What Is a Cyber Essentials Provider for Healthcare
Learn how to choose a Cyber Essentials provider with the healthcare experience and technical capability to support certification and Cyber Essentials Plus.
A cyberattack does not need to compromise a medical device to affect patient care.
In March 2026, a cyberattack on medical technology supplier Stryker disrupted its internal IT systems, halting production, shipping and distribution. NHS England and NHS Supply Chain subsequently introduced controls on the ordering of certain medical products while they worked to minimise disruption. Stryker said its connected and life-saving technologies remained safe to use, but the operational consequences were still significant. (NHS England)
That distinction matters.
Healthcare cybersecurity is often discussed in terms of patient records, ransomware and medical equipment. All are important. But cyber risk also lives in ordinary business systems: laptops, cloud accounts, supplier portals, remote access tools and software that quietly keeps operations moving.
When one of those systems fails, the impact can travel surprisingly far.
Cyber Essentials certification provides a practical baseline for reducing this exposure. Choosing the right provider, however, involves more than finding somebody who can help complete the assessment form.
What does a Cyber Essentials provider actually do?
The phrase “Cyber Essentials provider” is used rather loosely.
An organisation can prepare for certification itself, work with a cyber adviser, or buy a supported package from a Certification Body. The important distinction is that only a licensed Certification Body can conduct the assessment and issue the certification.
IASME, the official delivery partner for the scheme, maintains a directory of licensed Certification Bodies. These organisations employ qualified assessors who review Cyber Essentials applications. Some can also conduct the technical audit required for Cyber Essentials Plus. (IASME)
A good supported provider should help you:
- Define which people, devices, networks and cloud services are in scope.
- Understand how the Cyber Essentials requirements apply to your environment.
- Identify gaps before the formal assessment.
- Remediate weaknesses in configuration, access control and patching.
- Gather accurate information and supporting evidence.
- Coordinate the certification process.
- Prepare for Cyber Essentials Plus, where required.
- Maintain the controls after the certificate has been awarded.
That final point is worth dwelling on. Certification should describe how your organisation genuinely operates, not how it behaved during a particularly energetic fortnight before the assessment.
What does Cyber Essentials certification cover?
Cyber Essentials is the UK Government-backed minimum cybersecurity standard recommended by the National Cyber Security Centre. It focuses on five technical control areas:
- Firewalls
- Secure configuration
- Security update management
- User access control
- Malware protection
These controls are designed to defend against the most common internet-based attacks. Think of them as checking the doors, windows and locks before investing in motion sensors and a moat.
For healthcare organisations, these apparently basic controls can uncover meaningful risks:
- Former employees whose access has not been removed.
- Administrator accounts being used for everyday email and web browsing.
- Clinical or business applications running on unsupported software.
- Laptops missing important security updates.
- Cloud services without multi-factor authentication.
- Devices that nobody can confidently identify or manage.
- Remote access arrangements that have grown organically rather than securely.
The current Cyber Essentials requirements, version 3.3, took effect on 27 April 2026. Among the changes, the NCSC clarified that cloud services cannot simply be excluded from scope and placed greater emphasis on data backups. (NCSC requirements)
For a modern healthcare business using Microsoft 365, cloud-based patient systems, online booking platforms or outsourced applications, that clarification is particularly relevant. “It is hosted in the cloud” is not the same as “it is someone else’s security problem”.
Why healthcare experience matters
The Cyber Essentials controls are consistent across sectors, but applying them well requires context.
A provider working with a healthcare organisation needs to understand that security changes cannot be planned in isolation. Disabling an old system might improve the asset register while accidentally interrupting a clinical workflow. Tightening access may be sensible, but it still needs to accommodate clinicians working across locations. An update may be urgent, yet require coordination with a specialist software vendor.
Healthcare business security is a balancing act between confidentiality, integrity and availability. Patient information must be protected, records must remain accurate and services must remain accessible when care teams need them.
A provider with relevant experience should therefore ask questions beyond the certification form:
- Which systems are essential to delivering care?
- What happens if a booking, communications or patient-record system becomes unavailable?
- Which suppliers process or access health information?
- Are personal devices, home working or multiple sites part of the operating model?
- Who owns each system, account and remediation action?
- How will changes be tested without disrupting services?
- What evidence is also needed for contracts, insurers or the Data Security and Protection Toolkit?
Cyber Essentials can complement UK cybersecurity compliance work, but it does not replace every other obligation.
