If your ISO 27001 certificate covers all of your health and care data processing, the NHS Data Security and Protection Toolkit does two useful things with it. It marks the applicable evidence items as complete on its own, and it shrinks the scope of any independent audit to whatever your certification doesn’t already cover.
A certified vendor who does the mapping properly walks into a DSPT submission with most of the technical and organizational evidence already written, already audited, and already versioned.
What ISO 27001 won’t do is get you out of the DSPT. It says nothing about the NHS-specific information governance items, clinical safety, the national data opt-out, or Caldicott principles.
Vendors who assume “certified means done” usually discover this in the last two weeks of June.
This piece is for the founder, CTO, or ops lead at a UK health-tech company who owns compliance without being a compliance person. It covers what each framework asks for, which Annex A controls line up with which DSPT requirements, which evidence you can reuse as-is, which needs reframing around patient data, and a five-step workflow for turning an existing ISMS into a DSPT submission. One more thing on timing: NHS England published DSPT version 9 for the 2026/27 cycle on 4 September 2026, and the submission deadline is 30 June 2027. So this exercise belongs in your calendar now, not next spring.
Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.
Schedule Your Free Assessment Today
Understanding the Two Frameworks at a Glance
What ISO 27001:2022 Covers
ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS). It comes in two halves. Clauses 4 to 10 define the management system itself: context, leadership, risk assessment and treatment, resourcing, operation, performance evaluation, and continual improvement. Annex A lists 93 reference controls across four themes (organizational, people, physical, technological).
Your Statement of Applicability (SoA) records which of those controls you apply, which you exclude, and why.
An accredited certification body issues the certificate after a two-stage audit, then you keep it through annual surveillance audits and a three-year recertification cycle. The certificate covers a defined scope, and that scope statement is the first thing a DSPT assessor reads.
What the NHS DSPT Requires in 2026/27
The Data Security and Protection Toolkit (DSPT) is NHS England’s annual online self-assessment for every organization that touches NHS patient data or systems. It’s a contractual requirement under the NHS Standard Contract. Your published status (“Standards Met”, “Standards Exceeded”, “Approaching Standards”, “Standards Not Met”) is publicly searchable, so procurement teams and prospective NHS customers do look it up.
The Toolkit isn’t one assessment. NHS England tailors it by organization category, and your category decides which assertions you answer and whether you need an independent audit. Version 9 came out on 4 September 2026. The Category 1 view is aligned to CAF version 4.0, and the whole thing closes on 30 June 2027.
Insider Note: Most health-tech SaaS vendors are Category 3, not Category 2. To be an IT Supplier you need all three things at once: digital goods or services to the NHS, 50 or more staff, and £10 million or more in turnover. Picking “IT Supplier” because you sell NHS-facing software, without hitting the size thresholds, lands you in a heavier evidence set and a mandatory audit you may not need. Check the category before you check anything else.
Key Structural Differences Between ISO 27001 and DSPT
Four differences matter when you’re trying to reuse evidence.
- What they’re about.
ISO 27001 is an information security standard. The DSPT is an information governance standard that includes security. A good chunk of it deals with lawful basis, transparency, data subject rights, records management, and the SIRO and Caldicott Guardian roles. None of that is in Annex A. - How you’re assured.
ISO 27001 gets certified once and surveilled once a year by an accredited body. The DSPT starts from a blank submission every year, and Category 1 and 2 organizations get independently assessed every year too. - How granular they are.
Annex A controls read as objectives (“access rights shall be provisioned, reviewed, modified and removed”). DSPT evidence items read as things to upload (“a list of all systems that hold personal data, with the date of last review”). So the mapping runs many-to-one in both directions. - Where they’re heading.
Since 2024/25 NHS England has been moving the Toolkit onto the NCSC Cyber Assessment Framework (CAF). CAF is outcome-based: assessors score you Achieved, Partially Achieved, or Not Achieved against an NHS England profile, rather than accepting a policy upload as proof. Category 1 organizations are already there. Category 2 and 3 are still on assertions and evidence, but NHS England has said CAF alignment will reach more organization types over time.
The Business Case for Reusing ISO 27001 Evidence in DSPT
How Much of DSPT Can Realistically Be Satisfied by ISO 27001 Controls
For a Category 2 or 3 vendor with a full-scope ISO 27001 certificate, expect 60 to 75 percent of the mandatory evidence items to come from ISMS artifacts, either automatically (where the Toolkit auto-completes them) or with some light reframing. The rest is NHS-specific governance and information governance content that ISO 27001 doesn’t touch.
