Skip to main content

How to set up a CIS2 smartcard workstation

CIS2 allows users to authenticate with their smartcards over a standard internet connection, without needing access to the Health and Social Care Network (HSCN).

This page is for CIS2 Authentication smartcards over a standard internet connection

For smartcards that authenticate via the Health and Social Care Network (HSCN), you'll need to set up a CIS1 smartcard workstation instead.


System requirements

Please follow the guidance in sequence. For a full list of platforms compatible with Registration Authority (RA) software, check the Warrantied Environment Specification.

All users

These are the system requirements for an optimal smartcard workstation setup:

  • Operating system: Windows 10/Windows 11 64-bit
  • Browser: Edge or Chrome
  • Smartcard reader: HID Global Omnikey 3121 USB smartcard reader

Registration Authority users 

Additional requirements for a workstation used for servicing or printing smartcards:

  • Smartcard reader: secondary HID Global Omnikey 3121 USB smartcard reader
  • Smartcard printer (optional): Magicard DoH (V2) or DoH 300 (V2) smartcard printer

Unsupported

  • Java

Downloads and setup checklist

Mandatory steps for all users

 

Additional steps for RA users

Step

Action

Item

 

Step

Action

Item

1

Check

Internet-facing domains

 

8

Connect Secondary smartcard reader

2

Check

.NET 4.8 installation

 

9

Set up Smartcard printer (optional)

3

Install

Smartcard Connect

 

10

Set up

Smartcard printer reader drivers (optional)

4

Install

Oberthur middleware

 

 

   

5

Install

Idemia PIV minidriver

 

 

 

 

6

Install

Smartcard reader drivers

 

 

7

Reboot Restart machine

 

 

 

 

Optional steps for all users

 

 

Step

Action

Item

 

 

 

 

11

Install NHS England Diagnostic Tool

 

 

 

 


Mandatory steps

1. Internet-facing domains

To be able to access the newer, internet-facing parts of the Care Identity Service, the user will need to be able to access certain domains. There are also considerations for anyone using a web proxy or VPN.

Read our guidance for IT teams on allowing domains.

2. Check for installation of .NET 4.8

This is a mandatory requirement for setting up a workstation. Windows 10 does not install the older versions of .NET by default, but you cannot proceed without it. To check/install it:

  • open Control Panel
  • go to Programs > Programs and Features
  • on the left, choose 'Turn Windows features on or off'
  • check the box for .NET 4.8

Dot NET 3.5 settings window

3. Install NHS Smartcard Connect

Follow the supporting documentation for installing and configuring NHS Smartcard Connect, which also includes troubleshooting guidance for common issues.

4. Install Oberthur middleware

Oberthur middleware is a mandatory installation for all machines.

5. Install Idemia PIV minidriver

This is required for interacting with series 9 smartcards.

The Idemia PIV minidriver is installed automatically via Windows Update (If enabled). If automatic Windows Update is disabled, you can install the middleware manually.

6. Install the correct smartcard reader drivers

Download the manufacturer drivers for the NHS supported 3121 readers. To support all variants of the Omnikey 3121 smartcard reader, it is recommended to install both the HID Omnikey CCID and HID Global X-Chip driver (BU component). If you are using other smartcard readers to login with, install the manufacturer drivers for those smartcard readers. Find out how to update drivers for other smartcard readers.

7. Reboot the computer

Restart the machine to complete the setup process.


Additional steps for Registration Authority users only

You only need to complete these extra steps if you are Registration Authority users - check whether this is you.

8. Connect secondary smartcard reader

RA users who carry out smartcard management services will need to connect a secondary smartcard reader.

They also need to check and verify that the correct drivers are assigned to the secondary smartcard reader (see step 7).

9. Smartcard printer installation (optional)

See guidance on how to install smartcard printers.

We recommend you do not use an Omnikey 5321CR Contactless reader on a machine which has a Magicard DoH (V2) Printer (5x21 Reader) connected to it.

10. Check smartcard printer reader drivers

Check and verify that the correct drivers are assigned to the printer in-built smartcard readers.


Optional steps

11. NHS England Diagnostic Tool

The NHS England Diagnostic Tool comes as a standalone tool without an installer. It is designed to provide an easy method for support teams to gather information about the configuration of a user's computer. Providing a diagnostic log file is recommended when raising incidents involving Smartcard Connect or card management services in Care Identity Management.


Notes for RA users

You will need to complete the additional steps for Registration Authority users if you carry out any of the actions in the table below.

Registration Authority role

Issue, print and manage smartcards

Renew all certificates

Renew expiring certificates

Unlock smartcards

Registration Authority manager

Y

Y

Y

Y

Registration Authority agent / advanced agent

Y

Y

Y

Y

Sponsor

 

 

Y

Y

Local smartcard administrator

 

 

Y

Y

Important notes:

  • Registration Authority users must be logged in with their smartcard to perform card management services, as other authenticators do not support these operations.
  • It is not recommended to use an Omnikey 5321CR contactless reader on a machine which has a Magicard DoH (V2) Printer (5x21 Reader) connected to it.

IA Registry Editor

As smartcard authentication via CIS2 uses Smartcard Connect, there's no need to use the IA Registry Editor.


Troubleshooting

If you're having problems or need more help, go to our troubleshooting area.

Last edited: 20 August 2025 1:54 pm