Audit methodology · Last verified
Data Security and Protection Toolkit
The DSPT is NHS England's mandatory self-assessment toolkit for organisations with access to NHS patient data — the output is a status, not a certificate. It measures performance against the National Data Guardian's 10 data security standards, and larger organisations must also commission an independent audit.
- Class
- Audit methodology
- Owner
- NHS England
- Public register
- Verified working
- Last verified
What it is
The DSPT is described by its own owner as "an online self-assessment tool that allows organisations to measure their performance against the National Data Guardian's 10 data security standards." It is a self-assessment mechanism, not a certification: the output is a published status against an organisation's own entry in a public search tool, not a certificate.
Scope, in the owner's own words: "All organisations that have access to NHS patient data and systems must use this toolkit to provide assurance that they are practising good data security and that personal information is handled correctly." The organisation types named in the current improvement-plan scope statement are "NHS Trusts, Integrated Care Boards (ICBs), Commissioning Support Units (CSUs), Independent Providers who are Operators of Essential Services under NIS, Genomics organisations, Key IT Suppliers, Local Authorities and Department of Health and Social Care (DHSC) Arm's Length Bodies (ALBs)."
The current cycle is version 8, and it is aligned to the NCSC's Cyber Assessment Framework: "DSPT Version 8 is aligned to CAF version 3.4." CAF alignment was phased in — NHS Trusts, Operators of Essential Services, CSUs, ALBs and ICBs moved to a CAF-aligned DSPT in September 2024, and independent-provider OES and nominated Genomics organisations followed for 2025-26.
Who owns it
NHS England is the Data Controller for the DSPT website, in its own words: "NHS England is the Data Controller for the Data Security and Protection Toolkit website." The NHS Standards Directory records NHS England as the standard's owner and maintainer.
Who assesses it
The core mechanism is self-assessment against the National Data Guardian's 10 data security standards. For larger organisations, national assurance also rests on independent audit: "National assurance will continue to be based on organisations commissioning independent audits of their self-assessments, complemented by national sampling audits." For the current cycle, mandatory independent audit coverage differs by organisation type: NHS Trusts, Integrated Care Boards, Arm's Length Bodies and Commissioning Support Units face 9 mandatory audit outcomes plus 3 the organisation selects; independent Operators of Essential Services and Genomics organisations face 8 mandatory plus 4 selectable; IT Suppliers face 12 mandatory assertions.
Who asks for it
Statutory (scoped). Mandatory for organisations with access to NHS patient data and systems, under a mechanism combining a statutory information-standard power (Health and Social Care Act 2012 s.250, as amended by the Health and Care Act 2022) and the NHS Standard Contract. The scope statement names organisation types structurally tied to England (NHS Trusts, Integrated Care Boards, Commissioning Support Units, DHSC Arm's Length Bodies) — whether Scotland, Wales or Northern Ireland use the same toolkit or an equivalent was not verified in the sources reviewed as of 31 August 2026.
Standards.nhs.uk names two mechanisms behind the requirement: a statutory information-standard power under "Section 250 of the Health and Social Care Act 2012, as amended by the Health and Care Act 2022", and the NHS Standard Contract. This scheme runs on an annual cycle tied to the current version of the DSPT, rather than a single fixed calendar date that carries forward unchanged year to year; the specific deadline for each year's version is set separately for that version and is confirmed against the current DSPT News page rather than assumed to repeat.
Sources
- NHS Data Security and Protection Toolkit (scheme owner) ↗ — accessed
- NHS Standards Directory — Data Security and Protection Toolkit record (published 12 August 2025) ↗ — accessed
- DSPT — News: Outcomes, Assertions and Evidence items for the DSPT 2025-26 version 8 ↗ — accessed
- DSPT — News: DSPT Changes (CAF alignment transition timeline; independent audit model) ↗ — accessed
- DSPT — News: DSPT Audit 25-26 Areas of Mandatory Audit ↗ — accessed
- DSPT — Home/Privacy (Data Controller statement) ↗ — accessed
- DSPT — Help/29 (opened in a real browser: scope organisation list, incident-reporting routing) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.