1 April 2026

Common NHS contract terms: what to check before you bid

Contract terms are one of the easiest places for an NHS bid to go off course. A supplier may spend days refining the technical response, pricing carefully and lining up compliance evidence, only to realise too late that the contract carries obligations the business is not ready to accept.

That happens more often than it should because suppliers sometimes treat NHS contract terms as something to review after preferred bidder stage. In practice, the sensible point to start checking them is before you decide to invest too heavily in the bid at all.

At Bidding, we often see this issue most clearly where the opportunity looks familiar on the surface but uses a different contract model underneath. A supplier may assume the same commercial assumptions apply across NHS work, NHS Supply Chain frameworks and purchase order terms, when in reality the risk profile can shift quite a bit depending on what is being bought and how the procurement is structured.

Identifying the right contract model

“NHS terms” is often used as shorthand, but there is no single document that covers every NHS procurement.

For healthcare services, NHS England’s 2025/26 NHS Standard Contract remains the main reference point. The current contract is made up of Particulars, Service Conditions and General Conditions, with both full-length and shorter-form versions available for contracts from 1 April 2025.

For goods and non-clinical services, NHS England separately publishes terms and conditions for the supply of goods and the provision of services. The guidance makes it clear that these templates do not apply to contracts for healthcare services. It also distinguishes between versions aligned to the old Public Contracts Regulations 2015 and the Procurement Act 2023.

That sounds obvious, but it is a common source of confusion. If a supplier starts reviewing the wrong template, it can miss the clauses that matter most for the actual opportunity in front of it.

Why suppliers get caught out

A lot of contract problems do not come from obscure legal drafting. They come from assumptions.

Sometimes the supplier assumes the terms are “standard” and therefore must be low-risk. Sometimes it assumes anything difficult can be negotiated later. On other occasions, it notices one clause it does not like and focuses on that, while missing three or four other provisions that will have a more practical effect on delivery.

NHS bodies and NHS Supply Chain are not using contracts simply as formal paperwork. They are using them to define operational standards, reporting, information handling, delivery obligations, liability and remedies if things go wrong. Supplier monitoring continues beyond tender stage through economic and financial standing checks and ongoing contract management.

That means a contract review should not be reduced to “can legal sign this off?” The better question is whether the business can deliver under these terms without creating commercial risk it has not planned for. That is also where healthcare and NHS bid writing services can help, particularly when the bid response and the contract position need to line up.

The clauses suppliers should look at first

Some terms deserve attention earlier because they are more likely to create commercial or operational problems.

Liability and indemnities

This is usually near the top of the list. Suppliers need to understand whether liability is capped, whether different caps apply to different risks, and whether some liabilities are effectively uncapped. Data protection, IP infringement, confidentiality breaches and product-related liabilities can all be treated differently depending on the contract.

For MedTech and digital suppliers, this point matters even more because liability exposure can sit alongside cyber requirements, product performance issues or patient-impact concerns. That is one reason this topic overlaps naturally with Cyber Essentials Plus and information security for health and MedTech suppliers and insurance levels for healthcare and MedTech suppliers.

Data protection and information governance

If the contract involves patient data, staff data or any operational data exchange, the data terms need careful review. NHS England’s Standard Contract materials include a provider data processing agreement in the shorter-form contract pack, showing how embedded data handling obligations are in current NHS contracting.

The practical question is not only whether the supplier is comfortable with the wording. It is whether the internal processes, subcontractor arrangements and security controls match what the contract expects.

Service levels and performance management

A bid can look very attractive commercially until the supplier maps the service credits, KPIs, reporting duties and response times against how the service will actually run. Service level failures can have reputational as well as financial consequences, particularly in the NHS.

In healthcare settings, underestimating performance terms is risky. Service levels often connect directly to escalation, remedial action plans, withholding mechanisms or termination rights. Suppliers should be especially careful where the delivery model depends on third parties, specialist engineers, logistics partners or software uptime.

Change control and contract variations

NHS contracts can be detailed on how service changes, price changes or operational variations are handled. NHS England publishes separate guidance on varying the 2025/26 NHS Standard Contract and on updating multi-year contracts, which is a useful reminder that change is managed formally rather than informally.

This matters if your pricing depends on assumptions that may change, or if the service is likely to evolve after mobilisation.

Termination and exit obligations

Suppliers should review not just when the authority can terminate, but what happens after termination. Exit support, data return, cooperation obligations and continuity requirements can all create real cost and resource pressure.

This is one of the most overlooked parts of contract review because suppliers tend to focus on winning the work rather than planning for the end of it. Buyers, understandably, do not take that view.

Why purchase order terms should not be ignored

Purchase order terms are often treated as lighter-touch than a full contract, but that can be misleading.

Suppliers sometimes assume a purchase order arrangement is commercially simpler and therefore lower-risk. In practice, important terms on liability, acceptance, delivery, warranties, termination and data handling can still sit there. If the purchase order terms govern the relationship, they deserve the same basic scrutiny as a longer-form contract.

What to ask internally before you submit

A useful contract review is not just a legal exercise. It should involve the people who will have to live with the result.

Before submission, it is worth asking:

If the answer to those questions is unclear, the issue is usually not just the wording. It is that the contract has not been reviewed closely enough by the right people.

Where suppliers should be especially cautious

Some opportunities deserve more scrutiny than others.

That includes contracts involving sensitive data, connected devices, software or remote access; opportunities with unusual indemnities or low liability caps; arrangements that depend heavily on subcontractors; and any bid where the commercial model only works if service assumptions hold perfectly.

Suppliers should also be cautious where they are bidding through NHS Supply Chain or a framework route and assume the contract will be “off the shelf”. Frameworks and standard terms can still carry meaningful operational and commercial obligations. NHS Supply Chain expects continuing engagement through its portal, management processes and contract oversight.

A better way to think about contract review

The most useful question is usually not “can we sign this?” It is “can we deliver this without creating avoidable commercial risk?”

That change in mindset tends to improve bids. It forces the supplier to connect legal terms with delivery reality, insurance cover, cyber controls, reporting capacity and supply chain management. It also helps stop the common problem of making attractive promises in the tender response that become difficult to honour once the contract is live.

This is one reason the stronger suppliers tend to perform better across the whole NHS compliance picture. They do not treat Carbon Reduction Plans and Net Zero, the Modern Slavery Assessment Tool (MSAT), cyber requirements and contract terms as separate admin tasks. They review them together because the buyer will often read them together too.

How to approach NHS contracts

Common NHS contract terms are only “common” in the sense that they recur. They should not be assumed to be harmless, negotiable later or irrelevant until award.

For suppliers, the safest approach is to identify the contract model early, review the clauses that carry the biggest delivery and risk implications, and make sure the wider bid still makes sense in light of what the contract actually says.

That is usually the difference between spotting a manageable issue early and discovering a serious problem when there is very little room left to respond.