Skip to content
All posts

DSPT 2026-27: The 12 Mandatory Audit Areas for IT Suppliers

What is the DSPT 2026-27 audit for IT suppliers?

On 1 October 2026, NHS England published the mandatory audit scope for the Data Security and Protection Toolkit (DSPT) 2026-27 cycle.

If you're an IT supplier to the NHS (Category 2 in DSPT terms), your submission will no longer be taken on trust: an independent auditor must check it against 12 fixed assertions, covering everything from staff training to firewall management to supplier due diligence. Get these 12 areas wrong, or fail to evidence them properly, and you risk a "Standards Not Met" result, and with it, your ability to supply systems or services into the NHS.

Why IT suppliers get audited and other organisations don't (always)

Most DSPT submitters self-assess. NHS Trusts, ICBs and other large bodies already arrange an independent audit of their whole toolkit as standard practice. IT suppliers sit in a different position: NHS England treats you as part of the supply chain risk it has to manage, so your assertions can't just be self-declared and filed away. An approved independent auditor has to verify a fixed set of them, following NHS England's Strengthening Assurance Independent Assessment Guide, and report the results with due regard made to the findings.

The detailed audit guidance specific to IT suppliers for 2026-27 "will be shared shortly" by NHS England, but the 12 mandatory areas are already confirmed. Waiting for the detailed guide before you start preparing isn't a great strategy, because most of these 12 areas take weeks, not days, to put right if you're starting from a gap.

The 12 mandatory audit areas for IT suppliers

Ref

Assertion

What the auditor checks

1.1

Lawfulness, Fairness and Transparency

ICO registration, a documented record of what personal data you hold and why, a published privacy notice, and classified/owned hardware and software assets

2.2

Staff contracts set out data security responsibilities

Every employment contract contains data security requirements

3.1

IG and cyber security training and awareness

A formally endorsed training needs analysis covering all staff roles, evidence training is followed, and how you evaluate it

3.2

Proactive engagement, open and just culture

Board or senior leadership actively prioritise information governance and cyber security

4.1

Current record of staff and roles

You understand who has access to personal and confidential data through your systems

6.2

Anti-virus and email protections

AV installed, kept updated, scanning on access, malicious sites blocked, plus DMARC, DKIM, SPF and spam/malware filtering on email

7.1

Planned incident response

You understand the services you provide or support, with well-defined continuity processes for a data security incident

8.1

Software and hardware surveyed

Tracked, recorded software assets, end-user devices and removable media

8.2

Unsupported software managed

A prioritised list of unsupported software with a remediation plan, and SIRO sign-off reported to the board

9.2

Penetration testing

Annual pen test scoped between the SIRO, business and testing team, including a vulnerability scan and default-password checks, with SIRO review of the results and an action plan

9.6

Well-managed firewall

Boundary firewalls installed, admin interfaces locked down, default-deny inbound rules, documented/approved rule changes, regular ruleset reviews, and personal firewalls on endpoints

10.2

Basic supplier due diligence

Your own IT system suppliers hold appropriate certification, and you understand/record which security responsibilities stay with you versus an outsourced provider

 

How to prepare before the detailed guidance lands

  1. Map your evidence against all 12 areas now. Don't wait for NHS England's IT supplier-specific audit guide; the assertions are already published, and most of the evidence is stuff you should hold anyway.
  2. Book your annual penetration test early (area 9.2). Auditors want to see it scoped jointly by your SIRO, the business and the testing team, with a vulnerability scan and default-password checks included, not just a tick-box scan. Periculo's CREST-accredited penetration testing covers exactly this scope.
  3. Get your unsupported software estate documented (8.1/8.2), with a remediation plan your SIRO has actually signed off and reported to the board.
  4. Formalise supplier due diligence (10.2): check your own IT suppliers hold Cyber Essentials, Cyber Essentials Plus, ISO 27001 or DSPT Standards Met/Exceeded, and record who owns which security responsibility where anything is outsourced. Periculo's Cyber Essentials certification is a quick route to evidencing this for your own supply chain too.
  5. Refresh training records and board engagement evidence (3.1, 3.2, 4.1): a training needs analysis that was signed off two years ago and never revisited won't hold up.
  6. Get independent eyes on the whole submission before the auditor does. Periculo's NHS DSPT audit service reviews your evidence against the mandatory scope and flags gaps while you still have time to close them.

FAQs

How many assertions must be independently audited under DSPT 2026-27 for IT suppliers?
Twelve, published by NHS England on 1 October 2026: 1.1, 2.2, 3.1, 3.2, 4.1, 6.2, 7.1, 8.1, 8.2, 9.2, 9.6 and 10.2.
Who counts as an "IT supplier" under DSPT?
DSPT Category 2 organisations: businesses supplying IT systems, software or IT support services to NHS organisations, where those systems could affect care delivery or process personal identifiable data.
Does self-assessment still count for anything?
Yes. The 12 areas above are the fixed mandatory scope an independent auditor must check; the rest of your DSPT submission is still self-assessed, though a full submission review before the auditor's visit catches most inconsistencies early.
What happens if an IT supplier fails the audit?
The DSPT status moves to "Standards Not Met" or similar, visible to NHS organisations assessing you as a supplier, which can affect existing contracts and new procurement opportunities.
When is the detailed IT supplier audit guidance due?
NHS England has said guidance specific to IT suppliers "will be shared shortly" after the 1 October 2026 announcement of the mandatory areas; check the DSPT Toolkit news page for updates.
Is a penetration test always required?
Yes, for IT suppliers it's one of the 12 mandatory areas (9.2): an annual test scoped jointly by the SIRO, the business and the testing team, including a vulnerability scan.

Need an audit? Get in touch and we'll review your DSPT submission against the full mandatory scope.