Viewee
Start free
Pricing
Sign in
← Legal and assurance

Bottom line

The three badges do not represent three comparable, open certification schemes. Cyber Essentials Plus is the fastest credible win and is realistic before revenue if Viewee's small device and cloud estate is clean. ISO/IEC 27001 is a real management-system certification: valuable for larger procurements, but it needs a working ISMS and continuing audit budget, so Viewee should build toward it now and book certification when a buyer, investor or revenue justifies the cost. There is no single, generally available "NHS Assured Solution" badge for any health or social care supplier. NHS assurance is route-specific. Viewee should build a DTAC evidence pack and keep its DSPT work moving; it would enter NHS England's formal solution/API assurance only if a customer or planned integration gives it a specific route.

At a glance

RouteWhat it provesEarliest sensible targetIndicative cash cost, ex VATViewee call
Cyber Essentials PlusIndependent technical testing against the same five controls as basic Cyber Essentials4-8 weeks if the estate is small and cleanAbout £1.3k-£3k for micro/small, plus remediation or adviceDo first
ISO/IEC 27001:2022A certifying body has audited Viewee's information security management system4-9 months; 3-6 months only with a tight, stable scope and focused ownerRoughly £8k-£25k in year one; lean startup cases may be lowerBuild now; certify when commercially justified
NHS digital assuranceProduct and supplier evidence for the relevant NHS/social care use or integrationEvidence pack in 1-3 months; formal assurance only once a route/customer existsDTAC self-prep can be mainly internal time; integration or clinical-safety work varies widelyDo not buy or claim a generic badge

Costs are planning ranges, not official tariffs. BSI and most accredited ISO certification bodies quote by scope, headcount, sites and complexity. IASME sets the basic Cyber Essentials fee; Plus is quoted by certification bodies.

1. Cyber Essentials Plus

What the badge means

Cyber Essentials is the UK Government-backed baseline built around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Basic Cyber Essentials is a verified self-assessment. Plus starts with a valid basic certificate and adds independent technical testing. It is a point-in-time assessment, not a full security-management-system audit.

Prerequisites

Step-by-step

  1. Download IASME's current requirements and question set. Work through it before opening the paid assessment.

  2. Define one defensible scope and inventory every in-scope device, user, cloud service and internet-facing IP.

  3. Remediate the basics: MFA, supported software, patches, firewalls, least privilege, malware controls and secure defaults.

  4. Buy basic Cyber Essentials through IASME or a licensed certification body. Complete the portal questionnaire and board attestation. The organisation has up to six months from application to pass.

  5. Once basic is issued, appoint an IASME-licensed Plus certification body and obtain a scoped quote. The Plus audit must be completed within three months of the basic certificate.

  6. Give the assessor access to sampled devices/users. Expect remote vulnerability scanning, checks of internet-facing services, malware/file handling, email/browser protections, patch status and confirmation that normal users cannot perform administrator functions. Testing can be remote or on-site.

  7. Fix findings quickly. IASME describes a 30-day remediation window for non-compliances; every required test must pass unless a narrow scheme exception applies.

  8. Display the Plus badge only within IASME's mark terms and renew annually. Basic and Plus certificates expire after 12 months.

Cost and timing

Ongoing obligations

Maintain the controls continuously, repeat basic and Plus every 12 months, reassess scope after staff/device/cloud changes, keep MFA and patching evidence, and budget for another technical audit. Plus does not replace risk management, incident response, data protection, DSPT or penetration testing of Viewee's web application.

2. ISO/IEC 27001

What the badge means

ISO/IEC 27001:2022 specifies requirements for an information security management system (ISMS). Certification assesses Viewee's risk-based management system, not just a security checklist. ISO publishes the standard, while independent certification bodies conduct audits. BSI is one respected body, not the only option. For strongest procurement credibility, Viewee should use a UKAS-accredited certification body and verify it on UKAS CertCheck.

What Viewee must have operating before audit

ISO 27001 does not explicitly mandate a penetration test. For a customer-facing platform handling sensitive care information, however, recent independent application/infrastructure testing is strong evidence and will also matter to customers and DTAC/security assurance.

Step-by-step

  1. Buy/access the current standard and confirm the certification edition and UK implementation with the chosen body.

  2. Name an accountable ISMS lead. Set scope, interfaces, interested parties and security objectives.

  3. Run a gap assessment against clauses 4-10 and all Annex A controls. Reuse Viewee's existing ISO readiness roadmap, requirements sheet, DSPT plan, incident response, backup/restore, architecture and Cyber Essentials work.

  4. Build the risk method, risk register, treatment plan and Statement of Applicability. Policies must describe what Viewee actually does.

  5. Operate the ISMS long enough to produce evidence, usually at least several months. Close technical gaps and complete a proportionate penetration test before Stage 2.

