A current Cyber Essentials Plus certificate, combined with a "Standards Met" result, is enough on its own to move most organisations' NHS DSPT status to "Standards Exceeded."
Anyone working with the NHS or adult social care in England will eventually run into the Data Security and Protection Toolkit, better known as the DSPT. It is the annual self-assessment that measures your organisation against the National Data Guardian's 10 data security standards, and it is a condition of nearly every NHS service delivery contract.
What is less well understood is how directly Cyber Essentials Plus feeds into your DSPT result and why it is worth pursuing even when nobody has explicitly asked you for it.
The DSPT is broader than most people expect. It covers digital systems and cyber security, but also paper records, verbal disclosures of information, and your organisation's duty to share information appropriately to support someone's care. It is designed specifically for health and social care settings, which is why the questions read very differently to a generic cyber security framework.
Organisations self-assess against the toolkit each year, and the outcome is reported as a status: "Standards Not Met," "Standards Met," or "Standards Exceeded."
Cyber Essentials Plus is not part of the DSPT, but the two are designed to work together:
That distinction matters commercially as well as technically. "Standards Exceeded" is a visible, easily checked signal to NHS commissioners, referring clinicians, and partner organisations that you have gone beyond the minimum. In competitive procurement and partnership conversations, it is a genuine differentiator.
One exception worth flagging: NHS trusts, ICBs, ALBs, CSUs, and organisations designated as Operators of Essential Services complete a different, more detailed version of the DSPT aligned to the NCSC's Cyber Assessment Framework (CAF). For these larger bodies, "Standards Exceeded" is judged against forecast achievement levels rather than simply holding Cyber Essentials Plus, and recent DSPT cycles have removed blanket audit exemptions for organisations that already hold Cyber Essentials Plus or ISO 27001, though those certifications still reduce the scope of the independent audit required. If you supply into this tier of NHS organisation, treat this post as directional rather than definitive and check your specific category's requirements.
It is specifically Cyber Essentials Plus that unlocks this benefit, not standard Cyber Essentials. The difference is meaningful:
The DSPT gives credit for Cyber Essentials Plus specifically because the independent audit behind it maps to the level of assurance the DSPT's own cyber-related standards are looking for. Standard Cyber Essentials does not carry the same weight in this particular context.
It is worth being clear about the limits here, because we see this misunderstood often:
Think of Cyber Essentials Plus as a way to strengthen and accelerate your DSPT submission, not as a substitute for it.
For organisations already required to hold Cyber Essentials Plus for other reasons, DTAC submissions, wider government contract requirements, or simply good practice, recording it against your DSPT profile is close to a free win. You get:
Not automatically, you still need to reach "Standards Met" on the DSPT itself. But for most organisations, holding a current Cyber Essentials Plus certificate alongside "Standards Met" is enough on its own to move your overall status to "Standards Exceeded."
No. ISO 27001 is not a precondition for "Standards Exceeded." It provides its own additional evidence and question exemptions where you hold it, but Cyber Essentials Plus alone is sufficient for most organisations.
No. There's no shortcut past the full toolkit — every organisation still completes the DSPT assessment in full, even with Cyber Essentials Plus and ISO 27001 in place. Cyber Essentials Plus only reduces the number of cyber security questions you need to answer in detail.
It has to be Cyber Essentials Plus specifically. The DSPT gives credit for it because its independent, hands-on technical audit matches the assurance level the DSPT's cyber-related standards look for — standard Cyber Essentials doesn't carry the same weight here.
Not in the same way. NHS trusts, ICBs, ALBs, CSUs, and Operators of Essential Services complete a different, CAF-aligned version of the DSPT, where "Standards Exceeded" is judged against forecast achievement levels rather than simply holding Cyber Essentials Plus.
We support NHS suppliers and adult social care providers across both sides of this relationship: