NHS DSPT: the Data Security and Protection Toolkit, explained
The Data Security and Protection Toolkit is the NHS’s annual data-security self-assessment, completed each year by every organisation with access to NHS patient data and systems. Some of those organisations are now assessed against the NCSC’s Cyber Assessment Framework; the rest answer a standards-based question set mapped to it in the background. EJN Labs is a CREST-accredited testing company and a Cyber Essentials certification body licensed by IASME, so the evidence a submission leans on can come from one UK-based team.
- Free retest of every fix
- Fixed price agreed up front
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
WHO SUBMITS
Who has to complete the DSPT
Every organisation with access to NHS patient data and systems submits every year. Which toolkit you see depends on which of four groups you are in.
NHS trusts and foundation trusts, integrated care boards, commissioning support units and DHSC arm’s length bodies complete the CAF-aligned toolkit and are independently assessed against it.
Independent providers designated operators of essential services under the NIS Regulations, and genomics organisations nominated by DHSC, joined the CAF-aligned track with the 2025-26 toolkit.
Suppliers whose systems the NHS depends on stay on the standards-based toolkit but carry its heaviest evidence set, an independent assessment, and an annual penetration testing evidence item.
GP practices, dentists, opticians, pharmacies, social care providers, local authorities and universities complete the standards-based toolkit matched to their category, with a lighter evidence set.
Category question sets and the current cycle’s documents are published on dsptoolkit.nhs.uk.
TWO TRACKS
Standards-based or CAF-aligned: which toolkit you are filling in
The DSPT now runs on two tracks, and the track decides what your evidence has to prove.
Outcome-based assessment against the NCSC’s Cyber Assessment Framework: what counts is what your controls achieve, not what your policies say. The 2025-26 toolkit, version 8, is aligned to CAF version 3.4, and NHS England has said the next version moves to CAF 4.0.
A prescriptive question set for every other category, mapped nationally in the background against a CAF profile. The framework’s expectations reach you either way; the interface just hides its language.
Under the Strengthening Assurance regime, some groups, key IT suppliers among them, have their submissions independently assessed against a mandated scope. That assessment, not the portal, is where weak evidence gets found.
Who is assessed, how the scoring works and the version 8 MFA evidence trap are in our DSPT CAF guide. The official guidance is on NHS England’s CAF-aligned DSPT pages.
THE CYCLE
Where the DSPT cycle stands right now
The toolkit is annual, and late summer sits between two versions. That makes it the cheapest time to fix what the last submission exposed.
The 2025-26 toolkit closed on 30 June 2026. Organisations that finished short of the standard are now on the improvement-plan route, with instructions issued in May 2026 for trusts, ICBs, CSUs, operators of essential services, genomics organisations, key IT suppliers, local authorities and arm’s length bodies. If that is you, assessors will want the plan’s actions closed with dated evidence, not restated.
NHS England has said the next toolkit will carry new and updated directive policies, including multi-factor authentication, high-severity alerting and endpoint detection, and will move to CAF 4.0 on a roadmap that tightens each year to 2030. Four outcomes are already forecast to expect a higher achievement level, so evidence that only just met the standard last cycle may not hold in this one.
Both halves are NHS England’s own statements: see the board assurance guidance and the forecast in the DSPT help overview.
THE EVIDENCE
What the DSPT asks for, and where we fit
Version 8 asks key IT suppliers to evidence annual penetration testing, scoped between the risk owner, the business and the testing team. For most other categories it is good practice rather than a mandatory item, and a current Cyber Essentials Plus certificate can stand in for it. The toolkit names no testing scheme; a DSPT-scoped penetration test from a CREST-accredited company is evidence assessors recognise on sight.
The toolkit treats Cyber Essentials as the kind of certification suppliers point to, and for standards-based categories a current Cyber Essentials Plus certificate, recorded in your Organisation Profile, lifts Standards Met to Standards Exceeded. EJN Labs is a certification body licensed by IASME for both Cyber Essentials and Cyber Essentials Plus, so certificate and test can come from the same team.
