Need help? Contact us or call us on
020 7702 2141

Suppliers urged to review cyber security requirements following NHSSC webinar

Last Updated on 09/06/2026 by Sarah Sarsby

NHS Supply Chain (NHSSC) used its June 2026 supplier webinar to share important updates for suppliers, with cyber security requirements forming the main focus of the session.

Cyber security remains a key priority

Cyber security was a major focus of the webinar, reflecting the growing risks facing healthcare supply chains. NHSSC highlighted how cyber incidents can disrupt operations, affect product availability, and ultimately impact patient care.

Suppliers were reminded of several practical steps that can help strengthen cyber security, including enabling multi-factor authentication, training staff to recognise and report phishing emails, using strong, unique passwords, implementing conditional access policies, maintaining business continuity and disaster recovery plans, and building a strong cyber security culture through awareness and training.

Suppliers in scope of Procurement Policy Note (PPN) 014 are expected to demonstrate compliance with Cyber Essentials Plus. This applies to relevant suppliers handling personal information relating to employees, customers, or suppliers, or providing ICT systems and services.

Where a supplier does not hold Cyber Essentials Plus certification, NHSSC requires completion of an Information Security Third Party Questionnaire (ISTPQ). This is reviewed by NHSSC’s cyber security team and is only required where a valid Cyber Essentials Plus certificate is not held.

Suppliers that handle patient information, such as home addresses, must also demonstrate compliance with the Data Security and Protection Toolkit (DSPT). NHSSC emphasised that DSPT is a separate NHS England requirement to Cyber Essentials Plus and must be reviewed and submitted annually where applicable.

NHSSC also clarified that routine business emails alone do not automatically trigger a Cyber Essentials Plus requirement. The requirement applies where a supplier stores, processes, retains, or has ongoing access to personal data, such as information relating to employees, patients, customers, or other individuals, as part of the service, system, or solution it provides.

business laptop image

Members may also wish to attend NHS England’s free Cyber Resilience Across the Health and Care Supply Chain webinar on 30 June. The session will cover evolving cyber security expectations across the health and care system, what these mean in practice for NHS suppliers, and how suppliers can support stronger supply chain resilience.

Supplier Management Team update

NHSSC also provided an update on its newly established Supplier Management Team, which brings together supplier relationship management, supplier development, resilience, sustainability, performance, and risk functions into a single team.

The aim is to create a more integrated approach to supplier management, strengthen supplier relationships, improve resilience and sustainability, and support better risk management across the supply chain.

Recent activity includes supplier assurance work, lessons learned from supply disruptions experienced during the year, and development of a new Incident Management Framework intended to improve future responses to supply chain incidents.

NHSSC is also working to provide suppliers with greater visibility of customer demand through initiatives such as a Customer Insights Dashboard and enhanced demand allocation processes. Other ongoing work includes Clinical Product and Supplier Risk Segmentation, due diligence activity, and closer alignment with NHS England on cyber security.

The team is also increasing engagement with suppliers and industry bodies. Planned activity includes SME-focused forums, workshops for medium-sized and smaller businesses, renewed engagement with trade associations, and broader collaboration with industry partners and health innovation organisations.

NHS Core List update

NHSSC also briefly provided an update on the NHS Core List programme, an NHS England initiative designed to simplify procurement, reduce unnecessary product variation, and leverage collective buying power through a single procurement route.

Products included within the NHS Core List are selected against a range of principles, including standardisation, resilience, supplier assurance, and the availability of clinically appropriate alternatives.

At present, NHS Core List products do not cover BHTA member product categories. The BHTA will continue to monitor developments and assess whether relevant product categories become available through the NHS Core List in future.