Cyber Horizon
Back to Blog
NHS DSPTHealthcareUK

The NHS Data Security and Protection Toolkit (DSPT): A Practical Guide

7 August 2026·7 min read·Cyber Horizon Team

If your organisation handles NHS patient data or connects to NHS systems — a trust, GP practice, social-care provider, or a supplier to any of them — you must complete the Data Security and Protection Toolkit (DSPT) every year. It’s an online self-assessment against a national standard, and for many suppliers it’s a contractual gate to working with the NHS at all.

What the DSPT is

The DSPT is an annual assessment operated by NHS England that lets organisations measure their data-security and information-governance practices. It has historically been built around the ten National Data Guardian (NDG) data-security standards, covering people, processes and technology. Completion is published, and organisations declare a status such as Standards Met or Approaching Standards.

The move to a CAF-aligned model

The DSPT has been transitioning to align with the NCSC’s Cyber Assessment Framework (CAF) — an outcome-based approach rather than a checklist. In practice that means assessors increasingly want to see that security outcomes are genuinely achieved and evidenced, not just that a policy exists. If you’ve prepared for the CAF, much of that thinking carries straight over.

The ten NDG standards, grouped

ThemeFocus
PeopleEveryone handles data responsibly; training completed; clear accountability.
ProcessPersonal data is used and shared lawfully; risks are managed; incidents are reported; continuity is planned.
TechnologySystems are protected, unsupported software is managed, and access is controlled.

Where organisations struggle

  • Evidence, not assertions — the shift to CAF-style outcomes means “we have a policy” no longer suffices; you need to show the control operating.
  • Unsupported systems — a recurring weak point; you must know what’s out of support and how the risk is managed.
  • Staff training completion — tracked, all-staff, and current, not a stale spreadsheet.
  • Supplier assurance — trusts increasingly push DSPT expectations down to their suppliers, so being a supplier means doing your own DSPT.
  • Incident reporting — knowing what must be reported to the NHS and the ICO, and being able to do it promptly.

How it fits with ISO 27001 and Cyber Essentials

The DSPT overlaps heavily with an ISO 27001 ISMS and with Cyber Essentials — the same underlying controls (access, patching, training, incident response, risk management) answer all three. Organisations with an established control library map their evidence once and reuse it across the DSPT, ISO and CE, rather than re-gathering per scheme.

Passing efficiently

  • Assign an accountable owner (often the SIRO / Caldicott Guardian context) and start well before the annual deadline.
  • Map the NDG standards / CAF outcomes to your existing controls and evidence, filling only the gaps.
  • Prioritise the perennial weak spots: unsupported systems, training completion, and demonstrable incident response.
  • Keep evidence live and dated, so next year’s DSPT is a refresh rather than a rebuild.

The bottom line

The DSPT is the NHS’s annual data-security gate, and it’s becoming outcome-based like the CAF. Build on a real control library, keep dated evidence, and the yearly assessment becomes a confirmation — not a scramble — while satisfying ISO 27001 and Cyber Essentials at the same time.

Answer the DSPT and ISO 27001 from one place

Cyber Horizon maps the NHS DSPT and CAF outcomes onto the same control library as ISO 27001 and Cyber Essentials — with evidence and training records tracked where assessors look for them.

Book a Demo