DSPT 2026-27: The 12 Mandatory Audit Areas for IT Suppliers
What is the DSPT 2026-27 audit for IT suppliers?
On 1 October 2026, NHS England published the mandatory audit scope for the Data Security and Protection Toolkit (DSPT) 2026-27 cycle.
If you're an IT supplier to the NHS (Category 2 in DSPT terms), your submission will no longer be taken on trust: an independent auditor must check it against 12 fixed assertions, covering everything from staff training to firewall management to supplier due diligence. Get these 12 areas wrong, or fail to evidence them properly, and you risk a "Standards Not Met" result, and with it, your ability to supply systems or services into the NHS.
Why IT suppliers get audited and other organisations don't (always)
Most DSPT submitters self-assess. NHS Trusts, ICBs and other large bodies already arrange an independent audit of their whole toolkit as standard practice. IT suppliers sit in a different position: NHS England treats you as part of the supply chain risk it has to manage, so your assertions can't just be self-declared and filed away. An approved independent auditor has to verify a fixed set of them, following NHS England's Strengthening Assurance Independent Assessment Guide, and report the results with due regard made to the findings.
The detailed audit guidance specific to IT suppliers for 2026-27 "will be shared shortly" by NHS England, but the 12 mandatory areas are already confirmed. Waiting for the detailed guide before you start preparing isn't a great strategy, because most of these 12 areas take weeks, not days, to put right if you're starting from a gap.
The 12 mandatory audit areas for IT suppliers
|
Ref |
Assertion |
What the auditor checks |
|---|---|---|
|
1.1 |
Lawfulness, Fairness and Transparency |
ICO registration, a documented record of what personal data you hold and why, a published privacy notice, and classified/owned hardware and software assets |
|
2.2 |
Staff contracts set out data security responsibilities |
Every employment contract contains data security requirements |
|
3.1 |
IG and cyber security training and awareness |
A formally endorsed training needs analysis covering all staff roles, evidence training is followed, and how you evaluate it |
|
3.2 |
Proactive engagement, open and just culture |
Board or senior leadership actively prioritise information governance and cyber security |
|
4.1 |
Current record of staff and roles |
You understand who has access to personal and confidential data through your systems |
|
6.2 |
Anti-virus and email protections |
AV installed, kept updated, scanning on access, malicious sites blocked, plus DMARC, DKIM, SPF and spam/malware filtering on email |
|
7.1 |
Planned incident response |
You understand the services you provide or support, with well-defined continuity processes for a data security incident |
|
8.1 |
Software and hardware surveyed |
Tracked, recorded software assets, end-user devices and removable media |
|
8.2 |
Unsupported software managed |
A prioritised list of unsupported software with a remediation plan, and SIRO sign-off reported to the board |
|
9.2 |
Penetration testing |
Annual pen test scoped between the SIRO, business and testing team, including a vulnerability scan and default-password checks, with SIRO review of the results and an action plan |
|
9.6 |
Well-managed firewall |
Boundary firewalls installed, admin interfaces locked down, default-deny inbound rules, documented/approved rule changes, regular ruleset reviews, and personal firewalls on endpoints |
|
10.2 |
Basic supplier due diligence |
Your own IT system suppliers hold appropriate certification, and you understand/record which security responsibilities stay with you versus an outsourced provider |
How to prepare before the detailed guidance lands
- Map your evidence against all 12 areas now. Don't wait for NHS England's IT supplier-specific audit guide; the assertions are already published, and most of the evidence is stuff you should hold anyway.
- Book your annual penetration test early (area 9.2). Auditors want to see it scoped jointly by your SIRO, the business and the testing team, with a vulnerability scan and default-password checks included, not just a tick-box scan. Periculo's CREST-accredited penetration testing covers exactly this scope.
- Get your unsupported software estate documented (8.1/8.2), with a remediation plan your SIRO has actually signed off and reported to the board.
- Formalise supplier due diligence (10.2): check your own IT suppliers hold Cyber Essentials, Cyber Essentials Plus, ISO 27001 or DSPT Standards Met/Exceeded, and record who owns which security responsibility where anything is outsourced. Periculo's Cyber Essentials certification is a quick route to evidencing this for your own supply chain too.
- Refresh training records and board engagement evidence (3.1, 3.2, 4.1): a training needs analysis that was signed off two years ago and never revisited won't hold up.
- Get independent eyes on the whole submission before the auditor does. Periculo's NHS DSPT audit service reviews your evidence against the mandatory scope and flags gaps while you still have time to close them.
FAQs
How many assertions must be independently audited under DSPT 2026-27 for IT suppliers?
Who counts as an "IT supplier" under DSPT?
Does self-assessment still count for anything?
What happens if an IT supplier fails the audit?
When is the detailed IT supplier audit guidance due?
Is a penetration test always required?
Need an audit? Get in touch and we'll review your DSPT submission against the full mandatory scope.