Need help? Contact us or call us on
020 7702 2141

Suppliers urged to review cyber security requirements following NHSSC webinar

Suppliers urged to review cyber security requirements following NHSSC webinar

NHS Supply Chain (NHSSC) used its June 2026 supplier webinar to share important updates for suppliers, with cyber security requirements forming the main focus of the session.

Cyber security remains a key priority

Cyber security was a major focus of the webinar, reflecting the growing risks facing healthcare supply chains. NHSSC highlighted how cyber incidents can disrupt operations, affect product availability, and ultimately impact patient care.

Suppliers were reminded of several practical steps that can help strengthen cyber security, including enabling multi-factor authentication, training staff to recognise and report phishing emails, using strong, unique passwords, implementing conditional access policies, maintaining business continuity and disaster recovery plans, and building a strong cyber security culture through awareness and training.

Suppliers in scope of Procurement Policy Note (PPN) 014 are expected to demonstrate compliance with Cyber Essentials Plus. This applies to relevant suppliers handling personal information relating to employees, customers, or suppliers, or providing ICT systems and services.

Where a supplier does not hold Cyber Essentials Plus certification, NHSSC requires completion of an Information Security Third Party Questionnaire (ISTPQ). This is reviewed by NHSSC’s cyber security team and is only required where a valid Cyber Essentials Plus certificate is not held.

Suppliers that handle patient information, such as home addresses, must also demonstrate compliance with the Data Security and Protection Toolkit (DSPT). NHSSC emphasised that DSPT is a separate NHS England requirement to Cyber Essentials Plus and must be reviewed and submitted annually where applicable.

NHSSC also clarified that routine business emails alone do not automatically trigger a Cyber Essentials Plus requirement. The requirement applies where a supplier stores, processes, retains, or has ongoing access to personal data, such as information relating to employees, patients, customers, or other individuals, as part of the service, system, or solution it provides.

business laptop image

Members may also wish to attend NHS England’s free Cyber Resilience Across the Health and Care Supply Chain webinar on 30 June. The session will cover evolving cyber security expectations across the health and care system, what these mean in practice for NHS suppliers, and how suppliers can support stronger supply chain resilience.

Supplier Management Team update

NHSSC also provided an update on its newly established Supplier Management Team, which brings together supplier relationship management, supplier development, resilience, sustainability, performance, and risk functions into a single team.

The aim is to create a more integrated approach to supplier management, strengthen supplier relationships, improve resilience and sustainability, and support better risk management across the supply chain.

Recent activity includes supplier assurance work, lessons learned from supply disruptions experienced during the year, and development of a new Incident Management Framework intended to improve future responses to supply chain incidents.

NHSSC is also working to provide suppliers with greater visibility of customer demand through initiatives such as a Customer Insights Dashboard and enhanced demand allocation processes. Other ongoing work includes Clinical Product and Supplier Risk Segmentation, due diligence activity, and closer alignment with NHS England on cyber security.

The team is also increasing engagement with suppliers and industry bodies. Planned activity includes SME-focused forums, workshops for medium-sized and smaller businesses, renewed engagement with trade associations, and broader collaboration with industry partners and health innovation organisations.

NHS Core List update

NHSSC also briefly provided an update on the NHS Core List programme, an NHS England initiative designed to simplify procurement, reduce unnecessary product variation, and leverage collective buying power through a single procurement route.

Products included within the NHS Core List are selected against a range of principles, including standardisation, resilience, supplier assurance, and the availability of clinically appropriate alternatives.

At present, NHS Core List products do not cover BHTA member product categories. The BHTA will continue to monitor developments and assess whether relevant product categories become available through the NHS Core List in future.

Overview of the December NHS Supply Chain Supplier Webinar

Overview of the December NHS Supply Chain Supplier Webinar

The latest NHS Supply Chain (NHSSC) supplier webinar, held on 3 December 2025, provided essential updates for suppliers on cybersecurity compliance and sustainability expectations. The session, part of NHSSC’s regular information series, featured speakers from its Cyber Security and Sustainability teams, offering insight into upcoming requirements that suppliers will need to meet to remain eligible for tenders and contracts.

Cyber security requirements for suppliers

Jennie Lewis, Cyber Security Compliance Coordinator at NHS Supply Chain, led the session’s opening presentation on supplier cybersecurity. She outlined NHSSC’s adoption of the UK Government’s Procurement Policy Note (PPN) 014, which sets out new baseline security expectations for all suppliers in scope.

All suppliers handling personal information or providing ICT systems and services will be required to demonstrate compliance with Cyber Essentials Plus — a government-backed certification that confirms an organisation has robust cybersecurity controls in place. Certificates must be renewed annually and verified through an external audit. Suppliers can confirm certification validity via IASME, the national accreditation body.

Suppliers processing NHS patient data will also need to complete the Data Security and Protection Toolkit (DSPT), an NHS England-mandated self-assessment to evidence responsible data handling and compliance with information governance standards. For questions on data or security requirements, suppliers can contact cybersecurity@supplychain.nhs.uk.

Where suppliers do not yet hold Cyber Essentials Plus or DSPT certification, NHS Supply Chain has introduced an Information Security Third Party Questionnaire (ISTPQ). This pass/fail assessment, completed at the Supplier Questionnaire stage of a tender, will be reviewed by NHSSC’s Cyber Security Team to assess equivalency to Cyber Essentials standards. NHSSC will take a risk-based approach to non-compliance, weighing the criticality of the product or service against potential cyber risk. However, suppliers without certification may face reduced opportunities for participation in future tenders.

The Cyber Security Team also confirmed that NHS England will be notified of any vulnerable or insecure products or services identified through this process, as part of broader efforts to strengthen supply chain resilience across the NHS.

Evergreen deep dive: sustainability and net zero

The second presentation, delivered by Jade Gaffney, Sustainability Advisor, and Heidi Barnard, Head of Sustainability, explored the Evergreen Sustainable Supplier Assessment, one of five key sustainability criteria suppliers must meet. The “Five Asks” — covering Carbon Reduction Plans, Social Value, the Evergreen Assessment, Horizon Scanning, and Modern Slavery — are central to NHS England’s net zero and sustainability strategy.

From 1 April 2026, all suppliers bidding for new NHSSC tenders will be required to achieve Evergreen Level 1 or above. Level 1 aligns with the Carbon Reduction Plan requirements, meaning suppliers must publicly commit to achieving net zero carbon emissions by 2050 for all scopes. Suppliers unable to meet this requirement will remain eligible for existing contracts but may be excluded from new tenders after this date.

The Evergreen Assessment is hosted on the Atamis platform, accessible under the Information section. NHSSC advised suppliers to ensure their Evergreen submission is correctly linked to their Atamis account to prevent data visibility issues. Annual updates are mandatory, with no automatic reminders issued. Suppliers gathering Scope 3 emissions data should enter “0” placeholders where figures are unavailable, ensuring the assessment remains complete. Queries about sustainability assessments can be directed to sustainability@supplychain.nhs.uk.

The Evergreen framework supports NHSSC’s goal of embedding environmental accountability throughout its supply base, ensuring that procurement decisions contribute directly to the NHS’s wider sustainability and net zero commitments.