NHS DSPT penetration testing is now an evidence-based requirement. It is no longer a tick-box declaration. Is your organisation a Category 2 IT supplier, an operator of essential services, or a genomics provider handling NHS data? Then the 2025-26 Data Security and Protection Toolkit expects more from you. It wants an independent, CREST-approved penetration test report. That report must cover your external infrastructure, applications and APIs. It must also show that critical and high findings have been fixed. Here is what that means in practice, who it applies to, and how to get ready for the next submission window.

Table of Contents
What is the NHS Data Security and Protection Toolkit?
The Data Security and Protection Toolkit (DSPT) is NHS England’s online self-assessment tool. It measures how well an organisation performs against the National Data Guardian’s ten data security standards. Because access to NHS data carries real risk, every organisation with access to NHS patient data or NHS systems must use it. That includes NHS trusts, integrated care boards and clinical support units. It also reaches well beyond the NHS itself. Any commercial IT supplier that processes NHS data, or connects to national NHS systems, has to complete it too.
For years the toolkit worked mostly on self-declaration. An organisation ticked a box confirming a control was in place, then moved on. That changed with version 8, and NHS DSPT penetration testing is where the change shows most.
Why the penetration testing requirement got stricter
The 2025-26 DSPT is aligned to the NCSC’s Cyber Assessment Framework (CAF). NCSC built CAF to help operators of essential services show they meet expected resilience standards under the NIS Regulations. CAF is outcomes-based. Instead of asserting that a control exists, an organisation now has to demonstrate, with evidence, that the control actually works. Each outcome gets scored as not achieved, partially achieved, or achieved.
Applied to security testing, that shift matters a lot. A screenshot of a vulnerability scanner’s summary page is no longer good enough. Assessors want a genuine, independently run penetration test. They also want to see what happened after the findings landed, not just the findings themselves. That is the core of what NHS DSPT penetration testing now demands.
Who needs an independent penetration test for DSPT?
Under the 2025-26 toolkit, mandatory independent assessment, rather than self-assessment, applies to:
- Category 2 IT suppliers: commercial IT suppliers that process or access NHS patient data, or connect to national NHS systems.
- Operators of Essential Services (OES) within scope of the NIS Regulations.
- Genomics organisations nominated by the Department of Health and Social Care.
For these groups, an external assessor now reviews the evidence directly. They no longer accept a self-declared assertion. NHS England has also added the ability to upload independent audit evidence straight into the toolkit.
What NHS DSPT Penetration Testing Needs to Cover
The DSPT doesn’t hand suppliers a rigid testing specification the way PCI DSS does. Still, a clear pattern satisfies assessors, drawn from the toolkit’s own CAF outcomes and from how NHS-focused security firms scope this work:
- Independent execution. A third party runs the test, not an internal team marking its own homework.
- CREST-approved provider. Reports from a CREST member firm carry more weight, because CREST accreditation is itself independently audited.
- Meaningful scope. External infrastructure, web applications and APIs that touch NHS data, not just a token slice of the estate.
- Recognised standards. Findings mapped to the OWASP Testing Guide and scored with CVSS, so severity is comparable across reports.
- Annual cadence. A test older than twelve months won’t satisfy an assessor looking for current evidence.
- Remediation evidence. Not just a list of findings, but proof that critical and high issues were fixed, ideally backed by a retest.
That last point trips up more suppliers than any other. A report ending with a long list of unresolved critical findings, and no follow-up, is not evidence of a working control. If anything, it’s evidence of the opposite. Our guide to what a good penetration test report looks like covers what assessors and auditors actually want to see in that document.
DSPT and DTAC are not the same thing
It’s easy to mix up the DSPT with the Digital Technology Assessment Criteria (DTAC). Both sit under NHS England, and both ask about penetration testing. Still, they check different things. DSPT is an organisation-wide toolkit. It covers a supplier’s entire data security posture. DTAC is a product-level assessment instead. It applies when a specific digital health technology, an app or a clinical platform, is being procured or listed. A supplier selling one product into the NHS may need to satisfy both: DSPT for the organisation, DTAC for the product, each with its own evidence of testing.
Key dates for the current cycle
The 2025-26 DSPT cycle runs on an annual rhythm. Organisations completing a CAF-aligned assessment had to publish interim improvement plan updates by the end of December 2025. Instructions for the next round of improvement plans followed in May 2026, with independent assessments running through the first half of the year. Because the requirement repeats every year, the real takeaway isn’t one deadline to hit and forget. So treat NHS DSPT penetration testing as a recurring annual task. Time it so a current report, and a documented remediation trail, are ready before each new submission window opens.
Choosing a provider for DSPT-aligned testing
Assessors check who did the work, not just what it found. So provider choice matters more here than for a routine internal test. Look for a firm with CREST-certified consultants and a track record testing NHS or healthcare-adjacent environments. NHS DSPT penetration testing gets checked by an outside assessor. So a good provider starts with a scoping conversation about what data and systems actually need covering, rather than sending a fixed-price quote with no questions asked. Our longer guide to choosing a penetration testing company covers the red flags worth watching for, whichever compliance framework is driving the requirement.
Aardwolf Security’s consultants are CREST-certified. We scope engagements around what a specific framework, DSPT included, actually needs evidenced. If your DSPT submission is approaching and you need a report an assessor will accept, we can scope a penetration test around it. Just get in touch to talk through timing and scope.
Frequently asked questions
How often do you need a penetration test for DSPT?
Annually. A report older than twelve months won’t stand as current evidence for a CAF-aligned assessment.
Do all NHS suppliers need a CREST-approved tester?
The toolkit doesn’t mandate CREST by name. But CREST accreditation is the credential assessors recognise most consistently, because CREST member firms are themselves independently audited on methodology and staff competence. A non-CREST report can still be accepted if it shows equivalent independence and rigour, but that’s a harder case to make.
Does Cyber Essentials Plus cover the NHS DSPT penetration testing requirement?
No. Cyber Essentials Plus is its own independent technical check. It is not a substitute for the scoped penetration test that CAF-aligned outcomes expect. Most suppliers need both a current Cyber Essentials or Cyber Essentials Plus certificate and a separate penetration test report.
What’s the difference between DSPT and DTAC penetration testing?
DSPT assesses the whole organisation’s data security posture. DTAC assesses one specific digital product being procured by the NHS. A supplier can need evidence for both at once, scoped differently for each.
What happens if we don’t have a current penetration test report?
The relevant CAF outcome gets marked not achieved or partially achieved. That weakens the overall DSPT submission, and it can affect contracts that require a satisfactory DSPT status as a condition of doing business with the NHS.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.