In this guide
What Is the DSPT and Who Needs to Complete It?
The Data Security and Protection Toolkit is an online self-assessment portal maintained by NHS England. It measures how well your organisation meets the National Data Guardian's 10 data security standards. Every organisation that accesses NHS patient data or NHS systems must complete it annually and publish the result.
The DSPT is not optional. Without a published assessment, you cannot access NHS systems, bid for NHS contracts, or maintain existing data-sharing agreements. It is the baseline security assurance mechanism for the entire health and social care system.
Who must complete it
- NHS Trusts and Foundation Trusts
- Integrated Care Boards (ICBs)
- GP practices, dental practices, opticians, pharmacies
- Social care providers (domiciliary and residential)
- Universities handling health data
- Local authorities with health or care data access
- IT suppliers — any company supplying digital software or hardware to the NHS or care sector
IT Supplier Threshold
If your company has 50+ employees AND £10m+ annual turnover AND supplies digital goods or services to the NHS, you are a Category 2 IT Supplier. This triggers a mandatory independent audit of 11 assertions. Below those thresholds, you complete a less stringent self-assessment — but completion is still required.
What Changed in Version 8
V8 was released on 1 September 2025 following a full review of evidence items, outcomes, and assertions. The changes are substantive, not cosmetic.
| Change | Impact |
|---|---|
| Senior officer must own security | A named senior officer must actively direct the security programme, not just be listed. Board-level ownership, not delegation. |
| Digital asset register mandatory | All hardware and software assets must be recorded in a formal register. Many SME suppliers have never done this. |
| Business continuity plans more prescriptive | Must include communication plans for outages (covering IT suppliers and patients) and a prioritised system recovery list. |
| Software Security Code of Practice | Category 2 organisations developing software are now advised to follow the UK Government's Software Security Code of Practice. Advisory in V8, mandatory direction of travel. |
| MFA assertion updated | Evidence item 4.5.3 for IT Suppliers and MFA has been explicitly amended. Legacy systems without MFA will struggle. |
| Independent audit codified | V8 makes the third-party audit requirement for qualifying IT suppliers unambiguous. No more grey area. |
The 10 NDG Data Security Standards
The DSPT is built on the National Data Guardian's 10 data security standards, grouped under three leadership obligations. Understanding these is essential — your evidence must map directly to them.
People (Standards 1–3)
Standard 1: Personal Data Handled Securely. All staff ensure personal confidential data is handled, stored, and transmitted securely — electronic and paper. This covers physical documents, email, removable media, and screen locking.
Standard 2: Staff Responsibility and Accountability. All staff understand their responsibilities and personal accountability for deliberate or avoidable breaches. Not just awareness — personal accountability is explicit.
Standard 3: Annual Data Security Training. All staff complete appropriate annual training and pass a mandatory test. Must be completed yearly with records kept as evidence. 100% completion required, not a sample.
Process (Standards 4–7)
Standard 4: Access Control. Personal confidential data is only accessible to staff who need it. Role-based access control, minimum-necessary access, and regular access reviews.
Standard 5: Process Improvement for Breaches. Processes are reviewed annually to identify those that caused breaches or near-misses, or that force staff to use workarounds. Near-misses must be recorded and acted on.
Standard 6: Cyber Attack Resistance. Cyber-attacks are identified and resisted. CareCERT and NCSC security advisories are responded to promptly. Includes threat detection and incident containment.
Standard 7: Business Continuity. A continuity plan is in place, covering threats to data security including significant data breaches. The plan must be tested annually — an untested plan will not pass audit.
Technology (Standards 8–10)
Standard 8: No Unsupported Systems. No unsupported operating systems, software, or internet browsers within the IT estate. End-of-life software is a hard blocker.
Standard 9: Cyber Security Strategy. A strategy is in place based on a proven framework (NCSC CAF, ISO 27001, or Cyber Essentials Plus), reviewed at least annually.
Standard 10: Accountable Suppliers. IT suppliers are held accountable via contracts for protecting personal data and meeting the NDG standards. This is the standard that creates downstream obligations — NHS organisations must flow DSPT requirements down to their vendors.
Timeline and Deadlines
| Date | Milestone | Who |
|---|---|---|
| 1 Sep 2025 | V8 toolkit opens | All organisations |
| 31 Dec 2025 | Interim baseline submission | Category 1 (CAF-track) only |
| Jan–Jun 2026 | Independent audit window | Category 2 IT Suppliers (50+/£10m+) |
| 30 Jun 2026 | Final submission deadline | All organisations |
If you have not yet submitted
The final submission deadline of 30 June 2026 has passed. If you have not submitted, treat this as urgent — engage an auditor immediately and document your remediation timeline. A late submission with a credible plan is a materially better position than no submission at all.
