The Data Security and Protection Toolkit for 2026-27 went live on 4 September 2026. Version 9 is now aligned to the Cyber Assessment Framework (CAF) version 4.0, and organisations have until 30 June 2027 to complete their assessment.
If you're an IT supplier to health and care, here's the part worth knowing early: most of what's new for you this year has already been published, but the specific areas NHS England will select for mandatory audit haven't been, yet.
NHS England has published the updated Outcomes, Assertions and Evidence items for version 9, with downloadable spreadsheets covering NHS Trusts, ICBs, ALBs, CSUs, OES and Genomics organisations, plus separate versions for IT Suppliers, dentists, GPs, local authorities, opticians, pharmacies, social care providers and universities.
The headline change is the shift from CAF v3.2 to CAF v4.0. The security framework DSPT is built on. Alongside that, a changelog is available showing exactly what's moved between version 8 and version 9, so organisations can see precisely what's new before they start evidencing.
For Category 2 IT Suppliers specifically, the evidence requirements are already out, and there's a fair amount to get ahead of:
None of that depends on what comes next. It's confirmed, it's published, and it can be actioned now.
Separately, NHS England has confirmed the mandatory audit areas for this cycle but only for NHS Trusts, ICBs, ALBs, CSUs, OES and Genomics organisations. Those organisations must audit 11 mandatory outcomes (covering areas including roles and responsibilities, asset management, privileged user and identity access management, understanding your data, secure management, organisational culture, training, monitoring capability, testing and exercising, and records management), plus one further outcome of their own choosing. There's also guidance on which optional outcome different organisation types should lean towards. Backups for OES and Genomics organisations, Response Plan for Trusts, ICBs, ALBs and CSUs, and Risk Management Process for CNI operators.
The audit areas for IT Suppliers have not been included in this announcement. NHS England has said these will be shared separately, so as things stand, suppliers know what they need to evidence for 26-27, but not yet which of it will be selected for independent audit.
Waiting for the audit scope isn't a reason to wait on the evidence itself. If you supply software or services into health and care, it's worth using this gap to:
We'll publish a follow-up as soon as NHS England confirms the mandatory audit areas for IT Suppliers.