CAF vs DSPT: The UK Shift

CAF vs DSPT: The UK Shift

The UK health and care sector is moving from a checklist-style compliance mindset toward a more outcome-based cyber resilience model. The NHS Data Security and Protection Toolkit, commonly known as DSPT, has long helped health and care organizations assess data security and protection responsibilities. The Cyber Assessment Framework, known as CAF, introduces a broader resilience approach focused on governance, risk management, protection, detection, response and recovery.

For NHS, health and care, public sector and regulated organizations, this shift matters because cybersecurity can no longer be treated as an annual compliance submission. Organizations need evidence that cyber risks are understood, managed, monitored and improved continuously.

Executive Summary

DSPT and CAF are connected, but they are not the same thing. DSPT has traditionally been used by health and care organizations to demonstrate data security and protection compliance. CAF, developed by the National Cyber Security Centre, is an outcome-focused framework designed to help organizations assess cyber security and resilience, especially where essential services are involved.

The shift toward CAF alignment means organizations need to move beyond static checklist responses. They need stronger evidence of security governance, risk ownership, identity and access control, supply chain assurance, incident response, monitoring, recovery and continuous improvement.

For leadership, this means cyber resilience must become part of operational governance. For security, privacy, compliance and IT teams, it means evidence must be maintained throughout the year, not collected only when an assessment deadline arrives.

What Are DSPT and CAF?

DSPT: Data Security and Protection Toolkit

The Data Security and Protection Toolkit is used across NHS, health and social care settings to support data security and information governance assurance. It has historically helped organizations demonstrate that they are meeting expected data security and protection practices.

DSPT is closely connected with health and care information governance, UK GDPR, data protection, confidentiality, security responsibilities and organizational accountability.

CAF: Cyber Assessment Framework

The Cyber Assessment Framework is a cyber security and resilience assessment framework developed by the UK National Cyber Security Centre. CAF is designed to help organizations assess whether cyber risks to essential functions are being managed effectively.

CAF focuses on outcomes. It asks whether organizations can show that cyber risks are governed, protected against, detected, responded to and recovered from in a way that supports essential service continuity.

CAF vs DSPT: Quick Comparison

Area DSPT CAF
Full name Data Security and Protection Toolkit Cyber Assessment Framework
Primary use Health and care data security and protection assurance Cyber security and resilience assessment for essential functions
Main focus Data security, information governance and protection of health and care information Governance, risk management, cyber protection, detection, response and recovery
Assessment style Historically more compliance and submission focused Outcome-based and resilience focused
Common audience NHS, health care, adult social care and connected suppliers Essential service operators, public sector, health care and regulated environments
Evidence expectation Data protection and security practice evidence Evidence that cyber risks to essential services are understood, managed and improved
Best used for Demonstrating data security and protection assurance Demonstrating cyber resilience maturity and operational control effectiveness

Why the UK Is Moving Toward CAF-Aligned Cyber Resilience

Cyber threats affecting health, care and essential services have become more operationally disruptive. A data protection checklist alone is not enough when ransomware, supplier compromise, identity attacks, service outages and system disruption can affect patient care and public trust.

CAF alignment supports a stronger model because it focuses on whether cyber risk is being managed in practice. This includes governance, risk management, identity controls, monitoring, incident response, recovery planning and supply chain resilience.

The practical message is simple: organizations must show that cyber resilience is operating continuously, not only documented during an annual assessment.

What Changes for Health and Care Organizations?

Organizations that previously treated DSPT as an annual submission need to prepare for a more evidence-driven approach.

Key changes include:

  • Stronger focus on cyber resilience outcomes
  • More emphasis on governance and accountable ownership
  • Better evidence of security risk management
  • Clearer mapping of essential functions and critical services
  • Improved incident response and recovery evidence
  • Stronger supply chain and third-party risk controls
  • Continuous evidence collection throughout the year
  • More leadership visibility into cyber risk and remediation

The shift is not only about filling in a different assessment. It is about proving that controls are implemented, monitored and improved.

CAF Objectives Explained

CAF is organized around high-level cyber security and resilience objectives. These objectives help organizations assess whether they can manage cyber risk and protect essential services.

Objective A: Managing Security Risk

Organizations need appropriate governance, policies, processes and accountability to understand and manage cyber security risks. This includes leadership ownership, risk assessment, asset understanding, supplier oversight and security governance.

Objective B: Protecting Against Cyber Attack

Organizations need proportionate security controls to protect systems and services from compromise. This includes identity and access control, secure configuration, vulnerability management, network security, endpoint protection and data protection.

Objective C: Detecting Cyber Security Events

Organizations need the ability to detect cyber security events that could affect essential services. This includes monitoring, logging, alerting, threat detection, SOC visibility and investigation capability.

Objective D: Minimising the Impact of Cyber Security Incidents

Organizations need the ability to respond to and recover from cyber incidents. This includes incident response planning, escalation, communication, containment, recovery and post-incident improvement.

Common CAF Readiness Gaps

Many organizations will find that the largest gaps are not technical tools. The real gaps are often around ownership, evidence and repeatability.

