Bottom line
The three badges do not represent three comparable, open certification schemes. Cyber Essentials Plus is the fastest credible win and is realistic before revenue if Viewee's small device and cloud estate is clean. ISO/IEC 27001 is a real management-system certification: valuable for larger procurements, but it needs a working ISMS and continuing audit budget, so Viewee should build toward it now and book certification when a buyer, investor or revenue justifies the cost. There is no single, generally available "NHS Assured Solution" badge for any health or social care supplier. NHS assurance is route-specific. Viewee should build a DTAC evidence pack and keep its DSPT work moving; it would enter NHS England's formal solution/API assurance only if a customer or planned integration gives it a specific route.
At a glance
| Route | What it proves | Earliest sensible target | Indicative cash cost, ex VAT | Viewee call |
|---|---|---|---|---|
| Cyber Essentials Plus | Independent technical testing against the same five controls as basic Cyber Essentials | 4-8 weeks if the estate is small and clean | About £1.3k-£3k for micro/small, plus remediation or advice | Do first |
| ISO/IEC 27001:2022 | A certifying body has audited Viewee's information security management system | 4-9 months; 3-6 months only with a tight, stable scope and focused owner | Roughly £8k-£25k in year one; lean startup cases may be lower | Build now; certify when commercially justified |
| NHS digital assurance | Product and supplier evidence for the relevant NHS/social care use or integration | Evidence pack in 1-3 months; formal assurance only once a route/customer exists | DTAC self-prep can be mainly internal time; integration or clinical-safety work varies widely | Do not buy or claim a generic badge |
Costs are planning ranges, not official tariffs. BSI and most accredited ISO certification bodies quote by scope, headcount, sites and complexity. IASME sets the basic Cyber Essentials fee; Plus is quoted by certification bodies.
1. Cyber Essentials Plus
What the badge means
Cyber Essentials is the UK Government-backed baseline built around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Basic Cyber Essentials is a verified self-assessment. Plus starts with a valid basic certificate and adds independent technical testing. It is a point-in-time assessment, not a full security-management-system audit.
Prerequisites
Fix the scope: Viewee Limited, its people, laptops, mobiles where in scope, cloud services, networks and any segregated exclusions. The Plus scope must match the valid basic certificate.
Meet the current April 2026 requirements. MFA for cloud services where available and timely security updates are critical pass items under the tightened 2026 marking.
Use supported operating systems and applications; remove or isolate unsupported software.
Enforce least privilege and separate day-to-day accounts from administrator access.
Have working patch evidence, device inventory, secure configuration and malware protection.
Complete and pass basic Cyber Essentials first. A board member or equivalent signs the answers.
Step-by-step
Download IASME's current requirements and question set. Work through it before opening the paid assessment.
Define one defensible scope and inventory every in-scope device, user, cloud service and internet-facing IP.
Remediate the basics: MFA, supported software, patches, firewalls, least privilege, malware controls and secure defaults.
Buy basic Cyber Essentials through IASME or a licensed certification body. Complete the portal questionnaire and board attestation. The organisation has up to six months from application to pass.
Once basic is issued, appoint an IASME-licensed Plus certification body and obtain a scoped quote. The Plus audit must be completed within three months of the basic certificate.
Give the assessor access to sampled devices/users. Expect remote vulnerability scanning, checks of internet-facing services, malware/file handling, email/browser protections, patch status and confirmation that normal users cannot perform administrator functions. Testing can be remote or on-site.
Fix findings quickly. IASME describes a 30-day remediation window for non-compliances; every required test must pass unless a narrow scheme exception applies.
Display the Plus badge only within IASME's mark terms and renew annually. Basic and Plus certificates expire after 12 months.
Cost and timing
Basic official price: £320 + VAT for a micro organisation (0-9 people), £440 for small (10-49), £500 medium and £600 large under current 2026 pricing.
Plus: IASME says pricing depends on network size and complexity and requires a certification-body quote. One IASME certification body's published September 2026 rate is £1,195 + VAT for micro and £1,495 for small; its basic-plus bundle is £1,364/£1,742. Other assessors may quote more for a larger, mixed or on-site estate.
Planning allowance for Viewee: £1,300-£3,000 + VAT for basic plus Plus, assuming a handful of standard, remotely assessable devices. Add £500-£2,500 if hands-on advisory help is needed; remediation hardware/software is extra.
Timeline: about 2-6 weeks for a prepared micro company, or 4-8 weeks allowing remediation and assessor scheduling. The hard sequencing point is basic first, then Plus within three months.
