The NHS Data Security and Protection Toolkit (DSPT) is not simply a compliance exercise. For organisations working with NHS systems, services, or patient information, it shows that the right data security arrangements are in place and maintained.
The NHS Data Security and Protection Toolkit is an online assessment that measures how well an organisation meets the National Data Guardian’s data security standards. Depending on the organisation, this can involve self-assessment, evidence submission and independent assessment.
In this blog, we’ll look at the 10 data security standards, how DSPT categories and assertions work, what evidence you may need, how independent audits fit into the process, and the common issues that can make an assessment harder than expected. We’ll also cover how to prepare for submission and what organisations can do when security weaknesses are found.
What Is the NHS Data Security and Protection Toolkit?
The NHS Data Security and Protection Toolkit (DSPT) is an online assessment used by organisations that access NHS patient data and systems to show that they are managing data security and handling personal information appropriately. NHS England provides it, and it operates within Department of Health and Social Care (DHSC) policy, involving several national bodies in its operation.
The developers built the framework around the National Data Guardian’s 10 data security standards, covering areas such as staff responsibilities, access management, incident response, continuity planning, IT protection and supplier management. For organisations covered by the CAF-aligned DSPT, the toolkit uses the National Cyber Security Centre’s Cyber Assessment Framework (CAF) as the basis for cyber security assurance and maps CAF objectives to the relevant DSPT requirements.
The current framework also includes Objective E, which focuses on using and sharing information appropriately as part of the health and care CAF approach. This is especially relevant in healthcare, where organisations need to protect confidential patient information while ensuring they can use and share it lawfully for patient care and other permitted purposes.
Who Needs to Complete the DSPT?
The DSPT applies to organisations that have access to NHS patient data and systems. This covers NHS organisations as well as a range of healthcare providers, suppliers and other organisations that handle NHS information.
For digital health technologies, the NHS DTAC may also be relevant alongside the DSPT when assessing areas such as clinical safety, data protection, technical security, interoperability and usability and accessibility.
Depending on the type of organisation and the services it provides, this can include:
- NHS Trusts and other NHS bodies that provide or manage NHS services
- Integrated Care Boards (ICBs) responsible for commissioning and coordinating local NHS services
- GP practices and Primary Care Networks (PCNs) that handle NHS patient information
- Social care providers where their work involves access to NHS information or systems
- IT suppliers, managed service providers and other technology suppliers that provide services involving NHS systems or patient data
- Third-party processors and service providers handling NHS information under an NHS contract
Not every organisation completes the same DSPT assessment. The toolkit uses different organisation types and assurance levels to determine which requirements apply. In practice, this means different sets of questions, evidence expectations and assertions depending on whether you are, for example, an NHS body, a GP practice, a social care provider, or a supplier/processor handling NHS data under contract.
This distinction matters when preparing your assessment. Rather than working from a generic DSPT checklist, an organisation should first identify its category and then review the outcomes, assertions and evidence items that apply to it.
What Changed in DSPT Version 9 (2026 – 27)?
DSPT Version 9 is the current framework for the 2026 – 27 assessment cycle, with organisations required to publish their assessment by 30 June 2027. The updated Outcomes, Assertions and Evidence items were released in September 2026.
One of the main changes is the move to CAF version 4.0 for organisations covered by the CAF-aligned DSPT. The updated version also includes changes to the Outcomes, Assertions and Evidence items, so organisations should not assume that evidence from the previous assessment cycle will cover the current requirements.
This is particularly important for organisations that have carried forward policies, records or technical evidence from Version 8. Previous evidence can still be useful, but you should check it against the Version 9 requirements and update it where needed.
For organisations preparing their 2026–27 assessment, the safest approach is to start with the current organisation type and the Version 9 Outcomes, Assertions and Evidence items that apply to it.
The definitive source for the current requirements and any changes between assessment cycles is the DSPT guidance and documentation published by NHS England.
