On 1 October 2026, NHS England published the mandatory audit scope for the Data Security and Protection Toolkit (DSPT) 2026-27 cycle.
If you're an IT supplier to the NHS (Category 2 in DSPT terms), your submission will no longer be taken on trust: an independent auditor must check it against 12 fixed assertions, covering everything from staff training to firewall management to supplier due diligence. Get these 12 areas wrong, or fail to evidence them properly, and you risk a "Standards Not Met" result, and with it, your ability to supply systems or services into the NHS.
Most DSPT submitters self-assess. NHS Trusts, ICBs and other large bodies already arrange an independent audit of their whole toolkit as standard practice. IT suppliers sit in a different position: NHS England treats you as part of the supply chain risk it has to manage, so your assertions can't just be self-declared and filed away. An approved independent auditor has to verify a fixed set of them, following NHS England's Strengthening Assurance Independent Assessment Guide, and report the results with due regard made to the findings.
The detailed audit guidance specific to IT suppliers for 2026-27 "will be shared shortly" by NHS England, but the 12 mandatory areas are already confirmed. Waiting for the detailed guide before you start preparing isn't a great strategy, because most of these 12 areas take weeks, not days, to put right if you're starting from a gap.
|
Ref |
Assertion |
What the auditor checks |
|---|---|---|
|
1.1 |
Lawfulness, Fairness and Transparency |
ICO registration, a documented record of what personal data you hold and why, a published privacy notice, and classified/owned hardware and software assets |
|
2.2 |
Staff contracts set out data security responsibilities |
Every employment contract contains data security requirements |
|
3.1 |
IG and cyber security training and awareness |
A formally endorsed training needs analysis covering all staff roles, evidence training is followed, and how you evaluate it |
|
3.2 |
Proactive engagement, open and just culture |
Board or senior leadership actively prioritise information governance and cyber security |
|
4.1 |
Current record of staff and roles |
You understand who has access to personal and confidential data through your systems |
|
6.2 |
Anti-virus and email protections |
AV installed, kept updated, scanning on access, malicious sites blocked, plus DMARC, DKIM, SPF and spam/malware filtering on email |
|
7.1 |
Planned incident response |
You understand the services you provide or support, with well-defined continuity processes for a data security incident |
|
8.1 |
Software and hardware surveyed |
Tracked, recorded software assets, end-user devices and removable media |
|
8.2 |
Unsupported software managed |
A prioritised list of unsupported software with a remediation plan, and SIRO sign-off reported to the board |
|
9.2 |
Penetration testing |
Annual pen test scoped between the SIRO, business and testing team, including a vulnerability scan and default-password checks, with SIRO review of the results and an action plan |
|
9.6 |
Well-managed firewall |
Boundary firewalls installed, admin interfaces locked down, default-deny inbound rules, documented/approved rule changes, regular ruleset reviews, and personal firewalls on endpoints |
|
10.2 |
Basic supplier due diligence |
Your own IT system suppliers hold appropriate certification, and you understand/record which security responsibilities stay with you versus an outsourced provider |
Need an audit? Get in touch and we'll review your DSPT submission against the full mandatory scope.