Skip to main content

News

Updated Guidance to CIS1 Deprecation

Internal NHS England (previously NHS Digital) services are to migrate to NHS CIS2 Authentication by the original date of September 2023. Suppliers have an additional year to migrate to NHS CIS2 Authentication, with a new retirement date of 30 September 2024.

The original plan was to retire Care Identity Service authentication (aka ‘CIS1’) by September 2023, and for systems to have migrated to NHS CIS2 Authentication. 

Whilst progress has been made; it is clear that not all suppliers will complete the migration within this timeframe.   

Therefore, we intend to change approach and: 

  • Migrate internal NHS England (previously NHS Digital) services to NHS CIS2 Authentication by the original date of September 2023 as some suppliers had dependencies on us to migrate first.   
  • Offer suppliers an additional year to migrate to NHS CIS2 Authentication, with a new retirement date of 30 September 2024 
  • Account for any suppliers who have not completed the migration to NHS CIS2 Authentication or have not completed the rollout of their changes to all sites, by continuing to support CIS1, but at a reduced service level.   

Currently both CIS1 and NHS CIS2 Authentication are supported to a Platinum SLA - supported hours are 24 hours a day, 365 days a year with 99.9% availability target (max of 44 mins downtime per month)

Revised CIS support plans

On 30 September 2024

  • We will reduce the support level for the CIS1 authentication service to a Silver SLA.
  • Operational hours will remain 24 hours a day, 365 days a year, but supported hours will be reduced to 8 am to 6 pm Monday – Friday and 99.5% availability (target max of 3.5 hours of downtime per month).  
  • NHS CIS2 Authentication will continue to be run to Platinum SLA.

On 30 September 2025

  • We will reduce the support level for CIS1 authentication service to a Bronze SLA.
  • Operational hours will remain 24 hours a day, 365 days a year, but support hours will be to 8 am to 6 pm Monday - Friday and 98% availability (target max of 14.5 hours of downtime per month) 
  • NHS CIS2 Authentication will continue to be run to Platinum SLA.

Benefits of migration to NHS CIS2 Authentication

  • NHS CIS2 Authentication is built using common open standards such as OIDC, FIDO2 and WebAuthn which are widely used and understood within the market. This should increase the availability of relevant engineering skills, reducing time-to-market. 
  • NHS CIS2 Authentication supports new features such as modern alternatives to smartcards, and supports access over the internet via devices other than Windows PCs 
  • NHS CIS2 Authentication is more secure and better optimised for high availability and for the addition of new capabilities wherever demand creates a need. 



Last edited: 23 August 2023 11:32 am