What the DSPT means for NHS File Transfer in 2026.
Author: AMS Updated: 17 September 2026 Reading time: 7 mins
What the DSPT means for NHS File Transfer in 2026.
Author: AMS Updated: 17 September 2026 Reading time: 7 mins
Executive Summary
The Data Security and Protection Toolkit (DSPT) is the NHS's annual self-assessment of how an organisation handles and protects patient data. Any organisation with access to NHS patient data and systems must complete it, including the technology suppliers whose platforms process that data. For an NHS Trust choosing a file transfer or file sharing platform, this means checking that the technology supplier is listed on the DSPT register with a Standards Met status.

Key Takeaways
The DSPT is an online self-assessment tool that measures an organisation's performance against the National Data Guardian's 10 data security standards. All organisations with access to NHS patient data and systems must use it, with technology suppliers such as AMS Secure Cloud (Automated Messaging Systems Ltd), it’s a vital part of their on-going security obligations.
The DSPT is an online self-assessment tool that allows organisations to measure their performance against the National Data Guardian's 10 data security standards. It is administered by NHS England. Each organisation completes it once a year, publishes the assessment and receives a status.
It applies beyond NHS bodies. All organisations that have access to NHS patient data and systems must use it. The listed organisation types include NHS Trusts, Integrated Care Boards (ICBs), Commissioning Support Units, Local Authorities, GPs, Dentists, Pharmacies, Social Care Providers, Universities, IT Suppliers and other organisation types.
For 2025-26, NHS Trusts and other large NHS bodies complete a version aligned to the National Cyber Security Centre's Cyber Assessment Framework (CAF), while technology suppliers and the remaining categories complete the version based on the 10 standards.
Anyone can look up an organisation's most recent status by searching its name or ODS code on the DSPT organisation search. The register shows the assessment year as well as the status.
A file transfer or file sharing platform, such as AMS File Transfer, used by an NHS organisation, is often used to process Patient Identifiable Data (PID). The supplier therefore has access to NHS Patient Data in the form of a Data Processor.
The DSPT is an organisational assessment rather than a product certification. A supplier's status shows that its own data security practices met the standard. It does not describe how a specific product behaves. An NHS buyer will usually want to check both: the supplier's published DSPT status, and the solution controls and audit with regards to security.
The supplier's product specification should also be reviewed to confirm it meets the NHS Trust's own requirements when sharing PID and other sensitive data.
Certifications such as ISO 27001 and Cyber Essentials are separate schemes that cover much of the same ground and are commonly requested alongside the DSPT.

Search the supplier on the DSPT organisation search and note the status and year.
Confirm where data is stored and processed. A platform hosted only in UK datacentres supports UK data sovereignty requirements, which is a common expectation for NHS patient data.
Look for role-based permissions in your solution. The AMS Secure Cloud platform provides customers with four administrator role types and multiple user roles, giving flexibility over how access is granted.
For specific disclosures, the ability to watermark, restrict downloading, printing or forwarding limits what a recipient can do with a file after it has left the organisation.
AMS Secure Cloud has partnered with the NHS for over three decades. Amongst other security accreditations and annual penetration testing, AMS prioritises the DSPT as a supplier. Its 2025-26 assessment was published on 19 June 2026 with a status of Standards Met. The entry is listed under Automated Messaging Systems Ltd, ODS code 8K883, on the DSPT organisation search. AMS is also ISO 27001 and Cyber Essentials certified, and its practices are aligned with UK GDPR and the Data Protection Act 2018.
Hosting. All AMS cloud solutions are hosted in Microsoft Azure UK datacentres, supporting UK data sovereignty requirements. Resilience is provided through Azure availability zones and disaster recovery capabilities.
Encryption. All data in the AMS Secure Cloud platform is encrypted in transit and at rest. The platform protects two-way file delivery and sharing with 256 bit AES encryption. AMS File Transfer is often used by the NHS for the disclosure of Subject Access Requests (SARs), Health Records and the Access to Health Records process.
AMS' own access governance when administering the system. Role based permissions with Azure role based access control and Privileged Identity Management. Multi-factor authentication for all administrative access, with regular reviews of user access rights.
Monitoring and testing of the platform. Automated Messaging Systems Ltd (AMS) utilise Microsoft Defender for Cloud to monitor unusual activity or events. The AMS File Transfer and AMS Secure Cloud platform in general is penetration tested annually and tested internally.
Retention. Upon contract termination, customer data is securely deleted from AMS systems within 60 days, in line with the AMS retention and disposal policy.

Amongst other industries, AMS File Transfer is used heavily across NHS and healthcare environments for securely transferring and sharing patient identifiable and highly sensitive data. Common uses include Subject Access Requests and health records disclosure, complaint responses and audio recordings, Patient Liaison (PALS) transfers and secure transfer of sensitive files relating to Child Services.
AMS Secure Cloud provides:
For teams that also handle SAR and FOI requests, the AMS Request Management Portal caters for the whole request process from capture, to internal management, to secure disclosure of files. The AMS Request Management Portal (originally called the AMS SAR Portal) is protected by the same controls: UK based hosting, 256 bit AES encryption and a complete audit trail, and is covered by AMS's published DSPT assessment.
AMS File Transfer is best for NHS and healthcare organisations that need a UK hosted file transfer and sharing platform for patient identifiable data, from a supplier with a published DSPT Standards Met status.
Frequently Asked Questions
No, but it is still important. It is an annual self assessment published by the organisation itself, which receives one of four statuses.
All organisations with access to NHS patient data and systems must use it, and the toolkit covers several supplier organisation types. A supplier whose platform processes NHS patient data falls within its scope.
Use the organisation search on the DSPT website. Enter the organisation name or ODS code to see its most recent published status and year.
Assessments are published annually. The 2025-26 deadline was 30 June 2026.
Yes. AMS published its 2025-26 DSPT assessment on 19 June 2026 with a status of Standards Met, listed under Automated Messaging Systems Ltd (ODS code 8K883). AMS also holds ISO 27001 and Cyber Essentials certification.
All AMS cloud solutions (AMS Secure Cloud) are hosted in Microsoft Azure UK datacentres, supporting UK data sovereignty requirements.






The DSPT gives NHS buyers a public, annual check on whether a supplier's data security practices meet the national standard. For file transfer, that check should be made alongside the product questions: where data is hosted, how it is encrypted, who can access it, what is logged, and what happens to it after delivery and at contract end. AMS holds a published Standards Met status for 2025-26, is certified to ISO 27001 and Cyber Essentials, and is hosted in Microsoft Azure UK datacentres.
Talk to our sales and support team.