Skip to main content
    NixInfinity-AI
    NHS Supply Chain

    NHS DSPT Supplier Requirements: What Evidence You Actually Need

    Published 4 August 2026

    Who has to engage with the DSPT

    The DSPT applies to organisations that have access to NHS patient data or systems. That includes NHS bodies themselves, but also a long tail of suppliers: software vendors, clinical service providers, transcription and coding firms, IT managed service providers, transport and logistics providers handling patient records, and research partners. If your contract touches patient identifiable data, expect to be asked.

    The exact standard you must meet depends on your category. Some suppliers must reach "Standards Met"; others complete an entry-level assertion. The contracting NHS body will confirm which applies – always ask before you scope any certification work.

    Where certification fits

    The DSPT itself is a self-assessment. That is precisely why NHS buyers lean on independent certification as corroborating evidence. Two certificates do most of the heavy lifting:

    • Cyber Essentials evidences the five technical controls: firewalls, secure configuration, user access control, malware protection and patch management. Several DSPT assertions reference it directly.
    • IASME Cyber Assurance evidences the surrounding governance: information security policy, asset management, risk assessment, staff training, incident response, business continuity and supplier assurance – the areas the DSPT keeps asking about that Cyber Essentials does not reach.

    How Cyber Assurance themes line up with DSPT topics

    DSPT topic areaCorresponding Cyber Assurance evidence
    Personal confidential data and governanceInformation security policy, data asset register, legal and regulatory theme
    Staff responsibilities and trainingPeople theme: training records, acceptable use, onboarding and leavers
    Managing data accessAccess control theme: least privilege, MFA, joiners/movers/leavers process
    Process reviews and riskRisk management theme: risk register, treatment plan, review cadence
    Responding to incidentsRespond and recover: incident response plan, reporting routes, lessons learned
    Continuity planningBusiness continuity theme: tested backups, recovery time objectives, BC plan
    Unsupported systems and updatesCyber Essentials patch management plus the asset lifecycle theme
    Supplier and third-party assuranceSupplier management theme: due diligence, contract clauses, review register

    This is a practical mapping, not an official DSPT crosswalk. Always check your assertions against the current toolkit version.

    What NHS buyers actually check

    • A current, in-date certificate – lapsed certification fails due diligence immediately.
    • Scope alignment – the certified scope must cover the people and systems delivering the contract.
    • Third-party issued, not self-declared.
    • Evidence you maintain it: a risk register with recent review dates, not a document written once.
    • An incident response plan with named contacts and realistic reporting timescales.

    Sensible sequencing for a supplier

    1. Confirm with the NHS body which DSPT standard applies to you.
    2. Scope Cyber Essentials to cover the contract delivery estate, then certify.
    3. Complete the DSPT assertions, noting gaps in governance areas.
    4. Close those gaps through Cyber Assurance Level 1, which forces the documentation into existence.
    5. Step to Level 2 if the buyer wants an audited certificate.

    If a tender deadline is driving this, read Cyber Assurance for tenders – Level 1 is achievable in 4–8 weeks where ISO 27001 is not.

    Supplying the NHS and unsure what evidence is enough?

    Send us the DSPT requirement or contract clause and a UK IASME-licensed assessor will map it to the certification you actually need.

    Frequently Asked Questions

    Related Cyber Essentials Guides