NHS procurement asks a clinical research software supplier for a defined set of evidence before the system holds any trust data. The pack contains the supplier’s Data Security and Protection Toolkit (DSPT) publication, a current Cyber Essentials certificate, a completed Digital Technology Assessment Criteria (DTAC) form, and the material a trust needs for its own data protection impact assessment. Two of those items carry a date on a public register. The rest are documents, and a document stays accurate only for the release and the architecture it was written against.
That pack answers a single question: whether an organisation holding NHS patient data manages its security to a national standard. A clinical trial management system, an electronic investigator site file and a research quality management system carry a second obligation that sits outside information governance. The MHRA and the sponsor examine the same software for evidence that it holds regulated trial records correctly, and they read it against ICH-GCP E6(R3) rather than the National Data Guardian standards.
This guide sets out each instrument in the NHS assurance pack: its legal basis, who holds it, how a trust verifies it and when it expires. It then covers the evidence the pack leaves open, and how an NHS R&D office runs the whole check on a calendar rather than once at contract signature.
What Question Does Each Assurance Stack Answer?
Research software sits in the one procurement category where two separate assurance regimes apply to the same product. Both examine the same system. They are held by different people, tested at different moments, and graded against different documents. An R&D office that treats them as one stack discovers the second one during a monitoring visit.
| Dimension | NHS information governance assurance | GCP computerised-system evidence |
| The question it answers | Is this organisation safe to hold NHS patient data? | Does this system hold trial evidence to a regulated standard? |
| Who asks | The trust’s information governance team, procurement, and NHS England through the contract | The MHRA, the sponsor, and the trust’s own research quality function |
| The reference standards | National Data Guardian data security standards, the NCSC Cyber Assessment Framework, UK GDPR | ICH-GCP E6(R3) Annex 1 section 4, the Clinical Trials Regulations as amended |
| When it is tested | At procurement, then on each annual renewal | At a monitoring visit, a sponsor audit, or an MHRA GCP inspection |
| The artefacts it produces | DSPT publication, Cyber Essentials certificate, DTAC form, data protection impact assessment | Validation documentation, an intact audit trail, access records tied to the delegation log, a retention schedule |
| What a gap costs | A blocked or delayed procurement, and an information governance exception on the trust’s own register | A graded inspection finding against the trust or the sponsor |

The split is organisational before it is technical. Information governance assurance is collected by a team that reads DSPT statuses and Cyber Essentials certificates all year. GCP evidence is collected by a research quality function that reads validation summaries and audit trails. Those two teams rarely review the same procurement together, and the system passes into use with whichever half its sponsor inside the trust happened to own.
What Is the DSPT and Who Does It Bind?
The Data Security and Protection Toolkit describes itself as “an online self-assessment tool that allows organisations to measure their performance against the National Data Guardian’s 10 data security standards”, and states that all organisations with access to NHS patient data and systems must use it. The toolkit is a published information standard under section 250 of the Health and Social Care Act 2012, carries the reference DAPB0086, and holds an active status. The standard records that bodies which fail to submit a DSPT return “may be subject to enforcement action under the powers in the Health and Social Care Act 2012, which may include fines”.
Scope is set by the relationship to NHS data rather than by organisation type. The published standard lists five categories.
- All organisations that have access to NHS patients and to their information.
- All organisations which provide support services directly to an NHS organisation.
- All organisations which have either direct or indirect access to national informatics services.
- Social care providers that provide care through the NHS Standard Contract.
- Any party seeking approval for access to NHS patient information from either the Confidentiality Advisory Group or NHS England.
A supplier of clinical research software falls inside the second category through the service it provides, and inside the first wherever the system holds participant identifiers. The associated information standards notice records an implementation date of 1 August 2025 and a full conformance date of 30 June 2026, which sets the annual rhythm a trust should expect a supplier to keep.
