Folelse
NHS Resources

DSPT Toolkit Guidance

A practical guide to the NHS Data Security and Protection Toolkit — what it covers, how to meet each CAF contributing outcome, and how Folelse makes submission faster and audit-ready.

What is it?

The Data Security and Protection Toolkit

The NHS Data Security and Protection Toolkit (DSPT) is an online self-assessment tool produced by NHS England. For 2025/26 the toolkit (v8) is aligned to the NCSC Cyber Assessment Framework (CAF) — replacing the earlier ten-standard, mandatory-assertion model.

All organisations that have access to NHS patient data and systems must complete the DSPT annually. The assessment is now made across contributing outcomes, each rated Achieved, Partially Achieved, or Not Achieved. Meeting the required levels is typically a prerequisite for NHS data sharing agreements, commissioning contracts, and connection to NHS systems such as HSCN.

The CAF groups those outcomes under five objectives — A Managing risk, B Protecting against cyber attack and data breaches, C Detecting cyber security events, D Minimising the impact of incidents, and E Using and sharing information appropriately.

The five objectives

CAF objectives & contributing outcomes

Each objective groups a set of principles and contributing outcomes. Each outcome is rated Achieved, Partially Achieved, or Not Achieved.

Objective A

Managing risk

  • Board-level accountability, with SIRO/SRO sign-off
  • Information risk assessed and managed across the organisation
  • Asset register covering data, systems and services
  • Supply-chain assurance — DPAs in place for all data processors

Objective B

Protecting against cyber attack and data breaches

  • Identity and access control — least privilege and MFA
  • Data protected in transit and at rest (encryption)
  • Secure configuration and timely security-update management
  • Mandatory staff data security training (95%+ completion)

Objective C

Detecting cyber security events

  • Security monitoring and logging across key systems
  • Alerting for anomalous or malicious activity
  • Regular review of security events and logs
  • Proactive discovery of threats and vulnerabilities

Objective D

Minimising the impact of incidents

  • Incident response plan documented, tested and rehearsed
  • Business continuity and disaster recovery plans
  • Backups and restoration with defined RTO/RPO
  • Post-incident review and lessons-learned process

Objective E

Using and sharing information appropriately

  • Register of processing activities (ROPA) maintained
  • Records management and retention schedules enforced
  • National Data Opt-Out applied to relevant data
  • Sharing governed by agreements and a lawful basis
Planning

Recommended submission timeline

April

New DSPT submission cycle opens — review previous year actions and improvement plans

May

Begin systematic evidence collection against all CAF contributing outcomes

June

Complete cyber security evidence (Cyber Essentials, pen test reports)

July–Aug

Training completion drive — target 95%+ staff completion

Sep–Oct

Board review session; SIRO confirms evidence sufficiency

Nov–Dec

Internal audit of evidence quality; address any gaps

Jan–Mar

Final evidence review; prepare for submission

March

Submit — target the required Achieved levels by the 30 June deadline

How Folelse helps

Accelerate your DSPT submission

Pre-loaded outcomes

The DSPT (v8) contributing outcomes pre-mapped to Folelse features — no manual mapping required.

Evidence linking

Attach documents, screenshots, and records directly to each contributing outcome as evidence.

Progress dashboard

Real-time completion dashboard shows where you stand against the submission deadline.

Audit-ready export

Export a full evidence pack for your SIRO review or external IG audit.

Frequently asked questions

What is the DSPT submission deadline?

The DSPT annual submission deadline is typically 30 June each year — 30 June 2026 for the 2025/26 edition. NHS England may adjust deadlines, so always check the official DSPT website for the current cycle dates.

How is the DSPT assessed now?

The 2025/26 DSPT (v8) is aligned to the NCSC Cyber Assessment Framework (CAF). It is assessed across contributing outcomes grouped under five objectives (A–E), and each outcome is rated Achieved, Partially Achieved, or Not Achieved — the older "Standards Met / mandatory assertions" model has been retired. Organisations not yet meeting the required achievement levels submit an improvement plan; falling short may affect commissioning and information sharing agreements.

Who is responsible for the DSPT submission?

The Senior Information Risk Owner (SIRO) is ultimately accountable for the submission. In practice, the Data Protection Officer or Information Governance Manager typically leads the evidence collection and submission process, with sign-off from the SIRO and board.

Which organisations must complete the DSPT?

All NHS Trusts, GP Practices, CSUs, NHS England arms-length bodies, and organisations processing NHS patient data under a Data Sharing Agreement must complete the DSPT. Many independent sector providers working for the NHS are also required to submit.

Can Folelse submit the DSPT on my behalf?

No — the DSPT submission is made directly on the NHS Digital portal by your SIRO or nominated submitter. Folelse helps you prepare the evidence, track completion, and link evidence to each contributing outcome, making the submission process significantly faster and audit-ready.

How does Folelse map to the CAF contributing outcomes?

Folelse pre-loads the current DSPT (v8) contributing outcomes and maps platform features to the relevant evidence. For example, your ROPA module evidence links to the outcomes under Objective E (using and sharing information), and your policies and risk register link to outcomes under Objectives A and B (managing risk, protecting against cyber attack).

Related resources