DSPT Version 9: What NHS Organisations Need to Know for 2026–27

The 2026–27 DSPT requirements are now live. Is your organisation ready?

For organisations working across NHS and healthcare environments, demonstrating that patient information and systems are properly protected is not optional.

The Data Security and Protection Toolkit (DSPT) provides the framework organisations use to assess and demonstrate their approach to data security and information governance. Organisations that access NHS patient data and systems are expected to use the Toolkit to provide assurance that personal information is being handled appropriately and that effective security controls are in place.

And now, the next cycle is underway.

The requirements for DSPT Version 9, covering 2026–27, were released on 4 September 2026, giving organisations the opportunity to start preparing well ahead of the submission deadline of 30 June 2027.

For organisations that have gaps in their cybersecurity controls, waiting until the deadline is approaching could make preparation considerably more difficult.

What is the DSPT?

The DSPT is an online self-assessment framework designed to help organisations measure their performance against national data security standards.

It covers the processes, policies and technical controls organisations should have in place to protect sensitive information and maintain secure systems.

The Toolkit isn’t simply about completing a questionnaire. Organisations need to be able to demonstrate that appropriate controls are operating effectively and, where required, provide supporting evidence.

For NHS organisations, the DSPT forms an important part of demonstrating that cybersecurity and information governance risks are being actively managed.

NHS England has highlighted five broad cybersecurity objectives within its DSPT expectations:

  • Managing cyber risk
  • Protecting against cyber attacks and data breaches
  • Detecting cybersecurity events
  • Minimising the impact of incidents
  • Using and sharing information appropriately

What’s new with DSPT Version 9?

One of the key developments for the 2026–27 cycle is the continued alignment between the DSPT and the NCSC Cyber Assessment Framework (CAF).

DSPT Version 9 is aligned with CAF Version 4.0, helping organisations take a more structured, risk-based approach to cybersecurity.

This means organisations shouldn’t look at the DSPT in isolation.

The work involved should form part of a wider cybersecurity programme — helping organisations understand their risks, assess the effectiveness of their controls and continually improve their security posture.

The detailed Version 9 outcomes, assertions and evidence requirements are now available, allowing organisations to start mapping their existing controls against the new requirements.

When is the DSPT deadline?

The deadline for completing and publishing the 2026–27 DSPT is 30 June 2027.

That may seem a long way away, but cybersecurity improvements can take time.

If an organisation identifies weaknesses in areas such as vulnerability management, network security, endpoint protection, email security or access controls, simply identifying the problem doesn’t make it compliant.

There may be remediation work, testing, procurement, implementation and evidence gathering required before the organisation can demonstrate that the appropriate controls are in place.

Starting early gives organisations time to address those gaps properly rather than rushing to meet a deadline.

What should organisations be doing now?

With Version 9 now available, organisations should consider taking a structured approach.

1. Understand the new requirements

Start by reviewing the Version 9 outcomes, assertions and evidence requirements relevant to your organisation.

Don’t assume that last year’s submission can simply be copied across.

The DSPT evolves, and organisations should confirm that existing controls continue to meet the current requirements.

2. Assess your current security posture

Look beyond policies and documentation.

Ask whether the technical controls you rely on are actually working as intended.

For example:

  • Are vulnerabilities being identified and remediated within appropriate timescales?
  • Are critical systems regularly assessed?
  • Is your email environment adequately protected against phishing and sophisticated attacks?
  • Are endpoints monitored for suspicious activity?
  • Are privileged accounts appropriately protected?
  • Is multi-factor authentication being used where appropriate?
  • Are network security controls regularly reviewed?
  • Can you detect and respond to a cybersecurity incident?
  • Do you have evidence demonstrating that these controls are operating effectively?

3. Identify your gaps

A gap assessment can help separate the requirements you already meet from those requiring further work.

This creates a practical roadmap rather than leaving DSPT preparation as a last-minute compliance exercise.

