How can NHS Trusts check a File Transfer supplier is DSPT compliant?

What the DSPT means for NHS File Transfer in 2026.

Author: AMS                                     Updated: 17 September 2026                     Reading time: 7 mins      

Executive Summary

The Data Security and Protection Toolkit (DSPT) is the NHS's annual self-assessment of how an organisation handles and protects patient data. Any organisation with access to NHS patient data and systems must complete it, including the technology suppliers whose platforms process that data. For an NHS Trust choosing a file transfer or file sharing platform, this means checking that the technology supplier is listed on the DSPT register with a Standards Met status.

a-medical-professional-speaking-with-a-women-in-finance

Key Takeaways

  • The DSPT is an online self-assessment tool that measures an organisation's performance against the National Data Guardian's 10 data security standards. All organisations with access to NHS patient data and systems must use it, with technology suppliers such as AMS Secure Cloud (Automated Messaging Systems Ltd), it’s a vital part of their on-going security obligations.

  • Assessments are published annually and each organisation receives one of four statuses: Standards Met, Standards Exceeded, Approaching Standards or Standards Not Met. Any organisation's most recent status can be checked on the public DSPT organisation search above.
  • The DSPT assesses the supplier's organisation, not the product. A buyer should check the supplier's published status and the product's own controls, such as hosting location, encryption, access controls and audit logging, to confirm the platform is suitable for the sensitive data it will handle.
  • AMS holds a published DSPT status of Standards Met for 2025-26 (published 19 June 2026, ODS code 8K883), is ISO 27001 and Cyber Essentials certified, and hosts all cloud solutions in Microsoft Azure UK datacentres.

What is the Data Security and Protection Toolkit?

  • The DSPT is an online self-assessment tool that allows organisations to measure their performance against the National Data Guardian's 10 data security standards. It is administered by NHS England. Each organisation completes it once a year, publishes the assessment and receives a status.

  • It applies beyond NHS bodies. All organisations that have access to NHS patient data and systems must use it. The listed organisation types include NHS Trusts, Integrated Care Boards (ICBs), Commissioning Support Units, Local Authorities, GPs, Dentists, Pharmacies, Social Care Providers, Universities, IT Suppliers and other organisation types.

  • For 2025-26, NHS Trusts and other large NHS bodies complete a version aligned to the National Cyber Security Centre's Cyber Assessment Framework (CAF), while technology suppliers and the remaining categories complete the version based on the 10 standards.

The four DSPT statuses

Anyone can look up an organisation's most recent status by searching its name or ODS code on the DSPT organisation search. The register shows the assessment year as well as the status.

Standards Met — The organisation has met the expected achievement level for every outcome. No improvement plan is required.

Standards Exceeded — The organisation has gone beyond the expected achievement levels. No improvement plan is required.

Standards Not Met — The organisation has not met the expected level for all outcomes and must submit an improvement plan.

Approaching Standards — A Standards Not Met organisation whose improvement plan has been approved.

Why the DSPT applies to Secure File Transfer suppliers

A file transfer or file sharing platform, such as AMS File Transfer, used by an NHS organisation, is often used to process Patient Identifiable Data (PID). The supplier therefore has access to NHS Patient Data in the form of a Data Processor.

The DSPT is an organisational assessment rather than a product certification. A supplier's status shows that its own data security practices met the standard. It does not describe how a specific product behaves. An NHS buyer will usually want to check both: the supplier's published DSPT status, and the solution controls and audit with regards to security.

The supplier's product specification should also be reviewed to confirm it meets the NHS Trust's own requirements when sharing PID and other sensitive data.

Certifications such as ISO 27001 and Cyber Essentials are separate schemes that cover much of the same ground and are commonly requested alongside the DSPT.

a-medical-professional-speaking-with-a-women-in-finance

How to choose a File Transfer platform for NHS data

How AMS Secure Cloud approaches the DSPT

AMS Secure Cloud has partnered with the NHS for over three decades. Amongst other security accreditations and annual penetration testing, AMS prioritises the DSPT as a supplier. Its 2025-26 assessment was published on 19 June 2026 with a status of Standards Met. The entry is listed under Automated Messaging Systems Ltd, ODS code 8K883, on the DSPT organisation search. AMS is also ISO 27001 and Cyber Essentials certified, and its practices are aligned with UK GDPR and the Data Protection Act 2018.

  • Hosting. All AMS cloud solutions are hosted in Microsoft Azure UK datacentres, supporting UK data sovereignty requirements. Resilience is provided through Azure availability zones and disaster recovery capabilities.

  • Encryption. All data in the AMS Secure Cloud platform is encrypted in transit and at rest. The platform protects two-way file delivery and sharing with 256 bit AES encryption. AMS File Transfer is often used by the NHS for the disclosure of Subject Access Requests (SARs), Health Records and the Access to Health Records process.

  • AMS' own access governance when administering the system. Role based permissions with Azure role based access control and Privileged Identity Management. Multi-factor authentication for all administrative access, with regular reviews of user access rights.

  • Monitoring and testing of the platform. Automated Messaging Systems Ltd (AMS) utilise Microsoft Defender for Cloud to monitor unusual activity or events. The AMS File Transfer and AMS Secure Cloud platform in general is penetration tested annually and tested internally.

  • Retention. Upon contract termination, customer data is securely deleted from AMS systems within 60 days, in line with the AMS retention and disposal policy.

abstract-curls

Amongst other industries, AMS File Transfer is used heavily across NHS and healthcare environments for securely transferring and sharing patient identifiable and highly sensitive data. Common uses include Subject Access Requests and health records disclosure, complaint responses and audio recordings, Patient Liaison (PALS) transfers and secure transfer of sensitive files relating to Child Services.

AMS Secure Cloud provides:

  • A full end to end audit trail.
  • Transfer of files of any size, subject to administrator permissions.
  • Automated file expiry and lifecycle rules.
  • Permissions based access with reporting.
  • Custom branding with your own web and email domains.
  • Optional PACS Server integration to cater for DICOM files and radiology images.
  • Optional Digital Rights Management to limit downloading, printing or forwarding.

For teams that also handle SAR and FOI requests, the AMS Request Management Portal caters for the whole request process from capture, to internal management, to secure disclosure of files. The AMS Request Management Portal (originally called the AMS SAR Portal) is protected by the same controls: UK based hosting, 256 bit AES encryption and a complete audit trail, and is covered by AMS's published DSPT assessment.

AMS File Transfer is best for NHS and healthcare organisations that need a UK hosted file transfer and sharing platform for patient identifiable data, from a supplier with a published DSPT Standards Met status.

Frequently Asked Questions

No, but it is still important. It is an annual self assessment published by the organisation itself, which receives one of four statuses.

abstract-tubes
abstract-tubes
abstract-tubes
abstract-tubes
abstract-tubes
abstract-tubes

Conclusion

The DSPT gives NHS buyers a public, annual check on whether a supplier's data security practices meet the national standard. For file transfer, that check should be made alongside the product questions: where data is hosted, how it is encrypted, who can access it, what is logged, and what happens to it after delivery and at contract end. AMS holds a published Standards Met status for 2025-26, is certified to ISO 27001 and Cyber Essentials, and is hosted in Microsoft Azure UK datacentres.

Want to learn more?

Talk to our sales and support team.