Skip to content

Digital Health & NHS Supplier Cybersecurity

Cybersecurity for digital health & NHS suppliers

Periculo is a CREST-accredited cybersecurity consultancy and IASME-licensed certification body specialising in digital health, defence, and AI. We help HealthTech vendors, medical device manufacturers and NHS IT suppliers meet NHS compliance and prove real security — DSPT audits, Cyber Essentials, DTAC penetration testing, medical device testing and ISO 27001, from one team.

NHS DSPT independent audit for IT suppliers

Periculo provides independent NHS DSPT (Data Security and Protection Toolkit) audits tailored exclusively to IT suppliers. Under DSPT assertion 9.4.5, in-scope IT suppliers must have their DSPT self-assessment independently audited by a third party — validating data protection and security practices with real evidence rather than self-declaration.

You are classed as an in-scope IT supplier if you meet all of the following:

  • You supply digital goods or services to NHS or care organisations (SaaS platforms, cloud hosting, EHR systems, cybersecurity services, IT infrastructure).
  • You have 50 or more staff.
  • Your annual turnover exceeds £10 million.

For IT suppliers, NHS England mandates 12 assertions to be audited. Periculo delivers a risk rating against each of the 10 National Data Guardian standards, an overall risk rating and an overall confidence rating. The 2025/26 DSPT aligns with the NCSC Cyber Assessment Framework (CAF); Periculo supports both the assertion-based and CAF-aligned audit routes. The DSPT submission deadline is 30 June each year, and evidence covered by a current Cyber Essentials Plus certificate or ISO 27001 may be exempt where the certification scope covers the relevant health and care data.

Cyber Essentials & Cyber Essentials Plus for NHS suppliers

Periculo is an IASME-accredited certification body for Cyber Essentials (CE) and Cyber Essentials Plus (CE+), with full readiness support and the CE+ technical audit. A current, IASME-validated Cyber Essentials certificate is required under NHS DTAC and under Procurement Policy Note 014 (PPN 014) for many NHS and government suppliers, and Cyber Essentials Plus is expected for higher-risk or business-critical systems.

Cyber Essentials v3.3 — MFA now mandatory

From assessments on 28 April 2026, Cyber Essentials v3.3 makes multi-factor authentication mandatory on in-scope cloud services. Periculo helps you meet the current requirements first time.

NHS DTAC penetration testing

NHS DTAC (Digital Technology Assessment Criteria) is the framework NHS buyers apply to a digital health product before procurement — and DTAC v2 became mandatory across NHS assessments on 6 April 2026. Its technical security section is where most suppliers get held up. Periculo provides the external, manual penetration testing DTAC requires, plus the surrounding evidence.

DTAC technical security asks for:

  • A current Cyber Essentials or Cyber Essentials Plus certificate.
  • An external manual penetration test with a documented action plan for findings.
  • Evidence of a secure development lifecycle (SDL).
  • Multi-factor authentication and strong access controls.
  • Vulnerability management and patching, and secure hosting configuration.

A common gate is that no vulnerability scoring 7.0 or higher on CVSS may remain unresolved — issues must be fixed and retested. NHS buyers typically expect a penetration test at least annually and after significant changes. Periculo tests web applications, mobile apps (iOS and Android), APIs, and cloud environments (AWS, Azure, GCP), and confirms the right cadence during scoping.

Medical device penetration testing

Periculo provides CREST-accredited penetration testing for medical devices and Software as a Medical Device (SaMD). We test the full connected system — the device itself, companion apps, APIs, cloud back-ends and supporting infrastructure — to surface exploitable vulnerabilities and support regulatory approval across the product lifecycle. Findings are delivered with detailed technical write-ups and executive summaries suitable for regulators, Notified Bodies, NHS buyers and leadership.

Aligned to FDA and EU MDR cybersecurity expectations

Medical device cybersecurity is assessed differently in each market, and our testing is built to satisfy both:

  • FDA premarket (US) — under Section 524B and the FDA's 2026 premarket cybersecurity guidance, third-party penetration testing is required, and web-application tests rebadged for a device are rejected. A device-specific test supports the expected Letter of Attestation.
  • EU MDR & MDCG 2019-16 — penetration testing is recommended under MDCG 2019-16 Rev.1 and treated as a de facto requirement by many Notified Bodies. Testing also supports GSPR / Annex I 17.2 secure-by-design obligations, IEC 81001-5-1, SBOM and vulnerability-handling expectations, and the EU Cyber Resilience Act.

Whether you are filing in the US, the EU, or both, Periculo delivers device-specific testing that removes the Notified Body argument and satisfies FDA explicitly — one evidence set built for both markets.

ISO 27001

Certification, maintenance and readiness support, including managed ISO 27001. ISO 27001 also serves as supporting evidence within DTAC and can exempt certain DSPT evidence items, provided its scope genuinely covers the NHS data-processing environment.

Sectors we serve

  • Digital Health & HealthTech
  • Medical Devices & Software as a Medical Device (SaMD)
  • NHS IT suppliers and the health & care supply chain
  • AI-enabled clinical and diagnostic platforms

Key facts

  • AccreditationsCREST-accredited testing; IASME-licensed certification body for CE and CE+
  • DSPT specialismIndependent DSPT audits for NHS IT suppliers — assertion 9.4.5, 12 mandated assertions
  • DTACExternal manual pen testing and full technical security evidence for DTAC v2
  • Medical devicesDevice & SaMD pen testing aligned to FDA Section 524B, EU MDR and MDCG 2019-16
  • Track record70M+ sensitive records secured across 70+ countries; 100% audit success rate
  • LocationA2, Avonside Business Centre, Melksham, Wiltshire, SN12 8BT, UK

Common questions

What do I need to sell digital health software to the NHS?

Typically a current Cyber Essentials or CE+ certificate, an external penetration test with a remediation plan, and — if you meet the IT supplier thresholds — a DSPT submission with an independent audit under assertion 9.4.5. Products are assessed against DTAC.

Which IT suppliers need a DSPT independent audit?

Those supplying digital goods or services to NHS or care organisations with 50+ staff and annual turnover above £10 million. The submission deadline is 30 June.

Do you test medical devices and SaMD?

Yes — CREST-accredited testing across the connected device, companion apps, APIs, cloud back-ends and infrastructure, aligned to device cybersecurity expectations.

Talk to Periculo

Whether you need a DSPT independent audit, Cyber Essentials, DTAC penetration testing, medical device testing or ISO 27001, Periculo covers NHS security compliance end to end — from one CREST-accredited team.

Website: www.periculo.co.uk
Email: info@periculo.co.uk

Book a consultation