Prepare for the NHS Data Security and Protection Toolkit

Understand the current position, organise the evidence, and identify the work needed before submission.

What the assessment can cover

The assessment is shaped around the organisation, the toolkit requirements that apply, and the evidence already available.

  • Current positionCompleted responses, known gaps, previous submissions, and the people responsible for each area.
  • Policies and evidenceWhere supporting documents, records, approvals, or operational evidence are missing or out of date.
  • Technology controlsRelevant security, access, device, backup, and information-handling arrangements against the evidence required.
  • People and responsibilitiesOwnership, training, incident processes, and the practical work needed from different parts of the organisation.
  • Gap prioritiesUrgent submission blockers separated from improvements that can be planned in a controlled order.
  • Submission readinessWhat is ready, what remains incomplete, and what evidence should be retained.

From current position to a practical plan

Nothing begins until applicability, responsibilities, evidence, output, and cost are clear.

Confirm applicability

Agree the organisation in scope, current submission position, available evidence, responsibilities, and assessment boundaries.

Review responses and evidence

Work through the agreed requirements and identify where claims need stronger support or further action.

Provide a practical action plan

Receive prioritised gaps and clear next steps. Your organisation remains responsible for approving and submitting its declaration.

Be clear before you submit

Tell us where the submission stands and what evidence is already available. We will confirm a sensible assessment scope.