CYBER CERTIFICATION

NHS Data Security and Protection Toolkit (DSPT) Independent Audit

What is the NHS Data Security and Protection Toolkit (DSPT) Independent Audit?

The NHS Data Security and Protection Toolkit (DSPT) Independent Audit is a mandatory, formal review of how organisations, including healthcare providers and IT suppliers, protect NHS patient data. From 2024, the audit is now aligned with the UK Government’s Cyber Assessment Framework (CAF), raising the bar for cyber resilience and aligning health and care cybersecurity with wider critical national infrastructure standards.

How does it work?

The audit is based on CAF-aligned controls, which now underpin the DSPT’s implementation of the 10 National Data Guardian Standards. It covers a broad range of areas such as risk management, access control, data sharing, incident response, and cyber threat defence.

Organisations must first complete their DSPT self-assessment on the NHS Toolkit portal. If classified as a large organisation or IT supplier handling NHS data, you are then subject to an annual third-party independent audit conducted by a qualified assessor. The audit confirms whether your submitted evidence truly meets DSPT’s CAF-aligned expectations, and whether key risks to NHS data are effectively managed.

Downloads

  • tbc

Where is this required?

  • Required for organisations with a DSPT status of “Standards Met” and that:
    • Handle NHS data under contract
    • Are classed as large providers or suppliers
    • Are IT service or software vendors hosting NHS patient data
  • Must align with the CAF-based DSPT standards
  • Audit is required annually and must follow submission of the self-assessment

Why use StarSwift?

We specialise in helping healthcare organisations and IT suppliers navigate the new CAF-aligned DSPT audit process. We can assist with readiness assessments, evidence alignment, risk gap analysis, and coordination of the independent audit, ensuring a confident, compliant outcome that supports your ongoing NHS contracts.

Align with CAF. Build trust with NHS partners. Protect patient data.

With the new DSPT audit framework grounded in the Cyber Assessment Framework, achieving compliance means showing operational and technical maturity. Whether you’re a care provider or an NHS IT supplier, passing the audit proves your organisation is serious about data protection and resilient to cyber threats.

Aligned with the Cyber Assessment Framework (CAF)

Demonstrates cyber maturity in line with UK Critical National Infrastructure (CNI) standards, not just box-ticking.

Mandatory for NHS DSPT “Standards Met” submissions

Applies to large care organisations and IT suppliers hosting NHS data.

Supports secure NHS contract delivery

A gateway to gaining or retaining NHS data access and commercial engagements.

End-to-end support from StarSwift

We handle everything from audit readiness to evidence mapping and assessor engagement.

Improves governance and public confidence

Strengthens your position as a secure, trustworthy partner to the NHS.

Get A Quote

Get a NHS DSPT Independent Audit Quote

Get in touch today to find out more about the NHS Data Security and Protection Toolkit (DSPT) Independent Audit, and how the we can help your organisation.

Contact Us

Contact Form Demo

Have Any Questions?

Find the most frequently asked questions and find your answer

What’s changed with the DSPT audit?

From 2024, the audit is now aligned with the UK Cyber Assessment Framework (CAF), expanding focus from compliance to cyber resilience.

Who needs to complete the audit?

Large NHS providers and IT suppliers who declare “standards met” in the DSPT and handle NHS patient data.

What is CAF and why is it important?

The Cyber Assessment Framework is the UK’s official standard for assessing cyber risk in critical sectors like health, energy, and finance. NHS England now uses it to benchmark DSPT audit compliance.

Are software and cloud providers included?

Yes. IT suppliers managing, storing, or transmitting NHS data must undergo the audit.

How does StarSwift help?

We provide expert-led DSPT readiness reviews, evidence mapping to CAF, and support through the full audit lifecycle.

Is the audit different from ISO 27001?

Yes. While ISO 27001 is helpful, the DSPT audit is NHS-specific and now aligned with CAF controls — including NHS data sharing, patient privacy, and operational resilience.

What if we don’t pass the audit?

NHS England may downgrade your DSPT status, pause data access, or suspend contracts until remediation is complete.

Can StarSwift work with IT teams directly?

Absolutely. We collaborate with your in-house IT and governance leads to ensure audit readiness from both a technical and policy perspective.

Does the audit help with GDPR and DPA 2018?

Yes. The DSPT and CAF standards reflect many legal obligations under UK GDPR and the Data Protection Act.

How long does it take to complete the audit?

With good preparation, the audit typically takes 2–4 weeks from readiness to final report.

What our customers say

Musketeer Solutions

Business Director Peterborough, Management Consultancy East Anglia

We are incredibly pleased with the outstanding service provided by Rob Lancaster of StarSwift in supporting us through the Cyber Essentials certification process and delivering ongoing IT security services.  Rob has worked with us for several years and established an excellent understanding of our business and requirements.

Hallinans

Namita, Managing Director

We were fortunate to be invited to work with Rob and he made the process seamless, straightforward and without the jargon and complication that often comes which computers and technology. Rob’s knowledge is first rate as is his swift communication and competitive pricing. Options were always provided to us along with reasoning and recommendation. Cannot recommend Rob and StarSwift highly enough. 

Lone Star Analysis

Kat Simmonds, CoS

Well organised, Rob is very clear in his explanations and communicates well throughout the assessment.

Growth Studio Group

Andy Bennett, Director

Rob was extremely helpful and responsive to questions we had with our Cyber Essentials Certification. It made the whole process seamless. 

Related Articles