Sovereign Cloud for Healthcare: NHS DSPT Compliance and Patient Data Sovereignty

The NHS Data Security and Protection Toolkit (DSPT) is an annual self-assessment that every organisation with access to NHS patient data or systems must complete, including commercial suppliers. Since its alignment to the NCSC Cyber Assessment Framework, it no longer accepts stated controls as proof. It asks for evidence that controls work. Where patient data is hosted, and under which country’s law, is part of that evidence.

Quick facts

  • The framework: the DSPT is the NHS’s annual self-assessment for every organisation with access to NHS patient data and systems – including suppliers.
  • The change: DSPT v8 (published 18 September 2025) is aligned to the NCSC Cyber Assessment Framework v3.4 – outcome-based evidence rather than checkbox compliance.
  • The cycle: the 2025/26 submission closed on 30 June 2026. NHS England issues a new version each September, and has signalled that CAF alignment will extend to more organisation types.
  • Who is audited: Category 1 and Category 2 organisations require an independent audit. Category 2 covers IT suppliers with 50+ staff and £10m+ turnover – including cloud hosting providers.
  • The supply chain: the NHS Standard Contract requires providers to verify that their processors and joint controllers have completed a DSPT or equivalent. Submission status is publicly visible.
  • No shortcuts: ISO 27001 and Cyber Essentials Plus do not exempt an organisation from the CAF-aligned DSPT – but they are the strongest evidence base for completing it.
  • The sovereignty angle: patient data held with a US-owned provider remains subject to the US CLOUD Act. A UK sovereign provider removes that exposure from the risk assessment.

What is the NHS DSPT and who must complete it?

The Data Security and Protection Toolkit is an online self-assessment against national data security and information governance standards. Every organisation with access to NHS patient data and systems must complete it annually.

That scope is wider than the NHS itself. It covers trusts and integrated care boards, but also GP practices, care providers, and pharmacies. Critically, it also covers the commercial suppliers and IT companies that process patient data on their behalf – including hosting providers.

Since September 2024, the DSPT has been progressively aligned to the National Cyber Security Centre’s Cyber Assessment Framework. NHS trusts, integrated care boards, commissioning support units, and arm’s length bodies moved first. Designated operators of essential services and genomics organisations followed from September 2025.

The CAF-aligned assessment is structured around five objectives. Four come from the CAF itself: managing risk, protecting against attack, detecting events, and minimising impact. The fifth is NHS-specific, covering the lawful and appropriate use and sharing of patient information.

Which DSPT category are you in?

The DSPT sorts organisations into four categories. Your category determines which evidence items apply, how the questions are worded, and whether you need an independent audit.

CategoryWho it coversIndependent audit required?
Category 1Large NHS bodies – trusts, integrated care boards, commissioning support units, and DHSC arm’s length bodiesYes
Category 2Large IT suppliers – external organisations supplying digital goods or services to the NHS or care sector with 50+ staff and £10m+ turnover, plus designated operators of essential servicesYes
Category 3Community providers – pharmacies, domiciliary care providers, residential care homes, and smaller IT suppliersNo
Category 4GP practices delivering primary care, diagnostics, minor surgery, and health promotionNo

If you supply cloud hosting, SaaS, or IT infrastructure to an NHS or care organisation and you exceed both the staff and turnover thresholds, you are a Category 2 IT supplier and an independent audit is mandatory. Smaller suppliers should confirm their organisation type on the toolkit rather than assuming, because selecting the wrong category creates an evidence mismatch that surfaces at audit.

Key takeaway: The DSPT is not an NHS-internal exercise. If your organisation touches NHS patient data – as a provider, a supplier, or a processor – an annual DSPT submission is the price of admission. Your status is publicly visible.

What changed with the CAF-aligned DSPT?

