The short answer: The DSPT (Data Security and Protection Toolkit) is NHS England’s online self-assessment of how well an organisation protects personal data. Care providers complete a version with 45 mandatory questions to reach Standards Met, and must republish it every year by 30 June; the current 2026-27 toolkit is due by 30 June 2027. It is a contractual requirement if you deliver NHS-funded care, it is needed to use NHS systems such as NHS.net Connect and GP Connect, and it is expected of every CQC-registered care provider.
Last updated: 30 September 2026. Checked against the DSPT website, NHS England guidance and the Better Security, Better Care programme on that date.
In this guide
- What is the DSPT?
- Do care homes have to complete it?
- Deadlines and versions
- The status levels
- What the 45 questions cover
- The IT questions, and who does the work
- How Cyber Essentials fits in
- Free help for care providers
- Frequently asked questions
What is the DSPT?
The Data Security and Protection Toolkit is, in NHS England’s words, “an online self-assessment tool that enables organisations to measure and publish their performance against the National Data Guardian’s ten data security standards”. You answer questions about how your organisation handles personal information and protects its IT, upload or describe your evidence, and publish the result. Published statuses can be looked up on the DSPT website, so commissioners and NHS partners can check yours.
Health organisations such as NHS trusts now complete a longer version aligned to the NCSC’s Cyber Assessment Framework. Adult social care is not part of that change: NHS England says the change affects a specific group of large health and care organisations, and social care providers, GPs, dentists and pharmacies still complete the assertion and evidence version of the toolkit.
Do care homes have to complete the DSPT?
It depends on how you work with the NHS, but in practice almost every care provider should complete it. The position is:
| Your situation | What applies |
|---|---|
| You deliver care under the NHS Standard Contract, for example continuing healthcare | A contractual requirement to complete and publish the DSPT every year |
| You want NHS.net Connect (formerly NHSmail) | You need at least Approaching Standards |
| You want GP Connect, a shared care record or proxy access to GP records | You need Standards Met |
| You want to be counted as fully digitised under the government’s Digitising Social Care programme | You need Standards Met plus an assured digital social care record |
| You hold local authority contracts | Some councils require it in their contracts, so check yours |
| None of the above | Strongly recommended, and increasingly expected by CQC |
The NHS Standard Contract is explicit: “The Provider must complete and publish an annual information governance assessment in accordance with, and comply with the mandatory requirements of, the NHS Data Security and Protection Toolkit” (General Condition 21.2, 2026/27). Official sources differ on whether every other care provider is obliged to complete it: the Digitising Social Care programme says all CQC-regulated adult social care providers must, while Better Security, Better Care describes it as strongly recommended. Either way, the safe assumption is that it is expected.
CQC links it directly to leadership. Its Well-led quality statement on governance lists “Cyber security and data security and protection toolkit (DSPT)” as a topic inspectors look at (CQC assessment framework). CQC is piloting new sector-specific assessment frameworks in 2026, so the exact wording may change.
When is the DSPT deadline?
The deadline is 30 June every year. A new version of the toolkit is released each year, usually in September: the 2026-27 version (version 9) was released in September 2026, and NHS England confirms that the deadline is 30 June 2027.
Publishing once is not enough. Your assessment must be reviewed, updated and republished at least once a year, otherwise it goes out of date and no longer counts, as Digital Care Hub explains. Many providers leave it until June; starting in the autumn gives time to fix the IT gaps properly rather than writing an action plan for them.
What are the DSPT status levels?
When you publish, the toolkit gives you one of these statuses, set out in the DSPT help pages:
| Status | What it takes | Notes for care providers |
|---|---|---|
| Approaching Standards | The 26 questions mandatory at this level, plus an uploaded action plan | Available to social care as a one-off, for your first publication only; you cannot republish at this level |
| Standards Met | All 45 mandatory questions answered | The level to aim for, and the one needed for GP Connect and shared care records |
| Standards Exceeded | Standards Met plus a current Cyber Essentials Plus certificate recorded in your profile | Shows the strongest assurance to commissioners |
What do the 45 mandatory questions cover?
