Cloud compliance gaps for NHS and education suppliers
Suppliers to the NHS, schools, colleges and universities may be asked to explain how they protect accounts, devices, cloud services and personal or sensitive information. The exact obligations depend on the organisation, service, data and contract. A cloud security tool can provide useful evidence, but it cannot decide which requirements apply or make a supplier compliant on its own.
Common gaps that slow down assurance
Unclear scope and ownership
Teams may not know which systems, subcontractors, users or data flows support a particular public service. A control can be in place but have no named owner or review date.
Review and improve: map the service, information, cloud accounts, tenants and suppliers in scope. Assign an accountable owner for each key control and agree how changes are approved.
Identity controls that are uneven
MFA may be enabled for some users but not privileged, emergency or service accounts. Administrators may use everyday accounts, and joiner, mover and leaver processes may not be evidenced.
Review and improve: check identity policies and actual sign-in coverage, protect privileged access, document exceptions, and test account removal and recovery procedures.
Device, patching and configuration evidence is incomplete
Policies may describe an update process without showing which devices and workloads are covered, what is overdue, or how exceptions are handled.
Review and improve: reconcile device and cloud inventories, document patch responsibilities and timelines, and retain records of exceptions and follow-up. Map controls to the framework or contract rather than assuming one report satisfies every assessor.
Logging and incident processes are not demonstrated
Logging may be enabled but not retained centrally, reviewed, or linked to a tested incident response process. Small teams can also be unsure who is contacted outside office hours.
Review and improve: identify events needed to investigate relevant services, check retention and access restrictions, nominate alert owners and exercise the escalation process.
Backups exist, but recovery has not been tested
A backup status can show that a job ran; it does not prove that critical data can be restored within the organisation's recovery expectations.
Review and improve: identify critical services, define recovery objectives with service owners and test restoration. Record the result, issues and actions.
Evidence is stale, scattered or inconsistent
Questionnaire answers, policies, screenshots and technical exports can refer to different dates, systems or control owners.
Review and improve: maintain a single evidence index with the source, scope, owner, collection date and review date for each item. Redact sensitive information before sharing it with customers or assessors.
Use cloud tools to support the review—not replace it
Cloud-native security services and CNAPP platforms can help surface configuration, identity, vulnerability and exposure findings. Depending on the provider and licensed capability, tools such as Microsoft Defender for Cloud, Google Cloud security services, Wiz or Palo Alto Networks Prisma Cloud can contribute technical evidence.
Use those findings to support a control review:
- Confirm the account, tenant, workload and time period represented.
- Validate important findings with the control owner.
- Map evidence to the relevant assertion, contract or customer question.
- Record gaps the tool cannot assess, such as staff processes, supplier arrangements or tested recovery.
- Track fixes and re-test the control after implementation.
Do not upload patient, student or other sensitive data to a security platform or share detailed evidence without confirming the organisation's data-handling and access requirements.
A sensible readiness sequence
- Confirm the service, contractual requirements and assessment scope.
- Map information, systems, cloud accounts, users and suppliers.
- Review technical controls and the evidence supporting them.
- Prioritise gaps based on risk to the service and the requirement.
- Agree owners and a remediation plan with realistic dates.
- Retest fixes and maintain evidence for future assurance cycles.
We can help review cloud and identity controls, organise evidence and prepare a prioritised remediation plan. Formal certification or assessment decisions remain with the relevant independent body or authority. Explore our framework support or public sector services.