Your first submission will likely have provided valuable insights into the areas that are already supporting good cyber resilience, alongside opportunities for further development.
The move to a CAF-aligned Data Security and Protection Toolkit (DSPT) has encouraged NHS organisations to think about cyber resilience in a broader and more connected way. Rather than a box-ticking exercise, mapping DSPT requirements against the Cyber Assessment Framework (CAF) gives trusts a clearer, ongoing view of their cyber security posture, one that reflects how services, systems and suppliers actually work together across healthcare IT services.
Rather than being viewed solely as an annual exercise, DSPT (CAF) can provide a framework for understanding cyber resilience, supporting organisational conversations, and building a richer picture of cyber risk across services. As another submission cycle comes to a close, it's the best time to pause, reflect and turn the insights gained into practical next steps from tightening controls to strengthening board-level cyber risk and compliance more widely.
Reflecting on your CAF journey so far...
Your first submission will likely have provided valuable insights into the areas that are already supporting good cyber resilience, alongside opportunities for further development.
It may have helped build a clearer picture of governance arrangements, asset visibility, assurance activities and operational processes, as well as where cyber risk sits across the organisation. We’re noticing for many customers, the process also helps highlight where additional support, resource or focus could add the greatest value. DSPT (CAF) is designed to support outcomes and continuous improvement, rather than simply measuring completion against a checklist.
Perhaps the most useful reflection is not the act of submitting itself, but the extent to which the process has helped strengthen understanding, inform priorities and support progress over the past twelve months.
What did year two look like?
For many NHS organisations, year two is where DSPT (CAF) started to mature. It was the point where teams began moving beyond self-assessment, focusing on how controls operate in practice, how assurance activities are applied and how consistently outcomes are achieved across the organisation.
The organisations making the greatest progress were asking:
- Are we more confident in our DSPT (CAF) position than we were last year?
- Have we addressed the risks identified in previous assessments?
- Can we demonstrate measurable improvement?
- Do leadership teams have clear visibility of cyber resilience priorities?
- Are we prepared for greater scrutiny and assurance requirements?
As DSPT (CAF) becomes more embedded, many organisations used year two as an opportunity to reflect on the progress made so far, consider how their approach has evolved, and identify where further development may add value. Our CAF & DSPT 2026 checklist is a useful starting point for that conversation.
How is planning going for next year?
With the next submission cycle on the horizon, it’s important to reflect on the insights gained from previous assessments and how these can help shape future priorities.
DSPT (CAF) is designed to support ongoing learning and continuous improvement, providing a framework that helps organisations understand their current position, inform decision-making and strengthen cyber resilience over time.
From our own experience, reviewing progress ahead of the next cycle provides a helpful opportunity for NHS organisations to build on existing work, consider future areas of focus and ensure plans remain aligned to organisational priorities.
Looking ahead
Whether you're seeking an independent perspective, a broader understanding of your current position, or support in preparing for future Cyber Assessment Framework (CAF) activities, we can work alongside you to help make sense of where you are today and how your approach continues to evolve.
Our DSPT (CAF) aligned services are designed to support you in:
- Developing a clearer understanding of your current DSPT (CAF) position
- Learning from your progress since previous assessments
- Informing future planning and decision-making
- Supporting organisational and leadership conversations around cyber resilience
- Providing independent insight and assurance where required
- Building a broader picture of cyber resilience across your organisation
DSPT (CAF) is intended to support ongoing reflection and continual development over time. Each submission provides an opportunity to build on previous insights, deepen understanding, and help inform future cyber resilience priorities.
Five questions to consider before your next DSPT (CAF) cycle
As you build on the lessons learned from your most recent submission, these questions can help shape discussions across IT, cyber, operational and leadership teams:
1. Do we have a clear view of our most critical services and supporting assets?
Understanding which systems, suppliers and technologies support key patient and business services helps focus cyber resilience efforts where they matter most.
2. Are cyber risks being discussed at leadership level often enough?
DSPT (CAF) encourages organisations to view cyber resilience as an organisational responsibility, not simply an IT concern. Regular discussions help align priorities, investment and risk management.
3. Can we demonstrate improvement since our last assessment?
Consider what has changed over the past year. Have identified risks been addressed? Have controls matured? Are assurance activities providing greater confidence?
4. Are we confident in our response and recovery capabilities?
Recovery plans, incident response processes and testing activities all contribute to resilience. Planning for disruption is just as important as preventing it.
5. What are our priorities before the next submission cycle begins?
Identifying a small number of achievable objectives can help maintain momentum and support continual improvement throughout the year.
Remember: DSPT (CAF) isn't simply about preparing for the next submission. It's an opportunity to strengthen cyber resilience, support informed decision-making and build confidence across your organisation.
Let's talk
Every organisation's DSPT (CAF) journey is different.
If you'd like to discuss your experiences so far, reflect on the insights gained through previous assessments, or explore the opportunities ahead, our NHS cyber specialists would be pleased to help.