Blog DSPT and Cyber Essentials

DSPT and Cyber Essentials for care providers: what you need and how they fit together

By Andrew Heppinstall, founder of Unavoidable Studio · 30 September 2026 · 7 min read

Most adult social care providers in England are expected to complete the Data Security and Protection Toolkit (DSPT) every year, while Cyber Essentials is a separate, voluntary certification that many providers choose to hold as well. The two are not alternatives. The DSPT asks whether you handle people's information safely across your whole organisation, including policies, training and incidents. Cyber Essentials focuses on five technical controls that stop the most common cyber attacks. Get the second right and a large part of the first becomes easier.

This guide explains what each one asks of a care provider, where they overlap, and a sensible order to tackle them in. The same approach works for care charities and small community organisations that handle health or social care information.

Do care providers have to complete the DSPT?

Yes, if you are a CQC-registered adult social care provider in England, the DSPT is the expected way to show you look after people's information properly. Digital Care Hub's guidance for 2026-27, updated on 1 September 2026, says providers must complete the toolkit at least once a year, with a deadline of 30 June. It describes the DSPT as recognised by CQC, local authorities and the NHS, which is why commissioners and NHS partners often ask for your status.

When we checked the official DSPT website on 30 September 2026, the current toolkit was 2026-27 version 9, with its outcomes, assertions and evidence items published on 8 September 2026. The official news pages did not yet state a 2026-27 submission date, so confirm it on the DSPT site before you plan. For reference, the official DSPT news item for 2025-26 gave that year's deadline as 30 June 2026.

What level should a care provider aim for?

Aim for Standards Met. According to Digital Care Hub, Standards Met means answering 45 mandatory questions covering staffing and roles, policies and procedures, data security, and IT systems and devices. There is also an entry-level status, Approaching Standards, which has 26 mandatory questions. It is a useful first step if you are completing the toolkit for the first time, but it is not where you want to stay.

What is Cyber Essentials, and is it compulsory for care providers?

Cyber Essentials is a government-backed scheme, run by the National Cyber Security Centre, that certifies an organisation has five basic technical controls in place. It is not a legal requirement for care providers, but some contracts and partners ask for it, and it is one of the clearest ways to show that your IT basics are sound.

The five controls, in the NCSC's own words, are:

Certification is delivered through IASME, the NCSC's Cyber Essentials delivery partner, and its network of certification bodies. Cyber Essentials Plus assesses the same five controls but adds independent technical testing. We compare the two in detail in Cyber Essentials vs Cyber Essentials Plus.

How do the DSPT and Cyber Essentials overlap?

They overlap most in the technical section of the DSPT. The toolkit asks about supported software, applying updates, anti-malware, secure configuration and controlling access to systems. Those are the same areas Cyber Essentials checks. If your devices and accounts would pass Cyber Essentials, you will be able to answer many of the DSPT's IT questions with confidence and with evidence to hand.

The DSPT goes wider. It also covers things Cyber Essentials does not touch:

So Cyber Essentials will not complete your DSPT for you, and the DSPT will not give you a Cyber Essentials certificate. Each supports the other.

Which should a care provider do first?

Start with the DSPT if you have not published this year, because it is the one commissioners and NHS partners expect. Then use the technical questions as a checklist to work towards Cyber Essentials. In practice we suggest this order:

  1. Register and assign roles. Make sure at least two people can log in to the DSPT, and name your senior lead for data security.
  2. Start staff training early. Training depends on other people finding time, so it is usually the slowest item.
  3. Fix the technical basics. Remove old accounts, turn on multi-factor authentication for email and remote access, replace unsupported devices and switch on automatic updates. Our MFA guide for small teams covers the rollout.
  4. Gather evidence as you go. Keep screenshots, policies and training records in one folder.
  5. Publish the DSPT. Our step-by-step DSPT guide walks through each stage.
  6. Then consider Cyber Essentials. With the basics fixed, the self-assessment becomes far less daunting.

What do care providers commonly get wrong?

Shared logins on care planning devices

Phones and tablets used by care staff are often shared, with one login between several people. Both the DSPT and Cyber Essentials expect access to be controlled and traceable, so individual accounts matter.

Old devices that no longer get updates

An old office PC or an unsupported tablet can undermine an otherwise good submission. Keep a simple list of every device, who uses it and whether it still receives security updates.

Forgetting the website and email

Your website, enquiry forms and email domain handle personal information and are visible to anyone. If criminals can send email that appears to come from your service, families and staff can be deceived. Our free email spoofing check shows in seconds whether your domain is protected.

How we can help

Unavoidably Secure reviews your controls and web-facing risk against what the DSPT asks for, and helps you get ready for Cyber Essentials. We do not certify, accredit or guarantee compliance: certification comes from an IASME certification body, and the DSPT is your own self-assessment. What we give you is a plain-English list of what to fix first. If you run a dental practice rather than a care service, see our DSPT guide for dental practices, or browse more guides on the blog.

Want to know where your care service stands?

Book a free external audit. We will review your controls, website and email security and tell you plainly what to fix for the DSPT and Cyber Essentials.

Book a free audit

← Back to the blog