Compliance

NHS DSPT for dental and GP practices: what it actually takes

NHS Data Security and Protection Toolkit compliance for dental and GP practices: ten standards and the annual submission deadline

If you run a dental or GP practice, the Data Security and Protection Toolkit tends to arrive as a reminder email, get filed under “next month”, and then turn into a scramble in June. The reason is rarely negligence. It is that the toolkit asks questions about backups, access control, supplier assurance and staff training that nobody in a practice was hired to answer.

This is a plain-English account of what the DSPT actually asks for, what “Standards Met” means, what genuinely happens if you miss the deadline, and a realistic timetable for getting there. It is written for practices in East London and Essex, but the toolkit is national and none of it is local.

What the DSPT actually is

The Data Security and Protection Toolkit is an online self-assessment, hosted by NHS England at dsptoolkit.nhs.uk. You answer a set of assertions about how your organisation handles patient data, attach evidence for each one, and publish a submission once a year.

Two words in that sentence do most of the work. Self-assessment means nobody visits, nobody audits you as a matter of course, and no certificate arrives in the post. You declare your own position and you are accountable for its accuracy. Evidence means an assertion is not answered by ticking a box; it is answered by being able to produce the policy, the log, the register or the training record that backs the tick up.

The toolkit is structured around the ten National Data Guardian data security standards, which is why so much of it is about people and process rather than firewalls. The current version, DSPT v8, went live in September 2025 and is aligned to the National Cyber Security Centre's Cyber Assessment Framework. The heavier CAF-based assessment applies to large NHS organisations, integrated care boards, local authorities and designated operators of essential services, not to an ordinary practice, which completes a category-specific set of items instead.

Do you actually have to do it?

The requirement follows access to NHS data and NHS systems, not whether you think of yourself as an NHS provider. In practice you are in scope if any of the following is true:

  • You use NHSmail.
  • You connect to the NHS Spine or use the Electronic Prescription Service.
  • You hold a data sharing agreement with an ICB or another NHS body.
  • You hold an NHS contract of any size, including a mixed NHS and private list.

Dental practices, GP practices, community pharmacies, opticians and care providers each complete a slightly different set of items, sized to the risk profile of the organisation. A GP practice answers a GP-specific set; dental practices sit in the category used for pharmacies, dentists and opticians, which is a core assessment with no independent audit attached.

A practice with no NHS connection at all is generally outside the toolkit, but it is not outside UK GDPR, the Data Protection Act 2018 or the CQC's expectations on information governance. And a surprising number of “fully private” practices are still using NHSmail, which puts them straight back in scope.

The ten standards, in plain English

Strip out the phrasing and the ten National Data Guardian standards ask ten fairly blunt questions.

StandardWhat it is really asking
1. Personal dataDo you know what patient data you hold, where it lives, and who can reach it?
2. Staff responsibilitiesDoes everyone understand that data security is part of their job, not the IT provider's?
3. TrainingHas every member of staff had current data security and awareness training, and can you prove it?
4. Managing accessDoes each person have only the access their role needs. And does access actually get removed when someone leaves?
5. Process reviewsDo you review how you handle data and act on what you find, rather than reviewing once and filing it?
6. Responding to incidentsWould you detect a breach, and does someone know what to do and who to tell in the first hour?
7. Continuity planningIf the practice management system went down tomorrow, could you keep seeing patients, and have you tested that?
8. Unsupported systemsIs anything still running on software the vendor no longer patches?
9. IT protectionAre the technical controls, meaning patching, encryption, firewalls and backups, in place and evidenced?
10. SuppliersDo the companies handling your data meet the same standards, and can you show you checked?

Standard 10 catches people out more than any other. Your practice management vendor, your imaging supplier, your document scanning company and your IT provider all touch patient data, and “we assumed they were fine” is not evidence. Written assurance is.

Standards Met, and what the other outcomes mean

The toolkit does not produce a pass mark so much as a published status.

  • Standards Met. Every applicable assertion answered, with evidence behind it. This is the level data sharing agreements and NHS contracts normally refer to.
  • Approaching Standards. The mandatory items are complete but the assessment is not. Acceptable as a staging post with a dated improvement plan, not as a destination.
  • Not published. The outcome that causes actual problems, because it looks identical to not having tried.