The 10 National Data Guardian Standards Explained
The DSPT is based on 10 data security standards set by the National Data Guardian. Together, they cover how organisations protect personal confidential data, manage access, train staff, respond to incidents, protect IT systems and manage suppliers.
| National Data Guardian standard | What it covers |
| 1. Personal Confidential Data | Making sure personal confidential data is handled, stored and shared securely and only for appropriate purposes. |
| 2. Staff Responsibilities | Making sure staff understand their responsibilities when handling information and are accountable for their actions. |
| 3. Training | Ensuring staff receive the required data security training and complete the relevant assessment. |
| 4. Managing Data Access | Restrict access to personal confidential data to people who need it for their role and ensure that access can be attributed to individual users. |
| 5. Process Reviews | Reviewing processes to identify and address weaknesses that may have contributed to breaches, near misses or other data security problems. |
| 6. Responding to Incidents | Making sure cyber incidents, data breaches and near misses can be identified, reported and managed appropriately. |
| 7. Continuity Planning | Having plans to respond to threats to data security and maintain important services when something goes wrong. |
| 8. Unsupported Systems | Identifying unsupported systems, software and browsers and taking appropriate action rather than leaving them in use without support. |
| 9. IT Protection | Putting measures in place to protect IT systems from cyber threats and reviewing those arrangements regularly. |
| 10. Accountable Suppliers | Ensure that suppliers processing personal confidential data manage it appropriately and are contractually accountable for protecting it. |
These standards provide the foundation for the DSPT, but organisations do not simply answer the same checklist for all 10 areas. The specific Outcomes, Assertions and Evidence items that apply depend on the organisation type and the requirements that apply to its assessment.
DSPT Categories and Assertions Explained
Not every organisation completing the DSPT sees the same set of requirements. The toolkit uses organisation categories and organisation types to determine which questions, Outcomes, Assertions and Evidence items apply. The requirements that apply differ according to factors such as the type of organisation, the services it provides and the nature of the data it handles.
It defines requirements by organisation type (for example: NHS trusts, ICBs, CSUs, arm’s length bodies, GP practices, social care providers, pharmacies, dentists, opticians, universities, and suppliers/processors handling NHS data) and by the assurance requirements that apply to them, including the requirements for achieving a “Standards Met” outcome. Each organisation type sees a customized set of Outcomes, Assertions and Evidence items, and some types are subject to independent assessment.
The Assertions sit within the suitable DSPT requirements and help organisations show that the required security and information governance controls are in place. Evidence items are then used to support those assertions. Not every assertion or evidence item applies to every organisation, which is why identifying the correct organisation type and assurance requirements is an important first step.
For organisations using the CAF-aligned version of the DSPT, the exact CAF version in use can change between cycles; you should confirm the current CAF alignment and evidence set via the DSPT guidance for your assessment year rather than assuming a fixed version number.
How the Toolkit Works: Self-Assessment vs. Independent Audit
The DSPT starts with a self-assessment, but the process does not look the same for every organisation. The questions, evidence requirements and level of independent assurance depend on the organisation type and the requirements that apply to it.
Once the required questions and evidence items have been completed, the organisation can publish its assessment. Depending on the organisation type and the requirements that apply, the published status can include:
Requirement:
- Standards Met means the organisation has met the applicable DSPT requirements.
- Standards Exceeded means the organisation has gone beyond the requirements for Standards Met. The requirements for achieving this status vary by organisation type.
- Approaching Standards is available to eligible organisations where progress has been made, but the requirements for Standards Met have not yet been reached.
- Standards Not Met means the organisation has not met the required standard.
Independent audit provides an additional level of assurance for organisations where it is required. For certain NHS bodies and other organisation types covered by the DSPT independent assessment requirements, specific DSPT Outcomes are subject to mandatory independent security audit. The audit does not replace the DSPT self-assessment. Instead, it provides independent assurance around selected security and information governance controls and the evidence supporting them.
For 2026–27, NHS Trusts, ICBs, ALBs, CSUs, OES and Genomics organisations will audit 11 mandated Outcomes, with one additional Outcome selected by the organisation. The exact audit requirements depend on the organisation type.
This is why having a policy or completing the online assessment is not always enough. Where an audit applies, organisations must support their responses with appropriate evidence and demonstrate that they are actually maintaining the required controls.
NHS England published the DSPT independent assessment guidance, which sets out the exact organisations and outcomes subject to mandatory audit and the standard auditors that must be used.
Common Reasons Organisations Struggle to Meet DSPT Requirements
An organisation can have security policies in place and still struggle with its DSPT assessment when the controls behind those policies are not being maintained or cannot be evidenced. Some of the issues are technical, while others come down to outdated records, unclear ownership, or gaps in day-to-day processes.
