top of page

The DSPT Version Guide: Standards-Based to CAF-Aligned

  • Jul 2
  • 9 min read



What Is the DSPT?


The Data Security and Protection Toolkit (DSPT) is NHS England's annual online self-assessment that enables organisations to measure and demonstrate their compliance with the National Data Guardian's data security standards. It is a key assurance mechanism used across the health and care sector to assess how organisations protect sensitive information and manage cybersecurity, information governance, and data protection risks.

The DSPT is completed by NHS organisations, social care providers, digital health companies, healthcare technology suppliers, and other businesses that access, process, store, or support NHS health and care data. It is often a contractual or procurement requirement for organisations seeking to supply products or services to the NHS.


Upon completion, organisations receive a published assessment outcome, typically demonstrating that standards have been met or exceeded. Certain organisations, including larger suppliers meeting defined workforce and revenue thresholds, are also required to obtain independent assurance over their DSPT submission as part of NHS England's assurance framework.


The DSPT has evolved significantly since its introduction, reflecting changes in cyber threats, regulatory expectations, NHS procurement requirements, and the increasing digitisation of health and care services. This guide explores how the framework has developed over time and what those changes mean for organisations completing the DSPT today.




How the DSPT Has Evolved


The Data Security and Protection Toolkit (DSPT) was introduced in 2018 as the successor to the Information Governance (IG) Toolkit, reflecting a shift from a predominantly information governance-focused framework towards a broader assessment of data security, cyber resilience, and organisational accountability. Since then, the DSPT has become the principal assurance mechanism used across the health and care sector to demonstrate compliance with the National Data Guardian's data security standards.

The DSPT operates on an annual cycle. Each assessment year, NHS England reopens the toolkit with updated requirements, guidance, and evidence expectations that reflect evolving risks, regulatory developments, and national policy priorities. Organisations are required to review and resubmit their assessment annually rather than relying on previous submissions.

A significant milestone in the DSPT's evolution was the publication of the Cyber Security Strategy for Health and Social Care: 2023 to 2030. This strategy accelerated the move away from purely compliance-focused assessments towards outcome-based assurance. Rather than simply demonstrating that policies and controls exist, organisations are increasingly expected to show that security measures are effective, proportionate, and capable of reducing real-world cyber risk.

This shift has driven greater alignment between the DSPT and the National Cyber Security Centre's Cyber Assessment Framework (CAF). Historically, the DSPT was primarily standards-based, focusing on whether specific requirements had been met. Increasingly, however, the framework is incorporating CAF principles that assess organisational outcomes, security effectiveness, and operational resilience. Understanding the differences between these standards-based and CAF-aligned approaches is essential to understanding how the DSPT continues to evolve and what organisations can expect from future assessment cycles.




Standards-Based vs CAF-Aligned DSPT


Since its introduction, the DSPT has evolved from a predominantly compliance-focused assessment towards a broader emphasis on cybersecurity resilience and organisational accountability. This reflects wider developments across the health and care sector, where assurance is increasingly focused not only on whether controls exist, but also on whether they are effective in protecting sensitive information and supporting operational resilience.


Historically, the DSPT has been structured around the National Data Guardian's 10 Data Security Standards. Under this approach, organisations demonstrate compliance by providing evidence against defined requirements and assertions. Assessment is largely based on whether specific policies, procedures, controls, and governance activities can be evidenced and shown to meet the relevant standard.


More recently, NHS England has increasingly drawn on principles found within the National Cyber Security Centre's Cyber Assessment Framework (CAF). The CAF takes a more outcome-focused approach to cybersecurity, placing greater emphasis on how effectively organisations identify, manage, and respond to cyber risk. Rather than focusing solely on the existence of controls, the emphasis shifts towards demonstrating that security measures are delivering the intended outcomes.

This evolution reflects a broader trend across cybersecurity regulation and assurance frameworks. Organisations are increasingly expected to demonstrate not only compliance, but also resilience, risk awareness, and continuous improvement in their security posture.


Importantly, the core purpose of the DSPT remains unchanged. Organisations are still required to demonstrate that they meet the relevant data security and protection requirements applicable to their role within the health and care ecosystem. The familiar "Standards Met" outcome remains the principal assurance indicator relied upon by NHS organisations, procurement teams, and other stakeholders. Information governance, data protection, and confidentiality obligations also continue to form a central part of the framework alongside cybersecurity requirements.


