Supplying Email or Messaging to the NHS? The DCB1596 Security Testing Evidence Buyers Ask For

Supplying Email or Messaging to the NHS? The DCB1596 Security Testing Evidence Buyers Ask For

By EJN Labs · 7 Sep 2026 · 7 min read

NHS email and messaging suppliers accrediting to DCB1596 by the self-management route need to submit evidence of a penetration test or IT Health Check, reviewed by NHS England’s information security team. Suppliers accrediting through Office 365 face a narrower check, an IT Health Check against the CIS Microsoft 365 Foundation Benchmark, since Microsoft addresses most of the standard’s technical controls. A CREST-accredited penetration test, scoped to the platform itself, satisfies the standard’s own wording.

Why do NHS buyers ask for DCB1596 security testing evidence?

NHS buyers ask for DCB1596 security testing evidence because accreditation controls whether your platform can exchange information with NHS.net accounts at all. An unaccredited platform risks being blocked or restricted, so procurement and information governance teams raise it early in onboarding.

DCB1596 applies to any organisation providing health or social care that holds an active Organisation Data Service code and needs to exchange sensitive information with NHS.net accounts, whether that’s a referral system, a clinician-facing messaging app, or a platform sending appointment reminders. If your product falls into that scope, an NHS buyer’s IT or information governance contact will ask which accreditation route you’re taking before onboarding proceeds much further. It’s a question worth answering before a sales conversation gets serious, since a supplier caught without an accreditation plan tends to lose weeks explaining the standard to their own product team rather than progressing the deal.

What does DCB1596 actually require, and where does UK GDPR fit?

DCB1596 calls for organisations using the self-management accreditation route to submit evidence of a penetration test or IT Health Check, reviewed by NHS England’s information security team, alongside a signed conformance statement countersigned by a clinical safety expert and an ICT expert.

Organisations accrediting through Office 365 face a narrower version of that step: NHS England reviews a signed conformance statement evidenced by an ITHC scoped to the CIS Microsoft 365 Foundation Benchmark, because Microsoft has already addressed most of the platform’s technical requirements. Self-management, whether fully in-house or a hybrid setup, is the route that carries the full penetration testing obligation, and it’s the one most independent software vendors building their own messaging platform actually use. Alongside DCB1596, UK GDPR Article 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of your technical and organisational measures. It doesn’t name penetration testing as the method, but a DCB1596-scoped test is a natural way to evidence that obligation too.

Which parts of the platform does a DCB1596 test need to cover?

A DCB1596-ready penetration test typically covers the areas where a messaging platform’s real risk sits, not just the two words the standard uses. That means going beyond the mail flow itself into every route an attacker, or a misconfigured tenant, could reach patient-identifiable content.

  • Authentication and admin access. Login into the platform itself and any administrative console used to manage mailboxes or message routing.
  • Encryption. How messages and attachments are protected in transit and at rest.
  • Session handling. Whether authenticated sessions can be hijacked, replayed or extended beyond their intended lifetime.
  • Integration points. Any API or gateway connection that moves patient-identifiable data to or from NHS.net accounts.
  • Tenant isolation. Where one platform serves several NHS organisations, whether one trust’s mailbox or message thread is reachable from another’s session.

The integration point is usually where we recommend the most attention, since it’s often the piece a vendor’s own team has tested least. That connection deserves coverage from an API penetration test, alongside the web application testing that covers the platform’s own interface and admin console.

What happens between scoping and a report you can submit?

Scoping starts with your accreditation route: whether you’re self-managing DCB1596, which components handle patient-identifiable data, and whether the platform is multi-tenant. From there we agree scope, test against it, and deliver a severity-scored report your leads can countersign.

