DSPT Is Now CAF-Aligned: What NHS Suppliers Must Do Before 30 June 2026

DSPT Is Now CAF-Aligned: What NHS Suppliers Must Do Before 30 June 2026

By EJN Labs · 15 Jun 2026 · 10 min read

DSPT CAF means the NHS Data Security and Protection Toolkit now follows the NCSC Cyber Assessment Framework, an outcome-based model where you evidence that controls work rather than ticking boxes. Category 2 IT suppliers and OES or genomics organisations face an independent assessment, with the report and submission due by 30 June 2026, and the CAF outcomes expect an annual penetration test.

If you sell software to the NHS or process NHS patient data, your annual DSPT return has changed shape. The move to DSPT CAF replaced the old checklist with the NCSC Cyber Assessment Framework, which asks for evidence that your security actually holds up. This guide explains what the realignment changes, who now faces an independent audit, the annual penetration test the CAF outcomes imply, and how to have the evidence ready for the next submission window on 30 June 2026. For the full service view, see our DSPT penetration testing page.

What DSPT CAF actually means

DSPT CAF is the realignment of the Data Security and Protection Toolkit, NHS England‘s annual self-assessment for any organisation handling NHS patient data, to the NCSC Cyber Assessment Framework. Instead of a yes or no checklist, version 8 scores you as Not Achieved, Partially Achieved or Achieved against an NHS England profile.

For years the toolkit worked as a tick-box exercise: you asserted that a control existed and moved on. The Cyber Assessment Framework is the outcome-based model the NCSC uses for organisations performing essential functions, and version 8 of the toolkit, published on 18 September 2025, scores you against its contributing outcomes.

The practical difference is the burden of proof. Under the old toolkit you could claim a control was in place. Under the CAF-aligned model you have to demonstrate, with evidence, that the control is working. Two of the CAF outcomes in particular, around testing and vulnerability management, are very hard to satisfy on paper alone. They are the reason this realignment matters to a software supplier, and the reason an independent penetration test has become the natural evidence to produce.

Who now faces an independent assessment

The CAF realignment has rolled out in stages by organisation type, and not everyone faces the same obligation. The headline change for suppliers is the introduction of an independent assessment for a defined group.

  • The largest NHS organisations (Trusts and Foundation Trusts, Integrated Care Boards, CSUs and DHSC arm’s-length bodies) moved to the CAF-aligned DSPT first, from the 2024-25 cycle.
  • Category 2 IT suppliers carry the heavier obligation. These are commercial IT suppliers that process or access NHS patient data or connect to national NHS systems, and they now undergo an independent assessment rather than pure self-assessment.
  • Operators of Essential Services and genomics organisations were brought into the CAF-aligned model with version 8 from September 2025, alongside the same independent-assessment route.
  • Social care and smaller organisations follow a lighter-touch path that is migrating more gradually.

If you are a Category 2 IT supplier, this is the change that affects you most. An external assessor reviews your evidence rather than taking your word for it, and the independent assessments for the current cycle run across the first half of 2026, with the report and submission due by 30 June 2026. That date is the next submission window in an annual cycle, not a one-off cliff edge, but the assessment takes weeks to scope, run and remediate, so the time to start is well ahead of it.

The annual penetration test the CAF expects

The CAF outcomes do not contain a line that reads “buy a penetration test”, in the same way the framework never names a specific tool. What they do is set outcomes that, in practice, you cannot evidence without independent technical testing. The two that matter most to a supplier are the testing and vulnerability-management outcomes. For the OES and genomics profiles, outcome B4.d on vulnerability management is explicit, and the wider DSPT guidance points the same way.

NHS DSPT guidance (Guide 9, on IT protection) calls for penetration testing at least annually, scoped to web servers, vulnerability scans and critical network infrastructure, and it recommends using a CREST-approved member company with testers qualified under recognised schemes. Read alongside the CAF outcomes, the message is consistent: an annual, independent test by an accredited provider, with evidence that you act on the findings, is what assessors look for. This is an expectation set by the outcomes and the guidance, not a verbatim statutory rule, but for a Category 2 supplier facing an independent assessment it is the difference between an Achieved and a Partially Achieved outcome.

From the testing we deliver for UK suppliers, the report that satisfies a DSPT assessor has a recognisable shape. It scopes the live solution rather than a token sample, it maps findings to the OWASP Top 10, it scores every issue with CVSS so severity is consistent, and it carries a clear remediation narrative with a retest confirming that the serious findings were actually closed. An assessor reading that report can see exactly what was tested, what was found and what was fixed, which is precisely what the CAF outcome-based model is asking you to show.

The MFA evidence trap in DSPT v8

One change in DSPT v8 catches suppliers out, so it is worth naming directly. In earlier versions, holding Cyber Essentials Plus was accepted as covering the multi-factor authentication requirement. That shortcut has gone. In version 8, evidence item 4.5.3 can no longer be satisfied by “we hold CE Plus” alone. You now have to evidence MFA separately, covering remote and privileged access, even where your CE Plus certificate is current and valid.

Cyber Essentials Plus remains strong supporting evidence and a baseline expectation, and it overlaps usefully with the CAF technical outcomes. It is simply no longer a one-stop answer to the MFA item. The practical implication is that your DSPT evidence pack should pair a current Cyber Essentials or Cyber Essentials Plus certificate with a standalone MFA evidence set, then sit both alongside your penetration test report and remediation trail. Treating those as three separate artefacts, rather than assuming one certificate covers everything, is the cleanest way through version 8.

