A practical guide to the NHS Data Security and Protection Toolkit — what it covers, how to meet each CAF contributing outcome, and how Folelse makes submission faster and audit-ready.
The NHS Data Security and Protection Toolkit (DSPT) is an online self-assessment tool produced by NHS England. For 2025/26 the toolkit (v8) is aligned to the NCSC Cyber Assessment Framework (CAF) — replacing the earlier ten-standard, mandatory-assertion model.
All organisations that have access to NHS patient data and systems must complete the DSPT annually. The assessment is now made across contributing outcomes, each rated Achieved, Partially Achieved, or Not Achieved. Meeting the required levels is typically a prerequisite for NHS data sharing agreements, commissioning contracts, and connection to NHS systems such as HSCN.
The CAF groups those outcomes under five objectives — A Managing risk, B Protecting against cyber attack and data breaches, C Detecting cyber security events, D Minimising the impact of incidents, and E Using and sharing information appropriately.
Each objective groups a set of principles and contributing outcomes. Each outcome is rated Achieved, Partially Achieved, or Not Achieved.
Objective A
Objective B
Objective C
Objective D
Objective E
New DSPT submission cycle opens — review previous year actions and improvement plans
Begin systematic evidence collection against all CAF contributing outcomes
Complete cyber security evidence (Cyber Essentials, pen test reports)
Training completion drive — target 95%+ staff completion
Board review session; SIRO confirms evidence sufficiency
Internal audit of evidence quality; address any gaps
Final evidence review; prepare for submission
Submit — target the required Achieved levels by the 30 June deadline
The DSPT (v8) contributing outcomes pre-mapped to Folelse features — no manual mapping required.
Attach documents, screenshots, and records directly to each contributing outcome as evidence.
Real-time completion dashboard shows where you stand against the submission deadline.
Export a full evidence pack for your SIRO review or external IG audit.
The DSPT annual submission deadline is typically 30 June each year — 30 June 2026 for the 2025/26 edition. NHS England may adjust deadlines, so always check the official DSPT website for the current cycle dates.
The 2025/26 DSPT (v8) is aligned to the NCSC Cyber Assessment Framework (CAF). It is assessed across contributing outcomes grouped under five objectives (A–E), and each outcome is rated Achieved, Partially Achieved, or Not Achieved — the older "Standards Met / mandatory assertions" model has been retired. Organisations not yet meeting the required achievement levels submit an improvement plan; falling short may affect commissioning and information sharing agreements.
The Senior Information Risk Owner (SIRO) is ultimately accountable for the submission. In practice, the Data Protection Officer or Information Governance Manager typically leads the evidence collection and submission process, with sign-off from the SIRO and board.
All NHS Trusts, GP Practices, CSUs, NHS England arms-length bodies, and organisations processing NHS patient data under a Data Sharing Agreement must complete the DSPT. Many independent sector providers working for the NHS are also required to submit.
No — the DSPT submission is made directly on the NHS Digital portal by your SIRO or nominated submitter. Folelse helps you prepare the evidence, track completion, and link evidence to each contributing outcome, making the submission process significantly faster and audit-ready.
Folelse pre-loads the current DSPT (v8) contributing outcomes and maps platform features to the relevant evidence. For example, your ROPA module evidence links to the outcomes under Objective E (using and sharing information), and your policies and risk register link to outcomes under Objectives A and B (managing risk, protecting against cyber attack).
Related resources