Audit methodology · Last verified

Data Security and Protection Toolkit

The DSPT is NHS England's mandatory self-assessment toolkit for organisations with access to NHS patient data — the output is a status, not a certificate. It measures performance against the National Data Guardian's 10 data security standards, and larger organisations must also commission an independent audit.

Class
Audit methodology
Owner
NHS England
Public register
Verified working
Last verified

What it is

The DSPT is described by its own owner as "an online self-assessment tool that allows organisations to measure their performance against the National Data Guardian's 10 data security standards." It is a self-assessment mechanism, not a certification: the output is a published status against an organisation's own entry in a public search tool, not a certificate.

Scope, in the owner's own words: "All organisations that have access to NHS patient data and systems must use this toolkit to provide assurance that they are practising good data security and that personal information is handled correctly." The organisation types named in the current improvement-plan scope statement are "NHS Trusts, Integrated Care Boards (ICBs), Commissioning Support Units (CSUs), Independent Providers who are Operators of Essential Services under NIS, Genomics organisations, Key IT Suppliers, Local Authorities and Department of Health and Social Care (DHSC) Arm's Length Bodies (ALBs)."

The current cycle is version 8, and it is aligned to the NCSC's Cyber Assessment Framework: "DSPT Version 8 is aligned to CAF version 3.4." CAF alignment was phased in — NHS Trusts, Operators of Essential Services, CSUs, ALBs and ICBs moved to a CAF-aligned DSPT in September 2024, and independent-provider OES and nominated Genomics organisations followed for 2025-26.

Who owns it

NHS England is the Data Controller for the DSPT website, in its own words: "NHS England is the Data Controller for the Data Security and Protection Toolkit website." The NHS Standards Directory records NHS England as the standard's owner and maintainer.

Who assesses it

The core mechanism is self-assessment against the National Data Guardian's 10 data security standards. For larger organisations, national assurance also rests on independent audit: "National assurance will continue to be based on organisations commissioning independent audits of their self-assessments, complemented by national sampling audits." For the current cycle, mandatory independent audit coverage differs by organisation type: NHS Trusts, Integrated Care Boards, Arm's Length Bodies and Commissioning Support Units face 9 mandatory audit outcomes plus 3 the organisation selects; independent Operators of Essential Services and Genomics organisations face 8 mandatory plus 4 selectable; IT Suppliers face 12 mandatory assertions.

Who asks for it

Statutory (scoped). Mandatory for organisations with access to NHS patient data and systems, under a mechanism combining a statutory information-standard power (Health and Social Care Act 2012 s.250, as amended by the Health and Care Act 2022) and the NHS Standard Contract. The scope statement names organisation types structurally tied to England (NHS Trusts, Integrated Care Boards, Commissioning Support Units, DHSC Arm's Length Bodies) — whether Scotland, Wales or Northern Ireland use the same toolkit or an equivalent was not verified in the sources reviewed as of 31 August 2026.

Standards.nhs.uk names two mechanisms behind the requirement: a statutory information-standard power under "Section 250 of the Health and Social Care Act 2012, as amended by the Health and Care Act 2022", and the NHS Standard Contract. This scheme runs on an annual cycle tied to the current version of the DSPT, rather than a single fixed calendar date that carries forward unchanged year to year; the specific deadline for each year's version is set separately for that version and is confirmed against the current DSPT News page rather than assumed to repeat.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Data Security and Protection Toolkit." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/nhs-dspt

All frameworks & audits →