Building your DSPT CAF evidence pack

You can reduce the realignment to a short list of artefacts an assessor wants to see. Assembling them in advance, rather than during the submission week, is what keeps the 30 June 2026 window calm.

  • An annual penetration test report covering your applications, APIs and external infrastructure, OWASP-mapped and CVSS-scored, delivered by a CREST-approved provider.
  • Vulnerability management evidence that shows you find and fix issues on an ongoing basis, mapping to the CAF testing and B4.d vulnerability-management outcomes.
  • A current Cyber Essentials or Cyber Essentials Plus certificate, validated against the IASME database, at a scope that covers your NHS data-processing environment.
  • A standalone MFA evidence pack for remote and privileged access, to satisfy DSPT v8 item 4.5.3 in its own right.
  • A retest or remediation confirmation showing that Critical and High findings from the test were closed, not just logged.

The DSPT is the annual, organisation-level assurance your company completes. It sits alongside, and overlaps with, the NHS DTAC, which is the product-level assessment a buyer applies before adopting your software. DTAC is required in practice to sell to the NHS rather than legally mandatory, and its technical-security section leans on the same evidence: a current Cyber Essentials certificate and a recent penetration test. If you are mapping both at once, our selling software to the NHS security checklist walks through the full assurance picture, and our DCB0129 and DCB0160 explained guide covers the adjacent clinical-safety standards, which are a separate discipline from the cyber-security evidence we provide.

Why EJN Labs for DSPT CAF readiness

The DSPT CAF model rewards suppliers who can produce technical-security evidence from one coherent engagement, and that is exactly where EJN Labs sits. We are a CREST member for penetration testing, which is the accreditation NHS buyers and DSPT assessors recognise, and the same quality signal Guide 9 points organisations towards. Every test is delivered by senior and principal testers based in the UK, never junior staff, so the report your assessor reads reflects examined competence and a real understanding of how NHS suppliers are assessed.

We also cover the certification side under one roof. Through our IASME relationship we assess and certify Cyber Essentials and Cyber Essentials Plus directly, and we are ISO 27001 and ISO 9001 certified ourselves, so we understand the outcome-based assurance model from the inside as well as from the tester’s chair. That means one engagement can produce the penetration test, the Cyber Essentials evidence and a clear remediation trail, with honest advice on where standalone MFA evidence is needed for DSPT v8 item 4.5.3. Our remit is the technical-security evidence the CAF-aligned DSPT outcomes depend on, written so it drops straight into your submission. For the wider healthcare picture, see our healthcare penetration testing service.

Frequently Asked Questions

What does DSPT CAF mean?

DSPT CAF means the NHS Data Security and Protection Toolkit has been realigned to the NCSC Cyber Assessment Framework, an outcome-based model. Rather than ticking a box to assert that a control exists, you evidence that the control works, and each is scored Not Achieved, Partially Achieved or Achieved against an NHS England profile.

Version 8 of the toolkit, published on 18 September 2025, runs on this model.

Does the CAF-aligned DSPT require a penetration test?

In practice yes for most suppliers, although no single verbatim rule requires it. The CAF testing and vulnerability-management outcomes, together with DSPT Guide 9, expect an independent penetration test at least annually by a CREST-approved provider, scoped to your applications and critical infrastructure.

For a Category 2 IT supplier facing an independent assessment, that test is usually the difference between an Achieved and a Partially Achieved outcome.

Who has to submit by 30 June 2026?

Category 2 IT suppliers, Operators of Essential Services and genomics organisations must submit by 30 June 2026, with the independent assessment report due by the same date. The independent assessments for the current cycle run across the first half of 2026.

This is the next window in an annual cycle rather than a one-off deadline, but the assessment takes time to scope, run and remediate, so it pays to start well ahead.

Does Cyber Essentials Plus still cover the DSPT MFA requirement?

No, not on its own. In DSPT version 8, evidence item 4.5.3 can no longer be satisfied by holding Cyber Essentials Plus alone. You now have to evidence multi-factor authentication separately, and that evidence must cover both remote access and privileged access.

Cyber Essentials Plus remains valuable supporting evidence and a baseline expectation, but you should pair it with a standalone MFA evidence pack.

How does the DSPT relate to NHS DTAC?

The DSPT is the annual, organisation-level assurance your company completes for handling NHS patient data, while NHS DTAC is the product-level assessment a buyer applies before adopting your software. DTAC is required in practice to sell to the NHS rather than legally mandatory, and the two overlap on security evidence.

Both increasingly expect a current Cyber Essentials certificate and a recent independent penetration test. We support suppliers with the technical-security evidence for both.

Get your DSPT CAF evidence ready

The CAF-aligned DSPT expects evidence that your security works, and for Category 2 suppliers facing an independent assessment that means an annual penetration test, current Cyber Essentials and a standalone MFA pack, ready for the 30 June 2026 submission window. To get a fixed scope and price delivered by senior, CREST-certified UK testers, request a penetration testing quote, or read our full DSPT penetration testing service guide first. Price is driven by the complexity of your scope in tester days, and the quote form is the route to an exact, scoped figure.

Leave a Reply

Your email address will not be published. Required fields are marked *