ISO 27001 for healthcare companies: DSPT, DTAC and getting certified

How UK health-tech firms, care providers and NHS suppliers use ISO 27001 to answer procurement security questions, and how it sits alongside the NHS DSPT, DTAC and Cyber Essentials Plus without duplicating the work.

The short answer: ISO 27001 is the security certification UK healthcare buyers ask for most often, because it proves you run a managed information security management system instead of a folder of good intentions. It does not replace the NHS Data Security and Protection Toolkit, and it is not a UK GDPR certificate. What ISO 27001 gives a healthcare company is one evidence base, covering risk, policies, access records and supplier reviews, that answers most of what DSPT, DTAC and NHS procurement teams ask you to show.

Healthcare buying has changed. A trust's information governance lead, a private hospital group's DPO and a care provider's operations director are all asking suppliers the same question in different words: prove you can hold patient or staff data without becoming the reason we end up in an ICO enforcement notice. For a health-tech company with thirty staff, that question usually arrives as a 200-line security questionnaire, two weeks before the deal was meant to close. Certification is how you answer it once rather than forty times.

{{snapshot}}

ISO 27001 in healthcare at a glance

  • It is a procurement key, not a legal requirement. No UK law names ISO 27001, but NHS and private healthcare buyers ask for it constantly.
  • The DSPT is separate and still required for organisations with access to NHS patient data or systems. Your ISMS supplies much of the evidence, not the submission itself.
  • Health data is special category data under UK GDPR, so access control, logging and breach response get read far more closely than in other sectors.
  • ISO 27001:2022 has 93 Annex A controls in four themes. Around fifteen of them carry the weight in a clinical or patient-facing product.
  • Two to three months is realistic for a focused scale-up with a tight scope and someone senior who genuinely owns it.

{{/snapshot}}

Why ISO 27001 keeps coming up in NHS and private healthcare deals

Healthcare buyers cannot inspect every supplier. A trust may have hundreds of digital suppliers and a small information governance team, so it does what any rational buyer does and asks for a certificate somebody else has already tested. ISO 27001 is that certificate: issued after an accredited body audits your management system, not your marketing site.

The second reason is exposure. Health records are special category data, and losing them is not an abstract harm. A cancelled clinic list is a patient who does not get seen. Procurement teams understand that, which is why the security section of a healthcare tender runs longer and asks harder questions than the one you filled in for a retail customer last year.

Third, an ISMS travels. The same controls answer a private hospital group's due diligence, a US customer's SOC 2 questions and your cyber insurance renewal. That matters most for companies selling into both NHS and private markets, where every buyer has a different form and the same underlying worry. For the sector backdrop, see how cyber security is changing in the healthcare industry. For what certification does to your defences specifically, read how ISO 27001 certification improves healthcare cyber security.

DSPT, DTAC and Cyber Essentials Plus: who asks for what

These get muddled constantly, usually by whoever forwarded you the questionnaire. They are not competing standards. They are different questions, asked by different people, about the same organisation.

The NHS Data Security and Protection Toolkit is an annual self-assessment for organisations with access to NHS patient data or NHS systems. It grew out of the National Data Guardian's data security standards, and NHS England has been moving parts of it onto a Cyber Assessment Framework-aligned model, so confirm which version applies to your organisation type before you scope the work. ISO 27001 certification supports a large share of the evidence you will be asked for. It does not exempt you from submitting.

DTAC, the Digital Technology Assessment Criteria, is what NHS and social care organisations use to assess a digital health product before they buy it. It covers clinical safety, data protection, technical security, interoperability, and usability and accessibility. The technical security section asks directly about certifications and testing, so a valid certificate plus a recent penetration test does much of the answering. Clinical safety is a separate discipline with its own standards, and no ISMS will cover it for you.

Cyber Essentials Plus is the NCSC-backed scheme covering five technical controls, verified hands-on by an assessor rather than self-declared. It is cheap, quick and deliberately narrow. Plenty of NHS contracts ask for it alongside ISO 27001, and some ask for it first while you work towards the bigger certification.

