/

  / ISO 27001 to NHS DSPT Mapping: What Vendors Can Reuse

ISO 27001 to NHS DSPT Mapping: What Vendors Can Reuse

If your ISO 27001 certificate covers all of your health and care data processing, the NHS Data Security and Protection Toolkit does two useful things with it. It marks the applicable evidence items as complete on its own, and it shrinks the scope of any independent audit to whatever your certification doesn’t already cover.

A certified vendor who does the mapping properly walks into a DSPT submission with most of the technical and organizational evidence already written, already audited, and already versioned.

What ISO 27001 won’t do is get you out of the DSPT. It says nothing about the NHS-specific information governance items, clinical safety, the national data opt-out, or Caldicott principles.

Vendors who assume “certified means done” usually discover this in the last two weeks of June.

This piece is for the founder, CTO, or ops lead at a UK health-tech company who owns compliance without being a compliance person. It covers what each framework asks for, which Annex A controls line up with which DSPT requirements, which evidence you can reuse as-is, which needs reframing around patient data, and a five-step workflow for turning an existing ISMS into a DSPT submission. One more thing on timing: NHS England published DSPT version 9 for the 2026/27 cycle on 4 September 2026, and the submission deadline is 30 June 2027. So this exercise belongs in your calendar now, not next spring.

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

Understanding the Two Frameworks at a Glance​

What ISO 27001:2022 Covers

ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS). It comes in two halves. Clauses 4 to 10 define the management system itself: context, leadership, risk assessment and treatment, resourcing, operation, performance evaluation, and continual improvement. Annex A lists 93 reference controls across four themes (organizational, people, physical, technological).

Your Statement of Applicability (SoA) records which of those controls you apply, which you exclude, and why.

An accredited certification body issues the certificate after a two-stage audit, then you keep it through annual surveillance audits and a three-year recertification cycle. The certificate covers a defined scope, and that scope statement is the first thing a DSPT assessor reads.

What the NHS DSPT Requires in 2026/27

The Data Security and Protection Toolkit (DSPT) is NHS England’s annual online self-assessment for every organization that touches NHS patient data or systems. It’s a contractual requirement under the NHS Standard Contract. Your published status (“Standards Met”, “Standards Exceeded”, “Approaching Standards”, “Standards Not Met”) is publicly searchable, so procurement teams and prospective NHS customers do look it up.

The Toolkit isn’t one assessment. NHS England tailors it by organization category, and your category decides which assertions you answer and whether you need an independent audit. Version 9 came out on 4 September 2026. The Category 1 view is aligned to CAF version 4.0, and the whole thing closes on 30 June 2027.

Insider Note: Most health-tech SaaS vendors are Category 3, not Category 2. To be an IT Supplier you need all three things at once: digital goods or services to the NHS, 50 or more staff, and £10 million or more in turnover. Picking “IT Supplier” because you sell NHS-facing software, without hitting the size thresholds, lands you in a heavier evidence set and a mandatory audit you may not need. Check the category before you check anything else.

Key Structural Differences Between ISO 27001 and DSPT

Four differences matter when you’re trying to reuse evidence.

  • What they’re about.
    ISO 27001 is an information security standard. The DSPT is an information governance standard that includes security. A good chunk of it deals with lawful basis, transparency, data subject rights, records management, and the SIRO and Caldicott Guardian roles. None of that is in Annex A.

  • How you’re assured.
    ISO 27001 gets certified once and surveilled once a year by an accredited body. The DSPT starts from a blank submission every year, and Category 1 and 2 organizations get independently assessed every year too.

  • How granular they are.
    Annex A controls read as objectives (“access rights shall be provisioned, reviewed, modified and removed”). DSPT evidence items read as things to upload (“a list of all systems that hold personal data, with the date of last review”). So the mapping runs many-to-one in both directions.

  • Where they’re heading.
    Since 2024/25 NHS England has been moving the Toolkit onto the NCSC Cyber Assessment Framework (CAF). CAF is outcome-based: assessors score you Achieved, Partially Achieved, or Not Achieved against an NHS England profile, rather than accepting a policy upload as proof. Category 1 organizations are already there. Category 2 and 3 are still on assertions and evidence, but NHS England has said CAF alignment will reach more organization types over time.

