LOADING…
Platform  /  Health & care  ·  Sector
Health & care

The DSPT is CAF now.Are your suppliers ready?

E2ERisk helps NHS trusts, ICBs and care providers assure the suppliers behind patient-facing services - now the Data Security and Protection Toolkit (DSPT) is aligned to the NCSC CAF and annual submissions no longer reflect live risk.

See the platform
DSPT CAF-alignedDTAC readyUK GDPR native
The challenge

Supplier risk is a patient-safety risk.

NHS trusts, ICBs and care providers run patient-facing services on top of a deep supply chain: electronic patient records, e-referral and booking systems, diagnostics and pathology platforms, shared care records, and the processors and managed providers behind them. When one of those suppliers is breached or goes offline, the impact lands on clinical workflows, cancelled appointments and patients - not just a compliance report.

Now the DSPT is aligned to the NCSC CAF, the bar on supplier assurance has risen - and a once-a-year toolkit submission no longer reflects an estate that changes constantly. E2ERisk links every supplier and processor to the patient data it handles and the clinical services it supports: DSPT- and DTAC-aligned assessment, DPIA linkage and continuous outside-in monitoring, in one place.

Built for health-and-care data environments - UK data residency, customer-tenant deployment and an append-only audit trail - so privacy, security and continuity sit together rather than in three disconnected tools.

The brief

Assurance across health & care.

Most health-and-care organisations understand their obligations; what they lack is a current, connected view of which supplier holds which data. A single trust or ICB can depend on dozens of clinical-system, diagnostics and managed-service providers - each touching patient information - and a once-a-year DSPT scramble cannot keep pace. Here is the difference one shared evidence base makes.

Without E2ERisk
Clinical systems and data sit with dozens of third parties
The DSPT cycle is a yearly evidence scramble
Patient data flows you cannot fully see or evidence
Supplier outages can become patient-safety issues
With E2ERisk
Every clinical supplier assessed by the data they touch
DSPT evidence captured once and kept current
Processing mapped to suppliers, assets and DPIAs
Critical suppliers mapped to the services that depend on them
How it works

One lifecycle, end to end.

Every clinical supplier follows the same path, from the moment it is engaged through to continuous monitoring long after onboarding. How deep the assessment goes is set by the patient data it touches and the service it underpins - so a small information-governance team spends its effort where patient risk actually concentrates, not spread evenly across every vendor.

01 Onboard
It starts at intake
New suppliers captured the moment they are engaged.
No more shadow vendors found at audit.
02 Profile
Right depth
Criticality and data exposure set the assessment depth.
Effort lands where the risk actually is.
03 Assess
Native to your frameworks
Assessed against DSPT, CAF, DTAC and UK GDPR, at control level.
Defensible judgements, not a tick-box.
04 Evidence
Capture once
Evidence inherits across every overlapping requirement.
Re-used, not re-collected, each cycle.
05 Remediate
Close the gap
Findings become owned actions with dates.
Progress tracked, not forgotten.
06 Monitor
Stay current
Outside-in signals and review dates keep it live.
You see supplier exposure before it affects patient services.
CLINICAL SUPPLIERS Live
Onboard
Supplier and data flow logged
Classify
By the patient data it touches
auto
Assess
DSPT & CAF-aligned
DPIA link
Tied to processing
linked
Remediate
Gaps closed, owned
Monitor
Exposure watched live

You know which supplier holds which patient data - and that it is assured.

The difference

The DSPT cycle, made continuous.

The obligations do not change; the work behind them does. Instead of rebuilding the DSPT evidence by hand each year and tracking clinical suppliers in a spreadsheet, the same activity runs as one connected, auditable process - line by line, here is what moves.

What you doToolkit + spreadsheetsE2ERisk
DSPT evidenceAssembled once a year, by handCaptured once and kept current
Clinical suppliersTracked looselyAssessed by the data they touch
Patient data flowsHard to see end to endMapped to suppliers and DPIAs
DPIAsWord filesA living register, ICO-ready
ContinuityPer-supplier guessworkSuppliers mapped to clinical services
An auditA fire drillAn evidence pack on demand

The result is not just an easier toolkit submission - it is a defensible position on patient data. The moment a regulator or a board asks, you can show which supplier holds what, that it has been assessed, and that a DPIA covers the processing.

Where to start

The modules that matter most here.

You do not have to start everywhere. Most health-and-care teams begin with Supplier Assurance and the DPO Centre - the suppliers and processing that touch patient data - then add CAF and Business Resilience as the shared evidence base proves itself. Because every module runs on one engine, what you build for the first carries straight into the next.

By the numbers

What it means for patient data.

For a health-and-care organisation the payoff is a single, current picture of every supplier that touches patient information. One register holds every clinical supplier, each DPIA is linked to the processing and the suppliers behind it, and the DSPT evidence is captured once rather than rebuilt from scratch each year.

And because exposure is monitored continuously rather than checked once a year, you learn about a supplier problem as it emerges - not at the next audit, and not when it has already affected patient services.

1
register for every clinical supplier
Every
DPIA linked to processing & suppliers
0
annual evidence rebuilds
24/7
outside-in exposure monitoring
Native to your regimes

One evidence base for every regime.

A trust answers to more than one regime at once, and an assessor for the DSPT will not accept evidence shaped only for ISO. E2ERisk maps a single body of assessment answers to every regime health-and-care providers are held to - so the evidence holds up whichever one is asking.

DSPTUK GDPRNCSC CAF v4.0Cyber EssentialsISO 27001:2022NIS Regulations
Next step

Assure the data, protect the service.

A 30-minute walkthrough on your clinical suppliers and the DSPT - no slides.