Digital Signature Service - remote signing with smartcards - coming soon

We’re making a change to the Digital Signature Service (DSS). The change relates to whether documents (i.e. EPS prescriptions) are signed ‘locally’ or ‘remotely’.

What is happening

Currently:

  • if the end user uses a smartcard to complete the ‘presence check’, prescriptions are signed ‘locally’ on the client device
  • if the end user uses any other authenticator (such as a security key or Windows Hello), prescriptions are signed ‘remotely’ on our server

The change will mean that:

  • if the end user uses a smartcard to complete the presence check, and they are using Smartcard Connect, prescriptions are signed ‘remotely’
  • if the end user uses a smartcard to complete the presence check, but they are still using the legacy Identity Agent, prescriptions are still signed ‘locally’
  • if the end user uses any other authenticator (such as a security key or Windows Hello), prescriptions are signed ‘remotely’

Over time we will be retiring the legacy Identity Agent, after which point all prescriptions will be signed remotely.

Why we’re making the change

We’re making this change to:

  • improve the user experience for smartcard users - there are fewer clicks and pop-ups with remote signing
  • make the user experience more consistent across the various authenticators
  • remove friction from signing process offering a leaner user experience
  • make it easier for us to maintain the service going forward
  • make it easier for us to respond to future security requirements
  • reduce the impact on suppliers of future changes

How it affects end users

The user experience with remote signing is better - the user still needs to enter their smartcard PIN but will do so via the CIS2 Authentication user interface, and there are fewer clicks / pop-ups than with local signing.

How it affects your software

You shouldn’t need to make any changes to your software for it to work with remote signing.

That said, the validation checks are more rigorous than with local signing, especially related to the format of the signed JWT you send for the ‘Request signatures’ operation.

Therefore, we strongly recommend you test that your software works with remote signing by using an alternative authenticator to sign a prescription in the integration environment, in preparation for ‘remote signing with smartcards’. If you use a Windows device, Windows Hello is an easy option. Otherwise, you might need to purchase a security key, such as a YubiKey. To enable an alternative authenticator for your test user in the integration environment, contact itoc.supportdesk@nhs.net.

When it is happening

This change will happen:

  • On 10 August 2026 in the integration environment
  • Later in 2026 in the production environment, subject to completion of a limited private beta

If you are currently onboarding to EPS / DSS

We don’t want to disrupt your onboarding journey. As explained below, there is a way to temporarily disable the change in the integration environment. We’re happy to discuss your options to ensure a smooth onboarding.

Changes to the assurance process and SCAL

We’ve made a small update to the SCAL (section 2.3.2) to clarify the need to test signing with both smartcards and non-smartcards. This is already mentioned but we’ve made it more explicit. We’ve also altered the wording in section 2.4 (“Sign prescriptions in bulk”) to be less smartcard-specific to reflect the wider range of authenticators.

Configuring your application in the integration environment

From 10 August 2026, the integration and production environments will behave differently. If you want to replicate the production environment exactly in the integration environment during this period, you can configure your application as follows:

  1. Sign in to your developer account.
  2. Select ‘Environment access’.
  3. Select your application (or add an application if you haven’t already got one). This must be an application in the integration test environment.
  4. Select ‘Add custom attribute’.
  5. Set the custom attribute name to ‘signingServiceCIS2_SMARTCARDlocal’ and the value to ‘TRUE’.
  6. Select ‘Add’.

You can make this change in advance of 10 August.

If you have any questions or concerns, please contact us at england.epssupport@nhs.net (if you’re already live with DSS) or england.epsonboarding@nhs.net (if you’re still onboarding).