The NHS’s own guidance treats reuse as a scope question. The DSPT help pages say an ISO 27001 certification must cover all health and care data processing to receive the full exemption, and that a certificate scoped only to an IT department is good evidence for many of the IT questions but not all of them. If your certificate says “the SaaS platform hosted in AWS eu-west-2” and NHS data also passes through your support desk tooling, your analytics sandbox, and a contractor’s laptop, the auto-completion won’t apply. Your assessor will want to know how those flows are controlled.
Time and Cost Savings for Health-Tech Vendors
There’s no fee to submit the DSPT. The cost is internal time, plus, if you’re Category 2, the independent audit and the annual penetration test the mandatory assertions expect.
Building a first DSPT submission from nothing usually takes a small vendor three to five months of part-time effort: writing policies, standing up an asset register, documenting suppliers, running training, and producing evidence for each one. The same submission built on top of a live ISMS is normally a four to eight week job, and most of that goes on the NHS-specific gaps rather than on security basics. For Category 2 vendors the independent audit runs two to three days, and assessors will agree at scoping that anything your ISO 27001 audit already covered can come out of theirs.
The saving founders tend to underestimate isn’t year one. It’s years two through five, when a well-run ISMS produces the DSPT evidence pack as a by-product of the surveillance audit cycle instead of as a separate annual scramble.
Reducing Duplicate Audit Effort Across Frameworks
ISO 27001, Cyber Essentials Plus, the DSPT, and the Digital Technology Assessment Criteria (DTAC) all draw on overlapping evidence, and NHS procurement often asks for two or three of them together. The DTAC in particular uses your DSPT status and Cyber Essentials as inputs. Running one control set, one risk register, and one evidence library tagged against all four is what separates a compliance function that scales from one that grows with every new NHS contract.
ISO 27001 to NHS DSPT Control Mapping
Mapping Annex A Controls to DSPT Assertions
The National Data Guardian’s 10 Data Security Standards still sit underneath the Category 2, 3, and 4 Toolkit views, and they group naturally against Annex A themes. NHS England publishes the official cross-reference as a spreadsheet alongside the Toolkit, and that should be your source of truth when you fill in the submission.
Information Security Policies (A.5) → DSPT Data Security Standards
Your top-level information security policy (A.5.1) and the topic-specific policies under it map straight onto the DSPT’s requirement for approved, communicated, and reviewed policies. What the DSPT adds is proof that the board or senior leadership signed them off within the assessment year, plus a review date. A policy last approved 14 months ago is a finding under either framework. The DSPT assessor will just spot it first.
Access Control (A.5.15–A.5.18) → DSPT Access Control Requirements
This is the cleanest overlap. Your access control policy, joiner-mover-leaver procedure, privileged access records, and quarterly access reviews cover the DSPT’s requirements for role-based access, removing leavers, and periodic review. The one addition is multi-factor authentication. NHS England’s MFA policy expects MFA for all remote access and all privileged access to externally hosted systems, and since v8, Cyber Essentials Plus on its own no longer counts as evidence. Write up your MFA coverage explicitly, exceptions included.
Human Resource Security (A.6) → DSPT Staff Training and Responsibilities
Screening, contract terms, awareness training, and the disciplinary process (A.6.1 to A.6.4) map onto NDG standards 2 and 3. Since 2023/24, the DSPT no longer demands 95 percent completion of a specific e-learning module. It asks that all staff have an appropriate understanding of information governance and cyber security. Your A.6.3 training records will show that, as long as the content covers patient confidentiality and not just phishing.
Asset Management (A.5.9–A.5.14) → DSPT Asset and Device Management
Your information asset inventory (A.5.9), classification scheme (A.5.12), and acceptable use rules (A.5.10) cover the DSPT’s asset and device items. The DSPT is more prescriptive, though. It wants a register of systems holding personal data, with owners, and for some categories, a digital asset register of hardware and software. If your ISMS inventory is organized by information asset rather than by system, plan on adding a system-level view.
Cryptography and Data Protection (A.8.24) → DSPT Confidentiality Requirements
Your cryptography policy and proof of encryption at rest and in transit cover the DSPT’s confidentiality items for data in transit, on mobile devices, and in backups. The DSPT also asks about secure email (NHSmail or a DCB1596-compliant equivalent) for sending patient data. That’s an NHS-specific expectation your ISMS won’t have addressed unless you already serve the NHS.