The Business Case for Reusing ISO 27001 Evidence in DSPT

How Much of DSPT Can Realistically Be Satisfied by ISO 27001 Controls

For a Category 2 or 3 vendor with a full-scope ISO 27001 certificate, expect 60 to 75 percent of the mandatory evidence items to come from ISMS artifacts, either automatically (where the Toolkit auto-completes them) or with some light reframing. The rest is NHS-specific governance and information governance content that ISO 27001 doesn’t touch.

The NHS’s own guidance treats reuse as a scope question. The DSPT help pages say an ISO 27001 certification must cover all health and care data processing to receive the full exemption, and that a certificate scoped only to an IT department is good evidence for many of the IT questions but not all of them. If your certificate says “the SaaS platform hosted in AWS eu-west-2” and NHS data also passes through your support desk tooling, your analytics sandbox, and a contractor’s laptop, the auto-completion won’t apply. Your assessor will want to know how those flows are controlled.

Time and Cost Savings for Health-Tech Vendors

There’s no fee to submit the DSPT. The cost is internal time, plus, if you’re Category 2, the independent audit and the annual penetration test the mandatory assertions expect.

Building a first DSPT submission from nothing usually takes a small vendor three to five months of part-time effort: writing policies, standing up an asset register, documenting suppliers, running training, and producing evidence for each one. The same submission built on top of a live ISMS is normally a four to eight week job, and most of that goes on the NHS-specific gaps rather than on security basics. For Category 2 vendors the independent audit runs two to three days, and assessors will agree at scoping that anything your ISO 27001 audit already covered can come out of theirs.

The saving founders tend to underestimate isn’t year one. It’s years two through five, when a well-run ISMS produces the DSPT evidence pack as a by-product of the surveillance audit cycle instead of as a separate annual scramble.

Reducing Duplicate Audit Effort Across Frameworks

ISO 27001, Cyber Essentials Plus, the DSPT, and the Digital Technology Assessment Criteria (DTAC) all draw on overlapping evidence, and NHS procurement often asks for two or three of them together. The DTAC in particular uses your DSPT status and Cyber Essentials as inputs. Running one control set, one risk register, and one evidence library tagged against all four is what separates a compliance function that scales from one that grows with every new NHS contract.

ISO 27001 to NHS DSPT Control Mapping

Mapping Annex A Controls to DSPT Assertions

The National Data Guardian’s 10 Data Security Standards still sit underneath the Category 2, 3, and 4 Toolkit views, and they group naturally against Annex A themes. NHS England publishes the official cross-reference as a spreadsheet alongside the Toolkit, and that should be your source of truth when you fill in the submission.

Information Security Policies (A.5) → DSPT Data Security Standards

Your top-level information security policy (A.5.1) and the topic-specific policies under it map straight onto the DSPT’s requirement for approved, communicated, and reviewed policies. What the DSPT adds is proof that the board or senior leadership signed them off within the assessment year, plus a review date. A policy last approved 14 months ago is a finding under either framework. The DSPT assessor will just spot it first.

Access Control (A.5.15–A.5.18) → DSPT Access Control Requirements

This is the cleanest overlap. Your access control policy, joiner-mover-leaver procedure, privileged access records, and quarterly access reviews cover the DSPT’s requirements for role-based access, removing leavers, and periodic review. The one addition is multi-factor authentication. NHS England’s MFA policy expects MFA for all remote access and all privileged access to externally hosted systems, and since v8, Cyber Essentials Plus on its own no longer counts as evidence. Write up your MFA coverage explicitly, exceptions included.

Human Resource Security (A.6) → DSPT Staff Training and Responsibilities

Screening, contract terms, awareness training, and the disciplinary process (A.6.1 to A.6.4) map onto NDG standards 2 and 3. Since 2023/24, the DSPT no longer demands 95 percent completion of a specific e-learning module. It asks that all staff have an appropriate understanding of information governance and cyber security. Your A.6.3 training records will show that, as long as the content covers patient confidentiality and not just phishing.