For suppliers to the NHS, the DSPT remains an evidence-based assurance framework. However, understanding the increasing influence of outcome-focused cybersecurity models helps explain the direction of travel and the growing emphasis on demonstrating effective security practices rather than simply documenting compliance activities.




Inside the CAF-Aligned DSPT


The CAF-aligned DSPT adopts the structure of the National Cyber Security Centre's Cyber Assessment Framework (CAF) while incorporating additional requirements specific to health and care organisations. The framework is organised around five high-level objectives that together assess an organisation's ability to manage cyber risk and protect sensitive information.


Objective A: Managing Security Risk focuses on governance, risk management, asset management, and supply-chain security.


Objective B: Protecting Against Cyber Attack examines the controls used to prevent and resist cyber threats, including access management, secure configuration, vulnerability management, and user awareness.


Objective C: Detecting Cyber Security Events assesses an organisation's ability to identify suspicious activity, monitor systems, and detect security incidents in a timely manner.


Objective D: Minimising the Impact of Cyber Security Incidents considers incident response, business continuity, recovery capabilities, and organisational resilience.


Objective E: Using and Sharing Information contains health and care-specific requirements relating to information governance, data protection, confidentiality, and the lawful handling of information.


Together, these objectives are supported by 47 contributing outcomes. Of these, 39 are derived from the core Cyber Assessment Framework, with a further 8 outcomes included to address health and care-specific information governance requirements. Each outcome describes a security or governance objective that organisations are expected to achieve.


Achievement Levels


Assessment is based on three achievement levels:


  • Not Achieved - the outcome is not being met or significant weaknesses exist.

  • Partially Achieved - some elements of the outcome are being met, but gaps remain.

  • Achieved - the organisation can demonstrate that the outcome is being met to the required standard.


Assessment is supported by a series of Indicators of Good Practice (IGPs), which provide examples of the controls, processes, behaviours, and evidence that may demonstrate achievement. Importantly, organisations are not assessed solely on whether specific controls exist. The emphasis is on whether the intended outcome has been achieved.


To attain a "Standards Met" outcome, organisations must achieve the minimum performance level specified for each applicable outcome. This creates a more outcome-focused approach to assurance, encouraging organisations to demonstrate effective security practices rather than simply evidencing compliance activities.




Which DSPT Version Applies to You?


One of the most important changes to the DSPT in recent years has been the introduction of different assessment models for different types of organisation. The version of the DSPT you complete depends on how NHS England categorises your organisation and the level of cyber risk associated with your role within the health and care ecosystem.


Large NHS organisations, including NHS trusts, integrated care boards (ICBs), commissioning support units (CSUs), and Department of Health and Social Care arm's-length bodies, transitioned to the CAF-aligned DSPT from September 2024. This reflects the increasing focus on cyber resilience and outcome-based assurance within critical health and care infrastructure.


The CAF-aligned approach has subsequently been extended to additional high-impact organisations. From September 2025, operators of essential services and certain genomics organisations moved to the CAF-aligned model, reflecting their importance to the delivery of health and care services and the potential consequences of cyber disruption.


For most IT suppliers, digital health companies, software providers, medical device manufacturers, and smaller health and care organisations, the standards-based DSPT remains the primary assessment route. These organisations continue to demonstrate compliance through defined assertions and evidence requirements aligned to the National Data Guardian's data security standards. However, expectations around cyber resilience, assurance, and evidence quality continue to increase, meaning suppliers should expect ongoing evolution of assessment requirements over time.


Assessment requirements are also influenced by NHS England's organisation category framework. Organisations are assigned to different categories based on factors such as their role, size, access to health and care data, and the services they provide. These categories help determine which assertions apply, the scope of assessment activities, and whether independent assurance or audit requirements apply to the organisation's DSPT submission.


Understanding which version of the DSPT applies to your organisation is therefore an important first step in planning compliance activities and ensuring that the correct evidence, governance arrangements, and assurance processes are in place.




Key DSPT Dates and Deadlines


The DSPT operates on an annual assessment cycle, with organisations required to review, update, and submit their assessment each year. The published submission deadline is currently always June 30th. Organisations should always check the latest NHS England DSPT guidance for the current assessment year, as requirements, evidence expectations, and assurance obligations may change between versions.


Although the final deadline is in June, DSPT compliance should not be treated as a last-minute exercise. Evidence gathering, policy review, training records, incident management documentation, supplier assurance, technical controls, and independent audit activities can all take time to complete.


