If you supply the NHS, a trust may ask to see your published Data Security and Protection Toolkit assessment. If you’ve never completed one, this guide explains what it is and what you need to do.
The NHS Data Security and Protection Toolkit is an online self-assessment that every organisation with access to NHS patient data and systems has to complete each year. It checks you against the National Data Guardian’s 10 data security standards. The current 2026-27 version must be published by 30 June 2027.
The Data Security and Protection Toolkit, or DSPT, is how the NHS checks that anyone handling its patient data does so securely. Trusts and other large health organisations complete a version aligned to the Cyber Assessment Framework. GPs, pharmacies, care providers and IT suppliers complete the standard version.
Who Needs to Complete the NHS DSPT?
Any organisation that has access to NHS patient data and systems. The Toolkit’s own site says “all organisations that have access to NHS patient data and systems must use this toolkit”. That includes suppliers. Completing it is part of NHS England’s standard contract conditions, and Key IT Suppliers have extra requirements.
In practice, that includes NHS trusts, integrated care boards, GP practices, dentists, pharmacies, opticians, social care providers, local authorities, universities and the IT suppliers who work with them. Healthcare providers applying for NHSmail have to complete it too. It’s the same explanation Transputec gives its public sector clients.
Why Does It Matter If It Is a Self-Assessment?
Because the result is public, and other organisations use it. A summary of every completed NHS Data Security and Protection Toolkit assessment is published online. The certificate is also used as evidence for the CQC, commissioners, NHS partners and bids.
For the largest organisations, it isn’t only a self-assessment. NHS trusts, ICBs, CSUs, arm’s length bodies, operators of essential services and genomics organisations must also have parts of their 2026-27 assessment independently audited.
Handling NHS Data? Get the Security Work Right
Transputec's cyber security services produce NHS DSPT evidence as part of their standard monthly reporting, along with ISO 27001 and Cyber Essentials Plus evidence. Talk to our team about the security work behind your next assessment.
Get a Strategic ConsultationWhat Are the 10 Data Security Standards?
The NHS Data Security and Protection Toolkit checks you against the National Data Guardian’s 10 data security standards. They cover how staff handle data, who can access it, how incidents and continuity are managed, and how IT is protected. NHS England’s assessment guides set out each one:
| Standard | What it requires |
|---|---|
| 1. Personal confidential data | All staff ensure that personal confidential data is handled, stored and transmitted securely, whether in electronic or paper form |
| 2. Staff responsibilities | All staff must understand their responsibilities under the National Data Guardian’s Data Security Standards |
| 3. Staff training | Staff have appropriate understanding of information governance and cyber security, with an effective range of approaches taken to training and awareness |
| 4. Managing data access | Personal confidential data should only be accessible to staff who need it for their current role and access is removed as soon as it is no longer required |
| 5. Process reviews | Past security breaches and near misses are recorded and used to inform periodic workshops to identify and manage problem processes |
| 6. Responding to incidents | Cyber-attacks against services must be identified and resisted, and CareCERT security advice responded to |
| 7. Continuity planning | A continuity plan must be in place to respond to threats to data security, including significant data breaches or near misses |
| 8. Unsupported systems | No unsupported operating systems, software or internet browsers should be used within the IT estate |
| 9. IT protection | A strategy must be in place for protecting IT systems from cyber threats |
| 10. Accountable suppliers | IT suppliers must understand their obligations as data processors under the General Data Protection Regulation (GDPR) |
Standards 1 to 5 are mostly about people and processes. Standards 6, 8 and 9 are the technical ones, and they’re harder to evidence with documents alone. For example, unsupported software is either gone from the estate or it isn’t. Transputec’s vulnerability management and managed SOC services both include NHS DSPT in their compliance reporting, and that reporting is most useful for those three standards.
Which Version of the Toolkit Do You Complete?
There are two versions of the NHS Data Security and Protection Toolkit. Which one you complete depends on the type of organisation you are. For 2026-27, NHS trusts, integrated care boards, commissioning support units, arm’s length bodies, genomics organisations and independent providers designated as operators of essential services use the version aligned to the Cyber Assessment Framework (CAF) 4.0.
Everyone else uses the standard version, which is made up of assertions and evidence items. That includes IT suppliers, GPs, dentists, pharmacies, opticians, social care providers, local authorities and universities.
The CAF-aligned version moved from CAF 3.4 in 2025-26 to CAF 4.0 this year. The operators of essential services in that group are regulated under the UK’s NIS Regulations, which the Cyber Security and Resilience Bill is now reforming. We cover that in our NIS2 explainer.
How Do You Complete the NHS Data Security and Protection Toolkit?
You register, set up your organisation’s profile, answer the mandatory questions with evidence and publish by 30 June. If you’re working out how to complete the Data Security and Protection Toolkit for the first time, the process has five steps:
- Find your organisation’s ODS code and register on the Toolkit with an email address.
