DSPT version 9 is out: check your training assertion

Version 9 of the Data Security and Protection Toolkit is out, with mandatory audit areas published four days earlier and a changed staff training test.

Version 9 of the Data Security and Protection Toolkit was published on 8 September 2026. The mandatory audit areas were published four days earlier, on 4 September. If you completed version 8 in June and filed it away, the outcomes, assertions and evidence items you will be working against next have now changed.

What has been published

NHS England has published the Outcomes, Assertions and Evidence items for DSPT 2026-27, version 9. The announcements are on the DSPT news pages, with the mandatory audit areas published separately at News/170.

For context, version 8 covered 2025-26 and was aligned to the Cyber Assessment Framework version 3.4. The version 8 deadline was 30 June 2026.

The training assertion change to know about

The most operationally significant change in version 8 was to the staff training assertion. It moved away from a numeric target — 95% of staff — to a requirement that all staff have an appropriate understanding of information governance and cyber security.

That is a harder standard, and providers underestimate it. Under a 95% target, a handful of bank staff who never completed the module were absorbed by the percentage. Under an all-staff requirement they are not. Every bank worker, every night worker, every agency worker with a login, every member of the domestic team who has access to a shared terminal.

And appropriate understanding is not the same as completed a module. A completion certificate is evidence of attendance. Understanding is what you have to be able to assert.

Working with version 9 now

Read the version 9 outcomes, assertions and evidence items against your version 8 submission and identify what has moved. Doing that comparison now, while your version 8 evidence is still fresh and the people who assembled it are still in post, is much cheaper than doing it under deadline pressure.

The mandatory audit areas published on 4 September deserve separate attention. Knowing which areas are subject to mandatory audit tells you where evidence quality has to be strongest, and that is not always where you would guess.

What this means for you

  • Download the version 9 outcomes, assertions and evidence items and the mandatory audit areas, and give them to whoever owns your DSPT submission. In most social care providers that is one person, and if they leave, the knowledge leaves.
  • Run a gap comparison against your version 8 return. Mark every assertion where your previous evidence would not now suffice.
  • Audit your training position against the all-staff standard. Produce a list of every individual with any system access and check each one, rather than reporting a percentage.
  • Decide how you will evidence understanding rather than completion. Spot checks, competency questions in supervision, and simulated phishing results are all more persuasive than a completion report.
  • Look at your mandatory audit areas first when planning evidence work, since that is where scrutiny will be deepest.
  • Do not assume the version 8 deadline pattern repeats. Check the published deadline for version 9 on the toolkit itself rather than working from last year's date.

Care Shield can show you which staff have completed which training and when, which is the register the all-staff assertion depends on; it cannot tell you whether they understood it.

Where this came from

NHS England's DSPT news items on version 9 and the 2026-27 mandatory audit areas.

Sources

  1. DSPT news: version 9 publishedNHS England
  2. DSPT news: mandatory audit areasNHS England

Questions people ask about this

What is the deadline for DSPT version 9?

Check the toolkit directly. The version 8 submission for 2025-26 had a deadline of 30 June 2026, but do not assume version 9 repeats that pattern. NHS England published version 9 on 8 September 2026 along with the outcomes, assertions and evidence items, and the deadline is published on the toolkit itself.

How do we evidence that all staff have an appropriate understanding?

Completion records alone are weak evidence. Build a list of every individual with system access, including bank, night and agency staff, and check each one. Then add something that tests understanding: competency questions in supervision, spot checks, or simulated phishing results. Attendance shows a module was opened; understanding is what the assertion asks for.

Why do the mandatory audit areas matter separately?

They tell you where evidence quality will be scrutinised most closely. NHS England published the 2026-27 mandatory audit areas on 4 September 2026, four days before version 9 itself. Plan your evidence work around those areas first, since that is where a thin file will be found rather than assumed.

How this was written. Care Shield’s press desk drafts from primary sources — the statute book, regulator publications and government announcements — and publishes automatically once every factual claim traces to a named source. The sources are listed above so you can check them. It is not legal advice, and it is not a substitute for reading the regulation that applies to your service. If you find something wrong, tell us at hello@careshieldcompliance.co.uk and we will correct it in public, on this page.

Related