What it isWho asks for itWhat it provesOverlap with ISO 27001
NHS DSPTNHS England, trusts, anyone passing you NHS patient dataAnnual self-assessment against NHS data security expectationsHigh. Policies, training records, access control and incident evidence are reusable
DTACNHS and social care organisations buying digital health techProduct-level assessment across safety, data protection, security, interoperability and usabilityPartial. Covers the technical security and data protection sections, not clinical safety
Cyber Essentials PlusNHS contracts, public sector buyers, insurersFive technical controls, independently testedModerate. Sits inside your technological controls, but proves configuration rather than governance
ISO 27001NHS suppliers' customers, private providers, enterprise and international buyersA certified, audited management system for information security riskThe base layer the others draw from

The controls that carry the most weight when you hold patient data

All 93 Annex A controls apply until you justify otherwise in your Statement of Applicability. In healthcare, auditors and buyers reliably dig hardest into the same handful.

  • Access control and privileged access. Role-based access mapped to clinical and administrative roles, with support engineers held to break-glass access that is logged and reviewed. "Everyone in engineering can see production" ends a lot of healthcare deals.
  • Supplier and subprocessor security. Your hosting provider, your transcription API, your analytics tool. Buyers want the list, the due diligence behind it and the contract clauses. Sub-processor sprawl is the single most common gap we see.
  • Logging and monitoring. Who accessed which patient record, when, and how you would know if that access was inappropriate. Special category data raises the bar here well above a generic SaaS baseline.
  • Business continuity and availability. Downtime in healthcare has clinical consequences. Tested recovery plans beat documented ones, and auditors ask when you last actually ran the test.
  • Secure development. Code review, dependency management, separation of environments and, above all, no live patient data in test systems.
  • Screening and awareness. Right-to-work and reference checks, DBS where the role requires it, and training that people demonstrably completed rather than were emailed.

The ICO's guidance on special category data is worth reading alongside your risk assessment, because the two documents should agree with each other. If your risk register treats a patient record like a marketing email address, an auditor will notice before a regulator does.

Running DSPT and ISO 27001 from one evidence base

The expensive mistake is treating each framework as a separate project with its own spreadsheet, its own owner and its own annual panic. Health-tech companies end up maintaining three descriptions of the same access control process, which then drift apart, which is exactly what an auditor is trained to find.

Do it once instead. Build the ISMS properly, then map its outputs to DSPT assertions and DTAC sections. One asset inventory. One risk register that auto-populates from those assets so nothing gets missed when you add a new database. One set of policies mapped to controls, versioned, with evidence of approval. One evidence store where the annual access review lives, tagged to every framework that asks for it.

This is where compliance software earns its keep. Hicomply links policy and procedure templates directly to controls, so a single approved document satisfies the ISO clause and the toolkit assertion at the same time, and the dashboard shows where the ISMS actually stands rather than where you hoped it stood in January. What you build for ISO 27001 also powers SOC 2 and whatever framework a new customer invents next quarter.

A practical route to certification for a health-tech scale-up

Scope first, and scope narrowly. The platform, the team who build and run it, the offices and the cloud environments. Resist the urge to include the whole company because it sounds more impressive. Broad scope means more evidence, longer audits and a certificate that is harder to keep.

Then run a gap analysis against Annex A, assess your risks with a method you can defend, write the Statement of Applicability, close the gaps, and generate real operational evidence. That last part is what catches people out: a control implemented three days before Stage 2 has no records behind it. Auditors want to see the process running, not the process existing.

Finish with an internal audit and a management review, then Stage 1 (documentation) and Stage 2 (implementation) with your certification body. Typically two to three months for a focused team, which sounds optimistic until you see it done. HealthBoxHR, an HR and payroll platform holding sensitive employee data, put it plainly: "Starting without anything in place, we were able to achieve ISO/IEC 27001:2022 certification in 12 weeks." Their certification story is a fair template for a healthcare SaaS of similar size.

If you are a smaller clinic, care provider or early-stage product, the scoping logic in ISO 27001 for small businesses applies directly. If you deliver or host systems on behalf of healthcare clients, the supplier-side view in ISO 27001 for managed service providers is closer to your situation.

Where clinical AI changes the picture

Triage tools, diagnostic support, ambient scribing, waiting-list prediction. AI has arrived in UK healthcare faster than the assurance questions have, and buyers are starting to ask about model governance in the same breath as encryption.