For example, healthcare organisations processing NHS patient information may also need to complete the Data Security and Protection Toolkit. Cyber Essentials Plus is not universally mandatory for completing the DSPT, although relevant certification can support assurance and reduce duplication in some circumstances. Requirements may also arise through specific NHS contracts or procurement arrangements. (DSPT guidance)
A credible provider should explain these relationships accurately. Be cautious of anyone who presents one certificate as a universal compliance wand. Sadly, the compliance wand remains on back order.
Cyber Essentials or Cyber Essentials Plus?
Both certification levels use the same five technical control areas. The difference is how those controls are verified.
Cyber Essentials is a verified self-assessment. Your organisation answers questions about its systems and controls, a senior representative confirms the accuracy of the submission, and a qualified assessor reviews it.
Cyber Essentials Plus adds independent technical testing. This can include external vulnerability scanning and testing a representative sample of servers, laptops, desktops, mobile devices and other systems within scope. The assessor verifies whether the controls described in the Cyber Essentials submission are working in practice.
An organisation seeking Cyber Essentials Plus must complete the audit within three months of its Cyber Essentials certification. (IASME)
Cyber Essentials Plus may be appropriate when:
- A customer or contract requires it.
- The organisation handles particularly sensitive information.
- Directors want stronger assurance than a self-assessment alone.
- Certification forms part of an NHS or public-sector supply arrangement.
- The business wants to test whether policies and reported controls match reality.
Our view is that providers should discuss Cyber Essentials Plus at the beginning, even when the immediate goal is standard certification. Controls designed with future testing in mind tend to be clearer, more consistent and easier to evidence.
It is much less comfortable to discover just before the Plus audit that half the laptops are managed one way, the other half another, and one particularly mysterious machine is apparently owned by “Reception”.
How to evaluate a Cyber Essentials provider
Before appointing a provider, ask the following questions.
Are they licensed to certify you?
Check whether the organisation is an IASME-licensed Certification Body. If it is offering readiness support but cannot issue certification, establish which Certification Body will conduct the assessment and who remains accountable for each stage.
There is nothing inherently wrong with separating preparation from certification. It simply needs to be transparent.
Do they begin with scope and discovery?
Poor scoping produces unreliable certification.
The provider should understand your legal entities, locations, cloud services, devices, networks and remote-working arrangements before promising a timetable. It should also identify specialist or legacy systems rather than quietly leaving them until the assessment becomes inconvenient.
Can they implement improvements?
There is a considerable difference between telling you that multi-factor authentication is missing and safely implementing it across your organisation.
Look for practical capability in identity security, endpoint management, vulnerability scanning, patching, secure configuration and asset management. The provider should be able to translate findings into an ordered remediation plan with owners, priorities and realistic timescales.
Do they understand healthcare operations?
Ask for evidence of relevant sector experience without expecting confidential client details.
A capable provider should be comfortable discussing the DSPT, sensitive health information, clinical continuity, specialist suppliers and regulated procurement. More importantly, it should understand how to improve security without treating daily operations as an inconvenient obstacle.
Can they take you to Cyber Essentials Plus?
If Plus is a likely destination, confirm that the provider can perform or coordinate the audit. Ask how it selects representative devices, checks vulnerabilities and prepares teams for technical testing.
The answer should sound like a defined process, not “we will cross that bridge when procurement asks for it”.
What happens after certification?
Cybersecurity changes whenever somebody joins, leaves, buys a device, adopts an application or delays an update.
Ask how the provider will maintain the asset register, review access, monitor vulnerabilities and preserve evidence. A certification project that ends with a PDF and a cheerful email may have missed the more valuable opportunity.
A baseline, not the finish line
The Stryker disruption illustrates a wider business truth: healthcare organisations depend on a chain of interconnected technology providers, operational systems and suppliers. A cyber incident anywhere in that chain can affect availability, purchasing and ultimately the delivery of care.
Cyber Essentials does not cover every cyber risk. The NCSC itself describes it as a baseline against common attacks, not a replacement for organisation-specific risk analysis. (NCSC)
That is not a weakness. Foundations are useful precisely because everything else depends on them.
The right Cyber Essentials provider will help you achieve certification, but the certificate should be the visible result of better controls underneath: clearer ownership, stronger access, supported software, managed devices and fewer quiet surprises.
For a regulated healthcare organisation, that is where the real value sits.