Home/Blog/Healthcare Security
Healthcare Security

The DSPT Is Evolving: Key Changes from Version 7 to Version 9 and Why They Matter

The Data Security and Protection Toolkit (DSPT) is the annual self-assessment that organisations complete to show they handle NHS patient data and systems securely. Since 2024 it has changed more than in any previous period, moving the largest NHS organisations onto the National Cyber Security Centre's Cyber Assessment Framework (CAF) and raising the bar on evidence.

This page explains what changed in each version from 2024/25 to 2026/27, who each change applies to, and why it matters for penetration testing evidence. For detailed testing guidance, see penetration testing in the NHS DSPT for trusts and NHS DSPT and DTAC testing for health-tech vendors for suppliers.

The short version

  • Version 7 (2024/25): NHS trusts, ICBs, CSUs and DHSC arm's length bodies moved to a CAF-aligned toolkit in September 2024.
  • Version 8 (2025/26): the CAF-aligned approach extended to independent providers designated as operators of essential services (OES) and nominated genomics organisations.
  • Version 9 (2026/27): the toolkit went live on 4 September 2026 and is aligned to CAF version 4.0. The submission deadline is 30 June 2027.
  • IT suppliers and smaller organisations still answer assertions and evidence items rather than CAF outcomes.
  • Annual penetration testing remains an expectation for IT suppliers, and outcome-based assessment rewards evidence that controls actually work.

Version by version

ToolkitCycle and deadlineMain changeWho it affects
Version 72024/25, deadline 30 June 2025Switch to a CAF-aligned structure with 47 contributing outcomesNHS trusts and foundation trusts, ICBs, CSUs, DHSC arm's length bodies
Version 82025/26, deadline 30 June 2026CAF-aligned structure extended to more organisation typesIndependent providers designated as OES, nominated genomics organisations
Version 92026/27, deadline 30 June 2027Alignment updated from CAF version 3.2 to version 4.0All CAF-aligned organisations; refreshed evidence items for others

Version 7: the move to the CAF

In September 2024 the DSPT adopted the CAF as its basis for cyber security and information governance assurance. Larger NHS organisations saw a new interface built around CAF objectives, principles and contributing outcomes, each with indicators of good practice graded as Not Achieved, Partially Achieved or Achieved.

NHS England added a health and care overlay to the CAF's 39 contributing outcomes: a further eight outcomes under a new Objective E, "using and sharing information appropriately", covering data protection, confidentiality and disciplines such as clinical coding. That gave 47 contributing outcomes in total. Each organisation type has a profile setting the minimum achievement expected for each outcome.

Other organisations, including IT suppliers, kept the familiar assertions and evidence items, mapped to the CAF in the background.

Version 8: wider CAF coverage

For 2025/26 the CAF-aligned toolkit was extended to independent providers designated as operators of essential services and to genomics organisations nominated by the Department of Health and Social Care. IT suppliers stayed on a non-CAF assertion path, with independent audit of mandatory assertions. Our DSPT Version 8 and DTAC v2 guide covers that cycle in detail.

Version 9: CAF version 4.0

The 2026/27 toolkit went live on 4 September 2026, and NHS England published the version 9 outcomes, assertions and evidence items on 8 September 2026. It is aligned to CAF version 4.0, and NHS England has published a change log from version 8.

On 10 September 2026 NHS England confirmed the mandatory audit areas for NHS trusts, ICBs, ALBs, CSUs, OES and genomics organisations: 11 mandated outcomes plus one chosen by the organisation. Audit areas for IT suppliers were due to be published separately. IT suppliers continue to complete assertions and evidence items rather than CAF outcomes, but the evidence items have been refreshed. Industry summaries of the supplier spreadsheet highlight new items on multi-factor authentication or identity federation for supplied software, and on alignment with the government's Software Security Code of Practice.

Why the changes matter

Evidence over paperwork

The CAF asks whether security outcomes are achieved, not whether a policy exists. Independent assessors look for evidence that controls operate. A penetration test report with a clear scope, validated findings and tracked remediation is one of the more direct ways to show that technical defences have been challenged.

Vulnerability management is visible

Within the CAF, system security (principle B4) includes vulnerability management. Testing evidence supports that outcome when it is recent, covers the systems that matter, and shows that serious findings were addressed.

Suppliers face connected checks

For IT suppliers, an annual penetration test is still required. Suppliers selling digital health products also meet the Digital Technology Assessment Criteria (DTAC), which expects an independent penetration test within the last 12 months for internet-accessible products, with findings rated CVSS 7.0 or above mitigated.

Where organisations go wrong

  1. Treating the new interface as a form-filling exercise: outcome language without evidence underneath does not survive independent assessment.
  2. Copying the wrong path: CAF outcome wording pasted into a supplier assertion submission, or the reverse.
  3. Stale testing: a report from two cycles ago, or one that excludes the systems holding patient data.
  4. Open serious findings: high-severity issues with no owner or retest by the time of assessment.
  5. Assuming last year still applies: requirements, audit areas and exemptions change each cycle.

What this timeline does not settle

  • Requirements differ by organisation type. Always check the toolkit and NHS England Digital guidance for your category and cycle.
  • This page summarises published changes. It does not replace the toolkit's own outcomes, evidence items or audit guidance.
  • Penetration testing supports DSPT assurance. It does not complete the toolkit or guarantee a Standards Met outcome.
  • Attack Vector provides independent testing evidence and reports weaknesses clearly. Remediation and toolkit submission stay with your organisation.

For an indicative estimate, use the instant quote calculator or email [email protected]. Engagements start from £1,500 for a small, well-defined job.

FAQ

Which organisations use the CAF-aligned DSPT?

NHS trusts and foundation trusts, ICBs, CSUs and DHSC arm's length bodies since version 7, plus independent providers designated as operators of essential services and nominated genomics organisations since version 8. Others answer assertions and evidence items.

What is the deadline for version 9?

30 June 2027 for the 2026/27 cycle.

Do IT suppliers have to use the CAF format?

Not for 2026/27, unless they are separately designated as an operator of essential services. Supplier submissions remain assertion-based, with refreshed evidence items.

Does the DSPT require penetration testing?

IT suppliers are still expected to have an annual penetration test. For CAF-aligned organisations, testing is strong evidence for vulnerability management and system security outcomes rather than a single stand-alone requirement.

Where can we see exactly what changed?

NHS England publishes the outcomes, evidence items and a version 8 to version 9 change log on the DSPT website.

Suggested Resources

#dspt#caf#healthcare-security

Ready to strengthen your security?

Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.