DSPT v8, published on 18 September 2025 and aligned to CAF version 3.4, delivered the toolkit’s largest structural change since it launched. Three shifts matter most:

  • Outcome-based evidence. It is no longer enough to state that a control exists. Organisations must demonstrate that controls work and are maintained – training records, tested recovery plans, auditable access logs – not policy documents in a drawer.
  • Independent assessment. Category 1 and Category 2 organisations must have their self-assessment validated by an independent audit. NHS England points organisations toward assessors recognised under the NCSC Cyber Resilience Audit scheme. An interim self-assessment milestone at 31 December 2025 pulled the timetable forward.
  • No certification shortcuts. ISO 27001 and Cyber Essentials Plus do not exempt an organisation from any part of the CAF-aligned DSPT. They remain valuable, because independently audited certifications are exactly the kind of evidence the framework wants. They supplement the assessment rather than replace it.
Checklist transforming into a shield, representing the DSPT's shift from checkbox compliance to outcome-based evidence

Where the 2026/27 cycle stands

The 2025/26 submission closed on 30 June 2026. NHS England publishes a new toolkit version each September, so the 2026/27 edition is expected shortly, and NHS England has signalled that CAF alignment will extend to further organisation types.

For suppliers, that makes the second half of the year the working window, not a quiet period. Independent assessments take time to scope, run, and remediate. Evidence gathered now – access logs, tested failover, penetration test reports, current certificates – is the evidence the next submission draws on. Organisations that treat the DSPT as a June activity consistently discover gaps too late to close them.

Enforcement through the NHS Standard Contract

The commercial enforcement sits in the NHS Standard Contract. It requires every NHS provider to verify that its processors and joint controllers have completed a DSPT or equivalent. A supplier showing ‘Standards Not Met’ on the public register is a procurement problem, not just a compliance one. If you sell into the public sector, the same evidence supports G-Cloud and wider public sector procurement.

Why is hosting jurisdiction part of patient data security?

Health data is special category data under UK GDPR – the highest tier of protection the framework recognises. The DSPT’s NHS-specific objective is explicitly about the lawful and appropriate use and sharing of patient information. Both frameworks assume the organisation knows, and controls, who can access that data and under what legal authority.

Where the US CLOUD Act comes in

Patient data held with a US-headquartered cloud provider – even in a UK region – remains within reach of the US CLOUD Act. US authorities can compel disclosure without a UK court order, and potentially without notification to the data controller.

Storing data in a UK region gives residency. It does not give sovereignty. Residency describes where data sits; sovereignty describes which nation’s laws govern it. The mechanics are covered in our guide to UK sovereign cloud hosting.

For a healthcare organisation the practical point is simple. Foreign legal exposure over special category patient data is a risk that must be assessed, documented, and justified – or removed. A UK-incorporated sovereign provider removes it. The data is governed exclusively by UK law, and there is no foreign parent entity through which disclosure could be compelled.

Patient data protected within a UK jurisdiction boundary, shielded from foreign legal access

Key takeaway: The DSPT asks organisations to evidence control over patient data. Jurisdiction is part of control. A provider answerable to a foreign government is a gap in the evidence, however secure its UK data centre.

What did the Synnovis attack teach the health sector about suppliers?

On 3 June 2024, the Qilin ransomware group attacked Synnovis, a pathology services provider to London NHS trusts. By NHS England’s count, the attack caused delays to more than 11,000 outpatient and elective procedure appointments in south-east London – 10,152 acute outpatient appointments and 1,710 elective procedures at King’s College Hospital and Guy’s and St Thomas’. Services were not fully restored until December 2024.

The hospitals’ own systems were not the ones attacked. Their pathology supplier’s were, and the disruption became theirs overnight.

Two details matter more than the headline figures. The reported root cause was a service account without multi-factor authentication – a single access control gap of exactly the kind the DSPT asks organisations to evidence. And it took nearly 18 months for Synnovis to complete its forensic investigation and begin notifying downstream NHS organisations that their patients’ data had been compromised. Those trusts could not tell their own patients until their supplier told them.

Three questions to ask your hosting provider

The CAF-aligned DSPT reflects this directly. Supply chain assurance, incident response readiness, and minimising the impact of incidents are assessed outcomes, not aspirations. For hosting, that translates into three questions every healthcare organisation should be able to answer in writing:

  • What are the provider’s recovery commitments? The service agreement should define a recovery point objective and a recovery time objective, with evidence of tested failover. An assurance that backups exist is not enough.
  • Is the recovery environment as protected as the primary one? Replicated patient data carries the same UK GDPR and DSPT obligations as live data. This is the case for sovereign DRaaS: recovery infrastructure under the same UK jurisdiction and certifications as production, with continuous replication delivering a 1-second recovery point objective.
  • How quickly will they tell you? Breach notification duties under UK GDPR run to tight deadlines, and you cannot meet them if your processor takes months to establish what was taken. Ask what the contractual notification window is, and what the provider commits to telling you within it.

