News

DSPT v9 is here: What’s changed and what NHS organisations need to know

September 28, 2026

DSPT v9 is here: What’s changed and what NHS organisations need to know

NHS England has officially released Version 9 of the Data Security and Protection Toolkit (DSPT) for 2026–27 – but what are the key changes and what do NHS organisations need to know?

Aligned to CAF (Cyber Assessment Framework) v4.0, DSPT v9 includes a number of important changes to the way organisations will need to demonstrate their cyber security and information governance arrangements, alongside existing requirements that continue to apply.

With 49 outcomes, compared with 47 in the previous version, DSPT v9 represents more than a simple update to the assessment. The overall direction is towards greater operational maturity and continuous assurance – organisations increasingly need to demonstrate that controls are not only documented, but actively implemented, monitored, reviewed and improved.

With the submission deadline of 30th June 2027, now is a good time to understand what has changed and start preparing.

What are the biggest changes in CAF-DSPT V9?

While some areas of the framework have seen relatively minor refinements, there are several areas where the requirements have developed more significantly.

Security monitoring and detection

Security monitoring and detection is an area where the framework has evolved.

DSPT v9 places increased emphasis on demonstrating that organisations can effectively identify and investigate cyber security events.

This includes greater focus on:

•  What systems and services are being monitored
•  Logging coverage and retention
•  Protecting logging infrastructure
•  Alert tuning and reducing false positive
•  Detecting abnormal user and system behaviour
•  Security alert investigation and triage
•  Threat intelligence
•  Threat hunting
•  Appropriate skills and capacity within monitoring teams

The emphasis is increasingly on demonstrating that monitoring is effective in practice, rather than simply demonstrating that security technology has been deployed.

Threat intelligence and threat hunting

CAF v4.0 gives greater prominence to understanding attacker methods, motivations and techniques, and using this information to inform cyber risk decisions and security operations.

Threat hunting has a more explicit role within the updated framework, reinforcing the expectation that organisations should complement automated detection with proactive investigation. Rather than relying solely on automated alerts, organisations are expected to proactively search for indicators of compromise and use the findings to improve their detection capabilities.

Secure software development

CAF v4.0 introduces a new section covering the secure development and maintenance of software used in essential services, which is reflected in DSPT v9.

This increases the focus on security throughout the software lifecycle, including secure development practices, security testing, vulnerability management, software dependencies, development and production environments, software updates and ongoing support.

This will be particularly relevant to organisations that develop software internally, as well as those providing software and services to the health and care sector.

Supplier and supply-chain security

Supply-chain security has also been strengthened. Organisations will need to understand the cyber security risks associated with their suppliers and demonstrate that appropriate controls are in place.

This includes supplier assurance, contractual security requirements, dependency management and ongoing monitoring of third-party risk.

Incident response and learning

Incident response requirements have been expanded, particularly around post-incident analysis and learning.

Organisations are expected to review and test their response arrangements, learn from incidents and near misses, and use those lessons to improve their security and resilience.

There is also greater emphasis on understanding the factors that contributed to an incident, including its underlying causes, and using these lessons to inform improvements.

Mandatory requirements and evidence collections

Alongside the changes to the CAF-aligned outcomes, DSPT v9 continues to include a number of specific mandatory requirements and evidence collections. Some of these are established requirements that remain important, while others have been strengthened, expanded or updated for 2026–27.

These include:

•  Top three cyber security risks – organisations must provide their three most significant cyber security risks that could affect patient/service-user care or service delivery.
•  Multi-factor authentication (MFA) – the DSPT continues to collect assurance against the NHS MFA policy, including requirements covering remote access and privileged access. Organisations need a clear view of how MFA is enforced, where permitted exceptions apply, and the evidence available to support their assessment.
•  Post-quantum cryptography (PQC) – organisations need to begin preparing for the longer-term migration to quantum-safe cryptography, including discovery and planning activity in support of the 2028 milestone. Full implementation is not required by the v9 submission deadline; the current requirement is to have a plan addressing the 2028 milestone.
•  Acknowledgement of NHS cyber alerts, including high-severity – organisations must acknowledge high-severity alerts, record decisions and report actions within increasingly shorter timescales (48 hours from 1st July to 31st December 2026, reducing to 24 hours from 1 January to 30th June 2027). This makes it important to have an efficient process for assessing, recording and reporting actions.
•  Unsupported operating systems – organisations need visibility of supported and unsupported operating systems across their managed estate, together with appropriate action and risk management where unsupported systems remain.
•  EDR and ITDR – v9 includes specific requirements relating to Endpoint Detection and Response (EDR) and Identity Threat Detection and Response (ITDR), including requirements around deployment, exceptions and affected devices or identity infrastructure, where applicable.

What does this mean for DSPT preparation?

For organisations preparing for DSPT v9, the assessment is increasingly becoming an ongoing process rather than an annual exercise.

Teams need to be able to understand:
•  What needs to be completed
•  Who is responsible for each requirement
•  What evidence is needed
•  Where gaps or exceptions exist
•  What remediation is underway
•  How progress is being tracked
•  How controls are being reviewed and improved

Managing this across spreadsheets, documents and separate teams can make it difficult to maintain a clear picture of progress – particularly as the requirements become more operational and evidence-focused.

Keeping DSPT preparation on track with the ITHealth Dashboard

The ITHealth Dashboard CAF-DSPT Workflow Module is designed to help organisations manage this process in a structured, collaborative way.

The workflow allows teams to assign outcomes and tasks to the appropriate people, track progress, manage evidence against outcomes, identify gaps, and maintain a clear audit trail of activity.

Following the release of DSPT v9, the ITHealth Dashboard workflow has now been updated to reflect the new requirements.

This will allow NHS organisations using the ITHealth Dashboard to continue managing their DSPT preparation against the latest version of the framework, with the updated v9 outcomes and requirements incorporated.

Supporting more than the DSPT workflow

While the CAF-DSPT Workflow Module provides a structured way to manage the assessment, the requirements in DSPT v9 extend across many areas of day-to-day cyber security management.

The ITHealth Dashboard can help organisations manage this wider picture too – from automated cyber alert reporting, helping teams quickly assess whether they are affected and the potential scale of the impact, to software and licence management, identifying unsupported operating systems, and supplier and contract management to help maintain oversight of third-party risk.

These capabilities help organisations maintain greater visibility of their cyber security position and turn identified risks and requirements into manageable actions.

To find out more about the ITHealth Dashboard and how it can help your organisation prepare for DSPT v9, get in touch with the ITHealth team.

Leave a Comment