Penetration Testing7 min read27 September 2026

Penetration Testing for NHS Suppliers UK — Security Requirements for Healthcare Vendors

NHS suppliers face strict cybersecurity requirements including DSPT compliance and pen testing obligations. This guide explains what NHS vendors need to pass security assessments and keep contracts.

By Yrzo AI — UK cybersecurity specialists

Why NHS Suppliers Face Tougher Security Scrutiny Than Most Sectors

The NHS handles some of the most sensitive personal data in existence — medical records, diagnostic results, mental health histories, prescriptions. A breach affecting NHS systems does not just cost money. It affects patient safety, delays treatment, and can expose deeply private information about millions of people.

As a result, organisations supplying software, services, or data processing to NHS bodies are held to a higher standard than the average UK business. If you supply the NHS — whether as a software vendor, managed service provider, cloud storage company, or even a relatively simple SaaS tool — your security posture is subject to formal assessment.

This guide explains what NHS suppliers need to know about security requirements, the Data Security and Protection Toolkit, and why penetration testing is increasingly central to vendor security assessments.

The Data Security and Protection Toolkit (DSPT)

The DSPT is the NHS's primary mechanism for assessing the security of organisations that handle NHS patient data. It applies to NHS organisations themselves, but also to any third party that processes NHS data.

If your product handles patient-identifiable information — even indirectly, even in a limited scope — you are likely required to complete the DSPT. The toolkit is administered by NHS England and aligned with the National Data Guardian's ten data security standards.

The ten standards cover:

1. People — training, awareness, and responsible individuals named 2. Staff responsibilities — acceptable use policies, leaver procedures 3. Training — mandatory data security training for all staff with system access 4. Managing data access — minimum necessary access, MFA, review of access rights 5. Process reviews — regular review of information governance processes 6. Cyber threats — documented approach to identifying and responding to threats 7. Safe configuration — software patching, secure configuration, mobile device management 8. Unsupported software — no unsupported operating systems or applications in use 9. IT protection — firewalls, antivirus, and network security controls 10. Accountable suppliers — contractual obligations flowing down to your own sub-processors

For suppliers, the relevant DSPT assertions typically fall under Standards 6, 7, 8, 9, and 10. Standard 6 — cyber threats — is where penetration testing directly comes in.

When Penetration Testing Is Required for NHS Suppliers

The DSPT does not mandate penetration testing as an explicit checkbox for all organisations. However, several assessment routes effectively require it:

**High-risk data processing:** If your system processes sensitive patient data (clinical records, mental health data, safeguarding information) and does so in an internet-facing application, the DSPT assessment for that system will expect evidence of security testing — and a credible security testing programme for internet-facing systems means penetration testing.

**NHS Digital and NHS England procurement requirements:** Many NHS Digital contracts explicitly require suppliers to evidence penetration testing as part of supplier assurance. The Clinical Safety team and the Data Security Centre both use penetration testing reports as evidence of technical due diligence.

**DCB0129 and DCB0160 compliance:** These clinical safety standards apply to health software. While they focus on clinical risk rather than information security directly, the technical documentation they require overlaps with security assurance processes, and a penetration test report demonstrates rigour.

**Cyber Essentials Plus:** NHS England recommends Cyber Essentials Plus for suppliers accessing NHS systems. Cyber Essentials Plus involves a technical audit (see our guide to CE+ requirements) that verifies firewall configuration, patching, access controls, and malware protection on systems in scope.

What NHS Procurement Teams Actually Ask For

When responding to NHS supplier questionnaires or going through a formal procurement process, expect to be asked:

- **Do you hold Cyber Essentials or Cyber Essentials Plus certification?** The NCSC-backed scheme is widely used as a baseline indicator. - **Have you completed a DSPT submission?** At what level (Standards Exceeded, Standards Met, Approaching Standards)? - **When was your last penetration test?** Date, scope, and methodology. - **What vulnerabilities were found and how were they remediated?** An executive summary or remediation report is often requested. - **Do you have ISO 27001 certification?** Not universally required, but increasingly preferred for Tier 1 NHS contracts.

A penetration test report from a CREST-accredited firm carries more weight in NHS procurement than a report from an unaccredited assessor. CREST (the Council of Registered Ethical Security Testers) is the UK's primary professional body for penetration testers, and NHS Digital specifically references CREST accreditation in its supplier guidance.

The WannaCry Context

NHS organisations have not forgotten WannaCry. The 2017 attack encrypted systems across 80 NHS trusts, cancelled approximately 19,000 appointments, and cost the NHS an estimated £92 million. The root cause was unpatched Windows XP systems — a known vulnerability exploited via a tool developed by the NSA and leaked by Shadow Brokers.

WannaCry did not breach NHS suppliers directly. But it exposed the catastrophic consequences of poor patching hygiene in healthcare infrastructure. Since 2017, NHS Digital's CareCERT service has been significantly more active in issuing security guidance and vulnerability alerts to NHS organisations and their suppliers. The tolerance for "we weren't aware of the risk" has dropped dramatically.

Practical Steps for NHS Suppliers

If you supply or are looking to supply the NHS:

**Register for the DSPT.** Even if it is not yet mandatory for your contract, completing it signals seriousness and gives you a roadmap of what NHS bodies expect.

**Achieve Cyber Essentials at minimum.** Cyber Essentials Plus is preferred. Both are affordable relative to the contract value of NHS work.

**Run an automated security scan of your application.** This surfaces the most common web application vulnerabilities — the ones that appear in DSPT assessments and NHS security questionnaires — quickly and inexpensively. Yrzo AI's automated scanner covers 44 OWASP checks and returns a plain-English report in under 20 minutes.

**Commission a manual penetration test before a major NHS procurement.** Budget £4,000–£10,000 for a credible web application test from a CREST-accredited firm. The report is a commercial asset in the procurement process.

**Document your remediation.** A clean report is good. A report showing vulnerabilities found and a remediation log showing they were fixed is better. It demonstrates a functioning security programme, not just a point-in-time assessment.

The NHS is one of the UK's largest technology buyers. Suppliers who invest in demonstrable security have a competitive advantage that grows as procurement teams become more technically sophisticated.

Find out if your website has these vulnerabilities

Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.

Scan your website →