By EJN Labs · 8 Sep 2026 · 6 min read
Your penetration test report fits into the SCAL as evidence for step 8, “pass technical and security tests”, in NHS England’s Supplier Conformance Assessment List for CIS2 onboarding. The SCAL guide names penetration testing as part of that step, and NHS England reviews results before issuing a statement of technical conformance.
What is a SCAL, and why does NHS CIS2 authentication onboarding need one?
A SCAL is the Supplier Conformance Assessment List NHS England issues before a product connects to a national service such as CIS2. It pairs a shared supplier information sheet with a separate declaration sheet per service, covering compliance, risk and that service’s technical conformance requirements.
NHS England built CIS2 as the identity and authentication service that lets health and care staff log in to national clinical systems, extending access beyond the smartcard to newer options such as security keys and Windows Hello. Any product integrating with CIS2 goes through the same assurance route as other NHS APIs and services: the SCAL user guide sets out a ten-step onboarding sequence, and your penetration test report becomes evidence inside that sequence rather than a standalone document you submit on its own.
Why does NHS England ask for a penetration test before accepting a SCAL?
The SCAL user guide lists “pass technical and security tests” as step 8 of onboarding and names penetration testing, alongside solution assurance, as part of that step. Passing it is a condition of the connection agreement you sign, not a duty that sits outside CIS2 onboarding.
Two other essential requirements sit alongside the security testing step, and suppliers sometimes conflate them with the pen test. Where a product touches NHS patient data, the SCAL guide requires the Data Security and Protection Toolkit to be completed for the current reporting year, and where a product manages clinical risk it must meet the DCB0129 standard, which the guide describes as a legal requirement under the Health and Social Care Act 2012. These are separate lines on the SCAL, and a gap in one holds up the whole submission even if your penetration test is complete.
What does a CIS2-ready penetration test report need to cover?
A CIS2-ready report needs to cover the integration itself: the API or web service that talks to CIS2, the authentication exchange, and any backend handling the tokens or clinical data it returns. The SCAL guide sets no fixed methodology, so scope follows what your product does with CIS2, not a generic checklist.
In our experience testing CIS2 integrations, the areas that matter most are the OAuth 2.0 and OpenID Connect exchange with CIS2, session and token handling once a user is authenticated, and the authorisation logic that decides what a logged-in clinician can see. CIS2 integrations typically expose an API layer even where the front end is a web application, so we scope an API penetration test alongside the web or mobile client rather than testing the client in isolation.
Where in the SCAL and the onboarding timeline does the report sit?
The report sits inside the technical conformance declaration sheet for the CIS2 service, evidencing the “pass technical and security tests” step. On CIS2’s own onboarding journey, this falls under “get your software assured”, confirming security, clinical risk and service management alongside integration testing.
NHS England describes that assurance stage as typically taking two to twelve weeks, and says parts of it can run in parallel with your integration test environment work rather than strictly after it. That matters for scheduling: commissioning your penetration test once integration testing is under way, rather than waiting for a finished build, keeps the report ready when the SCAL is reviewed instead of becoming the reason a submission stalls.
Each additional NHS service you connect the same product to returns a fresh SCAL sheet to complete. A report scoped tightly to CIS2 will not automatically satisfy the next service you onboard to, so check what changed in the connection before assuming existing evidence still applies.
What does SCAL-ready penetration testing typically cost?
SCAL-ready penetration testing typically runs 4 to 6 days at UK day rates of £1,100 to £1,400, so £4,400 to £8,400 for a single CIS2 integration. Adding backend API and data-handling review widens that to 6 to 9 days, £6,600 to £12,600. The exact figure depends on scope, so a scoping call gives the accurate price.
These are UK market ranges rather than a quote, and scope is what moves the price, not which firm you choose. A retest once findings are fixed typically adds 1 to 2 days, £1,100 to £2,800. For the wider picture of how NHS and non-NHS engagements are priced, see our guide to penetration testing costs in the UK.
| Scope | Typical effort | Typical UK cost |
|---|---|---|
| Single CIS2 API or service integration | 4 to 6 days | £4,400 to £8,400 |
| Integration plus backend API and data handling | 6 to 9 days | £6,600 to £12,600 |
| Retest after remediation | 1 to 2 days | £1,100 to £2,800 |
How EJN Labs approaches penetration testing for NHS CIS2 suppliers
EJN Labs is a CREST-accredited penetration testing firm, certified to ISO 27001 and ISO 9001, with all testing carried out by UK-based testers. We scope CIS2 engagements around the integration you are submitting: the authentication exchange, the API surface behind it, and how tokens are handled once a session is live.
We write findings against the technical conformance declarations a SCAL submission needs to support, rather than a generic pen test template, and we time delivery so the report is ready before your assurance stage rather than commissioned in a rush once NHS England asks a question. Where a product also needs Data Security and Protection Toolkit evidence or clinical risk documentation, we scope alongside those workstreams rather than in isolation. If you are weighing up providers, our guide to CREST-accredited penetration testing sets out what accreditation should mean for a report like this.
Frequently Asked Questions
Does NHS CIS2 authentication onboarding require SCAL completion with a penetration test?
Yes. Any product connecting to CIS2 goes through SCAL completion, and the SCAL user guide lists “pass technical and security tests”, naming penetration testing, as step 8 of onboarding. NHS England reviews the results before issuing a statement of technical conformance and the connection agreement proceeds.
Which part of the SCAL does the penetration test report support?
It supports the technical conformance declaration sheet for the NHS service you are connecting to, in this case CIS2. The SCAL pairs a shared supplier information sheet with one declaration sheet per service, and your testing evidence sits against that service-specific sheet, not the general supplier information.
Who reviews the penetration test evidence in a CIS2 SCAL?
NHS England reviews the relevant sections of the SCAL, guides suppliers through completion, and issues a certificate or statement of technical conformance once testing and other declarations are accepted. Final approval to go live also sits with NHS England, not your testing provider.
How much does SCAL-ready penetration testing typically cost?
A single CIS2 integration typically takes 4 to 6 days at UK day rates of £1,100 to £1,400, so £4,400 to £8,400. Adding backend API and data-handling review takes it to 6 to 9 days, £6,600 to £12,600. The exact price depends on scope and comes from a quote.
When should CIS2 suppliers commission a penetration test before onboarding?
Commission it once integration testing is under way rather than waiting for a finished build, since NHS England says the assurance stage can run in parallel with integration testing and typically takes two to twelve weeks. Starting early keeps the report ready before the SCAL is reviewed.
Get a CIS2-ready penetration test scoped to your SCAL
If a CIS2 onboarding deadline is driving your timeline, we can scope a penetration test around the exact integration your SCAL declares. Get a CREST pentesting quote and we will return a fixed scope and price.




Leave a Reply