Back to Columns
ISMS & Certification11 min read

When ISMS Becomes a Condition of Trade: Hospital, Pharma and Government Procurement

September 14, 2026

When ISMS Becomes a Condition of Trade: Hospital, Pharma and Government Procurement
Share this article

When "do you hold ISMS certification?" surfaces early in a sales conversation, the thing to determine is whether it is small talk or a gate. Certification takes time and money; "let's get it just in case" is not a real plan.

Hospitals, pharmaceutical companies, and public bodies each require it for different reasons, and each words the requirement differently. Read the structure and you can judge how hard the requirement is and work backwards to what you need by when.

This article covers where the hospital requirement comes from, how it appears in pharmaceutical and public-sector procurement, the difference between mandatory and scored criteria in tenders, and what to do when you are not yet certified. For the overall picture, see What Is an ISMS (ISO/IEC 27001)?.

Disclaimer: This article is general information. Procurement and tender conditions are governed by each buying organisation's published specification and notice. Confirm eligibility against those documents and with the buyer.

Why Hospitals Ask

A hospital asking its supplier for evidence of security controls is not expressing a preference. It is discharging its own obligation.

The chain:

  1. Hospitals are expected to comply with the three-ministry guidelines (MHLW, METI, MIC) on the safe management of medical information systems
  2. The guidelines take the position that outsourcing the handling of medical information does not extinguish the hospital's responsibility
  3. The hospital must therefore confirm that its supplier operates at an equivalent standard, and keep a record of having done so
  4. The instruments for that confirmation are third-party certification and the hospital's own check sheets

Step 3 is the crux. Because responsibility does not transfer with the contract, the hospital carries an ongoing duty to understand how its supplier manages information. ISMS certification exists, from their side, as a way to compress that work dramatically.

See The Three-Ministry Guidelines, Implementation Steps for the Guidelines, and Demarcating Responsibility.

The point that matters to suppliers: the hospital's staff may have no discretion. "You have a track record, so we'll waive it this time" is often not theirs to say. Negotiating room is correspondingly thin.

How the Requirement Appears by Sector

BuyerBasis for the requirementTypical wordingRoom to negotiate
HospitalsObligations under the three-ministry guidelinesSafety management clauses in the contract, bespoke check sheets, RFP preconditionsVaries by size; large and university hospitals are firmest
Pharmaceutical companiesGlobal procurement standards, GxP-related requirements, parent company rulesVendor registration criteria, supplier assessment, MSA annexesRegistration criteria are firm; per-project sometimes flexible
Local and national governmentProcurement rules, information security policy, personal data ordinancesStated explicitly in the tender notice and specificationEssentially none after publication; pre-publication consultation is the only window
Large prime contractorsSupplier management standards, supply chain risk policyCredit and security screening at onboardingStaged compliance is sometimes accepted

With pharmaceutical companies, the commonly missed distinction is between vendor registration and project-level assessment. Where certification is a condition of appearing on the approved vendor list, no amount of per-deal negotiation moves it. Where you are already registered and the assessment is project-specific, alternatives are sometimes accepted.

Government is the clearest case. Requirements in a published tender do not change after publication. If the notice says "must hold ISO/IEC 27001 certification," an uncertified supplier cannot bid.

Mandatory versus Scored

Misreading this distinction causes the largest losses.

CategoryTypical wordingMeaningWhat to do
Mandatory (eligibility)"must hold," "shall be"Fail it and you cannot bidCertification is a precondition; otherwise pass or bid through a partner
Scored (evaluation)"points awarded where held," "desirable"You can still bid; it affects the total scoreModel whether other criteria can make up the gap
Disclosure (submission)"describe your arrangements for…"An explanation is wanted, not a certificateA check-sheet style answer suffices

"Desirable" is a scored criterion, not a mandatory one. Suppliers do pass on bids they were eligible for by misreading it. Conversely, bidding on a "must hold" requirement while arguing you have "substantially equivalent arrangements" fails at the formal eligibility check.

When in doubt, submitting a question during the notice's question period is the only reliable way to settle it. Answers are usually circulated to all bidders, but certainty is worth more.

For scored criteria, model certification cost against the probability of winning. If the points at stake are one or two percent of the total evaluation, other criteria may well cover it. See When Not to Certify and The Full Cost of ISMS Certification.

What to Do Before You Are Certified

Three workable moves.

1. Present a certification plan

Set out in writing by when, over what scope, and with which certification body you intend to certify. Showing that work has started opens room for a buyer to accept staged compliance. Evidence of a real kick-off — a signed engagement with the certification body, an internal organisation chart, records of a started risk assessment — changes how it reads. The standard timeline is about six months (ISMS Timeline).

2. Present your current arrangements as a structure

Even uncertified, if you have procedures, registers, access management, logging, and incident response, you can present them coherently. The point is presenting a document system rather than a pile of individual answers (ISMS Documentation: How Much to Build).

3. Certify a narrow scope first

Company-wide takes longer. Confining scope to the services, sites, and people relevant to the deal compresses both time and cost. But the scope is printed on the certificate and the buyer reads it — it must cover the work in question. See Defining ISMS Scope and Scope Design for Healthcare Companies.

With overseas buyers, the accreditation body can also be scrutinised (ISMS-AC, UKAS and ANAB). If you provide cloud services, 27017 and 27018 may be asked for as well (ISO 27017 and ISO 27018).

Conclusion

  1. The hospital requirement is not preference — it is the three-ministry obligation propagating to suppliers, often without staff discretion
  2. Firmness varies by sector; published government tenders are the firmest and do not change after publication
  3. Pharmaceutical buyers differ between vendor registration criteria and per-project assessment
  4. Misreading mandatory versus scored is the costliest error. "Desirable" is scored; when unsure, ask during the question period
  5. Before certification, the three moves are a credible plan, a structured presentation of current arrangements, and a narrow-scope certification
  6. Scope is printed on the certificate and read by the buyer — it must cover the work in question

Pottech supports ISMS certification with a focus on healthcare. Where certification has become a condition of a live deal, we design scope backwards from the deal's timeline and obtain competitive quotes from certification bodies. The standard programme runs about six months, with an option for accelerated delivery.

See ISMS Certification Support for scope and pricing, or contact us to discuss your situation.

References and Sources

Note: procurement and tender conditions are governed by each buying organisation's published specification and notice. The guidelines are revised periodically — always check the current edition.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.