Outsource DSPT assurance.
Keep the client.

Your NHS clients now face a CAF-aligned Data Security and Protection Toolkit and a 30 June 2026 deadline. InquilionGRC gives MSPs the specialist independent assessment of the Microsoft 365 estate behind that toolkit, sold under your own engagement: you keep the relationship, the procurement route and the remediation. We provide the evidence layer.

For the 2025/26 cycle, DSPT Version 8 assesses the larger and higher-risk NHS organisation categories against the Cyber Assessment Framework: outcomes and evidence, not tick-boxes. Every NHS client you hold, and every supplier to one, has to publish by 30 June 2026.

At the same time, NHS England's Strengthening Assurance programme has made self-assessment the weak position. It formally recognises DSPT independent assessment providers and expects independent assessment for higher-risk categories.

That is a service line your clients will buy this year, and most of the evidence involved is Microsoft 365 configuration you already live in. Building the specialist assessment capability in-house is slow and expensive. Buying it in, under your own engagement, is neither.

You deliver it. We assess it.

How the partner model works.

The commercial structure

Who contracts with the client
The MSP, on the framework or contract route the client already uses.
Who invoices the end client
The MSP, at its own price. InquilionGRC invoices the MSP.
Who does the assessment
InquilionGRC: a read-only assessment of the client's Microsoft 365 estate across sixteen governance domains, mapped to the five CAF objectives and independently validated before the client publishes.
What is in scope
The Microsoft 365 and Azure estate. DSPT areas outside it are reported as outside assessment scope; your wider service covers them.
Who does the remediation
The MSP. Findings arrive as a prioritised remediation plan, which is your margin, not ours.
Whose brand is on the engagement
Yours: co-branded or white-label. The assessment opinion is issued in InquilionGRC's name, because visible independence is what the client is buying.
Who handles direct NHS demand
Partners. InquilionGRC is not on NHS procurement frameworks, so inbound NHS enquiries are routed to a partner to transact.

A high-margin assurance line for you.
Independent evidence for your client's board.

Direct NHS demand
comes through partners.

We cannot transact it.

InquilionGRC is not on NHS procurement frameworks. Every direct enquiry from a trust, ICB or CSU needs a partner to contract through.

So partnering means inbound deals.

Qualified NHS demand generated by these pages and by the Strengthening Assurance shift is passed to partners to close, deliver and invoice.

And a defensible service line.

You sell independent assurance without the conflict of assuring your own work. The assessment sits outside your delivery, which is exactly what makes it credible at the client's board.

Independence still rules.

Remediation is yours and assessment is ours, and the two never swap. If we fixed what we found, the assurance would be worthless.

What we deliver under your engagement.

The assessment targets the client's Microsoft 365 estate, organised around the five objectives of the NHS Cyber Assessment Framework, so the evidence lands where an assessor, a commissioner or an auditor expects to find it.

Governance, ownership and decision-making, evidenced in the estate: named accountability for the tenant, privileged access under control, decisions recorded and auditable. An organisation chart is not an outcome.

Identity, access and data security as actually configured in Microsoft Entra ID and Microsoft 365: the controls claimed, tested against the controls that exist.

Monitoring coverage and the ability to notice, evidenced from audit logging, alerting and Defender configuration: what is watched, what is logged and what would actually be seen if something went wrong.

Response, recovery and resilience posture in the tenant: the configuration that determines how far an incident spreads and how quickly the estate comes back. Exercised plans, not filed ones.

The DSPT-specific objective: transparency, records management and lawful, well-governed sharing of patient data, evidenced from Microsoft Purview and sharing configuration.

If you are an NHS trust, ICB or CSU, see DSPT independent assessment for NHS organisations. If your clients supply the NHS through a framework, point them at DSPT for NHS suppliers.

Common questions.

The engagement wrapper can be co-branded or fully white-labelled: your proposal, your pricing, your client communications. The assessment opinion itself is issued in InquilionGRC's name, because an independent assessment is only worth buying if it is visibly independent.

You do. The MSP contracts with the client, invoices at its own price and keeps the remediation and ongoing support work. InquilionGRC does not invoice your end client and does not deliver remediation.

InquilionGRC is not on NHS procurement frameworks, so direct enquiries from NHS organisations are transacted through a partner that is. For partners this is the point of the programme: partnering brings inbound, qualified NHS deals as well as a deliverable service line.

No. You keep the client relationship, procurement route and remediation work; InquilionGRC provides the specialist assessment of the Microsoft 365 estate, organised around the five CAF objectives, for the 2025/26 cycle.

Scoping is joint. InquilionGRC runs the read-only assessment of the client's Microsoft 365 estate, organises the evidence across the five CAF objectives and independently validates the Microsoft 365 evidence in the client's DSPT submission before publication. Findings route to you as a prioritised remediation plan, which is your revenue line, not ours.

Add the assurance line. Get the inbound deals.

A partner conversation takes thirty minutes and commits you to nothing.

REQUEST INFO