Incident Management (A.5.24–A.5.28) → DSPT Incident Reporting
Your incident management plan, incident log, and lessons-learned records carry over well. What changes is the reporting route. The DSPT has its own incident reporting tool, and reportable personal data breaches involving NHS data have to go through it (it forwards to the ICO) rather than only through your own ICO process. Your A.5.26 response procedure needs a step that says so.
Supplier Relationships (A.5.19–A.5.23) → DSPT Third-Party Assurance
Supplier policy, due diligence records, and contractual security clauses transfer directly. The DSPT adds an explicit ask for an up-to-date list of suppliers processing health and care data, and the NHS Standard Contract expects you to confirm that your own processors have completed a DSPT or an equivalent. That second point catches cloud-hosted vendors who’ve never asked their sub-processors for anything beyond a SOC 2 report.
Business Continuity (A.5.29–A.5.30) → DSPT Continuity Planning
ICT readiness for business continuity, backup procedures, and tested recovery plans satisfy NDG standard 7. The DSPT wants proof that you tested the plan within the year and that the test dealt with losing access to patient data specifically. A generic tabletop on “office fire” won’t land as well as one on “ransomware locks the EHR integration for 72 hours.”
Where ISO 27001 Falls Short of DSPT Requirements
NHS-Specific Governance and SIRO/Caldicott Guardian Roles
The DSPT expects named accountability that ISO 27001 doesn’t ask for: a Senior Information Risk Owner (SIRO) at board level, a Caldicott Guardian if you handle confidential patient information, and a Data Protection Officer where UK GDPR requires one. Your ISMS “top management” clause won’t be accepted as a substitute. Appoint the roles, write them down, and show that the Caldicott Guardian has done the appropriate training.
National Data Opt-Out Compliance
The National Data Opt-Out lets patients block the use of their confidential patient information for anything beyond their own care, such as research and planning. Any vendor using NHS data for secondary purposes has to apply the opt-out and show how. ISO 27001 has no concept of it. If your product only supports direct care, document why the opt-out doesn’t apply. If it touches analytics, research datasets, or population health, you need a working process, and the NHS England national data opt-out guidance explains what compliance looks like.
Clinical Risk Management (DCB0129/DCB0160)
Software used in delivering care falls under DCB0129 (the manufacturer’s clinical risk management standard) and, on the NHS side, DCB0160 for the organization deploying it. Vendors have to appoint a Clinical Safety Officer, keep a hazard log, and produce a clinical safety case report. This usually surfaces through the DTAC rather than the DSPT itself, but assessors and procurement teams treat them as a package. The DCB0129 standard is a different discipline from information security, and it’s the most common blind spot for vendors coming from a pure ISO 27001 background. If your software also counts as a medical device, MHRA registration and UKCA or CE marking sit on top of all that.
Records Management Code of Practice
The NHS Records Management Code of Practice sets minimum retention periods for health records that are far longer and more specific than anything in a typical SaaS retention policy. The DSPT asks for a retention schedule aligned to the Code. Your A.5.33 records protection control gets you a policy. It doesn’t get you the right numbers.
Cyber Assessment Framework (CAF) Alignment in 2026/27
For Category 1 organizations the CAF-aligned Toolkit is fully in force and v9 maps to CAF v4.0. One point here matters a lot for vendors: CAF-aligned organizations no longer get any exemptions for holding Cyber Essentials Plus or ISO 27001. Both are still strong supporting evidence, especially for supply chain assurance, but they don’t auto-complete anything anymore. Category 2 and 3 vendors keep the exemption behavior for now. If NHS England pushes CAF alignment down the categories, the auto-completion benefit in this article goes with it, and the value of ISO 27001 shifts from “fewer questions” to “better answers.”
Worth Knowing: NCSC's Cyber Assessment Framework
The NCSC's Cyber Assessment Framework has four objectives (managing risk, protecting against attack, detecting events, minimizing impact). The NHS version adds a fifth, Objective E: using and sharing information appropriately, which holds the data protection and information governance outcomes. Objective E is where ISO 27001-certified organizations score worst on their first assessment, because it's the part with no ISMS equivalent. The NCSC CAF collection is the primary source for objectives A to D.
