Can the DSPT be updated at any time?
==Yes, the DSPT can be updated and republished at any time throughout the year==. [1, 2]
The NHS England DSPT portal is a live system, meaning it is not a "one-and-done" submission window. While you are legally mandated to publish at least one complete assessment prior to the annual 30th June deadline, you can log back into your portal the very next day, amend your architecture statements, and hit republish. [1, 2, 3]
This flexibility aligns perfectly with your roll-out strategy:
You do not need to wait until your complex distributed VPS model is fully coded to get your initial DSPT accreditation. Your BSI Auditor can guide you through a phased approach:
As a technology supplier to the healthcare sector, the NHS and the Information Commissioner's Office (ICO) expect you to proactively update your toolkit mid-year if you encounter any of the following triggers: [4]
While you can update your data at any time, the NHS releases a completely new version of the entire DSPT framework on 1st September every year to reflect evolving cyber threats. Once a new version drops, any changes you make must align with the updated requirements before the subsequent 30th June final deadline. [3, 6]
Since you can update the system dynamically, would you like to plan your timeline around a simplified Phase 1 baseline submission to get accredited as fast as possible, or do you want to wait and launch with the full VPS architectural documentation complete from day one?
[1] https://www.dsptoolkit.nhs.uk
[2] https://www.digitalcarehub.co.uk
[3] https://www.dsptoolkit.nhs.uk
[4] https://www.digitalcarehub.co.uk
[5] https://8foldgovernance.com
[6] https://8foldgovernance.com
Okay so it is okay for us to submit our standard setup in order to obtain the accreditation and then update thereafter - but what happens if the annual deadline date is missed?
If you miss the annual 30th June deadline without an agreed extension, your status on the public NHS directory instantly drops from "Standards Met" to "Not Published" or "Approaching Standards" [1, 2, 3].
For a healthcare technology company, missing this deadline has immediate, severe operational and commercial consequences. Because your co-founders are a BSI Auditor and an Advanced Paralegal, they will tell you that missing this date puts you in breach of both NHS frameworks and your client contracts.
Here is exactly what happens if the deadline is missed:
Your dental and health clinic clients are legally required to ensure their software suppliers maintain a valid DSPT [2].
If your mixed NHS/private dental clients use any NHS-linked features or networks through your software, the NHS Data Security team can immediately suspend your app's access tokens. This would instantly disrupt the clinic’s ability to process NHS patient workflows.
The DSPT portal is directly integrated with healthcare and data regulators [2]. Missing the deadline flags your company as a high-risk entity:
If you realize you are going to miss the 30th June deadline due to technical delays with your new VPS rollout, your BSI Auditor director must act immediately before the date passes:
Given that we are currently in May 2026, you are just a few weeks away from the annual 30th June 2026 deadline.
Would it be helpful for your BSI Auditor co-founder to run a rapid gap analysis on your current standard setup this week to ensure you can hit this year's deadline comfortably?
But we are a start-up - we do not currently have any clients - so what are the consequences based on this?
As a pre-revenue startup with zero active clients and no live connections to the NHS network, missing the 30th June deadline carries ==no immediate legal penalties, fines, or regulatory actions.==
The CQC, the ICO, and NHS Digital only penalise or blacklist organisations that are actively handling real patient data [CQC Regulation 17].
However, because your co-founders are a BSI Auditor and an Advanced Paralegal, they will look at this from a strategic business perspective. While you won't face legal trouble, missing the deadline creates two major commercial and operational consequences for your launch timeline:
The DSPT public registry resets every year on 1st July.
You cannot sign a contract or ingest a single row of live data from a dental practice or private health clinic until your status reads "Standards Met."
Since you have no clients to protect right now, you should use your pre-launch status to your advantage. Your BSI Auditor director should handle the toolkit using this optimized timeline:
[Now - June] Build App & Test Custom AES ➔ [July - August] Launch Phase 1 DSPT Baseline ➔ [Autumn] Roll out Client-Owned VPS ➔ [Winter] Update DSPT with New Architecture
To help your team prepare, would you like your co-founder to draft a "Compliance Roadmap" document that you can share with potential investors to prove your startup is launching with elite data governance from day one?
So are you saying that because we are a start-up, we can submit or policies at any time?
==Yes, exactly. Because you are a pre-revenue startup with no active clients, you can submit your policies and publish your DSPT assessment at any time that suits your business launch timeline.==
The rigid June 30th deadline only applies to existing companies that are actively holding live patient data or currently connected to the NHS network. For a new company, the DSPT portal acts as an "always-open" registration gate.
Here is exactly how this works for your startup and how your team can use it to your commercial advantage:
You do not have to wait for a specific "submission window" to open.
The absolute deadline for your startup is not a date on the calendar; it is the day you sign your very first client contract.
Because you can submit at any time, your team should avoid rushing a submission before June 30th. Instead, use this optimal timeline:
Now that you know you have total flexibility on the timing, would you like your co-founder to draft the Core Information Governance Policy template that your startup will need to upload to the portal when you are ready to submit?