4. Prioritise remediation

Not every issue will carry the same level of risk.

Organisations should prioritise improvements based on the potential impact on critical systems, sensitive data and essential services.

This is where cybersecurity and DSPT preparation should work together.

The objective isn’t simply to tick a box — it’s to reduce genuine cyber risk.

5. Start gathering evidence

Evidence is an important part of demonstrating that controls are not just documented but implemented.

Keeping evidence organised throughout the year can make the eventual DSPT submission significantly easier.

Rather than scrambling to find reports, policies and technical evidence in June 2027, organisations can build their evidence base as security activities take place.

Common areas that could require attention

Every organisation will have a different risk profile, but DSPT preparation can highlight weaknesses across a range of technical and operational areas.

Vulnerability management

Knowing where vulnerabilities exist — and having a defined process for prioritising and remediating them — is fundamental to managing cyber risk.

Regular vulnerability assessments can help organisations identify weaknesses before attackers exploit them.

Email security

Phishing remains one of the most common routes into an organisation.

Strong email security controls, combined with security awareness and effective monitoring, can help reduce the risk posed by malicious emails, credential theft and increasingly sophisticated social engineering attacks.

Endpoint security

Organisations need visibility across the devices connecting to their environments.

Endpoint detection and response can help identify suspicious activity and provide security teams with greater visibility when an incident occurs.

Network security

Firewalls, segmentation, secure remote access and appropriate network controls remain important components of a layered security strategy.

Regular health checks and configuration reviews can help identify weaknesses that may otherwise go unnoticed.

Monitoring and incident response

Prevention is only part of the picture.

Organisations also need to consider how quickly they can detect suspicious activity and what happens when an incident occurs.

Effective monitoring and response capabilities can significantly reduce the potential impact of a cyber attack.

DSPT shouldn’t become a once-a-year exercise

One of the biggest mistakes organisations can make is treating DSPT as an annual compliance task.

Cybersecurity isn’t static.

New vulnerabilities emerge. Attack techniques change. Systems are replaced. Users and suppliers change. Cloud services are introduced. Organisations restructure.

A security control that was appropriate 12 months ago may no longer provide the same level of protection today.

A better approach is to use DSPT as a framework for continuous security improvement.

That means regularly reviewing controls, testing their effectiveness, addressing vulnerabilities and maintaining evidence throughout the year.

How ANSecurity can help

Preparing for DSPT Version 9 doesn’t have to mean tackling everything internally.

ANSecurity can help organisations assess their current security posture, identify vulnerabilities and strengthen the technical controls that support their DSPT requirements.

Our approach is practical and tailored to the organisation rather than based on a one-size-fits-all technology stack.

Depending on your requirements, support can include areas such as:

Vulnerability Management
Identify, prioritise and manage vulnerabilities across your environment.

Email Security
Strengthen protection against phishing, business email compromise and other email-based threats.

Network & Firewall Security
Assess and improve firewall configurations, network security and segmentation.

Endpoint & XDR
Improve visibility of endpoint activity and strengthen detection and response capabilities.

Security Assessments
Identify weaknesses across your environment and create a prioritised roadmap for improvement.

Professional & Managed Services
Get additional cybersecurity expertise when you need it, without having to fully outsource your IT or security function.

Don’t wait until June 2027

The DSPT deadline might still be months away, but the requirements are already available.

Now is the time to understand what Version 9 means for your organisation, identify gaps and start addressing them.

Good DSPT preparation shouldn’t simply result in a completed assessment.

It should leave your organisation with stronger security controls, better visibility of cyber risk and greater confidence that your systems and information are protected.

Ready to prepare for DSPT Version 9?

ANSecurity can help you assess where you are today, identify areas for improvement and build a practical plan towards the 30 June 2027 deadline.

Get in touch with ANSecurity to discuss your DSPT requirements.

LET’S TALK ABOUT YOUR DATA SECURITY