DSPT Audit & Compliance Support
Speak to an expert
01234 923643









Get a Fast DSPT Audit and Compliance Support Quote
Why organisations choose our DSPT audit
DSPT audit: frequently asked questions
What is a DSPT audit?
A DSPT audit is an independent assessment of your Data Security and Protection Toolkit submission, carried out by someone outside your organisation. The auditor tests whether your evidence genuinely supports each assertion you have made against the Cyber Assessment Framework or the National Data Guardian’s 10 data security standards, and reports the findings in the format NHS England requires. It is separate from the self assessment itself, which remains your organisation’s responsibility.
Is an independent DSPT audit mandatory?
It is mandatory for Category 1 and Category 2 organisations. For other categories it is not required, but it is increasingly requested by NHS commissioners and prime contractors as a condition of contract, and it is the most reliable way to know your submission would survive challenge.
What is the DSPT deadline?
The annual DSPT submission deadline is 30 June, with improvement plan updates required during the year. Because evidence gathering and remediation take time, most organisations should begin their audit at least three months before the deadline. Starting in the spring leaves no room to fix anything you find.
What is the difference between the CAF and the 10 data security standards?
The Cyber Assessment Framework is an outcomes based framework from the National Cyber Security Centre, used for larger and higher risk organisations. The National Data Guardian’s 10 data security standards are a more prescriptive set used by everyone else. For 2025-26 the CAF route covers Category 1 NHS organisations, Category 2 Operators of Essential Services, independent providers who are OES, and nominated genomics organisations. Category 2 key IT suppliers and Category 3 and 4 organisations remain on the non CAF DSPT.
We are a supplier, not a healthcare provider. Do we need the DSPT?
If you process NHS patient data or connect to NHS systems, yes. Software suppliers, IT providers and hosting companies are all in scope, and key IT suppliers sit in Category 2, where an independent audit is mandatory. Many suppliers first discover this when a trust asks for their DSPT status during procurement.
What happens if we do not meet the standards?
You publish your status honestly and submit an improvement plan setting out how and when you will close the gaps. Publishing an inaccurate Standards Met is considerably more damaging than publishing an honest improvement plan, because it will be found, either at audit or after an incident.
How does the DSPT relate to UK GDPR and ISO 27001?
The DSPT is NHS specific assurance, but it draws heavily on the same controls as UK GDPR accountability and ISO 27001. If you already hold ISO 27001 a large part of your evidence base is reusable, and we map it across rather than duplicating work. Completing the DSPT does not by itself make you UK GDPR compliant, and we will tell you where the two diverge.
Remove the risk. get it right and Contact us Today.
Phone Number
01234 923643
Email Address
enquiries@privacyhelper.co.uk