ISO 27001 covers the security of the data your model consumes. It says nothing about whether the model is fit for clinical use, how you monitor drift, or who is accountable when an output is wrong. That is ISO 42001 territory, and the two systems share clause structure and most of their governance plumbing. We have covered what this means for providers in ISO 42001 in healthcare, and the mechanics of assessing model risk in our guide to AI risk management.

{{snapshot}}

Hicomply's take

The healthcare companies that stall are the ones who start with the questionnaire in front of them rather than the risks in their own product. They answer 200 questions, win one contract, then meet a different form and start again. Build the ISMS once, scoped to the platform, and let DSPT, DTAC and Cyber Essentials Plus draw from it. The other pattern we would flag: certifying with no evidence trail behind the controls. Auditors do not want your policy library. They want proof the access review happened in March and someone acted on it.

{{/snapshot}}

Get healthcare audit-ready without the spreadsheet sprawl

Most health-tech teams do not have a full-time compliance manager, and the CTO who ends up owning it has a product to ship. That is the real constraint, not the standard itself. Automating evidence collection, mapping policies to controls once and keeping the risk register live is how a small team holds a certification without it eating a quarter.

Start with the ISO 27001 readiness assessment to see how far off you actually are, then book a demo and we will show you how the same evidence base carries your DSPT submission, your DTAC responses and your next enterprise security review.

Ready to Take Control of Your Privacy Compliance?

Hicomply’s platform provides an all-in-one solution to streamline, automate, and centralise your compliance activities, ensuring complete control and efficiency.

Book a demo
Last updated
August 17, 2026
Category
ISO 27001 by Industry
Topics
No items found.
Lucy Murphy
Head of Customer Success

Lucy works closely with customers to help them get the most out of the Hicomply platform, from onboarding to audit success. She brings a user-focused mindset to everything she does, making her well-placed to write about day-to-day challenges, shortcuts, and success strategies. Her content is grounded in what real InfoSec and compliance teams need to know — and how to get there faster.Expect helpful walkthroughs, product tips, and practical insights.

Popular ISO 27001 for Healthcare Companies queries, answered!

Is ISO 27001 mandatory for NHS suppliers?

No. No UK law or blanket NHS rule requires ISO 27001. It is a procurement expectation rather than a legal one, and it appears in tenders, supplier due diligence and private provider contracts often enough that most health-tech companies treat it as necessary. What is required, for organisations with access to NHS patient data or systems, is the Data Security and Protection Toolkit submission.

Does ISO 27001 replace the NHS Data Security and Protection Toolkit?

It does not. The DSPT is an annual self-assessment you still have to submit, and certification does not exempt you. The overlap is in the evidence: policies, training records, access control reviews, incident logs and supplier due diligence built for your ISMS answer a large share of the toolkit. Build once, submit separately.

How long does ISO 27001 certification take for a healthcare SaaS company?

Typically two to three months for a focused scale-up with a tight scope, an owner who is senior enough to make decisions, and software rather than spreadsheets behind the evidence. HealthBoxHR reached ISO/IEC 27001:2022 certification in 12 weeks starting with nothing in place. Broad scope, part-time ownership and manual evidence collection push it past six months.

What is the difference between DTAC and ISO 27001?

DTAC assesses a digital health product before an NHS or social care organisation buys it, covering clinical safety, data protection, technical security, interoperability, and usability and accessibility. ISO 27001 certifies your organisation's management system for information security. A certificate helps you answer DTAC's technical security and data protection sections, but clinical safety needs its own separate work.

Do we need Cyber Essentials Plus as well as ISO 27001?

Often, yes. Many NHS and public sector contracts name Cyber Essentials Plus specifically, and it tests five technical controls hands-on rather than by self-declaration. ISO 27001 proves governance across the whole management system; Cyber Essentials Plus proves your configuration holds up under testing. Holding both is common in healthcare supply chains and the work substantially overlaps.

Unlock Your Path to ISO 27001 Success

Download our Ultimate ISO 27001 Compliance Checklist for clear, step-by-step guidance to fast-track your certification.

End to end ISO 27001 compliance documentation

Your hub for the fundamentals of ISO 27001 compliance, curated best practices, and resources for GRC professionals.

