Skip to content
Cloudreason

The NHS DSPT for cloud estates: evidence without the June scramble

Access to NHS data runs through the Toolkit, and the Toolkit falls due every June.

NHS DSPT · AWS + Azure

Published

If your organisation touches NHS patient data, as a provider or as a supplier, the Data Security and Protection Toolkit is the gate. It is an annual publication, due each June, and your status is visible to the NHS organisations that buy from you or share data with you. For suppliers it is routinely a bid requirement, and it sits inside the Digital Technology Assessment Criteria that NHS buyers apply to digital products. Miss it, or publish a poor one, and the problem is commercial before it is technical.

One toolkit, two shapes

The DSPT now comes in two forms. From the 2024-25 cycle, larger NHS organisations are assessed against a version aligned to the NCSC’s Cyber Assessment Framework: outcome-based objectives covering risk management, protection, detection and response, with independent audit behind the self-assessment. Most other organisations, including commercial suppliers and GP practices, complete the assertion-based version built on the ten data security standards.

The shift matters beyond the NHS bodies it directly covers, because the CAF is the same outcome-based style of assurance used across UK critical infrastructure, and the same style public sector buyers apply through the NCSC Cloud Security Principles. The direction of travel is consistent: fewer box-ticks, more “show us it works”.

What the assertions mean in a cloud estate

However your workloads are hosted, the Toolkit’s questions resolve to a familiar set of controls, and in a cloud estate each has a concrete implementation and a concrete piece of evidence:

  • Multi-factor authentication on remote access and privileged accounts: Entra ID conditional access on Azure, IAM and Identity Center on AWS, with coverage you can report rather than assert.
  • Patching within defined timescales, and no unsupported systems in scope. Update management and instance lifecycle policies produce the record; an aged, forgotten VM produces the finding. The same expectations are audited directly in Cyber Essentials Plus, which many NHS suppliers hold alongside the DSPT.
  • Logging and monitoring that someone demonstrably reviews: Microsoft Defender for Cloud and Sentinel, or CloudTrail, GuardDuty and Security Hub, with triage records.
  • Backups that restore. The Toolkit’s ransomware emphasis is explicit, and the evidence it wants is a tested restore and protected copies, not a backup job that reports green.
  • Access control with a working joiners-and-leavers process, evidenced by review records against the identity provider, not by a policy document.
  • Encryption in transit and at rest, which on both platforms is mostly a matter of switching it on everywhere and being able to show where it is not.

Public cloud is allowed; evidence is the catch

A surprising number of health and care organisations still treat cloud hosting as a compliance question in itself. It is not: NHS guidance has permitted public cloud for years, subject to risk assessment, and UK data residency is available on every major platform. What the Toolkit actually probes is whether the controls around the data operate all year. An estate configured well last June and untouched since will pass the question it is asked and fail the estate it describes.

That gap is the annual June scramble: a year of drift reconstructed into assertions in the fortnight before the deadline. The alternative is the same one that works for every framework on this list: monitor the controls continuously, fix findings when they appear, and let the evidence accumulate so that June is a publication exercise rather than an archaeology project. That is how Cloudreason’s cloud compliance service runs the DSPT for clients, alongside the other frameworks a health-sector estate typically carries. If next June already looks uncomfortable, talk to us while there is time to fix findings calmly.

← Cloud Compliance at Cloudreason

Frequently asked questions

Who has to complete the NHS DSPT?

Every organisation with access to NHS patient data or national NHS systems: trusts and other NHS bodies, GP practices, social care providers, and, importantly, commercial suppliers. If your product or service touches NHS data, buyers will expect to find a current DSPT publication for your organisation.

When is the DSPT deadline?

The annual publication falls due at the end of June each year, and your published status is visible to the NHS organisations you work with. An expired or lapsed publication is not a private problem; it is the first thing a diligent buyer checks.

What changed with the CAF-aligned DSPT?

From the 2024-25 cycle, larger NHS organisations such as trusts are assessed against a version of the Toolkit aligned to the NCSC's Cyber Assessment Framework, with outcome-based objectives and independent audit. Most other organisations, including suppliers and GP practices, continue with the assertion-based version built on the ten data security standards. Either way, the questions land on the same estate.

Can NHS data be hosted in the public cloud?

Yes. NHS guidance has permitted public cloud for years, subject to a risk assessment and appropriate safeguards, and both AWS and Azure offer UK data residency. The requirement is not a particular hosting model; it is being able to evidence that the controls around the data actually operate.

Got an audit date?

Tell us the date and the framework, and we'll tell you honestly what stands between your estate and passing.