What IT Suppliers Must Do
Step 1: Determine your category
If you meet all three criteria — 50+ staff, £10m+ turnover, and supplying digital products/services to NHS or care — you are Category 2. This triggers a mandatory independent audit. Below the threshold, you complete a self-assessment, but it is still mandatory.
Step 2: Independent audit (Category 2)
The independent audit covers 11 mandated assertions spanning:
- Accountability and governance for data protection and security
- Identity and access management — privileged user controls, JML processes, MFA, admin account separation
- Breach and incident reporting — vulnerabilities acted on, lessons documented
- Patch management — all systems kept current
- Vulnerability management — processes to prevent disruption to essential services
- Firewall management — documented, well-managed configurations
- Supply chain management — all suppliers identified, contracts and durations tracked
- Business continuity and incident response
- Data subject rights management under UK GDPR
- Data classification and handling
- Security monitoring and logging
The auditor reviews documentation, interviews staff (technical, operational, and senior), and performs technical validation including configuration reviews and penetration testing results.
Step 3: Cyber Essentials Plus (PPN 014)
From September 2025, NHS Supply Chain adopted Government Procurement Policy Note 014 (PPN 014). This mandates Cyber Essentials Plus certification for any supplier that processes personal data or delivers IT services to the NHS. This runs in addition to the DSPT — you need both.
A valid CE+ certificate can exempt certain DSPT evidence items from re-auditing, but only where the certification scope explicitly covers your NHS-facing infrastructure. A CE+ certification scoped to corporate IT that excludes customer-facing systems provides no DSPT benefit.
Step 4: Subprocessor obligations (Standard 10 / UK GDPR Article 28)
As a data processor, you must:
- Maintain a Register of Processing Activities (RoPA)
- Have written Data Processing Agreements with every NHS controller you serve
- Contractually bind your own subprocessors to the same Article 28 obligations
- Notify NHS controllers without undue delay following any data breach
- Support controllers in responding to data subject rights requests
- Not appoint a sub-processor without prior written authorisation
- Ensure subprocessors also hold DSPT certification (or equivalent) if they handle NHS patient data
Evidence Requirements
NHS England has made clear that generic policies are no longer acceptable. Auditors look for implementation evidence — logs, screenshots, system outputs, not just written documents. If your policy says you do access reviews but you cannot produce a dated review log, you will fail.
People and training
- Per-individual training completion records (dated, with pass confirmation)
- Training completion percentage against total headcount (must be 100%)
- Onboarding training records for new starters
- Policy acknowledgement logs (signed or countersigned)
Process and governance
- Board-approved Data Security and Protection Policy (reviewed within 12 months)
- Data Protection Impact Assessments for high-risk processing
- Risk register with data security risks identified and mitigated
- Incident and near-miss log with documented lessons learned
- Business continuity plan with communication cascade and system recovery priority list
- Annual BCP test report
- ICO registration certificate
- Data Processing Agreements with all sub-processors
- Supplier register listing all third parties handling NHS data
Technology and technical
- Digital asset register — all hardware and software (new in V8)
- Software inventory confirming no unsupported/end-of-life systems
- Patch management policy and recent compliance reports
- Vulnerability scan results (internal and external)
- Penetration testing report (annually typical)
- Firewall configuration and change management records
- Access control matrix and access review evidence
- Privileged access management records
- MFA implementation evidence (screenshots, configuration exports)
- Security monitoring/SIEM logs demonstrating active alerting
- Network segmentation diagrams
- Encryption-at-rest and in-transit configuration evidence
Why Infrastructure Choice Matters for Compliance
The DSPT does not mandate a specific hosting model. But the infrastructure you choose directly affects how much evidence you can produce, how quickly you can produce it, and how many third-party dependencies your audit trail includes.
Data residency is non-negotiable
NHS England guidance is explicit: all patient data stored at rest must remain within the UK. Processing in the EU is permitted under UK GDPR, but primary storage must be UK-based with a minimum of AES-256 encryption.
This creates an immediate compliance gap for any SaaS product hosted on US-based infrastructure without explicit UK data residency controls. The US CLOUD Act can compel disclosure of data held by US companies on any infrastructure globally — including UK data centres.