We agree testing dates as part of that same scoping conversation, since a fixed window matters more for NHS onboarding than for most commercial engagements. All testing is carried out by UK-based testers from a CREST-accredited firm, working from an agreed scope so there’s no ambiguity about what was and wasn’t covered when your buyer reviews the report. Where testing finds exploitable issues, we retest once fixes are in, so the version you submit reflects a resolved state rather than an open findings list. Turnaround from kickoff to signed-off report typically runs two to three weeks; a hard NHS onboarding deadline is worth flagging at the scoping call so we can plan around it.

What should suppliers budget for DCB1596 testing?

Budget by day count, not headline day rate: a single email or messaging platform with one admin interface and a few integrations typically needs 3 to 5 testing days. At a typical UK day rate of £1,100 to £1,400, that’s roughly £3,300 to £7,000.

Platform scopeTypical effortTypical UK cost
Single-tenant platform, one admin console, one gateway integration3 to 5 days£3,300 to £7,000
Multi-tenant platform or public API surface6 to 10 days£6,600 to £14,000
Retest after remediation1 to 2 days£1,100 to £2,800

These are typical UK ranges rather than quotes; the figure that matters is the one built from your actual architecture. A multi-tenant platform, or one exposing a public API alongside the email or messaging service itself, is what usually pushes an engagement from the lower band into the higher one. Our guide to penetration testing costs in the UK breaks down how scope drives day count across engagement types, and the quote form is the fastest way to get a fixed price against your platform.

How EJN Labs approaches DCB1596 penetration testing

EJN Labs approaches DCB1596 testing by scoping around your accreditation route first: which systems handle patient-identifiable data, whether you’re self-managing or hybrid, and what your clinical safety and ICT leads need signed off before submission.

We’re a UK CREST-accredited firm, also certified to ISO 27001 and Cyber Essentials Plus, and a licensed IASME Certification Body for Cyber Essentials; all testing is carried out by UK-based testers. The report is written to stand on its own once it reaches NHS England’s secure email team, with findings scored by severity and a retest included once fixes are made. Recurring issues we come across on messaging and email platforms include admin consoles reachable without multi-factor authentication and integration credentials reused across a staging and production environment; both are worth checking before evidence goes in, since either would show up as a finding. If your onboarding involves other NHS security evidence beyond DCB1596, we can often scope both from the same testing window rather than treating them as separate exercises.

Frequently Asked Questions

Why was I asked to have a penetration test completed as part of DCB1596 onboarding?

You were asked because you’re accrediting via the self-management route. NHS England’s guidance says that route needs a penetration test or IT Health Check (ITHC) completed and reviewed by its information security team. The Office 365 route instead carries a narrower check, an ITHC scoped to the CIS Microsoft 365 Foundation Benchmark.

Does the Office 365 accreditation route need a penetration test too?

Not a full one. The Office 365 route evidences conformance through an ITHC scoped to the CIS Microsoft 365 Foundation Benchmark, since Microsoft has already addressed most of the standard’s technical requirements. The full penetration test or ITHC requirement applies to the self-management route, in-house or hybrid.

How long does DCB1596 self-management accreditation take?

NHS England’s guidance puts self-management accreditation at six months to a year end to end, against one to three months for Office 365. Testing is one part of that timeline, so booking it early alongside your conformance statement keeps you nearer the shorter end.

What does a DCB1596 penetration test typically cost in the UK?

A single platform typically needs 3 to 5 testing days, which at a typical UK day rate of £1,100 to £1,400 works out at roughly £3,300 to £7,000. Multi-tenant or API-heavy platforms usually run 6 to 10 days, or £6,600 to £14,000.

What does EJN Labs’ DCB1596 test report include?

Every report includes an executive summary your clinical safety and ICT leads can sign off, findings scored by severity with remediation steps, and a retest once fixes are made, written to be submitted alongside your conformance statement as it stands.

Scope your DCB1596 penetration test

If NHS onboarding is waiting on your DCB1596 evidence, we can scope a penetration test around your platform’s accreditation route and your deadline. Get a CREST pentesting quote and we’ll come back with a fixed scope and price.

Leave a Reply

Your email address will not be published. Required fields are marked *