Skip to main content

28 May 2026 · 3 min read

The NHS onboarding portal is two systems in a trench coat

I lost the best part of a fortnight to a single domain that secretly hosts two different onboarding systems. If you're starting NHS CIS2 supplier onboarding, this is the trap I'd warn a colleague about first.

Dr Jez McCole

UK GP · Founder, Kairos Medical Informatics

One domain, two front doors

The domain in question is onboarding.prod.api.platform.nhs.uk. If you land there through an invitation from your NHS Digital contact, you see one thing. If you land there through the self-service register a product flow, you see something entirely different. Same URL bar, same NHS branding, different underlying system.

The two front doors are:

  1. DOS Assurance. Invitation-only. Your NHS Digital contact provisions your organisation, your product, and the APIs your product is allowed to consume, and then issues you an invitation. Once accepted, you see a dashboard with your product and the Supplier Assurance Assessment questions attached to it. This is the track that hosts CIS2 Authentication.
  2. API Application. Self-service. Anyone with a Developer Portal account can go to /MyApplications and create Teams, Applications, and API keys. This is the track for eRS, PDS, EPS and the other consumer APIs. CIS2 Authentication is not on the list of APIs you can pick from here — because CIS2 doesn't live on this track at all.

How I got trapped

When my Developer Portal account activated, it landed me straight on the API Application track's home screen — no signposting, no explanation that the DOS Assurance dashboard existed. I did what any reasonable person would do: I clicked register a product, filled the form in as best I could, and picked a placeholder API from the list because CIS2 wasn't there. I assumed I'd find the CIS2 option further down the workflow.

I did not. What I'd actually done was create a parallel product record on the self-service side that my NHS Digital contact could not see from his side. He was waiting for me to accept a DOS invitation I hadn't received (it had gone to junk, and the link had since expired). I was staring at a self-service dashboard convinced I was in the right place. We went round in circles for the better part of two weeks before somebody sent a screenshot and the penny dropped.

What to do if this happens to you

  • Check your junk folder for the DOS activation email. That's where mine went. It was sent by NHS Digital when the organisation was first provisioned, and the activation link expires — usually well before you notice.
  • Ask your NHS Digital contact to reissue the invitation. Fresh link, fresh window. Do not try to reach DOS Assurance from the self-service side — you can't.
  • Ignore any placeholder product you created on the self-service side. It's orphaned. Delete it once you can see your real product on the DOS Assurance dashboard.
  • Create Applications from inside the Team page, not the personal home. Applications created from your personal home screen land under your personal account, not your Team. They can't be self-transferred and it's faster to delete and recreate from inside the Team.

Why this matters

NHS Digital knows the portal has this trap; the CIS2 team was helpful and patient once we'd worked out what had happened. But the portal UX itself doesn't signal the distinction, and it's easy for a small supplier — the kind of team that has one person doing the onboarding rather than a dedicated PMO — to waste a full sprint before realising they're knocking on the wrong door.

Kairos is a one-person operation. I don't have the luxury of losing a fortnight to a portal quirk twice. Writing this down so I don't, and so anyone else starting out has a fair chance of avoiding it.

More on CIS2 onboarding

The full working playbook — thirteen milestones, marked lived, in-flight, or not yet reached.

Open the CIS2 playbook