plus certification recorded, its status will display as “Standards Exceeded”.

That does not mean DSPT replaces Cyber Essentials Plus in every situation, or vice versa. It means suppliers need to understand how the different assurance mechanisms fit together. In practice, health and MedTech suppliers need to map the whole security evidence set, not just the most visible requirement in the tender.

What buyers are usually trying to establish

Buyers aren’t asking for Cyber Essentials Plus just to create another hoop to jump through. They are trying to understand whether the supplier can manage real cyber risk in the context of the service or product being procured.

For a health or MedTech supplier, that can include questions like:

This is why the strongest responses usually treat cyber security as a delivery issue rather than a certificate issue. The buyer wants confidence that the controls are real, current and relevant.

Common weak spots in bids

There are a few recurring problems in this area.

One is overclaiming. For example, a supplier references Cyber Essentials Plus but does not explain whether it covers the environment relevant to the contract.

Another is under-explaining. Here, the organisation has the right certification, but the bid does not show how technical testing, access controls, patching or supplier oversight are handled in practice.

A third is inconsistency. The DSPT says one thing, the tender response says another, and the data protection or security schedule raises questions the bid has not anticipated.

At Bidding, we also see bids where the cyber position is treated in isolation from the wider compliance picture. In practice, this topic often overlaps with common NHS contract terms, insurance levels for healthcare and MedTech suppliers and, for digital products, broader procurement readiness through DTAC and DSPT.

What suppliers should check before bidding

Before a live NHS submission, it is worth checking whether:

Suppliers that review those points early are usually in a much stronger position than those trying to join everything together in the final days before submission.

How Cyber Essentials Plus fits into the bigger picture

Cyber Essentials Plus matters, but it is rarely the whole story for health and MedTech suppliers.

In NHS procurement, buyers are usually trying to understand whether the supplier’s security controls are credible, proportionate and capable of standing up in a healthcare environment. The certificate can be an important part of that picture, but the bids that perform best are usually the ones that show how the wider evidence fits together as well.