Digital Care Hub groups the care provider questions into four areas. These are the main things you will need to show for 2026-27, with the question numbers used in the toolkit. Always check the exact wording in the toolkit itself, because it changes each year.
Staffing and roles
- Security owned and directed by senior leaders, with regular discussion at that level (1.1.5).
- Data security requirements in every employment contract and volunteer agreement (2.2.1).
- Data security and cyber security covered at induction (2.1.1).
- At least 95% of staff, directors, trustees and volunteers trained in data security and protection in the last twelve months (3.2.1).
Policies and procedures
- Your ICO registration number (1.1.1).
- An up-to-date information asset register and record of processing activities (1.1.2).
- A privacy notice, data protection policies and a records retention and destruction process.
- A list of your suppliers, and assurance that your IT suppliers take cyber security seriously (10.1.2 and 10.2.1).
Data security
- A system for reporting data breaches (6.1.1). Incidents are reported through the toolkit, and a notifiable breach must reach the ICO without undue delay, normally within 72 hours.
- A business continuity plan that covers data and cyber security (7.1.2), which has been tested (7.2.1).
- Emergency contact details kept somewhere you can reach them if your systems are down (7.3.2).
IT systems and devices
This is often the section where care providers need help, because it depends on how your IT is set up. It is covered in detail below.
Which DSPT questions are about IT, and who does the work?
Many of the mandatory questions are about devices, accounts, backups and software. Someone in your organisation completes the toolkit, but the evidence for these usually has to come from whoever runs your IT:
| Question | What it asks | What your IT provider should give you |
|---|---|---|
| 4.2.4 | Access removed or changed when staff leave or change role | A leavers process and a record that accounts are disabled promptly |
| 4.5.3 | Multi-factor authentication on all remotely accessible accounts | MFA enforced on Microsoft 365, email and remote access, with a report to prove it |
| 4.3.1 | Administrators sign an accountability agreement | Separate admin accounts, and a signed agreement for anyone who has one |
| 6.2.1 | Up-to-date antivirus on all devices | Managed endpoint protection with a device report |
| 7.1.1 | A register of your digital assets | An up-to-date list of every laptop, PC, tablet, phone and system |
| 7.3.1 and 7.3.4 | Secure backups of important data, and tested restores | Independent backups, including Microsoft 365, and a record of a test restore |
| 8.1.4 | All IT systems and software still supported by the manufacturer, or the risks understood and managed | Evidence that nothing is out of support, such as old Windows versions |
| 8.3.5 | Updates installed promptly | Patching reports showing security updates are applied |
| 9.1.1 | Default router and network passwords changed | Confirmation for every router, firewall and Wi-Fi access point |
| 9.5.2 | Laptops, tablets and removable devices encrypted | BitLocker or equivalent enforced, with a report |
Question 8.1.4 is worth checking now. Windows 10 stopped receiving free security updates in October 2025, so any care office PC still running it needs upgrading or paid extended updates. See our Windows 10 end of life guide.
Email matters too. Emails exchanged with health and social care organisations must meet the secure email standard (DCB1596). NHS.net Connect meets it, and NHS England names Microsoft 365 and Google Workspace as able to meet it when they are configured correctly.
How does Cyber Essentials fit with the DSPT?
Cyber Essentials is not mandatory for the DSPT, but it helps. According to the DSPT FAQs, organisations that hold Cyber Essentials Plus are exempt from some toolkit questions, and the DSPT status rules give Standards Exceeded to organisations with Standards Met and a current Cyber Essentials Plus certificate. The exemptions apply to Cyber Essentials Plus only, as Digital Care Hub explains.
The two overlap heavily: multi-factor authentication, supported software, patching, antivirus and account control appear in both. If you are working towards one, the same IT work counts towards the other. Our Cyber Essentials requirements guide explains the 2026 rules.
