Skip to content

DSPT Audit: Who Actually Needs One

By Brian CrockerLast reviewed: 7 October 2026

If you have been told you need a "DSPT audit", check which group you are in before you go looking for an auditor. For most small providers the answer is that no audit is required, and the request is a misunderstanding worth clearing up rather than a cost worth budgeting for.

For 2026-27, NHS England's audit notice is headed "DSPT Audit 26-27 Areas of Mandatory Audit NHS Trusts, ICBs, ALBs, CSUs, OES, Genomics and IT Suppliers". Its 2024-25 audit guidance set out the contractual basis for independent providers and suppliers: "It is mandated via the NHS Standard Contract and the DSPT requirement that the following organisations annually complete a DSPT audit/independent assessment following this guidance: — Independent Providers who have been designated Operators of Essential Service. — IT Suppliers".

The same 2024-25 guidance covered the large NHS bodies separately — "NHS Trusts (Acute, Foundation, Ambulance and Mental Health), Integrated Care Boards, Commissioning Support Units and DHSC Arm's Length Bodies".

Neither list includes care homes, domiciliary care agencies, community pharmacies, dental practices, opticians or GP practices.

Why you may have been told otherwise

Four things generate the confusion, and they are worth separating because the right response differs:

"Audit" is used loosely. Plenty of guidance — including ours — talks about auditing your own evidence before you submit. That is a self-check, not an independent audit. Our DSPT readiness check is that kind of exercise.

Your IT supplier may genuinely be in scope. The Category 2 threshold is specific: a company "that meets all the criteria of 50+ staff, a turnover of £10m+ and supplies digital (either software and/or physical) goods and services to the NHS and/or care" completes the IT Supplier assessment — and IT Suppliers are one of the two mandated-audit groups. If your care planning or PMR supplier mentions their DSPT audit, they are talking about their own obligation, not yours. That is useful to you as Standard 10 evidence, which our supplier assurance guide covers.

A commissioner has asked for "assurance". Usually they want your published status. It is public — searchable on the DSPT portal by organisation name or ODS code — so you can point them at it directly.

Somebody has read trust-facing guidance. Most published material about DSPT audits is written for organisations on the CAF-aligned assessment. Our DSPT CAF alignment guide covers who is actually on that and who is not.

What an audit involves, for those who do need one

Worth knowing, if only so you can see how far it is from what a small provider does.

For CAF-aligned organisations, NHS England describes the scope: "There is a total of 47 outcomes in the CAF-aligned DSPT, which will all be assessed over a multi-year period. Each year, a selection of outcomes from across the five objectives will be tested by independent assessment providers." That page dates from 2024-25 and has not been updated for the outcome count: NHS England's 2026-27 (version 9) CAF-aligned workbook lists 49 outcomes.

The selection is part mandated, part chosen, and the split is set fresh each year. NHS England's original framing was that it would "mandate a common core set outcomes to be assessed for all organisations that undertake the CAF-aligned DSPT, while a further four outcomes will be selected by individual organisations", board-approved, reflecting "areas of concern that warrant additional assurance".

For the current cycle, NHS England's "DSPT Audit 26-27 Areas of Mandatory Audit NHS Trusts, ICBs, ALBs, CSUs, OES, Genomics and IT Suppliers (01 October 2026)" sets out two populations, and the numbers differ from that earlier framing:

  • NHS Trusts, ICBs, ALBs, CSUs, OES providers and Genomics organisations — "there are 11 mandated outcomes to be audited (listed below) with organisations selecting 1 outcome of their choice." The eleven are A1b Roles and responsibilities, A3a Asset management, B2c Privileged user management, B2d Identity and access management, B3a Understanding data, B4c Secure management, B6a Culture, B6b Training, C1e Personnel skills for monitoring and detection, D1c Testing and exercising, and E4a Managing records.
  • IT Suppliers — not CAF outcomes at all, but a list of 12 assertions: 1.1, 2.2, 3.1, 3.2, 4.1, 6.2, 7.1, 8.1, 8.2, 9.2, 9.6 and 10.2.

The 2025-26 notice (15 October 2025) was different: 9 mandated outcomes plus 3 chosen for NHS Trusts, ICBs, ALBs and CSUs, 8 plus 4 for OES and Genomics organisations, and a different list of 12 assertions for IT Suppliers, of which only 9.6 carries over. The mandated set is republished annually — check the current year's notice rather than reusing last year's list.

For an audit that covers evidence items (for 2026-27, IT Suppliers), certification can reduce that scope. NHS England's 2024-25 audit guidance says: "Evidence items which are covered by an exemption for CE+ and/or ISO27001 will not require further auditing, once it is confirmed that the scope of the certification covers all the health and care data being processed." Note where the weight sits in that sentence — the certificate has to cover all the health and care data, not some of it.

What Category 3 and 4 organisations face instead

No auditor, but not no scrutiny. Three things stand in for it:

Your submission is public. Anyone can look up your published level. Digital Care Hub is direct about who does: "Commissioners, CQC inspectors, families and people using care services can also check the DSPT status of a care service."

Your action plan is part of the record. Publishing at Approaching Standards requires uploading a plan for the remaining questions. That plan is a commitment with your name on it, and next year's submission is read against it.

Your assertions are yours. The DSPT is a self-assessment. Nobody validates your evidence before publication — which sounds lighter than an audit until the year an incident makes someone read back what you asserted.

The practical implication: the discipline that would survive an audit is worth having anyway. Dated policy reviews, a training completion report you can pull any week, an access register that matches reality, supplier assurance on file. Our evidence requirements guide sets out what that looks like standard by standard.

If someone asks you for an audit report

  1. Ask what they actually need. "Your DSPT audit" almost always means "confirmation you have published, and at what level".
  2. Send them the public record. Point them at the portal's organisation search with your ODS code. It is faster and more credible than an emailed screenshot.
  3. Send the action plan too, if you published at Approaching Standards. It answers the follow-up question before it is asked.
  4. If they insist on an independent report, ask which requirement they are relying on. For a Category 3 or 4 provider, no DSPT requirement produces one. It may be a term in their own contract with you, which is a legitimate thing for them to want — but it is a commercial ask, not a DSPT obligation, and it should be priced and scoped as such.
  5. Do not commission an audit to close the conversation. It is a significant cost against a requirement that does not exist for you.

For where you actually stand against the ten standards, the readiness quiz is a faster first move than any of this, and the evidence checklist generator turns the gaps into a list.

This guide is based on NHS England's DSPT Audit 26-27 mandatory-audit notice (1 October 2026), its independent assurance and audit guidance, and its organisation-types guidance, as at 7 October 2026. Audit arrangements are revised annually — confirm the current position on the official DSPT portal before acting on a commissioner request. This is not legal or compliance advice.

Sources

Get guided DSPT compliance when we launch

Join the waitlist for early access to DSPTready — step-by-step DSPT guidance built for small providers.

No spam. Unsubscribe any time. Privacy policy