How does hosting choice affect your DSPT evidence?

The DSPT does not prescribe a hosting model. It demands evidence. The hosting decision determines how much of that evidence already exists, and how easily it can be produced at audit.

Five-segment shield representing the CAF-aligned DSPT assessment outcomes
DSPT expectationWhat it means for hostingEvidence a sovereign provider gives you
Managing risk and supply chain assuranceYou must show your provider meets appropriate security standardsCurrent, independently audited ISO 27001, ISO 22301, CSA STAR Level 2, and Cyber Essentials Plus certificates, with registration numbers
Protecting against cyber attackPerimeter controls and vulnerability management that are actively maintained and testedNext-generation firewalls, encryption at rest and in transit, and annual penetration testing reports
Access control and accountabilityDemonstrable, auditable control over who touches systemsRole-based access, multi-factor authentication, full access logging, and security-cleared UK staff
Detecting and responding to eventsMonitoring and response capability that actually operates24/7/365 monitoring with UK-based support and documented response times
Minimising the impact of incidentsTested recovery, not theoretical backupContracted RPO and RTO, continuous replication, and failover testing evidence
Lawful use and sharing of patient informationWho can access patient data, and under which legal authorityUK-only residency and UK-exclusive jurisdiction – no foreign legal process can reach the data

DSPT hosting evidence checklist

Before your next submission, confirm you can produce each of the following from your hosting provider on request:

  • In-date certificates for ISO 27001, ISO 22301, and Cyber Essentials Plus, with registration numbers and scope statements covering the environment holding your data
  • A signed data processing agreement naming all sub-processors
  • Written confirmation of data residency, including backups and replicas
  • Written confirmation of corporate ownership and jurisdiction, including any foreign parent entity
  • The most recent independent penetration test report or summary
  • Contracted RPO and RTO figures, plus evidence of the last tested failover
  • Access control documentation covering role-based permissions, MFA enforcement, and log retention
  • Confirmation of where support staff are located and what vetting they hold
  • The contractual breach notification window

If your provider cannot supply an item quickly, that is the gap your assessor will find.

How does BlackBox support healthcare organisations?

BlackBox Hosting is a UK-incorporated sovereign cloud provider operating from Tier 3+ data centres in London, with no US parent entity, no US subsidiaries, and no US-based staff. Patient data hosted with BlackBox is governed exclusively by UK law, under UK-only residency covering every server, backup, and replica.

  • Independently audited certifications – ISO 27001:2022 (IS 766577), ISO 22301 (BCMS 773897), ISO 20000-1 (ITMS 689313), ISO 9001 (FD 689980), ISO 14001 (EMS 751332), CSA STAR Level 2 (STAR 743786), and Cyber Essentials Plus. Certificates are available to download for your evidence pack.
  • Security-cleared UK staff – 24/7/365 monitoring and support from UK-based engineers, with all staff security-cleared.
  • Tested protection – Fortinet next-generation firewalls, AES-256 encryption at rest and in transit, granular role-based access controls with full audit trails, and annual penetration testing.
  • Sovereign DRaaS – recovery infrastructure under the same UK jurisdiction and certifications as production, with a 1-second recovery point objective through continuous replication.
  • Public sector ready – 99.999% uptime guarantee and G-Cloud 14 listing on the Crown Commercial Service Digital Marketplace.

“Healthcare runs on trust twice over – patients trust clinicians, and clinicians trust the systems holding the record. The DSPT now asks organisations to prove that second layer works. Knowing exactly which law governs your patient data, and being able to say it is UK law alone, is the simplest piece of evidence there is.”

– Matt Burden, Founder & Managing Director, BlackBox Hosting

Key takeaway: The CAF-aligned DSPT rewards organisations that can produce evidence, not assertions. A sovereign hosting arrangement generates that evidence by design. Certified infrastructure, auditable access, tested recovery – and one answer to the jurisdiction question: the UK.

Building your DSPT evidence pack?

Talk to our UK team about sovereign hosting that produces the evidence your assessor asks for.

