NHS Cloud Migration Framework: A Practical Guide
Delaying your NHS trust’s cloud migration has a direct cost. Every month you stay on legacy infrastructure means higher maintenance spend, slower access to patient data, and increased security risk. A single major ransomware incident in the UK healthcare sector in 2025 cost over £300 million in disruption and recovery. Non-compliance with the NHS data security standards can halt projects and attract regulatory action.
But the path to cloud is not a free-for-all. The NHS cloud migration framework exists to protect patient data while enabling modernisation. This guide explains the regulatory standards you must meet, the step-by-step approach to a compliant migration, and how to choose a partner who has done it before.
Understanding the NHS Cloud Migration Landscape
The NHS is under sustained pressure to modernise its IT infrastructure. Legacy systems are expensive to maintain, difficult to scale, and increasingly vulnerable to cyber attacks. Cloud migration offers cost savings through elastic capacity, improved access to patient data for clinicians, and a platform for future innovation like AI-driven diagnostics.
But the regulatory framework is non-negotiable. Every trust and GP practice handling patient data must comply with the Data Security and Protection (DSP) Toolkit, ISO 27001, and Cyber Essentials Plus. Cloud providers must offer UK-sovereign data centres and demonstrate compliance with NHS Digital’s standards. This is not a barrier. It is a well-defined path. The organisations that treat compliance as a design requirement from the start complete their migrations faster and with fewer surprises.
Key Regulatory Frameworks for NHS Cloud Migration
The NHS cloud migration framework is built on several overlapping regulations. You need to understand how each applies to your specific workloads.
Data Security and Protection (DSP) Toolkit is the cornerstone. It is an annual self-assessment against 10 data security standards, covering things like staff training, incident response, and data encryption. Your cloud architecture must enable you to demonstrate compliance with each standard. For example, you need centralised logging to meet the monitoring and incident response requirements.
ISO 27001 certification is a common baseline. Many NHS trusts require their cloud providers and hosting partners to hold this certification. It provides an auditable information security management system.
Cyber Essentials Plus is mandatory for any supplier that handles patient data. It certifies basic cyber hygiene: firewalls, secure configuration, access control, malware protection, and patch management. Your cloud migration partner must hold this certification.
GDPR is woven into all of the above. Patient data is classified as special category data, requiring explicit consent or a lawful basis for processing. Data must be stored in the UK or European Economic Area unless adequacy decisions apply. Encryption at rest and in transit is mandatory. Key management should be separate from the cloud provider to maintain control.
The National Data Guardian has also published guidance on cloud storage and processing. It emphasises data minimisation, patient consent, and the importance of contractual safeguards with cloud providers. Your migration plan should reference this guidance directly.
Step by Step Approach to NHS Cloud Migration
A successful NHS cloud migration follows a phased approach. Rushing to move everything at once introduces unnecessary risk.
Phase 1: Discovery and audit. Inventory all existing workloads. Classify data by sensitivity (patient identifiable, operational, public). Perform a risk assessment for each workload. This phase identifies which systems are viable for cloud and in what order.
Phase 2: Select a UK-sovereign cloud provider. All major providers (AWS, Azure, GCP) operate UK regions that meet NHS sovereignty requirements. Your choice depends on existing commitments, specific service needs, and your in-house skills. We help trusts make that decision without bias towards any single platform. Our Infrastructure services cover multi-cloud architecture and vendor-neutral assessments.
Phase 3: Design the target architecture. This is where you map your DSP Toolkit controls into the cloud. Encryption strategies, access logging, network segmentation, and incident response playbooks must be built in from day one. Our cybersecurity team works alongside your architects to ensure every control is covered.
Phase 4: Pilot migration. Start with low-risk systems such as HR, finance, or back-office applications. This validates your migration process, VPC design, and data transfer mechanisms before touching clinical systems. Document everything.
Phase 5: Full migration. Clinical applications and patient databases are moved next. This requires careful cutover planning, rollback procedures, and post-migration validation of data integrity and performance. Our database migration experience covers zero-downtime approaches for SQL Server, PostgreSQL, and Oracle workloads commonly found in NHS trusts.
Phase 6: Ongoing compliance. Cloud migration is not a one-off project. You must maintain DSP Toolkit compliance annually, patch systems, review access controls, and run recovery drills. Automation through Infrastructure-as-Code (Terraform, Ansible) makes this manageable.
Data Protection and GDPR Considerations
Patient data is special category data under GDPR. This brings specific obligations that affect every cloud migration decision.
First, you must have a lawful basis for processing. For direct care, this is often consent or vital interests. For secondary uses such as research or population health, explicit consent or a legal obligation may apply. Your Data Protection Officer should be involved from Phase 1.
