By EJN Labs · 6 Oct 2026 · 8 min read
NHS CTOs typically ask suppliers for three things before granting HSCN access: a signed HSCN Connection Agreement, confirmation that patient data is encrypted in transit, and independent evidence of security testing, usually a Data Security and Protection Toolkit submission, a CREST-accredited penetration test report, or both. The Connection Agreement itself does not name penetration testing; that request comes from the trust’s own local review.
Why do NHS CTOs vet suppliers before opening HSCN access?
NHS CTOs vet suppliers because HSCN access extends the trust’s network boundary to your systems. A vulnerability on a connected supplier can become an incident inside the trust, so IT and information governance teams review a supplier’s security evidence before connectivity is arranged.
That review sits outside the network paperwork itself. NHS England Digital’s own guidance states that HSCN customers, not the network operator, carry responsibility for encrypting patient data crossing the network, that connection ownership must sit at a senior level, and that a named security contact must be reachable during an incident. A CTO’s questions mirror that same due diligence.
For a supplier this shows up as a questionnaire, a scoping call, or both, usually run separately from the network provisioning itself. Getting your evidence in order before that conversation starts, rather than scrambling once a trust asks, is what keeps a deal on schedule.
Does the HSCN Connection Agreement require a penetration test?
No. The HSCN Connection Agreement does not name penetration testing. What it requires is that signatories treat patient data as needing encryption in transit, assign senior ownership of the connection, and provide named security contacts, obligations set out in the agreement itself, not testing evidence.
Signing the Connection Agreement lets your organisation send and receive data across HSCN. It does not automatically grant access to the systems and services that sit on top of it. Reaching those, NHS Digital’s national applications or a trust’s own local systems, is where the Data Security and Protection Toolkit comes in, and where testing evidence starts to matter. The toolkit’s IT protection standard lists an annual penetration test among the evidence organisations submit for assessment, the practical route by which testing enters an HSCN-adjacent review.
Knowing which layer you are actually being asked about saves a lot of back-and-forth. If a CTO’s question is about the pipe, point to your signed Connection Agreement. If it is about the data flowing through it, that is a DSPT and testing question.
What third-party assurance requirements come up in an HSCN access review?
Third-party assurance requirements commonly cluster around four items: a Data Security and Protection Toolkit submission, evidence of Cyber Essentials, a penetration test report from a CREST-accredited firm, and a named security contact. Which apply depends on what your systems touch, not on HSCN membership itself.
| What the trust asks | Why it comes up | Evidence that satisfies it |
|---|---|---|
| Have you completed or started a DSPT submission? | governs access to patient data and trust systems | Current DSPT status and confirmation date |
| Can you evidence Cyber Essentials? | baseline hygiene across the supplier estate | A current CE or CE+ certificate |
| Do you have a recent penetration test report? | independent proof beyond a self-assessment | CREST-accredited report scoped to the systems reaching HSCN |
| Who do we contact if something goes wrong? | the incident-response obligation in the Connection Agreement | Named security contact and escalation path |
If what you supply counts as a digital health product, buyers commonly add the Digital Technology Assessment Criteria (DTAC)‘s technical security section, which expects evidence that testing has been carried out, typically an annual external test against the OWASP Top 10, plus a documented remediation plan. Our guide to the NHS Data Security and Protection Toolkit covers the DSPT side in more depth.
How should a supplier prepare penetration test evidence before an access review?
Start by scoping the systems that will actually exchange data across HSCN, not your whole estate; a CTO’s review focuses on what touches the trust, not everything you run internally. Commission testing against those systems specifically, timed so the report stays current when the review happens.
Timing matters more than suppliers expect, because the toolkit’s own annual submission cycle means a report over twelve months old is routinely treated as due for renewal, whatever the underlying system looks like. A few habits keep the evidence usable across more than one ask:
- Scope to the boundary. Externally reachable infrastructure, any web application or API staff or patients touch, and anything carrying data over the connection.
- Choose accredited testing. A report from a CREST-accredited firm is accepted without a follow-up ask about who did the work.
- Build in remediation time. An open finding when the trust reviews your evidence stalls the conversation; leave room to fix and retest first.
