ISO 27001 consultants for NHS and healthcare suppliers
Start with the finding that matters most, because it is the opposite of what a site funded by ISO 27001 consultancies would be expected to say: ISO 27001 does not replace the NHS Data Security and Protection Toolkit, and it cannot be submitted instead of it.
What the toolkit is, and who has to complete it
The NHS Data Security and Protection Toolkit is, in its own words, an online self-assessment tool that allows organisations to measure their performance against the National Data Guardian’s 10 data security standards.
On who must use it, the toolkit is equally direct: all organisations that have access to NHS patient data and systems must use this toolkit to provide assurance that they are practising good data security and that personal information is handled correctly.
That is a wider net than people expect. It is not only clinical suppliers. If your product touches patient data or connects to NHS systems — a scheduling tool, a document platform, an analytics service — you are inside it, and the assurance is an annual submission rather than a one-off.
Where ISO 27001 actually helps
Holding ISO 27001 does not exempt you from anything, and any consultancy suggesting otherwise is worth a second look. What it does is reduce the amount of separate evidence you have to assemble, because work already done for the management system can be reused against toolkit items rather than produced again.
The overlap is real and it is not trivial. A risk assessment and risk treatment plan, an access control policy with evidence of review, an incident management process with records of use, supplier controls, business continuity arrangements, staff awareness training records: all of these exist because clauses 6 to 10 and Annex A required them, and all of them are things the toolkit asks about.
The submission itself is still yours to make, annually, and the parts of the toolkit that have no ISO 27001 counterpart — the ones written specifically around NHS data and NHS systems — are still work.
The certification most NHS procurement actually names
If the requirement you have been sent names a certificate at all, it is more often Cyber Essentials or Cyber Essentials Plus than ISO 27001, because that is what the government’s procurement policy specifies. NHS bodies are inside the scope of that policy.
This ordering surprises people who assume the bigger standard subsumes the smaller one. It does not, for procurement purposes. Cyber Essentials is a defined scheme with a defined assessment, and a buyer specifying it wants that specific assessment. Some NHS buying organisations state in terms that ISO 27001 will not be accepted in its place.
The practical order for a supplier starting from nothing is usually: Cyber Essentials, then Cyber Essentials Plus if the contract requires it, then the toolkit submission, and ISO 27001 where a customer specifically asks for it or where you are selling outside the NHS as well. Doing ISO 27001 first and discovering it does not satisfy the requirement is an expensive and entirely avoidable order of operations.
What an assurance pack for a trust usually needs
Requirements vary between trusts and between frameworks, and the only reliable method is to read the specific one you have been sent rather than a general guide, including this one. That said, the recurring shape of the ask is:
- A current toolkit submission, if you touch patient data or NHS systems.
- Cyber Essentials or Cyber Essentials Plus, where the contract or framework specifies it.
- Evidence about the specific product, not the company in general — which is why the scope on any certificate matters more here than almost anywhere else.
- Answers about where data is processed and stored, and about sub-processors.
- Clinical safety documentation, where the product is a health IT system. This is a separate discipline from information security and needs separate people.
Ask the trust or the framework, in writing, which of these they require, before buying any of them. It is one email and it prevents the most common expensive mistake in this sector.
Three annual clocks, and they do not line up
The thing that catches suppliers in this sector is not any single requirement. It is that there are several, each renews annually, and none of them shares a date with the others.
The toolkit is an annual submission with its own deadline, set nationally. Cyber Essentials and Cyber Essentials Plus expire twelve months after certification, so their clock starts on whatever day you happened to certify. ISO 27001 runs on its own cycle: a surveillance audit in each of years one and two, recertification in year three, all scheduled around your certification body’s availability rather than around anything NHS-related.
Three clocks, three owners, and in most small suppliers the same one or two people behind all of them. The failure is rarely a decision to let something lapse. It is that a Cyber Essentials certificate quietly expires six weeks before a framework renewal asks for it, and the reassessment cannot be compressed into the gap.
The fix is unexciting and effective: one calendar, owned by a named person, with all three renewal dates and a reminder well ahead of each — far enough ahead to book an assessment, not just to notice. If you are certified to ISO 27001, this belongs inside the management system rather than beside it. Clause 9.3 requires a management review, and the status of external assurance obligations is exactly the kind of thing that review exists to surface while there is still time to act on it.
What this does not change
Whatever sits on top, the arithmetic underneath is the same for every sector. Audit days come from ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21) and are a function of the people inside your scope, your sites and your complexity. Surveillance is one third of the initial audit every year and recertification is two thirds in year three. Your certification body cannot be your consultant, and cannot do the internal audit clause 9.2 requires.
Work out the cost for your headcount, or see the full audit-day table.
Common questions
Does ISO 27001 replace the NHS Data Security and Protection Toolkit?
No. The toolkit is a separate annual self-assessment against the National Data Guardian's 10 data security standards and must be completed by all organisations with access to NHS patient data and systems. ISO 27001 cannot be submitted instead of it. What holding the certificate does is reduce how much separate evidence you have to assemble, because the risk assessment, policies, incident process and supplier controls you built for the management system can be reused against toolkit items.
Do we need Cyber Essentials as well?
Very probably, and it is worth establishing before you spend anything else. The government's procurement policy on Cyber Essentials applies to NHS bodies, and where a contract or framework specifies Cyber Essentials or Cyber Essentials Plus, that is the certificate being asked for. Some NHS buying organisations say explicitly that ISO 27001 is not an acceptable substitute. Read the requirement you were actually sent.
Which order should we do these in?
For a supplier starting from nothing, usually Cyber Essentials first, then Cyber Essentials Plus if the contract requires it, then the toolkit submission, then ISO 27001 if a customer specifically asks for it or you sell outside the NHS too. Cyber Essentials is the cheapest and fastest, it is most often what is actually specified, and the work is not wasted if you go on to the larger standard.
We only process anonymised data. Are we in scope?
Ask, rather than assuming, and ask the organisation giving you the data. The toolkit's own wording is about access to NHS patient data and systems, and whether a particular dataset falls inside that is a question about the data and the connection, not one a general guide can settle. Access to NHS systems can bring you into scope even where the data you see is limited.
Does the toolkit require an independent audit?
Requirements have changed over time and differ by organisation type and by the route you submit under, and some suppliers are required to have an independent audit accompanying the submission. Because this genuinely varies and changes year on year, check the current requirement on the toolkit itself for your organisation type rather than relying on any third-party summary of it.
Sources cited on this page
- NHS Data Security and Protection Toolkit
- PPN 014: Cyber Essentials Scheme (Cabinet Office procurement policy note)
- IASME, Cyber Essentials certification fees
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Get a costed answer, not a call-back to discuss pricing
Five questions, all of them click-only. Your details are the last step, never the first.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.