Blog DSPT

DSPT 2026-27 version 9: what has changed for small organisations

By Andrew Heppinstall, founder of Unavoidable Studio · 8 October 2026 · 6 min read

Version 9 of the Data Security and Protection Toolkit (DSPT), the 2026-27 edition, was released on 1 September 2026, and for most dental practices, care providers and small charities it is a refinement rather than a rewrite. The toolkit is still an annual self-assessment against the National Data Guardian's 10 data security standards, and you still need to complete and publish it each year if your organisation has access to NHS patient data and systems. What has changed sits mainly in how suppliers and products are described, a handful of policy items and some new support for certain care providers. This guide sets out what the official release notes say, what they mean for a small organisation, and what to do now.

What is new in DSPT version 9?

The DSPT team's system changes and release notes (updated 4 September 2026) list the main changes for 2026-27. The ones most likely to matter to a small organisation are:

On 2 October 2026 the toolkit also published the full list of outcomes, assertions and evidence items for version 9 as a spreadsheet, on the DSPT news page. It is worth downloading, because it is the quickest way to see exactly what your assessment will ask for.

Does version 9 change much for a dental practice, care home or charity?

For most small organisations, not a great deal. The release notes do not list any changes aimed specifically at dental practices, GP surgeries, care homes, home care providers or charities. The CAF-based outcomes, such as B2.a, belong to the CAF-aligned version of the toolkit, which NHS England introduced in September 2024 for NHS trusts, integrated care boards, commissioning support units and arm's length bodies, and later extended to some other organisation types. If your organisation completes the standards-based assessment, you may never see those items.

The simplest way to be sure is to log in, open your 2026-27 assessment and compare it with the spreadsheet for your organisation type. If something looks new, read the guidance attached to that item before you answer it.

When is the 2026-27 DSPT deadline?

As of 8 October 2026, the DSPT news pages do not state a submission deadline for the 2026-27 toolkit. The deadline for the previous year, 2025-26, was 30 June 2026, as the toolkit's improvement plan instructions confirm. Until a 2026-27 date is published, a sensible working assumption is that you should be ready by the end of June 2027, and check the toolkit's home page for the confirmed date.

Starting early matters more than the exact date. The items that take longest in a small team are rarely technical: they are staff training, gathering policies and getting the right person to sign things off.

What if you did not reach Standards Met last year?

For 2025-26, certain organisation types that could not meet the required level by the deadline could submit an improvement plan. The improvement plan instructions name NHS trusts, integrated care boards, commissioning support units, independent providers who are Operators of Essential Services, genomics organisations, key IT suppliers, local authorities and DHSC arm's length bodies. An approved plan changes the 2025-26 status to "Approaching Standards", and organisations are reminded to send progress updates by 30 September 2026 and 31 December 2026.

Most dental practices, care homes and small charities are not on that list. If your 2025-26 assessment was not published as Standards Met, the practical step is to treat the open items as the first things to fix in your 2026-27 assessment, rather than waiting for the deadline to come round again.

What stays the same?

Most of what you did last year still applies. You will still need to:

Our step-by-step guide to completing the DSPT walks through the process from registration to publishing, and the DSPT overview explains who needs to complete it.

What should you do now?

  1. Check your log-in. Make sure at least two people in your organisation can access the toolkit, so you are not stuck if one is away.
  2. Download the version 9 spreadsheet. Compare it with last year's evidence and note anything new for your organisation type.
  3. Review your supplier list. With the move from "IT supplier" to "supplier", make sure your records cover every company that handles your data, such as your practice management system, payroll provider, rota software and website host.
  4. Book staff training early. It is usually the slowest item to complete in a small team.
  5. Tighten account security. If multi-factor authentication is not on for email and cloud systems, start there. Our MFA guide for small teams shows how to roll it out without locking anyone out.
  6. Keep your evidence in one place. Store policies, training records and screenshots as you go, so publishing is a final check rather than a scramble.

Dental practices can find sector-specific points in our DSPT guide for dental practices, and care providers in DSPT and Cyber Essentials for care providers.

How we can help

Unavoidably Secure reviews your controls, website and email security against what the DSPT asks for, and helps you get ready for Cyber Essentials. We do not certify, accredit or guarantee compliance: the DSPT is your organisation's own self-assessment, and Cyber Essentials certification comes from an IASME certification body. What we give you is a plain-English list of what to fix first, written for small teams.

This guide is general information, not legal advice. Facts were checked against the DSPT website on 8 October 2026. For more practical guides, browse the blog.

Want to know where you stand on the DSPT?

Book a free external audit. We will review your controls, website and email security and tell you plainly what to fix before you publish your 2026-27 DSPT.

Book a free audit

← Back to the blog