Home/Blog/Healthcare Security
Healthcare Security

DSPT Version 8 and DTAC Version 2: What Changed for Penetration Testing Evidence

NHS England has spent recent cycles making assurance less repetitive on paper and more demanding on proof. The Data Security and Protection Toolkit (DSPT) Version 8 cycle and the refreshed Digital Technology Assessment Criteria (DTAC) form both push organisations toward evidence that controls work, not only that policies exist. Penetration testing sits in that evidence story because it shows technical defences have been challenged by an independent practitioner.

This article is for NHS providers, digital health suppliers and security leads who need a clear “what changed / what still matters” brief on the 2025/26 cycle as 2026/27 begins. It is not a substitute for the live toolkit guidance or the live DTAC form.

Key points

  • DSPT v8 continues the CAF-aligned, outcome-based assessment introduced for designated organisation types in version 7 (2024/25); IT suppliers stay on a non-CAF assertion path for 2025/26 with 12 mandatory audit assertions.
  • The refreshed DTAC form (Feb 2026) is shorter and de-duplicated; previous form should not be used from 6 April 2026.
  • The 2026/27 toolkit (version 9) went live on 4 September 2026, with a submission deadline of 30 June 2027.
  • Neither update removes the need for credible technical security evidence.
  • Penetration testing remains one of the clearest ways to support vulnerability management and product security claims.
  • Testing produces evidence. It does not automatically equal a passed toolkit or a cleared DTAC assessment.

Context: less admin, more evidence

Older NHS assurance journeys frustrated vendors with duplicated questionnaires. The 2024-2026 reforms try to cut repetition while raising the bar on whether controls operate. That is good for honest teams and uncomfortable for organisations that relied on certificates as a blanket shortcut.

If you need the vendor-shaped playbook rather than the change log, start with NHS DSPT and DTAC penetration testing for health-tech vendors. If you need trust-side DSPT scoping, see penetration testing in the NHS DSPT.

DSPT Version 8: what actually changed

CAF alignment for designated organisation types

NHS England Digital describes CAF-aligned DSPT for NHS trusts and foundation trusts, ICBs, CSUs, DHSC arm’s length bodies, designated Operators of Essential Services, and nominated genomics organisations. The model emphasises NCSC Cyber Assessment Framework outcomes: show that security results are achieved, with sample testing by independent assessors where required. CAF alignment first arrived for trusts and other Category 1 organisations in version 7 (2024/25); version 8 continued it.

IT suppliers are not on the same path in 2025/26

This is the accuracy point many blogs blur. For 2025/26, NHS England states that IT suppliers undertake a non-CAF aligned DSPT assessment, following the assertion-and-evidence approach suppliers already know. They still face independent audit. The DSPT’s 2025/26 audit notice lists 12 mandatory assertions for IT suppliers, spanning governance, identity and privileged access, incident reporting and response capability, patching, vulnerability management, protection of sensitive systems, firewall management, and supplier mapping.

Exemptions and equivalences tightened in practice

Practitioner guidance around v8 consistently warns that holding Cyber Essentials Plus or ISO 27001 is not a free pass through the toolkit. Certificates can still reduce audit burden or auto-complete some items where scope genuinely matches, but MFA and NHS-specific evidence often need direct artefacts. Do not assume last year’s equivalence still holds. Check your organisation type’s live help text for the cycle you are submitting.

Dates and continuity

The 2025/26 submission deadline was 30 June 2026. The 2026/27 toolkit (version 9) went live on 4 September 2026, with a submission deadline of 30 June 2027. After each deadline, the work does not stop: maintain evidence for the next cycle and for buyer due diligence between annual submissions.

DTAC refreshed form: shorter, stricter on proof

NHS England’s February 2026 DTAC update, following the 2024 review, includes:

  • A new form with roughly 25% fewer questions
  • De-duplication against processes such as DSPT and the Pre-Acquisition Questionnaire
  • Clearer purpose and scope guidance
  • Confirmed alignment with NICE around software-based digital health technologies
  • Instruction that the previous form should not be used from 6 April 2026

Technical security remains a core assessed theme. For internet-accessible products, the form expects an independent external penetration test covering OWASP Top 10 issues within the last 12 months, with findings rated CVSS 7.0 or above mitigated, alongside Cyber Essentials evidence and stronger MFA expectations for privileged and supplier access. Secure development declarations referencing the DSIT/NCSC Software Security Code of Practice appear in the updated technical narrative. Clinical safety still matters under DCB0129 expectations even where training form wording has been simplified.

