Blog DSPT and Cyber Essentials

Cyber Essentials for dental practices: do you need it alongside the DSPT?

By Andrew Heppinstall, founder of Unavoidable Studio · 3 October 2026 · 6 min read

Cyber Essentials is voluntary for dental practices: no law requires it, and holding a certificate does not complete your Data Security and Protection Toolkit (DSPT). The DSPT is different. If your practice has access to NHS patient data and systems, you are expected to complete it every year. For most practices the sensible order is to complete the DSPT first and then consider Cyber Essentials, because the technical work for one does much of the heavy lifting for the other.

This guide explains what each one asks of a dental practice, where they overlap, the gaps we see most often in small practices, and a practical order to tackle them in.

Does my dental practice need to complete the DSPT?

Yes, if your practice has access to NHS patient data and systems. The official DSPT website says: "All organisations that have access to NHS patient data and systems must use this toolkit to provide assurance that they are practising good data security and that personal information is handled correctly." For a dental practice that usually means one providing NHS dental care, including mixed NHS and private practices, or one using NHS systems such as NHSmail.

Our plain-English guide to the DSPT for dental practices walks through the standards in detail.

Which version of the toolkit is current?

When we checked the official DSPT website on 3 October 2026, the current toolkit was 2026-27 version 9. The site did not yet state a 2026-27 submission deadline, so check the DSPT website before you set your own timetable. For reference, the 2025-26 deadline was 30 June 2026.

What is Cyber Essentials?

Cyber Essentials is a certification scheme backed by the National Cyber Security Centre, which describes it as "the minimum standard of cyber security recommended by the Government for organisations of all sizes". It checks five technical controls:

Certification is delivered by IASME and its network of certification bodies. Cyber Essentials is a self-assessment checked by a certification body, while Cyber Essentials Plus adds a hands-on technical audit. Since 27 April 2026, new assessments use IASME's "Danzell" question set, which replaced "Willow", according to IASME's question set page. Our comparison of Cyber Essentials and Cyber Essentials Plus explains which level suits which organisation.

Is Cyber Essentials compulsory for dental practices?

No. There is no law that requires a dental practice to hold Cyber Essentials. Practices choose it for practical reasons: it gives an independent check of the technical basics, insurers, partners or contracts may ask about it, and it is a structured way to fix the weaknesses criminals most often exploit. For a practice that holds health records for thousands of patients, those basics matter.

How do the DSPT and Cyber Essentials overlap?

They overlap on the technical controls and differ on almost everything else. The DSPT asks about unsupported software, keeping systems up to date, protection against malware, secure set-up and who can access your systems and patient records. Those are the same areas Cyber Essentials tests, so fixing them helps with both.

The DSPT then goes further, into areas Cyber Essentials does not cover:

Neither replaces the other. A Cyber Essentials certificate will not answer your DSPT, and publishing the DSPT does not give you a certificate.

Where do dental practices usually fall short?

The technical gaps we see in small practices tend to be the same few.

Shared logins on reception

One login shared by everyone on the front desk makes it impossible to see who opened which record. Both the DSPT and Cyber Essentials expect individual accounts, with administrator rights kept for the few people who need them.

Older surgery PCs

PCs that run imaging or X-ray software are sometimes left on old operating systems because the software has not been updated. An unsupported device counts against you in both. Where a machine cannot be updated, talk to your supplier and keep it away from email and web browsing until it can be replaced.

Email without multi-factor authentication

Email is a common way in. Turning on multi-factor authentication for email and any cloud system holding patient data closes off a large share of attacks. Our MFA rollout guide for small teams shows how to do it without locking anyone out.

Leavers who keep access

Associates, locums and nurses move between practices. Keep a simple list of who has access to what, and remove access on the day someone leaves.

Spoofed practice emails

Criminals pretend to be a practice or its owner to request payments or change bank details. Check whether your domain is protected with our free email spoofing check.

What order should a practice tackle them in?

  1. Name the person responsible for data security, and keep the practice owner or partners informed.
  2. Check your DSPT registration and make sure at least two people can log in.
  3. Book data security training for the whole team early. It is often the slowest item.
  4. Fix the technical basics: individual accounts, multi-factor authentication on email, automatic updates and a plan for unsupported machines.
  5. Keep your evidence in one place as you go: policies, training records and screenshots.
  6. Publish the DSPT before the deadline.
  7. Then apply for Cyber Essentials, reusing the same technical evidence.

How we can help

Unavoidably Secure reviews your controls and your website and email security against what the DSPT asks for, and helps you get ready for Cyber Essentials. We do not certify, accredit or guarantee compliance: certification comes from an IASME certification body, and the DSPT is your practice's own self-assessment. What we give you is a plain-English list of what to fix first, written for small teams.

This guide is general information, not legal advice. For more practical guides, browse the blog.

Want to know where your practice stands?

Book a free external audit. We will review your controls, website and email security and tell you plainly what to fix for the DSPT and Cyber Essentials.

Book a free audit

← Back to the blog