The toolkit changed shape for large NHS organisations in September 2024. NHS trusts, integrated care boards, commissioning support units and DHSC arm’s length bodies moved to an assessment aligned to the NCSC Cyber Assessment Framework, built on 47 contributing outcomes, 39 taken from the CAF and a further 8 in a custom section on using and sharing information appropriately, each graded Not Achieved, Partially Achieved or Achieved. Independent providers designated as operators of essential services moved at the same point, and genomics organisations nominated by the Department of Health and Social Care joined for 2025-26. Other organisation types, including IT suppliers and universities, answer their own set of assertions and evidence items. The current toolkit is version 8 for the 2025-26 assessment year, aligned to version 3.4 of the Cyber Assessment Framework.
Three published statuses carry different meanings, and the difference matters at evaluation.
- Standards Met. The organisation reached every achievement level NHS England set for that assessment year.
- Approaching Standards. The organisation fell short and has an agreed improvement plan, which the toolkit expects to be timebound, credible and sufficiently resourced.
- Standards Not Met. The organisation fell short with no agreed plan to reach the required levels.
The toolkit’s own guidance to organisations that rely on a “Standards Met” status for contracting is to review the new standard against their security requirements rather than read the label as equivalent to the previous one. A trust writing a specification should treat the status as the start of a question. The contractual hook sits in the NHS Standard Contract 2026/27 general conditions, where clause 21.2 requires that “the Provider must complete and publish an annual information governance assessment in accordance with, and comply with the mandatory requirements of, the NHS Data Security and Protection Toolkit, as applicable to the Services and the Provider’s organisation type”. Clause 21.4 adds the National Data Guardian standards, and clause 21.6 requires the submission to be audited in accordance with information governance audit guidance where applicable.
Also Read: Clinical Trial Management Software for NHS Trusts: 2026 Buyer’s Guide
What Do Cyber Essentials and Cyber Essentials Plus Certify?
Cyber Essentials covers five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. The NCSC frames the scheme as protection against the most common internet based cyber security threats, and describes most attacks as basic in nature, “the digital equivalent of a thief trying your front door to see if it’s unlocked”. IASME, the NCSC’s official delivery partner, describes it as “an annually renewable certification scheme aligned to the UK Government’s minimum baseline standard for cyber security for organisations of all sizes”, and states that certification is valid for 12 months.
Cyber Essentials Plus assesses the same technical requirements and adds independent testing. IASME states that it “includes a technical audit of your IT systems to verify that the controls are in place”, covering user devices, internet gateways and internet-facing servers. The difference between the two is the difference between a self-assessment that has been verified for accuracy and a technical audit of the running estate.
| Control | What the certificate establishes | What a research team still has to establish |
| Firewalls | Boundary controls exist between the internet and the supplier’s estate | Which country the study data is hosted in, and under what contract |
| Secure configuration | Default accounts and unnecessary services are removed | Whether the system’s audit trail can be switched off by a privileged role |
| Security update management | High-risk and critical fixes are applied within 14 days | Whether a patch or release triggers regression testing against the validated state |
| User access control | Accounts are provisioned and removed under a process | Whether permissions follow the study delegation log and its effective dates |
| Malware protection | Endpoint and gateway defences are in place | Whether an uploaded record can be altered without an attributable audit entry |
The scheme tightened with Cyber Essentials Requirements for IT Infrastructure v3.3, which applies to assessment accounts created from 27 April 2026. Multi-factor authentication became mandatory for all cloud services where it is available, and IASME states that cloud services cannot be excluded from scope. The two questions covering security updates became auto-fail questions, requiring high-risk and critical security updates and vulnerability fixes within 14 days. IASME also defines the point in time a certificate describes as “the date the certificate is issued”. Assessment accounts created before that date have six months to certify under the previous requirements.
A certificate describes the date it was issued. The twelve months after it rest on what the organisation keeps doing.
The DTAC and What It Adds to the Assurance Pack
The Digital Technology Assessment Criteria published by NHS England gives buyers a single form covering clinical safety, data protection, technical security, interoperability, and usability and accessibility. The supplier completes it. The purchasing organisation assesses it and decides what its own thresholds are, which makes the DTAC a structured conversation rather than a certificate.
NHS England refreshed the form and its guidance on 4 March 2026, with a transition deadline of 6 April 2026. The published summary of the refresh describes “a new DTAC form with a 25% reduction in questions, de-duplicated with processes such as the data security and protection toolkit” and the pre-acquisition questionnaire, clearer guidance on purpose and scope, and confirmed scope alignment with NICE focusing the DTAC on software-based digital health technologies. Three points follow for an R&D office.