Asset Management (A.5.9–A.5.14) → DSPT Asset and Device Management

Your information asset inventory (A.5.9), classification scheme (A.5.12), and acceptable use rules (A.5.10) cover the DSPT’s asset and device items. The DSPT is more prescriptive, though. It wants a register of systems holding personal data, with owners, and for some categories, a digital asset register of hardware and software. If your ISMS inventory is organized by information asset rather than by system, plan on adding a system-level view.

Cryptography and Data Protection (A.8.24) → DSPT Confidentiality Requirements

Your cryptography policy and proof of encryption at rest and in transit cover the DSPT’s confidentiality items for data in transit, on mobile devices, and in backups. The DSPT also asks about secure email (NHSmail or a DCB1596-compliant equivalent) for sending patient data. That’s an NHS-specific expectation your ISMS won’t have addressed unless you already serve the NHS.

Incident Management (A.5.24–A.5.28) → DSPT Incident Reporting

Your incident management plan, incident log, and lessons-learned records carry over well. What changes is the reporting route. The DSPT has its own incident reporting tool, and reportable personal data breaches involving NHS data have to go through it (it forwards to the ICO) rather than only through your own ICO process. Your A.5.26 response procedure needs a step that says so.

Supplier Relationships (A.5.19–A.5.23) → DSPT Third-Party Assurance

Supplier policy, due diligence records, and contractual security clauses transfer directly. The DSPT adds an explicit ask for an up-to-date list of suppliers processing health and care data, and the NHS Standard Contract expects you to confirm that your own processors have completed a DSPT or an equivalent. That second point catches cloud-hosted vendors who’ve never asked their sub-processors for anything beyond a SOC 2 report.

Business Continuity (A.5.29–A.5.30) → DSPT Continuity Planning

ICT readiness for business continuity, backup procedures, and tested recovery plans satisfy NDG standard 7. The DSPT wants proof that you tested the plan within the year and that the test dealt with losing access to patient data specifically. A generic tabletop on “office fire” won’t land as well as one on “ransomware locks the EHR integration for 72 hours.”

Where ISO 27001 Falls Short of DSPT Requirements

NHS-Specific Governance and SIRO/Caldicott Guardian Roles

The DSPT expects named accountability that ISO 27001 doesn’t ask for: a Senior Information Risk Owner (SIRO) at board level, a Caldicott Guardian if you handle confidential patient information, and a Data Protection Officer where UK GDPR requires one. Your ISMS “top management” clause won’t be accepted as a substitute. Appoint the roles, write them down, and show that the Caldicott Guardian has done the appropriate training.

National Data Opt-Out Compliance

The National Data Opt-Out lets patients block the use of their confidential patient information for anything beyond their own care, such as research and planning. Any vendor using NHS data for secondary purposes has to apply the opt-out and show how. ISO 27001 has no concept of it. If your product only supports direct care, document why the opt-out doesn’t apply. If it touches analytics, research datasets, or population health, you need a working process, and the NHS England national data opt-out guidance explains what compliance looks like.

Clinical Risk Management (DCB0129/DCB0160)

Software used in delivering care falls under DCB0129 (the manufacturer’s clinical risk management standard) and, on the NHS side, DCB0160 for the organization deploying it. Vendors have to appoint a Clinical Safety Officer, keep a hazard log, and produce a clinical safety case report. This usually surfaces through the DTAC rather than the DSPT itself, but assessors and procurement teams treat them as a package. The DCB0129 standard is a different discipline from information security, and it’s the most common blind spot for vendors coming from a pure ISO 27001 background. If your software also counts as a medical device, MHRA registration and UKCA or CE marking sit on top of all that.

Records Management Code of Practice

The NHS Records Management Code of Practice sets minimum retention periods for health records that are far longer and more specific than anything in a typical SaaS retention policy. The DSPT asks for a retention schedule aligned to the Code. Your A.5.33 records protection control gets you a policy. It doesn’t get you the right numbers.

