DSPT 2027: What’s Changed and How CAF Is Changing the Game
09 September
The DSPT is changing. And for NHS organisations, 2027 is about much more than completing another annual assessment.
For years, the Data Security and Protection Toolkit (DSPT) has provided NHS and care organisations with a structured way to demonstrate that they have appropriate data security and information governance arrangements in place.
But the direction of travel is changing.
The introduction of the Cyber Assessment Framework (CAF)-aligned DSPT represents a significant shift towards assessing whether organisations can actually manage cyber risk, protect critical services, detect threats and recover from incidents – rather than simply demonstrating that policies and controls exist.
For organisations preparing for DSPT 2027, this means a different way of thinking about cyber security.
From ticking boxes to demonstrating resilience
Traditional DSPT assessments have often felt like a compliance exercise: identify the requirements, gather evidence, answer the questions and submit the return.
The CAF approach is different.
The NCSC describes CAF as an outcomes-based framework designed to help organisations achieve and demonstrate an appropriate level of cyber resilience, rather than simply providing a compliance checklist.
That distinction matters.
Having a vulnerability management process is one thing.
Being able to demonstrate that vulnerabilities are identified, prioritised according to risk, remediated within appropriate timescales and continually monitored is another.
Having an incident response plan is one thing.
Being able to demonstrate that the plan works, that responsibilities are understood and that essential services can continue during a cyber incident is another.
DSPT is increasingly asking organisations to demonstrate that security works in practice.
What has changed?
1. A greater focus on cyber risk
CAF places significant emphasis on understanding the risks to the systems and services that matter most.
Organisations need to understand their critical and essential functions, the technology that supports them, their dependencies and the threats that could disrupt them.
The NCSC’s CAF guidance highlights the importance of understanding threats and vulnerabilities and having a systematic process for managing identified risks.
For healthcare organisations, this means asking questions such as:
- What systems are essential to patient care?
- What happens if they become unavailable?
- Which systems and suppliers do they depend on?
- Where are the vulnerabilities?
- Which risks pose the greatest threat to essential services?
- Can the organisation demonstrate that those risks are being actively managed?
This is a much more strategic conversation than simply asking whether a security control is present.
2. Asset and supply-chain visibility matters more
You cannot protect what you cannot see.
Understanding the assets, systems, services and suppliers supporting essential functions is fundamental to effective cyber risk management.
For NHS organisations with complex estates, multiple sites, legacy systems, cloud services and third-party suppliers, this can be challenging.
A CAF-aligned approach encourages organisations to understand the relationships and dependencies between systems rather than assessing technologies in isolation.
That makes asset visibility, vulnerability management, architecture reviews and third-party risk management increasingly important components of DSPT readiness.
3. Detection and threat hunting are becoming more important
Cyber security cannot stop at prevention.
CAF includes dedicated principles for security monitoring and threat hunting, under Objective C – Detecting Cyber Security Events.
The latest CAF v4.0 strengthens this area further, with the NCSC specifically highlighting updates to security monitoring and threat hunting as one of four major changes in the latest version.
This reflects the reality of modern attacks.
Attackers may bypass preventative controls. Credentials can be compromised. Legitimate accounts can be abused. Malware may evade traditional detection.
Organisations therefore need the capability to identify suspicious activity and investigate potential threats before they become major incidents.
For healthcare organisations, this could mean reviewing:
- Security monitoring coverage
- Endpoint detection
- Network visibility
- SIEM capabilities
- Threat detection
- Threat hunting
- Incident escalation
- Alert response
- Log retention and analysis
4. AI is now part of the cyber risk conversation
AI has rapidly changed the threat landscape.
CAF v4.0 includes improved coverage of AI-related cyber risks, recognising that organisations need to consider how AI affects both attackers and defenders.
For healthcare organisations, this raises questions around:
- How is AI being used within the organisation?
- What sensitive information is being entered into AI tools?
- How could attackers use AI against the organisation?
- Are existing security controls capable of identifying AI-enabled attacks?
- Are staff aware of the risks associated with using AI?
AI should no longer be treated simply as an emerging technology issue. It is increasingly part of the wider cyber risk landscape.
5. Resilience and recovery are critical
CAF is ultimately concerned with protecting essential functions.
That means organisations need to consider what happens when preventative security measures fail.
CAF Objective D focuses on minimising the impact of cyber security incidents, including response and recovery planning. The framework expects organisations to have well-defined and tested incident management processes designed to maintain continuity of essential functions during system or service failure.
