Only suppliers that meet all three of NHS England's IT Supplier criteria need a DSPT independent audit:
50 or more staff, a turnover of £10m or more, and supplying digital goods or services to the NHS or care.
Those organisations select Supplier as their Primary Sector, complete the large assessment of 102 evidence items, and must be audited. Everyone else selects Other, completes a smaller assessment of 45 evidence items, and is not required to complete an audit.
We asked NHS Digital directly because this is the question we're asked most often by suppliers starting DSPT 26-27, and the answers online don't all agree. Here's what they told us, and how to work out which side of the line you sit on.
NHS England confirmed to us that the audit requirement follows the Primary Sector an organisation selects in the toolkit, and that the Primary Sector follows the IT Supplier criteria.
|
Supplier (Category 2) |
Other (Category 3) |
|
|---|---|---|
|
Who selects it |
Meets all three criteria: 50+ staff, £10m+ turnover, supplies digital goods or services to the NHS and/or care |
Doesn't meet all three criteria |
|
Assessment size |
Large: 102 evidence items |
Smaller: 45 evidence items |
|
Independent audit |
Required |
Not required |
This matches the organisation type guidance published on the DSPT website, which says a company meeting all of the criteria should select Supplier, and one that doesn't should select Other (including charities, some companies and NHS Business Partners). The toolkit then serves Category 2 evidence items to Supplier and Category 3 items to Other.
Two details matter here. "Digital" covers both software and physical goods, so hardware suppliers count. And the criteria are joined by "and", not "or": a 200-person company turning over £8m is not a Supplier for DSPT purposes.
Answer these in order. A single "no" means you select Other.
1. Do you supply digital goods or services to the NHS and/or care? Software, SaaS, hosting, infrastructure and physical digital products all count.
2. Do you have 50 or more staff?
3. Is your turnover £10m or more?
Three yeses: select Supplier, complete 102 evidence items, and book an independent audit before your 30 June 2027 submission.
Any no's: select Other, complete 45 evidence items, with no audit required.
One exception to keep in mind: independent providers formally designated as Operators of Essential Services (OES) under the NIS Regulations follow their own route and complete the CAF-aligned toolkit, regardless of headcount or turnover.
Many digital health and SaaS companies pick Supplier simply because they supply software to the NHS. Without the staff and turnover thresholds, that's the wrong Primary Sector, and it commits you to more than double the evidence items plus an audit you aren't required to have.
The opposite mistake happens too. A growing supplier that crossed 50 staff and £10m turnover during the year may still have Other selected from a previous submission. Check your Primary Sector against your current numbers before you start, because switching late means re-evidencing against a different item set.
The independent audit is evidenced through sub-assertion 9.4.5, and the auditor reviews whether your evidence holds up, not just whether it exists. For 2026-27, the large assessment also brings new mandatory items, including MFA or identity federation on supplied software (4.5.6) and alignment with the Software Security Code of Practice (9.5.11).
NHS England hasn't yet published which areas will be selected for mandatory audit for IT Suppliers this cycle. That's a reason to start evidencing now rather than wait, so the audit becomes a review rather than a rush.
If you select Other, you don't need an independent audit, and you shouldn't buy one on the assumption that DSPT demands it. A well-evidenced self-assessment against the 45 items is what the toolkit asks of you. That said, there are three reasons smaller suppliers still invest in assurance.
1. Getting your 45 items right first time. A self-assessment is only as good as its evidence. If NHS customers query your status, or you later grow into Supplier, gaps become visible fast. Readiness support helps you evidence the smaller assessment properly, without overbuilding.
2. A voluntary audit as a procurement differentiator. Your DSPT status is publicly searchable, and NHS buyers increasingly ask for more than a self-assessment. An independent review of your submission gives procurement teams third-party evidence your competitors may not have, and prepares you for the full audit if you cross the Supplier thresholds.
3. Penetration testing and Cyber Essentials Plus as evidence you still need. No audit doesn't mean no testing. Assertion 9.2 asks for an annual penetration test across the assertion-based toolkit, including Category 3. And Cyber Essentials Plus is commonly requested in NHS supplier assurance and DTAC, independently of DSPT.
Periculo can help you meet DSPT evidence item 9.4.5 with an independent audit of your submission. As a CREST-accredited penetration testing provider and IASME-licensed Certification Body, we work with suppliers across digital health.
If you don't need an audit, we can still review your DSPT submission before you publish it, to make sure your evidence supports a Standards Met status.
Not sure which one you are? Get in touch, and we'll help you confirm your Primary Sector before you start evidencing.