Care Circle Network | The Digital Assurance Divide: Why Provider Scale Is Becoming a Governance Issue

Care Circle Network Intelligence Insight

New Care Circle Network analysis reveals a striking relationship between provider scale and current digital assurance. Among active care locations with an exact DSPT match, 69.5% of locations operated by single-location providers currently show 2025/26 Standards Met or Standards Exceeded. For the largest provider groups, that figure rises to 98.2%.

Adult social care has spent several years talking about digital adoption.

Electronic care records. Digital medicines management. Rostering. Remote monitoring. NHS integration. Cyber security. Connectivity. AI.

But as more of care becomes dependent upon technology, another question is becoming increasingly important:

Who has the organisational capacity to govern it properly?

Analysis from the Care Circle Network Provider Intelligence Observatory suggests provider scale is becoming a significant dividing line.

Not necessarily because larger providers care more about information governance.

Not because smaller providers are inherently less secure.

And certainly not because a published assurance status proves that an organisation is cyber resilient.

The difference appears more structural.

Larger organisations are more likely to possess something that can be extremely difficult for smaller care businesses to manufacture:

dedicated capacity.

People with responsibility for information governance.

Central IT oversight.

Formal procurement processes.

Asset registers.

Training systems.

Policy ownership.

Supplier scrutiny.

Business-continuity planning.

Internal auditing.

Board-level accountability.

The smaller the organisation becomes, the greater the likelihood that many of those responsibilities eventually arrive on the desk of the same person who is already managing staffing, safeguarding, recruitment, quality, families, commissioners and the delivery of care.

And our intelligence suggests that difference is becoming visible.


A 28.7 percentage-point assurance gap

For this analysis, Care Circle Network examined 25,093 active adult social care locations where the Provider Intelligence Observatory has an exact CQC ODS-code match to a Data Security and Protection Toolkit record.

We then looked specifically for a current 2025/26 Standards Met or Standards Exceeded status.

The relationship with provider scale is remarkably consistent.

Care Circle Network Intelligence Insight

Among exactly matched active locations:

Single-location providers — 69.5%

Small groups operating 2–4 locations — 80.1%

Groups operating 5–9 locations — 87.1%

Groups operating 10–24 locations — 91.0%

Groups operating 25+ locations — 98.2%

From the smallest providers to the largest groups, that represents a 28.7 percentage-point difference.

And it does not appear as a random jump between two categories.

The percentage rises at every step as provider scale increases.

That is what makes the finding important.


First, an important distinction: DSPT is not a cyber-security certificate

The Data Security and Protection Toolkit is an online self-assessment mechanism through which organisations can measure their performance against the National Data Guardian’s ten data-security standards.

For adult social care providers completing the 2025/26 version, reaching Standards Met requires responses to mandatory requirements covering areas including staffing and responsibilities, policies and procedures, data security, and IT systems and devices. The latest version requires providers to address 45 mandatory questions.

But that distinction matters:

Standards Met does not mean “cyber secure”.

It should not be read as proof that an organisation could withstand every attack, that every control has been independently tested, or that every supplier in its digital environment is secure.

Government-commissioned research into cyber security in adult social care made precisely this point. Participants regarded the DSPT as useful in raising awareness and encouraging basic controls, but did not regard DSPT compliance alone as an accurate measurement of cyber resilience.

That makes the Care Circle finding more interesting, not less.

Because this article is not really about cyber security.

It is about organisational governance.


Look at what sits underneath digital assurance

Strip away the acronym and consider what an organisation actually has to understand in order to maintain good digital assurance.

Who is accountable for information?

What systems does the organisation operate?

What hardware does it own?

What software does it use?

Who has administrator privileges?

Who can access sensitive information?

Are staff appropriately trained?

Are policies current?

Are systems backed up?

What happens if a supplier fails?

Can the organisation continue delivering safe care if its systems become unavailable?

Who responds to a data incident?

How are former employees’ accounts removed?

How are devices managed?

How does the organisation know whether its suppliers are protecting information appropriately?

For 2025/26, two additional mandatory DSPT requirements included formal accountability for IT system administrators and maintaining an up-to-date asset register of hardware, software and data.

Those are technology questions.

But they are also management questions.

And that distinction is becoming increasingly important.


Digital transformation creates governance work

Every new piece of technology introduced into a care organisation creates something beyond the functionality it provides.

It creates a responsibility.

A digital care-record system has to be administered.

