DSPT Version 9 for 2026–27 is now live. Most established suppliers do not need another long summary of the Toolkit. They need to know what has actually changed, what matters to them, and what they should do differently now.
IN SHORT In short: DSPT Version 9 is the 2026-27 Toolkit cycle, aligned to CAF 4.0, with the submission deadline set for 30 June 2027. For established suppliers, the important job is not simply completing the return: it is checking which Version 9 changes apply and whether last year's answers still match today's environment. |
|---|
Use this alongside NHS supplier readiness guidance, the ongoing assurance article and the Cyber Security Charter evidence guide.
The question is not just 'when is the deadline?'
Whenever a new DSPT version lands, it is easy to turn it into a compliance admin exercise. The question we are hearing in supplier conversations is much more practical: what has actually changed for us, and what do we need to do differently?
The usual instinct is understandable: download the new requirements, pull up last year's submission, work out what changed and start filling the gaps.
That will probably get the return submitted. It can also miss the more useful question: are the answers still true in the business today?
DSPT Version 9 for 2026-27 is now live. The submission deadline is 30 June 2027, Category 2 material is available for IT suppliers, and the cycle is aligned to CAF 4.0 (NHS England, 2026a).
For suppliers already working with NHS organisations, that matters more than the date in the diary. An NHS buyer questionnaire, audit request or renewal conversation can arrive well before June.
What actually changed around Version 9?
Version 9 changes more than the deadline. The September release updates supplier information and the assessment experience, including the move from 'IT supplier' to 'supplier', richer product and service information, and clearer identification of organisations that need to answer supplier questions (NHS England, 2026b).
Version 9 also updates the MFA wording and introduces a mandatory Extended Detection and Response (XDR) policy within the Toolkit. Not every platform change applies identically to every supplier category, so scope matters: confirm the category, the service and the evidence requirement before acting on a generic checklist (NHS England, 2026b).
The product-and-service emphasis is worth noticing. It makes the Toolkit easier to connect to the product or service the NHS organisation is actually buying, rather than treating cyber assurance as a separate annual exercise run by one person in the business.
Do not start by copying last year's answers
Start with scope, not the form.
First confirm which assessment category applies. Then compare Version 9 with the previous cycle and isolate the requirements that materially affect your environment. After that, check the evidence against what is actually operating today.
Only then start writing the return. It sounds slower. In practice, it usually prevents a lot of circular checking later.
AI is another reason last year's answer may no longer be true
DSPT v9 does not create a blanket new AI requirement. But if AI adoption has changed how personal or confidential information is processed, accessed, shared or governed, previous answers may no longer describe the current environment.
Typical triggers include new AI-enabled SaaS, Microsoft 365 Copilot, meeting assistants, AI coding tools, automated document processing and AI features switched on inside existing platforms. Before reusing an answer, check whether data flows, access, suppliers or subprocessors have changed, whether risk assessments or DPIAs need reviewing, and whether policies still match what staff actually do. The ICO's AI and data protection risk toolkit is a practical way to structure that check (ICO, n.d.).
Existing assurance counts, but it is not a blanket answer. A4 recognises DSPT, DTAC, ISO 27001 and Cyber Essentials Plus where they are relevant and proportionate, while leaving room for NHS organisations to ask for more specific evidence where the service or risk justifies it (NHS England, 2026c).
That distinction is important. A current badge or return is useful. An NHS organisation may still want to know what sits underneath it.
Do not build a separate evidence pile for DSPT
One of the easiest ways to create unnecessary work is to collect a fresh set of screenshots, policies and exports for DSPT, then do the same thing again for ISO, an NHS buyer questionnaire and the next audit.
Where the underlying requirement is genuinely the same, maintain the evidence once, keep it current and reuse it appropriately.
The important word is current. Reusing last year's evidence without checking it is not efficiency. It is just a faster way to repeat an old answer.
