NHS Data Security and Protection Toolkit

DSPT submission ready — without the IG consultant

The NHS Data Security and Protection Toolkit is a mandatory annual self-assessment against the 10 National Data Guardian standards. Fortify gives you an AI-guided audit across all 10 standards, per-assertion evidence capture, and a clear gap analysis — so your submission is accurate and evidenced.

Requires a Fortify portal subscription · DSPT audit is a separate add-on · View pricing

Who requires DSPT

Mandatory for the NHS and its supply chain

If your organisation processes NHS patient data or operates within the NHS data ecosystem, an annual DSPT submission is required — not optional.

GP practices

Mandatory annual submission for all GP practices. NHS England reviews submissions and compliance affects your practice QI ratings and CQC assessments.

NHS Trusts & ICBs

All NHS organisations must complete the annual DSPT submission. Trusts achieving "Standards Met" demonstrate compliance to NHS England and CQC.

Health tech suppliers

Any company building software that processes NHS patient data must complete a supplier DSPT submission — a condition of NHS data sharing agreements and DSPTs.

Independent healthcare providers

Private clinics, diagnostic centres, and community health organisations processing NHS-referred patient data typically require a DSPT submission.

Social care organisations

Care homes, domiciliary care, and adult social care providers that share data with the NHS or receive NHS-funded clients are within scope.

NHS supply chain companies

Pharmaceutical, medical device, and logistics companies with NHS contracts that involve access to patient or staff personal data face DSPT requirements.

The 10 NDG Data Security Standards

Every standard. Every assertion. Fully guided.

The DSPT measures your organisation against all 10 National Data Guardian standards. Fortify works through each one with you — identifying what you have in place and what still needs to be evidenced.

01

Personal Confidential Data

Data flows mapped, privacy notices in place, data sharing agreements with all third parties, and a current record of processing activities.

02

Staff Responsibilities

Data security responsibilities in all job descriptions, a named SIRO and DPO in post, and staff who know how to report concerns.

03

Training

At least 95% of staff complete annual data security awareness training. Completion records maintained and new starters onboarded promptly.

04

Managing Data Access

Least-privilege access, robust joiners-movers-leavers process, MFA for remote access, and no shared user accounts for patient data systems.

05

Process Reviews

DPIAs conducted for new or changed processes, information assets registered with named owners, and risks formally assessed.

06

Responding to Incidents

Documented incident response process, reportable breaches identified and notified to ICO within 72 hours, post-incident reviews completed.

07

Continuity Planning

Business continuity plan covers system unavailability, data backups are tested with defined recovery times, plans reviewed annually.

08

Unsupported Systems

Full hardware and software inventory, no end-of-life operating systems in use without a managed risk exception, security patches applied promptly.

09

IT Protection

Cyber Essentials certification in place, anti-malware on all devices, network access controlled, staff trained to recognise phishing.

10

Accountable Suppliers

Data processing agreements with all suppliers, security standards assessed before engagement, supplier risk reviewed annually.

How it works

From gap check to submission-ready evidence

Fortify handles the hard part — systematically working through every assertion, capturing evidence, and producing a clear picture of your DSPT position.

01

AI-guided readiness assessment

Dr. Priya Nair, your DSPT specialist, takes you through the 10 NDG standards section by section — asking the right questions, identifying gaps, and building a clear picture of your submission readiness.

02

Gap analysis mapped to DSPT assertions

Every identified gap is mapped to a specific DSPT assertion reference. Your portal shows exactly which assertions are met, partially met, or not yet evidenced.

03

Evidence capture per assertion

Attach training completion records, policy documents, data flow maps, and DPAs directly against each DSPT assertion — building your evidence pack as you go.

04

Annual submission ready

Export a summary of your evidenced assertions, gaps, and remediation progress — giving you everything you need to complete your annual DSPT submission accurately.

DSPT Audit — Fortify Portal

AI-guided DSPT audit across all 10 standards

Dr. Priya Nair, your NHS data security specialist, guides your team through every DSPT assertion with structured questions, practical guidance, and per-assertion evidence capture. No IG consultant required.

  • 10 standards · All DSPT assertions covered with AI-guided questioning
  • Evidence attached per assertion — training records, DPAs, policy documents
  • Gap register with DSPT assertion references and remediation priorities
  • Supports Standards Met and Standards Exceeded submission levels
  • Exportable evidence summary for your submission and ICO investigations

What you need

Step 1 — Portal subscription

from £49/person/mo

Findings, roadmap, policies, incidents, vendor register

Step 2 — DSPT audit add-on

£99/mo · 12-month sub

AI-guided audit across all 10 NDG standards

Cyber Essentials Plus

Standard 9 requirement

DSPT Standard 9 requires Cyber Essentials certification

Achieving the highest DSPT assessment level requires Cyber Essentials (at minimum) for Standard 9 IT Protection. Fortify's CE+ audit module runs alongside your DSPT work in the same portal.

Learn about CE+ →

Ready to prepare your DSPT submission?

Start in the Fortify portal. Set your goal to DSPT readiness and work through the 10 NDG standards with AI-guided assessments and built-in evidence capture.

Need more information? Read our healthcare sector guide