NHS Data Security and Protection Toolkit

DSPT submission ready — without the IG consultant

The NHS Data Security and Protection Toolkit is a mandatory annual self-assessment against the 10 National Data Guardian standards. Fortify gives you an AI-guided audit across all 10 standards, per-assertion evidence capture, and a clear gap analysis — so your submission is accurate and evidenced.

DSPT audit is included in Fortify portal plans from Essential and above.

Who requires DSPT

Mandatory for the NHS and its supply chain

If your organisation processes NHS patient data or operates within the NHS data ecosystem, an annual DSPT submission is required — not optional.

GP practices

Mandatory annual submission for all GP practices. NHS England reviews submissions and compliance affects your practice QI ratings and CQC assessments.

NHS Trusts & ICBs

All NHS organisations must complete the annual DSPT submission. Trusts achieving "Standards Met" demonstrate compliance to NHS England and CQC.

Health tech suppliers

Any company building software that processes NHS patient data must complete a supplier DSPT submission — a condition of NHS data sharing agreements and DSPTs.

Independent healthcare providers

Private clinics, diagnostic centres, and community health organisations processing NHS-referred patient data typically require a DSPT submission.

Social care organisations

Care homes, domiciliary care, and adult social care providers that share data with the NHS or receive NHS-funded clients are within scope.

NHS supply chain companies

Pharmaceutical, medical device, and logistics companies with NHS contracts that involve access to patient or staff personal data face DSPT requirements.

The 10 NDG Data Security Standards

Every standard. Every assertion. Fully guided.

The DSPT measures your organisation against all 10 National Data Guardian standards. Fortify works through each one with you — identifying what you have in place and what still needs to be evidenced.

01

Personal Confidential Data

Data flows mapped, privacy notices in place, data sharing agreements with all third parties, and a current record of processing activities.

02

Staff Responsibilities

Data security responsibilities in all job descriptions, a named SIRO and DPO in post, and staff who know how to report concerns.

03

Training

At least 95% of staff complete annual data security awareness training. Completion records maintained and new starters onboarded promptly.

04

Managing Data Access

Least-privilege access, robust joiners-movers-leavers process, MFA for remote access, and no shared user accounts for patient data systems.

05

Process Reviews

DPIAs conducted for new or changed processes, information assets registered with named owners, and risks formally assessed.

06

Responding to Incidents

Documented incident response process, reportable breaches identified and notified to ICO within 72 hours, post-incident reviews completed.

07

Continuity Planning

Business continuity plan covers system unavailability, data backups are tested with defined recovery times, plans reviewed annually.

08

Unsupported Systems

Full hardware and software inventory, no end-of-life operating systems in use without a managed risk exception, security patches applied promptly.

09

IT Protection

Cyber Essentials certification in place, anti-malware on all devices, network access controlled, staff trained to recognise phishing.

10

Accountable Suppliers

Data processing agreements with all suppliers, security standards assessed before engagement, supplier risk reviewed annually.

How it works

From gap check to submission-ready evidence

Fortify handles the hard part — systematically working through every assertion, capturing evidence, and producing a clear picture of your DSPT position.

01

AI-guided readiness assessment

Priya, your DSPT specialist, takes you through the 10 NDG standards section by section — asking the right questions, identifying gaps, and building a clear picture of your submission readiness.

02

Gap analysis mapped to DSPT assertions

Every identified gap is mapped to a specific DSPT assertion reference. Your portal shows exactly which assertions are met, partially met, or not yet evidenced.

03

Evidence capture per assertion

Attach training completion records, policy documents, data flow maps, and DPAs directly against each DSPT assertion — building your evidence pack as you go.

04

Annual submission ready

Export a summary of your evidenced assertions, gaps, and remediation progress — giving you everything you need to complete your annual DSPT submission accurately.

DSPT Audit — Fortify Portal

AI-guided DSPT audit across all 10 standards

Priya, your NHS data security specialist, guides your team through every DSPT assertion with structured questions, practical guidance, and per-assertion evidence capture. No IG consultant required.

