<15 min Response

20+ Years Experience

Cyber Essentials Certified

Check Your IT Score

Remote SOS Support

DSPT for Care Homes: A Plain-English Guide to the Data Security and Protection Toolkit

IT and data security for care homes

The short answer: The DSPT (Data Security and Protection Toolkit) is NHS England’s online self-assessment of how well an organisation protects personal data. Care providers complete a version with 45 mandatory questions to reach Standards Met, and must republish it every year by 30 June; the current 2026-27 toolkit is due by 30 June 2027. It is a contractual requirement if you deliver NHS-funded care, it is needed to use NHS systems such as NHS.net Connect and GP Connect, and it is expected of every CQC-registered care provider.

Last updated: 30 September 2026. Checked against the DSPT website, NHS England guidance and the Better Security, Better Care programme on that date.

In this guide

What is the DSPT?

The Data Security and Protection Toolkit is, in NHS England’s words, “an online self-assessment tool that enables organisations to measure and publish their performance against the National Data Guardian’s ten data security standards”. You answer questions about how your organisation handles personal information and protects its IT, upload or describe your evidence, and publish the result. Published statuses can be looked up on the DSPT website, so commissioners and NHS partners can check yours.

Health organisations such as NHS trusts now complete a longer version aligned to the NCSC’s Cyber Assessment Framework. Adult social care is not part of that change: NHS England says the change affects a specific group of large health and care organisations, and social care providers, GPs, dentists and pharmacies still complete the assertion and evidence version of the toolkit.

Do care homes have to complete the DSPT?

It depends on how you work with the NHS, but in practice almost every care provider should complete it. The position is:

Your situationWhat applies
You deliver care under the NHS Standard Contract, for example continuing healthcareA contractual requirement to complete and publish the DSPT every year
You want NHS.net Connect (formerly NHSmail)You need at least Approaching Standards
You want GP Connect, a shared care record or proxy access to GP recordsYou need Standards Met
You want to be counted as fully digitised under the government’s Digitising Social Care programmeYou need Standards Met plus an assured digital social care record
You hold local authority contractsSome councils require it in their contracts, so check yours
None of the aboveStrongly recommended, and increasingly expected by CQC
Sources: NHS Standard Contract 2026/27, the DSPT access to shared systems guidance, GOV.UK and Better Security, Better Care.

The NHS Standard Contract is explicit: “The Provider must complete and publish an annual information governance assessment in accordance with, and comply with the mandatory requirements of, the NHS Data Security and Protection Toolkit” (General Condition 21.2, 2026/27). Official sources differ on whether every other care provider is obliged to complete it: the Digitising Social Care programme says all CQC-regulated adult social care providers must, while Better Security, Better Care describes it as strongly recommended. Either way, the safe assumption is that it is expected.

CQC links it directly to leadership. Its Well-led quality statement on governance lists “Cyber security and data security and protection toolkit (DSPT)” as a topic inspectors look at (CQC assessment framework). CQC is piloting new sector-specific assessment frameworks in 2026, so the exact wording may change.

When is the DSPT deadline?

The deadline is 30 June every year. A new version of the toolkit is released each year, usually in September: the 2026-27 version (version 9) was released in September 2026, and NHS England confirms that the deadline is 30 June 2027.

Publishing once is not enough. Your assessment must be reviewed, updated and republished at least once a year, otherwise it goes out of date and no longer counts, as Digital Care Hub explains. Many providers leave it until June; starting in the autumn gives time to fix the IT gaps properly rather than writing an action plan for them.

What are the DSPT status levels?

When you publish, the toolkit gives you one of these statuses, set out in the DSPT help pages:

StatusWhat it takesNotes for care providers
Approaching StandardsThe 26 questions mandatory at this level, plus an uploaded action planAvailable to social care as a one-off, for your first publication only; you cannot republish at this level
Standards MetAll 45 mandatory questions answeredThe level to aim for, and the one needed for GP Connect and shared care records
Standards ExceededStandards Met plus a current Cyber Essentials Plus certificate recorded in your profileShows the strongest assurance to commissioners
Question counts for 2026-27 from Digital Care Hub; status definitions from the DSPT help pages.

What do the 45 mandatory questions cover?

Digital Care Hub groups the care provider questions into four areas. These are the main things you will need to show for 2026-27, with the question numbers used in the toolkit. Always check the exact wording in the toolkit itself, because it changes each year.

Staffing and roles

  • Security owned and directed by senior leaders, with regular discussion at that level (1.1.5).
  • Data security requirements in every employment contract and volunteer agreement (2.2.1).
  • Data security and cyber security covered at induction (2.1.1).
  • At least 95% of staff, directors, trustees and volunteers trained in data security and protection in the last twelve months (3.2.1).

Policies and procedures

  • Your ICO registration number (1.1.1).
  • An up-to-date information asset register and record of processing activities (1.1.2).
  • A privacy notice, data protection policies and a records retention and destruction process.
  • A list of your suppliers, and assurance that your IT suppliers take cyber security seriously (10.1.2 and 10.2.1).

Data security

  • A system for reporting data breaches (6.1.1). Incidents are reported through the toolkit, and a notifiable breach must reach the ICO without undue delay, normally within 72 hours.
  • A business continuity plan that covers data and cyber security (7.1.2), which has been tested (7.2.1).
  • Emergency contact details kept somewhere you can reach them if your systems are down (7.3.2).

IT systems and devices

This is often the section where care providers need help, because it depends on how your IT is set up. It is covered in detail below.

Which DSPT questions are about IT, and who does the work?