- The de-duplication changes what to ask for. Questions the DSPT already answers were removed from the form, so a supplier’s DSPT publication now carries more of the technical security answer than it did under the previous version. Ask for both and read them together.
- The data protection impact assessment stays with the trust. A supplier’s own assessment is an input to it. The trust processes the data and holds the duty under UK GDPR to complete its assessment in advance of the processing.
- Clinical safety applicability is a decision the trust records. DCB0160 is an information standard under section 250 of the same Act and applies to “health organisations responsible for ensuring clinical safety in the deployment, use, maintenance or decommissioning of IT systems”. NHS England’s own position is that not all digital solutions require formal clinical safety assurance, and it publishes a tool for deciding whether the standards apply. A research management system that never informs a care decision may fall outside them, and the trust records that determination rather than leaving it open.
One more instrument sits behind all of these. The Cyber Security and Resilience (Network and Information Systems) Bill passed the House of Commons and received its second reading in the House of Lords on 14 July 2026. It amends the Network and Information Systems Regulations 2018 and widens their scope, bringing data centres and third party IT products and services inside the regime. The Bill has not received Royal Assent, so nothing in it binds a procurement today. A trust writing a five-year contract for a research platform has a reason to ask a supplier how it is preparing.
The Gap Between One Signature and Four Renewal Dates
Consider a hypothetical trust that buys an electronic site file platform in May. The evaluation is thorough. Procurement records a DSPT status of Standards Met, a Cyber Essentials certificate, a completed DTAC form and the supplier’s data protection material. The system goes live in July across nine studies. Sixteen months later a sponsor audit and an internal information governance review land in the same quarter, and the pack no longer describes the system in use.
- The DSPT publication is for the wrong assessment year. The status recorded at evaluation was accurate for 2025-26. The 30 June cycle has turned twice since, and nobody re-read the entry.
- The Cyber Essentials certificate expired in November. Certification runs 12 months from the issue date, and the issue date never entered the contract register alongside the certificate itself.
- The DTAC answers describe a previous release. The supplier shipped a single sign-on integration and a new hosting region, and neither triggered a reassessment because no clause required one.
- The trust’s data protection impact assessment predates the hosting change. The assessment was completed before go-live and describes an architecture the system no longer runs on.
- The sponsor asks for validation documentation. Nothing in the procurement pack contained it, because no instrument in the pack asks for it.

Nobody in that trust did anything wrong. The assurance was checked once, and every instrument in it renews on a clock the check never watched.
The Evidence NHS Assurance Leaves Open
A complete and current assurance pack establishes that the supplier manages security and data protection to a national standard. It says nothing about whether the system holds trial evidence to a regulated standard, because none of its instruments were written to ask. That evidence comes from ICH-GCP E6(R3) Annex 1 section 4 and from the Clinical Trials Regulations as amended.
Five requirements sit in that second stack, and a trust asks for each of them separately.
- Validation as fit for purpose. E6(R3) section 4.3.4 expects a risk-based approach to validation, and places the duty on the responsible party for systems including those developed by other parties. The supplier’s documentation shortens that work, and GAMP 5 gives the trust the structure for the part it keeps.
- An audit trail that stays enabled. E6(R3) section 4.2.2 requires audit trails, reports and logs to remain enabled. Ask which roles can alter or disable the trail, and read the answer against that clause.
- Access that follows the delegation log. E6(R3) section 4.3.8 requires access limited to authorised users, attributability to an individual, permissions revoked when no longer needed, periodic review, and documented records of authorised users with the time each permission was granted.
- Retention on the statutory clock. Regulation 31A of the Clinical Trials Regulations, as amended by SI 2025/538 and in force from 28 April 2026, requires trial master file documents including those held electronically to be kept for at least 25 years, complete, legible and readily available.
- Copies that stand as the record. A scan that permanently replaces a paper original has to meet the certified copy definition, which depends on a validated process and a documented check rather than on the storage platform.
