The NHS Data Security and Protection Toolkit (DSPT) is an online self-assessment tool that NHS organisations must complete annually. For 2025/26 (v8) it is aligned to the NCSC Cyber Assessment Framework (CAF). Folelse maps every CAF contributing outcome to the relevant data in your account, automatically linking evidence as you complete compliance activities.
The CAF groups contributing outcomes under five objectives (A–E). Each outcome is rated Achieved, Partially Achieved, or Not Achieved — replacing the older "Standards Met / mandatory assertions" model. For example, staff data security training sits under Objective B (protecting against cyber attack), and DPIAs and information-risk management sit under Objective A (managing risk).
Aim to reach the required achievement levels across the applicable contributing outcomes before your DSPT submission deadline. The DSPT deadline is typically 30 June each year (30 June 2026 for 2025/26), but check NHS England's current deadline.
Need more help with this?
Contact support