DSPT 2026-27 Is Live: What's Confirmed, and What IT Suppliers Are Still Waiting On...
The Data Security and Protection Toolkit for 2026-27 went live on 4 September 2026. Version 9 is now aligned to the Cyber Assessment Framework (CAF) version 4.0, and organisations have until 30 June 2027 to complete their assessment.
If you're an IT supplier to health and care, here's the part worth knowing early: most of what's new for you this year has already been published, but the specific areas NHS England will select for mandatory audit haven't been, yet.
What's confirmed for DSPT 26-27
NHS England has published the updated Outcomes, Assertions and Evidence items for version 9, with downloadable spreadsheets covering NHS Trusts, ICBs, ALBs, CSUs, OES and Genomics organisations, plus separate versions for IT Suppliers, dentists, GPs, local authorities, opticians, pharmacies, social care providers and universities.
The headline change is the shift from CAF v3.2 to CAF v4.0. The security framework DSPT is built on. Alongside that, a changelog is available showing exactly what's moved between version 8 and version 9, so organisations can see precisely what's new before they start evidencing.
For Category 2 IT Suppliers specifically, the evidence requirements are already out, and there's a fair amount to get ahead of:
- A new mandatory requirement (4.5.6) that software supplied to health and care organisations supports multi-factor authentication or identity federation to industry standards or has a credible, resourced plan to get there by 30 June 2027.
- A new mandatory requirement (9.5.11) that software is developed in line with the government's Software Security Code of Practice.
- A reworked requirement (9.5.10) around signing the Supply Chain Charter.
- A new "Products and Services" section, where suppliers declare each product or service they provide to health and care, along with its security controls, vulnerability management process, access controls, incident management process, and DTAC status.
- Two requirements dropped entirely for Category 2 (around NDG training and responding to a cyber alert) — a rare case of the toolkit asking for less.
None of that depends on what comes next. It's confirmed, it's published, and it can be actioned now.
What IT suppliers are still waiting on
Separately, NHS England has confirmed the mandatory audit areas for this cycle but only for NHS Trusts, ICBs, ALBs, CSUs, OES and Genomics organisations. Those organisations must audit 11 mandatory outcomes (covering areas including roles and responsibilities, asset management, privileged user and identity access management, understanding your data, secure management, organisational culture, training, monitoring capability, testing and exercising, and records management), plus one further outcome of their own choosing. There's also guidance on which optional outcome different organisation types should lean towards. Backups for OES and Genomics organisations, Response Plan for Trusts, ICBs, ALBs and CSUs, and Risk Management Process for CNI operators.
The audit areas for IT Suppliers have not been included in this announcement. NHS England has said these will be shared separately, so as things stand, suppliers know what they need to evidence for 26-27, but not yet which of it will be selected for independent audit.
What to do in the meantime
Waiting for the audit scope isn't a reason to wait on the evidence itself. If you supply software or services into health and care, it's worth using this gap to:
- Work through the 35 changed evidence items in the Category 2 spreadsheet and flag which ones need new evidence, new processes, or a conversation with your development team, the MFA/identity federation requirement in particular has a hard deadline attached.
- Draft your Products and Services entries now, while the detail is fresh, rather than leaving all of it until closer to submission.
- If you haven't already, get a penetration test booked in and, if you're not currently Cyber Essentials Plus certified, look at getting it in place. A pentest is mandatory evidence in its own right (assertion 9.2), slots book up well in advance of the June deadline, and Cyber Essentials Plus already covers a meaningful chunk of the Category 2 evidence items, so both are worth having sorted before audit scope is even confirmed.
- Keep an eye out for the audit areas announcement; we'll cover it here as soon as it lands.
We'll publish a follow-up as soon as NHS England confirms the mandatory audit areas for IT Suppliers.