Skip to content
All posts

How Cyber Essentials Plus Helps You Reach "Standards Exceeded" on the NHS DSPT

A current Cyber Essentials Plus certificate, combined with a "Standards Met" result, is enough on its own to move most organisations' NHS DSPT status to "Standards Exceeded."

Anyone working with the NHS or adult social care in England will eventually run into the Data Security and Protection Toolkit, better known as the DSPT. It is the annual self-assessment that measures your organisation against the National Data Guardian's 10 data security standards, and it is a condition of nearly every NHS service delivery contract.

What is less well understood is how directly Cyber Essentials Plus feeds into your DSPT result and why it is worth pursuing even when nobody has explicitly asked you for it.

What the DSPT Actually Covers

The DSPT is broader than most people expect. It covers digital systems and cyber security, but also paper records, verbal disclosures of information, and your organisation's duty to share information appropriately to support someone's care. It is designed specifically for health and social care settings, which is why the questions read very differently to a generic cyber security framework.

Organisations self-assess against the toolkit each year, and the outcome is reported as a status: "Standards Not Met," "Standards Met," or "Standards Exceeded."

Where Cyber Essentials Plus Comes In

Cyber Essentials Plus is not part of the DSPT, but the two are designed to work together:

  • If you hold a current Cyber Essentials Plus certificate, you can record it on your DSPT organisation profile, and doing so lets you skip a number of the toolkit's cyber security questions, because the independent audit behind Cyber Essentials Plus already provides that assurance.
  • For most organisations, reaching "Standards Met" on the DSPT while also holding a current Cyber Essentials Plus certificate is enough on its own to move your overall status to "Standards Exceeded." ISO 27001 is not a precondition, it simply provides additional evidence and question exemptions of its own where you hold it.

That distinction matters commercially as well as technically. "Standards Exceeded" is a visible, easily checked signal to NHS commissioners, referring clinicians, and partner organisations that you have gone beyond the minimum. In competitive procurement and partnership conversations, it is a genuine differentiator.

One exception worth flagging: NHS trusts, ICBs, ALBs, CSUs, and organisations designated as Operators of Essential Services complete a different, more detailed version of the DSPT aligned to the NCSC's Cyber Assessment Framework (CAF). For these larger bodies, "Standards Exceeded" is judged against forecast achievement levels rather than simply holding Cyber Essentials Plus, and recent DSPT cycles have removed blanket audit exemptions for organisations that already hold Cyber Essentials Plus or ISO 27001, though those certifications still reduce the scope of the independent audit required. If you supply into this tier of NHS organisation, treat this post as directional rather than definitive and check your specific category's requirements.

Why the Basic (Not Just "Plus") Detail Matters

It is specifically Cyber Essentials Plus that unlocks this benefit, not standard Cyber Essentials. The difference is meaningful:

  • Cyber Essentials is a self-assessed questionnaire, verified by a certification body, covering five technical control areas.
  • Cyber Essentials Plus assesses the same five controls but adds an independent, hands-on technical audit, remote and on-site vulnerability testing that actually verifies the controls work, not just that they are documented.

The DSPT gives credit for Cyber Essentials Plus specifically because the independent audit behind it maps to the level of assurance the DSPT's own cyber-related standards are looking for. Standard Cyber Essentials does not carry the same weight in this particular context.

What Cyber Essentials Plus Does Not Replace

It is worth being clear about the limits here, because we see this misunderstood often:

  • Cyber Essentials Plus does not exempt you from completing the DSPT. There is no shortcut past the full toolkit, you still need to complete the assessment in full, even with Cyber Essentials Plus and ISO 27001 both in place.
  • The DSPT covers ground Cyber Essentials Plus does not touch at all, including paper records, information governance, and verbal information sharing. Cyber Essentials Plus only addresses cyber security and digitally held or transferred data.
  • The DSPT is recognised within the CQC's Single Assessment Framework as a source of governance evidence; Cyber Essentials Plus on its own is not referenced there. For CQC-regulated providers, the DSPT itself remains the document of record.

Think of Cyber Essentials Plus as a way to strengthen and accelerate your DSPT submission, not as a substitute for it.

The Practical Payoff

For organisations already required to hold Cyber Essentials Plus for other reasons, DTAC submissions, wider government contract requirements, or simply good practice, recording it against your DSPT profile is close to a free win. You get:

  • Fewer DSPT questions to answer in detail, because the independent audit already provides that evidence
  • A stronger, more differentiated DSPT status ("Standards Exceeded" instead of "Standards Met")
  • A single, coherent security story that works across DSPT, DTAC, and general NHS or government procurement questions, rather than separate certifications that don't reinforce each other

Frequently Asked Questions

Does Cyber Essentials Plus automatically give you "Standards Exceeded" on the DSPT?

Not automatically, you still need to reach "Standards Met" on the DSPT itself. But for most organisations, holding a current Cyber Essentials Plus certificate alongside "Standards Met" is enough on its own to move your overall status to "Standards Exceeded."

Do I need ISO 27001 as well as Cyber Essentials Plus for "Standards Exceeded"?

No. ISO 27001 is not a precondition for "Standards Exceeded." It provides its own additional evidence and question exemptions where you hold it, but Cyber Essentials Plus alone is sufficient for most organisations.

Does Cyber Essentials Plus replace the need to complete the DSPT?

No. There's no shortcut past the full toolkit — every organisation still completes the DSPT assessment in full, even with Cyber Essentials Plus and ISO 27001 in place. Cyber Essentials Plus only reduces the number of cyber security questions you need to answer in detail.

Is standard Cyber Essentials enough, or does it have to be Cyber Essentials Plus?

It has to be Cyber Essentials Plus specifically. The DSPT gives credit for it because its independent, hands-on technical audit matches the assurance level the DSPT's cyber-related standards look for — standard Cyber Essentials doesn't carry the same weight here.

Does this apply to NHS trusts and ICBs too?

Not in the same way. NHS trusts, ICBs, ALBs, CSUs, and Operators of Essential Services complete a different, CAF-aligned version of the DSPT, where "Standards Exceeded" is judged against forecast achievement levels rather than simply holding Cyber Essentials Plus.

How Periculo Helps

We support NHS suppliers and adult social care providers across both sides of this relationship:

  • Cyber Essentials Plus certification, including the independent technical audit
  • NHS DSPT audit and submission support, aimed at "Standards Exceeded" wherever Cyber Essentials Plus is in place
  • Guidance on recording certifications correctly in your DSPT organisation profile so you actually receive the credit you are entitled to
  • Ongoing support to keep both certifications current, since both Cyber Essentials Plus and the DSPT require annual renewal

Contact Us