Cyber Assessment Framework (CAF) Alignment in 2026/27

For Category 1 organizations the CAF-aligned Toolkit is fully in force and v9 maps to CAF v4.0. One point here matters a lot for vendors: CAF-aligned organizations no longer get any exemptions for holding Cyber Essentials Plus or ISO 27001. Both are still strong supporting evidence, especially for supply chain assurance, but they don’t auto-complete anything anymore. Category 2 and 3 vendors keep the exemption behavior for now. If NHS England pushes CAF alignment down the categories, the auto-completion benefit in this article goes with it, and the value of ISO 27001 shifts from “fewer questions” to “better answers.”

Worth Knowing: NCSC's Cyber Assessment Framework

The NCSC's Cyber Assessment Framework has four objectives (managing risk, protecting against attack, detecting events, minimizing impact). The NHS version adds a fifth, Objective E: using and sharing information appropriately, which holds the data protection and information governance outcomes. Objective E is where ISO 27001-certified organizations score worst on their first assessment, because it's the part with no ISMS equivalent. The NCSC CAF collection is the primary source for objectives A to D.

Evidence You Can Reuse Directly

Risk Assessments and Statement of Applicability

Your risk assessment methodology, risk register, risk treatment plan, and SoA are the backbone of the submission. The SoA is what an assessor uses to understand which controls you claim, and cross-referencing it to DSPT assertions is Step 2 of the workflow below. Make sure the version you present is the one your certification body signed off on, not a working copy.

Information Security Policies and Procedures

Every approved ISMS policy is reusable. Upload the approved PDF with the approval date visible, not the editable source. Assessors have learned to check version-control metadata.

Training Records and Awareness Programmes

Your LMS exports, attendance logs, and phishing simulation results satisfy the training assertion, provided the content covers confidentiality of patient data. If it doesn’t, add a short NHS-specific module rather than rebuilding the whole programme.

Internal Audit Reports and Management Reviews

Clause 9.2 internal audit reports and Clause 9.3 management review minutes are strong evidence for the DSPT’s process review and leadership assertions. They show controls being checked rather than just documented, which is what the outcome-based direction of the Toolkit rewards.

Supplier Due Diligence Documentation

Supplier assessments, security questionnaires you’ve sent out, and signed data processing agreements transfer directly once you’ve tagged which suppliers touch health and care data.

Penetration Test Results and Vulnerability Scans

A penetration test of your NHS-facing applications and infrastructure from the last 12 months, with a remediation tracker, satisfies the relevant technical assertions. For Category 2 vendors the mandatory audit expects an annual test from an independent provider. Vulnerability scan reports showing critical and high findings patched inside your defined SLA back up the patching assertion.

Pro Tip: Build your Evidence Library

Build your evidence library with a tag per framework, not a folder per framework. One access review record tagged "ISO A.5.18", "DSPT 4.2.4", "SOC 2 CC6.3", and "DTAC C2" gets uploaded once and reused four times. A folder structure copied per framework drifts within a quarter, and it's the usual reason a vendor ends up submitting last year's policy to this year's Toolkit.

Evidence That Needs Adaptation for DSPT

Reframing Data Flows Around Patient Data

Your ISMS data flow diagrams are almost certainly organized around systems. The DSPT wants them organized around personal confidential data: where it comes in, who can see it, where it goes, and on what lawful basis. Redraw the flows with patient data as the subject, add the lawful basis for each one, and you’ve got most of an Information Asset and Flows Register. NHS England publishes a template for that.

Adjusting Retention Schedules to NHS Standards

Take your existing retention schedule and add a column mapping each record type to the Records Management Code of Practice. Where your period is shorter than the Code’s, the Code wins for NHS records. Where it’s longer, write down why.

Documenting NHS-Specific Data Sharing Agreements

The DSPT expects a register of Data Sharing Agreements (DSAs) and data processing agreements with each NHS customer, plus evidence they’ve been reviewed. Most vendors have the contracts. Few have the register. Build it before the assessor asks.

Aligning Incident Response with NHS Reporting Channels

Add the DSPT incident reporting tool, the relevant ICB or trust contacts, and the 72-hour UK GDPR notification window to your incident runbook. Then run one tabletop where the scenario is an NHS data breach, so the log shows the route has been exercised.

A Practical Workflow for ISO 27001-Certified Vendors

Common Pitfalls When Reusing ISO 27001 Evidence

Assuming Certification Equals DSPT “Standards Met”

It doesn’t, and the NHS guidance says plainly that certified organizations get no exemption from completing the Toolkit. The certificate cuts the work down. It doesn’t take it away.

Overlooking Sub-Processor and Cloud Hosting Requirements

Your cloud provider’s certifications are evidence of their controls, not yours. The DSPT wants your configuration, your access model, and your assurance over the sub-processors who see NHS data. A vendor that can’t list which sub-processors touch patient data won’t reach Standards Met, however good the hyperscaler’s SOC 2 report is.

Missing the CAF-Aligned Profile Changes

If you are, or expect to become, a Category 1 organization (a designated Operator of Essential Services, say), the ISO 27001 exemption no longer applies, and your assessment is outcome-scored. Plan for evidence that shows controls working over time, not just existing.

Underestimating Clinical Safety Documentation

Assessors and procurement teams increasingly ask for the DCB0129 safety case alongside DSPT status. Vendors who turn up with an immaculate ISMS and no hazard log lose weeks at the point of contract.

Important: The most common failure we see in ISO 27001-certified vendors approaching the DSPT is scope mismatch, not missing controls. The ISO certificate covers the production platform. NHS data also sits in the customer support ticketing tool, the sales team’s demo environment, and a data scientist’s notebook. None of those are in the certified scope, so the Toolkit’s auto-completion doesn’t apply, and the assessor’s first question is “how are those controlled?” Extend the ISMS scope before you submit, or be ready to evidence those environments on their own.

Tooling and Automation to Streamline the Mapping

A GRC platform with multi-framework control mapping makes the tagging approach above practical: one control, one piece of evidence, mapped to ISO 27001, DSPT, DTAC, Cyber Essentials Plus, and SOC 2 at the same time, with evidence pulled automatically from your cloud, identity provider, and endpoint tooling for the technical assertions. It won’t write your Caldicott Guardian appointment letter or your clinical safety case. The platform handles collection and monitoring. The NHS-specific governance still needs a human who knows what an assessor is looking for.

Axipro’s ISO 27001 certification and NHS services are built around that combination: platform-native evidence collection with a delivery team that has mapped ISMS controls across ISO 27701, ISO 27017, and the other frameworks NHS procurement tends to ask for. If you’re coming to ISO 27001 for the first time with the DSPT already on the horizon, the scope decision above is the conversation to have with an ISO 27001 consultant before the ISMS gets designed, not after the certificate is issued.

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

Conclusion: Turning ISO 27001 Into a DSPT Accelerator

A full-scope ISO 27001 certificate auto-completes the applicable DSPT evidence items for Category 2 and 3 vendors, narrows the independent audit, and supplies most of the security evidence the Toolkit wants. It doesn’t cover the SIRO and Caldicott roles, the national data opt-out, clinical risk management, NHS retention periods, or NHS incident reporting routes, and for CAF-aligned Category 1 organizations the exemptions are already gone. Confirm your category, extend your ISMS scope to every environment that touches patient data, tag your evidence once against every framework, and clear the NHS-specific gaps in a planned four to six week block. Do it that way and the DSPT stops being an annual scramble and turns into a by-product of the ISMS you’re already paying to maintain.

Frequently Asked Questions

Does ISO 27001 certification automatically satisfy the NHS DSPT?

No. Certified organizations still have to complete the DSPT. For Category 2 and 3 vendors, a certificate whose scope covers all health and care data processing marks the applicable evidence items complete and reduces independent audit scope, but the NHS-specific governance and information governance items still need answering. Category 1 organizations on the CAF-aligned Toolkit get no exemptions at all.

