Skip to main content

Infrastructure hosting standards for the NHS

Current Chapter

Infrastructure hosting standards for the NHS


Draft standards under review by NHSE governance. 


These standards have been produced by the Frontline Productivity Programme and Infrastructure Centre of Excellence in NHS England to support NHS organisations. They are for all NHS organisations in England.

All standards should be considered applicable to all NHS organisations and infrastructure hosting environments.

Where relevant supporting metrics for standards are included in Appendix A: Supporting technical measures.


When to meet the standards

These standards represent ongoing requirements that NHS organisations should self-assess against annually and whenever:

  • making major changes to their infrastructure hosting environments
  • organisational changes or mergers impact ownership and responsibility for sites or infrastructure

Adherence to these standards should also be a consideration of standard business continuity and risk reviews.

Where meeting the standard is not currently possible, organisations should create and maintain a plan that outlines:

  • identified risks and impacts
  • interim mitigation measures
  • anticipated timeline for achieving the standard

Where a standard has a specific date, timeline or condition of when to meet it that differs from the above this will be highlighted within the When to meet the standard heading of the standard.

These standards provide best practice operating approaches for NHS IT infrastructure hosting solutions when designing, deploying, or managing infrastructure across all provisioning formats (cloud-based provisioning, on-premises, hybrid, Crown Hosting). The standards should be considered alongside your organisations business continuity and disaster recovery plans and requirements.

These standards do not provide detailed implementation guidance, and do not replace or supersede any existing government or industry environmental management standards.

Some responsibilities in the standards may be outsourced to third parties, such as cloud hyperscalers or Crown Hosting, however accountability for the standard remains with the NHS organisation. For example, under a cloud based or hybrid infrastructure it is expected some responsibilities of a standard will be discharged via the hyperscaler shared responsibility model (Appendix A).

In the case where third parties are relied on to comply with specific requirements, NHS organisations must establish and maintain appropriate monitoring and assurance mechanisms, including SLAs, oversight, reporting, and independent auditing and contractual safeguards to verify that outsourced activities meet the defined standards. This must be explicitly documented and enforceable within contractual arrangements to ensure that third-party performance is subject to ongoing review and remediation where necessary.


Security of Network and Information Systems Regulations (NIS Regulations) alignment

The Security of Network and Information Systems Regulations (NIS Regulations) define that An Operator of Essential Services (OES) must take appropriate and proportionate technical and organisational measures to manage risks to the security and resilience of network and information systems used to provide the essential service.”

Healthcare providers (including NHS Trusts and other organisation types) are designated as “Operators of Essential Services” under Schedule 2 of the Regulations. As such the NHS organisations networking equipment detailed in these Infrastructure Hosting Standards fall under this regulation as they are network and information systems used to provide essential services.


Last edited: 21 July 2026 12:31 pm