DSPT CAF Alignment: What Category 3 Files
If you run a care home, a community pharmacy, a dental practice or a GP practice and someone has told you the DSPT is "going CAF", here is the short version: not for you, not yet, and not in the form the large trusts got.
NHS England's guidance on organisation types is unambiguous about who sees the CAF-aligned assessment: "Category 1 organisations will view a Cyber Assessment Framework (CAF) aligned view of the DSPT requirements." Category 1 is NHS trusts, integrated care boards, commissioning support units, arm's length bodies and a small designated group of independent providers. Category 3 and Category 4 — which is where care homes, domiciliary care, pharmacies, dentists, opticians, local authorities, universities, charities and GP practices sit — are not on it.
That does not mean nothing changes. It means what changes for you is different from what changed for a trust, and the published plan carries an explicit caveat.
What CAF is, briefly
The Cyber Assessment Framework is the NCSC's tool, described by the NCSC as "a tool to help organisations assess and improve their cyber security and resilience, managing cyber risks and protecting essential services from cyber threats." It was built for operators of essential services — energy, healthcare, transport, digital infrastructure, government.
It works differently from the DSPT you know. Instead of assertions with evidence items attached, CAF is built around contributing outcomes, each assessed as Not Achieved, Partially Achieved or Achieved, using indicators of good practice to guide the judgement. NHS England describes those indicators as "examples of procedures and processes which help inform your organisation's decision about whether it has achieved a contributing outcome."
The shift is from "did you upload the document?" to "can you justify that you achieved the outcome?" NHS England is explicit that this is deliberate: the CAF-aligned DSPT "places a bigger emphasis on good decision-making guided by expert judgment at the local level."
The health and care overlay
NHS England did not adopt the NCSC framework unchanged. In its own words: "NHS England (NHSE) and DHSC have enhanced NCSC's existing cyber framework with a health and care CAF overlay which covers data protection, confidentiality, and other information governance disciplines such as clinical coding."
The most visible piece of that overlay is a fifth objective. Asked why objective E exists, NHS England answers: "As part of the Health and Care overlay, objective E was added to ensure appropriate outcomes were included to cover 'Using and sharing information appropriately'."
That matters conceptually even for organisations not on CAF, because it signals the direction: cyber security and information governance are being treated as one discipline rather than two. NHS England puts it directly — "cyber security and IG are being treated as two sides of the same discipline… preventing gaps and minimising unnecessary duplication between disciplines."
Who moved, and when
| Group | Position |
|---|---|
| NHS trusts and foundation trusts, ICBs, DHSC arm's length bodies, commissioning support units | Moved to the CAF-based DSPT in summer 2024 |
| Independent providers designated Operators of Essential Services (and Genomics organisations) | Moved for 2025-26, as planned. NHS England's news page is titled "Changes to the DSPT for large NHS Organisations in 2024-25 and Independent providers who are Operators of Essential Services (OES) and Genomics organisations in 25-26" (updated 13 February 2026), and its organisation-type guidance records that an OES independent provider's "DSP Toolkit view is based on the Category 1 requirements and will view a Cyber Assessment Framework (CAF) aligned view of the DSPT requirements." The 25-26 audit guidance confirms it in practice: "For OES providers and Genomics organisations there are 8 mandated outcomes to be audited" — CAF outcome codes, not assertions. |
| Larger IT suppliers | Did not move. NHS England's organisation-type guidance still lists "Large IT Supplier - Category 2", and the 25-26 audit guidance sets "12 mandated assertions to be audited" for IT Suppliers — assertion numbers, not CAF outcomes. |
| "Other" organisations — dentists, GP practices, local authorities, opticians, pharmacies, social care, universities, charities and NHS business partners | A different approach entirely — see below |
For that last group, which is almost certainly you, NHS England's CAF-aligned DSPT FAQ answers the question head-on: "A checklist approach mapped to CAF will be developed and implemented Summer 2026, however this is still subject to review."
Two things to take from that sentence, and both matter.
It is a checklist mapped to CAF, not CAF itself. Nobody is proposing that a 25-bed care home works through all 47 outcomes of the CAF-aligned DSPT, weighs the indicators of good practice under each, and justifies every judgement to an auditor. The stated plan is a checklist that maps to the framework — closer in shape to what you complete now.
"Still subject to review" is doing real work. That FAQ is the 2024-25 edition. As at September 2026 the portal's own organisation-types guidance continues to show only Category 1 on the CAF-aligned view, which is the position you should plan against. If the checklist approach lands, it will be announced on the DSPT news page.
So what do you actually file?
For Category 3 and Category 4 organisations, the assessment remains what it has been: assertions with evidence items, structured around the ten National Data Guardian standards, categorised by organisation type. NHS England's own framing is that "each category has a pre-determined set of evidence items, with some mandatory and some non-mandatory".
Version 8 is aligned to the framework — NHS England states plainly that "DSPT Version 8 is aligned to CAF version 3.4" — but alignment at framework level is not the same as being assessed against it. Our DSPT v8 changes explained guide covers what actually changed in the questions you answer, and the evidence requirements guide works through the current items standard by standard.
If you want the framework itself explained rather than its effect on your filing, our Cyber Assessment Framework guide covers the structure.
What to do with this now
Not much, honestly — and that is the useful answer. Three things are worth doing:
- Do not restructure your evidence for CAF. A checklist mapped to CAF, if it arrives, will draw on the same underlying artefacts you already keep: policies with review dates, training records, an access register, supplier assurance, a continuity plan. Nothing about a possible future format makes those less useful.
- Watch the outcome-shaped language. One transferable idea from CAF is worth adopting early: the question is moving from "do you have a document" to "can you justify the outcome". A policy nobody follows will look thinner under that lens. Where you have a document holding a gap open, close the gap rather than improving the document.
- Check the news page, not the rumour. Changes of this size are announced on the DSPT news page. Commissioners and suppliers pass on half-remembered versions of trust-facing changes; the news page is the source.
In the meantime, the evidence checklist generator produces the current list for your category, and the readiness quiz shows where your gaps are against the ten standards as they stand today.
This guide is based on NHS England's published DSPT guidance, its CAF-aligned DSPT FAQ (2024-25 edition) and the NCSC Cyber Assessment Framework collection, as at September 2026. The timing of any move for Category 3 and 4 organisations is explicitly subject to review by NHS England — confirm the current position on the official DSPT portal. This is not legal or compliance advice.
Sources
- DSPT 2025-26 version 8 announcement — NHS England
- DSPT organisation types and categories — NHS England
- Frequently Asked Questions – CAF aligned DSPT 2024–2025 (PDF) — NHS England
- Changes to the DSPT for large NHS organisations and OES/Genomics providers — NHS England
- DSPT Audit 25-26: Areas of Mandatory Audit (15 October 2025) — NHS England
- DSPT news — NHS England
- Cyber Assessment Framework — NCSC