Jessica Entwistle
October 9 2026
IT Governance UK has published guidance on the NHS Data Security and Protection Toolkit (DSPT) requirements for the 2026/27 submission period. The DSPT is the mandatory self-assessment framework that all organisations processing NHS patient data must complete annually to demonstrate they are meeting data security and protection standards. The guidance outlines updated expectations, key deadlines and areas where organisations commonly struggle to meet compliance requirements. For many UK businesses that provide services to the NHS, including IT suppliers, managed service providers, software vendors and outsourced support organisations, DSPT compliance is a contractual and regulatory requirement. Failure to achieve the required standards can result in loss of contracts, reputational damage and regulatory scrutiny.
The DSPT is not a one-off exercise but an ongoing governance commitment that requires organisations to demonstrate they have appropriate policies, training, technical controls and incident response processes in place throughout the year. For businesses new to NHS work or those that have struggled with previous submissions, understanding what evidence is required and where gaps exist is essential to maintaining contracts and avoiding compliance issues. The toolkit covers areas including access controls, data protection impact assessments, staff training, incident management, business continuity and secure data handling, many of which align with broader good practice but require specific evidence and documentation for NHS purposes. The 2026/27 submission period may include updated expectations or clarifications on areas where organisations have previously struggled, making it important to review the guidance early and plan accordingly. For organisations that supply multiple NHS trusts or bodies, ensuring consistent compliance across all contracts and understanding how evidence can be reused or adapted is also an important consideration. The DSPT is increasingly seen as a baseline standard for organisations handling sensitive health data, and demonstrating compliance can also support broader assurance and due diligence processes beyond NHS contracts.
UK organisations that supply or support the NHS should review whether DSPT submission plans are in place, whether evidence gathering has started, and whether the organisation has the governance, technical controls and documentation required to meet the standards. Consider whether responsibility for DSPT compliance is clearly assigned, whether internal teams understand what is expected, and whether there is a process for coordinating evidence collection across IT, HR, governance and operational teams. Organisations should also consider whether they have addressed any gaps or issues identified in previous submissions, and whether policies, training records, risk assessments and technical controls are up to date and documented in a way that meets DSPT requirements. Where organisations are new to NHS work or have not previously completed the DSPT, consider whether external support or guidance is needed to understand the requirements and avoid common pitfalls. This is also a prompt to review whether incident response, business continuity and data protection processes are documented and tested, and whether staff training on data security and confidentiality is current and evidenced. Organisations should also consider whether they have a clear understanding of the submission deadline and whether there is sufficient time to address any gaps or gather missing evidence before the assessment is due.
Source: IT Governance UK