For NHS organisations, this means cyber resilience needs to connect directly with business continuity and disaster recovery.
Questions should include:
Can we continue operating?
How quickly can we recover?
What systems need to be restored first?
Have we tested our assumptions?
Do our recovery plans work in practice?
CAF v4.0: keeping pace with the threat
The NCSC released CAF v4.0 in August 2025, introducing four significant areas of change:
- A deeper understanding of attacker methods and motivations
- Greater emphasis on secure software development and maintenance
- Updates to security monitoring and threat hunting
- Improved coverage of AI-related cyber risks
These changes reflect a simple reality: the threat landscape has moved on.
Cyber security frameworks need to evolve with it.
For NHS organisations preparing for DSPT 2027, this means looking beyond last year’s evidence and asking whether existing security arrangements remain effective against today’s threats.
So what should organisations do now?
DSPT preparation shouldn’t begin a few weeks before submission.
Instead, organisations should use the CAF-aligned approach to establish a continuous cycle of:
Assess → Prioritise → Remediate → Test → Monitor → Improve
Start by understanding where you currently stand.
Step 1: Assess your current position
Map your existing security capabilities against the relevant CAF/DSPT outcomes.
Identify where you are:
- Achieving the required outcome
- Partially achieving it
- Not achieving it
Then prioritise the gaps that represent the greatest risk to your essential functions.
Step 2: Understand your exposure
Review your:
- Assets
- Vulnerabilities
- Network architecture
- Identity and access controls
- Email security
- Endpoint security
- Third-party suppliers
- Internet-facing systems
- Security monitoring
- Incident response capabilities
Step 3: Fix the gaps
A gap assessment is only useful if it leads to action.
Develop a prioritised remediation plan that connects security improvements to business and clinical risk.
Step 4: Test whether your controls work
Don’t simply assume that a security control is effective because it has been deployed.
Test it.
That could mean vulnerability assessments, penetration testing, threat emulation, phishing simulations, firewall health checks, incident response exercises or reviewing whether security alerts are actually being detected and investigated.
Step 5: Keep improving
CAF is not intended to be a once-a-year exercise.
Cyber risk changes continuously, and your security posture needs to change with it.
How ANSecurity can help
Preparing for a CAF-aligned DSPT doesn’t necessarily mean buying more technology.
It means understanding where your risks are, whether your existing controls are working and what needs to happen next.
That’s where ANSecurity can help.
We work with organisations to assess, improve and strengthen their cyber security posture across the areas that matter most.
Assess
Our advisory and assessment services can help organisations understand their current position, identify gaps and develop a practical roadmap towards improved cyber resilience.
Protect
From vulnerability management and network security to email, endpoint and identity security, we can help organisations strengthen the controls protecting critical systems and information.
Detect
Through security monitoring, XDR, SIEM and threat-focused services, ANSecurity can help organisations improve their ability to identify suspicious activity and respond to emerging threats.
Test
Security controls should be tested, not assumed.
Our vulnerability management, threat emulation and security assessment services can help organisations understand how their defences perform against real-world attack techniques.
Respond and recover
We can help organisations strengthen incident response, resilience and recovery planning, ensuring that cyber security is connected to the wider requirement to keep essential services running.
Co-Driver: cyber security expertise when you need it
Not every organisation needs – or wants – to outsource its entire cyber security operation.
That’s why ANSecurity offers Co-Driver.
Co-Driver provides flexible access to cyber security expertise, combining professional services and managed support to help organisations address specific challenges without giving up control of their own IT environment.
Whether you need additional expertise for a CAF/DSPT assessment, help remediating identified gaps, ongoing security support or specialist assistance with a particular project, Co-Driver can provide support around your existing team.
DSPT 2027 is an opportunity, not just another deadline
The biggest change is perhaps the mindset.
The question is no longer simply:
“Have we completed our DSPT?”
It is becoming:
“Can we demonstrate that we understand our cyber risks, that our security controls are effective and that we can continue delivering essential services when something goes wrong?”
That is the real value of the CAF-aligned approach.
And organisations that start preparing now will be in a much stronger position when DSPT 2027 arrives.
ANSecurity can help you move from compliance to confidence – with practical, proportionate cyber security built around your organisation’s risks, priorities and essential services.
Want to understand how prepared your organisation is for CAF-aligned DSPT? Talk to ANSecurity about a practical DSPT/CAF readiness assessment.