The short answer: ISO 27001 is the security certification UK healthcare buyers ask for most often, because it proves you run a managed information security management system instead of a folder of good intentions. It does not replace the NHS Data Security and Protection Toolkit, and it is not a UK GDPR certificate. What ISO 27001 gives a healthcare company is one evidence base, covering risk, policies, access records and supplier reviews, that answers most of what DSPT, DTAC and NHS procurement teams ask you to show.
Healthcare buying has changed. A trust's information governance lead, a private hospital group's DPO and a care provider's operations director are all asking suppliers the same question in different words: prove you can hold patient or staff data without becoming the reason we end up in an ICO enforcement notice. For a health-tech company with thirty staff, that question usually arrives as a 200-line security questionnaire, two weeks before the deal was meant to close. Certification is how you answer it once rather than forty times.
{{snapshot}}
ISO 27001 in healthcare at a glance
- It is a procurement key, not a legal requirement. No UK law names ISO 27001, but NHS and private healthcare buyers ask for it constantly.
- The DSPT is separate and still required for organisations with access to NHS patient data or systems. Your ISMS supplies much of the evidence, not the submission itself.
- Health data is special category data under UK GDPR, so access control, logging and breach response get read far more closely than in other sectors.
- ISO 27001:2022 has 93 Annex A controls in four themes. Around fifteen of them carry the weight in a clinical or patient-facing product.
- Two to three months is realistic for a focused scale-up with a tight scope and someone senior who genuinely owns it.
{{/snapshot}}
Why ISO 27001 keeps coming up in NHS and private healthcare deals
Healthcare buyers cannot inspect every supplier. A trust may have hundreds of digital suppliers and a small information governance team, so it does what any rational buyer does and asks for a certificate somebody else has already tested. ISO 27001 is that certificate: issued after an accredited body audits your management system, not your marketing site.
The second reason is exposure. Health records are special category data, and losing them is not an abstract harm. A cancelled clinic list is a patient who does not get seen. Procurement teams understand that, which is why the security section of a healthcare tender runs longer and asks harder questions than the one you filled in for a retail customer last year.
Third, an ISMS travels. The same controls answer a private hospital group's due diligence, a US customer's SOC 2 questions and your cyber insurance renewal. That matters most for companies selling into both NHS and private markets, where every buyer has a different form and the same underlying worry. For the sector backdrop, see how cyber security is changing in the healthcare industry. For what certification does to your defences specifically, read how ISO 27001 certification improves healthcare cyber security.
DSPT, DTAC and Cyber Essentials Plus: who asks for what
These get muddled constantly, usually by whoever forwarded you the questionnaire. They are not competing standards. They are different questions, asked by different people, about the same organisation.
The NHS Data Security and Protection Toolkit is an annual self-assessment for organisations with access to NHS patient data or NHS systems. It grew out of the National Data Guardian's data security standards, and NHS England has been moving parts of it onto a Cyber Assessment Framework-aligned model, so confirm which version applies to your organisation type before you scope the work. ISO 27001 certification supports a large share of the evidence you will be asked for. It does not exempt you from submitting.
DTAC, the Digital Technology Assessment Criteria, is what NHS and social care organisations use to assess a digital health product before they buy it. It covers clinical safety, data protection, technical security, interoperability, and usability and accessibility. The technical security section asks directly about certifications and testing, so a valid certificate plus a recent penetration test does much of the answering. Clinical safety is a separate discipline with its own standards, and no ISMS will cover it for you.
Cyber Essentials Plus is the NCSC-backed scheme covering five technical controls, verified hands-on by an assessor rather than self-declared. It is cheap, quick and deliberately narrow. Plenty of NHS contracts ask for it alongside ISO 27001, and some ask for it first while you work towards the bigger certification.
| What it is | Who asks for it | What it proves | Overlap with ISO 27001 |
|---|---|---|---|
| NHS DSPT | NHS England, trusts, anyone passing you NHS patient data | Annual self-assessment against NHS data security expectations | High. Policies, training records, access control and incident evidence are reusable |
| DTAC | NHS and social care organisations buying digital health tech | Product-level assessment across safety, data protection, security, interoperability and usability | Partial. Covers the technical security and data protection sections, not clinical safety |
| Cyber Essentials Plus | NHS contracts, public sector buyers, insurers | Five technical controls, independently tested | Moderate. Sits inside your technological controls, but proves configuration rather than governance |
| ISO 27001 | NHS suppliers' customers, private providers, enterprise and international buyers | A certified, audited management system for information security risk | The base layer the others draw from |
The controls that carry the most weight when you hold patient data
All 93 Annex A controls apply until you justify otherwise in your Statement of Applicability. In healthcare, auditors and buyers reliably dig hardest into the same handful.
