NHS DSPT · AWS + Azure
Published
If your organisation touches NHS patient data, as a provider or as a supplier, the Data Security and Protection Toolkit is the gate. It is an annual publication, due each June, and your status is visible to the NHS organisations that buy from you or share data with you. For suppliers it is routinely a bid requirement, and it sits inside the Digital Technology Assessment Criteria that NHS buyers apply to digital products. Miss it, or publish a poor one, and the problem is commercial before it is technical.
One toolkit, two shapes
The DSPT now comes in two forms. From the 2024-25 cycle, larger NHS organisations are assessed against a version aligned to the NCSC’s Cyber Assessment Framework: outcome-based objectives covering risk management, protection, detection and response, with independent audit behind the self-assessment. Most other organisations, including commercial suppliers and GP practices, complete the assertion-based version built on the ten data security standards.
The shift matters beyond the NHS bodies it directly covers, because the CAF is the same outcome-based style of assurance used across UK critical infrastructure, and the same style public sector buyers apply through the NCSC Cloud Security Principles. The direction of travel is consistent: fewer box-ticks, more “show us it works”.
What the assertions mean in a cloud estate
However your workloads are hosted, the Toolkit’s questions resolve to a familiar set of controls, and in a cloud estate each has a concrete implementation and a concrete piece of evidence:
- Multi-factor authentication on remote access and privileged accounts: Entra ID conditional access on Azure, IAM and Identity Center on AWS, with coverage you can report rather than assert.
- Patching within defined timescales, and no unsupported systems in scope. Update management and instance lifecycle policies produce the record; an aged, forgotten VM produces the finding. The same expectations are audited directly in Cyber Essentials Plus, which many NHS suppliers hold alongside the DSPT.
- Logging and monitoring that someone demonstrably reviews: Microsoft Defender for Cloud and Sentinel, or CloudTrail, GuardDuty and Security Hub, with triage records.
- Backups that restore. The Toolkit’s ransomware emphasis is explicit, and the evidence it wants is a tested restore and protected copies, not a backup job that reports green.
- Access control with a working joiners-and-leavers process, evidenced by review records against the identity provider, not by a policy document.
- Encryption in transit and at rest, which on both platforms is mostly a matter of switching it on everywhere and being able to show where it is not.
Public cloud is allowed; evidence is the catch
A surprising number of health and care organisations still treat cloud hosting as a compliance question in itself. It is not: NHS guidance has permitted public cloud for years, subject to risk assessment, and UK data residency is available on every major platform. What the Toolkit actually probes is whether the controls around the data operate all year. An estate configured well last June and untouched since will pass the question it is asked and fail the estate it describes.
That gap is the annual June scramble: a year of drift reconstructed into assertions in the fortnight before the deadline. The alternative is the same one that works for every framework on this list: monitor the controls continuously, fix findings when they appear, and let the evidence accumulate so that June is a publication exercise rather than an archaeology project. That is how Cloudreason’s cloud compliance service runs the DSPT for clients, alongside the other frameworks a health-sector estate typically carries. If next June already looks uncomfortable, talk to us while there is time to fix findings calmly.