Who holds a current NHS data-security assessment: a census of the Data Security and Protection Toolkit register Published dataset: nhs-dsp-toolkit-supplier-compliance-2026.csv WHAT THIS IS A census of every organisation on the public register of the NHS Data Security and Protection Toolkit: 93,260 registered entries, counted by whether they have published an assessment for the 2025-26 (version 8) cycle or later. One row per registered entry. This is a population, not a sample. THIS IS A CENSUS OF A REGISTER, NOT OF A SECTOR. Nothing published by NHS England identifies which rows on the register are there by requirement rather than by choice, or lists the organisations required to complete the toolkit. An organisation that never registered leaves no row and is invisible here. Every figure derived from this dataset must be qualified 'of the organisations registered on the toolkit'. No claim of any kind can be made from this data about organisations that never registered. NO CURRENT ASSESSMENT DOES NOT MEAN INSECURE. It means no assessment from the 2025-26 cycle or later appears on the register on 2026-09-25. An organisation may hold certification under another regime, may have merged or closed, or may have stopped handling NHS data. 45.61% of the entries with a lapsed assessment are marked Inactive in NHS ODS, against 1.55% of current ones. Nothing in this dataset is a security test: no system was scanned, probed or accessed. NO REGISTERED ORGANISATION IS NAMED, AND THE CODE IS NOT ANONYMOUS. The source register publishes each organisation's name and this dataset reproduces none of them, no email address and no postcode, because the register includes sole traders whose organisation name is a person's name. The one column that does carry organisation names is icb: the Integrated Care Board is the commissioning-geography label NHS ODS puts on a row, not the identity of the row, and a board figure is a figure about the entries in a geography rather than about the board. The ODS code is kept so the census can be reproduced, and this file makes no claim that the code is anonymous: it is an organisation identifier that resolves to an organisation name through the public ODS API documented below. What this file is, therefore, is a code-level extract of an already-public register. No finding in the accompanying study is attached to any individual code, no named organisation is described as insecure or non-compliant anywhere, and this file must not be republished as a named list of organisations without a current assessment. SNAPSHOT: 2026-09-25, register export retrieved 2026-09-25T09:06:54Z. The register refreshes continuously, and the toolkit's help says the organisation search is updated every 10 minutes. A second complete pull 10 minutes after the first (2026-09-25T09:17:23Z) returned the same 93,260 organisation codes, with 1 row's status changed and 2 rows' publication dates changed, and none added or removed. Status and Date Of Publication were the fields compared. That window is too short to say how much the register moves over a day; it shows only that no bulk republication happened during collection. Every figure is dated; a later read will differ, and the source file's hash will not match. ROWS: 93,260 COLUMNS: 21 SHA256 of this CSV: 5284c1b02cac4121e7472e0dae6e7f904fd065b23f0ecf87b06750799bdaddae HEADLINE FIGURES, WITH THEIR DENOMINATORS * 21.93% — of the registered entries whose ODS code is still marked Active in NHS ODS have no assessment from the 2025-26 cycle or later. n = 17,477. Denominator: the 79,678 registered entries whose ODS code is still marked Active in the NHS Organisation Data Service, 2026-09-25. * 31.94% — of the whole register has no assessment from the 2025-26 cycle or later. n = 29,791. Denominator: all 93,260 registered entries on the DSP Toolkit register, 2026-09-25. * 5,436 — have registered and never published an assessment at all. n = 5,436. Denominator: all 93,260 registered entries on the DSP Toolkit register, 2026-09-25. * 45.61% — of the registered entries with a lapsed assessment are marked Inactive in NHS ODS. n = 11,007. Denominator: the 24,132 of 24,355 entries in this bucket whose code resolves in NHS ODS. * 787 — registered entries carry the supplier label or its immediate predecessor — and the register still cannot measure supplier compliance. n = 787. Denominator: the 87,824 registered entries that have published at least once. * 13.17% to 27.09% — spread across the Integrated Care Boards recorded on the register, in the share with no current assessment. n = 36. Denominator: the 67,919 registered entries with an Integrated Care Board recorded, across 36 named boards. COLUMNS code: The organisation's ODS code, as published on the register. This is the register's own public identifier and the join