By EJN Labs · 4 Sep 2026 · 7 min read
NHS DCB1596, the secure email standard, covers health and social care organisations that exchange sensitive information by email. Adopting an already-accredited service such as NHSmail is one compliance route; accrediting your own service is the other. Only the second route names an independent test: DCB1596’s Service Provider requirements mandate a penetration test or IT Health Check before accreditation is approved.
Who has to meet DCB1596, and why the standard exists
Health and social care organisations that send or receive sensitive information by email have to meet DCB1596, whether that’s an NHS trust, a GP practice, a private care provider, or a supplier handling patient data directly under an NHS contract.
NHS England’s own framing of the standard is blunt: everyone exchanging that information needs to be confident it stays secure in transit, regardless of which side of the conversation sent it.
The standard sits under NHS.net Connect, and it exists because so much clinical correspondence, referrals, discharge summaries, multidisciplinary team messages, still travels by email and counts as confidential by definition. In our experience, organisations rarely set out to comply with DCB1596 specifically; they encounter it once a data-sharing agreement, a security review or a new NHS contract asks how outgoing email is protected.
Two ways to comply, and where testing enters the picture
NHS England sets out two ways to meet DCB1596, and an organisation has to choose one. The first route is adopting a service already accredited to the standard, such as NHSmail, a correctly configured Microsoft 365 tenant, or Google Workspace; that route is mostly a policy exercise, covering breach notification, mobile device rules and staff training, with no independent test named. The second route is self-management: demonstrating that your own email or messaging service meets the standard by going through NHS England’s accreditation process directly.
Self-management is where a technical test enters the requirements. Evidence goes through NHS England’s ServiceNow portal to its secure email team, and has to cover the conformance template’s information security evidence, including the penetration test, plus separate clinical safety and ICT declarations, each signed off before submission.
Why you might be asked to have a penetration test completed as part of DCB1596 onboarding
You are asked for a penetration test because DCB1596’s Service Provider requirements name one directly for any organisation running its own email service: a suitably scoped independent penetration test or IT Health Check, reviewed by NHS England’s secure email team before accreditation is approved.
That sits alongside the clinical safety and wider information security sections of the conformance statement rather than replacing them, so the test is one exhibit in a larger evidence pack. A CREST-accredited engagement against whichever component actually carries the sensitive email traffic, the hosting infrastructure, a web or API layer where the service has a browser or app front end, and the controls guarding access to it, produces findings that map onto that section directly. We scope around the component handling the traffic rather than an organisation’s whole estate, since that is what the conformance statement asks for.
Concretely, that means confirming encryption holds up for messages both in transit and at rest, attempting to bypass or brute-force whatever authenticates a user or a connecting system, and checking whether an unauthorised access attempt would actually surface in your organisation’s logging and monitoring. Weak transport encryption on a legacy relay, an authentication bypass on an admin console, and audit logging that silently drops failed login attempts are the kinds of findings this style of engagement is designed to catch before an assessor does.
Fitting testing into your DCB1596 accreditation timeline
NHS England’s ServiceNow portal aims to respond within 10 working days once your evidence pack is submitted. What actually varies is how long that pack takes to assemble: self-management needs a penetration test report, remediation evidence, ISO 27001 or DSPT evidence, and sign-off from a clinical safety officer and an ICT lead, where adopting an already-accredited service is largely a policy and configuration exercise.
We generally recommend testing once the service is feature-complete but before the conformance statement itself is drafted, leaving time to remediate and retest ahead of clinical safety and ICT sign-off. DCB1596’s own requirements expect medium-or-higher risk findings to be remediated before residual risk is accepted, so in our experience a report that still carries open high-severity findings tends to draw follow-up questions rather than a straightforward approval.
What we hand back is built with that submission in mind: an executive summary an ICT lead can lift into the conformance statement almost unedited, findings ranked by severity with clear reproduction steps, and a remediation section the clinical safety and ICT signatories can point to as evidence the issues were closed, not just identified.
What a DCB1596 penetration test costs in the UK market
A DCB1596 test typically scopes as an external infrastructure engagement, priced at the UK’s usual CREST day rate of £1,100 to £1,400 per day. An infrastructure-only engagement commonly needs 2 to 4 testing days, which puts the likely total at £2,200 to £5,600 in the current UK market.
Widen the scope to include a web application or API layer, which applies where the service has a browser or app front end, and the engagement grows to roughly 4 to 7 days, totalling £4,400 to £9,800.
Treat those as UK market bands rather than a fixed quote; what applies to your service depends on its architecture and is set once we scope the engagement properly. For the wider picture of how scope drives day count, see our cost guide; for DCB1596 specifically, the quote form is the fastest way to get a number against your own conformance statement.
How EJN Labs approaches DCB1596 secure email testing
EJN Labs holds CREST accreditation as a testing firm, alongside ISO 27001 and Cyber Essentials Plus certification, with every engagement carried out by UK-based testers. For DCB1596 work we scope directly against the self-management conformance statement your submission needs to satisfy.
That means the report your ICT lead submits lines up section by section with what the secure email team reviews, rather than a generic write-up that needs reshaping before it goes anywhere near your submission.
Where an organisation is also working towards the Data Security and Protection Toolkit or the Digital Technology Assessment Criteria alongside DCB1596, we design the engagement so the same testing evidence can support more than one submission where the frameworks overlap. Our external infrastructure penetration testing service covers the layer self-management submissions typically need evidenced first.
Frequently Asked Questions
Does DCB1596 require a penetration test?
Only if you run your own email service. DCB1596’s Service Provider requirements mandate an independent penetration test or IT Health Check for that route. Adopting NHSmail, Office 365 or Google Workspace instead follows a policy-based route with no independent test named.
Who has to comply with the NHS secure email standard?
Any health or social care organisation sending or receiving sensitive information by email has to comply with DCB1596, including NHS trusts, GP practices and organisations handling patient data for the NHS. Compliance means adopting an already-accredited service or accrediting your own.
What does a DCB1596 penetration test need to cover?
It needs to cover whichever component carries the sensitive email traffic: usually the hosting infrastructure, plus any web or API layer with a browser or app front end, and the access controls protecting it. Findings feed into the conformance statement’s information security evidence.
What does DCB1596 penetration testing cost in the UK?
For an infrastructure-only DCB1596 engagement, expect 2 to 4 days of CREST-accredited testing: £2,200 to £5,600 at the UK’s £1,100 to £1,400 day-rate band. Add a web or API layer and that stretches to 4 to 7 days, or £4,400 to £9,800. Exact scope is confirmed through the quote form.
How long does DCB1596 self-management accreditation take?
NHS England aims to review a submitted conformance statement within 10 working days once your evidence pack is complete. Assembling that pack, the penetration test, remediation evidence, and clinical safety and ICT sign-off, is what takes time, so scheduling the test early keeps it off your critical path.
Ready to scope DCB1596 testing evidence?
Where DCB1596 self-management is on your roadmap, we can scope a penetration test against the conformance statement sections your submission needs to satisfy. Start with a CREST pentesting quote and we will reply with a scope and price built around your service.




Leave a Reply