- Set up your organisation profile: choose your sector and add details of the main roles.
- Answer the mandatory questions and add your evidence. They’re grouped under the 10 data security standards.
- Publish the completed assessment by 30 June.
- Republish if anything important changes during the year.
Your answers from last year carry forward, but you still need to review and confirm them. Gathering the evidence usually takes longer than answering the questions.
DSPT Standards Met vs Approaching Standards: What Is the Difference?
Standards Met means you’ve met the expected level for every mandatory requirement. Approaching Standards means you haven’t yet, but you’ve shown good progress. Social care providers can use it as a one-off status. It’s also the status an organisation moves to once its improvement plan is approved.
Every NHS Data Security and Protection Toolkit assessment is published with one of four statuses:
- Standards Exceeded: for CAF-aligned organisations, this means meeting the expected achievement levels forecast for the following year. For everyone else, it means Standards Met plus a current Cyber Essentials Plus certification.
- Standards Met: every mandatory question and evidence item is completed to the expected level.
- Approaching Standards: good progress, but not yet Standards Met. Social care providers can use it once, and it’s given when an improvement plan is approved.
- Standards Not Met: the expected achievement levels haven’t been met for all outcomes. You still publish, and you submit an improvement plan.
Under the 2025-26 process, improvement plans were submitted at the point of publishing and reviewed in July and August 2026. Progress updates are due by 30 September 2026 and 31 December 2026.
When Is the DSPT Deadline?
The DSPT deadline for the 2026-27 NHS Data Security and Protection Toolkit is 30 June 2027. Version 9 was published on 8 September 2026, so you can already start work on your assessment. The previous 2025-26 deadline was 30 June 2026.
DSPT compliance is annual, and the Toolkit expects a self-assessment every year. Nine months can be less time than it sounds, because most of the work is producing evidence: training records, access reviews, incident logs and proof that nothing in the estate runs unsupported software. Transputec’s managed IT services include NHS DSPT evidence packs in their standard reporting.
Your NHS DSPT Requirements Checklist
Work through these before you open the NHS Data Security and Protection Toolkit questions.
- Confirm which version applies to you: CAF-aligned or the standard version.
- Find your ODS code and register on the Toolkit if you haven’t already.
- Add the main roles to your organisation profile.
- Match the evidence you already have to the 10 data security standards.
- Remove unsupported operating systems, software and browsers from the estate.
- Check that staff training and access reviews are recorded.
- If you’re outside the CAF group and want Standards Exceeded, keep your Cyber Essentials Plus certification current.
- Publish by 30 June 2027, and republish if anything important changes.
- If you won’t meet the standards in time, prepare an improvement plan to submit when you publish.
Conclusion
The NHS Data Security and Protection Toolkit is a self-assessment, but the results are public. Your status is published online, other organisations use it as evidence, and the largest NHS organisations have parts of their assessment independently audited. For everyone else, the main thing to get right is starting the evidence work early. Version 9 was published on 8 September 2026 and the deadline is 30 June 2027.
Transputec supports NHS DSPT compliance as a CCS-listed supplier on G-Cloud 14 and TePAS 2 (RM6098). Our cyber security services produce NHS DSPT evidence as part of their standard monthly reporting. We don’t complete or audit your assessment for you. We do the security work the standards ask for, so the evidence is there when you need it. For more on how we support health organisations, see our guide to IT support for the healthcare sector.
If a trust or commissioner has asked you a DSPT question, talk to us about the security work behind your answer.
FAQs
Who Needs to Complete the NHS DSPT?
Any organisation with access to NHS patient data and systems. That includes NHS trusts, GP practices, dentists, pharmacies, opticians, social care providers, local authorities, universities and IT suppliers. It’s part of NHS England’s standard contract conditions, and healthcare providers applying for NHSmail have to complete it too.
How Often Do You Have to Complete the DSPT?
Every year. The 2026-27 NHS Data Security and Protection Toolkit, version 9, must be published by 30 June 2027. Your answers carry forward from the previous year, but you need to review and confirm them.
DSPT Standards Met vs Approaching Standards: What Is the Difference?
Standards Met means every mandatory requirement is met. Approaching Standards means good progress, but not yet at that level. Social care providers can use it as a one-off status, and organisations move to it once their improvement plan is approved.
What Happens If You Do Not Meet the Standards?
You publish a Standards Not Met assessment and submit an improvement plan. Under the 2025-26 process, plans were submitted when organisations published and reviewed in July and August 2026. Progress updates are due by 30 September and 31 December 2026.
Does Cyber Essentials Plus Help With the DSPT?
Yes, it can. If you complete the standard version, Standards Exceeded needs Standards Met plus a current Cyber Essentials Plus certification. Transputec holds Cyber Essentials Plus itself. The DSPT standards on unsupported systems and IT protection also overlap with the Cyber Essentials controls.
This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.



