Skip to content

NHS DCB1596 COMPLIANCE

NHS DCB1596 Assessment

Achieve compliance with the NHS Secure Email Standard. We provide the expert CIS Benchmark assessment required for Google Workspace environments to securely exchange information with the NHS.

CIS Benchmark Aligned
Expert Guidance
 
 
EQL
Huma
ATS Digital
Doccla
Lottie
Centervue
iCare
Micrima
Soter Analytics
National Trust

What is the CIS Benchmark Assessment?

Our CIS Benchmark Assessment for the NHS Secure Email Standard (DCB1596) is a comprehensive review of your Google Workspace environment. We evaluate your configuration against the internationally recognized Center for Internet Security (CIS) Benchmarks to ensure your email system is secure and compliant.

This assessment provides the technical evidence required to support your DCB1596 accreditation, allowing you to confidently and securely share sensitive health and care information with the NHS.

Why is This Assessment Needed?

The NHS Secure Email Standard (DCB1596) is mandatory for any organization exchanging patient-identifiable data with NHSmail users. If you use Google Workspace, you must prove your security posture.

 

Mandatory Compliance
Required for non-NHSmail organizations exchanging sensitive data.
Technical Evidence
Independent evaluation of your security controls against CIS standards.
Accreditation Support
Clear documentation to support your DCB1596 submission.

Why What We Deliver

We provide a comprehensive output designed to streamline your accreditation process.

CIS Benchmark Alignment

A comprehensive review of your Google Workspace configuration against the relevant CIS Benchmark controls.

Gap Analysis

Clear identification of any security gaps or areas of non-compliance that need attention.

Remediation Guidance

Actionable recommendations to address identified vulnerabilities and meet the standard.

Please note: While we provide the technical assessment and report, the formal risk assessment and risk ownership remain with your organization. We empower you with the data you need to make informed decisions.
 
DCB1596

Who Is This For?

This service is designed for organizations that handle sensitive health and care information and need to demonstrate DCB1596 compliance.

Our assessment is ideal for IT Security Managers, Compliance Officers, and CIOs who are responsible for ensuring the security and compliance of their organization's email systems.

 
 
Achieve DCB1596 Compliance
 
Enhance Security Posture
 
Enable Secure NHS Communication
Book a Call
 
Digital Health
Health Tech companies integrating with NHS systems.
 
Suppliers
Any organisation using Google Workspace to talk to the NHS.
 
NHS Trusts
And Commissioning Groups needing secure external comms.
We had a great experience working with Periculo for our Cyber Essentials Plus certification. From the very beginning, their team was incredibly responsive, supportive, and approachable, which made the preparation phase smooth and efficient.

They were always available to answer our questions, clarify requirements, and help us feel fully prepared before the audit. When it came time for the actual audit, the process was handled with impressive professionalism and thoroughness, giving us full confidence in their assessment.

Highly recommended for any organization looking for a dependable and knowledgeable partner for cybersecurity certifications.

 

FAQs

Find answers to frequently asked questions
Does this assessment guarantee DCB1596 accreditation?

This assessment provides the technical evidence required for the 'Information Security' section of the accreditation. You still need to complete the Clinical Safety Case and have your own Clinical Safety Officer (CSO) and Senior Information Risk Owner (SIRO) sign off on the final submission.

Is this the same as a Penetration Test?

No. This is a configuration review against CIS Benchmarks. A penetration test (IT Health Check) is a separate requirement for the 'Self-Managed' route. We can offer Penetration Testing as a separate service if needed.

 

What happens if I fail the assessment?

If you don't meet the requirements, Periculo will provide feedback on the areas that need improvement. You can address these gaps and resubmit your application.

How long does the assessment take?

Typically, the technical assessment takes 3-5 days, depending on the complexity of your Google Workspace environment and access provision.

Do you fix the issues found?

Our report provides detailed remediation guidance. We can assist with implementing the fixes as an additional service, or your internal IT team can apply the recommended changes.

 

How often do I need this?

DCB1596 accreditation is valid for one year. We recommend an annual reassessment to ensure continued compliance and security.

NHS DCB1596 COMPLIANCE

Still Have Questions?

Schedule a call with our founder or a member of our team to create a complimentary action plan.