Skip to main content

Deprecation notice: CIS1 Authentication

CIS1 Authentication was deprecated on 1 December 2023. The service will run at a reduced SLA from 1 October 2025. It will then be retired and removed from operational service by 28 February 2027.

We are updating the timelines for CIS1 Authentication depreciation given feedback from customers and suppliers on migrating to CIS2.

What we're doing

On 1 October 2025 (delayed from 1 October 2024):  

  • we will reduce the support level for the CIS1 Authentication service from Platinum to a Silver SLA

  • from speaking with suppliers, we expect the majority will have migrated to CIS2 Authentication by this time, so we will also reduce infrastructure for CIS1 as part of this including reducing platform redundancy

  • support hours will be reduced to 8am to 6pm Monday to Friday and availability targets will also be reduced 

On 1 March 2026:  

  • CIS1 will no longer have an SLA and will be supported on a 'reasonable endeavours' basis

  • costs will be reduced as much as possible by scaling down infrastructure and support to a bare bones service with little or no redundancy

By 28 February 2027, we will remove CIS1 Authentication from operational service, meaning it can no longer be used. 


Why we're doing this

We are retiring CIS1 Authentication and migrating to CIS2 Authentication to help NHS organisations take advantage of cheaper, more modern authentication methods including MFA, security keys and biometrics, as well as remove dependencies on HSCN connections.

CIS2 Authentication is also based on open standards, making it easier for suppliers to adopt changes compared to CIS1.   

As of December 2024, direct traffic through CIS1 has dropped by 54% as suppliers and NHS systems have moved across to CIS2.  All NHS England applications have all now completed the migration to CIS2 Authentication.

Progress has also been made by suppliers, but given there is still substantial use of CIS1 Authentication we are responding to concerns from customers who are worried about previously published timelines. As a result we have delayed timelines to reduce SLA to Silver and turn off CIS1 Authentication.


What this means for you

Suppliers and users of CIS1 Authentication services should switch to CIS2 Authentication now.

Suppliers must make their customers aware of a dependency on CIS1 Authentication and agree migration dates where relevant. We have contacted suppliers we are aware of that are impacted directly, throughout the deprecation period.  

If you as an NHS customer are impacted by these changes, the suppliers of your product are contractually obligated to inform you of upcoming changes. Please consult with your supplier or contact [email protected] for further information.


Previous communication


Last edited: 12 February 2025 9:23 am