Different questions from the same buyer. The DSPT is your organisation’s annual data-security self-assessment; DTAC is how an NHS buyer assesses one digital product before adopting it, and its technical section asks for Cyber Essentials and, unless you have signed the NHS Cyber Security Charter, a recent independent penetration test. Our NHS DTAC service covers the engagement, and the DTAC technical security guide sets out which evidence applies.
Every engagement is quoted as a fixed price against a defined scope, agreed before any work starts. What drives the day count, and how to keep it down without weakening your evidence, is in the DSPT cost breakdown, alongside the published tiers on the pricing page.
The DSPT covers data security. If your buyer also asks about clinical safety, that is DCB0129 and DCB0160, a separate discipline with its own standards and roles.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a DSPT quote in 24 hours
A fixed-price quote back in one working day, from a named CREST-certified consultant. No sales pipeline, no chasing.
- CREST-accredited, and licensed by IASME for Cyber Essentials and Cyber Essentials Plus. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price for a defined DSPT scope, agreed up front. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one working day with a fixed-price quote from a named CREST-certified consultant.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one working day with your fixed-price quote from a named CREST-certified consultant.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one working day. Your data stays with us. No newsletter signup.
BY SECTOR
Sectors we test
Law firms
Client files and case systems.
Law firms sector pageHealthcare
Patient data and clinical systems.
Healthcare sector pageFintech
Payment flows and FCA-regulated estates.
Fintech sector pageSaaS
Multi-tenant platforms and customer APIs.
SaaS sector pagePublic sector
Testing evidence procurement teams accept.
Public sector pageInsurance
Policyholder data and underwriting platforms.
Insurance sector pageWe deliver on-site or remotely UK-wide; for the capital, see penetration testing London, or browse all sectors.
FAQ
Frequently asked questions
What is the NHS Data Security and Protection Toolkit?
The DSPT is an online self-assessment through which every organisation with access to NHS patient data and systems evidences its data security each year. NHS trusts, integrated care boards, commissioning support units, arm’s length bodies, operators of essential services and genomics organisations are assessed against the NCSC’s Cyber Assessment Framework; every other category answers a standards-based question set. It is also the route for reporting data security incidents.
Which DSPT category is my organisation in?
Every organisation with access to NHS patient data or national systems completes it. Trusts, ICBs and other NHS bodies sit on the CAF-aligned track, while GP practices, dentists, opticians, pharmacies, social care providers, local authorities, universities and IT suppliers each get a standards-based question set matched to their category. Submission is annual.
Where does a penetration test fit in the DSPT?
For key IT suppliers, version 8 carries an annual penetration testing evidence item, and a current Cyber Essentials Plus certificate can stand in for it. For most other categories testing is good practice rather than a mandatory requirement. Where you do evidence a test, it needs to be scoped to the systems your submission covers and recent enough for the cycle. Assessors also read the report itself: see what an NHS-ready penetration test report contains.
Does the DSPT require a CREST-accredited company?
No. Neither the DSPT nor DTAC names any testing scheme, CREST included. A report from a CREST-accredited company is a quality signal reviewers accept readily, which is why NHS suppliers commonly choose one, but the choice is yours, not the toolkit’s.
When is the next DSPT deadline?
The 2025-26 toolkit closed on 30 June 2026. The 2026-27 version is expected to launch around September 2026, when updated directive policies and the move to CAF 4.0 take effect, and its submission deadline will be announced with it. If you missed 30 June, the improvement-plan route is already running and is worth starting before the new cycle lands.
What is the difference between the DSPT and DTAC?
The DSPT is organisation-level and annual: it evidences how you handle data security overall. DTAC is product-level: an NHS buyer uses it to assess one digital tool before adoption, including Cyber Essentials and penetration test evidence. Many suppliers need both in the same year, and much of the same evidence pack can serve both.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a DSPT quote in 24 hours
Tell us what needs testing and a CREST-accredited UK team replies within one working day with a fixed price.