Common gaps include:

  • No clear owner for cyber risk decisions
  • Asset inventories not linked to critical services
  • Supplier risk not monitored continuously
  • Weak evidence of access control reviews
  • Incident response plans not tested
  • Limited SOC or monitoring visibility
  • Incomplete recovery evidence
  • Audit evidence stored across emails and spreadsheets
  • No consistent remediation tracking
  • Limited leadership reporting on cyber resilience

These gaps make it hard to prove cyber resilience even if individual security tools are already deployed.

What Organizations Should Do Now

Organizations preparing for CAF alignment should start with a practical readiness plan.

Build a Cyber Resilience Evidence Inventory

Create a central evidence repository for governance, risk assessments, policies, access reviews, supplier checks, incident response tests, vulnerability records and audit outputs.

Map Critical Services and Essential Functions

Identify the systems, suppliers, applications, users and data that support critical services. Cyber resilience cannot be assessed properly if critical dependencies are unclear.

Review Identity and Access Controls

Check privileged access, MFA coverage, joiner-mover-leaver processes, service accounts, shared accounts and access review evidence.

Strengthen Incident Response and Recovery

Test response plans, escalation paths, containment actions, recovery steps and communications. Keep evidence of exercises and lessons learned.

Improve Supplier and Third-Party Risk Visibility

Review suppliers that support essential functions, cloud platforms, software, managed services and data processors. Track assurance evidence and remediation actions.

Connect Security Monitoring to Governance

SOC alerts, SIEM telemetry, EDR signals, vulnerability findings and incident records should be linked to business risk and compliance evidence.

CAF vs DSPT Readiness Checklist

Use this checklist to assess readiness:

  • Do you have a current cyber risk register?
  • Are critical services and supporting systems mapped?
  • Are cyber risks owned by named business and technical owners?
  • Are identity and access reviews documented?
  • Is MFA enforced for privileged and high-risk access?
  • Are suppliers assessed for cyber resilience?
  • Are incident response plans tested?
  • Is recovery evidence documented?
  • Are security events monitored and triaged?
  • Are vulnerabilities tracked to remediation?
  • Is audit evidence stored centrally?
  • Can leadership see current cyber risk and control status?
  • Is compliance evidence updated continuously rather than once a year?
How SUSAN Supports CAF and DSPT Readiness

SUSAN, ServQual’s AI driven cybersecurity, privacy and GRC platform, helps organizations connect security, privacy, compliance and operational risk evidence into one assurance view.

For CAF and DSPT readiness, SUSAN can help organizations support:

  • Cyber risk visibility
  • Control ownership tracking
  • Continuous Monitoring & Evidence
  • Audit-ready evidence management
  • Third-party and vendor assurance
  • SOC and cloud validation workflows
  • Compliance mapping
  • Remediation ownership
  • Risk scoring and prioritisation
  • Leadership reporting
  • Continuous Assurance

SUSAN helps teams move away from scattered spreadsheets and point-in-time evidence collection. It supports a more continuous operating model where cyber risk, compliance evidence, remediation actions and leadership reporting are managed together.

Learn more about SUSAN here: https://srql.com/services/susan/

What This Means for Leadership

 CAF alignment is not only an IT activity. It is a leadership and governance issue.

Boards and senior leaders should expect clearer answers to questions such as:

  • What are our most important services?
  • Which systems and suppliers support those services?
  • What cyber risks could disrupt them?
  • Which controls are operating effectively?
  • Where is remediation overdue?
  • How do we know incidents can be contained and recovered from?
  • What evidence proves our cyber resilience position?

Organizations that can answer these questions clearly will be better prepared for CAF-aligned assurance and wider cyber resilience expectations.

Picture of Dara Sturgeon

Dara Sturgeon

Security Success Manager | ServQual

FAQ

Most frequent questions and answers

DSPT stands for Data Security and Protection Toolkit. It is used by health and care organizations to support data security and protection assurance.

CAF stands for Cyber Assessment Framework. It is a cyber security and resilience assessment framework developed by the UK National Cyber Security Centre.

DSPT has traditionally focused on health and care data security and protection assurance. CAF is broader and more outcome-based, focusing on governance, cyber risk management, protection, detection, response and recovery.

The health and care sector is moving toward CAF-aligned cyber resilience assessment. Organizations should review current NHS and regulatory guidance to understand exactly how the transition applies to them.

CAF matters because health and care organizations depend on digital services, suppliers, systems and data. Cyber incidents can affect patient care, service continuity, privacy and public trust.

Organizations should start by mapping critical services, assigning risk ownership, reviewing controls, testing incident response, assessing suppliers and maintaining continuous audit evidence.

SUSAN helps organizations connect cyber risk, control ownership, compliance evidence, SOC and cloud validation, third-party assurance, remediation tracking and leadership reporting into a structured Continuous Assurance model.

CAF alignment requires more than a completed assessment. Health and care organizations need clear ownership, evidence-backed cyber resilience, tested incident response, supplier assurance and continuous monitoring.

Explore SUSAN, ServQual’s AI driven cybersecurity, privacy and GRC platform, or contact ServQual to discuss how your organization can strengthen CAF readiness, DSPT evidence, cyber resilience and Continuous Assurance.

Disclaimer:This article is educational and does not constitute legal, regulatory or compliance advice. CAF, DSPT and UK health and care cyber security requirements should be validated against current NHS, NCSC, ICO and regulatory guidance for the organization’s specific context.

What do you think?

What to read next