NHS DSPT COMPLIANCE · United Kingdom

NHS DSPT Compliance UK

NHS Data Security and Protection Toolkit (DSPT) compliance for UK SMEs handling NHS data — annual toolkit completion, evidence gathering, and assertion support. We guide you through the 10 data security standards and get you to 'Standards Met'. Fixed-scope.

Standards Met Annual cycle ICO + CQC aligned Fixed price

Fixed

DSPT support from

10

Data security standards

Annual

Submission cycle

100%

Evidence gathered for you

Cybersecurity Consulting + 24/7 SOC Monitoring

Every Gridisys engagement is built on two pillars — strategic consulting to design the right controls, and managed SOC monitoring to keep them effective.

Cybersecurity Consulting

UK consulting engagements: risk assessment, security architecture, conditional access design, compliance (Cyber Essentials, UK GDPR, FCA PS21/3, NIS2), incident-response planning. Board-ready documentation, no jargon, no surprise invoices.

  • Risk assessment + security architecture review
  • Conditional access + Entra ID hardening design
  • Cyber Essentials / UK GDPR / FCA / NIS2 compliance support
  • Incident response planning + tabletop exercises
  • Vendor + supply-chain security assessment
  • Board / DPO reporting + evidence pack

Managed SOC Monitoring · 24/7

AI-augmented Security Operations Centre — continuous monitoring across Microsoft 365 / Entra ID, Defender, on-prem, and cloud. UK-based analysts, sub-hour triage on critical alerts. No long contract required.

  • 24/7 SIEM monitoring — Microsoft 365, Entra ID, Defender, Azure, on-prem logs
  • BEC + mailbox-compromise + OAuth grant abuse detection
  • Suspicious sign-in + conditional access drift alerting
  • Ransomware + lateral-movement detection from EDR + Defender
  • Sub-hour triage on critical alerts, monthly ops report
  • Optional + integrated with consulting engagements

Most engagements start with consulting (1-2 weeks), then SOC monitoring (ongoing ) keeps the controls effective.

GET A QUOTE

Pricing tailored to your needs

Every engagement is scoped to your environment and requirements. Book a free consultation for a tailored quote — no obligation.

What we cover

Practical, board-ready consulting — no jargon, no surprise invoices.

DSPT Gap Analysis

We assess your current posture against the 10 NHS data security standards and identify gaps before you submit.

Evidence Gathering

We gather the evidence each assertion requires — policies, configurations, training records, and incident logs.

Toolkit Completion

We complete the DSPT toolkit with you — answering each assertion with evidence and achieving 'Standards Met'.

Policy Development

We draft the policies DSPT requires — data protection, incident response, acceptable use, and information governance.

Staff Training

We deliver the mandatory data security training DSPT requires — and provide completion records as evidence.

Annual Maintenance

We maintain your DSPT submission annually — updating evidence, re-completing assertions, and tracking changes.

How we work

1

Gap analysis (1 week)

We assess your posture against the 10 standards. Gaps identified and remediation plan agreed.

2

Remediation + evidence (2-3 weeks)

We fix gaps, gather evidence, draft policies, and deliver training.

3

Toolkit submission (1 week)

We complete the toolkit with you and submit. 'Standards Met' achieved.

Sectors we protect

Pharmacies GP practices Dental practices Care homes Doctors NHS suppliers Healthcare MSPs serving NHS
FREE CONSULTATION

Achieve DSPT 'Standards Met' — with expert support

Gap analysis, evidence gathering, policies, training, and submission. Fixed price.

Frequently asked questions

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.