The DSPT stopped being a checklist.
DSPT independent assessment starts in your Microsoft 365 estate.

For the 2025/26 cycle the Data Security and Protection Toolkit assesses NHS trusts, ICBs and CSUs against the Cyber Assessment Framework, and the final publication deadline is 30 June 2026. InquilionGRC independently assesses the Microsoft 365 estate that carries much of that evidence, so the layer your submission leans on is proven rather than self-attested and your board is not marking its own homework.

The Data Security and Protection Toolkit used to be a form. For the 2025/26 cycle, Version 8 assesses the larger and higher-risk NHS organisation categories against the National Cyber Security Centre's Cyber Assessment Framework: an outcomes-based, evidence-heavy model. The question is no longer whether a box is ticked. It is whether an outcome is achieved, and whether you can prove it.

That changes the workload. Evidence has to be gathered, kept current and organised across five objectives, and for most organisations a large share of it is configuration: identity, access, data protection, audit and information governance, concentrated in Microsoft 365.

And it changes the risk. A self-assessment signed off inside the organisation is a claim. Under an outcomes-based framework, an unsupported claim is exactly what an audit, an incident or a commissioner will test.

The publication deadline for the 2025/26 assessment is 30 June 2026.

Marking your own homework
is not assurance.

Self-assessment is a claim.

Standards Met, self-attested by the team that operates the controls, proves commitment. It does not prove the outcome. Independent assessment does.

The NHS has said so.

NHS England's Strengthening Assurance programme formally recognises DSPT independent assessment providers and expects independent assessment for higher-risk organisation categories. Read the NHS's own Strengthening Assurance guidance.

The CAF makes the gap visible.

An outcomes-based framework exposes the distance between what is claimed and what is evidenced. That distance is now a governance risk owned at board level.

Independence is the point.

InquilionGRC assesses. It does not operate or remediate what it assesses. That separation is what makes the assurance worth having.

Independently assessed across all five CAF objectives.

The assessment targets the Microsoft 365 and Azure estate, organised the way the CAF-aligned DSPT is organised, so every piece of evidence lands where an assessor, a commissioner or an auditor expects to find it. The toolkit covers more than Microsoft 365: anything outside the estate is reported as outside assessment scope rather than passed.

Governance, ownership and decision-making, evidenced in the estate: named accountability for the tenant, privileged access under control, decisions recorded and auditable. An organisation chart is not an outcome.

Identity, access and data security as actually configured in Microsoft Entra ID and Microsoft 365: the controls claimed, tested against the controls that exist.

Monitoring coverage and the ability to notice, evidenced from audit logging, alerting and Defender configuration: what is watched, what is logged and what would actually be seen if something went wrong.

Response, recovery and resilience posture in the tenant: the configuration that determines how far an incident spreads and how quickly the estate comes back. Exercised plans, not filed ones.

The DSPT-specific objective: transparency, records management and lawful, well-governed sharing of patient data, evidenced from Microsoft Purview and sharing configuration.

What an engagement delivers.

The Microsoft 365 evidence layer for DSPT compliance

Where every engagement begins
A structured gap assessment of your Microsoft 365 estate against the CAF-aligned DSPT for your organisation category, for the 2025/26 cycle.
Evidence, not folders
A read-only, organised evidence base across sixteen governance domains, mapped to the five CAF objectives and their expected achievement levels.
Independent validation
An independent assessment of the Microsoft 365 evidence behind your submission before you publish. What cannot be assessed in the estate is reported as outside scope, never waved through.
A board-ready readout
A clear statement of where you stand, what would not survive scrutiny and what to fix first.
Continuity
Optional continuous assurance through the year, so next June is a publication, not a project.
How it is transacted
InquilionGRC is not on NHS procurement frameworks. Engagements are delivered with an accredited delivery partner, typically your existing managed service provider, so procurement runs through a route you already have.

Your team keeps its day job.
Your board gets evidence it did not have to mark itself.

If you are a managed service provider with NHS clients, see outsource DSPT assurance for MSPs. If you supply the NHS through a procurement framework, see DSPT for NHS suppliers.

Common questions.

Standards Met is the published status an organisation reaches when its Data Security and Protection Toolkit assessment meets the expected level for its organisation category. For the 2025/26 cycle, larger and higher-risk NHS categories are assessed against the Cyber Assessment Framework, so Standards Met means the CAF outcomes are achieved and evidenced, not that a checklist is complete.

The final publication deadline for the 2025/26 DSPT assessment is 30 June 2026. Evidence gathering across five CAF objectives takes months rather than weeks, so the practical deadline for starting is much earlier.

It is a review of your DSPT self-assessment and its supporting evidence by an assessor outside your organisation. NHS England's Strengthening Assurance programme formally recognises DSPT independent assessment providers, and InquilionGRC acts as one for the Microsoft 365 estate: we independently validate the evidence behind what you intend to publish, before you publish it.

Not universally. For the 2025/26 cycle NHS England expects independent assessment for higher-risk organisation categories under its Strengthening Assurance programme, and recommends it more widely. Even where it is not required, it is the difference between claiming an outcome and proving it.

The Cyber Assessment Framework (CAF) is the National Cyber Security Centre's outcomes-based model for assessing cyber resilience. The DSPT now uses a CAF-aligned approach for larger NHS organisations, structured around five objectives: managing risk, protecting against cyber attack, detecting cyber security events, minimising the impact of incidents, and using and sharing information appropriately.

No. The assessment targets the Microsoft 365 and Azure estate, where most of the toolkit's technical evidence lives for most organisations. DSPT areas outside that estate are reported as outside assessment scope rather than passed, for your team or delivery partner to cover. That honesty is what makes the rest of the evidence credible.

Standards Met, independently assured.

Tell us where you are in the 2025/26 cycle. We respond within one working day, and delivery is routed through an accredited partner so procurement is not the hard part.

REQUEST INFO