key to the NHS Organisation Data Service. Organisation NAME is deliberately not included. status_raw: The Status string exactly as the register publishes it, e.g. '2025-26 (version 8) - Standards met', or the literal 'Not Published'. Cycle and outcome are encoded together in this one field. published: 1 if an assessment has ever been published, 0 if the status is 'Not Published'. cycle_label: The cycle of the most recent published assessment, e.g. '2025-26'. Empty when nothing has been published. cycle_start_year: The first year of that cycle, as an integer. Empty when nothing has been published. version: The toolkit version of that cycle, 1 to 9. Empty when nothing has been published. outcome: The outcome of the most recent published assessment: Standards met, Standards exceeded, Approaching standards, Standards not met, or Entry level. 'Entry level' occurs only in the earliest cycles. Empty when nothing has been published. publication_date: ISO date of the most recent published assessment. The source publishes this in British long form ('23 June 2026'); it is normalised here. Empty when nothing has been published. currency: One of: current (published in the 2025-26 version 8 cycle or later), lapsed (published at some point, but before that), never published. has_current_assessment: 1 if currency is 'current', else 0. This is the column every headline is computed from. primary_sector_raw: The Primary Sector exactly as the register publishes it. NOTE: this is frozen at the cycle in which the organisation last published, so retired labels persist. 'No Sector Identified' appears on, and only on, rows that have never published. primary_sector_pooled: The present-day sector label, after retired labels have been pooled into their equivalent. Empty for rows that have never published, because those carry no sector at all. sector_pooling_basis: How primary_sector_pooled was arrived at: 'current_label' (the raw label is already the present-day one); 'nhs_england_published_mapping' (NHS England publishes this mapping in its organisation-types guidance); 'inferred_renaming' (our inference from the label wording and the version range it occupies); 'not_assignable' (never published, no sector). sector_label_is_retired: 1 if primary_sector_raw is a label the register no longer offers, 0 if it is a present-day label, empty if the row has no sector. icb: Integrated Care Board, exactly as the register publishes it. The source column is headed 'Integrated Care Board (where available, from ODS)': it comes from the NHS Organisation Data Service at export time, not from the organisation's assessment, which is why it is present on rows that have never published. Empty where ODS has none. NOTE some ICB names contain commas, so parse this file as CSV rather than splitting on commas. icb_present: 1 if icb is non-empty, else 0. ods_matched: 1 if the code resolves to a record in the NHS Organisation Data Service, else 0. ods_status: 'Active' or 'Inactive' from ODS. Empty when the code does not resolve. An Inactive record usually means the organisation has closed, merged or been dissolved. ods_primary_role_id: ODS primary role code, e.g. RO157. Empty when the code does not resolve. ods_primary_role_description: ODS primary role description, e.g. NON-NHS ORGANISATION. Empty when the code does not resolve. snapshot_date: Always 2026-09-25. The register is live and a later read will differ. METHOD The register's own CSV export was taken once with a single anonymous GET, and stored with its hash, its response headers, the site's robots.txt and the verbatim terms page beside it. No authenticated access was attempted at any point, and no search form was submitted. The export was parsed with its quirks handled explicitly: a UTF-8 byte-order mark, and exactly one leading space padding every field including every header. The parser asserts the header is unchanged and stops rather than guessing if it is not. The Status field encodes cycle and outcome in one string. All of its distinct values were enumerated from the data rather than assumed, and each was split into cycle, version and outcome. A parser that assumed the obvious four outcomes would have silently mis-bucketed 'Entry level', which exists only in the earliest cycles. Publication dates arrive in British long form and were normalised to ISO. No future dates exist in the data. Every row was joined to the NHS Organisation Data Service on the organisation code, to establish whether the organisation is still marked Active. ODS postcode was deliberately not read. Retired sector labels were pooled into their present-day equivalent before any sector figure was computed, because a sector label is frozen at the cycle in which an organisation last published and a retired label is therefore lapsed by construction. Five of the mappings are NHS England's own published mapping; the rest are our inference and are flagged as such on every row of the dataset. Both pooled and unpooled counts are published. Sector figures are computed only among entries that have published at least once, because the register reveals no sector until an assessment is published. The whole export was pulled a second time and compared row by row to measure how fast the register moves. This analysis makes no network request. It runs entirely against the stored snapshot and can be rerun by anyone who has it. DEFINITIONS current: an assessment published in the 2025-26 (version 8) cycle or later. 