Blog
Company Update
NHS DSPT v8
July 20, 2026
Approx min read

How to complete the NHS DSPT

An NHS information-governance reviewer looks for one thing before a contract can move: a current "Standards Met" status on the NHS DSPT. Until that status is published, the deal sits in due diligence and the access you need to NHS systems stays closed. How quickly you get through the toolkit sets how quickly the contract can proceed.

This is the practical how-to: registration, choosing your category, gathering evidence, and publishing your submission. For what the NHS Data Security and Protection Toolkit is and who has to complete it, the NHS DSPT spoke guide covers the background. Here we stay on the process.

What the NHS DSPT asks of you

The NHS DSPT is an annual online self-assessment on dsptoolkit.nhs.uk that any organisation handling NHS health and care data, or using national systems such as NHSmail, the Spine or the e-Referral Service, must complete. It shows you handle that data securely and lawfully (NHS England, dsptoolkit.nhs.uk).

The latest version is v8 for the 2025/26 cycle, published on 18 September 2025 (NHS England, dsptoolkit.nhs.uk/News/161). v8 is restructured around the National Cyber Security Centre's Cyber Assessment Framework, aligned to CAF version 3.4. In practice the toolkit now runs as a set of CAF outcomes, broken into assertions, each supported by evidence items you confirm. Every assertion maps to a CAF principle. If you completed the toolkit under the older data security standards layout, the shape has changed and your existing evidence maps differently. ``

The published outcome is either "Standards Met", where you meet all mandatory assertions and their evidence, or "Approaching Standards", where you meet the mandatory assertions to a minimum and attach a documented improvement plan. There is no certificate. The record you publish is the proof a buyer relies on.

How to complete the NHS DSPT, step by step

The route below reflects the v8 structure. Most of the work sits in the evidence, so the earlier you set up correctly, the less rework you carry.

1. Register or log in. Create or access your organisation account on dsptoolkit.nhs.uk, using your ODS code where you hold one. This links your submission to your organisation so a buyer can find your status by name.

2. Confirm your category. Most suppliers sit in Category 3 and should plan against it unless they clearly meet the criteria for a higher category. The category decides which evidence set applies, so getting it wrong means gathering the wrong evidence and reworking it later. When in doubt, default to Category 3 and verify against your organisation type. ``

3. Download your evidence set. NHS England publishes a v8 evidence spreadsheet per organisation type, listing the CAF-aligned outcomes, assertions and evidence items that apply to you. Treat it as your working checklist for the whole cycle.

4. Name an accountable owner. Assign a data-security or information-governance lead who owns the submission, with a Senior Information Risk Owner and Caldicott Guardian named where your organisation type requires them. A submission without a clear owner tends to stall between departments.

5. Work through the mandatory assertions. Answer each assertion and attach the evidence behind it. For a Category 3 supplier this usually means a reviewed data-security and IG policy with staff acknowledgement, completion records for annual data-security awareness training, a current risk assessment and register with remediation, an asset register, access-control records with review dates, business continuity and incident-response plans, and supplier and vendor assurance including your data-processing agreements.

6. Confirm every evidence item. Move through the toolkit assertion by assertion, confirming each evidence item is present and in date. This is where gaps surface, so leave time to close them before you publish.

7. Arrange an independent audit only if your category requires it. Higher-category organisations face a mandatory independent audit of defined audit areas, with the 2025/26 mandatory audit areas announced on 15 October 2025 (NHS England, dsptoolkit.nhs.uk/News). Category 3 suppliers self-assess and do not commission an audit.

8. Publish your submission. Aim for Standards Met. If you are not there when the deadline lands, publish Approaching Standards with an improvement plan and keep working. The toolkit stays open, so a late gap does not lock you out of finishing.

9. Maintain it annually. The DSPT is an annual commitment, and organisations on Approaching Standards work to a mid-year improvement-plan checkpoint. Keeping evidence current between cycles is far cheaper than rebuilding it each year.

