The NHS Data Security and Protection Toolkit (DSPT) asks organisations that handle health and care data to show that cyber and information governance controls are real. Policies and diagrams help. Independent penetration testing helps more when the question is whether technical defences stand up to a competent attacker. Boards, SIROs and independent assessors increasingly want that distinction visible in evidence packs.
This guide is written primarily for NHS trusts, foundation trusts and other provider organisations completing DSPT. Suppliers should read it alongside the health-tech vendor guide, because product DTAC evidence and organisational DSPT evidence are related but not interchangeable.
The short version
- DSPT is organisational assurance; use penetration testing to challenge critical technical controls, not to fill a compliance folder.
- Plan annual testing of the systems that matter, plus retesting after major change.
- Keep vulnerability scanning frequent; do not confuse it with a pentest.
- Document scope and exclusions honestly for assessors.
- Attack Vector finds and evidences weaknesses; your teams prioritise remediation.
Context: why DSPT conversations return to testing
Since version 7 (2024/25), DSPT has used CAF-aligned outcome assessment under the NCSC Cyber Assessment Framework for designated organisation types, and version 8 continued that approach. Independent assessment arrangements apply to trusts, ICBs, CSUs, ALBs, designated OES providers and nominated genomics organisations. IT suppliers followed a separate non-CAF assertion path for 2025/26 with their own mandatory audit assertions. The 2026/27 toolkit (version 9) went live on 4 September 2026, with a submission deadline of 30 June 2027. Details and cycle dates change; treat NHS England Digital and the DSPT website as primary sources. A change summary sits in DSPT v8 and DTAC v2 penetration testing evidence.
In day-to-day assurance language inside trusts, penetration testing supports questions such as:
- Have internet-facing services been challenged recently?
- Are critical clinical or corporate applications resistant to common and logic-level attacks?
- Is vulnerability management more than a scanner licence?
- Can we show the board a clear risk story after testing, with remediation ownership?
There is rarely a single DSPT checkbox that says “attach any PDF labelled pentest.” Assessors and local cyber teams look for quality, relevance and follow-through.
Distinguishing scanning and penetration testing inside DSPT
Vulnerability scanning finds known weaknesses and misconfigurations at machine speed. It belongs on a short cadence for estates that change weekly. Penetration testing validates exploitability, chains issues and assesses impact with a human attacker model against an agreed objective.
For toolkit evidence and board reporting, a recent penetration test report usually carries more weight than a scanner export alone. The two work best together. If you need the commercial distinction spelled out, see penetration testing versus vulnerability scanning.
What to put in scope for a DSPT-aligned year
Agree scope with SIRO/CISO priorities and essential function thinking where CAF alignment applies. Common building blocks:
- External infrastructure facing the internet (remote access, public portals, mail and collaboration edges as relevant)
- Critical internal segments and identity paths that protect sensitive services
- Key clinical or corporate web applications that process personal or patient data
- APIs that move health, staff or partner data
- Important cloud tenancy and hosting controls supporting those systems
- Retest windows for Critical and High findings before submission or major go-lives
Document exclusions deliberately. Third-party SaaS you cannot test, air-gapped networks outside the engagement, or deferred sites should appear in the report so toolkit evidence stays honest.
DSPT guidance has long stressed web server security, vulnerability assessment activity, default password hygiene on network devices, and protection of critical network structure. Treat those themes as a starting point for risk-based scope rather than a rigid checklist.
Choosing how to deliver the test
Specialist commercial testing
Outsourcing to a UK specialist brings independence and depth. Cost is higher than an internal scan cycle, which is appropriate for assurance work. Attack Vector engagements start from £1,500 for tightly defined scopes; trust estates usually need a broader day count. Lead credentials include Cyber Scheme Team Leader (CSTL), from The Cyber Scheme, and Chartered Cyber Security Professional (ChCSP), the UK Cyber Security Council's chartered title.
In-house red team or security team testing
Possible where skills, tooling and objectivity exist. Independence is harder to evidence to external assessors when the same team both builds and “tests” controls. Conflict management and peer review matter.
Partnering across organisations
Shared testing arrangements between similar organisations can spread cost. They only work when expertise, legal cover and scoping discipline are comparable on both sides.
Most trusts combine managed vulnerability scanning in-house or via MSSP with periodic independent penetration testing from a specialist firm.
Briefing checklist for your testing partner
Copy and adapt:
- Organisation type and DSPT cycle timing (including independent assessment windows).
- Essential services / critical systems list and data classification notes.
- In-scope URLs, IP ranges, apps, APIs and cloud accounts.
- Authentication roles available for testing (including privileged roles where safe).
- Environments (staging parity versus production constraints) and change freeze dates.
- Out-of-hours rules and clinical safety contacts for escalation.
- Whether the audience is board, SIRO, independent assessor, or all three.
- Retest expectations for Critical/High closure evidence.
- Any parallel DTAC product work with suppliers that needs coordinating (link teams early).
- Procurement constraints (company CREST/CHECK if mandatory).
Suppliers serving NHS organisations
If you are a digital supplier, your DSPT journey differs from a trust’s, but an annual penetration test is still required, and DTAC expects findings rated CVSS 7.0 or above to be mitigated. Align product testing to DTAC technical security needs where procurement requires it, and keep organisational testing current if you complete DSPT as an organisation. Start with NHS DTAC penetration testing and the vendor guide.
Three ways DSPT testing goes wrong
Weak DSPT-related testing usually fails in one of three ways: scope misses the systems that hold patient or staff data; the “test” is an unauthenticated scan; or findings sit open with no remediation owner when the independent assessor asks for proof. The result is avoidable remediation pressure at submission time, or worse, untested exposure in a care environment.
What testing does not do for your toolkit
- Penetration testing supports DSPT assurance. It does not complete the toolkit for you.
- CAF versus non-CAF paths depend on organisation type and year. Verify against NHS England Digital for your category.
- We identify weaknesses and document them; we do not remediate your systems as part of the test fee.
- No engagement guarantees a particular DSPT status outcome.
- Email scoping is available when estates are too complex for an instant estimate alone.
For an indicative figure on a bounded scope, try the instant quote calculator. For trust-scale scoping, email [email protected]. Keep supplier product work joined up via NHS DTAC penetration testing.
FAQ
How often should an NHS organisation run a penetration test for DSPT?
At least annually is the usual planning assumption, plus after significant infrastructure or application change. Confirm with your cyber strategy and independent assessor expectations.
Does DSPT require CREST company membership?
Not universally as a single public rule for every organisation. Some local procurement policies and guidance notes prefer accredited providers. If your policy mandates company CREST or CHECK, follow it. Otherwise evaluate competence, methodology and report quality carefully. Attack Vector’s lead credentials are CSTL and ChCSP.
Can we rely on vulnerability scanning alone?
For continuous hygiene, scanning is essential. For assurance depth, it is not enough on its own where assessors and boards expect independent testing of critical systems.
Should we test production clinical systems?
Only with careful rules of engagement, clinical safety awareness and, where possible, representative staging. Never improvise production testing without agreed escalation paths.
What report audience should we request?
Ask for an executive summary for SIRO/board readers and a technical section engineers can use. Assessors often want both clarity and evidence depth.
Will you fix the vulnerabilities you find?
No. Attack Vector identifies and evidences issues so your organisation can prioritise remediation. Retest can verify fixes when scoped.
Suggested Resources
Ready to strengthen your security?
Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.