GDPR Foundation Package Icon

DSPT Audit & Compliance Support

An independent DSPT audit gives you evidence backed assurance that your Data Security and Protection Toolkit submission will stand up to scrutiny. We assess your organisation against the Cyber Assessment Framework or the National Data Guardian's 10 data security standards, evidence every assertion and hand you a clear improvement plan. Certified UK data protection practitioners, fixed scope, no jargon.

Speak to an expert
01234 923643

Data protection expertise trusted by hundreds of organisations.
Hippodrome Casino London Logo
Rocco Forte Hotels Logo
Bedfordshire Chamber of Commerce Logo
Hippodrome Casino London Logo
Hippodrome Casino London Logo
PMDSC Logo
SwiftComm Logo
iCabbi Logo
The Kemnal Academies Trust Logo

Get a Fast DSPT Audit and Compliance Support Quote

What the Data Security and Protection Toolkit actually asks of you

The Data Security and Protection Toolkit (DSPT) is an online self assessment published by NHS England. Any organisation that accesses NHS patient data or systems has to complete it every year, and has to keep meeting the standards for the rest of the year, not just on submission day.

What you are assessed against depends on which category your organisation sits in. Larger and higher risk organisations are assessed against the National Cyber Security Centre’s Cyber Assessment Framework (CAF). Everyone else is assessed against the National Data Guardian’s 10 data security standards. For the 2025-26 assessment year the CAF route applies to Category 1 NHS organisations, Category 2 Operators of Essential Services, independent providers who are OES, and genomics organisations nominated by the Department of Health and Social Care. Category 2 key IT suppliers and Category 3 and 4 organisations continue on the non CAF DSPT.

The distinction matters more than most guidance admits. The two routes ask for different evidence in a different structure. Organisations that start collecting evidence before confirming their category routinely rebuild the whole submission in the weeks before the deadline.

In practice the DSPT is rarely a security problem. It is an evidence problem. Most organisations we work with already do the right things. What they lack is the documented proof, in the format an auditor expects, that they do them consistently.

Why organisations choose our DSPT audit

Independent audit that satisfies NHS England

Category 1 and Category 2 organisations must have their DSPT independently audited. We deliver that audit to the NHS England framework and produce a report you can upload directly to the Toolkit.

CAF or 10 standards, assessed correctly

Which route you follow depends on your category. We confirm your correct assessment path first, so you are not building evidence against the wrong framework and rewriting it.

Evidence written once, and written properly

Most failed submissions are evidence problems, not security problems. We tell you exactly which policy, log, register or screenshot proves each assertion, and flag anything that will not survive an auditor reading it.

A costed improvement plan, not a list of gaps

Where you fall short you get a prioritised improvement plan with owners and realistic dates, in the format the Toolkit expects for its improvement plan updates.

Certified practitioners, not a questionnaire

Your DSPT audit is delivered by certified privacy experts, with team qualifications including CIPP/E, CIPM, FIP and ISO 27001. You’ll work directly with a dedicated lead practitioner throughout. No ticket queues, just tailored guidance.

Who has to complete the DSPT, and which route applies

If your organisation handles NHS patient data or connects to NHS systems, the DSPT applies to you. That covers far more than NHS trusts. It reaches:

  • Independent healthcare providers and private clinics delivering NHS funded care
  • Adult social care providers, care homes and domiciliary care agencies
  • GP practices, dental practices, pharmacies and optometrists
  • Software suppliers, IT suppliers and hosting providers handling NHS data
  • Local authorities and their commissioned services
  • Research and genomics organisations working with NHS datasets

An independent audit is mandatory for Category 1 and Category 2 organisations. For everyone else it is optional, but commissioners, NHS trusts and prime contractors increasingly ask for independent assurance before they will contract with you. A DSPT status of Standards Met with nothing behind it is a weak answer in a procurement process. An audited submission is a strong one.

Submissions run on an annual cycle with a 30 June deadline, and improvement plan updates are required in between. The Toolkit now supports uploading your audit directly, so the report has to be produced in a form NHS England will accept.

What happens during a DSPT audit with us

1. Scoping and category confirmation. We establish which DSPT route applies to you, which systems and data flows are in scope, and who owns what internally. Half a day, and it prevents the most expensive mistake in the process.

2. Evidence review. We work through every assertion and evidence item in the current Toolkit version, assess what you already hold, and identify what is missing, out of date or too thin to rely on.

3. Testing and interviews. We speak to the people who actually operate your controls, not just the people who wrote the policy. Auditors look for the gap between the two, so we find it first.

4. Audit report. You receive a written report against the framework, in the format required for submission, with a clear position on each assertion and the reasoning behind it.

5. Improvement plan and handover. Prioritised actions with owners, effort and dates. We can hand this to your team, or stay on to deliver it and support the submission itself.

DSPT audit: frequently asked questions

What is a DSPT audit?

A DSPT audit is an independent assessment of your Data Security and Protection Toolkit submission, carried out by someone outside your organisation. The auditor tests whether your evidence genuinely supports each assertion you have made against the Cyber Assessment Framework or the National Data Guardian’s 10 data security standards, and reports the findings in the format NHS England requires. It is separate from the self assessment itself, which remains your organisation’s responsibility.

Is an independent DSPT audit mandatory?

It is mandatory for Category 1 and Category 2 organisations. For other categories it is not required, but it is increasingly requested by NHS commissioners and prime contractors as a condition of contract, and it is the most reliable way to know your submission would survive challenge.

What is the DSPT deadline?

The annual DSPT submission deadline is 30 June, with improvement plan updates required during the year. Because evidence gathering and remediation take time, most organisations should begin their audit at least three months before the deadline. Starting in the spring leaves no room to fix anything you find.

What is the difference between the CAF and the 10 data security standards?

The Cyber Assessment Framework is an outcomes based framework from the National Cyber Security Centre, used for larger and higher risk organisations. The National Data Guardian’s 10 data security standards are a more prescriptive set used by everyone else. For 2025-26 the CAF route covers Category 1 NHS organisations, Category 2 Operators of Essential Services, independent providers who are OES, and nominated genomics organisations. Category 2 key IT suppliers and Category 3 and 4 organisations remain on the non CAF DSPT.

We are a supplier, not a healthcare provider. Do we need the DSPT?

If you process NHS patient data or connect to NHS systems, yes. Software suppliers, IT providers and hosting companies are all in scope, and key IT suppliers sit in Category 2, where an independent audit is mandatory. Many suppliers first discover this when a trust asks for their DSPT status during procurement.

What happens if we do not meet the standards?

You publish your status honestly and submit an improvement plan setting out how and when you will close the gaps. Publishing an inaccurate Standards Met is considerably more damaging than publishing an honest improvement plan, because it will be found, either at audit or after an incident.

How does the DSPT relate to UK GDPR and ISO 27001?

The DSPT is NHS specific assurance, but it draws heavily on the same controls as UK GDPR accountability and ISO 27001. If you already hold ISO 27001 a large part of your evidence base is reusable, and we map it across rather than duplicating work. Completing the DSPT does not by itself make you UK GDPR compliant, and we will tell you where the two diverge.

Remove the risk. get it right and Contact us Today.

Phone Number
01234 923643