Common problem areas include:
- Backups that have not been tested. Having backups is not enough if the organisation cannot show that they can be restored when needed.
- Missing or inconsistently enforced MFA. Particularly for privileged accounts, remote access, and systems containing sensitive information where stronger authentication controls are expected.
- Joiner, mover, and leaver (JML) gaps. Former staff may retain access, or permissions may not be updated when someone changes role.
- End-of-life and legacy systems. Unsupported software can leave organisations with vulnerabilities that are difficult to remediate or protect.
- Weak third-party assurance. Suppliers may access NHS information or systems without sufficient evidence that their security arrangements are being reviewed.
- Incomplete asset registers. Organisations cannot properly protect systems when they do not know they have them, particularly as they add cloud services, applications and other assets over time.
- Evidence that no longer matches the environment – policies and records may be in place, but they can become outdated when systems, suppliers, staff roles or security controls change.
These issues can make healthcare data security compliance harder to show because the organisation may have the right policy but lack current evidence that the control is working as intended.
The common thread is that DSPT preparation should not stop at collecting documents. Organisations need to check whether their controls are operating, whether they have fixed weaknesses, and whether the evidence still matches the environment they are running today.
How Cloud Infrastructure and Cybersecurity Audits Support DSPT Compliance
Policies and assessment responses can show how an organisation says it manages security, but technical testing can provide evidence of whether those controls are working as intended. This is particularly useful for organisations that need to support DSPT requirements around IT protection, access management, asset management and security testing.
A healthcare cloud infrastructure audit can review cloud configurations, identity and access controls, exposed services, storage permissions and other security settings that may affect NHS data. Vulnerability assessments can help identify weaknesses across systems and applications, while penetration testing can go further by testing whether those weaknesses can actually be exploited.
For organisations reviewing their NHS England cyber security arrangements, the important point is to connect testing back to the specific DSPT Outcomes, Assertions and Evidence items that assess. A penetration test report, for example, can provide evidence of security testing, but it does not show that the team handled identified vulnerabilities. Remediation records and retesting can provide the additional evidence needed to show what happened after the findings identified them.
Qualysec can support this part of DSPT preparation through penetration testing, vulnerability assessments, and cloud security testing. Its workflow tracks findings, remediation actions, and retests, helping security and compliance teams keep technical evidence linked to the relevant DSPT Outcomes and Evidence items.
Step-by-Step: How to Prepare for and Submit Your DSPT
Preparing for the DSPT is easier when the work is spread across the year rather than left until the submission deadline. A simple process can help you identify what needs attention, collect the right evidence, and deal with security issues before they become a problem during assessment.
Step 1: Carry Out a Gap Analysis
Start by reviewing the DSPT requirements that apply to your organisation. Compare them with your current policies, security controls, records and evidence.
Look for areas such as access management, staff training, incident response, asset management, vulnerability management and supplier assurance. Record anything that is missing, outdated or not working as expected, and give each action a clear owner.
Step 2: Collect and Check Your Evidence
Bring together the evidence needed to support your applicable Outcomes, Assertions and Evidence items. This may include policies, training records, access reviews, asset registers, incident records, supplier assessments, vulnerability reports and penetration testing reports.
Don’t just collect documents because they existed last year. Check that they are current and still match how your organisation operates.
Step 3: Review the Security Controls Internally
Before publishing the assessment, review the evidence and controls with the teams responsible for them. Check whether someone is actually maintaining important security measures.
This is a good point to review open vulnerabilities, user access, backups, unsupported systems, cloud configurations, and incident response arrangements. Where testing identifies weaknesses, make sure to assign and track them through remediation.
Step 4: Complete and Submit the Assessment
Once you have reviewed the applicable questions and evidence items, complete the DSPT assessment and confirm the required assertions. Make sure the information submitted matches your current environment before publishing the assessment.
Keep a record of the evidence used and the decisions made during the review. This makes it easier to respond if you need further assurance or clarification later.
Step 5: Prepare for Independent Audit Where Required
If your organisation must undergo independent assessment, check the applicable audit outcomes and evidence requirements well before the audit takes place.
