Choosing an NHS Supplier? Why Cyber Essentials Plus Matters for PCNs & GP Practices
|
Getting your Trinity Audio player ready...
|
- Why should GP practices care?
- What is Cyber Essentials Plus?
- Why is Cyber Essentials Plus important for NHS suppliers?
- Core Prescribing Solutions’ Commitment to Data Security
- Questions to ask an NHS supplier about cyber security
- How does it differ from the Data Security and Protection Toolkit?
Every GP practice and Primary Care Network relies on external suppliers to deliver essential services. That means you are trusting more than clinical expertise. You are trusting how those organisations protect sensitive NHS information, maintain resilient systems, and keep services running. Cyber Essentials Plus NHS certification provides independent evidence that a supplier has implemented recognised cyber security controls that have been independently tested.
Key Takeaways
- Procurement relevance: For many NHS contracts involving sensitive data or digital services, Cyber Essentials or Cyber Essentials Plus may be required as part of proportionate procurement controls under PPN 014 guidance.
- Independent verification: Unlike standard self-assessment, the Plus tier involves a technical audit of a supplier’s actual systems, supporting robust NHS cyber security.
- Toolkit alignment: While it supports the Data Security and Protection Toolkit, holding Cyber Essentials Plus requires separate evidence for the DSPT v8 submission.
Why should GP practices care?
Patient safety extends beyond clinical decisions. It also depends on operational resilience and the protection of health data. When evaluating external partners, primary care leaders need confidence that their data is safe. Choosing a secure NHS supplier is an important part of the information governance NHS practices are expected to uphold.
Choosing a supplier with Cyber Essentials Plus NHS certification can help practices:
- Reduce supplier risk by ensuring technical defences are actively tested against cyber-attacks.
- Strengthen procurement due diligence when commissioning a Clinical pharmacist support service.
- Support information governance NHS requirements and improve confidence around patient data protection.
- Demonstrate good governance to commissioners and regulatory bodies.
- Provide greater confidence when selecting long-term clinical partners.
What is Cyber Essentials Plus?

Cyber Essentials Plus NHS certification is a government-backed scheme that assesses an organisation against five technical controls. The Cyber Essentials scheme covers:
- Firewalls and internet gateways: Creating a secure boundary between internal networks and the internet.
- Secure configuration: Setting devices and software up safely to minimise vulnerabilities.
- User access control: Restricting data access to people who need it.
- Malware protection: Defending against malicious software.
- Security update management: Keeping systems and software patched and up to date.
The key difference between standard Cyber Essentials and the Plus tier is verification. Standard Cyber Essentials is based on a self-assessment that is reviewed by a certification body. The Plus tier includes independent technical testing, such as external vulnerability scanning and device testing. It provides independent assurance that a supplier’s controls are working in practice.
| Feature | Standard Cyber Essentials | Cyber Essentials Plus |
| Assessment type | Self-assessment questionnaire | Independent technical audit |
| Independent verification | No | Yes |
| External vulnerability testing | No | Yes |
| Device testing | No | Yes |
| Procurement suitability | May suit lower-risk requirements | May suit contracts requiring greater assurance |

Need greater assurance when choosing a clinical pharmacy partner?
Discuss secure clinical pharmacy supportExpert insight from Adeem Azhar, qualified Clinical Pharmacist and CEO
GP practices and PCNs place enormous trust in the organisations they work with. Cyber Essentials Plus gives our partners confidence that our cyber security controls have been independently assessed, allowing them to focus on delivering safe patient care.
Adeem Azhar, MPharm, IPres
Co-Founder and Chief Executive Officer – Core Prescribing Solutions
Qualified Clinical Pharmacist
Why is Cyber Essentials Plus important for NHS suppliers?
The threat landscape in healthcare is evolving rapidly, making healthcare cyber resilience a priority for commissioners and NHS leadership. According to the UK Government’s Cyber Security Breaches Survey 2025/2026, 43% of UK businesses reported a cyber security breach or attack in the previous 12 months. This reinforces why supplier due diligence is a core part of NHS cyber security when practices choose long-term partners.
For many contracts involving sensitive data or digital services, Cyber Essentials Plus NHS certification may be relevant under PPN 014. The policy requires in-scope organisations to apply effective and proportionate cyber security controls. It also requires them to consider Cyber Essentials, Cyber Essentials Plus, or equivalent controls for qualifying contracts.
For GP practices engaging a ,
certification does not remove the need for wider due diligence. However, it provides independent assurance that a supplier has implemented technical controls to defend against common cyber-attacks, protect patient records, and maintain operational continuity.
How does it differ from the Data Security and Protection Toolkit?

It is common to confuse Cyber Essentials NHS requirements with the Data Security and Protection Toolkit. The DSPT is an online self-assessment tool that measures performance against the National Data Guardian’s data security standards.
While both are important for NHS cyber security, they serve different functions. The toolkit covers broader information governance NHS organisations are expected to meet, including staff training, data protection policies, and organisational accountability. Cyber Essentials Plus focuses on technical defences.
For the v8 submission, holding Cyber Essentials Plus cannot be used as direct equivalence for certain technical questions. Separate evidence is required. However, the technical controls established during the independent audit can support a well-evidenced submission.
Core Prescribing Solutions’ Commitment to Data Security

Cyber Essentials Plus NHS certification forms one part of our wider information governance framework. Alongside our 2025/26 DSPT assessment of Standards Exceeded, it demonstrates our ongoing commitment to protecting NHS data security, supporting GP practices, and giving our clients confidence that security is embedded throughout our organisation.
Questions to ask an NHS supplier about cyber security
Before commissioning any external clinical service, it is worth asking prospective suppliers the following questions:
- Do you hold Cyber Essentials or Cyber Essentials Plus? The Plus tier provides independently verified assurance.
- Is your certification current? Cyber Essentials Plus must be renewed every 12 months.
- What is your latest Data Security and Protection Toolkit status? Look for Standards Met or Standards Exceeded.
- How do you protect NHS data? Ask specifically about access controls, encryption, data storage, and staff training.
- How do you manage cyber incidents? A credible supplier will have a documented incident response plan.
These questions take minutes to ask and can meaningfully inform procurement decisions.

FAQs
Choose clinical pharmacy support with security and governance built in
Core Prescribing Solutions combines clinical pharmacy delivery with Cyber Essentials Plus certification and wider information-governance controls. We can support GP practices and PCNs with clinically governed pharmacy capacity while giving procurement teams stronger assurance around cyber security, data protection and operational resilience.
Discuss your clinical pharmacy requirements
01274 442076