Where can care providers get free DSPT help?
The government funds free support through Better Security, Better Care. DHSC has confirmed £21 million to March 2029 to continue it, delivered by Digital Care Hub and the National Care Association. It offers a helpline on 0808 196 4848, templates, e-learning and local support organisations. In our area, the local partner for East and West Sussex and Brighton and Hove is West Sussex Partners in Care.
Take-up is high and rising. By 30 June 2026, almost 76.5% of CQC-registered adult social care services in England had an up-to-date DSPT: 22,429 services, including 12,887 care homes. A DHSC-commissioned survey found that a third of care providers had experienced a cyber incident or unsuccessful attack in the previous three years, and phishing was involved in three quarters of those.
ATS Connection looks after IT, Microsoft 365 and cyber security for care providers across Sussex. For the DSPT, we handle the IT side: multi-factor authentication, patching, encryption, backups and device records, and we give your DSPT lead the evidence they need for those questions. See our IT support for care homes and IT support for healthcare, or book a free IT review to find out where you stand.
Frequently asked questions
What is the DSPT?
The Data Security and Protection Toolkit is NHS England’s online self-assessment against the National Data Guardian’s ten data security standards. Organisations answer questions about how they protect personal data and IT, provide evidence and publish the result each year.
Is the DSPT mandatory for care homes?
It is a contractual requirement for providers delivering care under the NHS Standard Contract, and it is needed to use NHS systems such as NHS.net Connect and GP Connect. For other CQC-registered providers, the government’s Digitising Social Care programme says it is required, while Better Security, Better Care describes it as strongly recommended. Either way, CQC expects to see it.
When is the DSPT deadline?
30 June every year. The deadline for the 2026-27 toolkit is 30 June 2027. Your assessment must be republished at least annually or it goes out of date.
How many mandatory questions are there for care providers?
For 2026-27, care providers answer 45 mandatory questions to reach Standards Met, and 26 of them are mandatory for Approaching Standards.
What is the difference between Approaching Standards and Standards Met?
Approaching Standards is a one-off status for a care provider’s first publication, needing 26 questions and an action plan. Standards Met needs all 45 mandatory questions, and is required for GP Connect and shared care records.
Does Cyber Essentials count towards the DSPT?
Cyber Essentials Plus exempts you from some DSPT questions, and combined with Standards Met it gives Standards Exceeded. The exemptions are for Cyber Essentials Plus only, but the IT controls in basic Cyber Essentials help with both.
Who can help with the DSPT for free?
Better Security, Better Care offers free help to adult social care providers, including a helpline on 0808 196 4848, templates and local support partners. In Sussex, the local partner is West Sussex Partners in Care.
Sources
- NHS England Digital: Data Security and Protection Toolkit
- DSPT: publication statuses
- DSPT: 2026-27 toolkit release
- NHS England: NHS Standard Contract 2026/27, shorter-form General Conditions
- DSPT: access to shared systems
- GOV.UK: Digital social care records, choosing and implementing solutions
- Digitising Social Care: fully digitised FAQs for care providers
- CQC: Well-led, governance, management and sustainability
- Digital Care Hub: about the DSPT
- Digital Care Hub: answering the DSPT questions
- Digital Care Hub: publishing or republishing your DSPT
- Digital Care Hub: record numbers of care services have a DSPT
- DSPT: frequently asked questions
- NHS England: CAF-aligned DSPT, evolution of our assurance model
- NHS England Digital: the secure email standard
- Digital Care Hub: £21m confirmed for Better Security, Better Care
- DHSC: Understanding the state of cyber security in adult social care
Free • 12 minutes • Written PDF report
Who actually holds the keys to your systems?
List the systems your business runs, answer plain-English questions about how they are controlled, and get a report with a red, amber and green rating for every area and what to fix first. Nothing on your systems is touched.
Cyber Essentials certified · Microsoft Partner · rated 5.0 on Google
