The quiet reception area of a small UK GP surgery in early morning light, a switched-off desktop monitor on the front desk, a patient appointment card rack and a wall noticeboard with pinned notices n

Choosing Endpoint Protection for a Small UK GP or Dental Practice Ahead of the DSPT Deadline

12 min read

Small UK GP and dental practices must publish a DSPT self-assessment every 30 June or risk losing NHS Mail and e-Referral access. ESET, Bitdefender and Sophos differ sharply on whether MFA is enforced by default on their admin consoles, which is the practical factor that should drive the choice.

Daniel Thomas
Written by Daniel Thomas

Every organisation with access to NHS patient data must publish a Data Security and Protection Toolkit (DSPT) self-assessment by 30 June each year, and losing that status can mean losing NHSmail and e-Referral Service access. ESET, Bitdefender and Sophos all cover the practical endpoint requirement, but they differ on how strictly multi-factor authentication (MFA) is enforced by default and on how directly a small practice can buy them. A small practice with 10 to 30 devices and no dedicated IT team should weigh MFA defaults and buying route first, not marketing claims about detection rates.

Key pointers

  • The DSPT deadline is fixed at 30 June every year; the active 2026/27 cycle is version 9, aligned to the government's Cyber Assessment Framework 4.0, with a deadline of 30 June 2027.
  • Missing the deadline risks NHS Mail suspension and the loss of e-Referral Service access, forcing a return to paper-based referrals.
  • Bitdefender GravityZone turns on console MFA by default and will not let a user skip setup past five logins; Sophos Central requires TOTP or a passkey for every admin and has deprecated SMS and email-plus-PIN as MFA methods.
  • ESET's console MFA, via the ESET Business Account portal, is available free at every tier but is opt-in, not on by default; an admin has to switch it on.
  • ESET also sells a separate, dedicated MFA module for staff logging into VPNs, Windows machines and other network resources; it is bundled free only from ESET PROTECT Elite upward, and Elite is quote-only rather than instant checkout.
  • ESET and Bitdefender both run live, configurable online price calculators by device count and term; Sophos does not publish pricing and sells only through resellers and managed service providers.
  • Confirmed live on ESET's own checkout: £562.00 excluding VAT for its Entry tier, 20 devices, 1 year, rising to £900.00 for the same 20 devices on Complete.
  • Achieving "Standards Met" plus a current Cyber Essentials Plus certificate lifts a practice's DSPT status to "Standards Exceeded".
How Endpoint Protection Feeds a DSPT Submission
MFA, asset records and staff training all feed one annual submission that keeps NHS system access live.

What the DSPT Deadline Means for a Small Practice

The DSPT replaced the old Information Governance Toolkit and now runs every year: a practice with access to NHS patient information, NHS systems or NHS infrastructure must publish at least one assessment before 30 June, or risk losing the digital tools it relies on daily. NHS England treats it as a self-assessment against the National Data Guardian's ten data security standards, and completing it is a contractual requirement under the NHS Standard Contract, not a voluntary extra.

The active cycle, 2026/27, is version 9 of the toolkit, aligned to the government's Cyber Assessment Framework 4.0, with a submission deadline of 30 June 2027; the previous 2025/26 (v8) cycle has already closed. Smaller organisation types, including dentists and opticians, answer a shorter set of mandatory questions than an NHS Trust does, but the same annual clock applies. A GP surgery, dental practice, pharmacy or care home only needs one published assessment a year to stay compliant; endpoint protection sits inside that assessment as evidence for the standards covering access control, incident response and technical vulnerability management, not as a separate submission.

Because NHS Digital treats it as an operational gate, not a paperwork exercise, a lapsed DSPT status can trigger suspension of NHS Mail and a loss of e-Referral Service access, pushing referrals back onto paper. ICBs are expected to monitor DSPT compliance among the practices in their area and can escalate persistent gaps to NHS England, so this is not a risk that stays hidden until an inspection.

MFA Is the Real Differentiator Between These Three

A practice manager comparing ESET, Bitdefender and Sophos on antivirus detection rates alone is looking at the wrong criterion. Detection engines across all three are broadly comparable at the level a small practice needs. What varies sharply, and what actually matters for the Cyber Essentials requirement that every in-scope cloud service use MFA, is whether the security vendor's own management console enforces it or leaves it to the practice to remember.

Bitdefender's GravityZone Control Center turns on two-factor authentication by default the moment a company account is created, and the setting cannot be switched off centrally. A user can skip the setup prompt at login, but only five times; on the sixth attempt they are locked out until they configure an authenticator app. Sophos goes further still: every admin must authenticate with a username and password plus a second factor, and Sophos has now deprecated SMS and email-plus-PIN as that second factor, so new admins must set up either a TOTP authenticator app or a passkey. Sophos Central locks an account out after five consecutive incorrect sign-in attempts, starting at one minute and escalating to a maximum of five hours.

ESET's console is different in one respect: it is opt-in rather than on by default. Two-factor authentication is available at no extra cost at every tier through the ESET Business Account portal, the account layer used to reach the management console. An administrator can require it for the whole company from Settings, or enable it per user, using the ESET Secure Authentication mobile app or a third-party TOTP app; once switched on, anyone who has not completed setup is locked out on their next login. The point is that nothing enforces this for a practice by default, unlike Bitdefender and Sophos, so it depends on someone remembering to turn it on.

