DSPT 2025/26: What GRC Leaders Need to Get Right Before 30 June
A practical guide for care homes, charities, community services, and other NHS-aligned organisations on completing the Data Security and Protection Toolkit before the deadline.
What is the DSPT and why does it apply to your organisation?
A mandatory annual self-assessment required by NHS England for any organisation that handles health or care data, connects to NHS systems, or delivers services under an NHS or local authority contract. It measures performance against the National Data Guardian’s ten data security standards.
The DSPT applies well beyond NHS Trusts. If your organisation handles patient or service user data, or operates under an NHS or local authority contract, you are required to complete it. That includes:
- Care homes and residential care providers
- Domiciliary and home care services
- Charities delivering health or care services
- Community service providers
- Hospices and specialist care organisations
- GP practices and primary care networks
- Community pharmacy organisations
Most of these organisations submit under Category 3 of the framework. The assessment is not a tick-box exercise. It requires evidence that your controls are genuinely in place and working.
The deadline for final submission is 30 June 2026. Missing or failing the submission has immediate operational consequences, not gradual ones.
If the deadline landed next week, would you be ready?
Most organisations do not ignore DSPT. It sits on the list, gets discussed, and there is usually a broad expectation that it will get done.
Then June arrives and the tone changes.
Questions start surfacing that no one can answer quickly. Where is the training evidence? Who last reviewed access permissions? Has anyone checked whether your suppliers meet the required standard?
At that point, the issue is whether the organisation can stand behind what it believes is in place. That gap between belief and proof is where pressure builds and where risk sits.
DSPT 2025/26 Evidence Checklist
A printable checklist mapping every Category 3 mandatory evidence item to where it typically lives. Used by our own consultants on engagements.
Why DSPT carries more weight than most compliance work
Many compliance frameworks allow for a degree of slippage. A delayed internal audit or a late policy review tends to have a gradual impact. DSPT does not work that way. It is tied directly to your ability to operate within the NHS ecosystem. If a submission is not completed, or if compliance falls short, the consequences are immediate:
- Access to NHSmail can be restricted, disrupting day-to-day communications
- Connectivity to NHS systems and the Spine can be affected
- Care providers can lose visibility of critical patient information
- Pharmacies may be unable to process certain prescriptions
- Contract renewals and commissioning approvals can be delayed or blocked
For anyone with responsibility for governance, risk, or compliance, whether that is a Finance Director, Operations Director, or a senior manager, this is not an abstract risk. It sits close to day-to-day operations, which makes the June deadline far more significant than it might initially appear.
What has actually changed for 2025/26
On paper, the updates look measured. But several changes have a meaningful practical effect, and the underlying shift is significant: the DSPT now expects you to evidence that controls are working, not just that they exist on paper.
For example, in earlier versions you could meet the training requirement by stating that staff had access to e-learning. Under 2025/26, you need records showing who completed what, when, and how any gaps were managed. The same shift applies across access control, asset registers, and supplier assurance.
The toolkit now aligns more closely with the NCSC Cyber Assessment Framework. It is no longer enough to state that a policy exists. You are expected to demonstrate that controls are working in practice and being maintained over time. If your organisation already holds Cyber Essentials Plus or ISO 27001, much of this evidence will already exist in a usable form.
Where the real work sits
The questions in the toolkit are the straightforward part. The effort sits in gathering and validating the evidence behind them.
Training records
Often spread across different systems or held informally. The DSPT requires you to show who completed what, when, and how gaps were addressed.
Access control
Understood operationally but formal reviews and audit trails are harder to demonstrate. Access must be actively managed, not just assumed to be correct.
Policies and documentation
Often exist but may not have been reviewed recently, updated to reflect current practice, or formally acknowledged by staff.
Asset registers
Frequently incomplete or based on an out-of-date snapshot. A maintained register reviewed in the last 12 months is now a mandatory requirement.
Individually, none of these gaps are difficult to address. Together, they create friction, particularly when time is limited. This is why leaving DSPT to June consistently creates pressure that could have been avoided.
