Not as a standalone legal requirement, but the relationship with DSPT compliance makes it effectively necessary for many. The DSPT references Cyber Essentials standards, and holding certification strengthens a care home’s submission considerably. The five controls it requires address the most commonly exploited attack vectors in health and social care.
The NCSC has specifically flagged care providers as cyber attack targets, and a breach in a regulated setting carries regulatory implications that go well beyond IT disruption. We advise all care provider clients to pursue Cyber Essentials as a minimum baseline and manage the certification process as part of the overall IT support relationship.