2025-26 is the most recently CLOSED cycle and its 30 June 2026 deadline has passed. The 2026-27 (version 9) cycle opened in late August 2026, a month before this snapshot, and 1,350 entries have already filed under it; requiring version 9 would be an unfair test. This threshold is the most consequential judgement in the study. lapsed: published at least once, but the most recent assessment predates 2025-26. never published: status 'Not Published', no publication date, and no sector. no current assessment: lapsed plus never published. THREE THINGS THIS DATA CANNOT DO 1. It cannot give a never-published figure for any sector. The register reveals a sector only once an assessment is published: all 5,436 rows with status 'Not Published' carry 'No Sector Identified', and all 5,436 rows carrying 'No Sector Identified' have status 'Not Published'. The two sets are identical. 2. It cannot support an unpooled sector comparison. A sector label is frozen at the cycle in which the organisation last published, so 19 retired labels have no current assessments at all, by construction. Retired labels must be pooled into their present-day equivalent before any sector rate is computed. The pooling is published in the sector_pooling_basis column: five mappings are NHS England's own and the rest are our inference, flagged as such. Sector figures are computed only among entries that have published at least once (n = 87,824). 3. It cannot measure supplier compliance. The supplier label has been rewritten twice and the three versions occupy non-overlapping cycles; NHS England's 2024-25 organisation-types guidance reserves the label in force for versions 6 to 8, 'IT Supplier', for firms with 50 or more staff and £10m or more turnover and tells everyone smaller to register as 'Other', a bucket of 12,041 entries shared with charities and hospices; no published source defines the version 9 label 'Supplier', so carrying that threshold across to it is our inference; and NHS ODS has no IT- supplier role to fall back on. TWO THINGS WE COULD NOT EXPLAIN * 87.80% of the 1,131 entries labelled 'OES Independent Provider' have no assessment from 2025-26 or later — far more than any other present-day sector label. It is not an artefact of a retired label: the label is still offered by the register's own search filter and none of its rows came in from pooling. Not established: Why. No published source collected for this study explains it. Two possibilities the data is consistent with, neither of which we can confirm: the label may have been superseded for the 2025-26 cycle, in which case these organisations have filed under another label and the figure is a vocabulary artefact like the retired ones; or a headquarters assessment may cover these entries, most of which carry an ODS role ending in SITE rather than an organisation-level role. * 63.04% of the 25,341 entries with no Integrated Care Board recorded have no current assessment, against 13.17% to 27.09% across the named boards. Most of that gap is closure, not geography: 12,906 of the 12,913 entries marked Inactive in NHS ODS have no board recorded. Restricted to entries still Active on both sides it roughly halves, to 31.12% (3,662 of 11,766) against 20.34% (13,815 of 67,912), with the named boards running 13.18% to 27.10%. What remains after that correction is still the largest divergence in the study, and it is the corrected figure that is reported as one. Not established: Whether the missing board is a cause or a symptom, and what explains the gap that survives the ODS-Active correction. ICB is supplied from ODS 'where available', and an organisation that has closed, or that never had an English commissioning geography, will lack one. The direction is not established. LICENCE AND ATTRIBUTION SOURCE REGISTER: Crown copyright with a free-reproduction permission. This is NOT the Open Government Licence, and must never be cited as OGL or as OGL v3.0. The toolkit's terms and conditions page states, verbatim: "The material on this website is protected by Crown copyright unless otherwise indicated. Crown copyright protected material may be reproduced free of charge in any