Periculo Blog

Does DSPT Require Penetration Testing?

Written by Craig Pepper | Sep 22, 2026, 6:00:00 AM

What Every Organisation Needs to Know

Under Data Security Standard 9 (IT Protection), assertion 9.2 requires an annual penetration test, scoped in negotiation between the SIRO, the business and the testing team, and including a vulnerability scan plus a check that default passwords on networking components have been changed.

This isn't a requirement that only applies to IT suppliers. NHS England's own Standard 9 guidance frames it as applying to every organisation handling health and social care information, with the detail of how it's met varying by organisation type and size.

What does change by organisation type is who can carry out the test, and how much scrutiny the resulting evidence needs to survive.

What assertion 9.2 actually asks for

Per NHS England's Standard 9 guidance, there are three legitimate ways to meet this requirement: commission a commercial specialist, use in-house capability if you genuinely have it, or "buddy up" with another health or care organisation and test each other's systems. There's no blanket rule in the assertion itself that every organisation must use an external tester.

Findings matter as much as the test itself. Anything rated critical or high risk needs remediating within 14 days, or the risk has to be documented and formally accepted by the SIRO. A test report with no remediation evidence behind it doesn't satisfy the assertion on its own.

Who this applies to

The assertion-based version of DSPT, the one where you'll see "assertion 9.2" by name, covers Category 2 IT suppliers, and Category 3/4 organisations including GPs, dentists, opticians, pharmacies, social care providers, local authorities and universities. If your organisation completes this version of the toolkit, penetration testing evidence is expected from you directly, not just from suppliers.

Larger NHS bodies, trusts, integrated care boards, arm's-length bodies, commissioning support units, genomics organisations and OES-designated providers now complete a CAF-aligned version of DSPT, built around Objectives, Principles and Outcomes rather than the old assertion numbers.

The underlying expectation that IT systems are tested for vulnerabilities still sits within that structure, just under different terminology, so "assertion 9.2" isn't the reference point for these organisations, even though the same broad principle applies.

Why the bar is higher for IT suppliers in practice

The assertion doesn't name IT suppliers specifically as needing an independent tester, but Category 2 suppliers have their overall DSPT submission independently audited rather than self-assessed, and that changes what "good enough" evidence looks like in practice.

An external assessor reviewing a supplier's submission is far less likely to accept an in-house test as adequate proof than a self-assessing organisation would be reviewing its own evidence internally.

So while the rulebook technically allows in-house or buddy-up testing, independent commercial testing is the safer, often effectively necessary route for suppliers specifically, because it's their evidence that has to survive someone else's scrutiny.

DSPT vs DTAC: two different penetration testing requirements

This is where a lot of suppliers get tangled up, because DTAC (the Digital Technology Assessment Criteria) has its own, separate penetration testing requirement and the two get treated as interchangeable when they're not.

DTAC's cyber security component asks for the results of an external, manual penetration test and a documented action plan for findings, as part of assessing a specific product being procured or assessed for use by an NHS organisation.

DSPT's assertion 9.2, by contrast, is an annual toolkit requirement covering your organisation's systems, submitted as part of your yearly DSPT assessment.

In practice, a well-scoped penetration test can often support both, but they sit in different processes, on different timelines, assessed by different people. Don't assume a pentest done for one automatically closes out the other; check what each specifically asks you to evidence before assuming coverage.

When to book it in

DSPT 26-27 has to be completed by 30 June 2027, and that date creeps up faster than it looks. CREST-accredited penetration testers, especially, book up well in advance of the deadline crunch, and a rushed test with unremediated findings can do more harm to your submission than not having one booked at all: remember, anything critical or high risk needs fixing within 14 days of the test, or signed-off SIRO acceptance in its place.

If you're an IT supplier and not currently Cyber Essentials Plus certified, it's worth looking at alongside this: CE+ maps to a meaningful chunk of the wider Category 2 evidence set, though it doesn't replace the assertion 9.2 penetration testing requirement itself.

What to do next

  • If you're a Category 2 IT supplier, treat independent commercial testing as the default rather than the exception, given your submission is independently audited.
  • Make sure findings come with a documented remediation plan, and that anything critical or high risk is closed out within 14 days or formally risk-accepted by your SIRO.
  • If DTAC assessment also applies to any of your products, check its cyber security criteria separately rather than assuming your DSPT pentest already covers it.