The shared-responsibility gap
AWS has achieved “Standards Exceeded” on its own DSPT assessment. But this does not transfer to customers. The shared-responsibility model means you are still responsible for data configuration, access controls, and every DSPT assertion about your own environment. The hyperscaler's compliance covers their layer only.
Where self-hosted infrastructure strengthens your position
| DSPT Area | Self-Hosted | Cloud SaaS |
|---|---|---|
| Data residency | Physical location known, demonstrable | Depends on vendor config and contractual guarantees |
| Audit trail | End-to-end control, no “contact your provider” gaps | May require specific compliance tiers for full log access |
| Standard 8 (no unsupported systems) | Direct control over OS and software versions | Dependent on vendor patching timelines |
| Penetration testing | Test freely against your own infrastructure | Cloud providers restrict testing scope |
| Supply chain (Standard 10) | Shorter chain, fewer Article 28 DPAs | Every SaaS dependency adds a subprocessor |
| Vulnerability management | Direct access to all components for patching and scanning | Black-box dependencies on vendor schedules |
Cloud is not inherently incompatible with the DSPT. The requirements are UK data residency confirmed in writing, a vendor that holds their own DSPT certification covering your use case, a written DPA under Article 28, and independent evidence production capability. But self-hosted infrastructure gives you direct control over all of these — and the DSPT rewards control.
11 Mistakes That Fail Audits
1. Starting in May
Board sign-off on dated policies, training completion evidence, and audit reports cannot be backdated. Evidence must be ready by May for June board approval. Starting now (April) is already tight.
2. Not knowing your category
Discovering you are above the 50-staff/£10m threshold in April means you need an independent audit you have not booked and cannot schedule in time.
3. Vendor not DSPT-compliant
Standard 10 requires your IT suppliers and subprocessors to hold DSPT certification. Discovering a key vendor is non-compliant weeks before submission is a blocker you cannot fix quickly.
4. Policies without practice evidence
A written access review policy with no dated review log will fail. NHS England explicitly states generic policies are no longer acceptable. Auditors want system outputs, not PDFs.
5. Missing ICO registration
ICO registration is a prerequisite. First-time DSPT submitters sometimes do not hold it. This is an immediate blocker that takes days to resolve.
6. Training not at 100%
Getting every staff member — including contractors, part-time, and high-turnover roles — through annual training with documented pass records is operationally harder than it sounds.
7. No asset register
V8 makes the digital asset register explicit. Many SME IT suppliers track hardware informally and do not inventory software licences. Building this from scratch takes weeks.
8. Auditor not booked
Qualified DSPT auditors are in high demand between January and June. Booking in April risks missing the window entirely.
9. MFA on legacy systems
Evidence item 4.5.3 (MFA) is updated in V8. Retrofitting MFA onto legacy authentication is often a major infrastructure project, not a configuration change.
10. Certification scope mismatch
Holding CE+ or ISO 27001 provides exemptions only where the scope covers your NHS-facing infrastructure. Corporate IT certification that excludes customer-facing systems provides zero DSPT benefit.
11. Business continuity plan never tested
Standard 7 requires annual testing. A plan that was written and filed without a tabletop exercise or live drill will not pass. V8's more prescriptive BCP requirements make untested plans obvious.
90-Day Preparation Checklist
If you are starting now (April 2026), here is the minimum path to a credible submission by 30 June.
Weeks 1–2: Foundations
- ☐ Confirm your organisation category on dsptoolkit.nhs.uk
- ☐ Verify ICO registration is current
- ☐ Assign named senior officer for data security
- ☐ Book independent auditor (if Category 2)
- ☐ Begin digital asset register
Weeks 3–6: Evidence Gathering
- ☐ Review and update Data Security and Protection Policy
- ☐ Complete staff training and collect pass records
- ☐ Compile incident and near-miss log
- ☐ Run vulnerability scans (internal + external)
- ☐ Export access control matrix and review logs
- ☐ Document MFA implementation across all systems
- ☐ Verify all DPAs with subprocessors are current
- ☐ Complete supplier register
Weeks 7–10: Testing and Validation
- ☐ Schedule and complete business continuity test
- ☐ Commission penetration test (if not done in last 12 months)
- ☐ Complete independent audit (Category 2)
- ☐ Remediate any audit findings
- ☐ Update risk register with remediation status
Weeks 11–12: Submission
- ☐ Upload all evidence to dsptoolkit.nhs.uk
- ☐ Board review and senior officer sign-off
- ☐ Submit and publish (final deadline was 30 June 2026)