- Access control and privileged access. Role-based access mapped to clinical and administrative roles, with support engineers held to break-glass access that is logged and reviewed. "Everyone in engineering can see production" ends a lot of healthcare deals.
- Supplier and subprocessor security. Your hosting provider, your transcription API, your analytics tool. Buyers want the list, the due diligence behind it and the contract clauses. Sub-processor sprawl is the single most common gap we see.
- Logging and monitoring. Who accessed which patient record, when, and how you would know if that access was inappropriate. Special category data raises the bar here well above a generic SaaS baseline.
- Business continuity and availability. Downtime in healthcare has clinical consequences. Tested recovery plans beat documented ones, and auditors ask when you last actually ran the test.
- Secure development. Code review, dependency management, separation of environments and, above all, no live patient data in test systems.
- Screening and awareness. Right-to-work and reference checks, DBS where the role requires it, and training that people demonstrably completed rather than were emailed.
The ICO's guidance on special category data is worth reading alongside your risk assessment, because the two documents should agree with each other. If your risk register treats a patient record like a marketing email address, an auditor will notice before a regulator does.
Running DSPT and ISO 27001 from one evidence base
The expensive mistake is treating each framework as a separate project with its own spreadsheet, its own owner and its own annual panic. Health-tech companies end up maintaining three descriptions of the same access control process, which then drift apart, which is exactly what an auditor is trained to find.
Do it once instead. Build the ISMS properly, then map its outputs to DSPT assertions and DTAC sections. One asset inventory. One risk register that auto-populates from those assets so nothing gets missed when you add a new database. One set of policies mapped to controls, versioned, with evidence of approval. One evidence store where the annual access review lives, tagged to every framework that asks for it.
This is where compliance software earns its keep. Hicomply links policy and procedure templates directly to controls, so a single approved document satisfies the ISO clause and the toolkit assertion at the same time, and the dashboard shows where the ISMS actually stands rather than where you hoped it stood in January. What you build for ISO 27001 also powers SOC 2 and whatever framework a new customer invents next quarter.
A practical route to certification for a health-tech scale-up
Scope first, and scope narrowly. The platform, the team who build and run it, the offices and the cloud environments. Resist the urge to include the whole company because it sounds more impressive. Broad scope means more evidence, longer audits and a certificate that is harder to keep.
Then run a gap analysis against Annex A, assess your risks with a method you can defend, write the Statement of Applicability, close the gaps, and generate real operational evidence. That last part is what catches people out: a control implemented three days before Stage 2 has no records behind it. Auditors want to see the process running, not the process existing.
Finish with an internal audit and a management review, then Stage 1 (documentation) and Stage 2 (implementation) with your certification body. Typically two to three months for a focused team, which sounds optimistic until you see it done. HealthBoxHR, an HR and payroll platform holding sensitive employee data, put it plainly: "Starting without anything in place, we were able to achieve ISO/IEC 27001:2022 certification in 12 weeks." Their certification story is a fair template for a healthcare SaaS of similar size.
If you are a smaller clinic, care provider or early-stage product, the scoping logic in ISO 27001 for small businesses applies directly. If you deliver or host systems on behalf of healthcare clients, the supplier-side view in ISO 27001 for managed service providers is closer to your situation.
Where clinical AI changes the picture
Triage tools, diagnostic support, ambient scribing, waiting-list prediction. AI has arrived in UK healthcare faster than the assurance questions have, and buyers are starting to ask about model governance in the same breath as encryption.
ISO 27001 covers the security of the data your model consumes. It says nothing about whether the model is fit for clinical use, how you monitor drift, or who is accountable when an output is wrong. That is ISO 42001 territory, and the two systems share clause structure and most of their governance plumbing. We have covered what this means for providers in ISO 42001 in healthcare, and the mechanics of assessing model risk in our guide to AI risk management.
{{snapshot}}
Hicomply's take
The healthcare companies that stall are the ones who start with the questionnaire in front of them rather than the risks in their own product. They answer 200 questions, win one contract, then meet a different form and start again. Build the ISMS once, scoped to the platform, and let DSPT, DTAC and Cyber Essentials Plus draw from it. The other pattern we would flag: certifying with no evidence trail behind the controls. Auditors do not want your policy library. They want proof the access review happened in March and someone acted on it.
{{/snapshot}}
Get healthcare audit-ready without the spreadsheet sprawl
Most health-tech teams do not have a full-time compliance manager, and the CTO who ends up owning it has a product to ship. That is the real constraint, not the standard itself. Automating evidence collection, mapping policies to controls once and keeping the risk register live is how a small team holds a certification without it eating a quarter.
Start with the ISO 27001 readiness assessment to see how far off you actually are, then book a demo and we will show you how the same evidence base carries your DSPT submission, your DTAC responses and your next enterprise security review.







