After the DSPT Deadline: What to Do Next and How to Prepare for Next Year
The 30 June 2026 DSPT deadline has passed. If you've submitted — even at Approaching Standards — you've met the most important requirement. Now comes the less visible but genuinely useful work: improving what you submitted, keeping evidence current, and getting ahead before the next annual cycle opens in September.
This guide covers what actually happens after you submit, the difference between maintaining your submission and starting over, and what to expect when the next version of the DSPT arrives.
What your submission status means now
The DSPT has two compliance levels: Approaching Standards and Standards Met.
Approaching Standards means you completed all mandatory assertions and uploaded the minimum required evidence. Your organisation's compliance status is shown as "Approaching Standards" on the public register at dsptoolkit.nhs.uk. For most small Category 3 and 4 providers, this is the appropriate first target.
Standards Met means you completed all assertions, including non-mandatory ones, with full evidence. For NHS-contracted organisations, Standards Met is often the expectation in your data sharing agreement — check your contract terms.
If you submitted at Approaching Standards, you can continue working toward Standards Met by adding evidence to the portal. The deadline is when you publish your initial submission, not when you stop improving it.
Improving your submission after June
The portal remains open throughout the year. Common post-deadline improvements:
Filling gaps in non-mandatory items. You may have left some non-mandatory assertions incomplete to hit the deadline. Work through these systematically over July and August while the submission is fresh.
Replacing partial evidence. Some providers submit a policy that was outdated but the only one available, or a training log that was incomplete. Replace these with updated evidence once you've had time to gather it properly.
Updating the assessment notes. Where you wrote "in progress" or "we are working on this" against evidence items, replace those notes with confirmed evidence once it's complete.
Requesting updated supplier assurance. If you submitted a supplier assurance letter that was close to 12 months old, request a fresh one now and upload it. You'll want current documentation before the next cycle opens anyway.
Maintaining evidence between submissions
The most common reason organisations struggle with the DSPT year after year is treating it as a June task rather than an ongoing process. Organisations that submit comfortably in future years — in a fraction of the time compared to the first cycle — typically do three things throughout the year.
Keep training records current. Every new staff member, every joiner after June, needs data security awareness training. If you update your training log as people complete it rather than chasing everyone in April, the evidence is ready when you need it. The same applies to leaving dates: remove leavers from your active staff list at the point they leave, not when the DSPT opens.
Date-stamp policy reviews. When you review your data security policy (which your access control register should show as annual), mark the review date in the document header and on your review schedule. A 12-month-old policy with a visible review date is acceptable evidence. A two-year-old policy with no review date is not.
Ask your IT provider about changes. If your IT setup changes — new server, new cloud platform, new device management solution — ask your provider to confirm in writing how the change affects your data security posture. You'll need this confirmation for the next cycle.
What to expect from the next cycle
NHS England typically releases a new version of the DSPT each September. The v8 cycle, which opened 18 September 2025 and runs to 30 June 2026, will be followed by v9 — expected in September 2026 based on the annual release pattern.
Each new version reflects updated guidance from NHS England and, where relevant, changes to the underlying Cyber Assessment Framework. For Category 3 and 4 organisations, the structure tends to be more stable than for larger organisations. Version 7 to version 8 was unusually disruptive because of the CAF alignment — most Category 3 providers should expect a more incremental update.
When v9 opens, you'll start a new assessment from scratch. Your underlying evidence documents carry over if they remain current: a data security policy reviewed in May 2026 should still be valid for your September 2026 v9 submission, as long as you confirm it against any new requirements. Training records carry over if the training was completed in the last 12 months from the date of assessment.
It's worth setting a diary reminder for September — or watching the DSPT portal for the v9 announcement. Organisations that start the new cycle in September or October tend to submit comfortably by June; those who wait until March scramble.
Check your evidence stays live
One thing that's easy to forget after submission: some of your evidence has an expiry horizon. Policies reviewed in May 2026 are fine for this cycle, but by March 2027 they'll be approaching 10-12 months old and will need refreshing before your v9 submission. Training certificates for staff who completed training in June 2026 will be approaching 12 months old by June 2027.
A simple review schedule helps:
| Evidence type | Typical refresh frequency |
|---|---|
| Data security policy | Annual (at minimum) |
| Staff training records | Annual per staff member |
| IT assurance letter from IT provider | Annual |
| Supplier assurance (PMS, cloud storage) | Annual or on renewal |
| Access control register | Review quarterly; confirm annually |
| Business continuity plan | Annual review (test where possible) |
| Incident log | Ongoing (add incidents as they occur) |
Using your submission for other purposes
A current DSPT submission is useful beyond the toolkit itself:
- CQC well-led assessments reference data security governance. A current, Standards Met or Approaching Standards submission is positive evidence.
- ICB contract renewals often check your DSPT status. Being ahead — Standards Met rather than Approaching Standards — signals organisational maturity.
- NHS Digital Care Hub and similar support networks sometimes ask for DSPT status when organisations request technical assistance or access to NHS shared services.
- Staff onboarding. Your data security policy and training records are the foundation of good information governance for new starters — not just DSPT paperwork.
Next steps
- Take the DSPT readiness quiz to identify any standards where your evidence could be strengthened.
- Use the evidence checklist generator to track which items you've completed and which need work.
- If you're a GP practice, pharmacy, or care home, our ICP-specific guides cover the evidence requirements most relevant to your setting: GP practices, pharmacies, care homes.
This guide is based on DSPT v8 (2025/26) as published by NHS England. Future version details (v9 release date, structure changes) are based on the established annual pattern and have not yet been confirmed by NHS England. Always check the official DSPT portal for current guidance. This is not legal or compliance advice.