The DSPT for Care Providers: What It Asks, and What to Ask Your Supplier
Most care providers meet the Data Security and Protection Toolkit the same way: an email lands saying the deadline is approaching, somebody opens it, finds a long list of questions about things like asset registers and incident response, and closes it again. It gets done in the last fortnight, by one person, at the level of "what is the least we can type here".
That is understandable and it is a missed opportunity, because the DSPT is one of the few pieces of compliance in social care that is genuinely useful to the provider completing it — and increasingly, one that other people check.
This guide covers what the toolkit is, who has to complete it, what the three outcomes mean, where providers usually get stuck, and what to ask the software suppliers you are about to name in your own submission.
What the DSPT actually is
The Data Security and Protection Toolkit is an online self-assessment published by NHS England. Organisations that have access to NHS patient data and systems use it to publish an assessment against the National Data Guardian's 10 data security standards.
Two words in that sentence do a lot of work.
Self-assessment means nobody visits you. You answer, you provide evidence, you publish. That is not a loophole — a published assessment is a statement of position that others rely on, and getting it wrong in your favour is a worse problem than not doing it at all.
Publish means the outcome is public. Anyone can look up an organisation by its ODS code and see its status and its publication history. That includes commissioners, prospective clients, partners and, increasingly, the software suppliers and providers checking each other.
Who has to complete it
Wider than most providers assume. The obligation attaches to access to NHS patient data or systems, not to being an NHS body.
In practice a care provider is usually in scope if it uses NHSmail, or has access to shared care records, GP Connect, the Summary Care Record or similar. Many providers also find it is a condition attached to something else they want:
- Local authority and ICB contracts frequently require a current DSPT.
- Digitisation funding routed through Integrated Care Boards is tied to systems on NHS England's assured list — and the suppliers on that list must hold a DSPT status themselves.
- Data sharing with NHS partners tends to stall without it.
If you are not sure whether you are in scope, the toolkit's own guidance is the place to check, and the answer changes as your integrations do. A provider that adopts shared care records this year is in scope this year even if it was not last year.
The three outcomes, and why the middle one is the one that matters
A published DSPT assessment lands on one of three statuses:
Standards Not Met. Some mandatory evidence is missing or an assertion has not been satisfied. It is a published position, visible to anyone who looks — but it is also recoverable, and organisations do move off it within the same year by completing the outstanding items and republishing.
Standards Met. All mandatory requirements satisfied. This is the bar that matters commercially: it is the level referenced by contracts, and it is the prerequisite NHS England applies to suppliers seeking a place on the assured list for digital social care records.
Standards Exceeded. Everything mandatory, plus the additional assertions the toolkit sets above the baseline.
For most providers, Standards Met is the target and Exceeded is not worth contorting your operation to reach. The gap between them is not where your risk lives. The gap between Not Met and Met is.
What it actually asks of you
The toolkit organises around the National Data Guardian's ten standards, which group into three ideas:
People. Everyone handling personal confidential data understands their responsibilities, training is current and recorded, and there is a named person accountable for data security.
Process. You know what personal data you hold and where. There is a plan for responding to an incident, and it has been tested rather than merely written. Access is granted on the basis of role and removed when someone leaves. Contracts with suppliers who process data on your behalf say the right things.
Technology. Systems are supported and patched, unsupported software is identified and dealt with, and there is protection against the common attack routes.
None of that is exotic. What catches providers out is not the difficulty of any single item — it is that the evidence has to exist, and most of it is the kind of thing that exists informally in a good service and not at all on paper.
Where providers most often get stuck
The asset register. "What systems hold personal data, and who is the supplier?" is a simple question that takes a fortnight the first time, because the honest answer usually includes three things nobody thought of: a spreadsheet on somebody's laptop, a WhatsApp group, and a legacy system still running because one report only exists there.
Leavers. Access removal is the single most common real-world gap. Not policy — practice. A carer who left in March who is still on the rota system in September is both a DSPT finding and an actual risk.
Training records that are current. Not "we do training" but "here is who has done it and when, and here is who is overdue". This is the item most likely to be technically true and evidentially absent.
Unsupported software. Usually a Windows version, sometimes a line-of-business system whose vendor stopped patching it. The toolkit does not require you to have solved it; it requires you to know about it and have a plan.
Incident response that has been rehearsed. A plan nobody has walked through is a document, not a capability, and the toolkit increasingly asks which one you have.
Most of these are easier if your operational systems already record the underlying facts as a by-product of ordinary work — which is the same argument that applies to CQC evidence and for the same reason. A live workforce compliance matrix answers the training and leavers questions directly; a spreadsheet maintained when somebody has time does not.
DSPT, DSCR and the assured list are three different things
This is where the vocabulary gets genuinely confusing, and where you should be most sceptical of supplier marketing — including ours.
DSPT is the data security self-assessment described above. Providers complete it. Suppliers complete it. It says something about data security practice.
DSCR — Digital Social Care Records — is the NHS England programme encouraging providers to move off paper care records, with funding routed through Integrated Care Boards.
The Assured Solutions List is NHS England's list of digital social care record systems that have been through its capability assessment and standards assurance process. Buying from that list is a prerequisite for accessing DSCR funding through your ICB.