  • ✓10 standards · All DSPT assertions covered with AI-guided questioning
  • ✓Evidence attached per assertion — training records, DPAs, policy documents
  • ✓Gap register with DSPT assertion references and remediation priorities
  • ✓Supports Standards Met and Standards Exceeded submission levels
  • ✓Exportable evidence summary for your submission and ICO investigations

Pricing

DSPT audit

Included in portal plans

Available from Essential plan and above · View portal pricing

Common questions

Plain-English answers to the DSPT questions we hear most often

What is the DSPT (Data Security and Protection Toolkit)?

The Data Security and Protection Toolkit is NHS England's annual online self-assessment against the 10 National Data Guardian (NDG) data security standards. Any organisation that processes NHS patient data or connects to NHS systems — GP practices, trusts, health tech suppliers, social care providers — is required to complete it. Your published status (Standards Met, Standards Exceeded, or Approaching Standards) is visible to NHS commissioners and partners.

How do DSPT submissions work, and when is the deadline?

You submit self-assessed evidence against every assertion under the 10 standards through the official NHS toolkit at dsptoolkit.nhs.uk, once per assessment year — the standard deadline is 30 June, though you should always confirm the current year's date on the official toolkit. Fortify helps you prepare and evidence every assertion in advance, so the actual submission is a formality rather than a scramble.

Do I need a consultant for DSPT, or can I do it myself?

Most organisations can complete DSPT without an external IG consultant if they have a structured way to work through all 10 standards and capture evidence as they go — that's exactly what Fortify's AI-guided audit does. A consultant may still be worth it for complex trusts with multiple systems and a large evidence backlog, but for most GP practices, smaller providers, and health tech suppliers it's not required.

What DSPT training is required for staff?

The DSPT requires at least 95% of staff — including contractors and temporary staff with system access — to complete annual data security awareness training, typically the NHS Data Security Awareness training on the Learning Management System, with completion tracked and new starters onboarded within a defined period.

What counts as a reportable incident under DSPT?

Data security incidents and personal data breaches need to be logged, and reportable ones notified through NHS England's incident reporting mechanism as well as the ICO within 72 hours where UK GDPR applies. The DSPT expects a documented incident response process covering both IT-related incidents (ransomware, phishing) and non-IT breaches (a misdirected letter, a verbal disclosure), plus evidence that post-incident reviews actually happen.

What are DSPT "assertions"?

Each of the 10 NDG standards is broken down into specific assertions — individual statements you self-assess as met or not met, backed by evidence. For example, Standard 4 (Managing Data Access) includes assertions on least-privilege access, joiners/movers/leavers processes, and multi-factor authentication. Fortify maps every gap it finds directly to its DSPT assertion reference, so you know exactly what evidence is still needed.

What's the difference between "Standards Met" and "Standards Exceeded"?

"Standards Met" is the baseline compliant status most organisations aim for — every mandatory assertion evidenced. "Standards Exceeded" is a voluntary higher tier demonstrating additional maturity beyond the minimum, and from 2023/24 onwards requires Cyber Essentials certification as part of Standard 9. "Approaching Standards" means gaps remain against the mandatory assertions.

Does DSPT completion give you a certificate?

No — DSPT is a self-assessment, not a certification scheme, so there's no physical certificate to display. What you get is a published compliance status on the national DSPT system that commissioners, NHS partners, and auditors can check directly, which is why the evidence behind each assertion matters more than the assessment itself.

Want the step-by-step version? Read our guide to preparing a DSPT submission.

Cyber Essentials Plus

Standard 9 requirement

DSPT Standard 9 requires Cyber Essentials certification

Achieving the highest DSPT assessment level requires Cyber Essentials (at minimum) for Standard 9 IT Protection. Fortify's CE+ audit module runs alongside your DSPT work in the same portal.

Learn about CE+ →

Ready to prepare your DSPT submission?

Start in the Fortify portal. Set your goal to DSPT readiness and work through the 10 NDG standards with AI-guided assessments and built-in evidence capture.

Need more information? Read our healthcare sector guide