Separately from console access, ESET also sells a dedicated MFA product for securing staff logins to VPNs, Windows machines and other network resources, the kind of access DSPT's guidance on NHS-system remote access is really about. This module is bundled free only from ESET PROTECT Elite upward; the lower Entry, Advanced and Complete tiers, which cover the endpoint, server and encryption needs of most small practices, do not include it and would need it bought as an add-on. Elite itself has no instant online price on its page; the only route shown is "Request customised offer", so getting this module bundled with ESET means starting a quote conversation rather than checking out immediately.

Pricing and Cost Model

ESET publishes a live UK checkout price directly on its own site, in GBP and marked "excl. VAT", for between 5 and 99 devices and a choice of one, two or three year terms. Checked live on 29 September 2026, ESET PROTECT Entry (console, endpoint and server protection only) costs £562.00 for 20 devices on a 1 year term; the same 20 devices cost £732.00 on Advanced (adds mobile, cloud workload and disk encryption cover) and £900.00 on Complete (adds mail, cloud app and patch management cover). That works out at roughly £28, £37 and £45 per device per year respectively, excluding VAT, at this device count. Elite, the tier that adds the end-user MFA module, drops out of the instant checkout and moves to "Request customised offer", so a practice wanting that module bundled with ESET needs a quote rather than a card payment.

Bitdefender's GravityZone Business Security page runs a similar instant, configurable price calculator, letting a buyer pick a device count and term online with a "Taxes not included" label, so it is not a quote-only product either; a practice needing more endpoints than the online tier covers is directed to a partner. Sophos frames its whole buying process around resellers and managed service providers rather than a direct vendor checkout, so a Sophos quote will normally come from a partner rather than sophos.com. Whichever vendor a practice leans toward, treat any total figure as provisional until it is broken into the components below.

Cost componentWhat to confirm before signing
Per-device or per-user feeWhich tier the price covers (entry-level endpoint only, or a bundle including server and mobile cover), and whether it is billed per device or per user
MFAWhether console MFA is on by default (Bitdefender, Sophos) or has to be switched on (ESET, free at every tier); separately, whether the dedicated end-user MFA module is included, which for ESET means Elite or above
Full disk encryptionWhether it ships in the base tier or needs an add-on (Bitdefender's Full Disk Encryption and ESET's Entry tier are both separate from their entry-level cover)
Server and mobile coverWhether clinical servers, Windows and Linux machines, and staff mobile devices are all covered or licensed separately
Minimum term and device countThe contract length (commonly one or three years) and any minimum seat count for online purchase
Deployment and onboardingWhether initial setup, migration from an existing product, and staff training are included or chargeable
Renewal upliftWhether the renewal price is fixed for the term or subject to increase, and how much notice is given
VATWhether the quoted figure includes UK VAT at the standard rate; most practice non-clinical software purchases are VAT-able even though NHS-funded clinical services are usually exempt

Rollout Checklist for a Small Practice

  1. Confirm the exact device count and operating system mix, including any Windows or Linux clinical servers, before requesting quotes.
  2. Ask each vendor or reseller in writing whether console MFA is on by default and whether an end-user MFA module is included at the tier being quoted, using the differences above as a checklist.
  3. Back up clinical and practice-management data, and confirm the backup actually restores, before installing any new endpoint agent.
  4. Pilot the chosen product on two or three non-clinical machines first and watch for conflicts with clinical systems such as EMIS or SystmOne before a wider rollout.
  5. Schedule the main rollout outside clinic hours, with a documented rollback step, in case an agent update disrupts a clinical workstation.
  6. Update the practice's information asset register to include the new endpoint product once installed.
  7. Confirm staff know what a genuine security alert looks like, and who to call, rather than clicking through an unfamiliar pop-up.
  8. Record the installation and configuration evidence in the practice's DSPT evidence folder well ahead of the 30 June submission, not on the day itself.

Vendor and Option Comparison

CriteriaESET PROTECTBitdefender GravityZone Business SecuritySophos Endpoint (Central)
Console MFAFree at every tier via ESET Business Account, but opt-in; an admin must switch it onEnabled by default on account creation; cannot be permanently skippedMandatory from first admin sign-in; cannot be bypassed
End-user MFA moduleBundled free only from Elite up (quote-only); a paid add-on at Entry, Advanced and CompleteNot separately confirmed on the pages checked for this articleNot separately confirmed on the pages checked for this article
Full disk encryptionIncluded from the Advanced tier upSold as a separate add-on to Business SecurityNot confirmed as bundled in the base Endpoint agent; check the quote
Ransomware-specific controlsAdvanced Threat Defence at Advanced tier and aboveMultilayered machine learning and behavioural analysis in Business SecurityCryptoGuard file-encryption monitoring with automatic rollback, built into the base agent
Server and mobile coverageWindows, macOS, Linux endpoints; Windows Server, Linux and Azure server security; iOS/Android MDM, all tier-dependentDesktops, laptops, physical and virtual servers in the base tier; mobile via a separate add-onEndpoint and server agents; workspace protection extends to apps and remote workers
Published UK pricingEntry, Advanced and Complete price instantly online in GBP, excl. VAT, for 5 to 99 devices; Elite is quote-onlyInstant online price calculator confirmed on the product page; exact figures load via the page's own scriptsNo list price on sophos.com; sold through a reseller or managed service provider
UK support footprintESET reports 70,000+ UK business customersNot separately published for the UKNot separately published for the UK

