Are You Prepared for the NHS Charter?

In May 2025, NHS England issued a letter to all current and prospective suppliers, introducing the NHS Cyber Security Charter.

The Charter is part of a broader push to strengthen the digital defences of the health and social care system and is expected to be operational by autumn 2025, giving suppliers a short but vital window to align with its requirements.

The Charter sets out a series of commitments that suppliers must meet to continue working with the NHS. These commitments are designed to reduce the risk of cyber attacks, particularly ransomware, which has become a growing threat to healthcare systems.

In this article, we’ll break down each of the charter’s key points and what they may mean for your organisation.

Who Needs to Sign the NHS Cyber Security Charter?

The NHS Cyber Security Charter will be applicable to all current, potential or aspiring suppliers to the NHS.

This includes any organisation whose services support clinical systems or involve the processing (including storage) of confidential information, such as confidential patient data.

Does the NHS Cyber Security Charter Replace the Data Security and Protection Toolkit?

While the Data Security and Protection Toolkit (DSPT) remains in place, the Charter introduces more specific and proactive expectations. It may eventually replace or significantly reshape the DSPT, especially for suppliers handling sensitive systems or data.

1. Keep Systems Supported and Patched

Your software and systems must be actively supported by vendors and regularly updated. This helps close known security gaps before attackers can exploit them.

What to do:

  • Avoid using outdated or unsupported software
  • Apply security patches as soon as they are released
  • Use tools to automate patch management where possible

2. Meet DSPT Standards

You must achieve and maintain at least a “Standards Met” rating in the DSPT. This demonstrates that your organisation handles data securely and responsibly.

What to do:

3. Use Multi-Factor Authentication (MFA)

MFA adds an extra layer of security by requiring more than just a password to access systems. If you provide software to the NHS, you must also support identity federation or offer MFA functionality.

What to do:

  • Enable MFA on all systems that support it
  • Enforce MFA on all privileged accounts
  • Ensure any products you create support MFA for NHS users
  • Align with NHS England’s MFA policy

4. Monitor Systems 24/7

You must have monitoring and logging of your critical IT infrastructure. This helps detect and respond to threats quickly.

What to do:

  • Assess and prioritise your infrastructure to determine what’s “critical”
  • Consider using a Security Operations Centre (SOC) or managed service
  • Alternatively, deploy intrusion detection tools, there are some free options like Wazuh, although these can be complex to deploy and maintain
  • Retain logs for incident investigation

5. Maintain Immutable Backups

Immutable backups cannot be changed or deleted, even by attackers. They are essential for recovering from ransomware or other destructive attacks.

What to do:

  • Store backups off-site or in the cloud
  • Test your recovery process regularly
  • Back up both business data and product systems
  • Consider implementing technologies such as WORM (Write Once, Read Many) storage

6. Conduct Board-Level Cyber Exercises

Your leadership team must be involved in planning and testing your response to cyber incidents.

What to do:

7. Report Incidents Promptly

If a cyber incident affects patient care or data, you must report it quickly and work with NHS England to manage the response.

What to do:

  • Establish clear reporting procedures
  • Train staff to recognise and escalate incidents

8. Follow Secure Software Development Practices

If you develop software for the NHS, it must follow the DSIT/NCSC Software Code of Practice. This ensures your products are secure by design.

What to do:

  • Build security into your development lifecycle
  • Use secure environments for building and testing
  • Keep customers informed about risks and updates

Final Thoughts

The NHS Cyber Security Charter is a call to action for suppliers to take cyber security seriously and work in partnership with the NHS to protect vital services.

Start by reviewing your current practices against the Charter’s commitments. If you’re unsure where to begin, Evolve North can help you establish gaps in your current cyber security approach and create a prioritised action plan to support your organisation in adhering with the NHS Cyber Security Charter.

Evolve North can offer support and guidance in each of the charter’s requirements. Our relevant services include NCSC Assured Cyber Incident Exercising, Cyber Incident Response Planning, NHS DSPT Support and Penetration Testing. Call us on 01748 905 002 or email info@evolvenorth.com to get started.

 

Arrange a FREE Consultation

Want to learn more about improving your organisation's security? Our team is here to answer your questions and explain the options available. In a free consultation, we'll help you understand the services we offer and how they can support your goals. It's a simple, no-obligation way to start exploring the right approach for your business.