Skip to main content

Framework · NHS cyber assurance

NHS Data Security and Protection Toolkit (DSPT)

The annual NHS cyber assurance framework administered by NHS England, structured around the National Data Guardian's Ten Data Security Standards. Required for all organisations with access to NHS patient data, including NHS Trusts, GP practices, ICBs, and NHS suppliers.

NHS DSPT submission is mandatory for organisations handling NHS patient data. Goldline supports NHS Trusts and NHS suppliers through DSPT submission preparation, gap analysis, evidence development, and ongoing compliance posture management.

WHERE THIS FRAMEWORK FITS

Where this framework fits at Goldline

Goldline's active service lines are ISO 42001 (AI governance) and ISO 27001 (information security) implementation. NHS DSPT is not a service Goldline delivers as a standalone product.

The Data Security and Protection Toolkit applies to NHS-connected organisations. It maps substantially onto ISO 27001 Annex A controls. Organisations approaching NHS DSPT typically find that ISO 27001 implementation addresses the majority of DSPT assertions while delivering an internationally recognised certificate as a second outcome.

For active engagement, book a free 45 minute diagnostic and we will confirm whether the ISO 27001 Sprint (or, where AI governance is also in scope, the ISO 42001 Sprint) fits your specific circumstances.

Book the Free Diagnostic

Browse all frameworks

What is the NHS Data Security and Protection Toolkit?

The Data Security and Protection Toolkit (DSPT) is the NHS cyber assurance framework administered by NHS England Digital. It is an annual online self-assessment that organisations handling NHS patient data must complete to demonstrate they are practising good data security and that personal information is handled correctly. DSPT submission status is reported publicly, and organisations not meeting expectations face increased NHS England scrutiny and procurement implications.

DSPT is structured around the National Data Guardian's Ten Data Security Standards (NDG Standards), covering personal accountability, staff training, processes for handling personal confidential data, supplier assurance, and IT protection. The Toolkit translates these standards into mandatory and advisory assertions that organisations evaluate themselves against.

DSPT submission deadlines run annually on a refresh cycle. NHS Trusts, Integrated Care Boards (ICBs), GP practices, NHS suppliers, social care providers, and other organisations with access to NHS data systems must submit. Submission status (Standards Met, Standards Not Fully Met, Approaching Standards) is published on the DSPT portal.

What DSPT covers

Ten National Data Guardian Standards translated into mandatory and advisory assertions across data security, information governance, training, supplier assurance, and IT protection.

Personal accountability and leadership

NDG Standards 1 to 3. Senior Information Risk Owner (SIRO) appointment, Caldicott Guardian role where applicable, board-level cyber accountability, and senior management oversight of data security.

Staff training and awareness

NDG Standards 4 to 5. Annual mandatory staff training on data security, role-based information governance training, and induction processes for new staff covering NHS data handling.

Data flow mapping and asset management

NDG Standards 6 to 7. Records of processing activities, data flow mapping across the organisation, IT asset inventory, and information asset registers.

Technical security controls

NDG Standard 8 (IT protection). Network security, access control, vulnerability management, patch management, malware protection, and encryption of NHS data at rest and in transit.

Supplier assurance

NDG Standard 9. Third-party supplier security assurance, contractual data protection arrangements, supplier DSPT status verification, and supply chain risk management.

Incident response and continuity

NDG Standard 10. Cyber incident response capability, breach notification processes, business continuity arrangements, and lessons-learned processes following incidents.

Why NHS Trusts prioritise DSPT

  • DSPT submission is mandatory for all NHS organisations accessing patient data. Failure to submit, or submission with 'Standards Not Fully Met' status, triggers NHS England escalation and remedial action requirements.

  • DSPT status affects supplier eligibility. NHS Trusts increasingly require their own suppliers and partners to hold current DSPT status before contract award.

  • Public reporting of DSPT status affects organisational reputation. The DSPT portal publishes submission status, visible to NHS England, ICBs, and the public.

  • Cyber Essentials Plus is now a DSPT requirement for many organisations. The integration of UK Cyber Essentials Plus into DSPT submission creates compounding compliance overhead without coordinated delivery.

  • ISO 27001 alignment with DSPT provides clearer evidence trail. NHS Trusts pursuing ISO 27001 certification find substantial overlap with DSPT requirements, enabling parallel compliance with shared evidence pack.

DSPT vs ISO 27001 vs Cyber Essentials Plus

How DSPT sits alongside the two other frameworks NHS Trusts and their suppliers most often evaluate together.

 DSPTISO 27001Cyber Essentials Plus
TypeNHS-specific self-assessment cyber assurance framework administered by NHS England.International management system standard for information security, audited by an accredited certification body.UK government-backed cyber hygiene certification scheme, audited by an IASME-accredited assessor.
ScopeOrganisations handling NHS patient data: Trusts, ICBs, GP practices, NHS suppliers, social care providers.Any organisation, scoped to defined ISMS boundary covering people, processes, and technology.Whole-organisation or defined scope covering internet-facing systems, devices, and user accounts.
CycleAnnual self-assessment cycle culminating in submission to the DSPT portal.Three-year certification cycle with annual surveillance audits and recertification.Annual certification cycle, with technical audit conducted within a defined window each year.
RecognitionMandatory across the NHS supply chain and reported publicly on the DSPT portal.Globally recognised certification used by enterprise buyers, regulators, and procurement teams.Required for many UK government contracts and increasingly cited in NHS supplier assurance.

METHODOLOGY

How Goldline delivers DSPT compliance readiness

The Goldline Method applied to NHS DSPT. Five phases from current state analysis through annual submission, calibrated to your Trust scale, operational maturity, and existing cyber governance posture.

  1. 01

    Phase 1

    Current state analysis and DSPT scope confirmation

    Senior practitioner-led review of current DSPT submission status, gap analysis against current Toolkit version, organisational scope confirmation, and stakeholder mapping across SIRO, Caldicott Guardian, DPO, and Trust cyber leadership.

    • Current state analysis
    • Scope confirmation
    • Stakeholder map
  2. 02

    Phase 2

    Gap analysis against all DSPT assertions

    Comprehensive gap analysis across all ten NDG Standards and the mandatory and advisory assertion structure. Existing evidence catalogued and mapped to assertions. Gaps prioritised by submission impact and remediation effort.

    • Assertion-level gap analysis
    • Evidence inventory
    • Remediation prioritisation
  3. 03

    Phase 3

    Evidence development and policy framework

    Remediation delivery across identified gaps. Policy framework development for missing or outdated policies. Training documentation development. Supplier assurance evidence development. Technical control evidence collation.

    • Policy framework
    • Evidence pack
    • Supplier assurance
  4. 04

    Phase 4

    Submission preparation and internal review

    Senior practitioner-led internal review of assertion responses prior to submission. SIRO and Caldicott Guardian briefing. Risk acceptance documentation where assertions are not fully met. Submission readiness confirmation.

    • Internal review
    • SIRO briefing
    • Submission readiness
  5. 05

    Phase 5

    Submission and continuous compliance

    DSPT portal submission support. Continuous compliance posture management between submission cycles. Quarterly evidence refresh. Preparation for next annual cycle and tracking of any DSPT version updates affecting Trust assertions.

    • Submission complete
    • Continuous compliance
    • Next cycle preparation

Frequently asked

Discuss where this framework fits your programme

Whether your Trust is preparing for an upcoming DSPT submission cycle, addressing remediation following a 'Standards Not Fully Met' assessment, or evaluating ongoing senior practitioner-led DSPT posture management, Goldline provides senior practitioner-led delivery calibrated to NHS Trust operational realities.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.