None of the three is a bad technical choice for a small practice on detection alone. On console MFA, Bitdefender and Sophos give the practice one less thing to remember, since both enforce it without a configuration step; ESET matches them in capability but leaves the switch to the admin. On the dedicated end-user MFA module that protects VPN and Windows logins, ESET's position depends entirely on which tier is quoted: it is a free extra at Elite, or a separate purchase below it. A practice already committed to a particular reseller or MSP for its wider IT support will often find that relationship, rather than the vendor brochure, decides which of the three ends up cheapest and easiest to run.

Editorial Analysis

For a practice with no dedicated IT team, the safer default on console access is whichever product enforces MFA without requiring a configuration step: Sophos, then Bitdefender. ESET's console MFA is equally capable once turned on, but it depends on an admin remembering to enable it in Settings, which is exactly the kind of gap a rushed DSPT submission can miss. On the separate question of end-user MFA for VPN and Windows logins, a practice already being quoted for ESET PROTECT Elite gets that module bundled; one quoted for Entry, Advanced or Complete would need to add it, or look at what Bitdefender and Sophos offer for the same purpose before deciding. This is our reasoning, not a ranking based on independent lab testing; a practice with in-house IT confident in remembering to enable ESET's console MFA, or one already quoted for Elite, may reasonably prefer ESET for other reasons, including its large UK reseller base and its published, instantly checked-out pricing at the lower tiers. Whichever product is chosen, the MFA settings and encryption cover described above should be checked and evidenced before the 30 June submission, not assumed to be covered by default.

Sources

Data & Insights

ESET's reported business customer base

ESET's own UK business page reports a UK customer count well below its worldwide total, indicating most of its 500,000+ business customers are outside the UK.

ESET's reported business customer baseESET's own UK business page reports a UK customer count well below its worldwide total, indicating most of its 500,000+ business customers are outside the UK.0100,000200,000300,000400,000500,000UK business customersUK business cus…Worldwide business customersWorldwide busin…UK business customers, Business customers: 70,000Worldwide business customers, Business customers: 500,000
View the data
ESET's reported business customer base
CategoryBusiness customers
UK business customers70,000
Worldwide business customers500,000
Source: ESET UK business page

Frequently Asked Questions

Does completing the DSPT mean an outside auditor checks our practice?

No, by default. The DSPT is a self-assessment: your practice records its own evidence against the National Data Guardian's ten standards and submits it. An independent element only enters if you separately pursue Cyber Essentials Plus certification, which does involve an external assessor and, if current, lifts your recorded DSPT status to "Standards Exceeded".

Do we have to pick exactly one of ESET, Bitdefender or Sophos to pass the DSPT?

No. The DSPT does not name specific products; it asks whether your practice has effective technical controls in place, including malware protection and access management. These three are simply well-established, UK-serving options a small practice is likely to be quoted; any product that genuinely delivers the underlying controls, correctly configured, can support your evidence.

Which of the three enforces MFA on its console without us having to configure it?

Bitdefender GravityZone enables two-factor authentication by default when an account is created, and Sophos Central makes MFA mandatory from an admin's first sign-in; neither can be permanently switched off. ESET's console MFA is free at every tier too, but it is opt-in: an admin has to turn it on in Settings before it applies. Separately, ESET's dedicated MFA module for staff VPN and Windows logins is bundled free only from its Elite tier upward.

Can we buy directly from the vendor, or do we need a reseller?

ESET and Bitdefender both run instant online price calculators for smaller device counts, checking out directly in GBP without a quote; ESET's covers Entry, Advanced and Complete for 5 to 99 devices, though its Elite tier (with the bundled end-user MFA module) is quote-only. Bitdefender's calculator is on the same product page but does not show a fixed number until you configure it. Sophos routes purchases through resellers and managed service providers rather than a direct vendor checkout.

Will achieving Cyber Essentials Plus help our DSPT submission?

Yes. If your practice has "Standards Met" on the DSPT and a current Cyber Essentials Plus certificate covering your health and care data processing, recording that certificate in your DSPT Organisation Profile lifts your displayed status to "Standards Exceeded". From 27 April 2026, Cyber Essentials also makes MFA mandatory on every in-scope cloud service, reinforcing the same console-MFA question that separates these three vendors.

What actually happens if we miss the 30 June deadline?

A lapsed DSPT status can trigger suspension of NHS Mail and loss of access to the e-Referral Service, forcing a return to paper-based referrals, and your Integrated Care Board is expected to monitor and can escalate persistent non-compliance to NHS England. There is no grace period built into the toolkit itself, so start the review well before June rather than in the final week.