Gap analysis
Review your current toolkit position, identify missing evidence and prioritise the work that matters most.
Independent DSP Toolkit help for health and care organisations
We help suppliers, care providers, clinics and healthcare teams understand what is required, gather the right evidence, close gaps and prepare for submission or audit.
Organisations that access NHS patient data or systems use the Data Security and Protection Toolkit to provide assurance on data security and information handling. This site offers independent support, not an official NHS service.
Core services
Review your current toolkit position, identify missing evidence and prioritise the work that matters most.
Turn policies, registers, technical controls, training records and procedures into usable DSPT evidence.
Work through responses, wording, blockers and final checks before the annual toolkit submission.
Prepare for independent assessment with an evidence pack, mock walkthrough and clear remediation plan.
What we cover
DSPT is not just a form. The evidence needs to reflect how your organisation handles people, data, systems, suppliers and incidents.
Senior ownership, accountability, risk registers and evidence of oversight.
Information security, access control, retention, acceptable use and supplier management.
DPIAs, ROPA, privacy notices, lawful basis and data sharing arrangements.
MFA, patching, backups, device security, logging and vulnerability management.
Breach triage, escalation routes, reporting and lessons learned.
Assurance for outsourced services, processors and hosted systems.
Training and awareness
Training can be tailored for directors, managers, care teams, admin staff, clinicians, IT teams and suppliers. The focus is practical behaviour, clear reporting routes and evidence you can actually use.
Common sessions
How it works
Confirm your organisation type, deadline, current DSPT status and risk areas.
Check documents, technical controls, training records and evidence quality.
Prioritise fixes, close obvious gaps and prepare evidence for scrutiny.
Support the final responses and create a plan for the next submission cycle.
Partnered with an East Midlands based independent cyber security consultancy, bringing practical security, governance and assurance experience into DSPT support.
Common questions
It commonly applies to NHS organisations, primary care, adult social care providers, suppliers and organisations that handle NHS patient data or need assurance for NHS work.
We can guide, review, map evidence and support responses, but the submission should still reflect how your organisation actually works.
Some organisation categories have independent assessment expectations. We can help you understand whether that applies and prepare your evidence.
No. This is independent support. The official toolkit remains the NHS England service.
Enquiry form
Send the basics and we will come back to you. If a call is useful, include your number and preferred time.