Ongoing obligations
Maintain the controls continuously, repeat basic and Plus every 12 months, reassess scope after staff/device/cloud changes, keep MFA and patching evidence, and budget for another technical audit. Plus does not replace risk management, incident response, data protection, DSPT or penetration testing of Viewee's web application.
2. ISO/IEC 27001
What the badge means
ISO/IEC 27001:2022 specifies requirements for an information security management system (ISMS). Certification assesses Viewee's risk-based management system, not just a security checklist. ISO publishes the standard, while independent certification bodies conduct audits. BSI is one respected body, not the only option. For strongest procurement credibility, Viewee should use a UKAS-accredited certification body and verify it on UKAS CertCheck.
What Viewee must have operating before audit
Defined ISMS scope and boundaries, ideally narrow but honest: Viewee Limited and the production feedback platform, people, suppliers and supporting cloud/services.
Organisational context, interested parties, security objectives, roles and leadership commitment.
Information asset and supplier inventory, data flows, risk assessment method, completed risk assessment and risk treatment plan.
Statement of Applicability covering all 93 Annex A controls, showing what applies, implementation status and justified exclusions.
Controlled policies and evidence for access, joiner/mover/leaver, secure development/change, vulnerability and patch management, backups/restores, incidents, continuity, supplier security, data retention/deletion and staff awareness.
Measurable operation over time: logs, tickets, approvals, reviews, restore tests, vulnerability work, training and corrective actions.
At least one internal audit and management review, with nonconformities tracked to closure.
ISO 27001 does not explicitly mandate a penetration test. For a customer-facing platform handling sensitive care information, however, recent independent application/infrastructure testing is strong evidence and will also matter to customers and DTAC/security assurance.
Step-by-step
Buy/access the current standard and confirm the certification edition and UK implementation with the chosen body.
Name an accountable ISMS lead. Set scope, interfaces, interested parties and security objectives.
Run a gap assessment against clauses 4-10 and all Annex A controls. Reuse Viewee's existing ISO readiness roadmap, requirements sheet, DSPT plan, incident response, backup/restore, architecture and Cyber Essentials work.
Build the risk method, risk register, treatment plan and Statement of Applicability. Policies must describe what Viewee actually does.
Operate the ISMS long enough to produce evidence, usually at least several months. Close technical gaps and complete a proportionate penetration test before Stage 2.
Conduct staff awareness, an independent internal audit and a management review. Close material findings.
Get at least two quotes from UKAS-accredited certification bodies. Ask each quote to separate Stage 1, Stage 2, travel, certificate/admin fees, annual surveillance and three-year recertification. BSI can quote, but price and auditor fit should be compared.
Stage 1: the auditor reviews readiness and documented ISMS, including scope, risk method, Statement of Applicability, treatment plan, internal audit and management review. Resolve readiness findings.
Stage 2: the auditor tests whether the ISMS and applicable controls are implemented and effective, sampling people, records, suppliers, technical evidence and management activity. Correct any nonconformities within the body's deadlines.
Certification is normally maintained over a three-year cycle with surveillance audits at least annually, followed by recertification.
Cost and timing
Accredited bodies mostly quote rather than publish rates. Current UK market benchmarks should be treated as estimates:
Certification body, Stage 1 + Stage 2: commonly about £3,500-£8,000 for a small organisation, driven by scope and audit days.
Consultancy: £0 if genuinely self-led; about £3,000-£12,000 for targeted to full support. Typical quoted day rates are £600-£1,400.
Gap analysis/internal audit if bought separately: often £1,000-£4,000 combined depending on scope.
Application/infrastructure penetration testing: commonly £2,000-£5,000 for a small SaaS footprint. Useful and likely expected evidence, but not a clause that automatically mandates a pen test.
Realistic Viewee year-one planning range: £8,000-£25,000 + VAT and substantial founder/technical time. A very lean, well-prepared micro scope could land nearer £7,000-£15,000; full-service implementation can exceed the range.
Ongoing: surveillance audit commonly £2,000-£3,500 a year, plus internal audit, testing, training and tooling. Plan roughly £5,000-£12,000 annually all-in if continuing external support and testing are included.
A focused startup can implement and certify in 4-6 months only if its production design and suppliers are stable, one person owns the programme and evidence is already accumulating. Six to nine months is more realistic from an early-stage starting point. Audit findings or a changing architecture can extend it.
Ongoing obligations
Run the ISMS as business-as-usual: risk and supplier reviews; security objectives/metrics; awareness; access reviews; incident and continuity exercises; internal audits; management reviews; corrective action; document/evidence control; annual surveillance; and recertification after the three-year cycle. Material scope or platform changes must be assessed rather than saved for the next audit.
