Guides/DSPT
Step-by-step guide

How to prepare a DSPT submission

Not a form to fill in once a year — a rolling evidence exercise across 10 standards. This guide covers how the DSPT is actually structured, the two standards that cause the most last-minute scrambles, and how to make next year's submission far less stressful than this one.

01

Understand what the DSPT actually asks for

The DSPT isn't a single form — it's a self-assessment against 10 National Data Guardian standards, each broken down into individual assertions you evidence one by one. Treating it as "one big annual task" is exactly how organisations end up scrambling in June. Treat it as ongoing evidence collection instead.

Standards, then assertions

Each of the 10 standards (Personal Confidential Data, Staff Responsibilities, Training, Managing Data Access, Process Reviews, Responding to Incidents, Continuity Planning, Unsupported Systems, IT Protection, Accountable Suppliers) contains several specific assertions — the actual statements you evidence as met or not met.

Evidence, not assertions

A published status only means something if the evidence behind it holds up. NHS England and your commissioners can review the evidence attached to any assertion, not just the headline status.

02

Confirm your assessment year and deadline

DSPT runs on an annual cycle with a standard submission deadline of 30 June, though the exact date is confirmed each year on the official toolkit at dsptoolkit.nhs.uk. Know your deadline early — it drives everything else in this list.

Check dsptoolkit.nhs.uk directly

Dates occasionally shift year to year. The official toolkit, not a third party, is the source of truth for your current submission window.

Work backwards from it

Give yourself at least 8-10 weeks before the deadline to close gaps — training completion in particular can't be rushed in the final week if staff haven't done it yet.

03

Map what you already have against each standard

Before chasing new evidence, take stock of what already exists — policies, training records, access reviews, supplier agreements. Most organisations have more evidence than they realise; it's just scattered across different systems and owners.

Assign an owner per standard

Ten standards, one person trying to evidence all of them alone is how deadlines slip. Split ownership — IT for access/patching standards, HR for training, a named SIRO/DPO for governance standards.

Log gaps as you go, don't wait

A running gap list from week one is far more useful than discovering everything at once in week seven.

04

Close the two standards most organisations fail first

Two assertions cause more late scrambles than any others: staff training completion, and access control evidence.

Training — the 95% threshold

DSPT requires at least 95% of staff, including contractors with system access, to complete annual data security awareness training, with completion tracked throughout the year, not just checked before submission.

Access control — MFA and least privilege

Least-privilege access, a working joiners/movers/leavers process, and MFA for remote access and privileged accounts are all explicitly assessed. Shared logins for clinical systems are one of the most commonly failed assertions.

Worth knowing

Both of these take weeks to evidence properly, not days — training records need real completion data, and access reviews need an actual audit trail. Start these two first, before anything else on this list.

05

Get your incident response and continuity evidence in order

Standard 6 (Responding to Incidents) and Standard 7 (Continuity Planning) both expect a documented, evidenced process — not just a policy that exists but has never been tested.

Incident response

A written process covering both IT incidents (ransomware, phishing) and non-IT breaches (a misdirected letter, verbal disclosure), reportable incidents notified to the ICO within 72 hours where required, and evidence that post-incident reviews actually happen.

Continuity planning

A plan for system unavailability scenarios, tested data backups with defined recovery times, and annual review — see our full guide to building a disaster recovery plan if this is a genuine gap rather than a documentation gap.

06

Submit, then keep evidence current — don't start from zero next year

DSPT is annual, but the evidence it asks for is operational, not a point-in-time snapshot. Organisations that treat it as a rolling process rather than a June deadline consistently submit faster and with less stress the following year.

Review after any material change

A new clinical system, a new supplier, a change in headcount — update the relevant assertions when it happens, not eleven months later.

Keep training and access reviews continuous

The two assertions that cause the most last-minute pressure are also the two that are easiest to keep current year-round with the right tracking in place.

Common questions about DSPT submissions

Who actually has to complete the DSPT?

Any organisation that processes NHS patient data or connects to NHS systems — GP practices, NHS trusts and ICBs, health tech suppliers, independent healthcare providers, social care organisations working with the NHS, and NHS supply chain companies with access to patient or staff data. It's a condition of most NHS data sharing agreements and contracts, not optional participation.

What happens if we don't submit, or land on "Approaching Standards"?

"Approaching Standards" signals gaps against mandatory assertions and is visible to NHS commissioners and partners reviewing your status — it can affect contract renewals, data sharing agreements, and in the case of GP practices, wider quality assessments. Not submitting at all is treated as non-compliance with your data sharing obligations.

How long does DSPT preparation actually take?

For an organisation starting with reasonable evidence already scattered across systems, 8-10 focused weeks is realistic. For one starting from very little — no training tracking, no access review process — closing gaps properly (particularly the 95% training threshold) can take a full quarter. Starting early is the single biggest factor in how stressful the final weeks are.

Does DSPT replace Cyber Essentials or ISO 27001?

No — they're complementary, not interchangeable. DSPT Standard 9 (IT Protection) specifically requires Cyber Essentials certification as a minimum for the highest assessment level, so most organisations pursuing "Standards Exceeded" need both. ISO 27001 isn't required by DSPT but its evidence (risk register, ISMS documentation) often overlaps usefully with several DSPT standards.

Turn this into tracked, evidenced progress

Fortify's DSPT audit works through all 10 standards with AI-guided questioning, maps every gap to its exact assertion reference, and lets you attach evidence as you go — so your submission is a formality, not a scramble.