  6. Conduct staff awareness, an independent internal audit and a management review. Close material findings.

  7. Get at least two quotes from UKAS-accredited certification bodies. Ask each quote to separate Stage 1, Stage 2, travel, certificate/admin fees, annual surveillance and three-year recertification. BSI can quote, but price and auditor fit should be compared.

  8. Stage 1: the auditor reviews readiness and documented ISMS, including scope, risk method, Statement of Applicability, treatment plan, internal audit and management review. Resolve readiness findings.

  9. Stage 2: the auditor tests whether the ISMS and applicable controls are implemented and effective, sampling people, records, suppliers, technical evidence and management activity. Correct any nonconformities within the body's deadlines.

  10. Certification is normally maintained over a three-year cycle with surveillance audits at least annually, followed by recertification.

Cost and timing

Accredited bodies mostly quote rather than publish rates. Current UK market benchmarks should be treated as estimates:

A focused startup can implement and certify in 4-6 months only if its production design and suppliers are stable, one person owns the programme and evidence is already accumulating. Six to nine months is more realistic from an early-stage starting point. Audit findings or a changing architecture can extend it.

Ongoing obligations

Run the ISMS as business-as-usual: risk and supplier reviews; security objectives/metrics; awareness; access reviews; incident and continuity exercises; internal audits; management reviews; corrective action; document/evidence control; annual surveillance; and recertification after the three-year cycle. Material scope or platform changes must be assessed rather than saved for the next audit.

3. "NHS Assured Solution": what exists today

The important correction

There is no single open application that turns an arbitrary adult social care SaaS product into an "NHS Assured Solution" and awards a general endorsement badge. NHS England uses several assurance mechanisms for different purposes:

The screenshot badge may therefore be a programme-specific or legacy mark. Viewee should not reproduce or claim it unless NHS England has explicitly awarded the mark for a named programme/use and supplied brand terms.

The practical route for Viewee

  1. Classify the product and intended use. Document that Viewee collects and manages resident/family/staff feedback and actions. Decide whether it influences individual clinical decisions, integrates with care records/NHS services, or is administrative/quality-improvement software. That decision drives clinical-safety and medical-device duties.

  2. Ask each target customer what assurance route they require. For independent care homes this may be DSPT status, Cyber Essentials/Plus, data protection documents and pen testing rather than a national NHS route. NHS/ICB/local-authority procurements may request DTAC and contractual standards.

  3. Build a DTAC evidence pack now. Maintain a completed supplier response plus evidence for data flows/DPIA support, UK GDPR roles, security architecture and testing, incident response, business continuity, accessibility (including WCAG evidence), usability work, interoperability/API standards and clinical-safety applicability.

  4. Decide DCB0129 applicability with a qualified clinical safety officer. If the product is health IT with potential to introduce clinical risk, appoint a Clinical Safety Officer and produce a clinical safety case/hazard log. If it is out of scope, document the reason. Customer deployers may have separate DCB0160 duties.

  5. Continue DSPT work and publish at the right organisation category. Confirm Viewee's correct category with the DSPT helpdesk or contracting body. Keep evidence aligned rather than treating annual publication as a one-off badge.

  6. Only enter NHS England solution/API assurance when there is a concrete trigger: a national service integration, named NHS programme, framework or commissioner requirement. Follow that route's onboarding, conformance tests, security, information governance and clinical-safety requirements.

  7. Use precise claims. Say "Cyber Essentials Plus certified", "ISO/IEC 27001 certified by [body]" or "DSPT status: [published status/date]" only once true. For DTAC, say the product's DTAC evidence has been completed/assessed by the named buyer, not "NHS approved" unless NHS England explicitly says so.

Cost and timing

Stage-honest plan for Viewee

Now: £0/low-cost groundwork

Next 3-6 months

  1. Complete basic Cyber Essentials and Plus first. It is the clearest independent badge at Viewee's stage and tests foundational hygiene.

  2. Commission an appropriately scoped independent web application/infrastructure penetration test after the production architecture stabilises; remediate high findings.

  3. Operate the ISMS, complete internal audit and management review, then seek two or three UKAS-accredited certification quotes.

  4. Proceed to ISO Stage 1/2 within this window only if the scope is stable, evidence is mature and a buyer/investor/revenue case supports both year-one and annual costs.

  5. Present the DTAC/DSPT evidence pack to design partners and ask them to confirm their exact assurance/procurement gates.

Wait for revenue, scale or a named procurement trigger

Cyber Essentials Plus -> independent pen test -> operational ISMS and DTAC/DSPT evidence -> ISO 27001 when commercially justified -> route-specific NHS assurance when triggered.

This order gives Viewee useful buyer evidence quickly without spending scarce pre-revenue cash on a badge that cannot be obtained generically. It also avoids duplicate effort: the same inventories, policies, risk records, technical controls and test evidence support all later routes.

Sources

Official and primary

Market cost checks, not official tariffs

Costs, programme names and assurance rules can change. Confirm the latest scope and written quote with the chosen UKAS-accredited/IASME certification body and the relevant customer or NHS England programme before committing or making a public claim.