The supplier question that catches organisations out
DSPT does not stop at your internal controls. It extends to the organisations you rely on to deliver IT services, host systems, or manage data on your behalf.
Under the 2025/26 requirements, supplier contracts must now comply with GDPR and reflect DSPT completion requirements. That creates a clear shift in accountability. Even where your internal position is strong, gaps in supplier assurance still sit with your organisation.
For those responsible for GRC, this raises a straightforward but uncomfortable question: you may trust your providers based on experience, but can you evidence that trust in a way that stands up to scrutiny?
If the answer is uncertain, that needs to be addressed before submission, not during it.
Completing DSPT is not the same as being confident in it
It is possible to complete DSPT and still feel uneasy about the result.
That tends to happen when the focus is on getting through the process rather than understanding what sits behind it. Evidence is gathered, documents are uploaded, and the submission is made, but there is still a sense that it was held together rather than fully controlled.
Confidence is different. It comes from knowing that training is genuinely embedded, that system access is actively managed, that asset registers are current, and that plans exist in a form that could be put to use under pressure. The submission itself is a requirement. The underlying position is what determines how the organisation responds if something goes wrong.
If the deadline were brought forward by a week, would you be confident?
Most organisations understand what DSPT requires. If you are uncertain about your current position, that uncertainty is where the risk sits today. A short readiness review gives you a clear answer without a drawn-out engagement.
Or email hello@bondgate.co.uk
A more controlled way to approach the next few weeks
With the deadline approaching, the aim is not perfection. It is to regain control of the process and reach a submission you can stand behind.
Confirm your current position
Identify your DSPT category, review the evidence you already hold, and map where the gaps sit. You cannot address what you have not assessed.
Address the high-impact areas first
Training records, access control, asset registers, and MFA have the greatest effect when resolved early. These are also the areas most commonly queried on submission.
Update policies and documentation
Ensure they reflect what is actually happening in the organisation, not what was intended when they were written. Review supplier contracts against the new requirements.
Prepare for submission
Organise evidence so it aligns clearly with the toolkit, check for consistency, and make sure what is presented can be explained if challenged.
Inside the Bondgate IT Readiness Review
A focused 90-minute session with one of our DSPT specialists. No charge, no obligation, no procurement involvement required.
- ✓Confirmation of your DSPT category and scope
- ✓Gap assessment against the 2025/26 mandatory items
- ✓Review of existing evidence and where it falls short
- ✓Top three risks for your organisation, documented
- ✓Prioritised action list with realistic timescales
- ✓Written summary you can take to your senior leadership
How Bondgate IT supports this process
Bondgate IT works with care homes, charities, community service providers, and other NHS-aligned organisations managing competing operational priorities. DSPT is rarely the only pressure point, which is why it often gets pushed later than it should.
DSPT readiness assessment
We assess where you are, identify what is missing, and give you a clear picture of your position before you commit to a submission.
Technical controls
Access control, MFA, asset register management, and vulnerability scanning. We put the technical foundations in place and document them properly.
Governance and documentation
Policies, training records, incident response plans, and supplier contracts reviewed and updated to meet the 2025/26 requirements.
Submission support
We help you organise evidence, align it to the toolkit, and ensure the submission reflects reality rather than something held together under pressure.
The aim is not to take ownership away from your team. It is to ensure that when you submit, you understand what sits behind it and can stand behind it with confidence.
Frequently asked questions about DSPT
Do care homes have to complete the DSPT?
Does the DSPT apply to charities working with the NHS?
What happens if we miss the DSPT deadline?
How long does DSPT take to complete?
What is the difference between DSPT and the Cyber Assessment Framework?
Can Bondgate IT help us complete the DSPT?
Not sure where you stand? Start with clarity.
A short readiness review gives you a clear view of your current DSPT position, the gaps that need attention, and the next steps required to reach a confident submission. No drawn-out engagement. Just a straight answer.
Bondgate IT is ISO 27001 and Cyber Essentialscertified, with over 26 years supporting regulated organisations across the UK.