With a full-scope certificate, roughly 60 to 75 percent of mandatory evidence items for a Category 2 or 3 vendor can come from existing ISMS artifacts. The rest concern SIRO and Caldicott Guardian roles, the national data opt-out, records retention, data sharing agreements, and NHS incident reporting. A certificate scoped only to an IT department or a single platform covers a lot less.

Yes, if you’re a separate legal entity with your own ICO registration. NHS England’s guidance is that each such entity completes its own Toolkit. You can use a parent company’s ISO 27001 certificate as evidence only if its scope explicitly includes your entity’s health and care data processing.

DSPT v9, published on 4 September 2026, aligns the Category 1 view to CAF v4.0 and closes on 30 June 2027. For Category 1 organizations, ISO 27001 and Cyber Essentials Plus no longer auto-complete anything and assessment is outcome-scored. Category 2 and 3 vendors stay on the assertion-and-evidence model with the exemption behavior intact this cycle, but should treat CAF alignment as where things are heading and start building outcome-style evidence now.

Yes. ISO 27701 extends the ISMS into a Privacy Information Management System and adds controls for lawful basis, data subject rights, transparency, and processor obligations. Those map onto the DSPT’s information governance items and the CAF-aligned Objective E far better than ISO 27001 alone. It still doesn’t cover the Caldicott Guardian role, the national data opt-out, or NHS retention periods, so the NHS-specific gap list gets shorter but doesn’t disappear.

At least once a year, in September, when NHS England publishes the new Toolkit version and its change log. Re-run the mapping whenever your ISMS scope changes, whenever you onboard an NHS customer with a different data flow, and after each ISO 27001 surveillance audit so any new nonconformities show up in the DSPT evidence before you submit.

