Skip to main content

Compliance Guide

NHS DSPT V8: The June 2026 Deadline Has Passed — Are You Actually Compliant?

The Data Security and Protection Toolkit Version 8 went live on 1 September 2025. If your company supplies digital products or services to the NHS, the final submission deadline was 30 June 2026 — and it has now passed. This guide covers what changed, what you need to prove, and how to avoid the mistakes that catch most suppliers still working towards compliance.

By Ben Gray · 9 April 2026 · 18 min read

The 30 June 2026 deadline has passed — are you actually compliant?

DSPT V8 Advisory — gap assessment + evidence review

From £2,500 per annual cycle. Scoped for NHS Cat 1 and Cat 2 IT suppliers.

Book a 30-min scoping call →

What Is the DSPT and Who Needs to Complete It?

The Data Security and Protection Toolkit is an online self-assessment portal maintained by NHS England. It measures how well your organisation meets the National Data Guardian's 10 data security standards. Every organisation that accesses NHS patient data or NHS systems must complete it annually and publish the result.

The DSPT is not optional. Without a published assessment, you cannot access NHS systems, bid for NHS contracts, or maintain existing data-sharing agreements. It is the baseline security assurance mechanism for the entire health and social care system.

Who must complete it

  • NHS Trusts and Foundation Trusts
  • Integrated Care Boards (ICBs)
  • GP practices, dental practices, opticians, pharmacies
  • Social care providers (domiciliary and residential)
  • Universities handling health data
  • Local authorities with health or care data access
  • IT suppliers — any company supplying digital software or hardware to the NHS or care sector

IT Supplier Threshold

If your company has 50+ employees AND £10m+ annual turnover AND supplies digital goods or services to the NHS, you are a Category 2 IT Supplier. This triggers a mandatory independent audit of 11 assertions. Below those thresholds, you complete a less stringent self-assessment — but completion is still required.

What Changed in Version 8

V8 was released on 1 September 2025 following a full review of evidence items, outcomes, and assertions. The changes are substantive, not cosmetic.

ChangeImpact
Senior officer must own securityA named senior officer must actively direct the security programme, not just be listed. Board-level ownership, not delegation.
Digital asset register mandatoryAll hardware and software assets must be recorded in a formal register. Many SME suppliers have never done this.
Business continuity plans more prescriptiveMust include communication plans for outages (covering IT suppliers and patients) and a prioritised system recovery list.
Software Security Code of PracticeCategory 2 organisations developing software are now advised to follow the UK Government's Software Security Code of Practice. Advisory in V8, mandatory direction of travel.
MFA assertion updatedEvidence item 4.5.3 for IT Suppliers and MFA has been explicitly amended. Legacy systems without MFA will struggle.
Independent audit codifiedV8 makes the third-party audit requirement for qualifying IT suppliers unambiguous. No more grey area.

The 10 NDG Data Security Standards

The DSPT is built on the National Data Guardian's 10 data security standards, grouped under three leadership obligations. Understanding these is essential — your evidence must map directly to them.

People (Standards 1–3)

Standard 1: Personal Data Handled Securely. All staff ensure personal confidential data is handled, stored, and transmitted securely — electronic and paper. This covers physical documents, email, removable media, and screen locking.

Standard 2: Staff Responsibility and Accountability. All staff understand their responsibilities and personal accountability for deliberate or avoidable breaches. Not just awareness — personal accountability is explicit.

Standard 3: Annual Data Security Training. All staff complete appropriate annual training and pass a mandatory test. Must be completed yearly with records kept as evidence. 100% completion required, not a sample.

Process (Standards 4–7)

Standard 4: Access Control. Personal confidential data is only accessible to staff who need it. Role-based access control, minimum-necessary access, and regular access reviews.

Standard 5: Process Improvement for Breaches. Processes are reviewed annually to identify those that caused breaches or near-misses, or that force staff to use workarounds. Near-misses must be recorded and acted on.

Standard 6: Cyber Attack Resistance. Cyber-attacks are identified and resisted. CareCERT and NCSC security advisories are responded to promptly. Includes threat detection and incident containment.

Standard 7: Business Continuity. A continuity plan is in place, covering threats to data security including significant data breaches. The plan must be tested annually — an untested plan will not pass audit.

Technology (Standards 8–10)

Standard 8: No Unsupported Systems. No unsupported operating systems, software, or internet browsers within the IT estate. End-of-life software is a hard blocker.

Standard 9: Cyber Security Strategy. A strategy is in place based on a proven framework (NCSC CAF, ISO 27001, or Cyber Essentials Plus), reviewed at least annually.

Standard 10: Accountable Suppliers. IT suppliers are held accountable via contracts for protecting personal data and meeting the NDG standards. This is the standard that creates downstream obligations — NHS organisations must flow DSPT requirements down to their vendors.

