NHS DSPT: Data Security and Protection Toolkit Guide
The NHS Data Security and Protection Toolkit (DSPT) is the annual online self-assessment tool that enables health and social care organizations in the UK to measure and publish their performance against the National Data Guardian's 10 data security standards. Completing the DSPT to "Standards Met" status is a prerequisite for accessing NHS patient data and connecting to NHS systems. For technology suppliers, it is increasingly a commercial requirement: NHS contracts routinely specify DSPT compliance as a condition of award and renewal. With NHS cyber incidents costing the health system tens of millions of pounds annually — most visibly the 2017 WannaCry attack and the 2024 Synnovis ransomware attack — the DSPT's role as a baseline security assurance mechanism has grown considerably.
What the NHS DSPT Is and Who Issues It
The DSPT was introduced in April 2018, replacing the previous Information Governance Toolkit (IGT) that had been in use since 2003. It is jointly owned by NHS England and the Department of Health and Social Care (DHSC), and is administered through the online DSPT portal at digital.nhs.uk/dspt.
The National Data Guardian (NDG) for Health and Social Care is an independent statutory role created under the Health and Social Care (National Data Guardian) Act 2018. The NDG sets and oversees the 10 data security standards that underpin the DSPT. NHS England holds operational responsibility for the toolkit and its annual submission cycle.
For the 2025-26 assessment year, NHS England aligned the DSPT more explicitly with the Cyber Assessment Framework (CAF) published by the National Cyber Security Centre (NCSC). This alignment means organizations with existing CAF assessments — particularly those designated as operators of essential services under the Network and Information Systems (NIS) Regulations — can use CAF evidence to support their DSPT submission. The integration reflects the UK government's broader push to harmonize NHS cyber assurance with the national critical infrastructure framework.
The Care Quality Commission (CQC) takes into account DSPT performance when assessing NHS trusts and other registered providers. The NHS Standard Contract requires NHS trusts and their contracted suppliers to meet DSPT requirements as a contractual obligation.
Who Must Comply
The DSPT applies to any organization that has access to NHS patient data or connects to NHS systems. The scope is deliberately broad and covers a wide range of organization types, each with a tailored assessment pathway:
NHS Trusts and Foundation Trusts — including acute trusts, mental health trusts, community trusts, and ambulance trusts — face the most comprehensive assessment requirements. These organizations hold large volumes of patient data and are required to meet all mandatory assertions across all 10 standards.
GP Practices and Primary Care Networks (PCNs) have a streamlined assessment pathway reflecting their scale, though they must still demonstrate compliance with core data security and training requirements.
Local Authorities providing adult social care are within scope where they access NHS data or have contracted arrangements with NHS organizations. The DSPT includes a specific pathway for social care organizations.
NHS Commissioning Support Units, Integrated Care Boards (ICBs), and other commissioning bodies must complete the toolkit to demonstrate oversight of the organizations they commission.
Technology suppliers and data processors — including SaaS vendors, cloud service providers, health IT companies, and data analytics firms — that access NHS patient data or connect to NHS systems must complete the Data Security Standard for Technology Suppliers assessment pathway. For health tech companies, DSPT compliance is typically a commercial necessity before NHS contracts can be signed.
Independent healthcare providers and third-sector organizations that handle NHS patient data through contracts or data sharing agreements are expected to maintain DSPT compliance.
Organizations that do not publish a completed DSPT assessment by the annual 30 June deadline are flagged as non-compliant, which can affect NHS contract award decisions, data sharing agreements, and N3/HSCN network access.
The 10 National Data Guardian Standards in Depth
The DSPT is organized around 10 data security standards developed from the National Data Guardian's 2016 Review of Data Security, Consent, and Opt-Outs. Each standard addresses a distinct area of data security and information governance:
Standard 1: Personal Confidential Data — All staff must understand their responsibilities regarding personal confidential data. Organizations must have data flows documented and must understand what information they hold and how it moves. Mandatory assertions cover Common Law Duty of Confidentiality, Caldicott Principles, and data sharing agreements.
Standard 2: Staff Responsibilities — All staff must complete mandatory data security training annually. Staff must be aware of their personal responsibilities and the penalties for misuse of personal information. The target is 95% completion of training for all current staff.
Standard 3: Training — Training must be comprehensive and regularly updated. Organizations must evidence that training content reflects current threats and responsibilities, and that new starters complete training promptly.
Standards 4, 5, and 6: Managing Data Access and Technology — Personal confidential data must only be accessible to those with a legitimate need. Access must be managed through role-based controls, and information systems must employ appropriate protective measures. Specific requirements cover password policies, identity verification, remote access controls, and the management of privileged access.