Second, data must stay within the UK or European Economic Area unless the ICO has an adequacy decision for the destination country. Most NHS migrations use AWS London, Azure UK South, or GCP London. Data residency is straightforward.
Third, encryption is mandatory both at rest (using AES-256) and in transit (TLS 1.2 or higher). Key management must be separated from the cloud provider. You can use a hardware security module (HSM) or a key management service with customer-managed keys. This prevents the cloud provider from accessing your data.
Fourth, you need a Data Processing Agreement (DPA) with your cloud provider that covers their obligations as a processor. Most providers have an NHS-specific DPA available.
Fifth, breach notification procedures must align with ICO requirements. Your incident response plan should include ICO notification within 72 hours for breaches likely to harm individuals. Cloud monitoring tools can automate detection and alerting.
If your trust also handles AI workloads, you may want to read our comparison of private AI vs public AI for regulated industries. The same data protection principles apply when hosting large language models in your own cloud environment.
How to Choose a Cloud Migration Partner for Your NHS Trust
Selecting the right partner is critical. Here is what to look for.
Proven experience with NHS standards. Ask for references from trusts they have migrated. Do they hold Cyber Essentials Plus? Do their engineers understand DSP Toolkit controls? We have delivered migrations for NHS bodies and other public sector organisations, always with fixed-price contracts and no hidden costs.
Hands-on technical delivery, not just reports. Some consultancies provide a strategy document and disappear. We provide the engineers who build the infrastructure, write the Terraform, run the migration, and stay for ongoing support. Our Infrastructure team is staffed by senior engineers, not account managers.
Zero-downtime migration approach. For clinical systems, downtime is not acceptable. Your partner should have a proven methodology for database migrations with no data loss. We have done this for SQL Server, Oracle, and PostgreSQL. Read about our approach in our guide on how to host an LLM in your own cloud for a related example of secure cloud deployment.
Fixed-price contracts. Avoid open-ended time-and-materials arrangements. We quote a fixed price for each phase, so you know your budget upfront.
Post-migration support. Cloud environments need patching, monitoring, and incident response. Your partner should offer managed support contracts with defined SLAs.
Frequently asked questions
What is the NHS cloud migration framework?
The NHS cloud migration framework is the set of regulatory standards, best practices, and guidance that governs how NHS organisations move their data and applications to the cloud. It includes the DSP Toolkit, ISO 27001, Cyber Essentials Plus, GDPR requirements, and specific guidance from NHS Digital and the National Data Guardian. The framework ensures that patient data remains secure and that migrations do not disrupt clinical services.
What are the main regulatory standards for NHS cloud migration?
The main regulatory standards are the Data Security and Protection (DSP) Toolkit, ISO 27001, Cyber Essentials Plus, and the UK GDPR. The DSP Toolkit is the most NHS-specific, with 10 data security standards that your cloud architecture must support. Cyber Essentials Plus is mandatory for any supplier handling patient data. ISO 27001 is a common baseline for cloud providers and hosting partners. All these standards require encryption, access controls, incident response plans, and staff training.
How long does an NHS cloud migration take?
The timeline varies significantly depending on the size of the trust and the complexity of its systems. A typical phased migration for a medium-sized acute trust can take six to twelve months from discovery to full migration. Small GP practices may complete in two to three months. The key variable is the number of clinical applications and legacy databases that need modernisation before migration.
What is a DSP Toolkit and how does it affect cloud migration?
The Data Security and Protection (DSP) Toolkit is an annual self-assessment that every NHS organisation must complete. It covers 10 data security standards, including staff training, incident response, data encryption, and supply chain security. During cloud migration, your target architecture must include controls that allow you to demonstrate compliance with each standard. For example, you need centralised audit logging to meet the monitoring requirement. Your cloud provider’s own compliance certifications (like ISO 27001) can help satisfy the supply chain standard.
Can NHS patient data be stored in the public cloud?
Yes, but with conditions. Patient data can be stored in the public cloud provided the cloud provider has UK data centres, the data remains within the UK or EEA, and you have a Data Processing Agreement in place. The cloud infrastructure must be configured to meet DSP Toolkit controls, including encryption at rest and in transit, strong access controls, and audit logging. Providers like AWS, Azure, and GCP offer dedicated UK regions and NHS-specific compliance documentation to support this.
Start your compliant NHS cloud migration today
If your NHS trust or GP practice is planning a cloud migration, we can help. Our hands-on engineers offer fixed-price consultancy with deep DSP Toolkit and NHS compliance experience. We do the discovery, design the target architecture, manage the migration, and stay for ongoing support. No account managers, no hidden costs, no lock-in.
Book a free initial consultation to audit your current setup and map a compliant migration path.