3. "NHS Assured Solution": what exists today
The important correction
There is no single open application that turns an arbitrary adult social care SaaS product into an "NHS Assured Solution" and awards a general endorsement badge. NHS England uses several assurance mechanisms for different purposes:
DTAC: a common assessment framework for digital health technologies used by NHS and adult social care buyers/providers. It covers clinical safety, data protection, technical security, interoperability, and usability/accessibility. It supports procurement and local assurance. It is not an NHS-wide product certification or endorsement that Viewee can independently buy.
DSPT: an annual organisation-level self-assessment/publication covering data security and protection. It may be contractually required or needed when accessing NHS patient data/systems. It is not product certification. Some IT suppliers and designated independent providers have independent audit requirements, depending on organisation type and contracts.
NHS England API/service assurance: a formal onboarding/conformance route when software connects to a specific NHS national API or service. The Digital Onboarding Service or, in some cases, a Supplier Conformance Assessment List process is tied to that integration. Approval is to go live with that service, not blanket assurance of the whole company.
Solution Assurance compliance/conformance catalogues: programme-specific lists of vendors/products that achieved named milestone or interoperability certificates. The NHS England Compliance Catalogue itself says it covers certificates from specified programmes and is not a general catalogue of all assured products.
The screenshot badge may therefore be a programme-specific or legacy mark. Viewee should not reproduce or claim it unless NHS England has explicitly awarded the mark for a named programme/use and supplied brand terms.
The practical route for Viewee
Classify the product and intended use. Document that Viewee collects and manages resident/family/staff feedback and actions. Decide whether it influences individual clinical decisions, integrates with care records/NHS services, or is administrative/quality-improvement software. That decision drives clinical-safety and medical-device duties.
Ask each target customer what assurance route they require. For independent care homes this may be DSPT status, Cyber Essentials/Plus, data protection documents and pen testing rather than a national NHS route. NHS/ICB/local-authority procurements may request DTAC and contractual standards.
Build a DTAC evidence pack now. Maintain a completed supplier response plus evidence for data flows/DPIA support, UK GDPR roles, security architecture and testing, incident response, business continuity, accessibility (including WCAG evidence), usability work, interoperability/API standards and clinical-safety applicability.
Decide DCB0129 applicability with a qualified clinical safety officer. If the product is health IT with potential to introduce clinical risk, appoint a Clinical Safety Officer and produce a clinical safety case/hazard log. If it is out of scope, document the reason. Customer deployers may have separate DCB0160 duties.
Continue DSPT work and publish at the right organisation category. Confirm Viewee's correct category with the DSPT helpdesk or contracting body. Keep evidence aligned rather than treating annual publication as a one-off badge.
Only enter NHS England solution/API assurance when there is a concrete trigger: a national service integration, named NHS programme, framework or commissioner requirement. Follow that route's onboarding, conformance tests, security, information governance and clinical-safety requirements.
Use precise claims. Say "Cyber Essentials Plus certified", "ISO/IEC 27001 certified by [body]" or "DSPT status: [published status/date]" only once true. For DTAC, say the product's DTAC evidence has been completed/assessed by the named buyer, not "NHS approved" unless NHS England explicitly says so.
Cost and timing
DTAC pack: no central certification fee. A lean first pack can take 2-6 weeks of concentrated internal work when policies and architecture already exist. External privacy, security, accessibility or clinical-safety specialists can add several thousand pounds depending on gaps.
DSPT: portal work itself is not a product certification purchase. Cost is internal time plus any specialist support or mandatory independent audit dictated by Viewee's category/contracts.
DCB0129: material cost and time only if applicable; obtain a scoped Clinical Safety Officer quote rather than assuming it is required.
NHS API/programme assurance: programme-specific and often dependent on a sponsor/customer and a mature integration. Plan in months, not weeks, once a real route exists.
Stage-honest plan for Viewee
Now: £0/low-cost groundwork
Keep the existing ISO 27001 roadmap, requirements sheet, Cyber Essentials preparation and DSPT plan as one evidence system rather than separate paperwork projects.
Fix and document scope; inventory users, devices, cloud services, code repositories, suppliers, information assets and data flows.
Turn on MFA everywhere it is available; separate admin access; enforce supported software and patching; enable disk encryption, endpoint protection and backups.
Finalise proportionate policies: access, secure development/change, vulnerability/patching, supplier management, incident response, backups/restores, continuity, retention/deletion and acceptable use.
Start evidence collection: monthly access/patch/supplier reviews, restore tests, incident exercises, training, risk reviews and decision records.