format or medium, provided it is reproduced accurately and not used in a misleading context." and adds, verbatim: "If Crown copyrighted or third-party material from the Data Security and Protection Toolkit is used the source of the material must be identified and, where appropriate, the copyright status acknowledged." Source: https://www.dsptoolkit.nhs.uk/Home/TermsAndConditions Required attribution for the register data: Contains material from the NHS Data Security and Protection Toolkit, Crown copyright, reproduced free of charge under the terms published at https://www.dsptoolkit.nhs.uk/Home/TermsAndConditions. SECOND SOURCE: the activity and role columns come from the NHS Organisation Data Service. NHS England states that ODS data is published under the Open Government Licence and asserts no version number, so no version is cited here. NHS England's terms publish two attribution statements and make the choice turn on what was done with the content. This dataset joins ODS records to the register row by row and re-expresses them as derived columns, so the content is combined and adapted and the required statement is: "Contains information from NHS England, licenced under the current version of the Open Government Licence". A reuser republishing the ODS data unmodified carries the other form instead: "Information from NHS England, licenced under the current version of the Open Government Licence". THIRD-PARTY MATERIALS: the toolkit's terms carry a third clause alongside the two above. It states, verbatim: "The help articles on this website may contain third party materials which have been generously donated by NHS and Social Care organisations. These materials may not be used (i.e. copied, adapted, reproduced, republished, downloaded, posted, broadcast or transmitted) in any way except for your own personal use or your organisation’s non-commercial use." It was read and does not bite here: the four passages this study quotes from help articles are NHS England's own operational guidance on registration, the deadline, the contractual hook and the organisation-type mapping, each short, quoted and attributed. No donated third-party material is reproduced. DERIVED WORK: Servnet's own analysis, the pooling map and the derived columns are offered under the Creative Commons Attribution 4.0 International licence (https://creativecommons.org/licenses/by/4.0/). Attribution: Servnet, nhs-dsp-toolkit-supplier- compliance-2026, https://www.servnetuk.com/research/nhs-dsp-toolkit-supplier-compliance-2026. That grant does not and cannot reach the whole file. It covers the columns that are Servnet's own work — currency, has_current_assessment, primary_sector_pooled, sector_pooling_basis, sector_label_is_retired, icb_present, ods_matched — and the tables and charts built from them. The reproduced register fields (code, status_raw, published, cycle_label, cycle_start_year, version, outcome, publication_date, primary_sector_raw, icb) stay Crown copyright under the free-reproduction permission, which Servnet cannot sub-license, and the ODS fields (ods_status, ods_primary_role_id, ods_primary_role_description) stay Open Government Licence material. Two licences apply to this file and they are not interchangeable. Reproducing the register columns requires the Crown copyright acknowledgement above; reusing Servnet's derived columns requires the CC BY attribution. PERSONAL DATA No organisation name from the register, no email address and no postcode appears in the data below, and the only organisation names anywhere in it are Integrated Care Board names in the icb column. Organisation names were read only to check the field count and were discarded before anything was written; ODS postcodes were deliberately never read; no individual is named anywhere in this dataset or in the study. The organisation code is retained and is not anonymous: it resolves to an organisation name through the public ODS API, and for the sole- trader entries on the source register that organisation name is a person's name. That is the reason names are dropped here, and the reason this file must not be republished as a named non- compliance list. REPRODUCING python3 scripts/research/nhs-dsp-toolkit-supplier-compliance-2026/analyse.py — makes no network request, reads only the stored snapshot in data/research/nhs-dsp-toolkit-supplier- compliance-2026/, and rewrites this file, the CSV and lib/research/nhs-dsp-toolkit-supplier- compliance-2026.json. The source export's sha256 is d87a279bc9f7a6d1fc508708097cb02abf2f064ae62afa0992ea14c1fb0ee5ec. A fresh download will not match, because the register is live. CORRECTIONS https://www.servnetuk.com/research/corrections or webmaster@servnetuk.com. If any figure here is wrong, it will be corrected on the page with a dated note saying what changed.