Confirm the organisation route
We identify the correct organisation type, current toolkit requirements, applicable assertions and responsible owners.
Health & care data security
The Data Security and Protection Toolkit helps health and care organisations measure performance against the National Data Guardian's data security standards. We help turn its assertions and evidence items into a practical annual programme—not a last-minute form-filling exercise.
How we can help
Prepare an accurate NHS Data Security and Protection Toolkit submission with practical evidence, policy, training, continuity and technical security support.
Who it supports
DSPT applies across a varied health and care ecosystem, including NHS organisations, primary care, pharmacies, dentists, social care organisations and some technology suppliers. The exact evidence route depends on the organisation type and current toolkit version.
We start by confirming that route and the services, people, systems, data and suppliers that support it, so work is proportionate to the organisation rather than copied from another sector.
Evidence over answers
A credible submission connects written policy with training records, system configuration, access reviews, incident arrangements, continuity testing and supplier management. If the evidence exposes a gap, the safest response is a controlled improvement action—not an optimistic answer.
We can coordinate the technical and documentation work with your Data Security and Protection Lead, senior owner, data protection support and existing IT provider.
Keep it live
Toolkit requirements and supporting evidence can change between reporting years. A simple evidence calendar makes training, risk review, supplier assurance, incident learning and continuity testing easier to maintain before the next deadline.
The result is a stronger operating process as well as a more defensible submission.
Simple process
We identify the correct organisation type, current toolkit requirements, applicable assertions and responsible owners.
Existing policies, records, training, systems and supplier arrangements are reviewed against the required evidence items.
Actions are prioritised, evidence is organised and authorised staff retain responsibility for the final annual submission.
Independent decisions stay independent
The submitting organisation remains responsible for the accuracy and approval of its DSPT return. Wrexham Tech Support provides readiness, technical remediation and evidence support and does not approve toolkit status on behalf of NHS England.
Check the current NHS DSPT requirementsConnected assurance
Use the framework that fits the requirement, then reuse compatible controls and evidence without confusing one standard for another.
Practical readiness support for Cyber Essentials, ISO 27001, Defence Cyber Certification, DSPT, PCI DSS and the NCSC Cyber Assessment Framework.
View readiness support Certification supportPrepare confidently for Cyber Essentials and Cyber Essentials Plus with practical gap analysis, remediation and evidence support.
View readiness support Information security managementBuild and prepare an ISO/IEC 27001 information security management system with practical gap analysis, risk treatment, documentation and audit readiness support.
View readiness support Essential services & resilienceAssess and improve cyber resilience against the NCSC Cyber Assessment Framework with outcome mapping, evidence review and prioritised remediation support.
View readiness supportCommon questions
Still unsure? A quick message is enough—we will point you in the right direction.
Organisations with access to NHS patient data and systems are generally expected to complete the toolkit, with requirements varying by organisation type. Confirm the current position with the official DSPT guidance and your NHS customer or contracting authority.
No. It is an annual online self-assessment. Some organisation types may also be subject to independent assessment or audit requirements.
We can coordinate evidence, explain technical requirements and help authorised staff prepare accurate answers. Your organisation must review, approve and publish its own submission.
Yes. DSPT crosses technology, information governance, people and suppliers, so we can divide responsibilities clearly and work alongside your DPO or data protection support.
Ready when you are