Evidence You Can Reuse Directly
Risk Assessments and Statement of Applicability
Your risk assessment methodology, risk register, risk treatment plan, and SoA are the backbone of the submission. The SoA is what an assessor uses to understand which controls you claim, and cross-referencing it to DSPT assertions is Step 2 of the workflow below. Make sure the version you present is the one your certification body signed off on, not a working copy.
Information Security Policies and Procedures
Every approved ISMS policy is reusable. Upload the approved PDF with the approval date visible, not the editable source. Assessors have learned to check version-control metadata.
Training Records and Awareness Programmes
Your LMS exports, attendance logs, and phishing simulation results satisfy the training assertion, provided the content covers confidentiality of patient data. If it doesn’t, add a short NHS-specific module rather than rebuilding the whole programme.
Internal Audit Reports and Management Reviews
Clause 9.2 internal audit reports and Clause 9.3 management review minutes are strong evidence for the DSPT’s process review and leadership assertions. They show controls being checked rather than just documented, which is what the outcome-based direction of the Toolkit rewards.
Supplier Due Diligence Documentation
Supplier assessments, security questionnaires you’ve sent out, and signed data processing agreements transfer directly once you’ve tagged which suppliers touch health and care data.
Penetration Test Results and Vulnerability Scans
A penetration test of your NHS-facing applications and infrastructure from the last 12 months, with a remediation tracker, satisfies the relevant technical assertions. For Category 2 vendors the mandatory audit expects an annual test from an independent provider. Vulnerability scan reports showing critical and high findings patched inside your defined SLA back up the patching assertion.
Pro Tip: Build your Evidence Library
Build your evidence library with a tag per framework, not a folder per framework. One access review record tagged "ISO A.5.18", "DSPT 4.2.4", "SOC 2 CC6.3", and "DTAC C2" gets uploaded once and reused four times. A folder structure copied per framework drifts within a quarter, and it's the usual reason a vendor ends up submitting last year's policy to this year's Toolkit.
Evidence That Needs Adaptation for DSPT
Reframing Data Flows Around Patient Data
Your ISMS data flow diagrams are almost certainly organized around systems. The DSPT wants them organized around personal confidential data: where it comes in, who can see it, where it goes, and on what lawful basis. Redraw the flows with patient data as the subject, add the lawful basis for each one, and you’ve got most of an Information Asset and Flows Register. NHS England publishes a template for that.
Adjusting Retention Schedules to NHS Standards
Take your existing retention schedule and add a column mapping each record type to the Records Management Code of Practice. Where your period is shorter than the Code’s, the Code wins for NHS records. Where it’s longer, write down why.
Documenting NHS-Specific Data Sharing Agreements
The DSPT expects a register of Data Sharing Agreements (DSAs) and data processing agreements with each NHS customer, plus evidence they’ve been reviewed. Most vendors have the contracts. Few have the register. Build it before the assessor asks.
Aligning Incident Response with NHS Reporting Channels
Add the DSPT incident reporting tool, the relevant ICB or trust contacts, and the 72-hour UK GDPR notification window to your incident runbook. Then run one tabletop where the scenario is an NHS data breach, so the log shows the route has been exercised.
A Practical Workflow for ISO 27001-Certified Vendors
Common Pitfalls When Reusing ISO 27001 Evidence
Assuming Certification Equals DSPT “Standards Met”
It doesn’t, and the NHS guidance says plainly that certified organizations get no exemption from completing the Toolkit. The certificate cuts the work down. It doesn’t take it away.
Overlooking Sub-Processor and Cloud Hosting Requirements
Your cloud provider’s certifications are evidence of their controls, not yours. The DSPT wants your configuration, your access model, and your assurance over the sub-processors who see NHS data. A vendor that can’t list which sub-processors touch patient data won’t reach Standards Met, however good the hyperscaler’s SOC 2 report is.
Missing the CAF-Aligned Profile Changes
If you are, or expect to become, a Category 1 organization (a designated Operator of Essential Services, say), the ISO 27001 exemption no longer applies, and your assessment is outcome-scored. Plan for evidence that shows controls working over time, not just existing.
Underestimating Clinical Safety Documentation
Assessors and procurement teams increasingly ask for the DCB0129 safety case alongside DSPT status. Vendors who turn up with an immaculate ISMS and no hazard log lose weeks at the point of contract.
Important: The most common failure we see in ISO 27001-certified vendors approaching the DSPT is scope mismatch, not missing controls. The ISO certificate covers the production platform. NHS data also sits in the customer support ticketing tool, the sales team’s demo environment, and a data scientist’s notebook. None of those are in the certified scope, so the Toolkit’s auto-completion doesn’t apply, and the assessor’s first question is “how are those controlled?” Extend the ISMS scope before you submit, or be ready to evidence those environments on their own.
