Blog DSPT and Cyber Essentials

DSPT and Cyber Essentials for charities: what small charities need to know

By Andrew Heppinstall, founder of Unavoidable Studio · 1 October 2026 · 7 min read

A charity needs to complete the Data Security and Protection Toolkit (DSPT) if it has access to NHS patient data or NHS systems, for example because it delivers a health or care service under contract or receives referrals containing patient information. Cyber Essentials is different: it is a voluntary, government-backed certification that any charity can choose to hold, and that some funders and commissioners ask for. Many small charities that work alongside the NHS end up needing the first and benefiting from the second.

This guide explains how to tell whether the DSPT applies to your charity, what Cyber Essentials covers, where the two overlap, and a practical order to tackle them in when you have a small team and a smaller budget.

Does my charity need to complete the DSPT?

Your charity needs to complete the DSPT if it has access to NHS patient data and systems. The official DSPT website says: "All organisations that have access to NHS patient data and systems must use this toolkit to provide assurance that they are practising good data security and that personal information is handled correctly."

For charities this commonly includes those that:

NHS England's guidance on sharing information with the voluntary sector confirms that the toolkit "includes a view for voluntary sector organisations to complete". If your NHS partner or commissioner has asked for your DSPT status, treat that as a clear sign it applies to you.

Which version of the toolkit is current?

When we checked the official DSPT website on 1 October 2026, the current toolkit was 2026-27 version 9, with its outcomes, assertions and evidence items published on 8 September 2026. The site did not yet state a 2026-27 submission deadline, so check the DSPT website before you set your own timetable. For reference, the official DSPT news item for 2025-26 gave that year's deadline as 30 June 2026.

Is Cyber Essentials compulsory for charities?

No, Cyber Essentials is not a legal requirement for charities. It is a scheme run by the National Cyber Security Centre that certifies an organisation has five basic technical controls in place: firewalls, secure configuration, security update management, user access control and malware protection. Certification is delivered through IASME and its network of certification bodies.

The Charity Commission's guidance, Protect your charity from cyber crime, points charities towards the scheme as a way to protect against the most common cyber attacks. It also reminds trustees that while cyber security tasks can be delegated, "all the trustees remain responsible for making sure your charity is protected." For a full explanation of the scheme, see our plain-English guide to Cyber Essentials.

How do the DSPT and Cyber Essentials fit together?

They overlap on technical security and differ on everything else. The DSPT's technical questions ask about supported software, updates, anti-malware, secure set-up and who can access your systems. Those are the same areas Cyber Essentials checks, so work on one directly helps the other.

The DSPT then goes wider, into areas Cyber Essentials does not cover:

Neither replaces the other. Cyber Essentials will not complete your DSPT, and publishing the DSPT does not give you a Cyber Essentials certificate.

What makes this harder for a charity?

Charities face the same threats as businesses but often with fewer people and less IT support. These are the gaps we see most often.

Volunteers using their own devices

Volunteers may read emails or case notes on personal phones and laptops. Both the DSPT and Cyber Essentials care about which devices can reach your data. Decide which tasks can be done on personal devices, require a screen lock and up-to-date software as a minimum, and keep sensitive records in systems that need a proper login rather than in email attachments.

Shared accounts

One shared email login or one shared case management account between several people makes it impossible to see who did what. Individual accounts, protected by multi-factor authentication, are expected by both. Our MFA rollout guide for small teams shows how to switch it on without locking anyone out.

People leaving without their access being removed

Turnover among volunteers and short-term staff is high. Keep a simple list of who has access to what, and remove access on the day someone leaves.

Donated or old equipment

Donated laptops are welcome but often run software that no longer receives security updates. An unsupported device can undermine both your DSPT answers and a Cyber Essentials assessment.

Email impersonation

Criminals often pretend to be a charity's chief executive or treasurer to request urgent payments or change bank details. Check whether your domain is protected with our free email spoofing check. If an attack does happen, the Charity Commission notes you may need to report it to them as a serious incident.

Where should a small charity start?

Start with whichever one a partner is waiting for, which for charities working with the NHS is usually the DSPT. Then use its technical questions to work towards Cyber Essentials. A practical order:

  1. Agree who is responsible. Name a senior lead, and make sure a trustee is kept informed.
  2. Register on the DSPT and make sure at least two people can log in.
  3. Book training early for staff and the volunteers who handle personal information. It is usually the slowest item.
  4. Fix the technical basics: individual accounts, multi-factor authentication on email, automatic updates, and replacing unsupported devices.
  5. Keep your evidence in one place as you go: policies, training records and screenshots.
  6. Publish the DSPT. Our step-by-step DSPT guide walks through each stage.
  7. Then go for Cyber Essentials. With the basics fixed, the self-assessment becomes far more manageable. If you are weighing up the two levels, read Cyber Essentials vs Cyber Essentials Plus.

How we can help

Unavoidably Secure reviews your controls and your website and email security against what the DSPT asks for, and helps you get ready for Cyber Essentials. We do not certify, accredit or guarantee compliance: certification comes from an IASME certification body, and the DSPT is your own self-assessment. What we give you is a plain-English list of what to fix first, written for small teams. If your charity provides care services, our guide to DSPT and Cyber Essentials for care providers covers the care-specific detail, or browse more guides on the blog.

Want to know where your charity stands?

Book a free external audit. We will review your controls, website and email security and tell you plainly what to fix for the DSPT and Cyber Essentials.

Book a free audit

← Back to the blog