The NHS Data Security and Protection Toolkit is a mandatory annual self-assessment against the 10 National Data Guardian standards. Fortify gives you an AI-guided audit across all 10 standards, per-assertion evidence capture, and a clear gap analysis — so your submission is accurate and evidenced.
DSPT audit is included in Fortify portal plans from Essential and above.
If your organisation processes NHS patient data or operates within the NHS data ecosystem, an annual DSPT submission is required — not optional.
Mandatory annual submission for all GP practices. NHS England reviews submissions and compliance affects your practice QI ratings and CQC assessments.
All NHS organisations must complete the annual DSPT submission. Trusts achieving "Standards Met" demonstrate compliance to NHS England and CQC.
Any company building software that processes NHS patient data must complete a supplier DSPT submission — a condition of NHS data sharing agreements and DSPTs.
Private clinics, diagnostic centres, and community health organisations processing NHS-referred patient data typically require a DSPT submission.
Care homes, domiciliary care, and adult social care providers that share data with the NHS or receive NHS-funded clients are within scope.
Pharmaceutical, medical device, and logistics companies with NHS contracts that involve access to patient or staff personal data face DSPT requirements.
The DSPT measures your organisation against all 10 National Data Guardian standards. Fortify works through each one with you — identifying what you have in place and what still needs to be evidenced.
Personal Confidential Data
Data flows mapped, privacy notices in place, data sharing agreements with all third parties, and a current record of processing activities.
Staff Responsibilities
Data security responsibilities in all job descriptions, a named SIRO and DPO in post, and staff who know how to report concerns.
Training
At least 95% of staff complete annual data security awareness training. Completion records maintained and new starters onboarded promptly.
Managing Data Access
Least-privilege access, robust joiners-movers-leavers process, MFA for remote access, and no shared user accounts for patient data systems.
Process Reviews
DPIAs conducted for new or changed processes, information assets registered with named owners, and risks formally assessed.
Responding to Incidents
Documented incident response process, reportable breaches identified and notified to ICO within 72 hours, post-incident reviews completed.
Continuity Planning
Business continuity plan covers system unavailability, data backups are tested with defined recovery times, plans reviewed annually.
Unsupported Systems
Full hardware and software inventory, no end-of-life operating systems in use without a managed risk exception, security patches applied promptly.
IT Protection
Cyber Essentials certification in place, anti-malware on all devices, network access controlled, staff trained to recognise phishing.
Accountable Suppliers
Data processing agreements with all suppliers, security standards assessed before engagement, supplier risk reviewed annually.
Fortify handles the hard part — systematically working through every assertion, capturing evidence, and producing a clear picture of your DSPT position.
AI-guided readiness assessment
Priya, your DSPT specialist, takes you through the 10 NDG standards section by section — asking the right questions, identifying gaps, and building a clear picture of your submission readiness.
Gap analysis mapped to DSPT assertions
Every identified gap is mapped to a specific DSPT assertion reference. Your portal shows exactly which assertions are met, partially met, or not yet evidenced.
Evidence capture per assertion
Attach training completion records, policy documents, data flow maps, and DPAs directly against each DSPT assertion — building your evidence pack as you go.
Annual submission ready
Export a summary of your evidenced assertions, gaps, and remediation progress — giving you everything you need to complete your annual DSPT submission accurately.
Priya, your NHS data security specialist, guides your team through every DSPT assertion with structured questions, practical guidance, and per-assertion evidence capture. No IG consultant required.
Pricing
The Data Security and Protection Toolkit is NHS England's annual online self-assessment against the 10 National Data Guardian (NDG) data security standards. Any organisation that processes NHS patient data or connects to NHS systems — GP practices, trusts, health tech suppliers, social care providers — is required to complete it. Your published status (Standards Met, Standards Exceeded, or Approaching Standards) is visible to NHS commissioners and partners.
You submit self-assessed evidence against every assertion under the 10 standards through the official NHS toolkit at dsptoolkit.nhs.uk, once per assessment year — the standard deadline is 30 June, though you should always confirm the current year's date on the official toolkit. Fortify helps you prepare and evidence every assertion in advance, so the actual submission is a formality rather than a scramble.
Most organisations can complete DSPT without an external IG consultant if they have a structured way to work through all 10 standards and capture evidence as they go — that's exactly what Fortify's AI-guided audit does. A consultant may still be worth it for complex trusts with multiple systems and a large evidence backlog, but for most GP practices, smaller providers, and health tech suppliers it's not required.
The DSPT requires at least 95% of staff — including contractors and temporary staff with system access — to complete annual data security awareness training, typically the NHS Data Security Awareness training on the Learning Management System, with completion tracked and new starters onboarded within a defined period.
Data security incidents and personal data breaches need to be logged, and reportable ones notified through NHS England's incident reporting mechanism as well as the ICO within 72 hours where UK GDPR applies. The DSPT expects a documented incident response process covering both IT-related incidents (ransomware, phishing) and non-IT breaches (a misdirected letter, a verbal disclosure), plus evidence that post-incident reviews actually happen.
Each of the 10 NDG standards is broken down into specific assertions — individual statements you self-assess as met or not met, backed by evidence. For example, Standard 4 (Managing Data Access) includes assertions on least-privilege access, joiners/movers/leavers processes, and multi-factor authentication. Fortify maps every gap it finds directly to its DSPT assertion reference, so you know exactly what evidence is still needed.
"Standards Met" is the baseline compliant status most organisations aim for — every mandatory assertion evidenced. "Standards Exceeded" is a voluntary higher tier demonstrating additional maturity beyond the minimum, and from 2023/24 onwards requires Cyber Essentials certification as part of Standard 9. "Approaching Standards" means gaps remain against the mandatory assertions.
No — DSPT is a self-assessment, not a certification scheme, so there's no physical certificate to display. What you get is a published compliance status on the national DSPT system that commissioners, NHS partners, and auditors can check directly, which is why the evidence behind each assertion matters more than the assessment itself.
Want the step-by-step version? Read our guide to preparing a DSPT submission.
Cyber Essentials Plus
Standard 9 requirementDSPT Standard 9 requires Cyber Essentials certification
Achieving the highest DSPT assessment level requires Cyber Essentials (at minimum) for Standard 9 IT Protection. Fortify's CE+ audit module runs alongside your DSPT work in the same portal.
Start in the Fortify portal. Set your goal to DSPT readiness and work through the 10 NDG standards with AI-guided assessments and built-in evidence capture.
Need more information? Read our healthcare sector guide