NHS DSPT Supplier Requirements: What Evidence You Actually Need
Published 4 August 2026
Who has to engage with the DSPT
The DSPT applies to organisations that have access to NHS patient data or systems. That includes NHS bodies themselves, but also a long tail of suppliers: software vendors, clinical service providers, transcription and coding firms, IT managed service providers, transport and logistics providers handling patient records, and research partners. If your contract touches patient identifiable data, expect to be asked.
The exact standard you must meet depends on your category. Some suppliers must reach "Standards Met"; others complete an entry-level assertion. The contracting NHS body will confirm which applies – always ask before you scope any certification work.
Where certification fits
The DSPT itself is a self-assessment. That is precisely why NHS buyers lean on independent certification as corroborating evidence. Two certificates do most of the heavy lifting:
- Cyber Essentials evidences the five technical controls: firewalls, secure configuration, user access control, malware protection and patch management. Several DSPT assertions reference it directly.
- IASME Cyber Assurance evidences the surrounding governance: information security policy, asset management, risk assessment, staff training, incident response, business continuity and supplier assurance – the areas the DSPT keeps asking about that Cyber Essentials does not reach.
How Cyber Assurance themes line up with DSPT topics
| DSPT topic area | Corresponding Cyber Assurance evidence |
|---|---|
| Personal confidential data and governance | Information security policy, data asset register, legal and regulatory theme |
| Staff responsibilities and training | People theme: training records, acceptable use, onboarding and leavers |
| Managing data access | Access control theme: least privilege, MFA, joiners/movers/leavers process |
| Process reviews and risk | Risk management theme: risk register, treatment plan, review cadence |
| Responding to incidents | Respond and recover: incident response plan, reporting routes, lessons learned |
| Continuity planning | Business continuity theme: tested backups, recovery time objectives, BC plan |
| Unsupported systems and updates | Cyber Essentials patch management plus the asset lifecycle theme |
| Supplier and third-party assurance | Supplier management theme: due diligence, contract clauses, review register |
This is a practical mapping, not an official DSPT crosswalk. Always check your assertions against the current toolkit version.
What NHS buyers actually check
- A current, in-date certificate – lapsed certification fails due diligence immediately.
- Scope alignment – the certified scope must cover the people and systems delivering the contract.
- Third-party issued, not self-declared.
- Evidence you maintain it: a risk register with recent review dates, not a document written once.
- An incident response plan with named contacts and realistic reporting timescales.
Sensible sequencing for a supplier
- Confirm with the NHS body which DSPT standard applies to you.
- Scope Cyber Essentials to cover the contract delivery estate, then certify.
- Complete the DSPT assertions, noting gaps in governance areas.
- Close those gaps through Cyber Assurance Level 1, which forces the documentation into existence.
- Step to Level 2 if the buyer wants an audited certificate.
If a tender deadline is driving this, read Cyber Assurance for tenders – Level 1 is achievable in 4–8 weeks where ISO 27001 is not.