Evidence area | DSPT | NHS buyer assurance | Other use |
|---|---|---|---|
MFA and privileged access | DSPT | NHS buyer assurance | Cyber Essentials Plus / ISO 27001 |
Vulnerability and patch management | DSPT | NHS buyer assurance | Cyber assurance |
Incident response | DSPT | NHS buyer assurance | Contract / SLA evidence |
Backup and recovery testing | DSPT | NHS buyer assurance | Business continuity |
Data flows and processing locations | DSPT | NHS buyer assurance | DPO / UK GDPR / DTAC |
Supplier and subcontractor risk | DSPT | NHS buyer assurance | Procurement / risk register |
Security governance and ownership | DSPT | NHS buyer assurance | ISO / board assurance |
Secure software practices | Where applicable | NHS buyer assurance | DTAC / Software Security Code of Practice |
Pay particular attention to what sits around your product
For healthtech and technology suppliers, it is very easy to focus all the attention on the product. What NHS buyers increasingly need confidence in is the business around it as well.
For software suppliers, A4 ties assurance directly to the Government's Software Security Code of Practice. The Charter, relevant DSPT status and DTAC can all demonstrate alignment, but they do not remove the need for specific software assurance where that would reduce ambiguity (NHS England, 2026c).
The Software Security Code of Practice covers secure design and development, build-environment security, secure deployment and maintenance, and communication with NHS organisations (DSIT, 2026).
So the practical question is broader than, 'is the application secure?' Can the supplier patch it, monitor it, support it, communicate vulnerabilities, respond when something goes wrong and keep the service secure over time?
Three things to do this month
For an established NHS supplier, the immediate response can stay simple.
1. Confirm what actually changed for your category and service. Do not circulate the whole Version 9 pack and hope every team works out what matters.
2. Pick five important answers from last year's return and verify them against today's environment. If the answer has changed, find out why and who now owns it.
3. Take a recent NHS buyer questionnaire and see how much of it the same evidence can answer. Any question that triggers a hunt across several people is a useful signal.
That exercise tells you much more than simply measuring how many boxes in the Toolkit are complete.
At the end of it, you should know which Version 9 changes matter to you, where the real gaps are, and how quickly you can support the answer when an NHS buyer asks.
The deadline is June. An NHS buyer will not necessarily wait until June.
That is the useful way to frame DSPT v9 for an established supplier.
Complete the Toolkit properly, of course. But use the new cycle to check whether the controls behind your NHS relationships have kept pace with the product, the team and the technology.
The deadline is 30 June 2027. The next NHS buyer question is not obliged to wait for it.
Frequently asked questions
What is DSPT v9?
DSPT Version 9 is the 2026–27 release of the Data Security and Protection Toolkit. The outcomes, assertions and evidence items were released on 2 October 2026, and Version 9 is aligned to CAF 4.0.
When is the DSPT 2026–27 deadline?
The published deadline for the 2026–27 DSPT is 30 June 2027.
Is there a DSPT version specifically for IT suppliers?
The DSPT site provides downloadable Version 9 material for IT Suppliers in Category 2. Suppliers should confirm the category and scope that apply to their organisation rather than assuming the same requirements apply to every supplier.
References
NHS England (2026a) Outcomes, Assertions and Evidence items for the Data Security and Protection Toolkit 2026–27 Version 9. 2 October. Available at: https://www.dsptoolkit.nhs.uk/News/169 (Accessed: 5 October 2026).
NHS England (2026b) System changes and release notes. Updated 4 September 2026. Available at: https://www.dsptoolkit.nhs.uk/News/release-notes (Accessed: 5 October 2026).
NHS England (2026c) Principle: A4 Supply chain. Available at: https://www.england.nhs.uk/long-read/principle-a4-supply-chain/ (Accessed: 5 October 2026).
Department for Science, Innovation and Technology (2026) Software Security Code of Practice. Updated 15 January 2026. Available at: https://www.gov.uk/government/publications/software-security-code-of-practice (Accessed: 5 October 2026).
Information Commissioner's Office (n.d.) AI and data protection risk toolkit. Available at: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/ai-and-data-protection-risk-toolkit/ (Accessed: 6 October 2026).



