Your DSPT Says ‘Standards Met’ on Penetration Testing. Does the Evidence Back That Up?

by Rebecca Sutton

Every year, some NHS suppliers and care providers submit a DSPT return that says “standards met” against penetration testing. Often it’s backed by nothing more than an automated vulnerability scan. NHS England’s own guidance says that does not count. The DSPT penetration testing requirements are stricter than that, and the gap between a scan and a real test is where most submissions fall down.

Two colleagues reviewing a DSPT penetration testing report together at a desk

A scan produces a list of patches to apply. A penetration test works towards a goal. That might mean reaching a network share, or getting an administrator account. It shows what an attacker could actually do. Confusing the two is the single most common way this evidence item goes wrong.

What the DSPT penetration testing requirements actually say

The DSPT sorts organisations into four categories. All of them touch NHS data or NHS systems in some way. The penetration testing expectation runs through the IT protection standard for every category. Category 1 covers large NHS bodies and other operators of essential services. Category 2 covers major IT suppliers. Both face independent audit on top of the self-assessment.

NHS England’s guidance on this evidence item is clear on four points. Testing should happen at least once a year. It should cover the organisation’s critical network structure, including server farms. It should be carried out, or overseen, by someone with recognised accreditation. Acceptable options are a CREST-scheme tester, The Cyber Scheme, a CHECK Team Leader, or a testing organisation certified to ISO 27001 and/or ISO 9001.

None of that is satisfied by pointing a free scanner at a public-facing site once a year and filing the output.

Why the gap persists

Part of the problem is cost. Smaller providers, especially community and social care organisations in Category 3, are working through a long self-assessment on a tight budget. A proper scoped penetration test can look like an expensive extra when a scanner subscription already exists. NHS England has actually built an answer into the toolkit itself. Organisations can “buddy up” with another care organisation and test each other’s environments. It’s a genuinely useful route that not enough smaller providers seem to know about.

The other part is timing. A test commissioned in the final fortnight before a DSPT deadline leaves no room to fix anything a tester finds. The submission then goes in with unresolved critical findings, or the deadline slips. Independent auditors reviewing Category 1 and 2 submissions notice both.

Category doesn’t change the standard, only the scrutiny

It’s tempting for a Category 3 or 4 organisation to read “self-assessment, no independent audit” and treat the DSPT penetration testing requirements as lower stakes. The wording of the requirement doesn’t change by category. Only the odds of an outside party checking it change. A commissioner deciding whether to award a contract can ask to see the evidence behind a self-assessed “standards met.” So can a larger NHS body deciding whether to accept a smaller supplier onto its network. A supplier that cannot produce a real test report loses that conversation, whichever category filed the toolkit.

Certification elsewhere is not a shortcut

Holding Cyber Essentials Plus or ISO 27001 does not exempt an organisation from the DSPT’s own penetration testing evidence item. NHS England has confirmed there is no automatic pass-through. But it can cut duplicated effort. If the testing behind that certification meets the DSPT’s own frequency and scope expectations, and the paperwork is kept, it may count twice. Treating the two as separate ticks on separate forms, run months apart against different scopes, wastes money that a single well-scoped test could have covered.

What good evidence actually looks like

Meeting the DSPT penetration testing requirements in a way that survives scrutiny needs three things behind the “standards met” answer. First, a test carried out by an accredited tester within the last year. Second, a scope that covers the systems that actually matter, not just the parts that are easiest to test. Third, proof that whatever the test found was fixed, not just filed. For Category 1 organisations, assessed against the Cyber Assessment Framework, that third point matters as much as the test itself. The framework is built around outcomes. “We found the problem and left it” is not the outcome anyone is asking for.

The report itself has to say something useful too. Picture a scan output listing forty medium-severity CVEs, with no context on which ones are actually reachable. Now compare that to a penetration test report that walks through how a tester chained a handful of those same weaknesses into real access to a patient scheduling system. They are not the same document, and auditors reviewing Category 1 and 2 evidence see both kinds often enough to tell the difference within a page.

Where the scan-as-pentest habit actually costs money

Most organisations that submit scan output as penetration testing evidence are not being careless. They are working through a long toolkit on a tight security budget. So they treat this item like the dozens of others that can be answered straight from existing documentation. But this one gets checked differently. An independent auditor reviewing a Category 1 or 2 submission can, and does, ask for the underlying report. They will also want the tester’s accreditation and the remediation trail. A submission that cannot produce those loses more time under deadline pressure than a proper test would have taken in the first place. The cheap route on paper becomes the expensive one once findings come back attached to it.

Frequently asked questions

Will a vulnerability scan satisfy the DSPT penetration testing evidence item?

No. NHS England’s guidance treats scanning and penetration testing as separate controls. A scan can support the evidence, but it does not replace goal-directed manual testing.

How often is “at least annually” actually enforced?

The guidance sets annual testing as the baseline. An extra test is expected after any significant change to the network or systems in scope, such as a new patient-facing system going live.

What accreditation should we ask a tester for?

NHS England’s guidance names CREST-scheme testers, The Cyber Scheme, CHECK Team Leaders, or an organisation certified to ISO 27001/9001. Ask for proof, not just a claim. CREST status can be checked directly on the CREST Marketplace.

Does CHECK accreditation matter for NHS suppliers specifically?

Not usually. CHECK is aimed mainly at central government and critical national infrastructure work. For most NHS-adjacent organisations, a CREST-accredited provider satisfies the DSPT’s accreditation list without needing CHECK.

What actually gets checked if an auditor questions our submission?

For Category 1 and 2 organisations, expect an auditor to ask for the underlying test report, evidence of the tester’s accreditation, and a record of what was found and fixed. A one-line summary with no supporting documentation is the most common reason this evidence item gets challenged.

We’re a small supplier with almost no security budget. What’s the realistic minimum?

Use the DSPT’s own “buddy up” option. Test another care organisation’s environment in exchange for having yours tested. It satisfies the independence requirement without a commercial engagement fee, and it’s a genuinely underused route worth raising with peer organisations before you assume a full commercial test is the only option.

If your last penetration test was really a scan with a different name on the cover, get a proper scoped test booked in before your next DSPT window opens. It’s better than an auditor finding out first. Get in touch to talk through what your category actually requires, and how to scope it against your submission deadline rather than your budget line.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like