If you are going to fall short, falling short visibly and on time, with a plan and dates attached, is treated very differently from missing the deadline in silence.

What happens if you miss it

There is no fine for a late DSPT. The consequences published guidance points to are operational, which for most practices is worse:

  • Loss of access to NHS systems. NHSmail, the Spine and the Electronic Prescription Service. For a practice that prescribes and refers electronically, that is a stoppage, not an inconvenience.
  • Data sharing agreements that an ICB declines to renew.
  • A worse position if something goes wrong. A breach at an organisation with a current submission is a bad day. A breach at an organisation with a lapsed one is a much harder conversation with the ICO and the CQC.

The CQC link is the one practices underestimate. Data security sits under the well-led question, and CQC guidance for general practice points providers at the DSPT as the recognised way to assess their own arrangements. Inspectors do not run the toolkit, but “show me how you assure yourselves on data security” is a reasonable question, and a current submission is the cleanest available answer.

The five things that actually hold practices up

The assertions are not the bottleneck. These are.

  1. Training records. The training itself is quick. Proving that everyone did it, including the part-time hygienist, the Saturday receptionist and the locum, means keeping a register through the year, not reconstructing one in June.
  2. Leavers who never left. Practice management logins, NHSmail accounts and shared drive access outliving the person. This is standard 4, and it is the single most common finding in any access review.
  3. Backups nobody has restored. A backup you have never tested is a belief, not a control. Standard 7 asks whether you could keep operating, and the honest answer requires an actual restore test with a date on it.
  4. Supplier assurance. Standard 10 needs written confirmation from every company touching patient data. Chasing four suppliers for a document takes weeks of calendar time and about an hour of work.
  5. Old software. An unsupported operating system or an out-of-date practice management server fails standard 8 outright, and cannot be fixed in the last fortnight because it usually means replacing something.

A timetable that works

Published guides put a first submission at roughly 20 to 40 hours over three to five months, and repeat submissions at 8 to 15 hours if the evidence has been maintained. Read that as a calendar problem rather than a workload problem, because the slow parts depend on other people.

WhenWhat to do
Three months outRegister on the toolkit, confirm your organisation category, and read your actual assertion list. Start the supplier assurance chase now. It is the longest pole.
Two months outAsset and data flow register. Access review: every account, every system, leavers removed. Book the staff training and open the register.
One month outTechnical evidence: patching, encryption, firewall, antivirus. Run a real restore test and record it. Write or refresh the incident response and business continuity notes.
Two weeks outComplete the assertions, attach evidence, and have whoever is accountable read it properly before sign-off. Publish with time in hand.

Confirm the current deadline for your organisation type on dsptoolkit.nhs.uk before you plan around any date, including the one in this article. Published 2025/26 guidance gives 30 June 2026, but categories and dates do move.

Where we come in

Most of the DSPT is evidence about your IT, which is why practices usually end up asking their IT provider for it. We publish an NHS DSPT compliance pack at £297 per practice, per month on our pricing page, alongside everything else we charge. It covers DSPT submission support, isolating the practice management system, immutable backups and staff training.

What that means in practice: we assemble and maintain the technical evidence, keep the asset and supplier registers current, run and document the restore tests, handle the access reviews, and work through the assertions with you so the answers are true and supportable. The relevant technical pieces sit in our cybersecurity and backup and recovery services, run by the same team as your day-to-day managed IT.

Two things we will not tell you, because they are not true of anyone. We cannot make the submission yours. It stays yours. The declaration is made by the practice and signed off by someone accountable in it, and that is the correct arrangement rather than a limitation. And nobody can guarantee Standards Met, because the outcome depends on evidence only the practice can produce: your training records, your policies, your decisions about old kit. Anyone promising a guaranteed outcome is describing something the toolkit does not work like.

Worth adding for completeness: the DSPT sits alongside Cyber Essentials rather than replacing it, and some NHS and local authority contracts ask for both. Our plain-English Cyber Essentials guide covers what that involves.