Speak to a specialist

FAQ: The NHS DSPT and cloud hosting

What is the NHS Data Security and Protection Toolkit?

The DSPT is an annual online self-assessment against national data security and information governance standards. It is required of every organisation with access to NHS patient data and systems. Since 2024 it has been progressively aligned to the NCSC Cyber Assessment Framework, with version 8 published on 18 September 2025 and aligned to CAF version 3.4.

Who needs to complete the DSPT?

NHS trusts, integrated care boards, GP practices, care providers, pharmacies, and any supplier or IT company that processes NHS patient data. The NHS Standard Contract also requires providers to verify that their processors and joint controllers have completed a DSPT or equivalent.

What are the DSPT categories?

The DSPT sorts organisations into four categories. Category 1 covers large NHS bodies such as trusts, integrated care boards, commissioning support units and arm’s length bodies. Category 2 covers large IT suppliers and designated operators of essential services. Category 3 covers community providers such as pharmacies and care homes, along with smaller IT suppliers. Category 4 covers GP practices. Categories 1 and 2 require an independent audit.

Am I a Category 2 IT supplier?

You are classified as a Category 2 IT supplier if you supply digital goods or services to NHS or care organisations, including cloud hosting, SaaS platforms or IT infrastructure, and your organisation has 50 or more staff and turnover above £10 million. Category 2 organisations must complete a mandatory independent audit as part of their submission.

When is the DSPT deadline?

The DSPT runs on an annual cycle with a 30 June deadline. The 2025/26 submission closed on 30 June 2026. NHS England publishes a new toolkit version each September, so evidence gathering for the following cycle begins immediately after submission rather than in the spring.

Does ISO 27001 or Cyber Essentials Plus exempt us from the DSPT?

No. There are no exemptions from the CAF-aligned DSPT for existing certifications. They are, however, strong supporting evidence. Independently audited security certifications are exactly what the outcome-based assessment wants to see, particularly for supply chain assurance.

Can NHS patient data be hosted with a US cloud provider?

Storing it in a US provider’s UK region gives residency only. The data remains subject to the US CLOUD Act through the provider’s American parent company. That foreign legal exposure over special category health data must be risk-assessed and justified. A UK-incorporated sovereign provider removes the exposure rather than mitigating it.

What does the NHS Standard Contract require of suppliers?

Providers must verify that processors and joint controllers handling patient data have completed a DSPT or equivalent. Submission status is publicly visible on the DSPT register, so an incomplete or failed submission is visible to commissioners and prospective NHS buyers.

How does sovereign cloud hosting support DSPT compliance?

It generates the evidence the CAF-aligned assessment asks for: certified and independently audited infrastructure, UK-only residency for patient data, auditable access controls with UK-based staff, tested recovery objectives, and annual penetration testing. It also gives a clean answer to the jurisdiction question, because the data is governed by UK law alone.

#main-content .dfd-content-wrap {margin: 0px;} #main-content .dfd-content-wrap > article {padding: 0px;}@media only screen and (min-width: 1101px) {#layout.dfd-portfolio-loop > .row.full-width > .blog-section.no-sidebars,#layout.dfd-gallery-loop > .row.full-width > .blog-section.no-sidebars {padding: 0 0px;}#layout.dfd-portfolio-loop > .row.full-width > .blog-section.no-sidebars > #main-content > .dfd-content-wrap:first-child,#layout.dfd-gallery-loop > .row.full-width > .blog-section.no-sidebars > #main-content > .dfd-content-wrap:first-child {border-top: 0px solid transparent; border-bottom: 0px solid transparent;}#layout.dfd-portfolio-loop > .row.full-width #right-sidebar,#layout.dfd-gallery-loop > .row.full-width #right-sidebar {padding-top: 0px;padding-bottom: 0px;}#layout.dfd-portfolio-loop > .row.full-width > .blog-section.no-sidebars .sort-panel,#layout.dfd-gallery-loop > .row.full-width > .blog-section.no-sidebars .sort-panel {margin-left: -0px;margin-right: -0px;}}#layout .dfd-content-wrap.layout-side-image,#layout > .row.full-width .dfd-content-wrap.layout-side-image {margin-left: 0;margin-right: 0;}