Practical, proportionate DSPT compliance and consultancy for organisations selling into the NHS.
JVR Consultancy provides expert Data Security and Protection Toolkit (DSPT) compliance support for small IT and digital service providers working with the NHS. We offer pragmatic DSPT consultancy, guiding you through the NHS Data Security and Protection Toolkit process and helping you achieve a published status of “Standards Met”, without unnecessary complexity or disruption to your business.
If you need DSPT compliance to win NHS work, access NHS systems, or maintain an existing contract, we help you get there in the right way, and with confidence.
Speak to our team: 01628 56 52 56
Email: [email protected]
Who this service is for
This service is designed for small IT and digital service providers that:
- Sell (or want to sell) services into the NHS
- Access NHS systems such as NHSmail or national NHS platforms
- Process health or care data under NHS contracts
- Have fewer than 50 staff or turnover below £10m
- Need to complete the Category 3 (“Other”) DSPT assessment
- Are registering for the first time or renewing an existing submission
If you operate across England and Wales, we can also help you complete the Welsh Information Governance Toolkit alongside the DSPT.
Why DSPT compliance matters
The NHS Data Security and Protection Toolkit (DSPT) is a mandatory annual self-assessment for organisations handling NHS data. It demonstrates that you meet the National Data Guardian’s 10 Data Security Standards and that you manage risk appropriately.
Without a published DSPT status of “Standards Met”:
- You are likely to be excluded from NHS procurement
- You may be denied or lose access to NHS systems
- Existing contracts may be put at risk
- Your non-compliance is publicly visible
DSPT compliance is not optional – it is the gateway to the NHS market.
What Category 3 DSPT compliance involves
Most small IT service providers should register under the “Other” organisation type, placing them into Category 3 of the DSPT.
Category 3 DSPT compliance requires you to provide documented evidence across 40+ mandatory evidence items, covering areas such as:
- Data protection policies and governance
- Staff responsibilities and training
- Access controls and user management
- Incident and breach response
- Business continuity planning
- Technical security controls (e.g. MFA, patching, encryption)
- Supplier and third-party assurance
- Digital asset register (introduced in DSPT Version 8)
Each requirement is evidence-based. The NHS expects you to demonstrate how risks are identified and reduced in practice, not simply that policies exist.

Start your DSPT compliance journey
If you need DSPT compliance to work with the NHS, don’t wait until deadlines approach.
Speak to JVR Consultancy today to take a structured, confident approach to DSPT compliance. To arrange a free consultation please call our head office or complete the form.
Book your free consultation today
How JVR Consultancy helps
Our DSPT consultancy is tailored to small and mid-sized IT suppliers, not large NHS Trusts. We focus on proportionate, defensible compliance that reflects how your organisation actually operates.
Gap analysis and readiness assessment
We assess your current position against Category 3 DSPT requirements, identifying:
- What you already have in place
- What is missing
- What needs strengthening or updating
This ensures your effort is focused on genuine risk and evidence gaps.
Policy and documentation support
We draft, review or update the documentation required for DSPT and DSP toolkit compliance, including:
- Data protection and information security policies
- Incident response and breach management plans
- Business continuity arrangements
- Records of processing activities
- Asset registers and supporting evidence
All documentation is aligned to DSPT expectations and your real working practices, not generic templates.
Technical guidance
We advise on the technical controls required to meet DSPT standards, including:
- Access management and least-privilege controls
- Encryption and authentication
- Patch and update management
- Asset tracking for Version 8 requirements
Where you already hold Cyber Essentials or similar certifications, we map this evidence to DSPT requirements to minimise duplication.
Portal and submission support
The DSPT portal can be unintuitive, particularly for first-time registrants. We can:
- Help you register under the correct organisation type
- Guide you through evidence entry and responses
- Review submissions before publication
…or manage the submission on your behalf
DSPT and Welsh IG Toolkit support
If you supply services into both NHS England and NHS Wales, we can manage:
- NHS DSPT submission
- Welsh Information Governance Toolkit submission
We reuse common evidence efficiently while ensuring each framework is completed correctly.