ISO 27001 Overview

Achieve ISO 27001 Certification

ISO 27001 is the globally recognised standard for building a structured Information Security Management System (ISMS) that protects the confidentiality, integrity and availability of information. This article explains what ISO 27001 is, how it works, the core principles behind it, and what organisations must do to achieve certification. You’ll learn the standard’s structure, its key requirements, how the certification process unfolds, and the practical steps needed to implement an ISMS that is both compliant and effective.

Learn more about Achieve ISO 27001 Certification

Benefits Of ISO 27001 For Businesses

ISO 27001 certification is one of the most credible ways for businesses to prove they protect sensitive information with structure, consistency, and internationally recognised best practice. This guide explains what ISO 27001 certification is, why companies pursue it, the core business benefits, the costs involved, and how organisations of any size can achieve and maintain certification. Whether you're preparing for your first audit or strengthening your security posture, this article gives you the clarity, detail, and practical steps to move forward with confidence.

Learn more about Benefits Of ISO 27001 For Businesses

History And Evolution Of ISO 27001

ISO 27001 is now recognised as the world’s leading standard for managing information security, but its journey spans decades of technological change, emerging cyber threats, and global collaboration. This article traces the origins of ISO 27001, from its earliest foundations to the modern 2022 revision. You’ll learn how the framework developed, why it became globally adopted, how ISO 27002 fits into the picture, and how ISO standards evolved more broadly over time.

Learn more about History And Evolution Of ISO 27001
ISO 27001:2022 Requirements

Actions To Address Risks And Opportunities | Clause 6.1

Clause 6.1 of ISO 27001 defines how organisations must identify, assess, and treat information security risks — and how they must uncover opportunities to strengthen their Information Security Management System (ISMS). This clause acts as the engine of the ISO framework: it drives risk-based thinking, aligns controls to real-world threats, and ensures continual improvement. In this guide, we break down Clause 6.1 line by line, explain its relationship with Annex A, show you what documentation is required, and provide examples and best practices to help you implement it correctly and confidently.

Learn more about Actions To Address Risks And Opportunities | Clause 6.1

ISO27001 Awareness | Clause 7.3

In this article, we explore everything you need to know about ISO 27001 Clause 7.3—its purpose, what the standard requires, how awareness strengthens your ISMS, and how to build a practical, auditor-ready awareness program that supports continuous security improvement.

Learn more about ISO27001 Awareness | Clause 7.3

ISO 27001 Communication | Clause 7.4

In this guide, we break down exactly what ISO 27001 Clause 7.4 requires, why structured communication is essential to an effective ISMS, and how organisations can build a clear, compliant communication process supported by practical, real-world examples.

Learn more about ISO 27001 Communication | Clause 7.4

Internal Audit | Clause 9.2

Understanding the intricacies of ISO 27001:2022 is crucial for organisations aiming to enhance their information security management systems. Clause 9.2, which focuses on internal audits, plays a pivotal role in this context.

Learn more about Internal Audit | Clause 9.2
Information Security Management System (ISMS)

ISO 27001 ISMS Audit And Review Process

The audit and review process is one of the most important pillars of ISO 27001. It ensures your Information Security Management System (ISMS) is working as intended, risks are managed effectively, controls are operating correctly, and continual improvement is actively taking place. This guide explains every component of the ISO 27001 audit lifecycle — internal audits, external audits, certification audits, surveillance audits, and management reviews — and shows you how to prepare, what evidence auditors expect, and how to maintain long-term compliance.

Learn more about ISO 27001 ISMS Audit And Review Process

ISO 27001 ISMS Continuous Improvement Cycle

In this end-to-end guide, you’ll learn how continual improvement works in ISO 27001, why it’s essential for long-term security maturity, how the PDCA cycle operates inside an ISMS, and what processes, documentation, and actions are required to maintain compliance year after year.

Learn more about ISO 27001 ISMS Continuous Improvement Cycle
Annex A Controls — Organizational

Acceptable Use Of Assets | Annex A 5.10

Information security policies serve as the foundation of any robust cybersecurity program. Without clearly defined rules for acceptable use of information assets, organizations face increased vulnerability to data breaches, compliance violations, and operational disruptions. Control 5.10 of ISO 27001:2022 specifically addresses this critical aspect of information security management, requiring organizations to establish formal guidelines for how information and associated assets should be handled.

