Healthcare & NHS

CE+, DSPT and CAF compliance.
Patient data stays where it belongs.

ZAP is self-hosted in your NHS or healthcare organisation's cloud tenancy. Patient data, findings and compliance evidence never leave your environment. CE+, DSPT and NCSC CAF monitored continuously.

CE+ NHS DSPT NCSC CAF CIS Azure 2.0 GDPR CQC Reg 17
Book a session 30 minutes · No commitment
Seconds
DSPT evidence generated
vs weeks manually
Minutes
Drift detected
Patient data protection
Zero
Patient data egress
GDPR satisfied structurally
6 weeks
CE+ assessment
vs 3–4 months traditional
Cyber Essentials Plus

CE+ for NHS contracts.
Ready when you need it.

Cyber Essentials Plus is a mandatory requirement for NHS contracts and any organisation processing NHS data. ZAP monitors all 5 CE+ technical areas continuously — evidence ready when the assessor arrives.

Firewalls and gateways — NSG/firewall rules monitored against CE+ requirements
Secure configuration — OS and application configuration baselines enforced
User access control — RBAC and privileged access monitored
Malware protection — AV and EDR coverage monitored
Patch management — VM and container patch compliance surfaced daily
CE+ Live Monitor
Firewalls & gateways 94%
2 NSG findings — fixes available
Secure configuration 97%
Configuration baseline met
User access control 100%
RBAC and PAM compliant
Malware protection 100%
AV coverage complete
Patch management 91%
3 VMs pending — fixes queued
Evidence pack: Generated in seconds. Assessor-ready. All 5 areas. Tamper-evident PDF.
NHS DSPT

DSPT evidence in seconds.
Not weeks.

NHS Data Security and Protection Toolkit submission requires evidence across 10 mandatory standards. ZAP generates this from live estate data on demand.

01
Personal confidential data
Data processing documentation, GDPR Article 30 records, consent mechanisms. ZAP maintains processing records for all cloud-based data workflows.
02
Staff responsibilities
Access control logs, RBAC assignments, privileged access review. Every access action logged with approver identity.
03
Training
System access provisioning linked to training completion. ZAP does not replace training systems but integrates access control evidence.
04
Managing data access
All cloud resource access documented. RBAC enforced. ZAP RBAC logs every action by role — Platform Lead approval required for all changes.
05
Process reviews
Continuous compliance monitoring replaces periodic manual reviews. Drift detected within minutes — not discovered at review.
06
Responding to incidents
ITSM auto-raise on security findings. RCA documented. Resolution with full audit trail. DSPT incident register automatically maintained.
07
Continuity planning
Backup job monitoring, DR replication compliance, ZAP Compliant Scan post-recovery. ICT continuity evidence generated automatically.
08
Unsupported systems
Patch compliance monitoring surfaces end-of-life OS. Unpatched VM compliance flagged. Patch management evidence generated.
09
IT suppliers and contracts
Shadow AI detection identifies unapproved third-party AI tools. All approved AI vendors documented in ZAP whitelist with DPIA reference.
10
Cyber security
CE+ continuous monitoring. NCSC CAF assessment support. CIS benchmark compliance. Full technical evidence for all 10 cyber security assertions.
Patient data sovereignty

ZAP cannot access your
patient data. Ever.

ZAP is self-hosted. It runs inside your NHS organisation's Azure or AWS subscription. Patient data, clinical records and compliance findings never leave your environment. Zentej has zero access — contractually and architecturally.

Patient data stays in your subscription
ICO registration requirements satisfied
GDPR Article 30 processing records maintained
Zero telemetry to Zentej systems
Air-gapped deployment supported
NHS Digital data governance compliant
ZAP Platform
Patient data
DSPT evidence
CE+ findings
Audit logs
NHS Azure / AWS
Zentej (outside your boundary) Delivers software updates as signed packages. No connection to your environment.
Shadow AI in healthcare

AI in clinical environments
needs governance. ZAP provides it.

Clinical AI tools, diagnostic support systems and unapproved LLMs in NHS cloud environments create GDPR, DSPT and EU AI Act exposure. ZAP detects them automatically.

AI diagnostic tools deployed by clinical teams without DPIA or DSPT approval
LLMs connected to patient data stores without GDPR Article 30 documentation
AI clinical decision support tools without clinical safety review documentation
Unapproved AI containers in NHS Kubernetes clusters processing patient data
Shadow AI tools used by clinical informatics teams without Information Governance approval
Customer outcomes

What NHS and healthcare
organisations achieve.

Microsoft Azure
NHS Trust · CE+ · DSPT
6 weeks

CE+ assessment passed in 6 weeks. DSPT evidence pack from first scan. 3 weeks of compliance team time per quarter recovered. No manual evidence assembly.

Amazon AWS
Healthcare · NCSC CAF
90 days

400 findings across inherited estate remediated in 90 days. NCSC CAF compliance achieved. Patient data sovereignty confirmed — zero data egress.

Azure · Merged Tenancies
NHS ICS · Multi-trust
1 view

Three NHS trust tenancies unified under one ZAP instance. One CE+, DSPT and CAF compliance score. ICS oversight dashboard. One annual DSPT submission.

Frequently asked questions

Healthcare and NHS questions answered.

Yes. ZAP generates a DSPT evidence pack from live estate data in seconds. All mandatory assertions covered. Data security controls, access management, system patching, backup and DR evidenced from ZAP continuous monitoring. Submitted annually — assembled in seconds, not weeks.
Yes. ZAP continuously monitors all CE+ technical controls across Azure, AWS and GCP. Evidence pack on demand. CE+ assessment preparation reduced from weeks of manual effort to a morning.
No. ZAP is self-hosted — it runs entirely within your NHS or healthcare organisation's Azure, AWS or GCP subscription. Patient data, findings and compliance evidence never leave your environment. ICO registration and GDPR Article 30 compliance satisfied structurally.
NHS Data Security and Protection Toolkit (DSPT), Cyber Essentials Plus (CE+), NCSC Cyber Assessment Framework (CAF) and CQC Regulation 17 (good governance). All monitored continuously and evidenced on demand.
ZAP continuously monitors NCSC CAF objectives — managing security risk, protecting against attack, detecting cyber security events and minimising impact. Evidence pack covers all four CAF objectives with control-level detail.
Yes. AI diagnostic tools, clinical decision support systems or unapproved AI containers in AKS or EKS clusters detected within scan cycle. HIGH severity ITSM auto-raised. Critical for GDPR compliance — AI processing patient data must be documented.
Yes. A single ZAP instance can govern multiple NHS trust tenancies — separate compliance scores, separate evidence packs, shared governance visibility for ICS oversight.
CQC Regulation 17 requires good governance of information systems. ZAP provides continuous technical evidence of security controls, access management and data protection — all available for CQC inspection on demand.
Free · 30 minutes · No commitment

See CE+ and DSPT evidence
generation live.

30 minutes. We show you ZAP generating a CE+ and DSPT evidence pack from a live estate.

Book a session
No commitment· 30 minutes· [email protected]