Many of the mandatory questions are about devices, accounts, backups and software. Someone in your organisation completes the toolkit, but the evidence for these usually has to come from whoever runs your IT:

QuestionWhat it asksWhat your IT provider should give you
4.2.4Access removed or changed when staff leave or change roleA leavers process and a record that accounts are disabled promptly
4.5.3Multi-factor authentication on all remotely accessible accountsMFA enforced on Microsoft 365, email and remote access, with a report to prove it
4.3.1Administrators sign an accountability agreementSeparate admin accounts, and a signed agreement for anyone who has one
6.2.1Up-to-date antivirus on all devicesManaged endpoint protection with a device report
7.1.1A register of your digital assetsAn up-to-date list of every laptop, PC, tablet, phone and system
7.3.1 and 7.3.4Secure backups of important data, and tested restoresIndependent backups, including Microsoft 365, and a record of a test restore
8.1.4All IT systems and software still supported by the manufacturer, or the risks understood and managedEvidence that nothing is out of support, such as old Windows versions
8.3.5Updates installed promptlyPatching reports showing security updates are applied
9.1.1Default router and network passwords changedConfirmation for every router, firewall and Wi-Fi access point
9.5.2Laptops, tablets and removable devices encryptedBitLocker or equivalent enforced, with a report
Question numbers and summaries from Digital Care Hub’s 2026-27 guidance.

Question 8.1.4 is worth checking now. Windows 10 stopped receiving free security updates in October 2025, so any care office PC still running it needs upgrading or paid extended updates. See our Windows 10 end of life guide.

Email matters too. Emails exchanged with health and social care organisations must meet the secure email standard (DCB1596). NHS.net Connect meets it, and NHS England names Microsoft 365 and Google Workspace as able to meet it when they are configured correctly.

How does Cyber Essentials fit with the DSPT?

Cyber Essentials is not mandatory for the DSPT, but it helps. According to the DSPT FAQs, organisations that hold Cyber Essentials Plus are exempt from some toolkit questions, and the DSPT status rules give Standards Exceeded to organisations with Standards Met and a current Cyber Essentials Plus certificate. The exemptions apply to Cyber Essentials Plus only, as Digital Care Hub explains.

The two overlap heavily: multi-factor authentication, supported software, patching, antivirus and account control appear in both. If you are working towards one, the same IT work counts towards the other. Our Cyber Essentials requirements guide explains the 2026 rules.

Where can care providers get free DSPT help?

The government funds free support through Better Security, Better Care. DHSC has confirmed £21 million to March 2029 to continue it, delivered by Digital Care Hub and the National Care Association. It offers a helpline on 0808 196 4848, templates, e-learning and local support organisations. In our area, the local partner for East and West Sussex and Brighton and Hove is West Sussex Partners in Care.

Take-up is high and rising. By 30 June 2026, almost 76.5% of CQC-registered adult social care services in England had an up-to-date DSPT: 22,429 services, including 12,887 care homes. A DHSC-commissioned survey found that a third of care providers had experienced a cyber incident or unsuccessful attack in the previous three years, and phishing was involved in three quarters of those.

ATS Connection looks after IT, Microsoft 365 and cyber security for care providers across Sussex. For the DSPT, we handle the IT side: multi-factor authentication, patching, encryption, backups and device records, and we give your DSPT lead the evidence they need for those questions. See our IT support for care homes and IT support for healthcare, or book a free IT review to find out where you stand.

Frequently asked questions

What is the DSPT?

The Data Security and Protection Toolkit is NHS England’s online self-assessment against the National Data Guardian’s ten data security standards. Organisations answer questions about how they protect personal data and IT, provide evidence and publish the result each year.

Is the DSPT mandatory for care homes?

It is a contractual requirement for providers delivering care under the NHS Standard Contract, and it is needed to use NHS systems such as NHS.net Connect and GP Connect. For other CQC-registered providers, the government’s Digitising Social Care programme says it is required, while Better Security, Better Care describes it as strongly recommended. Either way, CQC expects to see it.

When is the DSPT deadline?

30 June every year. The deadline for the 2026-27 toolkit is 30 June 2027. Your assessment must be republished at least annually or it goes out of date.

How many mandatory questions are there for care providers?

For 2026-27, care providers answer 45 mandatory questions to reach Standards Met, and 26 of them are mandatory for Approaching Standards.

What is the difference between Approaching Standards and Standards Met?

Approaching Standards is a one-off status for a care provider’s first publication, needing 26 questions and an action plan. Standards Met needs all 45 mandatory questions, and is required for GP Connect and shared care records.

Does Cyber Essentials count towards the DSPT?

Cyber Essentials Plus exempts you from some DSPT questions, and combined with Standards Met it gives Standards Exceeded. The exemptions are for Cyber Essentials Plus only, but the IT controls in basic Cyber Essentials help with both.

Who can help with the DSPT for free?

Better Security, Better Care offers free help to adult social care providers, including a helpline on 0808 196 4848, templates and local support partners. In Sussex, the local partner is West Sussex Partners in Care.

Sources

Free • 12 minutes • Written PDF report

Who actually holds the keys to your systems?

List the systems your business runs, answer plain-English questions about how they are controlled, and get a report with a red, amber and green rating for every area and what to fix first. Nothing on your systems is touched.

Cyber Essentials certified · Microsoft Partner · rated 5.0 on Google

Take the free IT Security Review

Free • No obligation • Senior engineer • 30 minutes

Want a straight answer about your own IT?

We look after IT, cyber security and phones for businesses across Sussex and the UK, on a fixed monthly price from £30 per user. Book a free review and a senior engineer will tell you plainly what is worth fixing first.

Your free IT review

  • Review WiFi, devices and network infrastructure
  • Benchmark Microsoft 365 and security posture
  • Assess backup, recovery and operational continuity
  • Map a clear, costed IT & security roadmap

Book your free IT & cyber review



Free, no obligation. We only use your details to arrange the review. Privacy policy.