The short version

The DSPT is an annual self-assessment against ten standards, submitted by you, evidenced by you, and required if you touch NHS data or NHS systems. Published guidance for 2025/26 gives a 30 June 2026 deadline; check yours on the toolkit itself. Missing it costs you NHSmail, the Spine and the Electronic Prescription Service rather than a fine, which is why it is an operational risk rather than a paperwork one.

The work is not hard, but it is slow in the places that depend on other people: training registers, supplier assurances, restore tests, old software. Start three months out and it is comfortable. Start three weeks out and it is the scramble everyone remembers from last year.

If you would like someone to look at where your practice currently stands, we will go through it with you and tell you honestly what is already fine and what is not. The free IT health check is a reasonable ten-minute starting point, or get in touch and we will talk it through.

Frequently asked questions

What is the NHS Data Security and Protection Toolkit?+

The DSPT is an online self-assessment run by NHS England at dsptoolkit.nhs.uk. Organisations that handle NHS patient data answer a set of assertions about how they protect it, upload supporting evidence, and publish a submission once a year. It is measured against the ten National Data Guardian data security standards, which cover people, process and technology rather than technology alone. It is not a certificate awarded by an assessor. You declare your own position, and you are accountable for the accuracy of what you declare.

When is the DSPT deadline?+

Published guidance for the 2025/26 toolkit gives a submission deadline of 30 June 2026, and the annual cycle has historically run to the end of June. Deadlines and category rules do change, so confirm the current date for your organisation type on dsptoolkit.nhs.uk rather than relying on any third-party article, including this one. If you know you will not make it, an improvement plan submitted on time is treated very differently from silence.

Does a private dental practice have to complete the DSPT?+

It depends on what you connect to rather than on whether you take NHS patients. The requirement follows access to NHS data and NHS systems: NHSmail, the NHS Spine, the Electronic Prescription Service, or a data sharing agreement with an ICB. A wholly private practice with none of those connections is generally outside the DSPT, but is still fully subject to UK GDPR and the Data Protection Act 2018, and the CQC still expects sound information governance. Many practices that consider themselves private turn out to be using NHSmail, which brings them back in scope.

What is the difference between Standards Met and Approaching Standards?+

Approaching Standards means the mandatory evidence items are complete but not the whole assessment. Standards Met is the full bar. Every applicable assertion answered with evidence behind it. Standards Met is what data sharing agreements and NHS contracts normally refer to, so treat Approaching Standards as a staging post you are actively working out of, with a dated improvement plan, rather than a resting place.

What happens if we miss the DSPT deadline?+

The practical consequences reported in published guidance are loss of access to NHS systems, meaning NHSmail, the Spine and the Electronic Prescription Service, and an ICB declining to renew a data sharing agreement. For a practice that prescribes and refers electronically, that is an operational stoppage rather than a paperwork problem. There is no fine attached to a late DSPT itself, but a data breach at an organisation with a lapsed submission is a much harder conversation with the ICO and the CQC.

Can our IT provider complete the DSPT for us?+

An IT provider can do most of the heavy lifting: the technical evidence, the asset and supplier registers, the backup and patching records, the network and access controls. We can draft the assertions with you. What a provider cannot do is own the declaration. The submission is made by the organisation, signed off by someone accountable within it, and it must be true. Be wary of anyone who offers to “guarantee Standards Met”: the outcome depends on evidence only the practice can produce, such as staff training records and your own policies.

How long does a first DSPT submission take?+

Published guides commonly put a first submission at roughly 20 to 40 hours of effort spread over three to five months, and repeat submissions at around 8 to 15 hours if the evidence has been kept up to date through the year. The hours are not the hard part. The elapsed time is, because training records, supplier assurances and policy sign-off all depend on other people. Starting three months out is comfortable; starting three weeks out usually is not.

Do we need Cyber Essentials as well as the DSPT?+

They are separate things and neither replaces the other. The DSPT is an annual self-assessment specific to health and care data. Cyber Essentials is a UK government-backed certification, assessed by IASME, that checks five technical controls. The controls overlap enough that the work you do for one materially helps the other, and some NHS and local authority contracts ask for Cyber Essentials on top of the DSPT. Our plain-English guide to Cyber Essentials explains what that involves.

Call usFree consultation