Ongoing annual support
DSPT compliance is an annual requirement, and evidence expectations evolve year to year. We provide ongoing support to:
- Refresh submissions
- Address new or updated requirements
- Maintain your published status without last-minute pressure
This turns DSPT into a managed, predictable process.
Why work with JVR Consultancy?
- Proven experience in DSPT compliance and DSPT consultancy
- Practical, proportionate support for small IT providers
- Clear advice focused on outcomes and risk reduction
- Compliance aligned with commercial reality
- Ongoing reassurance, not just a one-off submission
We help you pass procurement checks, access NHS systems, and protect your organisation – not just complete paperwork.
Roadmap of Engagement with JVR Consultancy
Your Compliance Challenges, Our Solutions
Why Certifications Are Essential for Your Business’s Success and Growth: At JVR Consultancy, we understand the critical challenges our clients face in today’s competitive landscape. Navigating complex compliance requirements and securing the necessary certifications can often be a barrier to growth. Whether it’s missing out on tenders due to insufficient compliance or struggling with industry-specific accreditation, these obstacles can limit your business potential.
Our tailored solutions ensure you overcome these challenges with ease. From achieving certifications to maintaining compliance and navigating audits, our expert team is here to help you gain the credentials you need—opening doors to new opportunities, winning tenders, and expanding your market reach.
Don’t let compliance be a barrier. Let it be your strength.
- Reach Out: Contact us via our website, phone, or email to start the conversation.
- Understanding Needs: We collect some basic information to understand your specific needs and challenges.
- Discovery Session: A free, no-obligation consultation with one of our senior consultants. We’ll discuss your requirements, objectives, and any compliance or certification challenges you’re facing.
- Tailored Guidance: We’ll outline the potential paths forward, providing initial advice on how best to achieve your goals.
- Identifying Gaps: We conduct a detailed gap analysis to assess your current status against the requirements of the desired certification or compliance standard.
- Custom Report: You’ll receive a detailed report that highlights areas of non-compliance, areas for improvement, and a clear action plan to bridge these gaps.
- Dedicated Consultant Assigned: A senior consultant with expertise in your industry will be assigned to guide you throughout the process.
- Step-by-Step Support: Our consultant will work alongside you to implement necessary changes, complete documentation, and provide training as needed.
- Actionable Plan: We provide a timeline and practical steps to achieve compliance, ensuring you stay on track.
- Pre-Audit Preparation: We assist in preparing for third-party audits by ensuring all processes and documents are in place.
- Audit Support: Our team will provide support during audits, whether remote or onsite, to ensure a smooth process and successful outcome.
- Maintenance and Updates: After achieving certification, we offer ongoing support to help maintain compliance, keep certifications up to date, and respond to any regulatory changes.
- Continuous Improvement: Our goal is not only to help you achieve compliance but also to foster continuous improvement, making compliance a seamless part of your business operations.
Related Data Protection Services
Nationwide Presence
26 national support locations throughout the UK. See Office Locations.
Fixed Fee Payments
There are no hidden charges, and what you see is what you pay.
Free Gap Analysis
Assess the difference between your business performance & your goals.
Audit Support
Supporting businesses with upcoming compliance audits. FAST TRACK priority support also available.
Ongoing Support
JVR offer Ongoing Support & Maintenance for peace of mind.
Customer Service
Our customer reviews are a testament to our work & the results we achieve.
Experience
Vast experience in developing compliant integrated management systems
Thorough Process
We write procedures, policies & associated documentation.
Bespoke
Our services are tailored to meet individual company requirements.
Audit Support
Get FAST TRACK Audit Support with JVR Consultancy Today. Click here to find out more.
Ongoing Support
Let us Manage your Accreditations with Ongoing Support and Maintenance. Click here to find out more.
Free Gap Analysis
Book a Free Gap Analysis for your business. To learn more, why not read our What is Gap Analysis? blog article and understand how a Gap report would benefit your company.
Related DSPT Compliance Articles
Learn more about DSPT compliance and Data Protection from our consultants in these related articles.





