DSPT Checker: How to Check Your Status
Two different questions hide behind "DSPT checker", and they need different answers.
"Has my organisation published, and at what level?" — there is an official answer. The DSPT portal has an organisation search that shows any organisation's published status, searchable by name or ODS code. It is public.
"Is my evidence actually good enough to publish?" — there is no official tool for this, because the DSPT is a self-assessment. Nobody checks your evidence before you publish; you assert it. What you can do is run a structured pass over your own position first, which is what the second half of this guide covers.
Checking your published status
Use the organisation search on dsptoolkit.nhs.uk. Digital Care Hub's guidance describes what it returns: it "will show you if your organisation has published, and at what level (eg Approaching Standards, Standards Met or Standards Exceeded)", and it "will also show you if your organisation is registered to use the DSPT but has not yet published."
Three things worth knowing before you search:
It is public. In Digital Care Hub's words: "It is public information. Commissioners, CQC inspectors, families and people using care services can also check the DSPT status of a care service." Your status is not a private conversation between you and NHS England.
Search by ODS code if you can. Organisation names in the register are often the legal entity rather than the trading name, so a name search can miss. If you do not know your ODS code, Digital Care Hub explains how to find it.
Registered-but-not-published is its own state. If a predecessor set the organisation up and never filed, the search shows that. It is a common finding when a new manager inherits the task and assumes nothing exists.
The three levels, and what they actually signal
| Level | What it means | What it gets you |
|---|---|---|
| Approaching Standards | Digital Care Hub: "you are meeting minimum legal standards. It's a temporary stepping stone to the next level and you will need to produce an Action Plan to show what you will do to get to Standards Met" | Enough to obtain NHS.net Connect (the service previously called NHSmail) — "an accredited, secure email system which helps you to share confidential information with local authority, NHS and other colleagues" |
| Standards Met | Digital Care Hub: "the level you really need to reach. It demonstrates that you are going above basic legal requirements" | The level commissioners expect to see |
| Standards Exceeded | Digital Care Hub: "indicates that you have gone beyond required standards and have Cyber Essentials Plus in place". NHS England is more specific, and its sentence starts with a scope clause worth keeping: "For all other organisations, if an organisation achieves 'Standards Met' and also has a current Cyber Essentials PLUS certification recorded in its Organisation Profile, then it's status will be displayed as 'Standards Exceeded'" | Above the expected bar. For most providers it is not reached by answering more questions: it needs a Cyber Essentials Plus certificate, recorded in your Organisation Profile, on top of Standards Met. The "all other organisations" clause matters if you are checking someone else's status — NHS Trusts, ICBs, ALBs, CSUs, Genomics organisations and independent providers designated as OES get there instead by meeting the achievement levels forecast for the following year, with no CE Plus involved. See our Cyber Essentials and the DSPT guide |
For adult social care, the mechanics of the first two are set out plainly: "If you have only completed the 26 mandatory questions for Approaching Standards you will be asked to complete and upload an action plan on how you will complete the remaining questions."
One caveat on question counts: Digital Care Hub's own page gives both "all 45 questions" and "the 42 questions for Standards Met" in adjacent paragraphs, and the total varies by organisation type in any case. Take the count from your own toolkit rather than from any guide, including this one. The 26-question threshold for Approaching Standards is the figure to plan around.
The readiness check to run before you publish
No tool can validate your evidence for you, so here is the pass to run yourself. Work through the ten National Data Guardian standards and give each one an honest colour. The test for green is not "we have a document" — it is "if a commissioner asked me to produce the evidence for this tomorrow, could I, within the hour, and is it dated within the last twelve months?"
1. Personal confidential data. Can you say who has access to patient data and on what basis?
2. Staff responsibilities. Is there a data security policy customised to your organisation, reviewed inside 12 months, with staff acknowledgements? Our guide on how to write a DSPT data security policy covers what it needs to contain.
3. Training. Can you produce a completion record for every current member of staff, agency and bank included, dated inside the assessment period? This is the item that most often fails the hour test. See DSPT staff training records.
4. Managing data access. Do you have an access register and a joiner/leaver process, and does the register include administrator accounts? DSPT access controls has a worked register.
5. Process reviews. Is there a review schedule showing when each policy was last looked at and when it is next due? DSPT risk assessment covers the risks those reviews exist to catch.
6. Responding to incidents. Is there a written procedure and a log — even an empty one? DSPT incident response.
7. Continuity planning. Is there a plan covering IT failure, cyber attack and data loss, with evidence it has been reviewed or walked through? DSPT business continuity.
8. Unsupported systems. Do you know whether every device and system in use is still supported by its vendor? This one has moved from theoretical to live for a lot of small providers.
9. IT protection. Firewalls, antivirus, encryption, patching — can you evidence them, or does your IT provider need to?
10. Accountable suppliers. Do you hold data processing agreements and assurance statements from the suppliers who touch patient data? DSPT supplier assurance.
Count your greens. If you have all ten, you are looking at Standards Met. If you have the mandatory items but genuine gaps elsewhere, Approaching Standards with an honest action plan is the right call — it is designed for exactly that position.
Our readiness quiz walks the same ten standards as a structured set of questions and returns where your gaps are, and the evidence checklist generator turns the result into a list of what to collect.
Three checks people skip
Check the status of your suppliers, not just your own. The organisation search works on any organisation. If a supplier handling patient data has never published, that is directly relevant to your own Standard 10 evidence.
Check what your organisation published last year, before you start this year. The previous action plan tells you exactly which items were left open, and that is your starting list.
Check the profile details, not just the answers. Publishing asks you to confirm the organisation profile is accurate. An out-of-date registered address or contact on a published record is a small thing that looks careless to anyone who looks it up.
Then plan the run-in
Once you know where you stand, the deadline calculator shows how many working days remain to 30 June and suggests milestones. For the full walk-through of the submission itself, see how to complete the DSPT.
This guide is based on NHS England's published DSPT guidance and Digital Care Hub's Better Security, Better Care guidance as at September 2026. Question counts and level thresholds vary by organisation type — confirm yours in the toolkit itself. Always verify current requirements on the official DSPT portal. This is not legal or compliance advice.