A medicines system requires controlled access.

Mobile devices have to be managed.

Software has to be updated.

User permissions have to be reviewed.

Information has to be protected.

Suppliers have to be understood.

Back-ups have to work.

Staff have to know what to do.

Incidents need a response.

Continuity plans need to account for technology failure.

Contracts need scrutiny.

Data has to move safely between organisations.

The technology may simplify care delivery.

It does not necessarily simplify governance.

In many cases, it creates additional governance requirements around the service.

That is where provider scale starts to matter.


The single-site provider problem

The Care Circle Network Provider Intelligence Observatory identifies 17,407 active provider organisations across the current adult social care population.

Within the Observatory’s provider-scale classification, 14,265 — approximately 82% — are independent or single-location providers.

That is important context.

Adult social care is not predominantly a market of large national organisations with central technology departments and information-security teams.

It contains thousands of small businesses.

For a large provider, the responsibility for digital assurance can potentially be distributed.

There may be an IT director.

An information-governance lead.

A data-protection officer.

A procurement team.

A learning and development function.

A quality team.

Regional operations.

External cyber specialists.

Formal governance committees.

A single-site provider may still have access to some of those capabilities externally.

But internally, the organisational reality can be radically different.

The registered manager or owner may be simultaneously dealing with staff absence, recruitment, safeguarding, medicines, family concerns, commissioning issues, maintenance, training and regulatory evidence.

Now add:

asset management;

cyber awareness;

supplier assurance;

access controls;

information governance;

business continuity;

software updates;

incident planning;

and annual DSPT evidence.

The question therefore becomes less:

“Why hasn’t the smaller provider completed the assurance?”

and more:

“Have we designed the digital expectations of modern care around the governance capacity available to deliver them?”


Government evidence points in the same direction

This isn’t simply a pattern within Care Circle’s data.

Government-commissioned research into cyber security across adult social care found that providers with 50 or more staff were more likely than smaller organisations to use a range of cyber controls and risk-management arrangements, including more frequent back-ups and secure external backup systems.

The research also identified two particularly significant barriers to improving cyber security:

cost, cited by 49%, and time and capacity, cited by 34%.

And when providers were asked about their relationships with technology suppliers, researchers identified limited ongoing monitoring of supplier cyber risk, associated with lack of time, organisations being too small to possess substantial bargaining power, and uncertainty about what checks providers should undertake.

That sounds remarkably similar to the structural divide visible in the Care Circle Network intelligence.

But there is another important finding in the government research.

Good cyber practice was found among providers of all sizes, while poor engagement was also found across different types of organisations. Researchers concluded that leadership and access to cyber expertise appeared particularly influential.

That prevents us drawing the wrong conclusion.

Scale is not destiny.

A small provider can have excellent digital governance.

A large provider can have weak controls.

What scale provides is capacity and infrastructure.

What determines how effectively that capacity is used is leadership.


69.5% should be read carefully

There is a danger with statistics like these.

Someone could look at the 69.5% figure for single-location providers and conclude that approximately 30% are unsafe.

That is not what this analysis establishes.

The Care Circle Network measure asks a much narrower question:

Among locations for which we have an exact DSPT record match, does that record currently show 2025/26 Standards Met or Standards Exceeded?

Where it does not, there can be several explanations.

A provider may have an older published DSPT.

It may have another current status.

It may not have completed or published the current assessment.

Its circumstances may have changed.

The data does not independently test the provider’s cyber controls.

And it does not establish whether an individual service is delivering safe or unsafe care.

That distinction is fundamental.

But at market level, the progression from 69.5% to 80.1%, 87.1%, 91.0% and finally 98.2% is too consistent to dismiss.

It points towards a structural question the sector needs to examine.


Adult social care has actually made enormous progress

This should not become another story portraying social care as digitally behind.

The opposite is true in many respects.

By the 30 June 2026 DSPT deadline, 76.5% of CQC-registered adult social care services across England had an up-to-date DSPT in place — 22,429 services in total. That compares with only 15% in 2021. Almost 14,500 had published for at least three consecutive years.

That is significant progress.

Digital social care record adoption has also risen substantially. DHSC reports that adoption among registered care providers increased from 41% in December 2021 to 80% by July 2025.

The policy direction is equally clear.

Government defines a fully digitised care provider as a CQC-registered provider using an assured digital social care record solution and meeting Standards Met on the DSPT. Its stated ambition is for all care providers to be fully digitised by the end of this Parliament.

