Your NHS revenue runs through a framework. Where it involves NHS patient data, buyers increasingly look for a current, credible DSPT status. InquilionGRC independently assesses the Microsoft 365 estate that carries most of your DSPT evidence, so that status is proof, not a self-signed claim, for the 2025/26 cycle and its 30 June 2026 deadline.
A place on an NHS framework is not revenue. It is permission to compete for revenue, and that permission carries conditions. Where NHS patient data is in scope, an annual Data Security and Protection Toolkit assessment is one of them, and many contracts and frameworks require an appropriate published status.
For the 2025/26 cycle the DSPT has changed underneath you. Version 8 assesses the larger and higher-risk organisation categories against the Cyber Assessment Framework: outcomes and evidence rather than tick-boxes, with publication due by 30 June 2026. For most suppliers, a large share of that evidence is Microsoft 365 configuration: identity, access, data protection, audit.
Buyers are changing with it. A status your own team signed off was always a claim. Under an evidence-based model, commissioners, framework authorities and prospective customers have both the reason and the means to ask what sits behind it.
DSPT compliance: proven, not claimed.
NHS England's Strengthening Assurance programme formally recognises DSPT independent assessment providers and expects independent assessment for higher-risk categories. Read the NHS's own Strengthening Assurance guidance.
What NHS England expects of its own organisations shapes what buyers ask of their suppliers. An independently assessed status answers the question before it is asked.
The cost of assurance is a project. The cost of a lapsed or challenged status is a bid you cannot enter and a contract conversation you do not want.
InquilionGRC assesses your DSPT position and does not remediate it. That separation is what makes the evidence credible to a buyer.
The assessment targets your Microsoft 365 estate, organised around the five objectives of the NHS Cyber Assessment Framework, so your evidence reads the way an NHS buyer, assessor or auditor expects it to read. Anything the toolkit asks for outside that estate is reported as outside assessment scope rather than passed.
Governance, ownership and decision-making, evidenced in the estate: named accountability for the tenant, privileged access under control, decisions recorded and auditable. An organisation chart is not an outcome.
Identity, access and data security as actually configured in Microsoft Entra ID and Microsoft 365: the controls claimed, tested against the controls that exist.
Monitoring coverage and the ability to notice, evidenced from audit logging, alerting and Defender configuration: what is watched, what is logged and what would actually be seen if something went wrong.
Response, recovery and resilience posture in the tenant: the configuration that determines how far an incident spreads and how quickly the estate comes back. Exercised plans, not filed ones.
The DSPT-specific objective: transparency, records management and lawful, well-governed sharing of patient data, evidenced from Microsoft Purview and sharing configuration.
Your framework place took years to win.
Do not let a self-signed form put it in question.
If you are an NHS trust, ICB or CSU, see DSPT independent assessment for NHS organisations. If you are a managed service provider, see outsource DSPT assurance for MSPs.
Any organisation with access to NHS patient data or systems is required to complete the Data Security and Protection Toolkit annually. Beyond that baseline, many NHS contracts and frameworks require an appropriate published DSPT status where patient data is in scope, so a lapsed or failed status can put contract awards and framework participation at risk.
Your published status for the 2025/26 cycle would lapse or show as not meeting the standard. Where a contract or framework requires a current DSPT status, buyers can treat that as non-compliance: it can block bids, delay awards and trigger contract-management questions from existing NHS customers.
Standards Met is the published DSPT status showing your assessment meets the expected level for your organisation category for the cycle. It is the status NHS buyers look for. For the 2025/26 cycle the assessment model is CAF-aligned for the larger and higher-risk categories, which means outcomes and evidence rather than tick-boxes.
It is not universally mandated. NHS England's Strengthening Assurance programme formally recognises DSPT independent assessment providers and expects independent assessment for higher-risk categories. For a supplier, the commercial logic is simpler: independently assessed Microsoft 365 evidence converts a self-signed claim into proof a buyer can rely on.
It depends on the gap. A supplier with mature controls may need weeks to organise and validate evidence; one with real gaps needs time to remediate before publication. With a hard deadline of 30 June 2026 for the 2025/26 cycle, the safe assumption is months, so a gap assessment early in the cycle is the cheapest insurance available.
Tell us which frameworks you sit on and where your 2025/26 assessment stands. We respond within one working day.
REQUEST INFO