For established NHS suppliers, passing assurance once is not the same as being ready when the next question from an NHS organisation you supply lands. The practical challenge is keeping the evidence, ownership and day-to-day reality aligned as the business changes.
IN SHORT In short: NHS supplier assurance continues after procurement. Under A4, appropriate assurance can be expected at the start of relevant contracts and regularly through their lifetime. The practical requirement is to keep controls current, ownership clear and evidence ready when an NHS organisation asks. |
|---|
For a wider view of NHS supplier readiness, compare the practical evidence questions here with DSPT v9 and the Cyber Security Charter.
The contract being signed does not freeze your environment
Winning the NHS contract can feel like the point where the assurance work is finally behind you. In practice, that is often where the ongoing part starts.
The more useful question is not simply, “Did we pass?” It is: if an NHS organisation we supply asked us to prove the same things again tomorrow, how much disruption would that cause?
NHS supplier assurance is not a one-off procurement exercise. The A4 supply-chain guidance expects appropriate assurance at the start of relevant contracts and regularly throughout their lifetime, with supplier risk revisited on a scheduled basis rather than left where it was at procurement (NHS England, 2026a).
The 2026 supplier steer goes further. Where a service is important to patient care or operational continuity, NHS England or the relevant contracting authority may discuss key cyber controls directly with the supplier and ask for supporting evidence where proportionate (NHS England and DHSC, 2026).
For established suppliers, the implication is simple: assurance has to operate as part of the business, not as an annual scramble. The controls should be current, the owner should be clear and the evidence should be available without stopping everything else.
What changes after the assessment?
Think about what can change in twelve months. A service moves to a new cloud environment. A new identity platform is introduced. Staff numbers double. A product team adopts a new development tool. A subcontractor changes. Someone replaces the backup platform. An acquisition brings another Microsoft 365 tenant into the business. A critical employee leaves.
Your certificate may still be current. Your original questionnaire may still be sitting in SharePoint. But are the answers still true?
A4 also makes clear that third-party assurance should be revisited when the environment changes: after system changes, incidents or near misses, audit findings, changes in business need or security requirements, or where a supplier no longer meets the required level of assurance (NHS England, 2026a).
That matters because the NHS organisation is not really buying last year's answer. It is buying confidence that today's business still matches it.
A recurring theme in the conversations we are having around NHS supplier readiness is not a lack of policies. It is the scramble that starts when a NHS organisation asks for proof at short notice. The information exists, but it is spread across people, systems and suppliers.
Your product may not use AI. Your back office probably does.
One of the easiest ways for last year's assurance answer to become outdated is not a major infrastructure project. It is the gradual adoption of AI inside the business.
A supplier may not sell an AI product at all. Its teams may still be using Microsoft 365 Copilot, generative AI assistants, meeting and transcription tools, coding assistants, CRM features or AI-enabled support platforms to summarise information, draft responses, analyse documents or automate routine work.
That can change the assurance picture. Information may now be reachable by another service. A new processor or subprocessor may sit in the chain. Existing permissions may expose more information than anyone expected. Data may be processed in a way that was not considered when the original questionnaire, data map or DPIA was completed.
NHS England now publishes a template DPIA specifically for Microsoft 365 Copilot in health and care, and notes that risk can vary with the use case (NHS England Digital, 2026). The ICO makes the wider point that adopting AI may require organisations to reassess their existing governance and risk-management practices (ICO, 2023).
For an NHS supplier, the useful question is therefore not simply, “Do we have an AI policy?” It is: where is AI actually being used, what information can it reach, who approved the use case, and could we evidence the answer if an NHS organisation asked tomorrow?
FIVE AI QUESTIONS WORTH ADDING TO YOUR ASSURANCE CHECK 1. Which AI tools and AI-enabled services are actually being used? 2. What customer, NHS, patient, employee or commercially sensitive information can they access? 3. Which suppliers, processors or subprocessors now sit behind those tools? 4. Have permissions, data flows, retention and risk assessments been reviewed for the real use cases? 5. What human review or fallback exists where an AI output or service cannot be relied on? |
|---|
None of this means an NHS supplier needs a new AI certification. It means AI use belongs in the same evidence and ownership picture as every other change to the business.
The five-person questionnaire problem
There is a very simple way to see whether assurance is embedded in the business or reconstructed every time somebody asks.
Imagine an NHS organisation you supply sends a security questionnaire at 9am tomorrow. It asks about MFA, privileged access, patching, backups, recovery testing, data locations, international transfers, subcontractors, incident response, vulnerability management and security ownership.
How many people need to get involved before you can reply confidently?
If answering it needs the CTO, the DPO, someone from operations, your IT provider and the person who completed the last DSPT return, you may not have a control problem at all. You may have an ownership and evidence problem.
This is where capable businesses lose time. Someone finds last year's spreadsheet. Somebody else checks whether an answer is still true. A supplier has changed. A policy and the technical configuration no longer quite match. Before long, a straightforward NHS buyer request has consumed several senior people and a handful of meetings.
The underlying control may be perfectly good. The expensive bit is proving it.
What NHS buyer scrutiny can include
Relevant NHS supplier contracts can include rights to audit, incident-notification and remediation requirements, ongoing assurance evidence, security SLAs, vulnerability and patch management, and expectations around security governance (NHS England, 2026a).