Also Read: NHS Clinical Research Software and ICH-GCP E6(R3): What the New UK CTR Requires
How Should an R&D Office Run the Check?
Each claim in an assurance pack is checked somewhere specific, and the place decides how visible a lapse is. The check becomes repeatable once the source, the field to read and the lapse signal are written down beside the claim.
| Supplier claim | Where it is verified | What to read | The signal it has lapsed |
| “We hold DSPT Standards Met” | The organisation search on the DSPT toolkit | The assessment year and the published status wording | The latest published entry is for an earlier assessment year |
| “We are Cyber Essentials certified” | The IASME certificate database | The certificate issue date and the certified scope | More than 12 months have passed since issue |
| “Our DTAC is complete” | The form itself, held by the trust | The release and hosting arrangement the answers describe | The supplier has changed hosting, sub-processors or authentication since |
| “A DPIA is in place” | The trust’s own information asset register | Whether the assessment describes the current architecture | An architecture change with no assessment review recorded |
| “The system is validated” | The supplier’s validation documentation and the trust’s own review | The requirements traced to test evidence, and the release it covers | A release has shipped with no regression evidence supplied |

The tier a claim sits in decides how a lapse reaches you. A DSPT publication and a Cyber Essentials certificate carry their own dates on a register, so an out of date entry is visible to anyone who looks. A DTAC form and a data protection assessment describe the release they were written against, and a supplier release changes what they describe without changing the document. Validation documentation has no register at all, which is why it belongs in a contract term rather than in a reminder.
Four contract terms turn that table into something that runs without a person remembering it.
- Record the Cyber Essentials issue date in the contract register, so the renewal is a diary entry rather than a discovery.
- Require notification of any material change to hosting, sub-processors or authentication within a defined number of working days, which gives the DTAC and the data protection assessment a trigger.
- Require the supplier’s DSPT publication to be maintained annually for the life of the contract, which mirrors the wording of the NHS Standard Contract rather than restating it loosely.
- Require validation documentation for each release the trust runs in production, which keeps the GCP stack current alongside the security stack.
Also Read: eISF for NHS Trusts: Electronic Investigator Site File Requirements
What Are the Risks of Treating Assurance as a Signature Event?
A pack checked once and filed creates four exposures, and each surfaces in a different room.
- Contractual exposure. A lapsed supplier DSPT publication puts the trust in breach of its own information governance position, with the breach dated to whenever the lapse began.
- Data protection exposure. An assessment describing an architecture the system has moved off leaves the trust holding a record of a decision it no longer made.
- Inspection exposure. An MHRA inspector asks for validation and audit trail evidence. A procurement pack containing five security artefacts and no validation summary answers a different question from the one asked.
- Portfolio exposure. Each additional research system carries its own assurance pack, its own renewal dates and its own access review, so the governance overhead multiplies with every point solution the R&D office adds.
The last of those four compounds with every addition. A trust running six research systems runs six assurance calendars, six sets of renewal dates and six access reviews. The case for consolidating is set out in what clinical research software is and how to choose it.
How Does AQ Meet NHS Procurement Assurance?
The AQ Platform carries both stacks from one product, which lets an R&D office assemble the security evidence and the GCP evidence from a single supplier relationship rather than from several.
- AQ completes the Data Security and Protection Toolkit, holds Cyber Essentials certification, and is available through G-Cloud, which gives a trust the three artefacts its procurement route asks for first.
- Validation, data security, data protection and governance evidence is issued to trust teams as a single NHS assurance pack, so the GCP stack arrives with the security stack instead of after it.
- Every action writes an attributable, time-stamped audit entry that stays enabled in normal use, which gives an inspector the record and its history from one place.
- Permissions derive from Digital DoA delegation entries and their effective dates, which holds the access list and the delegation log in agreement without an administrator reconciling them.
- Retention is configured per study, which lets a trust hold pre-2026 and post-2026 populations in one tenancy under their correct statutory clocks.
- Deviations raised against a record route into CAPA and the QMS, which keeps a finding, its root cause and its corrective action attached to the study that produced them.
Book a live demo to see the assurance pack, the audit trail and delegation-driven access inside one governed study record.