Timeline and Deadlines

DateMilestoneWho
1 Sep 2025V8 toolkit opensAll organisations
31 Dec 2025Interim baseline submissionCategory 1 (CAF-track) only
Jan–Jun 2026Independent audit windowCategory 2 IT Suppliers (50+/£10m+)
30 Jun 2026Final submission deadlineAll organisations

If you have not yet submitted

The final submission deadline of 30 June 2026 has passed. If you have not submitted, treat this as urgent — engage an auditor immediately and document your remediation timeline. A late submission with a credible plan is a materially better position than no submission at all.

What IT Suppliers Must Do

Step 1: Determine your category

If you meet all three criteria — 50+ staff, £10m+ turnover, and supplying digital products/services to NHS or care — you are Category 2. This triggers a mandatory independent audit. Below the threshold, you complete a self-assessment, but it is still mandatory.

Step 2: Independent audit (Category 2)

The independent audit covers 11 mandated assertions spanning:

  1. Accountability and governance for data protection and security
  2. Identity and access management — privileged user controls, JML processes, MFA, admin account separation
  3. Breach and incident reporting — vulnerabilities acted on, lessons documented
  4. Patch management — all systems kept current
  5. Vulnerability management — processes to prevent disruption to essential services
  6. Firewall management — documented, well-managed configurations
  7. Supply chain management — all suppliers identified, contracts and durations tracked
  8. Business continuity and incident response
  9. Data subject rights management under UK GDPR
  10. Data classification and handling
  11. Security monitoring and logging

The auditor reviews documentation, interviews staff (technical, operational, and senior), and performs technical validation including configuration reviews and penetration testing results.

Step 3: Cyber Essentials Plus (PPN 014)

From September 2025, NHS Supply Chain adopted Government Procurement Policy Note 014 (PPN 014). This mandates Cyber Essentials Plus certification for any supplier that processes personal data or delivers IT services to the NHS. This runs in addition to the DSPT — you need both.

A valid CE+ certificate can exempt certain DSPT evidence items from re-auditing, but only where the certification scope explicitly covers your NHS-facing infrastructure. A CE+ certification scoped to corporate IT that excludes customer-facing systems provides no DSPT benefit.

Step 4: Subprocessor obligations (Standard 10 / UK GDPR Article 28)

As a data processor, you must:

  • Maintain a Register of Processing Activities (RoPA)
  • Have written Data Processing Agreements with every NHS controller you serve
  • Contractually bind your own subprocessors to the same Article 28 obligations
  • Notify NHS controllers without undue delay following any data breach
  • Support controllers in responding to data subject rights requests
  • Not appoint a sub-processor without prior written authorisation
  • Ensure subprocessors also hold DSPT certification (or equivalent) if they handle NHS patient data

Evidence Requirements

NHS England has made clear that generic policies are no longer acceptable. Auditors look for implementation evidence — logs, screenshots, system outputs, not just written documents. If your policy says you do access reviews but you cannot produce a dated review log, you will fail.

People and training

  • Per-individual training completion records (dated, with pass confirmation)
  • Training completion percentage against total headcount (must be 100%)
  • Onboarding training records for new starters
  • Policy acknowledgement logs (signed or countersigned)

Process and governance

  • Board-approved Data Security and Protection Policy (reviewed within 12 months)
  • Data Protection Impact Assessments for high-risk processing
  • Risk register with data security risks identified and mitigated
  • Incident and near-miss log with documented lessons learned
  • Business continuity plan with communication cascade and system recovery priority list
  • Annual BCP test report
  • ICO registration certificate
  • Data Processing Agreements with all sub-processors
  • Supplier register listing all third parties handling NHS data

Technology and technical

  • Digital asset register — all hardware and software (new in V8)
  • Software inventory confirming no unsupported/end-of-life systems
  • Patch management policy and recent compliance reports
  • Vulnerability scan results (internal and external)
  • Penetration testing report (annually typical)
  • Firewall configuration and change management records
  • Access control matrix and access review evidence
  • Privileged access management records
  • MFA implementation evidence (screenshots, configuration exports)
  • Security monitoring/SIEM logs demonstrating active alerting
  • Network segmentation diagrams
  • Encryption-at-rest and in-transit configuration evidence

Why Infrastructure Choice Matters for Compliance

The DSPT does not mandate a specific hosting model. But the infrastructure you choose directly affects how much evidence you can produce, how quickly you can produce it, and how many third-party dependencies your audit trail includes.

Data residency is non-negotiable

NHS England guidance is explicit: all patient data stored at rest must remain within the UK. Processing in the EU is permitted under UK GDPR, but primary storage must be UK-based with a minimum of AES-256 encryption.

This creates an immediate compliance gap for any SaaS product hosted on US-based infrastructure without explicit UK data residency controls. The US CLOUD Act can compel disclosure of data held by US companies on any infrastructure globally — including UK data centres.

The shared-responsibility gap

AWS has achieved “Standards Exceeded” on its own DSPT assessment. But this does not transfer to customers. The shared-responsibility model means you are still responsible for data configuration, access controls, and every DSPT assertion about your own environment. The hyperscaler's compliance covers their layer only.

