- Best for
- GPs, dental, pharmacy, care homes
- Standard
- DSPT v8 (2025/26)
- Deadline
- 30 June 2026
- Typical time
- A few weeks
What the DSPT is, and who must do it
The Data Security and Protection Toolkit is NHS England's annual self-assessment for anyone handling health or care data or using NHS systems such as NHSmail or e-Referrals. If you deliver services under an NHS contract, it's effectively mandatory — and commissioners increasingly make ‘Standards Met’ a condition of the contract.
What changed in version 8
The 2025/26 toolkit (version 8) is the biggest change in years. It's now aligned to the NCSC Cyber Assessment Framework (CAF v3.4) and restructured around outcomes, assertions and evidence. The practical shift: it's no longer enough to say a control exists — you have to show it works and is maintained. If your policy says ‘all staff complete annual training’, you need the records to prove it. There's no exemption for holding Cyber Essentials Plus or ISO 27001.
The 30 June 2026 deadline
Final submissions for 2025/26 are due 30 June 2026. Submitting late risks your access to NHS contracts and data-sharing. If you genuinely can't hit it, the right move is to contact NHS England before the deadline — but for most small providers there's still time to reach ‘Standards Met’ comfortably if you start now.
How we get you there
We start with a plain gap review against your DSPT category, then fix the controls that move the most outcomes fastest — MFA, access control, patching, backups and your asset register — and assemble a clean, audit-ready evidence pack. You submit with confidence. Most practices, pharmacies and care providers reach ‘Standards Met’ in a few weeks; larger CAF-aligned organisations take longer given their scope.
Common questions
When is the DSPT deadline?
The 2025/26 submission (version 8) is due 30 June 2026. It's an annual cycle — NHS England releases a new version each September.
What's different about the CAF-aligned DSPT?
It's outcome-based and evidence-led. Instead of ticking that a control exists, you must demonstrate it works and is maintained — with records, not just policies. That raises the bar on evidence, which is where we do most of the work.
We're a small GP practice / care home — how long does it take?
Most small providers reach ‘Standards Met’ in a few weeks once we start. We prioritise the controls that move the most outcomes and assemble the evidence for you.
Does Cyber Essentials or ISO 27001 exempt us from the DSPT?
No — there's no exemption. That said, holding Cyber Essentials gets the technical controls the DSPT asks about into shape, which makes the toolkit much easier to evidence.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day