DSPT 2025/26 is in. Your evidence is at its freshest right now. Never do June again →

Who we serve

What a community pharmacy needs to do to be compliant

Publish the DSPT by 30 June every year, hold GPhC premises registration, meet the CPCF's clinical governance requirements, keep NHSmail active and pay the annual ICO fee. Online pharmacies follow the GPhC distance-selling guidance on top. CQC only enters when regulated activities leave the premises.

Reviewed 5 July 2026 · Neil Chandarana, founder, Highguard

The requirements

Every requirement for a community pharmacy, in plain English.

DSPT, Category 3, every year

  • Required by the NHS Terms of Service
  • Publish annually by 30 June
  • Category 3 question set

The DSPT is required under the NHS Terms of Service, so it sits inside your NHS contract rather than beside it. Pharmacies complete the Category 3 question set. The current toolkit is aligned to the Cyber Assessment Framework and asks directly about multi-factor authentication on clinical systems, so weak sign-in on your PMR is now a toolkit answer, not a private choice. Recent editions pre-fill your previous answers, which speeds things up, provided last year's answers were right. The new edition opens each autumn and your publication status is publicly visible.

Sources: Community Pharmacy England · DSPT Toolkit

GPhC premises registration

  • Enforced by the GPhC
  • Renewed annually
  • Distance-selling guidance applies online

Every registered pharmacy renews its premises registration with the General Pharmaceutical Council each year and must meet the GPhC standards for registered pharmacies. Pharmacies selling medicines online also follow the GPhC guidance for registered pharmacies providing services at a distance, updated in February 2025. The old internet-pharmacy logo scheme was discontinued in June 2025, so the distance-selling guidance is now the standard an online pharmacy is held to.

Sources: GPhC · GPhC distance-selling guidance

NHSmail

  • Mandatory for NHS community pharmacy
  • Shared mailbox per premises
  • DSPT Standards Met is a prerequisite

NHSmail is the mandatory secure email route for NHS community pharmacy, with a shared mailbox required per premises. Keeping it depends on your DSPT: Standards Met is a prerequisite, which is one of the quiet ways a lapsed toolkit turns into an operational problem. Multi-factor authentication is now mandatory on NHSmail accounts.

Sources: Community Pharmacy England · NHSmail support

CPCF clinical governance

  • Part of your NHS contract
  • Covers IG, audit and incident reporting
  • Ongoing, not annual

The Community Pharmacy Contractual Framework carries its own clinical governance requirements under the NHS regulations: information governance arrangements, clinical audit and incident reporting among them. These are contractual obligations, checked through contract monitoring rather than a separate certificate, and they apply continuously rather than at a renewal date.

Sources: Community Pharmacy England

Pharmacy Quality Scheme

  • Declaration window announced each year
  • DSPT is a gateway requirement

PQS is optional, but if you claim it the declaration has hard gateways and a current DSPT is one of them. The 2025-26 declaration window ran from 2 to 27 February 2026, and the window is announced fresh each year. Miss the toolkit and the scheme payment goes with it.

Sources: Community Pharmacy England

ICO fee, and CQC in specific cases

  • ICO fee renews annually
  • CQC only for regulated activities off premises

Every pharmacy processing personal data pays the ICO data protection fee annually, with the tier set by size. CQC registration is not needed for standard pharmacy services, but it becomes relevant when you deliver regulated activities outside your registered premises. Online prescribing services run only by pharmacists currently sit in an acknowledged gap between the two regulators, one the GPhC has said it wants closed, so expect that boundary to move.

Sources: ICO · The Pharmaceutical Journal

How it grows

Pharmacy compliance as you grow.

Stage 1

Single premises

One DSPT publication, GPhC registration, CPCF governance, NHSmail and the ICO fee. The full list, but at single-site scale.

Stage 2

Multi-site group

A Pharmacy HQ ODS code lets a head office publish the DSPT for the whole group in one go. Governance has to hold across every branch, not just the first one.

Stage 3

Clinical services beyond the premises

Deliver regulated activities outside registered premises and you enter CQC territory: registration, Regulation 17 governance and inspection.

Common questions

Pharmacy compliance, asked and answered.

When is the pharmacy DSPT deadline?

30 June each year. The 2025-26 deadline was 30 June 2026, and the next publication is due by 30 June 2027. The new toolkit edition usually opens in the autumn.

Is the DSPT mandatory for community pharmacies?

Yes. It is required under the NHS Terms of Service, and Standards Met is also a prerequisite for keeping NHSmail and for Pharmacy Quality Scheme declarations.

What DSPT category is a pharmacy?

Community pharmacies complete the Category 3 question set. Multi-site groups with a Pharmacy HQ ODS code can publish once at group level.

Do online pharmacies have extra requirements?

Yes. Distance-selling pharmacies follow specific GPhC guidance for providing services at a distance, updated in February 2025, on top of everything a bricks-and-mortar pharmacy does.

Does a pharmacy need CQC registration?

Usually not. CQC registration applies when regulated activities are carried out away from registered pharmacy premises, such as clinics delivered off site.

Highguard

Why this list keeps getting longer.

Somewhere along the way, compliance stopped being about security and became about admin. Portals, spreadsheets, evidence uploaded again and again, policy templates nobody reads.

The result is organisations that are certified but not secure. Teams that are busy but not protected.

It should not work like this. Compliance should be a side effect of good practice. Evidence of the work you already do, not a second job on top of it.

That is why Highguard exists. We are your compliance department. Specialists and AI agents do the work on this page, and you approve every word before anything is submitted.

Every engagement starts with an audit. In your first week you get a report of where you are compliant and where you are exposed, specific to your organisation.

Talk to us →
Get started

Talk to us.

Book a 15-minute call. We'll show you where you stand and how fast we can get you certified.