Where self-hosted infrastructure strengthens your position

DSPT AreaSelf-HostedCloud SaaS
Data residencyPhysical location known, demonstrableDepends on vendor config and contractual guarantees
Audit trailEnd-to-end control, no “contact your provider” gapsMay require specific compliance tiers for full log access
Standard 8 (no unsupported systems)Direct control over OS and software versionsDependent on vendor patching timelines
Penetration testingTest freely against your own infrastructureCloud providers restrict testing scope
Supply chain (Standard 10)Shorter chain, fewer Article 28 DPAsEvery SaaS dependency adds a subprocessor
Vulnerability managementDirect access to all components for patching and scanningBlack-box dependencies on vendor schedules

Cloud is not inherently incompatible with the DSPT. The requirements are UK data residency confirmed in writing, a vendor that holds their own DSPT certification covering your use case, a written DPA under Article 28, and independent evidence production capability. But self-hosted infrastructure gives you direct control over all of these — and the DSPT rewards control.

11 Mistakes That Fail Audits

1. Starting in May

Board sign-off on dated policies, training completion evidence, and audit reports cannot be backdated. Evidence must be ready by May for June board approval. Starting now (April) is already tight.

2. Not knowing your category

Discovering you are above the 50-staff/£10m threshold in April means you need an independent audit you have not booked and cannot schedule in time.

3. Vendor not DSPT-compliant

Standard 10 requires your IT suppliers and subprocessors to hold DSPT certification. Discovering a key vendor is non-compliant weeks before submission is a blocker you cannot fix quickly.

4. Policies without practice evidence

A written access review policy with no dated review log will fail. NHS England explicitly states generic policies are no longer acceptable. Auditors want system outputs, not PDFs.

5. Missing ICO registration

ICO registration is a prerequisite. First-time DSPT submitters sometimes do not hold it. This is an immediate blocker that takes days to resolve.

6. Training not at 100%

Getting every staff member — including contractors, part-time, and high-turnover roles — through annual training with documented pass records is operationally harder than it sounds.

7. No asset register

V8 makes the digital asset register explicit. Many SME IT suppliers track hardware informally and do not inventory software licences. Building this from scratch takes weeks.

8. Auditor not booked

Qualified DSPT auditors are in high demand between January and June. Booking in April risks missing the window entirely.

9. MFA on legacy systems

Evidence item 4.5.3 (MFA) is updated in V8. Retrofitting MFA onto legacy authentication is often a major infrastructure project, not a configuration change.

10. Certification scope mismatch

Holding CE+ or ISO 27001 provides exemptions only where the scope covers your NHS-facing infrastructure. Corporate IT certification that excludes customer-facing systems provides zero DSPT benefit.

11. Business continuity plan never tested

Standard 7 requires annual testing. A plan that was written and filed without a tabletop exercise or live drill will not pass. V8's more prescriptive BCP requirements make untested plans obvious.

90-Day Preparation Checklist

If you are starting now (April 2026), here is the minimum path to a credible submission by 30 June.

Weeks 1–2: Foundations

  • Confirm your organisation category on dsptoolkit.nhs.uk
  • Verify ICO registration is current
  • Assign named senior officer for data security
  • Book independent auditor (if Category 2)
  • Begin digital asset register

Weeks 3–6: Evidence Gathering

  • Review and update Data Security and Protection Policy
  • Complete staff training and collect pass records
  • Compile incident and near-miss log
  • Run vulnerability scans (internal + external)
  • Export access control matrix and review logs
  • Document MFA implementation across all systems
  • Verify all DPAs with subprocessors are current
  • Complete supplier register

Weeks 7–10: Testing and Validation

  • Schedule and complete business continuity test
  • Commission penetration test (if not done in last 12 months)
  • Complete independent audit (Category 2)
  • Remediate any audit findings
  • Update risk register with remediation status

Weeks 11–12: Submission

  • Upload all evidence to dsptoolkit.nhs.uk
  • Board review and senior officer sign-off
  • Submit and publish (final deadline was 30 June 2026)

DSPT V8 Advisory — from £2,500 per annual cycle

Gap assessment against the V8 schema, evidence review, and a remediation plan you can hand to your team or to us. Aimed at NHS Cat 1 and Cat 2 IT suppliers — the 30 June 2026 audit deadline has passed, so this is urgent for anyone who has not yet submitted.

Includes

  • · 10 NDG standard gap analysis
  • · Evidence-item walk-through
  • · Self-hosted control mapping
  • · Written remediation plan

Fits

  • · Cat 1 (CSU) — over 50 staff
  • · Cat 2 (CSU) — under 50 staff
  • · IT suppliers facing third-party audit
  • · Care groups in NHS supply chain

Doesn't fit

  • · Direct trust procurement (Wave 2)
  • · Orgs with no NHS data exposure
  • · Audits already in progress (different scope — book a call to discuss)

Pricing per the canonical matrix at /pricing. Complex or larger-scope engagements priced separately. Charity / NHS trust / state school community rates apply where eligible.

Global infrastructure·Your data, never ours·AI and infrastructure you control·GDPR by design