The NHS Data Security and Protection Toolkit has long anchored cyber assurance across health and care. As the threat landscape evolves and national capabilities grow, the question is no longer whether the DSPT is useful — but whether it is still the right instrument for the job.
The Question Nobody Wants to Ask Out Loud
The NHS Data Security and Protection Toolkit has been the backbone of cyber assurance across health and care for years. It provides a common framework, a consistent language, and a mechanism for organisations to demonstrate that minimum expectations around data security are being met. For a system as fragmented as the NHS, that is not a trivial contribution.
But the conversation is changing. As the threat landscape intensifies, as national capabilities mature, and as frontline organisations face mounting pressure to deliver digital transformation without additional resource, questions are growing louder: is the DSPT still the right instrument for the job — or has it become a costly distraction that consumes effort without meaningfully improving resilience?
This is not a comfortable question to ask. But it is the right one.
The Case for Scrapping It
The compliance burden is real and growing. For many NHS organisations, completing the DSPT annually consumes the equivalent of one full-time role. That is not a rounding error — it is a material proportion of a constrained cyber and IT team's capacity. Time spent on self-assessment is time not spent on improving controls, responding to vulnerabilities, or building operational security capability. In an environment where cyber resource is already stretched, that trade-off deserves scrutiny.
The DSPT risks anchoring organisations to the floor. It was not designed to do this, but in practice the toolkit can operate as a ceiling rather than a floor. Completing the DSPT becomes the goal. Meeting the standard becomes the measure of success. For organisations that could achieve significantly more — and some NHS organisations are already operating well ahead of DSPT expectations in key domains — the framework can actually constrain ambition rather than drive it.
The national capability landscape has changed substantially. When the DSPT was conceived, the NHS did not have a central Security Operations Centre providing near real-time visibility across large parts of the estate. It did not have the NHS.net central tenant offering advanced identity, collaboration, security, and device management capabilities at scale, centrally funded. These capabilities represent a fundamentally different assurance model — one based on observable control rather than self-declared compliance. The DSPT was built for a world that no longer fully exists.
Enforced national controls have proven more effective. The mandated rollout of Multi-Factor Authentication across NHS organisations is instructive. It was imperfect in its implementation, but it delivered tangible, system-wide resilience improvements at a fraction of the cumulative cost of annual DSPT compliance cycles. A clear, enforceable national standard with real consequences demonstrably outperformed a broad self-assessment framework in the one area where both applied. That comparison should give us pause.
The question worth asking is a provocative one. What if the NHS shifted from assurance by paperwork to assurance by control and testing? Redirecting the effort currently spent on DSPT submissions could return meaningful FTE capacity to local teams, reduce central administrative overhead, enable investment in red teaming and real-world attack simulation, leverage central SOC visibility for continuous rather than annual assurance, and allow organisations to focus on priority-driven improvements with realistic timelines — rather than completing a toolkit alongside everything else they are trying to deliver.
There is a secondary market that has grown up around DSPT compliance, and it is not serving organisations well. A proliferation of expensive vendor tools now exist whose primary value proposition is demonstrating alignment with the DSPT. They produce dashboards, reports, and indicators that give the appearance of rigorous assurance. In practice, they often generate static, incomplete management information that travels upward through the organisation and lands in front of boards who lack the specialist knowledge to interrogate it meaningfully.
The dynamic this creates is predictable. As long as the submission is complete and enough indicators are green, the conversation moves on. Risk is classified as managed. Scores sit below the threshold that would require escalation. The board sees a report that says standards have been met and, reasonably enough, concludes that the organisation is secure. What the report does not show — what it structurally cannot show — is whether the controls underlying those green indicators are actually working, whether they cover the systems that matter most, or whether they would withstand a determined adversary. That gap between assurance and reality is where incidents happen.
The DSPT did not create this market, and it is not solely responsible for it. But the framework's structure — broad, self-assessed, annual — creates the conditions in which this kind of tool thrives. If the assurance mechanism were based on tested controls and central observability rather than self-declared compliance, the market for tools that generate DSPT-aligned paperwork would shrink considerably. The money currently spent on those tools could be redirected toward the security improvements the tools are supposed to be demonstrating.
The Case Against Scrapping It
Consistency across a fragmented system matters. The NHS is not a single organisation. It is hundreds of trusts, ICBs, GP practices, community providers, ambulance services, and specialist organisations, each with different levels of technical maturity, resource, and risk profile. The DSPT provides a common baseline that applies universally. Remove it without a credible replacement and the risk is not that the well-resourced organisations suffer — it is that the least-resourced ones drift further, creating the weak points that adversaries reliably exploit.
There are regulatory and statutory dimensions that do not simply disappear. The DSPT is not purely a voluntary assurance mechanism. It embeds obligations that connect to legal, regulatory, and audit requirements — including data protection law, NHS Standard Contract conditions, and CQC oversight. Any transition away from the current model would require careful alignment with these obligations, not a clean break from them. The administrative architecture underneath the DSPT is more load-bearing than it sometimes appears.
Central capabilities do not yet cover everything. The NHS SOC and NHS.net controls are significant achievements, but they do not yet reach all systems, all suppliers, or all legacy environments. The DSPT still functions as a mechanism to surface minimum expectations in areas that central visibility cannot yet reach. Scrapping it before those gaps are closed would leave a period of genuine assurance vacuum.
The common language has value. The DSPT gives boards, commissioners, and regulators a shared vocabulary for discussing cyber maturity. Imperfect as it is, that vocabulary enables accountability conversations that would otherwise be much harder to have. Removing it without establishing a replacement language risks making cyber risk invisible at the governance level precisely when it needs to be most visible.
A Better Path Forward
The real opportunity may not be abolition but evolution. The binary choice between keeping the DSPT as it is and scrapping it entirely obscures a more productive question: what would a genuinely modern assurance model for the NHS look like?
A slimmer, more focused framework — one that mandates national controls in critical areas rather than self-assessing across hundreds of indicators, that uses central SOC visibility for continuous assurance rather than annual snapshots, that incorporates independent technical testing alongside self-assessment, and that measures outcomes rather than compliance outputs — could address the legitimate criticisms of the current model without creating the fragmentation risks that abolition would bring.
The MFA example points in the right direction. Fewer mandated controls, enforced with real consequence, tested in practice, supported centrally — that model scales better than broad self-assessment and produces demonstrably better security outcomes.
The goal should be clear and consistent with what the DSPT was always meant to serve: maximise real-world resilience, not compliance output. If the current mechanism no longer does that efficiently — and there is a reasonable case that it does not — then reform is not just desirable. It is overdue.