Axipro Author

Picture of Pedro Dias

Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

Blog Highlights

Explore More Articles

If your ISO 27001 certificate covers all of your health and care data processing, the NHS Data Security and Protection Toolkit does two useful things with it. It marks the applicable evidence items as complete on its own, and it shrinks the scope of any independent audit to whatever your certification doesn’t already cover. A certified vendor who does the mapping properly walks into a DSPT submission with most of the technical and organizational evidence already written, already audited, and already versioned. What ISO 27001 won’t do is get you out of the DSPT. It says nothing about the NHS-specific information governance items, clinical safety, the national data opt-out, or Caldicott principles. Vendors who assume “certified means done” usually discover this in the last two weeks of June. This piece is for the founder, CTO, or ops lead at a UK health-tech company who owns compliance without being a compliance person. It covers what each framework asks for, which Annex A controls line up with which DSPT requirements, which evidence you can reuse as-is, which needs reframing around patient data, and a five-step workflow for turning an existing ISMS into a DSPT submission. One more thing on timing: NHS England published DSPT version 9 for the 2026/27 cycle on 4 September 2026, and the submission deadline is 30 June 2027. So this exercise belongs in your calendar now, not next spring. Understanding the Two Frameworks at a Glance​ What ISO 27001:2022 Covers ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS). It comes in two halves. Clauses 4 to 10 define the management system itself: context, leadership, risk assessment and treatment, resourcing, operation, performance evaluation, and continual improvement. Annex A lists 93 reference controls across four themes (organizational, people, physical, technological). Your Statement of Applicability (SoA) records which of those controls you apply, which you exclude, and why. An accredited certification body issues the certificate after a two-stage audit, then you keep it through annual surveillance audits and a three-year recertification cycle. The certificate covers a defined scope, and that scope statement is the first thing a DSPT assessor reads. What the NHS DSPT Requires in 2026/27 The Data Security and Protection Toolkit (DSPT) is NHS England’s annual online self-assessment for every organization that touches NHS patient data or systems. It’s a contractual requirement under the NHS Standard Contract. Your published status (“Standards Met”, “Standards Exceeded”, “Approaching Standards”, “Standards Not Met”) is publicly searchable, so procurement teams and prospective NHS customers do look it up. The Toolkit isn’t one assessment. NHS England tailors it by organization category, and your category decides which assertions you answer and whether you need an independent audit. Version 9 came out on 4 September 2026. The Category 1 view is aligned to CAF version 4.0, and the whole thing closes on 30 June 2027. Insider Note: Most health-tech SaaS vendors are Category 3, not Category 2. To be an IT Supplier you need all three things at once: digital goods or services to the NHS, 50 or more staff, and £10 million or more in turnover. Picking “IT Supplier” because you sell NHS-facing software, without hitting the size thresholds, lands you in a heavier evidence set and a mandatory audit you may not need. Check the category before you check anything else. Key Structural Differences Between ISO 27001 and DSPT Four differences matter when you’re trying to reuse evidence. What they’re about. ISO 27001 is an information security standard. The DSPT is an information governance standard that includes security. A good chunk of it deals with lawful basis, transparency, data subject rights, records management, and the SIRO and Caldicott Guardian roles. None of that is in Annex A. How you’re assured. ISO 27001 gets certified once and surveilled once a year by an accredited body. The DSPT starts from a blank submission every year, and Category 1 and 2 organizations get independently assessed every year too. How granular they are. Annex A controls read as objectives (“access rights shall be provisioned, reviewed, modified and removed”). DSPT evidence items read as things to upload (“a list of all systems that hold personal data, with the date of last review”). So the mapping runs many-to-one in both directions. Where they’re heading. Since 2024/25 NHS England has been moving the Toolkit onto the NCSC Cyber Assessment Framework (CAF). CAF is outcome-based: assessors score you Achieved, Partially Achieved, or Not Achieved against an NHS England profile, rather than accepting a policy upload as proof. Category 1 organizations are already there. Category 2 and 3 are still on assertions and evidence, but NHS England has said CAF alignment will reach more organization types over time. The Business Case for Reusing ISO 27001 Evidence in DSPT How Much of DSPT Can Realistically Be Satisfied by ISO 27001 Controls For a Category 2 or 3 vendor with a full-scope ISO 27001 certificate, expect 60 to 75 percent of the mandatory evidence items to come from ISMS artifacts, either automatically (where the Toolkit auto-completes them) or with some light reframing. The rest is NHS-specific governance and information governance content that ISO 27001 doesn’t touch. The NHS’s own guidance treats reuse as a scope question. The DSPT help pages say an ISO 27001 certification must cover all health and care data processing to receive the full exemption, and that a certificate scoped only to an IT department is good evidence for many of the IT questions but not all of them. If your certificate says “the SaaS platform hosted in AWS eu-west-2” and NHS data also passes through your support desk tooling, your analytics sandbox, and a contractor’s laptop, the auto-completion won’t apply. Your assessor will want to know how those flows are controlled. Time and Cost Savings for Health-Tech Vendors There’s no fee to submit the DSPT. The cost is internal time, plus, if you’re Category 2, the independent audit and the annual penetration test the mandatory assertions expect. Building a first DSPT submission from nothing usually takes

ISO 27001 Gap Analysis
This step-by-step guide will help you understand an ISO 27001 gap analysis, its benefits, and how to execute it effectively. By following these best practices, your organization will be well-prepared for the ISO 27001 certification audit and subsequent ISO 27001 audits.