The toolkit typically reopens each year with updated assertions, guidance, and evidence requirements. Early preparation helps organisations identify gaps, implement improvements, and obtain any required independent assurance before submission.


Missing the DSPT deadline can create significant commercial and operational risk. Depending on contractual obligations, non-compliance may affect access to NHS data or systems, delay procurement activity, create issues with NHS customers, or put contract awards and renewals at risk.




What the Changes Mean for IT Suppliers


For most IT suppliers, digital health companies, SaaS providers, and medical device manufacturers, the standards-based DSPT remains the primary route to demonstrating compliance with NHS data security and protection requirements. However, the direction of travel is clear. As NHS England increasingly adopts principles drawn from the Cyber Assessment Framework (CAF), suppliers should expect greater scrutiny of how security controls operate in practice, not simply whether supporting documentation exists.


This does not mean that suppliers need to complete the CAF-aligned DSPT today. It does mean that organisations should focus on building demonstrable security maturity, effective governance, and robust evidence that can withstand increasing levels of assurance and due diligence. NHS buyers are placing growing emphasis on resilience, risk management, incident response, supplier assurance, and leadership accountability alongside traditional compliance requirements.


Many suppliers encounter difficulties when preparing their DSPT submission. Common challenges include incomplete or outdated evidence, inconsistent policy documentation, insufficient risk management processes, weak governance oversight, and limited visibility of how controls are monitored and reviewed. These issues can become particularly problematic when organisations are required to undergo independent assurance or respond to detailed customer security questionnaires.


Independent third-party DSPT audits and readiness assessments provide an effective way to identify gaps before submission. By reviewing evidence, testing assertions, assessing governance arrangements, and benchmarking current maturity, organisations can address weaknesses early and strengthen the credibility of their submission. This not only improves confidence in achieving a successful assessment outcome but also provides NHS buyers with greater assurance that security and information governance obligations are being managed effectively.


As expectations continue to evolve, organisations that treat the DSPT as part of a broader security and assurance programme are likely to be better positioned than those relying solely on annual compliance exercises.




DSPT Version FAQs


What is the DSPT and who must complete it?


The Data Security and Protection Toolkit (DSPT) is NHS England's annual data security and information governance assessment. It is completed by NHS organisations, social care providers, and organisations that access, process, store, or support NHS health and care data. This includes many digital health companies, IT suppliers, medical device manufacturers, and other organisations providing products or services to the NHS.


What is the difference between the standards-based and CAF-aligned DSPT?


The standards-based DSPT assesses compliance against defined requirements derived from the National Data Guardian's data security standards. The CAF-aligned approach draws on principles from the National Cyber Security Centre's Cyber Assessment Framework and places greater emphasis on demonstrating effective cybersecurity outcomes and organisational resilience. Both approaches aim to improve security and assurance but use different assessment methodologies.


Which DSPT version does my organisation use?


The version of the DSPT that applies depends on how NHS England categorises your organisation. Large NHS organisations and certain nationally significant health and care entities have transitioned to CAF-aligned assessments, while most suppliers, digital health companies, medical device manufacturers, and smaller organisations continue to complete the standards-based DSPT. Organisations should review current NHS England guidance to confirm the assessment model applicable to them.


What is the DSPT submission deadline?


The DSPT is completed on an annual basis, with submissions typically required by the end of June each year. NHS England publishes the specific deadline for each assessment cycle, and organisations should confirm the applicable date for the current year. Early preparation is strongly recommended, particularly where independent assurance activities or significant evidence gathering are required.


Does the CAF-aligned DSPT replace the 10 Data Security Standards?


No. The National Data Guardian's 10 Data Security Standards continue to underpin the DSPT. The CAF-aligned model introduces a more outcome-focused assessment approach, but the underlying objective remains the same: ensuring organisations protect sensitive information, manage cyber risks effectively, and maintain appropriate governance arrangements.


Do IT suppliers have to complete the CAF-aligned DSPT?


In most cases, no. Most IT suppliers, SaaS providers, digital health companies, and medical device manufacturers currently complete the standards-based DSPT. However, suppliers should be aware of the increasing emphasis on cyber resilience, assurance, and evidence quality across the health and care sector and should expect requirements to continue evolving over time.


How often do you have to complete the DSPT?


The DSPT is an annual assessment. Organisations are required to review and resubmit their assessment each year, ensuring that evidence, policies, governance arrangements, and security controls remain current. Previous submissions do not automatically carry forward, and organisations should review updated requirements each assessment cycle.












 
 
 

Comments


bottom of page