Tooling and Automation to Streamline the Mapping
A GRC platform with multi-framework control mapping makes the tagging approach above practical: one control, one piece of evidence, mapped to ISO 27001, DSPT, DTAC, Cyber Essentials Plus, and SOC 2 at the same time, with evidence pulled automatically from your cloud, identity provider, and endpoint tooling for the technical assertions. It won’t write your Caldicott Guardian appointment letter or your clinical safety case. The platform handles collection and monitoring. The NHS-specific governance still needs a human who knows what an assessor is looking for.
Axipro’s ISO 27001 certification and NHS services are built around that combination: platform-native evidence collection with a delivery team that has mapped ISMS controls across ISO 27701, ISO 27017, and the other frameworks NHS procurement tends to ask for. If you’re coming to ISO 27001 for the first time with the DSPT already on the horizon, the scope decision above is the conversation to have with an ISO 27001 consultant before the ISMS gets designed, not after the certificate is issued.
Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.
Schedule Your Free Assessment Today
Conclusion: Turning ISO 27001 Into a DSPT Accelerator
A full-scope ISO 27001 certificate auto-completes the applicable DSPT evidence items for Category 2 and 3 vendors, narrows the independent audit, and supplies most of the security evidence the Toolkit wants. It doesn’t cover the SIRO and Caldicott roles, the national data opt-out, clinical risk management, NHS retention periods, or NHS incident reporting routes, and for CAF-aligned Category 1 organizations the exemptions are already gone. Confirm your category, extend your ISMS scope to every environment that touches patient data, tag your evidence once against every framework, and clear the NHS-specific gaps in a planned four to six week block. Do it that way and the DSPT stops being an annual scramble and turns into a by-product of the ISMS you’re already paying to maintain.
Frequently Asked Questions
Does ISO 27001 certification automatically satisfy the NHS DSPT?
No. Certified organizations still have to complete the DSPT. For Category 2 and 3 vendors, a certificate whose scope covers all health and care data processing marks the applicable evidence items complete and reduces independent audit scope, but the NHS-specific governance and information governance items still need answering. Category 1 organizations on the CAF-aligned Toolkit get no exemptions at all.
What percentage of DSPT can ISO 27001 evidence cover?
With a full-scope certificate, roughly 60 to 75 percent of mandatory evidence items for a Category 2 or 3 vendor can come from existing ISMS artifacts. The rest concern SIRO and Caldicott Guardian roles, the national data opt-out, records retention, data sharing agreements, and NHS incident reporting. A certificate scoped only to an IT department or a single platform covers a lot less.
Do I still need a separate DSPT submission if my parent company is certified?
Yes, if you’re a separate legal entity with your own ICO registration. NHS England’s guidance is that each such entity completes its own Toolkit. You can use a parent company’s ISO 27001 certificate as evidence only if its scope explicitly includes your entity’s health and care data processing.
How does the 2026/27 CAF-aligned DSPT change the mapping?
DSPT v9, published on 4 September 2026, aligns the Category 1 view to CAF v4.0 and closes on 30 June 2027. For Category 1 organizations, ISO 27001 and Cyber Essentials Plus no longer auto-complete anything and assessment is outcome-scored. Category 2 and 3 vendors stay on the assertion-and-evidence model with the exemption behavior intact this cycle, but should treat CAF alignment as where things are heading and start building outcome-style evidence now.
Can I use ISO 27701 alongside ISO 27001 to cover more DSPT requirements?
Yes. ISO 27701 extends the ISMS into a Privacy Information Management System and adds controls for lawful basis, data subject rights, transparency, and processor obligations. Those map onto the DSPT’s information governance items and the CAF-aligned Objective E far better than ISO 27001 alone. It still doesn’t cover the Caldicott Guardian role, the national data opt-out, or NHS retention periods, so the NHS-specific gap list gets shorter but doesn’t disappear.
How often should the ISO 27001-to-DSPT mapping be reviewed?
At least once a year, in September, when NHS England publishes the new Toolkit version and its change log. Re-run the mapping whenever your ISMS scope changes, whenever you onboard an NHS customer with a different data flow, and after each ISO 27001 surveillance audit so any new nonconformities show up in the DSPT evidence before you submit.