The original plan was to retire Care Identity Service authentication (aka ‘CIS1’) by September 2023, and for systems to have migrated to Care Identity Authentication (CIA, aka ‘CIS2 Authentication’).
Whilst progress has been made; it is clear that not all suppliers will complete the migration within this timeframe.
Therefore, we intend to change approach and:
- Migrate internal NHS England (previously NHS Digital) services to CIA by the original date of September 2023 as some suppliers had dependencies on us to migrate first.
- Offer suppliers an additional year to migrate to CIA, with a new retirement date of 30 September 2024
- Account for any suppliers who have not completed the migration to CIA or have not completed the rollout of their changes to all sites, by continuing to support CIS1, but at a reduced service level.
Currently both CIS1 and CIA are supported to a Platinum Plus SLA - supported hours are 24x7x365 with 99.99% availability target (max of 4 mins downtime per month)
On 30 September 2024:
- We will reduce the support level for the CIS1 authentication service to a Silver SLA.
- Operational hours will remain 24x7x365, but supported hours will be reduced to 8 am to 6 pm Monday – Friday and 99.5% availability (target max of 3.5 hours of downtime per month).
- CIA will continue to be run to Platinum Plus SLA.
On 30 September 2025:
- We will reduce the support level for CIS1 authentication service to a Bronze SLA.
- Operational hours will remain 24x7x365, but support hours will be to 8 am to 6 pm Monday - Friday and 98% availability (target max of 14.5 hours of downtime per month)
- CIA will continue to be run to Platinum Plus SLA.
Benefits of migration to CIS2 CIA
- CIA is built using common open standards such as OIDC, FIDO2 and WebAuthn which are widely used and understood within the market. This should increase the availability of relevant engineering skills, reducing time-to-market.
- CIA supports new features such as modern alternatives to smartcards, and supports access over the internet via devices other than Windows PCs
- CIA is more secure and better optimised for high availability and for the addition of new capabilities wherever demand creates a need.