Standard 7: Process Reviews and Incident Response — Organizations must have clear processes for identifying, reporting, and managing data security incidents. All incidents meeting the threshold for notification must be reported to the Information Commissioner's Office (ICO) within 72 hours under UK GDPR. Major incidents must also be reported to NHS England. Organizations must demonstrate that lessons from incidents are acted upon.
Standards 8 and 9: Continuity Planning — Organizations must have a business continuity and disaster recovery plan that addresses data security scenarios. Plans must be tested, documented, and updated regularly. The NHS's experience of cyber attacks has made this standard particularly prominent in recent assessment cycles.
Standard 10: Unsupported Systems — No unsupported operating systems, software, or internet browsers must be used to access NHS patient data. Organizations must maintain an inventory of all systems used to access NHS data and have migration plans for any approaching end-of-life status. This standard was introduced directly in response to the WannaCry attack, which exploited vulnerabilities in unsupported Windows XP systems used across NHS trusts.
The DSPT Assessment and Submission Process
The annual DSPT cycle runs from April 1 to June 30, with the submission deadline of June 30 each year. The process follows a structured sequence:
-
Registration and organization profile — Organizations register on the DSPT portal and complete an organizational profile that determines their assessment pathway and which assertions apply.
-
Mandatory assertions completion — Each standard contains mandatory assertions that must be answered and evidenced. Assertions are typically answered with a status of "Not Started," "In Progress," or "Completed" and require evidence uploads or declarations.
-
Evidence collection — The DSPT requires documentary evidence for many assertions. Evidence types include policies and procedures, training completion records, incident logs, system inventories, and business continuity test records. Evidence is uploaded directly to the portal.
-
Internal review and sign-off — Before publication, the assessment must be reviewed and signed off by a senior organizational lead (typically the Senior Information Risk Owner, or SIRO) and an Caldicott Guardian for clinical organizations.
-
Publication — The completed assessment is published to the DSPT portal, making the organization's status visible to NHS commissioners, partner organizations, and the public.
The achievable statuses are: Standards Met (all mandatory assertions completed satisfactorily), Standards Exceeded (for organizations that have implemented additional optional good practice assertions), and Standards Not Met (for organizations that have not completed required assertions or whose responses indicate compliance gaps).
For the 2024-25 assessment year, NHS England introduced enhanced requirements around cyber incident response planning and supply chain security, reflecting the threat environment following the Synnovis ransomware attack that disrupted blood transfusion services at King's College Hospital and other London NHS trusts in June 2024.
Costs and Timeline
| Organization Type | Typical Timeline | Estimated Cost Range |
|---|---|---|
| Technology supplier (first submission) | 2–3 months | $10,000–$30,000 |
| GP practice or small social care provider | 1–2 months | $5,000–$15,000 |
| NHS trust or large community provider | 3–6 months | $30,000–$100,000 |
| Organization requiring significant remediation | 4–6 months | $50,000–$100,000+ |
The DSPT portal itself is free to access. Implementation costs arise from gap remediation — implementing required technical controls, developing or updating policies, rolling out mandatory training, and building the evidence base. Technology suppliers that already hold ISO 27001 certification will find significant overlap with DSPT requirements, reducing the incremental implementation effort.
The cost of non-compliance can be significant: organizations that fail to publish a completed DSPT assessment risk losing NHS data access, failing contract award criteria, and facing CQC regulatory consequences. For technology suppliers, loss of DSPT compliance status can directly affect revenue from NHS contracts.
Comparison with Related Frameworks
The DSPT sits within a broader ecosystem of UK and international security and data protection frameworks:
-
UK GDPR (approximately 65% overlap): The DSPT is explicitly designed to support compliance with the UK GDPR and the Data Protection Act 2018. Data security incidents meeting the DSPT's reporting threshold typically also require ICO notification under UK GDPR. Standard 1's requirements for data flows and data sharing agreements directly reflect UK GDPR accountability obligations. Organizations that have completed UK GDPR compliance programs will find the data mapping and governance requirements of the DSPT substantially covered.
-
ISO 27001 (approximately 50% overlap): ISO 27001's information security management system controls — covering access management, incident response, business continuity, asset management, and supplier security — align closely with the DSPT's 10 standards. NHS trusts pursuing ISO 27001 certification find that the DSPT's mandatory assertions map naturally to ISO 27001 control objectives. ISO 27001-certified organizations can leverage their existing ISMS documentation as DSPT evidence.