Most companies start their first SOC 2 or ISO 27001 project in a spreadsheet, only to have it fall apart in week 6. This is typically when they’ll call us asking us to implement a GRC system that scales. Excel holds 154 controls fine. The trouble starts when an auditor sends over an evidence request list, two frameworks need updating at once, and a control owner who hasn’t opened the file since March edits the wrong row. This article gives you a free GRC workbook template built to take into consideration the hundreds of engagements we’ve guided. It walks you through each tab and tells you plainly when you’ve outgrown it. We’ve worked with hundreds of companies implementing SOC 2 + ISO 27001 and to be honest, for 80% of cases, using excel is feasible and even advised. Its a tool most of the staff knows and using it cuts onboarding times from weeks to a few hours. It also makes it accessible to the whole organization. The workbook covers all 33 SOC 2 Common Criteria plus the Availability, Confidentiality, Processing Integrity, and Privacy criteria, all 93 ISO 27001:2022 Annex A controls, a crosswalk between the two, and the evidence, risk, policy, and gap trackers that sit around them. It’s free, there are no macros, and it opens in Excel or Google Sheets. Why Start SOC 2 and ISO 27001 Tracking in a Spreadsheet The obvious argument for using Excel is cost and ease of use. A GRC platform costs around $10,000 a year before you’ve put a single control in place, and it pushes you into its control library and its workflow before you understand your own environment. A spreadsheet costs nothing and holds exactly the columns you need. More usefully, it makes you think about scope, ownership, and evidence before you automate any of it, and that thinking is the part no platform does for you. There’s a less obvious reason too. Teams that build their first control inventory by hand understand it. They know why CC6.3 maps to A.5.18, why the offboarding checklist is evidence for both, and who actually owns it. Teams that inherit a pre-populated platform library often don’t, and it shows in audit interviews when the auditor asks a control owner to explain a control they’ve never read. When a GRC Workbook Makes Sense A spreadsheet is the right tool when you’re chasing one or two frameworks, your team is under about 50 people, and one person owns compliance day to day. It also suits the readiness phase for any company. Scoping, gap analysis, and control design all go faster in a workbook than in a platform because there’s nothing to configure first. If you’re aiming for a SOC 2 Type I, or an ISO 27001 certificate with a tightly bounded ISMS scope, the workbook can carry you all the way to the audit. When You’ve Outgrown Excel (and Need a Platform) Excel breaks at scale in predictable ways. Spreadsheet research going back decades keeps finding that most operational spreadsheets contain at least one error; a review of field audits across 88 operational spreadsheets found errors in 94% of them. A compliance workbook with 1,400 formulas and a dozen editors isn’t exempt. Add a Type II observation period, where you collect the same evidence every month for a year, and manual tracking stops being a discipline and becomes someone’s full-time job. The specific tripwires are covered later in the article, but the short version is that when evidence collection becomes the bottleneck, it’s time to stop. What’s Inside the Free GRC Workbook Template The workbook has nine tabs. Eight get their own section in the walkthrough below; the ninth, Gap Analysis, is a remediation log that feeds the dashboard. Every tab uses the same color convention.  Navy headers mean pre-filled reference content. Teal headers with light yellow cells are the fields you fill in. Grey headers are formula columns, and you should leave those alone. SOC 2 Trust Services Criteria Coverage All 61 criteria from the AICPA 2017 Trust Services Criteria (with the 2022 revised points of focus) are already in there: the 33 Common Criteria across CC1 through CC9, plus Availability (3), Confidentiality (2), Processing Integrity (5), and Privacy (18). Each row has a plain-English summary of what the criterion expects, so a control owner who has never opened the AICPA document can still understand what they’re being asked to prove. ISO 27001 Annex A Controls Coverage All 93 Annex A controls from ISO/IEC 27001:2022 are listed under their four themes: Organizational (37), People (8), Physical (14), and Technological (34). Each control has a short description of what it covers and a pre-computed column showing which SOC 2 criteria relate to it. Unified Control Mapping Between SOC 2 and ISO 27001 The Crosswalk tab maps every SOC 2 criterion to the Annex A controls and ISO clauses it overlaps with, labels the overlap as Shared, Partial, or SOC 2-specific, and pulls the live status and evidence IDs from the SOC 2 tab. A second table lists the 13 Annex A controls that have no meaningful SOC 2 counterpart, so you know what to track on its own. Evidence Tracker Every piece of evidence gets one row, tagged to the SOC 2 criteria and ISO controls it supports, with an owner, a source system, a location, the period it covers, and how often you collect it. A formula works out the next due date and flags each item as Current, Due Soon, Overdue, or Not Scheduled. Owner and Status Fields Both control tabs have a Control Owner column and a Status dropdown with five defined states: Not Started, In Progress, Implemented, Needs Remediation, and Not Applicable. The definitions sit on the Overview tab so that two people setting a status on the same day mean the same thing by it. Risk Register Tab Likelihood and impact on a 1 to 5 scale, an automatic score, a rating (Critical, High, Medium, Low), a treatment