Learn more about Acceptable Use Of Assets | Annex A 5.10

Access Control Policies | Annex A 5.14

Information rarely stays still. Every organisation transfers data daily—between teams, systems, partners, customers, cloud platforms, and suppliers. Emails are sent, files are shared, storage media is moved, meetings are held, and conversations take place across calls and video conferences. Each transfer represents a moment of heightened risk.

Learn more about Access Control Policies | Annex A 5.14

Access Rights Management | Annex A 5.16

ISO 27001 Annex A 5.16 focuses on how organisations manage access rights by governing the full lifecycle of identities. This control ensures that only authorised users, systems, and services can access information assets, and that access is removed when no longer required.

Learn more about Access Rights Management | Annex A 5.16
Annex A Controls — People

Confidentiality And NDA Management | Annex A 6.6

Confidentiality obligations sit at the very core of information security. Without enforceable confidentiality controls, even the strongest technical safeguards can be rendered ineffective by human behaviour, contractual gaps, or unclear responsibilities. ISO 27001:2022 Annex A 6.6 formalises this reality by requiring organisations to define, implement, communicate, and enforce confidentiality and non-disclosure obligations across employees, contractors, suppliers, and other relevant parties.

Learn more about Confidentiality And NDA Management | Annex A 6.6

Disciplinary Process And Enforcement | Annex A 6.4

Establishing a fair disciplinary process is essential for organizations that want to effectively manage security violations while maintaining employee trust. When security breaches occur, organizations often struggle to respond consistently, which can lead to resentment, legal complications, or ineffective deterrence. Consequently, ISO 27001 includes specific requirements under Annex A 6.4 to ensure disciplinary processes are both fair and effective.

Learn more about Disciplinary Process And Enforcement | Annex A 6.4

Employee Screening And Background Checks | Annex A 6.1

In this guide, we explain everything organisations need to know about ISO 27001:2022 Annex A 6.1 — Employee Screening and Background Checks. You’ll learn what the control requires, why it exists, how auditors assess compliance, what evidence is expected, and how to design a screening process that is legally compliant, proportionate, and effective across different roles and risk levels.

Learn more about Employee Screening And Background Checks | Annex A 6.1
Annex A Controls — Physical

Access Control To Premises | Annex A 7.2

Physical security remains one of the most underestimated components of information security. While organisations invest heavily in cybersecurity tools, a single uncontrolled door, shared workspace, or unlogged visitor can undermine even the most mature digital controls. ISO 27001 Annex A 7.2 exists to address this exact risk by requiring organisations to establish and maintain effective access control to premises where information and information-processing facilities are located.

Learn more about Access Control To Premises | Annex A 7.2

Cabling And Electrical Security | Annex A 7.12

Modern technologies rely heavily on fiber, network, and power cables to function correctly. When we focus on ISO cyber security, we often overlook these critical components' physical vulnerabilities. Power and information cables face risks of damage and interception. Cyber criminals who gain access to fiber cables can disrupt all network traffic with simple techniques like 'bending the fiber.' This makes data and information unavailable.

Learn more about Cabling And Electrical Security | Annex A 7.12
ISO 27001 by Industry

ISO 27001 for Small Businesses

A practical guide to ISO 27001 for small businesses in the UK: how to scope the ISMS small, what certification really costs, how long it takes, the four mistakes small firms make, and when Cyber Essentials is enough instead.

Learn more about ISO 27001 for Small Businesses

ISO 27001 for Healthcare Companies

How UK health-tech firms, care providers and NHS suppliers use ISO 27001 to answer procurement security questions, and how it sits alongside the NHS DSPT, DTAC and Cyber Essentials Plus without duplicating the work.

Learn more about ISO 27001 for Healthcare Companies

ISO 27001 for Consulting Firms

How consultancies get ISO 27001 certified when their assets are people, laptops and client system access. Scoping by service line, the people and supplier controls auditors sample, and whether you need a consultant.

Learn more about ISO 27001 for Consulting Firms

ISO 27001 for Managed Service Providers

How UK MSPs certify to ISO 27001: what belongs in scope when you hold privileged access to client estates, the Annex A controls auditors focus on, and how CE+, ISO 27001 and SOC 2 fit together.

Learn more about ISO 27001 for Managed Service Providers

Your ISO 27001 Compliance Newsletter

Stay ahead with the latest expert insights, news, and updates on compliance.
Decorative