-
Cyber Essentials / Cyber Essentials Plus (approximately 40% overlap): The UK government's Cyber Essentials scheme covers five basic security controls — boundary firewalls, secure configuration, access control, malware protection, and patch management — that directly address several DSPT Standard 10 and access management requirements. DSPT Standard 10 (no unsupported systems) aligns directly with Cyber Essentials' patch management requirement.
-
HIPAA: US health tech companies entering the UK market face both HIPAA (for US operations) and DSPT (for NHS access). The two frameworks share objectives around access controls, audit logging, incident response, and training, though their specific requirements differ. A well-designed security program can satisfy both with appropriate documentation.
-
NCSC Cyber Assessment Framework (CAF): From 2025-26, organizations covered by the NIS Regulations (including certain NHS trusts as operators of essential services) can align their DSPT submissions with CAF assessments, reducing duplicate assurance work.
How Automation Helps
The DSPT's annual submission cycle creates a recurring compliance burden: collecting evidence across 10 standards, tracking training completion percentages, managing policy review cycles, and maintaining incident logs. Compliance automation delivers measurable value:
- Automated evidence collection reduces the manual effort of gathering policy documents, training records, and system inventory information for each annual submission.
- Training management platforms track completion rates against the 95% target and generate evidence records ready for DSPT upload.
- Incident management workflows capture data security incidents, document response actions, and generate audit-ready records for Standard 7.
- Policy management tools maintain current versions of data security policies, track review dates, and flag policies approaching their review deadline.
- Supplier management workflows help NHS trusts assess their supply chain's DSPT compliance status, supporting Standard 6 requirements.
LowerPlane supports NHS DSPT compliance programs as part of its AI-powered compliance automation platform covering 50-plus frameworks including ISO 27001, HIPAA, and Cyber Essentials. At $4,000 per year starting price with a free tier available, and rated 9.4/10 on AuditXYZ, LowerPlane enables health tech companies and NHS organizations to manage evidence collection, training tracking, and audit readiness continuously rather than as a stressful annual exercise. For health technology companies building NHS-ready platforms, see /for/healthtech and /tools/compliance-automation/lowerplane.
Frequently Asked Questions
Is the DSPT mandatory for all organizations that want to work with the NHS?
Practically yes, for organizations that access NHS patient data or connect to NHS systems. The NHS Standard Contract requires contracted suppliers to maintain DSPT compliance. Data sharing agreements and N3/HSCN network access agreements also typically require a published DSPT assessment. While there is no statutory penalty for not completing the DSPT (beyond ICO enforcement for underlying UK GDPR failures), the commercial and contractual consequences of non-compliance effectively make it mandatory for health tech companies serving the NHS.
What is the difference between "Standards Met" and "Standards Exceeded"?
"Standards Met" means the organization has satisfactorily completed all mandatory assertions for its assessment type — this is the minimum requirement for NHS data access. "Standards Exceeded" means the organization has additionally completed optional good practice assertions that demonstrate a higher level of maturity. Standards Exceeded status is increasingly valued by NHS procurement teams as a differentiator, particularly for suppliers competing for sensitive or large-scale data processing contracts.
What must a technology supplier do to achieve DSPT compliance?
Technology suppliers must register on the DSPT portal under the Data Security Standard for Technology Suppliers pathway. The assessment covers how the supplier manages personal data on behalf of NHS organizations, including data processing agreements, staff training, access controls, incident response, and business continuity. Suppliers must complete all mandatory assertions and provide evidence before publishing their assessment. Many suppliers find that existing SOC 2 or ISO 27001 documentation provides a significant evidence base.
How does the 2024-25 CAF alignment affect organizations already completing the DSPT?
For organizations designated as operators of essential services under the NIS Regulations (including some NHS trusts), the 2025-26 DSPT incorporates CAF-aligned questions and allows CAF assessment evidence to be used in the DSPT submission. This reduces duplicate effort for organizations subject to both frameworks. For most other NHS organizations and suppliers, the CAF alignment introduces additional optional good practice assertions but does not change mandatory requirements.
What happens after a serious data security incident under the DSPT?
Standard 7 requires organizations to report serious incidents to NHS England's Data Security Centre and, where applicable, to the ICO under UK GDPR within 72 hours. Following an incident, the organization must document its response, identify root causes, and implement corrective actions. Incident records must be maintained and may be reviewed by NHS England, ICO, or CQC. High-profile incidents affecting large volumes of NHS patient data typically trigger formal investigations by NHS England and the ICO.