Skip to main content

econestech.com

NHS Data Security and Protection Toolkit:Complete Guide for GP and Dental Practices

The DSPT is mandatory for every NHS-connected organisation. The 2025/26 final deadline is 30 June 2026. This guide explains exactly what it is, who needs it, and how to complete it.

The nhs data security and protection toolkit is an annual online self-assessment that every organisation accessing NHS patient data or systems must complete. Missing the submission deadline can result in losing access to NHSmail, e-Referrals, and other NHS systems your practice depends on. This guide covers what the DSPT requires, who needs to complete it, and how to approach the submission as a GP or dental practice.

What the nhs data security and protection toolkit is

The DSPT is an online self-assessment provided by NHS England that measures your organisation against the 10 National Data Guardian (NDG) data security standards. It was introduced in 2018 to replace the previous Information Governance Toolkit and has been updated annually since. Version 8, released September 2025, introduced significant changes including alignment with the NCSC Cyber Assessment Framework for some organisation categories and mandatory independent audits for Category 1 and 2 organisations.

Nhs dspt guidance is published on the DSPT website and updated with each version. The data security and protection toolkit guidance for 2025/26 differs from previous years in several important ways — particularly the requirement for outcome-based evidence. Nhs digital data security standards now require you to show that controls actually work, not just that policies exist. Organisations cannot simply repeat last year’s submission without reviewing what has changed.

How to complete the NHS DSPT: step by step

01

Register and Identify Your Category

Access the DSPT portal at dsptoolkit.nhs.uk and register your organisation. Your organisation category determines which assessment framework applies. Most small NHS practices fall into Category 3 or Category 4, using the NDG 10 Standards framework, while larger organisations may fall into Category 1 or Category 2, requiring CAF alignment and independent audits.

Identifying the correct category is the essential first step. Choosing the wrong category can result in completing the wrong assessment and delay your compliance process.

02

Gather Evidence Before Starting

The DSPT requires outcome-based evidence to support every assertion you make. Common examples include annual staff data security training records, user access documentation, incident and near-miss logs, supplier contracts with data security clauses, and technical configuration records.

Collecting all required documentation before beginning the assessment makes the process much smoother. Under the NHS Digital Data Security Standards for 2025/26, the quality and completeness of your evidence play a major role in achieving a successful submission.

03

Complete Mandatory Items and Submit Before the DSPT Deadline

The DSPT distinguishes between mandatory and non-mandatory requirements. To achieve Standards Met status, every mandatory item must be completed and supported with appropriate evidence.

For the 2025/26 assessment cycle, the interim baseline submission deadline was 31 December 2025, while the final DSPT deadline is 30 June 2026. Missing these deadlines may affect access to NHS systems depending on your organisation category, so beginning the assessment 8–12 weeks in advance provides enough time to resolve any compliance gaps.

Frequently asked questions

What happens if a GP practice misses the DSPT deadline?

Failure to submit by 30 June 2026 can result in loss of access to NHSmail, e-Referrals, and other NHS systems. For some NHS contracts, DSPT compliance is a contractual requirement. Consequences vary by organisation type but disruption to clinical operations is a real risk for any NHS-connected practice.

Has the nhs data security and protection toolkit changed significantly for 2025/26?

Yes. Version 8 (September 2025) was the most significant update since the toolkit launched. CAF alignment was extended, evidence expectations became more specific and outcome-based, mandatory independent audits were added for Category 1 and 2, and an interim baseline submission by December 2025 was introduced. Organisations cannot use their 2024/25 submission approach without reviewing the nhs digital security standards changes introduced in version 8.

Can I complete the DSPT myself or do I need outside help?

Smaller practices with good existing documentation sometimes complete it themselves — though it takes several focused days. The main challenge for most practices is not the submission itself but having the underlying evidence in place. Training records, access documentation, tested backups — practices that lack these benefit most from professional dspt assessment help to build the evidence base first.

How to complete nhs dspt for a small dental practice?

Register on dsptoolkit.nhs.uk, identify your category (typically Category 3 or 4 for small dental practices), collect your evidence, complete all mandatory items, and submit before 30 June 2026. The most time-consuming parts are collecting staff training records and documenting your systems and access controls. Starting 8 to 10 weeks before the deadline allows sufficient preparation time.

// Let's talk about your business

Want help putting this into practice?

We handle every part of dental SEO so you can focus on your patients. Book a free audit to get started.