Holding a DSPT status is a prerequisite for a supplier seeking a place on the assured list. It is not the same as being on it. If a supplier's marketing blurs those two, treat that as information about the supplier.
What to ask a software supplier
You will name your software suppliers in your own DSPT submission and supplier register, which makes their posture partly your problem. Five questions worth asking, in the order they are most likely to be dodged:
- What is your DSPT status, for which year, and what is your ODS code? The code is the point — it lets you verify the answer rather than take it. A supplier who gives you a status without a code has given you a sentence.
- Where is our data stored? "The cloud" is not an answer. "The UK" is. Ask specifically whether that includes backups, which is where residency claims usually quietly stop being true.
- Is our data separated from other customers' data, and how? Shared tables with a customer column and a separate database per customer are very different answers to the same question.
- What happens at the end of the contract? Full export in a usable format, and deletion on a stated timetable. Get it in writing before you sign, not when you leave.
- Will you complete our security questionnaire and share evidence under NDA? A supplier who will not is telling you something.
Where CareOS stands
Since we are asking you to check suppliers, here is ours, with the means to verify it.
CareOS is operated by Byte River Ltd, registered on the DSPT as an IT supplier under ODS code L8N6V. Our current published status is Standards Exceeded for 2025-26 (version 8), published 22 July 2026. That record is public — you can look it up by the ODS code on the DSPT organisation search rather than taking our word for it, and we would rather you did.
Alongside that: Cyber Essentials Plus, independently assessed (2026); ICO registration ZB847215; all customer data at rest stored in the United Kingdom, backups included; and a separate database per customer organisation rather than shared tables. The detail is on our security page, and we complete security questionnaires and share further evidence under NDA.
To be explicit about the distinction drawn above: that is a DSPT status. It is not a place on the NHS Assured Solutions List, and we do not claim one.
Where to go next
If your own DSPT is due, start with the asset register — it is the item everything else depends on, and the one that takes longest the first time. If it is done and you are looking at what comes after, the questions above are the ones worth putting to whichever systems you are already running.
And if you are choosing a care system, the wider category is covered in our guide to care management software, with the sector-specific versions for home care, supported living, care homes and children's homes.
Frequently asked questions
Do care providers have to complete the DSPT?
The obligation attaches to access to NHS patient data or systems rather than to being an NHS body, so many care providers are in scope — commonly through NHSmail, shared care records, GP Connect or the Summary Care Record. It is also frequently required by local authority and ICB contracts. Scope changes as your integrations change, so a provider adopting shared care records this year is in scope this year even if it was not last year.
What is the difference between Standards Met and Standards Exceeded?
Standards Met means all mandatory requirements are satisfied. Standards Exceeded means those plus the additional assertions the toolkit sets above the baseline. For most providers Standards Met is the right target: it is the level referenced in contracts and the prerequisite NHS England applies to suppliers seeking a place on its assured list. The commercially and practically important gap is between Not Met and Met, not between Met and Exceeded.
Is a DSPT status the same as being on the NHS Assured Solutions List?
No, and the distinction matters. The DSPT is a data security self-assessment that providers and suppliers both complete. The Assured Solutions List is a separate list of digital social care record systems that have been through NHS England's capability assessment and standards assurance process, and buying from it is a prerequisite for DSCR funding through your ICB. Holding a DSPT status is a prerequisite for a supplier seeking a place on that list; it is not the same as having one.
Can I check a supplier's DSPT status myself?
Yes. Published assessments are public and searchable by ODS code on the DSPT portal, showing the organisation's status and its publication history. That is why the ODS code is the thing to ask for: a status without a code is a claim you cannot verify. CareOS is registered as an IT supplier under ODS code L8N6V.
What is CareOS's DSPT status?
Standards Exceeded for 2025-26 (version 8), published 22 July 2026, under ODS code L8N6V for Byte River Ltd, which operates CareOS. The record is public on the DSPT organisation search. A DSPT status is annual, so check the year alongside the status — on any supplier, including us. This is a DSPT status and not a place on the NHS Assured Solutions List, which we do not claim.
Keep reading
- AI Care Management Software in 2026: Every Native Capability, and What It Does for a Care ManagerA working guide to AI in care management software: what it genuinely does across rostering, assessment, care recording, early warning, medication and compliance, the four tests to hold any vendor to, and the questions to ask in a demo.
- Care Management Software: What It Does and How to ChooseWhat the category actually covers, the six modules a complete system needs, why social care and healthcare are different markets, and how to compare vendors against your own worst week rather than their demo.
- Care Home Management Software: A Buyer's Guide for UK HomesWhy residential care needs different software from home care, the eight things a care home system has to get right, what the CQC will ask it to evidence, and how to move off paper without a bad fortnight.
CareOS by care setting
The platform is one system with a workspace per setting. See what it looks like for yours:
See CareOS against your own worst-case Monday
CareOS is UK care management software: rostering, eMAR, care plans, compliance and finance in one system, with a workspace built for each care setting and designed around CQC, Ofsted and DSCR requirements.
Book a demo