Prepared: 16 September 2026 Status: Research analysis - no commitments made Audience: Alex / Cain / Jarvis co-pilot
1. What DSPT is
The Data Security and Protection Toolkit (DSPT) is NHS England’s online self-assessment for data security and protection. It replaced the IG Toolkit in 2018 and is the standard way organisations in health and care demonstrate they handle data responsibly. The current cycle is DSPT 2025-26 version 8, aligned to the NCSC’s Cyber Assessment Framework (CAF v3.4).
Key properties:
- Self-assessment for most organisation types - you declare compliance and upload evidence; there is no external auditor for standard submissions (independent assessment applies to NHS trusts and large IT suppliers only).
- Annual - submissions cover the financial year and are due 30 June each year. It expires; it is not a certificate you earn once.
- Evidence-based since v8 - each requirement is structured as Outcome > Assertion > Evidence item. “We have a policy” is no longer enough; you must show the policy works (training records, access review logs, screenshots, review dates).
Sources: https://www.dsptoolkit.nhs.uk/News/161 ; https://www.periculo.co.uk/cyber-security-blog/what-is-dspt-a-guide-for-digital-health-companies
2. Which track applies to Viewee
DSPT publishes organisation-type-specific assertion/evidence lists (IT Suppliers, Social care, GPs, Dentists, Pharmacy, Opticians, Local Authorities, Universities, Others).
- Viewee’s track: “IT Suppliers” (a software company supplying health/care organisations). Within that, requirements scale by size: large IT suppliers (50+ staff, >£10m turnover, established NHS contracts) face the full requirement set and independent audit; smaller suppliers like Viewee get the proportionate set - self-assessment, no mandatory audit.
- Viewee’s customers track: “Social care” - the care homes and home-care agencies Viewee sells to complete their own DSPT. This is why they will recognise and trust the badge.
- Strictly speaking, DSPT is mandatory for organisations accessing NHS patient data or systems. Viewee’s core data is social-care feedback, not NHS patient data - so DSPT is not legally forced on Viewee today. It becomes effectively mandatory through procurement: NHS bodies and an increasing share of care providers check DSPT status in due diligence, and assured-supplier routes (e.g. the Digital Social Care Records dynamic purchasing systems) list it among their assurance expectations. See NHSX’s Digital Social Care Record Systems DPS notice: https://www.find-tender.service.gov.uk/Notice/003785-2021/PDF
Bottom line: treat DSPT as required-in-practice. It is the recognised security badge in the exact market Viewee sells into.
3. What completing it takes (Category: small IT supplier)
Registration and governance basics
- ICO registration (data protection fee, ~£40/yr for small orgs)
- UK GDPR compliance artefacts: Record of Processing Activities (ROPA), published privacy notice, DPIA for high-risk processing (care feedback is health-adjacent special-category data - a DPIA is squarely required)
- Named data protection lead (can be a founder at this size)
Policy framework
- Data protection policy, information security policy, acceptable use policy, incident response plan, business continuity plan - each dated, owned, and reviewed within 12 months
Data documentation
- Data-flow map / system inventory: every system holding feedback data, what it holds, who accesses it
- Access control register + joiner/leaver process + admin account register (new emphasis in v8)
Technical controls
- MFA on all accounts, encryption at rest and in transit, patching regime, supported software only, firewall/AV, secure configuration of the SaaS stack
- Access reviews (at least annual) with evidence
People
- Data security training for all staff/contractors with completion records; confidentiality clauses in contracts
Incident readiness
- Incident response plan, breach-reporting process (72-hour ICO reporting), evidence of testing/review
Evidence volume for the proportionate IT-supplier track is in the tens of items, not hundreds; each item = document + proof it operates. See the category/evidence breakdown: https://dsptready.co.uk/blog/dspt-evidence-requirements/
4. Process, cost, timeline
| Aspect | Realistic answer |
|---|---|
| Submission cost | Free - the toolkit itself is an NHS England online tool |
| ICO registration | ~£40/yr (mandatory anyway) |
| Consultant (optional) | £2k-£10k typical for gap analysis + evidence support; NOT required for a small supplier self-assessment |
| Independent audit | Not required at Viewee’s size (required for large NHS trusts and large IT suppliers) |
| First-submission effort | 3-4 months elapsed is the consensus guidance for a first submission done properly; less if the policy/evidence base is built early |
| Ongoing | Annual renewal by 30 June; evidence must stay within 12-month review dates |
| Deadline risk | Missing 30 June leaves a visible gap in your public DSPT status during procurement checks |
Sequencing note: Viewee’s next 30 June deadline is 30 June 2027 (covering FY 2026-27). Starting the policy/evidence base NOW means the first submission is routine rather than a scramble; a submission can also be made mid-cycle and then renewed.
5. How care providers use DSPT in procurement
- As a checkbox in due diligence: care groups’ IT/compliance leads ask “do you have DSPT?” early; “Standards Met” answers it in one line.
- As a trust shortcut: providers complete the Social-care DSPT themselves; a supplier on the same framework speaks their language and de-risks the purchase conversation.
- In framework/assured-supplier routes: public and quasi-public buying routes for digital social care (DPS frameworks, ICB-backed procurement) name DSPT in their assurance requirements.
- In competitive positioning: most early-stage SaaS competitors will not have it; “DSPT Standards Met + Cyber Essentials” is a differentiator in a risk-averse, CQC-regulated market.
6. The honest fastest path
- Now (week 0-2): ICO registration; write the six core policies; data-flow map for the product as designed; name the data protection lead.
- Month 1-2: ROPA + DPIA for the feedback-processing product; access register; MFA everywhere; training records for the founding team.
- Month 2-3: incident response plan + one tabletop test; evidence file assembly; register on the DSPT portal and work the assertion list.
- Month 3-4: internal review against each evidence item (document
- proof); submit “Standards Met”.
- Ongoing: calendar the 30 June renewal; keep review dates fresh.
What NOT to do: claim DSPT before submitting (providers can check the public register); treat it as one-off paperwork (annual renewal, and v8 demands living evidence); buy a consultant before doing the free self-assessment groundwork (most of it is founder-doable at this size).
7. Interaction with the wider compliance stack
DSPT overlaps heavily with the Cyber Essentials / ISO 27001 work scoped separately: Cyber Essentials covers a large share of the technical-control evidence, and DSPT supplies the IG/GDPR documentation ISO 27001 will formalise later. Doing DSPT first is the cheapest way to build 60-70% of the evidence base the other two reuse.
Sources: dsptoolkit.nhs.uk (DSPT 2025-26 v8 announcement, assertion/evidence lists); digital.nhs.uk DSPT assessment guides and CAF-aligned independent assessment guidance; periculo.co.uk DSPT guide for digital health companies (2026); dsptready.co.uk evidence breakdown (reviewed Sept 2026); find-tender.service.gov.uk DSCR DPS notice. All retrieved 16 September 2026.