How long the NHS DSPT takes

Where the underlying policies, training records and registers already exist, a Category 3 self-assessment can be assembled in a few weeks. Building the evidence base from scratch takes longer, because the work is in producing the policies and records the assertions ask for, more than in the toolkit entries themselves (commercial DSPT guidance; no tier-1 published figure). The single biggest driver is how much of your data-security evidence already exists before you start.

The cycle runs annually with a fixed submission deadline in late June. The 2025/26 v8 deadline was 30 June 2026. ``

Where teams get stuck

The most common blocker is the category. Suppliers who assume that selling NHS-facing software makes them a higher-category IT supplier gather the wrong evidence and redo it.

Missing training evidence is the next. Annual data-security awareness training completion records are a mandatory item, and teams often reach submission without them logged for every member of staff.

Weak asset and risk registers sit behind many Approaching Standards results, because the CAF-aligned assertions expect a register that is maintained with review dates and kept live, beyond a one-off spreadsheet. Business continuity and incident-response evidence is often the last piece that lifts a submission from Approaching Standards to Standards Met.

Two further traps. Supplier and vendor assurance stalls when data-processing agreements are unmapped or missing. And assuming this year mirrors last year catches organisations out, because the CAF v3.4 restructure means older evidence maps to different assertions than it did before.

How Naq gets you submission-ready faster

Naq runs the NHS DSPT inside the same system as your other standards, so the toolkit is not a separate project each year.

Data-security evidence you have already proven for ISO 27001 and Cyber Essentials is reused into the toolkit, so you are not gathering the same policies and records twice. New DSPT instances default to Category 3, matching where most suppliers belong. Evidence enters through an OCR uploader that reads your documents, so your policies and registers can be mapped to the relevant assertions instead of rekeyed by hand.

Virtual DPOs handle the data-protection judgement, with Clinical Safety Officers on hand where clinical safety is also in play. Enforced review dates keep the evidence in date from one cycle to the next, so each year builds on a live position instead of a cold restart. The AI assistant summarises and checks evidence on demand and is read-only, so it never edits the formal record.

One point stays fixed: you submit your own toolkit. Naq gets you submission-ready and confirms the evidence stands up. Publishing the assessment on dsptoolkit.nhs.uk remains your action as the accountable organisation.

"I'm really impressed with the service I've received from Naq. Without their support, it would have been a nightmare to complete our NHS DSPT and Cyber Essentials applications."

Andy Hall, Chief Scientific Officer, RareCan

``

Frequently asked questions

Is there a certificate for the NHS DSPT?

No. The NHS DSPT produces a published self-assessment status on dsptoolkit.nhs.uk, either Standards Met or Approaching Standards, not a certificate. That published status is what an NHS buyer checks, and it can be verified by your organisation name before a contract proceeds.

Which DSPT category should we choose?

Most suppliers are Category 3 and should plan against it unless they clearly meet the criteria for a higher category. The category sets which evidence applies, so choosing wrongly means gathering the wrong evidence. Default to Category 3 and confirm against your organisation type.

What happens if we miss the June deadline?

The toolkit stays open after the deadline, so you can keep working toward Standards Met. If you are not there in time, publish Approaching Standards with a documented improvement plan and continue. A late submission puts NHS access and contracts at risk, though the deadline itself does not trigger an automatic same-day cut-off.

Do Category 3 suppliers need an independent audit?

No. Higher-category organisations face a mandatory independent audit of defined audit areas, but Category 3 suppliers complete a self-assessment and do not commission an audit. This is one reason confirming your category early matters to the timeline.

Can our ISO 27001 or Cyber Essentials evidence count toward the DSPT?

Yes. The data-security controls behind ISO 27001 and Cyber Essentials map onto DSPT assertions, so evidence proven for those standards supports the toolkit. Running them as one connected body of evidence is what keeps the cost of NHS readiness down.

Book a 15-minute demo and run the NHS DSPT against your own evidence. See where you already meet the assertions and what is left to close before you submit.