Attack Vector delivers product testing and reporting shaped for these conversations via NHS DTAC penetration testing. We do not issue DTAC approvals.

Why penetration testing still matters after the updates

Streamlined forms remove duplicated questions. They do not remove the need to show that applications, APIs and supporting infrastructure resist realistic attack.

Independent penetration testing helps you:

  • Evidence that vulnerabilities are found beyond scanner noise
  • Show exploitability and business impact in language IG and cyber teams share
  • Support remediation programmes with prioritised findings
  • Produce retest artefacts when buyers ask whether Critical and High issues were closed
  • Avoid the credibility failure of filing an unauthenticated scan as “annual penetration testing”

Scanning still belongs in the programme for regular hygiene. It is not a substitute for a pentest where assurance conversations ask for testing. See penetration testing versus vulnerability scanning.

Attack Vector identifies security weaknesses so your teams can prioritise remediation. Ownership of fixes stays with you.

Building evidence through the year

A durable pattern for 2026/27 preparation:

  1. Map which systems support NHS data flows and which product surfaces face NHS users.
  2. Schedule annual (and change-triggered) penetration testing against those surfaces.
  3. Keep vulnerability scanning on a shorter cadence between tests.
  4. Track mitigation of findings rated CVSS 7.0 or above with tickets and retest notes.
  5. Store reports where IG, cyber and commercial teams can retrieve them for DSPT, DTAC and buyer packs without a scavenger hunt.
  6. Revisit MFA, privileged access and supplier access evidence as standalone artefacts, not certificate assumptions.

What good evidence looks like after the updates

Whether you are preparing CAF-aligned outcomes, supplier assertions, or a DTAC technical security pack, assessors and buyers tend to reward the same habits:

  • Recent: testing inside a rolling 12-month window for internet-facing products and critical services
  • Relevant: scope matches the systems that handle NHS data or the product under procurement
  • Readable: executive summary plus technical evidence, not a raw tool dump
  • Actioned: findings rated CVSS 7.0 or above mitigated, with tickets, owners and retest notes
  • Consistent: MFA, privileged access and supplier access evidenced as operating controls, not assumed from a certificate alone

If your current pack fails any of those five, fix the pack before you buy more logos.

Two ways to misread the updates

The risk of misreading the updates is twofold. First, false comfort: “the form is shorter, so we can skip testing.” Second, false equivalence: copying CAF outcome language into an IT supplier assertion submission, or treating a DSPT status as DTAC product clearance. Both create avoidable procurement delay and weak security outcomes for care settings.

What this summary cannot replace

  • Framework wording changes. Always prefer NHS England Digital and DSPT primary pages for your organisation type over blog summaries (including this one).
  • IT suppliers: non-CAF DSPT path for 2025/26 per NHS England Digital. Trusts and other designated types: CAF-aligned path.
  • No test guarantees a “Standards Met” style outcome or a successful DTAC assessment.
  • From £1,500 is an entry point for limited scopes; NHS-facing multi-surface products usually need more days.

If you are aligning test timing to a toolkit submission or a trust procurement gate, use the instant quote calculator or email [email protected]. Pair this change brief with the health-tech vendor guide and the DSPT trust guide.

FAQ

Does DSPT v8 mandate a penetration test by name for every organisation?

For IT suppliers, an annual penetration test is still required. For other organisation types, toolkit outcomes and guidance emphasise protecting systems from exploitation and managing vulnerabilities, and recent independent penetration testing is one of the strongest supporting artefacts. Confirm expectations with your independent assessor and organisation-type guidance.

Are IT suppliers CAF-aligned in 2025/26?

No. NHS England Digital states IT suppliers undertake a non-CAF aligned DSPT assessment for 2025/26, with mandated independent audit assertions.

What is the headline DTAC date to remember?

Do not use the previous DTAC form from 6 April 2026 onwards. Use the refreshed form and current guidance.

Did the shorter DTAC form remove technical security?

No. It reduced duplication. Technical security evidence, including testing where relevant, remains central.

Can ISO 27001 or Cyber Essentials Plus replace a pentest for these frameworks?

Certificates help and may reduce some toolkit burden where scope matches, but they answer different questions from a product or infrastructure penetration test. Buyers often want both baseline certification evidence and recent testing evidence.

Will Attack Vector complete our DSPT or DTAC submission?

No. We provide independent penetration testing and clear reporting so you can evidence technical security. Toolkit completion and DTAC responses remain your organisation’s responsibility.

Suggested Resources

#dspt#dtac#nhs#penetration-testing

Ready to strengthen your security?

Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.