Each year, NHS England updates the Data Security and Protection Toolkit (DSPT) to reflect changes in legislation, cyber-threat intelligence, and best practice. The 2025/26 edition (v8) is the biggest change in years: the toolkit is now aligned to the NCSC Cyber Assessment Framework (CAF), replacing the ten-standard, mandatory-assertion model with objectives, principles, and contributing outcomes. This guide walks through everything you need to know ahead of the 30 June 2026 submission deadline.
What is the DSPT?
The DSPT is an online self-assessment tool published by NHS England. Health and social care organisations that access NHS patient data or systems — including NHS trusts, GP practices, ICBs, and independent providers with NHS contracts — must complete an annual submission. For 2025/26 the toolkit is structured around the NCSC Cyber Assessment Framework (CAF): five objectives (A–E), each with a set of principles and contributing outcomes covering people, processes, and technology.
Instead of the old 'Standards Met' pass/fail, each contributing outcome is now rated Achieved, Partially Achieved, or Not Achieved. Organisations are expected to reach the required achievement levels across the applicable outcomes; those not yet meeting them submit an improvement plan. The submission window typically opens in April and closes at the end of June each year.
Key Changes for 2025/26
1. Cyber Security: Raised Evidence Bar
Objective B (protecting against cyber attack and data breaches) continues to be the area generating the most queries. For 2025/26, NHS England has raised the bar, aligning the cyber security outcomes more closely with Cyber Essentials Plus rather than the basic Cyber Essentials certification. Organisations will need to evidence:
- Multi-factor authentication (MFA) on all remote access and cloud services, with evidence of its enforced application
- A documented and tested patch management process with evidence that critical patches are applied within 14 days
- Up-to-date asset inventory covering all endpoints, servers, and network devices
- Evidence of active mobile device management (MDM) for corporate devices
- Annual penetration testing for organisations in scope of the higher-tier outcomes
2. People: Updated Training Thresholds
The training outcomes under Objective B require that all staff complete annual data security awareness training. For 2025/26, the threshold for an Achieved rating has been reviewed. The current position is that:
- 95% of directly employed staff must complete the Data Security Awareness training by the submission deadline
- Bank, agency, and locum staff require a proportionate approach with documented processes
- New starters must complete training within 12 weeks of joining — evidence of an induction training process is now mandatory
- Evidence of a consequence management process for non-completion is required
3. Processes: Data Security Incident Reporting
Organisations must demonstrate that a clear data security incident reporting policy exists and that staff know how to use it. For 2025/26, the toolkit asks for evidence that:
- Near-misses are captured and reviewed, not just notifiable incidents
- Lessons learned from incidents are shared with staff and documented
- There is a named SIRO (Senior Information Risk Owner) and Caldicott Guardian where applicable, with documented sign-off of the organisation's approach to information risk
4. Sharper: Supply Chain Outcomes
Following the NCSC's increased focus on supply chain security, the 2025/26 DSPT strengthens the contributing outcomes around supplier management (Objective A — managing risk). Organisations must now evidence:
- A maintained register of all data processors and suppliers with access to patient or NHS system data
- Current Article 28-compliant Data Processing Agreements (DPAs) with all processors
- A process for reviewing supplier security posture — at minimum, reviewing DSPT or equivalent certification for NHS-connected suppliers
Submission Deadline and Consequences
The 2025/26 submission window is expected to close on 30 June 2026. Organisations that miss the deadline or fall short of the required achievement levels may face:
- Inclusion on NHS England's published non-compliance list
- Reporting to ICBs (Integrated Care Boards) and NHS England regional teams
- Contract implications for independent providers with NHS commissioning
- Referral to the ICO if breaches of UK GDPR are identified during the submission process
How to Prepare
With the submission window typically opening in April, now is the time to:
- Review your training completion rates and chase outstanding completions
- Audit your DPA register and identify any suppliers missing valid agreements
- Confirm your cyber essentials certification is in date and evidenced in the toolkit
- Ensure your SIRO and Caldicott Guardian roles are documented and up to date
- Familiarise yourself with the CAF objectives and contributing outcomes in the toolkit portal before starting your submission
Folelse automates DSPT evidence gathering and tracks your contributing-outcome status in real time. Start your free trial to see how much time you can save on this year's submission.
Start free trial