Complete free Cyber Essentials readiness resources and the current self-assessment question set.
Keep building the DSPT and DTAC evidence packs, including accessibility and the written clinical-safety applicability decision.
Next 3-6 months
Complete basic Cyber Essentials and Plus first. It is the clearest independent badge at Viewee's stage and tests foundational hygiene.
Commission an appropriately scoped independent web application/infrastructure penetration test after the production architecture stabilises; remediate high findings.
Operate the ISMS, complete internal audit and management review, then seek two or three UKAS-accredited certification quotes.
Proceed to ISO Stage 1/2 within this window only if the scope is stable, evidence is mature and a buyer/investor/revenue case supports both year-one and annual costs.
Present the DTAC/DSPT evidence pack to design partners and ask them to confirm their exact assurance/procurement gates.
Wait for revenue, scale or a named procurement trigger
Full ISO certification if cash is tight and no near-term deal values it. Continue building the ISMS so later certification is faster.
Expensive compliance automation platforms, full-time compliance hires or broad multi-entity certification.
Clinical-safety consultancy unless the intended use analysis shows DCB0129 applies or a buyer requires it.
NHS national API/service onboarding, programme catalogue status or use of any "NHS assured" mark until a specific integration/programme/customer route exists.
Recommended order
Cyber Essentials Plus -> independent pen test -> operational ISMS and DTAC/DSPT evidence -> ISO 27001 when commercially justified -> route-specific NHS assurance when triggered.
This order gives Viewee useful buyer evidence quickly without spending scarce pre-revenue cash on a badge that cannot be obtained generically. It also avoids duplicate effort: the same inventories, policies, risk records, technical controls and test evidence support all later routes.
Sources
Official and primary
ISO, ISO/IEC 27001:2022: https://www.iso.org/standard/27001
BSI, ISO/IEC 27001 implementation guide: https://www.bsigroup.com/siteassets/pdf/en/insights-and-media/insights/brochures/27001_implementation_guide.pdf
BSI, ISO/IEC 27001 client guide: https://www.bsigroup.com/siteassets/pdf/en/insights-and-media/insights/brochures/27001-iso-client-guide.pdf
UKAS, information-security accreditation: https://www.ukas.com/accreditation/sectors/digital/info-sec/
UKAS CertCheck: https://certcheck.ukas.com/certification-body
NCSC, Cyber Essentials overview: https://www.ncsc.gov.uk/cyberessentials/overview
IASME, Cyber Essentials: https://iasme.co.uk/cyber-essentials/
IASME, Cyber Essentials FAQ: https://iasme.co.uk/cyber-essentials/frequently-asked-questions/
IASME, Cyber Essentials versus Plus: https://iasme.co.uk/articles/cyber-essentials-and-cyber-essentials-plus-what-is-the-difference/
NCSC, Cyber Essentials Plus Test Specification v3.2: https://www.ncsc.gov.uk/files/cyber-essentials-plus-test-specification-v3-2.pdf
IASME, April 2026 scheme changes: https://iasme.co.uk/articles/important-update-changes-to-cyber-essentials-for-april-2026/
NHS England, DTAC guidance: https://transform.england.nhs.uk/key-tools-and-info/digital-technology-assessment-criteria-dtac/key-principles-success/
NHS England, Solution Assurance: https://digital.nhs.uk/services/solution-assurance
NHS England, Compliance Catalogue: https://digital.nhs.uk/services/solution-assurance/compliance-catalogue
NHS England, how to get assured for APIs/services: https://digital.nhs.uk/developer/assurance
NHS England, assurance process for APIs/services: https://digital.nhs.uk/developer/assurance/process-for-apis-and-services
NHS England, digital clinical safety assurance: https://www.england.nhs.uk/long-read/digital-clinical-safety-assurance/
DSPT, organisation types: https://www.dsptoolkit.nhs.uk/Help/Org-Types
Market cost checks, not official tariffs
ClauseWise, ISO 27001 UK cost benchmarks (March 2026): https://clausewise.co.uk/blog/iso-27001-certification-cost-uk/
ExpertSure, ISO 27001 UK cost comparison (August 2026): https://www.expertsure.com/uk/iso-certification/iso-27001-certification-cost/
Vincent Cyber Defence, published Cyber Essentials/Plus rates: https://vincentcyberdefence.co.uk/pricing/
Costs, programme names and assurance rules can change. Confirm the latest scope and written quote with the chosen UKAS-accredited/IASME certification body and the relevant customer or NHS England programme before committing or making a public claim.
