NHS DSP Toolkit: What Suppliers Need to Know
If you hold NHS patient data or supply an organisation that does, the Data Security and Protection Toolkit is the assurance you will be asked for. It changed substantially in September 2024, and a lot of guidance still describes the old version. This covers what the toolkit is now, which version applies to you, what suppliers specifically are asked for, and what it takes if you are outside the UK.
What the toolkit is
The DSP Toolkit is an online self-assessment. Organisations use it to demonstrate how they handle personal and patient data, and completion is the standard evidence an NHS body asks for before sharing data or awarding a contract.
Everyone with access to NHS patient data and systems is in scope. That covers NHS trusts and foundation trusts, integrated care boards, commissioning support units, independent providers including operators of essential services, genomics organisations, local authorities, arm's length bodies of the Department of Health and Social Care, and key IT suppliers.
That last category is why this matters to organisations that have never thought of themselves as healthcare. If you host, process or support a system that touches patient data, you are a key IT supplier and you will be asked to complete it.
The change most guidance has not caught up with
In September 2024 the toolkit changed its basis for the largest organisations. NHS trusts and foundation trusts covering acute, mental health, community and ambulance services, along with integrated care boards, commissioning support units and DHSC arm's length bodies, moved onto a version aligned to the National Cyber Security Centre's Cyber Assessment Framework.
That is a structural change rather than a cosmetic one. The CAF-aligned toolkit is organised into objectives, principles and contributing outcomes rather than a list of assertions. There are 47 contributing outcomes, each supported by indicators of good practice, and each is assessed as achieved, partially achieved or not achieved.
The practical difference is that you are no longer confirming statements. You are evidencing outcomes, and an assessor can disagree with your rating. Organisations that could previously complete the toolkit in a fortnight of documentation have found the CAF-aligned version needs a genuine assessment.
Where an outcome is not achieved, an improvement plan is required setting out how and when it will be. That plan is itself an artefact your commissioners can read.
Which version applies to you
Large NHS organisations and the categories listed above are on the CAF-aligned toolkit. Smaller organisations, including GP practices, community pharmacy, social care providers and most IT suppliers, remain on the older assertion-based version for now.
Check which applies before you plan the work, because the effort differs by an order of magnitude. Preparing for 47 CAF outcomes assessed against indicators of good practice is a different project from confirming a set of assertions.
The submission runs on an annual cycle with a deadline at the end of June, and the assessment work sits in the months before it. Organisations that start in May routinely miss.
What this means if you are a supplier
You will be asked for your toolkit status by name, usually with a required standard such as standards met or approaching standards. It appears in procurement questionnaires and in data sharing agreements, and a missing or expired submission stops the conversation.
The common mistake is treating it as a form to fill in near the deadline. The evidence it asks for, access reviews, incident processes, business continuity testing, staff training records, is the output of things you either do throughout the year or do not.
If you already hold ISO 27001, you have most of the underlying machinery. What does not transfer is the specific structure and the NHS-specific expectations around patient data, national data opt-out handling and the Data Security and Protection requirements themselves. Treat it as a mapping exercise onto a management system you already run, not a fresh programme.
If you are outside the UK
Nothing about the toolkit requires a UK entity. Overseas suppliers processing NHS data complete it in the same way, and being remote is not a barrier to the assessment itself.
What does need attention is the surrounding position. Data residency expectations, the UK GDPR analysis for transfers out, and whether your subprocessors are visible and contractually bound all become live questions in a way they may not be in your home market. The toolkit will surface them, and it is better to have answers than to discover them mid-submission.
The other thing worth knowing early is that the CAF-aligned structure will be unfamiliar even to organisations with strong security programmes, because it is a UK public sector framework rather than an international standard. The controls will be recognisable. The vocabulary and the evidence expectations will not.
How we help
Usually as a mapping exercise. If you hold ISO 27001 or SOC 2, most of the substance exists and the work is expressing it in the toolkit's terms, finding the genuine gaps, and building the improvement plan for anything not yet achieved.
For organisations moving onto the CAF-aligned version for the first time, the useful work is an honest pre-assessment: rating yourself against the 47 outcomes before the submission window, so the improvement plan is deliberate rather than assembled under deadline.
Related services
Talk to an engineer
We respond to every enquiry within one business day, and return a scoped proposal with fixed pricing within 48 hours.
Book a discovery call