DSPT and Penetration Testing: What NHS England Checks at Toolkit Review

DSPT and Penetration Testing: What NHS England Checks at Toolkit Review

By EJN Labs · 22 Jul 2026 · 8 min read

The DSPT does not name a specific penetration test clause, but NHS England expects risk-based technical assurance behind your self-assessment, and a recent penetration test is the strongest evidence most organisations can attach. Reviewers look for scope tied to systems holding patient data, findings with remediation dates, and retest proof. Typical DSPT penetration testing runs 4 to 8 days at £1,200 to £1,400 per day, so £4,800 to £11,200.

Why DSPT penetration testing comes up at toolkit review

DSPT penetration testing comes up because the toolkit is a self-assessment, and at review the question is not whether you ticked the boxes but whether you can evidence them. Every health and care organisation handling NHS patient data must complete the Data Security and Protection Toolkit each year.

The mandate comes from NHS England as a condition of data and system access, and it extends to every supplier that connects to NHS systems.

The assertions that cause the most difficulty are the technical ones: that vulnerabilities are identified and managed, that unsupported systems are known and contained, and that the organisation has confidence in the security of the systems processing patient data. A written policy demonstrates none of that; an independent penetration test report does. Our DSPT penetration testing service page covers the service itself in full; this article focuses on the narrower question of what a reviewer actually checks and how to prepare evidence that passes first time.

Does the DSPT actually mandate a penetration test?

No, no single line in the toolkit says you must commission a penetration test. The DSPT expects credible, risk-based assurance that your technical controls work, proportionate to the sensitivity of the data you hold, and that is very hard to satisfy without independent technical testing.

The DSPT is built on the National Data Guardian’s ten data security standards, which is where its risk-based position on technical testing comes from. For an organisation processing patient records or care data, that expectation carries its full weight.

In practice, three situations turn that soft expectation into a hard one:

  • Larger organisations, including NHS trusts and arm’s length bodies, now assess against the CAF-aligned DSPT, where objectives around resilience and security validation carry a clear expectation of technical testing evidence. Suppliers moving to that model should read our page on the CAF-aligned DSPT for NHS suppliers.
  • Category 1 organisations face independent audit of their submission, and auditors routinely sample the evidence behind technical assertions.
  • Commissioners and NHS buyers increasingly ask suppliers for their latest penetration test report alongside their DSPT status during onboarding, whatever the toolkit itself says.

So the accurate answer is that the DSPT requires assurance, and a penetration test is the evidence that most reliably provides it.

What NHS England reviewers check in your evidence

Whether your submission is desk-reviewed, audited or challenged by a buyer, the same five checks come up repeatedly.

1. Scope that matches your data flows

A test of your marketing website carries no weight if patient data lives in a clinical system, a patient portal and a set of integration APIs. Reviewers compare the report’s scope statement against the systems described elsewhere in your submission; a mismatch is the most common reason evidence is rejected.

2. Independence and tester credibility

An internal vulnerability scan is useful hygiene, not independent assurance. Evidence from a CREST-accredited firm answers the credibility question before it is asked, because methodology, tester competence and reporting standards are externally certified.

3. Recency

The DSPT is an annual cycle, and evidence must reflect the current environment. A report older than twelve months, or one predating a major change such as a migration to a new clinical platform, will be questioned.

4. Findings managed, not just found

A clean report raises eyebrows; a report with findings and no remediation plan raises more. Reviewers want severity ratings, owners, target dates and, ideally, retest confirmation that high and critical issues were closed, so the toolkit’s vulnerability management assertions and your test evidence tell the same story.

5. A repeatable cycle

One-off testing looks like compliance theatre. Evidence that testing recurs annually, and after significant change, demonstrates the process the standards are really asking about; a dated schedule alongside the report closes this off neatly. Our penetration testing checklist covers how to prepare so the engagement runs cleanly.

How a DSPT-driven engagement runs

Scoping starts from your toolkit submission, not a generic asset list, mapping the assertions you need to evidence onto the systems that hold or move patient data: exposed infrastructure, patient or clinician-facing web applications, APIs integrating with NHS systems or GP software, and the cloud environment.

This is how EJN Labs scopes DSPT work. From experience, health and care estates almost always have more externally reachable services than the IG lead expects, usually legacy remote access or a forgotten integration endpoint, so we begin with external discovery before fixing the final scope.

