By EJN Labs · 7 Sep 2026 · 7 min read
NHS CIS2 authentication onboarding and SCAL completion both name penetration testing directly in NHS England’s own guidance, each pointing to testing carried out to CHECK standards before go-live. In our experience, a CREST-accredited penetration test report, typically £3,300 to £11,200 in the UK market depending on scope, is the evidence suppliers commonly prepare for both submissions.
Why CIS2 and SCAL onboarding both raise the penetration testing question
Both onboarding tracks ask suppliers to prove their software is secure before it touches NHS data. CIS2 covers identity and access; SCAL covers product onboarding to services such as the National Care Records Service. Each includes a security assurance stage that penetration testing evidence typically answers.
Suppliers we work with often reach both tracks in the same release. A clinical software product typically needs CIS2 Authentication so care professionals can log in with a national smartcard or an app-based credential, and separately needs to pass SCAL if it also integrates with Spine services such as the Personal Demographics Service. Treating the two as one assurance exercise, rather than commissioning testing twice months apart, is usually the more efficient route.
What NHS CIS2 authentication onboarding and SCAL completion actually require
Both name penetration testing directly. SCAL lists it as a required step before go-live. CIS2 goes further: NHS England’s guidance for getting your software assured names a penetration test to CHECK standards as part of demonstrating your product’s core conformance, regardless of whether the product is new or existing.
The Supplier Conformance Assessment List process lists “pass technical and security tests, including solution assurance and penetration testing” as a numbered onboarding step, and NHS England’s guidance for onboarding to the National Care Records Service is more explicit again: penetration testing to CHECK standards must be completed before go-live, with an action plan in place for any findings.
CHECK is NCSC’s assurance scheme, developed for penetration testing carried out for central government departments, public sector bodies and critical-national-infrastructure organisations. Where a product also handles patient data directly, the underlying security declaration commonly runs through the Data Security and Protection Toolkit too, which requires an annual penetration test under its IT protection standard, something we cover in more depth in our guide to DSPT penetration testing.
What a CIS2 or SCAL penetration test needs to cover
Scope follows what you are integrating with, not a generic checklist. A CIS2 test exercises the login flow, token handling and session management used to authenticate care professionals. A SCAL-driven test typically extends further, covering the API or interface used to exchange data with Spine services.
Most products we test in this space combine a web application penetration test for the CIS2 login journey with an API penetration test for the Spine-facing interface, since patient-record lookups and cross-organisation access control usually sit behind the API rather than the login page. Findings we see most often involve token replay, session handling that survives re-authentication incorrectly, and access boundaries that do not fully respect a supplier’s assigned organisation code.
- Authentication and token handling. The full CIS2 login journey, including how your software validates and stores tokens once a user is authenticated.
- The Spine or NCRS interface. Message handling, input validation and error responses on the API your product uses to read or write patient data.
- Access control. Whether one organisation’s users, sessions or records are reachable from another organisation’s context.
When to schedule penetration testing inside the onboarding timeline
Schedule testing once your integration environment is stable, not right at the end. NHS England’s guidance puts CIS2’s assurance stage at two to twelve weeks, run alongside build and test work, and SCAL’s penetration testing step comes after functional and clinical safety checks pass.
We typically ask suppliers to book testing four to six weeks before their planned go-live date. That leaves room for a retest if the first pass surfaces findings that need fixing before the report can go into your submission. Suppliers integrating both CIS2 and SCAL in the same release tend to save calendar time by scoping one combined engagement rather than commissioning two reports weeks apart.
What CIS2 and SCAL penetration testing evidence costs in the UK market
Cost tracks the number of interfaces under test. Day rates for CREST-accredited work in the UK typically sit between £1,100 and £1,400, and a CIS2-only test usually needs fewer days than a combined engagement covering a Spine or NCRS interface too. Scope, not supplier size, moves the price.
| Scope | Typical effort | Typical UK cost |
|---|---|---|
| CIS2 authentication integration only | 3 to 5 days | £3,300 to £7,000 |
| SCAL-driven interface (Spine, PDS or NCRS API) | 5 to 8 days | £5,500 to £11,200 |
| Combined CIS2 and SCAL, web app plus API | 8 to 12 days | £8,800 to £16,800 |
| Retest after remediation | 1 to 2 days | £1,100 to £2,800 |
These are typical UK ranges rather than a quote; the exact price depends on how many interfaces your product exposes and comes from scoping. Our guide to penetration testing costs in the UK covers how scope translates into day count in more detail.
How EJN Labs approaches CIS2 and SCAL onboarding testing
We scope around the onboarding evidence gap you actually have, not a generic pentest package. EJN Labs is a UK CREST-accredited penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus. Every CIS2 or SCAL engagement starts by identifying which onboarding step the report must satisfy, including where that step names CHECK standards specifically. We help you confirm what your onboarding team will accept before scoping begins.
Where a product needs both CIS2 authentication and SCAL evidence, we scope a single engagement that covers the login flow and the Spine-facing interface together, then structure the report so each finding maps clearly to the onboarding step it supports. UK-based testers carry out all of the work, which matters when your product handles NHS patient data and your own declarations depend on knowing where testing took place. If you are still mapping out what your submission needs, our NHS security checklist for software suppliers is a useful starting point.
Frequently Asked Questions
Does NHS CIS2 authentication onboarding require a penetration test?
Yes. NHS England’s guidance for getting CIS2 software assured names a penetration test to CHECK standards as a core conformance step, regardless of whether the product is new or existing. This sits alongside a separate requirement to declare how you handle data security.
Does SCAL require penetration testing before go-live?
Yes, for products onboarding through the SCAL process. NHS England’s SCAL guidance lists penetration testing as a step within technical and security testing, and its guidance for National Care Records Service integration is explicit: penetration testing to CHECK standards must be completed before go-live.
What does penetration testing for NHS CIS2 and SCAL onboarding cost?
A CIS2-only authentication test typically runs 3 to 5 days at £1,100 to £1,400 per day, so £3,300 to £7,000. A combined engagement covering a SCAL-driven Spine or NCRS interface typically runs 5 to 8 days, or £5,500 to £11,200. The exact price depends on scope, confirmed through a quote.
Can one penetration test cover both CIS2 and SCAL evidence requirements?
Often, yes. Where a product needs both CIS2 authentication and a SCAL-driven interface, scoping one engagement that covers the login flow and the API together usually costs less and takes less calendar time than commissioning two separate reports. We typically recommend this once both onboarding tracks are confirmed.
How long before go-live should suppliers book penetration testing for CIS2 or SCAL?
Four to six weeks before your planned go-live date is a comfortable margin. That leaves time for testing itself, remediation of any findings, and a retest before the report needs to go into your submission, since SCAL and CIS2 assurance steps both sit near the end of onboarding, not the start.
Get penetration testing evidence ready for your CIS2 or SCAL submission
If CIS2 authentication or SCAL completion is sitting on your onboarding critical path, we can scope a combined engagement around the evidence you actually need to submit. Get a CREST pentesting quote and we will scope the work and fix the price for your product.




Leave a Reply