That gives suppliers a much more useful readiness test than simply asking whether a certification is current:
A concrete sign of where supplier scrutiny is heading
For suppliers working through NHS Supply Chain, that scrutiny is already practical. In-scope suppliers providing IT or digital products and services, or handling relevant personal data, may need to demonstrate Cyber Essentials Plus or provide equivalent assurance. Where a valid certificate is not available, an Information Security Third Party Questionnaire (ISTPQ) can be used to assess the applicable controls (NHS Supply Chain, 2025).
That is not a universal rule for every NHS contract, and the requirements depend on the organisation, service and procurement route. But it is a useful illustration of the direction of travel: certification, questionnaires and operational evidence can sit alongside one another. A mature supplier needs to know not only which assurance applies, but how quickly it can produce the evidence behind it.
Area | What you should be able to show |
|---|---|
Identity | Where MFA is enforced, how privileged access is controlled and who owns it |
Vulnerability management | How vulnerabilities are identified, prioritised, patched and evidenced |
Monitoring | What is monitored, when, by whom and how incidents are escalated |
Recovery | Which systems are critical, current backup arrangements and evidence of recovery testing |
Data | What NHS / patient data you hold, where it is processed, who has access and applicable retention rules |
Third parties | Which external providers are material to delivery and what assurance you hold on them |
Incident response | Roles, escalation routes, NHS notification process and evidence from exercises |
Assurance | Current DSPT, Cyber Essentials/Plus, ISO or other applicable evidence and its actual scope |
Build an evidence spine, not an evidence cupboard
One of the quickest improvements we see is not another policy. It is a simple assurance register. For each important control, record the owner, where the live evidence sits, when it was last checked, which NHS organisations or frameworks rely on it, and when it needs reviewing again.
That gives the business one usable spine. DSPT can use it. NHS buyer questionnaires can use it. ISO evidence can use it. Your DPO, board and IT provider can use the same underlying facts instead of maintaining separate versions of the truth.
More importantly, when something changes, you know which evidence needs to change with it.
The NHS has also acknowledged the burden of repetitive assurance. The 2026 supplier steer is explicit about minimising duplication and using existing assurance where possible for suppliers serving multiple NHS organisations (NHS England and DHSC, 2026). A supplier with one clear evidence base is in a much stronger position to benefit from that.
A 30-minute test worth doing
Take the most detailed NHS security questionnaire or assurance request you received in the last year. Put 30 minutes on the clock. Try to answer it using evidence that is available today, without calling a meeting.
Every answer you cannot produce confidently exposes one of four things: unclear ownership, missing evidence, an outdated control, or information sitting with the wrong person.
That is useful information. The goal is not to get brilliant at filling in questionnaires. The goal is to make the next questionnaire boring.
Assurance should make the contract easier to keep
Most established NHS suppliers do not need another explanation of what DSPT or Cyber Essentials stands for. The harder commercial problem is making sure the controls, people and evidence keep pace with the business.
Get that right and the benefits are very practical: less senior time lost to questionnaires, fewer surprises in audits, smoother renewal conversations, and more confidence that the business behind the product is as dependable as the product itself.
No one wins an NHS contract because their evidence folder is beautiful. But poor readiness can slow procurement, complicate renewals and expose gaps at exactly the wrong moment. The framework is rarely the hard bit. Keeping the business behind it ready is.
Frequently asked questions
Is NHS supplier assurance a one-off?
No. A4 treats assurance as part of the contract lifecycle, with appropriate evidence expected at the start of relevant contracts and regularly thereafter. The depth and frequency depend on the service and risk.
Does a DSPT return replace NHS buyer due diligence?
No. DSPT, DTAC, ISO 27001 and Cyber Essentials Plus can all contribute to assurance, but none removes the need for specific NHS buyer evidence where it is useful and proportionate.
What evidence should an NHS supplier keep ready?
A practical baseline includes evidence for identity and MFA, patching and vulnerabilities, monitoring, backups and recovery testing, data handling, material third parties, incident response and governance ownership.
Does back-office AI use matter if our product is not an AI product?
Yes, where it changes how information is accessed, processed, shared or governed. The issue is not whether the product you sell is labelled AI. It is whether AI adoption inside the business has changed the data, supplier, access or risk picture behind the assurance you give customers.
References
NHS England (2026a) Principle: A4 Supply chain. Available at: https://www.england.nhs.uk/long-read/principle-a4-supply-chain/ (Accessed: 5 October 2026).
NHS England and Department of Health and Social Care (2026) Implementing proactive cyber risk management in the health and social care supply chain. 21 January. Available at: https://www.england.nhs.uk/long-read/implementing-proactive-cyber-risk-management-in-the-health-and-social-care-supply-chain/ (Accessed: 5 October 2026).
NHS Supply Chain (2025) Cyber Security: Expectations of Suppliers. 6 August. Available at: https://www.supplychain.nhs.uk/news-article/cyber-security-expectations-of-suppliers/ (Accessed: 5 October 2026).
NHS England Digital (2026) Microsoft 365 Copilot template DPIA. Last edited May 2026. Available at: https://digital.nhs.uk/data-and-information/information-governance/templates/microsoft-365-copilot-template-dpia (Accessed: 6 October 2026).
Information Commissioner's Office (2023) Guidance on AI and data protection. Updated 15 March 2023. Available at: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/ (Accessed: 6 October 2026).



