Folelse
NHS Resources

DSPT Toolkit Guidance

A practical guide to the NHS Data Security and Protection Toolkit — what it covers, how to meet each assertion, and how Folelse makes submission faster and audit-ready.

What is it?

The Data Security and Protection Toolkit

The NHS Data Security and Protection Toolkit (DSPT) is an online self-assessment tool produced by NHS England that measures NHS organisations' compliance with the National Data Guardian's ten data security standards. It replaced the Information Governance Toolkit in 2018.

All organisations that have access to NHS patient data and systems must complete the DSPT annually. Achieving "Standards Met" status is typically a prerequisite for NHS data sharing agreements, commissioning contracts, and connection to NHS systems such as N3/HSCN.

The toolkit covers six key areas across data security, cyber security, and information governance — spanning leadership accountability, staff training, data management, data quality, cyber security, and business continuity.

The six areas

DSPT mandatory assertions

Each area contains mandatory and advisory assertions. You must meet all mandatory assertions to achieve Standards Met.

Area 1

Leadership

  • Mandatory data security training for all staff
  • Board-level ownership and SIRO appointment
  • Caldicott Guardian and DPO roles clearly defined
  • Annual board review of data security

Area 2

Training

  • Evidence of completed IG training for 95%+ of staff
  • Training records maintained and auditable
  • Role-specific training for clinical and data teams
  • Training completion tracked per individual

Area 3

Managing data

  • Register of processing activities (ROPA) maintained
  • Data flows mapped and documented
  • Retention schedules defined and enforced
  • Supplier DPAs in place for all data processors

Area 4

Managing data quality

  • Data quality policies and procedures documented
  • Processes for identifying and correcting inaccurate data
  • Access to national data sets reviewed regularly
  • Patient opt-outs (National Data Opt-Out) applied

Area 5

Cyber security

  • Cyber Essentials or Cyber Essentials Plus certification
  • Annual penetration testing by CREST-certified testers
  • Vulnerability and patch management process
  • Network security monitoring and alerting

Area 6

Continuity planning

  • Business continuity and disaster recovery plans tested
  • Recovery time and recovery point objectives defined
  • Critical system backup and restoration procedures
  • Incident response plan documented and rehearsed
Planning

Recommended submission timeline

April

New DSPT submission cycle opens — review previous year actions and improvement plans

May

Begin systematic evidence collection against all mandatory assertions

June

Complete cyber security evidence (Cyber Essentials, pen test reports)

July–Aug

Training completion drive — target 95%+ staff completion

Sep–Oct

Board review session; SIRO confirms evidence sufficiency

Nov–Dec

Internal audit of evidence quality; address any gaps

Jan–Mar

Final evidence review; prepare for submission

March

Submit — target Standards Met status by 30 June deadline

How Folelse helps

Accelerate your DSPT submission

Pre-loaded assertions

All DSPT assertions pre-mapped to Folelse features — no manual mapping required.

Evidence linking

Attach documents, screenshots, and records directly to each assertion as evidence.

Progress dashboard

Real-time completion dashboard shows where you stand against the submission deadline.

Audit-ready export

Export a full evidence pack for your SIRO review or external IG audit.

Frequently asked questions

What is the DSPT submission deadline?

The DSPT annual submission deadline is typically 30 June each year. NHS organisations are expected to achieve at least "Standards Met" status by this date. NHS England may adjust deadlines — always check the official DSPT website for the current cycle dates.

What does "Standards Met" mean?

Standards Met means your organisation has provided satisfactory evidence for all mandatory assertions in the current DSPT toolkit. Organisations that cannot reach Standards Met may submit as "Standards Not Met" with an improvement plan, but this may affect commissioning and information sharing agreements.

Who is responsible for the DSPT submission?

The Senior Information Risk Owner (SIRO) is ultimately accountable for the submission. In practice, the Data Protection Officer or Information Governance Manager typically leads the evidence collection and submission process, with sign-off from the SIRO and board.

Which organisations must complete the DSPT?

All NHS Trusts, GP Practices, CSUs, NHS England arms-length bodies, and organisations processing NHS patient data under a Data Sharing Agreement must complete the DSPT. Many independent sector providers working for the NHS are also required to submit.

Can Folelse submit the DSPT on my behalf?

No — the DSPT submission is made directly on the NHS Digital portal by your SIRO or nominated submitter. Folelse helps you prepare the evidence, track completion, and link evidence to each assertion, making the submission process significantly faster and audit-ready.

How does Folelse map to DSPT assertions?

Folelse pre-loads all current DSPT assertions and maps platform features to relevant evidence requirements. For example, your ROPA module evidence can be directly linked to Assertion 3 requirements, and your breach log links to Assertion 5 and 6 controls.

Related resources