- Write for reuse. A report with CVSS-scored findings and a remediation plan can satisfy a DSPT submission, a DTAC-compatible reporting request and a trust’s questionnaire together.
Our penetration testing checklist covers the preparation that makes scoping conversations like this shorter.
What does the penetration testing NHS buyers ask for typically cost?
UK penetration testing for HSCN-adjacent systems typically runs £3,300 to £7,000 for an external-facing infrastructure test of 3 to 5 days, rising to £6,600 to £12,600 for 6 to 9 days when a web application or patient-facing product sits in scope alongside it. A quote form gives an exact price once the scope is set.
UK market day rates for CREST-accredited testing typically range from £1,100 to £1,400. What moves the total is scope, not seniority or which firm you choose: the number of externally reachable systems, whether a web application or API sits behind them, and whether the engagement needs to satisfy DSPT, DTAC or both in a single report.
| Scope | Typical effort | Typical UK cost |
|---|---|---|
| External-facing infrastructure test for HSCN-connected systems | 3 to 5 days | £3,300 to £7,000 |
| Infrastructure plus web application or DTAC-scope digital product | 6 to 9 days | £6,600 to £12,600 |
| Retest after remediation | 1 to 2 days | £1,100 to £2,800 |
These are typical UK ranges, not quotes; the exact figure depends on your systems and comes from scoping. Our wider guide to penetration testing costs in the UK sets out how those ranges are built up, and the quote form is the fastest way to get a number for finance sign-off.
How does EJN Labs approach penetration testing for NHS supplier access?
EJN Labs is a UK-based, CREST-accredited penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus. All testing is carried out by UK-based testers, and we scope every NHS-adjacent engagement around what the trust will want to see: current DSPT alignment and, where relevant, DTAC-ready evidence.
That starts with asking what the review is actually for: a fresh HSCN connection, a DSPT renewal, a DTAC submission, or all three at once. We scope testing to the systems that reach the trust, test against the OWASP methodology a buyer’s security team will recognise, and hand back a report with CVSS-scored findings and a remediation plan ready to attach to a questionnaire. Where remediation is needed, a retest confirms it before your evidence goes back to the trust.
Frequently Asked Questions
Do we need a penetration test to get HSCN access?
No. The HSCN Connection Agreement does not require a penetration test; it covers encrypting data in transit, senior ownership of the connection and named security contacts. Testing evidence matters once you need access to systems or data on HSCN, usually via a Data Security and Protection Toolkit submission.
What is the difference between the HSCN Connection Agreement and the Data Security and Protection Toolkit?
The Connection Agreement governs the network layer: it lets you send and receive data across HSCN. The Data Security and Protection Toolkit governs the systems and data layer: national applications check it before granting patient-data access, and trusts often ask for the same evidence before opening local systems.
Will a DSPT-aligned penetration test report also satisfy a DTAC-compatible reporting request?
Usually, if it is scoped from the outset. A CREST-accredited report covering the OWASP Top 10 against your external-facing systems, with CVSS-scored findings and a remediation plan, commonly satisfies both a DSPT submission and a DTAC-compatible reporting request, since the evidence both ask for overlaps closely.
How long before applying for HSCN access should we commission testing?
Four to six weeks before your target connection date is a comfortable margin. That allows time for scoping, testing itself, typically one to two weeks, remediation of any findings, and a short retest, so the report you hand your NHS contact is current and free of unresolved high-severity issues.
What does penetration testing for an NHS supplier access review cost?
An external-facing infrastructure test typically runs 3 to 5 days at £1,100 to £1,400 per day, so £3,300 to £7,000. Adding a web application or patient-facing product takes it to 6 to 9 days, or £6,600 to £12,600. A retest after remediation runs 1 to 2 days, £1,100 to £2,800.
Get your evidence ready before the next access review
If an NHS trust has asked you for penetration test evidence ahead of HSCN access, a DSPT renewal, or a DTAC submission, we can scope testing around exactly what they need to see. Get a CREST pentesting quote and we will quote a fixed price for the exact scope for your systems.
Related research
For the broader set of questions NHS buyers raise before any contract, not just network access, see our guide to selling software to the NHS. For the report format itself, our guide to a DTAC-compatible penetration test report sets out what a trust expects to see on paper.




Leave a Reply