Skip to content
Phishing for Trouble –
The IO Podcast returns for Series 2
Listen now
ISO 27001 Healthcare Enterprise

NHS Professionals achieves ISO 27001 certification and improves their infosec management

ISO success

Achieved ISO 27001certification whilstincorporating their existingcompliance with ISO 9001,DSPT and GDPR.

Stronger security

Increased security andgreater level of compliancewithout further investment.

Refined process

Streamlined their ongoingmanagement of informationsecurity and reduced thetime taken to certification.

About NHS Professionals

NHS Professionals work in partnership with hospital trusts to provide a bank of highly skilled temporary staff who want to work flexibly within the NHS. They have over 130,000 registered members and more than 50 NHS client trusts. Staffing groups they supply include nurses, midwives, doctors and a variety of other high-quality health professionals.


The challenge

As a result of the nature of their business, processing staff, client and candidate personal data means information security is critical.

As such the information security management system underpinning the business is key.When NHS Professionals got in touch with ISMS.online they had two objectives: achieve UKAS certified ISO 27001 quickly and improve their ongoing management of information security.

These key business objectives were at the heart of the ISO implementation project and the driving force for achieving certification in such a short time. NHS Professionals had held ISO 9001 for 7 years and were already compliant with both the NHS Data Security Protection Toolkit (DSPT)and GDPR.

Like many organisations, they were documenting their InfoSec in Word and Excel and saving their policies on shared drives.As we often see with organisations using these types of solutions, it is hard to keep them up to date for one standard. So, when you have multiple standards or regulations to follow, the whole system can fall over or become very expensive to maintain. It can also result in practical challenges around collaboration, version control, policy approval and policy sharing. All of the above can ultimately cause non-compliance and increase business risk rather than reduce it.

Adding ISO 27001 certification could have resulted in duplicated efforts and policies increasing cost and adding risks, so we sought advice from a consultant who indicated that ISMS.online would help streamline our mature processes and reduce the time taken to certification.

Dean Fields IT Director, NHS Professionals

The solution

NHS Professionals had a new service offering which required them to be ISO 27001 certified within 6 months.It was important to NHS Professionals that all of their ISMS work could be managed in one application.

ISMS.online has a number of frameworks available, including the recently issued NHS Data Security Protection Toolkit (DSPT) replacing the IG Toolkit. This allows customers to achieve greater levels of compliance without further investment. NHS Professionals were already in a good position to start; they had a number of policies and processes covering many aspects of information security. Using the Assured Results Method, we were able to help them quickly move their good practices into ISMS.online.

The support team has been invaluable. They helped us migrate data, answered our everyday functionality questions, and their Information Security Experts were on hand to give us one-to-one support.

Dean Fields IT Director, NHS Professionals

The result

NHS Professionals completed their Stage 1 audit after only 6 weeks, with no significant findings.

This was closely followed by success at the Stage 2 Certification Audit with no non-conformities, observations or identified opportunities for improvement.This fantastic result proved the value of using the ISMS.online platform, the Virtual Coach and the Assured Results Method supplemented with some direct consulting support.

Thanks to ISMS.online, we achieved ISO 27001 UKAS certification within 4 months. I can honestly say we wouldn’t have been able to do it without ISMS.online and their support team.

Dean Fields IT Director, NHS Professionals

Want results like this?

Book a demo today and get compliance confidence

Book a demo
ISO 27001 IT & Services Medium business

Accelerating CCT to ISO 27001 certification and beyond

After attempting to build their own ISMS from scratch and hitting a wall, CCT needed a flexible, all-in-one platform to consolidate their compliance work and drive through to ISO 27001 certification.

ISO 27001 IT & Services Small business

Resilient IT partner with ISMS.online to help keep New Zealand companies safe and secure

As an ISO 27001 consultancy, Resilient IT needed a platform sophisticated enough to guide diverse clients to certification, yet flexible, simple, and cost-effective enough to work for organisations of any size.

ISO 27001 IT & Services Small business

Lanrex partner with ISMS.online to help their customers get ahead with their information security

Having achieved ISO 27001 via expensive consultants and a SharePoint-based ISMS, Lanrex found ongoing management increasingly time-consuming — and needed a purpose-built platform to replace their manual system and scale compliance for clients too.

You're in good company

Over 1,000 customers trust us with their compliance

Want to see how we could help you? Let's meet and see how you can get compliance confident.

Leader - Spring 2026
High Performer - Spring 2026 Small Business UK
Regional Leader - Spring 2026 EU
Regional Leader - Spring 2026 EMEA
Regional Leader - Spring 2026 UK
High Performer - Spring 2026 Mid-Market EMEA
ISO 27001
Cyber Exchange Member
ISO 27001
ISO 27701
Cyber Essentials
ISMS.online

Company number: 04922343

Nile House, Nile Street, Brighton, England, BN1 1HW
Copyright © 2026 Alliantist Ltd