Testing follows the standard phases of reconnaissance, vulnerability identification, controlled exploitation and post-exploitation review, performed by UK-based testers under our CREST accreditation and ISO 27001 controls. Reporting serves two audiences at once: a technical section your engineers can action, and an executive summary your CCIO or IG lead can attach directly to the toolkit as evidence. High and critical findings include a free retest, so your evidence pack shows closure rather than open risk.

Common scope components map onto our core services: external infrastructure testing for the perimeter, API penetration testing for NHS and GP system integrations, and cloud penetration testing for Azure or AWS environments hosting clinical workloads.

What DSPT penetration testing costs

Cost is driven by scope, not the framework. UK day rates for CREST-accredited testing typically run £1,200 to £1,400, and the day count depends on how many systems genuinely sit in the patient-data path:

ScopeTypical daysTypical cost
External infrastructure only2 to 3 days£2,400 to £4,200
Patient or clinician web portal4 to 6 days£4,800 to £8,400
Integration APIs3 to 5 days£3,600 to £7,000
Cloud configuration review3 to 4 days£3,600 to £5,600
Combined DSPT evidence package4 to 8 days£4,800 to £11,200

Most organisations preparing a DSPT evidence pack land in the combined range of 4 to 8 days, £4,800 to £11,200. Trimming scope to save money is a false economy, because evidence that omits a patient-data system invites exactly the reviewer challenge you are trying to avoid. For a fuller breakdown, see our guide to penetration testing costs in the UK; for an exact figure, use the quote form below.

How EJN Labs approaches DSPT evidence

EJN Labs is a UK firm holding CREST accreditation, Cyber Essentials Plus, ISO 27001 and ISO 9001, with all testing delivered by UK-based testers. For health and care clients we anchor scope to the toolkit: before testing starts we agree which assertions the report is intended to evidence, so the deliverable is usable at review without translation. We test out of hours where clinical availability demands it, and structure the report so the executive summary, findings register and retest certificate attach to your submission as-is. Where an organisation is moving to the CAF-aligned DSPT, we map findings to the relevant objectives so one engagement serves both the current and incoming model.

Frequently Asked Questions

Does the DSPT require a penetration test?

Not in a single explicit clause. The DSPT requires risk-based assurance that your technical controls protect patient data, and NHS England expects evidence behind those assertions. For most organisations handling patient data, an independent penetration test is the most credible and commonly accepted evidence.

CAF-aligned assessments and Category 1 audits make independent testing close to unavoidable.

What evidence does NHS England expect at toolkit review?

Reviewers expect five things: a test scope covering the systems that actually hold patient data, independence from the team that built them, a report less than twelve months old, findings with owners and remediation dates, and proof that high and critical issues were retested and closed.

The underlying check is that your evidence matches your submission. A dated annual testing schedule strengthens the pack further.

What does DSPT penetration testing cost?

Expect £4,800 to £11,200 for a combined DSPT evidence package covering external infrastructure, a patient-facing application and key APIs, which usually takes 4 to 8 days at UK day rates of £1,200 to £1,400 for CREST-accredited testing. Smaller scopes cost less.

External infrastructure alone is often 2 to 3 days, £2,400 to £4,200. Exact pricing depends on your estate.

When should we test relative to the DSPT deadline?

Test eight to twelve weeks before your submission deadline, which for most organisations falls at the end of June. That window leaves time to remediate high and critical findings and complete a retest, so the evidence you attach shows closed issues rather than open risk.

Work backwards from your annual publication date, and book in spring to avoid the pre-deadline rush that stretches every provider’s diary.

Do suppliers to the NHS need to complete the DSPT?

Yes. If you process NHS patient data or connect to NHS systems, completing the DSPT is a condition of that access, and commissioners check your published status. Digital health vendors, GP software suppliers and cloud or API providers all fall in scope.

Larger suppliers and those serving trusts increasingly face the CAF-aligned version, which raises the bar on technical testing evidence.

Get DSPT evidence a reviewer will accept

If your toolkit submission is due and the technical assertions need evidence behind them, we can scope a test against your patient-data systems and deliver a report built for review. Describe your estate via our CREST penetration testing quote form for a fixed scope and price within one working day.

Leave a Reply

Your email address will not be published. Required fields are marked *