The NHS Data Security and Protection Toolkit is a mandatory annual self-assessment against the 10 National Data Guardian standards. Fortify gives you an AI-guided audit across all 10 standards, per-assertion evidence capture, and a clear gap analysis — so your submission is accurate and evidenced.
Requires a Fortify portal subscription · DSPT audit is a separate add-on · View pricing
If your organisation processes NHS patient data or operates within the NHS data ecosystem, an annual DSPT submission is required — not optional.
Mandatory annual submission for all GP practices. NHS England reviews submissions and compliance affects your practice QI ratings and CQC assessments.
All NHS organisations must complete the annual DSPT submission. Trusts achieving "Standards Met" demonstrate compliance to NHS England and CQC.
Any company building software that processes NHS patient data must complete a supplier DSPT submission — a condition of NHS data sharing agreements and DSPTs.
Private clinics, diagnostic centres, and community health organisations processing NHS-referred patient data typically require a DSPT submission.
Care homes, domiciliary care, and adult social care providers that share data with the NHS or receive NHS-funded clients are within scope.
Pharmaceutical, medical device, and logistics companies with NHS contracts that involve access to patient or staff personal data face DSPT requirements.
The DSPT measures your organisation against all 10 National Data Guardian standards. Fortify works through each one with you — identifying what you have in place and what still needs to be evidenced.
Personal Confidential Data
Data flows mapped, privacy notices in place, data sharing agreements with all third parties, and a current record of processing activities.
Staff Responsibilities
Data security responsibilities in all job descriptions, a named SIRO and DPO in post, and staff who know how to report concerns.
Training
At least 95% of staff complete annual data security awareness training. Completion records maintained and new starters onboarded promptly.
Managing Data Access
Least-privilege access, robust joiners-movers-leavers process, MFA for remote access, and no shared user accounts for patient data systems.
Process Reviews
DPIAs conducted for new or changed processes, information assets registered with named owners, and risks formally assessed.
Responding to Incidents
Documented incident response process, reportable breaches identified and notified to ICO within 72 hours, post-incident reviews completed.
Continuity Planning
Business continuity plan covers system unavailability, data backups are tested with defined recovery times, plans reviewed annually.
Unsupported Systems
Full hardware and software inventory, no end-of-life operating systems in use without a managed risk exception, security patches applied promptly.
IT Protection
Cyber Essentials certification in place, anti-malware on all devices, network access controlled, staff trained to recognise phishing.
Accountable Suppliers
Data processing agreements with all suppliers, security standards assessed before engagement, supplier risk reviewed annually.
Fortify handles the hard part — systematically working through every assertion, capturing evidence, and producing a clear picture of your DSPT position.
AI-guided readiness assessment
Dr. Priya Nair, your DSPT specialist, takes you through the 10 NDG standards section by section — asking the right questions, identifying gaps, and building a clear picture of your submission readiness.
Gap analysis mapped to DSPT assertions
Every identified gap is mapped to a specific DSPT assertion reference. Your portal shows exactly which assertions are met, partially met, or not yet evidenced.
Evidence capture per assertion
Attach training completion records, policy documents, data flow maps, and DPAs directly against each DSPT assertion — building your evidence pack as you go.
Annual submission ready
Export a summary of your evidenced assertions, gaps, and remediation progress — giving you everything you need to complete your annual DSPT submission accurately.
Dr. Priya Nair, your NHS data security specialist, guides your team through every DSPT assertion with structured questions, practical guidance, and per-assertion evidence capture. No IG consultant required.
What you need
Step 1 — Portal subscription
from £49/person/mo
Findings, roadmap, policies, incidents, vendor register
Step 2 — DSPT audit add-on
£99/mo · 12-month sub
AI-guided audit across all 10 NDG standards
Cyber Essentials Plus
Standard 9 requirementDSPT Standard 9 requires Cyber Essentials certification
Achieving the highest DSPT assessment level requires Cyber Essentials (at minimum) for Standard 9 IT Protection. Fortify's CE+ audit module runs alongside your DSPT work in the same portal.
Start in the Fortify portal. Set your goal to DSPT readiness and work through the 10 NDG standards with AI-guided assessments and built-in evidence capture.
Need more information? Read our healthcare sector guide