IG Toolkit to DSPT: What Changed for You
If you last did this under the name "IG Toolkit", you are looking for something that no longer exists in England. NHS England's own page is blunt about it: "The Data Security and Protection Toolkit replaces the previous Information Governance toolkit from April 2018."
So the annual return you are being chased for is the Data Security and Protection Toolkit — the DSPT. Same broad purpose, different name, different structure, and a heavier weighting toward cyber security than the toolkit you remember. The deadline is 30 June each year. Your organisation completes it as a self-assessment and publishes the result; nobody files it on your behalf.
This guide covers what actually changed, what carries over from your old IG Toolkit work, and why searching the old name gives you two contradictory answers.
Why "IG Toolkit" still returns confusing results
Search the old name and you will get a mix of NHS trust information governance pages, vendor explainers, and — this is the one that trips people up — the Welsh Information Governance Toolkit, which is a genuinely separate and genuinely current instrument.
Digital Health and Care Wales runs its own toolkit for Welsh general practices, separate from the DSPT and on a different deadline. DHCW's guidance page states: "The 2026/2027 Welsh Information Governance Toolkit is now available for completion. Organisations have until the 31st of March 2027 to submit their form."
DHCW describes it as "a self-assessment tool enabling organisations to measure their level of compliance against national Information Governance standards and legislation", consisting of "simple to follow assessments, comprising of a range of rudimental questions requiring tick box answers, one-line statements and the facility to upload or link to documents as evidence". Queries go to welshigtoolkit@wales.nhs.uk.
One thing we are deliberately not stating: how the Welsh toolkit relates to NHS Spine access. DHCW's page does not address it, and we are not going to infer it — ask DHCW directly if that is your question.
The short version:
- England — you complete the DSPT at dsptoolkit.nhs.uk. Everything on this site is written for you.
- Wales — you are likely in scope for the Welsh IG Toolkit instead, and its 2026/2027 deadline is 31 March 2027, not 30 June. Confirm your position with Digital Health and Care Wales, not with us.
That single fork explains most of the contradictory advice you will find. Two nations, two live toolkits, one legacy name.
What the DSPT actually is
NHS England defines it as "an online self-assessment tool that enables organisations to measure and publish their performance against the National Data Guardian's ten data security standards."
Three words in that sentence do a lot of work:
Self-assessment. You answer the questions and upload the evidence. There is no inspector who comes and checks. That is not the same as saying nobody looks — commissioners, ICBs and, for CQC-registered providers, inspectors can all see your published status.
Publish. Your submission status is visible. This is why "we'll sort it in July" is a poor plan: the gap is public.
Ten data security standards. These are the National Data Guardian standards, and they are the skeleton the whole assessment hangs off. Our complete DSPT guide walks through all ten.
On scope, NHS England is broad: "All organisations that have access to NHS patient data and systems must use this toolkit to provide assurance that they are practising good data security and that personal information is handled correctly." If you hold NHS patient data or log in to an NHS system, you are almost certainly in.
What changed between the two toolkits
The 2018 change was more than a rebrand. Three shifts matter for a small provider:
1. Cyber security moved to the centre. The old toolkit was weighted toward information governance in the paper-records sense — confidentiality, Caldicott, records management. The DSPT keeps all of that but adds a substantial technical layer: who has administrator accounts, whether your software is still supported, whether staff use unique logins, what your suppliers do with your data.
2. The scope widened. The DSPT is explicitly the mechanism NHS organisations use to assure the data security of the organisations they work alongside. That pulled in a much larger population of small providers and suppliers than the IG Toolkit had ever reached.
3. The structure is categorised. NHS England now assigns every organisation to one of four categories: "There are four Categories: 1, 2, 3 and 4. Each category has a pre-determined set of evidence items, with some mandatory and some non-mandatory for an organisation and determines the language used in asking the evidence item."
For most readers of this guide that means Category 3 — the portal lists social care providers (including care homes, residential homes and domiciliary care), community pharmacies, dentists, opticians, local authorities and smaller IT suppliers under Category 3 — or Category 4, which is general practice.
What carries over from your old IG Toolkit work
More than you would think, and less than you would hope.
Reusable: the underlying documents. Your data protection policy, your staff confidentiality agreements, your supplier contracts, your incident procedure, your business continuity plan. These are all still the right kinds of artefact.
Not reusable: the answers. Eight versions have shipped since 2018 and the assertions have been restructured more than once. An answer written against the IG Toolkit question set does not map onto a current DSPT evidence item, and a policy last reviewed in 2018 will fail on currency alone regardless of content.
The practical approach for a returning filer:
- Pull out every document you used last time and check its review date. Anything over 12 months old needs re-reviewing and re-dating before it is worth uploading.
- Work through the current evidence list rather than your memory of the old one. Our evidence checklist generator will give you a categorised list for your organisation type.
- Expect the technical questions to be the gap. Administrator account registers, supported-software checks and supplier assurance are the items that most often have no predecessor document at all.
- Budget the time for gathering rather than writing. For most small providers the writing is quick; finding the training completion report from the agency that supplied three staff in March is what takes the afternoon.
Where the DSPT sits alongside everything else you file
A recurring source of confusion is whether the DSPT replaces or duplicates other assurance work. It does neither, mostly:
| You already do | Does it cover the DSPT? |
|---|---|
| CQC registration and inspection | No. CQC may ask about your data security arrangements and can see your published DSPT status, but registration does not complete the toolkit |
| Your own annual data protection review | Partly. The documents feed the DSPT; the assessment itself still has to be completed and published |
| An ICO registration | No. ICO registration is a separate legal obligation under data protection law |
| Cyber Essentials certification | Not on its own for a Category 3 provider. It can demonstrate some of the technical controls, but the DSPT assessment still has to be completed and published |
Your first hour back
If you are picking this up again after a gap, do these four things in order:
- Log in and check your category — do not assume it is right. Go to dsptoolkit.nhs.uk. Your ODS code identifies your organisation at registration, but your category follows from the sector you select, not from the code: NHS England states "you will be asked to choose the most appropriate sector for your organisation... The answers you give here will tailor the questions you need to respond to in your assessment", and "you can change your answers at any time". Since "the organisation type determines which Category of toolkit is to be completed", a predecessor's wrong sector choice will quietly give you the wrong question set — so check it before you start, and change it if it is wrong. Our DSPT toolkit prep guide covers what to gather before that first login.
- Check what your organisation last published. If a previous manager submitted, the status is there and tells you where the gaps were left.
- Date-check your document set. Review dates first, content second.
- Work out your runway. The deadline calculator shows the working days left to the next 30 June deadline and suggests milestones.
The name changed in 2018 but the underlying job did not: prove that the people who handle patient data in your organisation are doing it properly, and show your working. For the step-by-step version, see our guide on how to complete the DSPT.
This guide is based on NHS England's published DSPT guidance as at September 2026 and reflects the position for organisations in England. Always verify current requirements on the official DSPT portal. Welsh organisations should verify their position with Digital Health and Care Wales. This is not legal or compliance advice.
Sources
- Data Security and Protection Toolkit — NHS England Digital
- DSPT overview and deadline — NHS England
- DSPT organisation types and categories — NHS England
- DSPT overview (registration, sector selection, deadline) — NHS England
- DSPT organisation types and categories — NHS England
- Welsh Information Governance Toolkit — Digital Health and Care Wales