Make sure the required records are available and that important controls can be shown, not just described in a policy. If penetration testing or other security testing has identified vulnerabilities, keep evidence showing how those findings were assessed, remediated and retested where appropriate.
Consequences of Non-Compliance
Not meeting the applicable DSPT requirements can create problems beyond the assessment itself. For organisations that depend on NHS systems, contracts or access to patient information, unresolved security and information governance issues can affect how they work with the NHS.
Potential consequences can include:
- Contractual or service-access issues – NHS contracts may include security, assurance and DSPT-related requirements. Depending on the organisation and its arrangements with the NHS, failing to meet them can create issues during contract reviews, renewals, procurement or access to certain NHS systems or services.
- Regulatory and reputational exposure – weak data security can increase the risk of incidents involving confidential patient information, which may lead to regulatory scrutiny as well as loss of trust.
The impact will depend on the organisation’s role, the requirements that apply to it and what the issue involves. This is why DSPT preparation should focus on maintaining the underlying controls and evidence, rather than treating publication of the assessment as the end of the process.
How Qualysec Helps Healthcare Organisations Achieve DSPT Compliance
Qualysec can support the technical side of DSPT preparation where organisations need independent testing or help identifying security weaknesses.
- Penetration testing to identify exploitable weaknesses across applications, networks and external-facing systems.
- Cloud security audits to review configurations, access controls and potential exposure in cloud environments.
- DSPT-aligned gap reviews to identify areas where existing security controls or evidence may not fully meet the applicable DSPT Outcomes and Evidence items.
- Remediation and retesting to track findings, verify fixes, and keep supporting security evidence together.
The aim is not to replace the DSPT self-assessment or any required independent audit. It is to give your team clearer technical evidence and a better understanding of the security issues that need attention before submission.
Conclusion
Managing the DSPT is easier when organizations treat it as an ongoing security responsibility rather than a form to complete before the deadline. Meeting the requirements depends on more than having policies in place. Your organisation needs to know what systems and data it is responsible for, whether important controls are working, and whether the evidence behind your assessment is current.
For the 2026–27 assessment, start with the Version 9 requirements that apply to your organisation type and give yourself enough time to deal with gaps before the 30 June 2027 deadline. Where technical testing finds vulnerabilities, make sure someone assigns, fixes, and retests them where appropriate.
Independent security testing, such as penetration testing, vulnerability assessments and cloud configuration reviews, can provide useful assurance around applications, networks and cloud environments. The aim is not simply to produce another report, but to give your team a clearer view of where security needs attention before the assessment.
Preparing for your next DSPT assessment? Talk to Qualysec about testing the security controls behind your evidence.
Frequently Asked Questions
1. Is DSPT mandatory for GP practices?
Yes. GP practices that have access to NHS patient data and systems are required to complete the DSPT each year. GP practice requirements in the current DSPT guidance set the specific Outcomes, Assertions, and Evidence items they must meet.
2. How often must DSPT be submitted?
The DSPT is an annual assessment. Organisations must publish their assessment by the deadline set for that cycle. For the current 2026–27 cycle, organisations must publish their assessment by 30 June 2027.
3. What’s the difference between DSPT and Cyber Essentials?
Cyber Essentials focuses on a small set of basic technical controls. These include secure configuration, boundary firewalls, access control, malware protection and patch management. These controls help protect against common cyber threats. The DSPT is broader. It covers data security and information governance across the 10 National Data Guardian standards. These include staff responsibilities, access management, incident response, continuity, suppliers and ongoing assurance. They are not substitutes for each other. However, a current Cyber Essentials Plus certification can contribute to Standards Exceeded status for some organisation types.
4. What happens if we fail our DSPT audit?
The consequences depend on the organisation type and the specific DSPT Outcomes covered by the audit. An unsuccessful independent assessment can require remediation of the affected Outcomes and may lead to further assurance or contractual action, depending on the organisation and its NHS arrangements. Organisations must fix the findings, keep evidence of remediation and, where required, undergo follow‑up audit or assurance activity.
5. Does DSPT apply to software vendors and suppliers?
It can. Organisations that process or have access to NHS patient data and systems, including IT suppliers and other service providers, may need to complete the DSPT. The exact Outcomes, Assertions and Evidence items that apply depend on the supplier’s role, the services provided and the requirements set by the NHS body they support.







