Penetration Testing for DSPT: What Assessors Check When Your App Handles NHS Data

Penetration Testing for DSPT: What Assessors Check When Your App Handles NHS Data

By EJN Labs · 29 Sep 2026 · 7 min read

DSPT penetration testing is not one scripted check. DSPT is NHS England‘s self-assessment toolkit for any organisation with access to NHS patient data. If your app is classed as an NHS IT supplier, the toolkit can trigger independent assessment, and assessors typically want evidence that vulnerabilities are found and managed, most often an annual, CREST-accredited penetration test report.

Why does DSPT come up when your app handles NHS data?

DSPT comes up because your NHS customer, whether that is a trust, an integrated care board or a GP practice, itself completes the toolkit and accounts for every supplier with access to patient data. Your app inherits that obligation the moment it stores, transmits or displays anything the toolkit treats as NHS data.

Any organisation with access to NHS patient data and systems needs to complete the Data Security and Protection Toolkit (DSPT), an online self-assessment measured against the National Data Guardian’s ten data security standards. That obligation flows down contractually: if your app processes patient data on an NHS body’s behalf, its own DSPT submission depends on your evidence, not only its own systems. We have found procurement and information governance teams tend to raise this during onboarding, well before a contract is signed, rather than after go-live.

Which DSPT assurance tier applies to an app supplier?

DSPT’s independent-assessment tier covers IT suppliers, genomics organisations, OES providers and NHS bodies; every other organisation type self-assesses against the same ten standards. Your type is set at registration, and your NHS customer’s contract usually confirms which applies to you.

The 2025/26 toolkit moved to a structure aligned with NCSC’s Cyber Assessment Framework, judging evidence against outcomes rather than a fixed checklist. For an app developer this mostly changes how the evidence is written up, not what you need to gather: you are still building a case that vulnerabilities in the systems touching NHS data are found and managed. If you self-assess, there is no external assessor reviewing your submission, but a senior individual in your organisation still signs it off, so the practical bar for testing evidence rarely differs much between the two tiers.

What does DSPT’s technical protection standard expect from testing evidence?

DSPT’s technical protection standard expects evidence that vulnerabilities are found and managed; it does not name a fixed test method. In our experience, an annual, CREST-accredited penetration test is the evidence app suppliers typically submit against this standard, alongside patch records.

That distinction matters because the toolkit works by outcome, not by naming a product. In our experience, assessors treat a report showing independent, methodical testing as materially stronger evidence than an automated scan alone, since a scan cannot demonstrate that authentication, session handling and data flows have actually been exercised by a person. Some suppliers also hold a related NHS DTAC submission for the same app; where that applies, one well-scoped engagement can usually produce evidence for both.

What should a DSPT-focused penetration test cover for an app?

A DSPT-focused test should cover the app’s authentication and session handling, its API or backend, how patient data is stored and transmitted, and any third-party SDK with network access. These are the components most likely to carry a risk to NHS data.

  • Authentication and session handling. Login, token issuance and session expiry are tested for the flaws that let one user reach another patient’s records.
  • The API or backend. Most apps are thin clients over a backend API, and that is usually where patient data actually lives and where authorisation checks most often fail.
  • Data at rest and in transit. Local storage, cached responses and transport encryption are checked for anything that would expose data if a device were lost or intercepted.
  • Third-party SDKs. Analytics, crash reporting and push-notification libraries are reviewed for data they collect or transmit outside the paths your own code controls.

A mobile application penetration test covers the device-side build; the API work above is usually scoped alongside it rather than left as a separate exercise, since a DSPT submission judges the whole data path, not just the app on the device.

What does a DSPT-ready penetration test cost for an app?

A single-platform app typically costs £4,400 to £8,400 in the UK market, covering 4 to 6 days of testing. Adding the backend API or cloud configuration takes it to 6 to 9 days, £6,600 to £12,600. The quote form gives an exact, scoped price for your app.

ScopeTypical effortTypical UK cost
Single-platform app, DSPT evidence only4 to 6 days£4,400 to £8,400
App plus backend API or cloud configuration6 to 9 days£6,600 to £12,600
Retest of remediated findings1 to 2 days£1,100 to £2,800

For a wider view of how these ranges are built up across other test types, see our guide to penetration testing costs in the UK. DSPT does not set a budget or a minimum spend; NHS customers commonly want renewed evidence each year, so many app suppliers scope this as a repeatable annual engagement rather than a one-off purchase.

How EJN Labs approaches DSPT evidence for app suppliers

EJN Labs is a UK CREST-accredited penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus. All testing is carried out by UK-based testers, which matters when the systems under test hold NHS patient data and your governance lead needs to know exactly where the work happened.

When we scope this work, we start from the DSPT evidence items your organisation type has to satisfy and your app’s actual data flows, not a generic template. We map every place patient data enters, is stored by, or leaves the app, test authentication, the API and the third-party SDKs against that map, and hand back a report written so your DSPT submission, and your buyer’s due-diligence review, can lift the evidence directly. Where a finding contradicts what you expected the app to do, we set out the fix and how it affects the evidence you were planning to submit.

Frequently Asked Questions

Is CREST-accredited penetration-test evidence sufficient to satisfy NHS DSPT?

CREST-accredited penetration-test evidence is commonly accepted in a DSPT submission, alongside a remediation record showing findings were fixed and retested. DSPT does not name CREST as mandatory; it asks for evidence that vulnerabilities are managed, and a CREST-accredited report is strong evidence of that.

Does DSPT require an annual penetration test?

DSPT does not name penetration testing as mandatory; it requires evidence that vulnerabilities are found and managed under its technical protection standard. In our experience, NHS customers and DSPT assessors commonly treat an annual, CREST-accredited penetration test as the standard evidence here.

How does DSPT differ from NHS DTAC for app developers?

DSPT is an assurance toolkit your company completes annually to keep NHS access; NHS DTAC is a product-level assessment NHS buyers ask for before they commission a specific digital product. Many app suppliers need both: DSPT evidence to remain a supplier, and a DTAC submission per product.

How much does DSPT penetration testing cost for a mobile app?

A single-platform app typically costs £4,400 to £8,400 in the UK market, covering 4 to 6 days of testing. Adding the backend API or cloud configuration takes it to 6 to 9 days, £6,600 to £12,600. The quote form gives an exact, scoped price for your app.

Who has to complete DSPT as an app supplier?

Any organisation with access to NHS patient data and systems has to complete DSPT; this commonly includes app suppliers integrating with NHS systems or storing patient data for them. Which tier applies depends on your organisation type in the toolkit, which your NHS customer can usually confirm.

Get your app’s DSPT evidence scoped and priced

If your app needs DSPT-ready penetration test evidence before your NHS customer’s next submission, get a CREST pentesting quote and we will come back with a fixed scope, price and start date built around your app, its API and the data it touches.

Leave a Reply

Your email address will not be published. Required fields are marked *