The DSPT is the NHS Data Security and Protection Toolkit: an online self-assessment that organisations use to measure their performance against the National Data Guardian's ten data security standards. If your organisation has access to NHS patient information, you need to complete it every year. The 2026-27 toolkit is version 9, published on 2 October 2026, and the deadline is 30 June 2027.
On this page
What the DSPT is
The Data Security and Protection Toolkit is run by NHS England. It is a set of outcomes, assertions and evidence items grouped under the National Data Guardian's ten data security standards. You log in, answer each assertion for your organisation type, point to or attach the evidence behind your answers, and publish the result.
It is how the health and care system checks that everyone who touches patient data, from a large trust to a small dental practice or care home, meets a common baseline.
Who needs to complete it
NHS England's position is simple: all organisations that have access to NHS patient information must provide assurance that they have the proper measures in place, and they do it through the DSPT. Completing it is a contractual requirement for NHS contracts.
The toolkit has resources for many organisation types, including:
| Organisation type | Examples |
|---|---|
| NHS organisations | Trusts, integrated care boards, commissioning support units |
| Primary care | General practices, dentists, pharmacies, opticians |
| Social care | Care homes and home care providers that handle NHS data |
| Suppliers | IT suppliers and others processing NHS data on behalf of a health or care organisation |
| Others | Local authorities, universities and other bodies that process NHS patient information |
To register you need an email address and your organisation's ODS code.
The 2026-27 deadline and version 9
Version 9 of the toolkit was published on 2 October 2026. The submission deadline is 30 June 2027.
NHS England states that DSPT version 9 is aligned to version 4.0 of the Cyber Assessment Framework (CAF). The outcomes, assertions and evidence items differ by organisation type, so download the ones for your category from the official DSPT website before you start rather than working from last year's answers.
The long window is the opportunity. Most organisations that end up rushing do so because they left evidence gathering until late spring.
Standards Met, Exceeded and Approaching
| Status | What it means |
|---|---|
| Standards Met | You have completed all the mandatory questions and evidence items for your organisation type. |
| Standards Exceeded | For designated NHS organisations that go beyond the requirements, or any organisation that reaches Standards Met and holds a current Cyber Essentials Plus certificate. |
| Approaching Standards | For social care organisations that are making good progress but are not yet at Standards Met. |
For most organisations and most contracts, the goal is Standards Met. If you already hold Cyber Essentials Plus, Standards Met can become Standards Exceeded. See our guide to Cyber Essentials and Cyber Essentials Plus.
How to complete it, step by step
- Register or log in on the DSPT website with your email address and ODS code.
- Confirm your organisation profile so the toolkit shows the right assertions for your type.
- Download the 2026-27 version 9 outcomes, assertions and evidence items for your organisation type.
- Work through each assertion, attaching or pointing to evidence: policies, training records, an asset register, access controls, backup and incident procedures.
- Close the gaps you find, such as staff training, a named data security lead, tested backups, supported software and multi-factor authentication.
- Review honestly, then publish before 30 June 2027.
- Keep the evidence current through the year so next year is a review, not a scramble.
For a fuller walk-through, read the DSPT step by step.
Where organisations most often go wrong
- Training not completed, or not evidenced, for every member of staff.
- No named person responsible for data security and information governance.
- Backups that exist but have never been tested with a restore.
- Leavers who still have logins, shared accounts and weak sign-in.
- No written, rehearsed incident response procedure.
- Leaving evidence gathering too late in the year.
Not sure where you stand?
We run a free external audit of your public web and email setup, then show you where you stand against the ten standards. No charge, no obligation, and no access to your systems.
Request your free auditOr call 07749 941111
Guides for your sector
- DSPT for dental practices
- DSPT and Cyber Essentials for care providers
- DSPT and Cyber Essentials for charities
- Cyber Essentials for dental practices
Common questions
What does DSPT stand for?
DSPT stands for the Data Security and Protection Toolkit, the NHS online self-assessment that organisations use to measure their performance against the National Data Guardian's ten data security standards.
Is the DSPT mandatory?
If your organisation has access to NHS patient information, yes. NHS England says all organisations with access to NHS patient information must provide assurance through the DSPT, and completing it is a contractual requirement for NHS contracts. It must be completed every year.
When is the DSPT deadline?
The deadline for the 2026-27 toolkit is 30 June 2027. Version 9 of the toolkit for 2026-27 was published on 2 October 2026.
What changed in version 9?
The 2026-27 toolkit is version 9, and NHS England states that it is aligned to version 4.0 of the Cyber Assessment Framework (CAF). Check the outcomes, assertions and evidence items for your organisation type on the official DSPT website before you start.
What do Standards Met and Standards Exceeded mean?
Standards Met means you have completed all the mandatory questions and evidence items for your organisation type. Standards Exceeded is available to designated NHS organisations that go beyond the requirements, and to any organisation that reaches Standards Met and holds a current Cyber Essentials Plus certificate. Social care organisations that are making good progress but are not yet there can publish Approaching Standards.
Is the DSPT the same as Cyber Essentials or UK GDPR?
No, but they overlap. The DSPT is the NHS assessment of data security and information governance. Cyber Essentials is a separate UK certification focused on technical controls, and UK GDPR is the data protection law. Holding Cyber Essentials Plus alongside Standards Met can lift your DSPT status to Standards Exceeded.
What do I need to register?
You need an email address and your organisation's ODS code to register on the DSPT website.
This guide is general information, accurate at 4 October 2026, and is not legal advice. Requirements are set by NHS England and can change; always check the current guidance on the DSP Toolkit website for your organisation type. Sources: DSP Toolkit, "DSPT 2026-27 Information" and "Overview and introductory guidance".