So the next challenge is not persuading the sector that digital matters.

It is ensuring the capability to govern that digital environment develops as quickly as the technology itself.


Adoption itself is already showing a scale effect

There is another reason the Care Circle finding deserves attention.

DHSC’s 2025 adult social care technology survey found differences in technology use according to provider size.

For example, use of digital social care records among respondents increased from 57% among micro providers to 88% among large providers.

Financial accounting software ranged from 34% to 90%.

Digital rostering ranged from 52% among micro providers to 81% among large providers.

The same survey found the major barriers to care-technology adoption included set-up costs, ongoing licence costs, training and staff turnover, cyber and data-security costs, connectivity and digital skills.

So we may be looking at two connected divides.

The first is an adoption divide.

The second is an assurance divide.

And as increasingly important parts of care become digital, the two begin to compound one another.


Why this matters beyond IT

Imagine two care providers.

Both deliver good care.

Both want to integrate more closely with health services.

Both are considering new digital care technology.

The first operates 50 locations.

It can evaluate suppliers centrally, maintain an organisational asset register, standardise staff training, negotiate contracts, monitor permissions, employ technology expertise and spread specialist costs across a large estate.

The second operates one location.

Its manager may have to make many of those decisions personally while continuing to run the service.

The regulatory expectations around safe information do not disappear because the second organisation is smaller.

Nor should they.

The people receiving care deserve the same protection regardless of provider size.

But equal expectations do not necessarily mean equal capacity to satisfy them.

That is the policy issue hidden inside the numbers.


This is increasingly a Well-led issue

Digital assurance can still be treated as something belonging to the IT supplier, the DSPT lead or whoever happens to understand computers.

That model is becoming increasingly difficult to sustain.

CQC’s Regulation 17 requirements around good governance require providers to operate systems and processes that assess, monitor and improve quality and safety, assess and mitigate risks and maintain accurate and complete records.

CQC’s wider governance language also centres on clear responsibilities, accountability, governance and the effective use of information about risk, performance and outcomes.

That is why digital assurance should increasingly sit alongside:

quality assurance;

workforce governance;

clinical governance;

financial oversight;

safeguarding;

health and safety;

and business continuity.

It is part of how the organisation is run.

Cyber security may be technical. Accountability for cyber security is governance.

Data protection may involve systems. Accountability for information is governance.

Digital records may use software. Ensuring those records remain safe, accessible and accurate is governance.

And the board, owner or responsible individual cannot outsource that accountability simply because the software is supplied by somebody else.


Your supplier cannot become your governance system

This point deserves particular attention.

Smaller providers often rely heavily on external software and technology suppliers because maintaining specialist expertise internally is unrealistic.

That can be entirely appropriate.

But outsourcing a function is different from outsourcing accountability.

Government research found that providers placed considerable confidence in technology suppliers’ security arrangements while often lacking the expertise and resources needed to assess them. It also found that ongoing monitoring after procurement could be limited.

That creates an uncomfortable question.

If a provider uses:

a digital care-record platform;

eMAR;

rostering software;

payroll;

cloud storage;

email;

electronic call monitoring;

remote-care technology;

Wi-Fi infrastructure;

and perhaps AI-enabled tools,

who inside the provider has a complete view of the digital estate?

Not each individual system.

The whole environment.

Which supplier holds what information?

Which systems connect?

Who has access?

When was access last reviewed?

What happens when an employee leaves?

Where is information backed up?

What happens if broadband fails?

What happens if the principal software supplier becomes unavailable?

Who owns the incident response?

When was that response actually tested?

These are no longer questions reserved for large corporate IT departments.

They are becoming ordinary care-governance questions.


The danger of the annual compliance event

There is another risk.

When resources are stretched, assurance can become deadline driven.

The DSPT comes around.

Evidence is gathered.

Policies are updated.

Questions are completed.

The submission is published.

Then operational life resumes.

But the digital estate does not stand still for the next 12 months.

A new laptop arrives.

A manager leaves.

A new care-record module is introduced.

Someone changes broadband provider.

A software supplier adds functionality.

A new mobile device enters the service.

A member of staff gains administrator permissions.

An external consultant is given access.

A phishing email is clicked.

A backup quietly stops completing.

The organisation’s real risk position can therefore change long before the next annual submission.

Digital Care Hub itself now emphasises moving from DSPT compliance to implementation — ensuring the commitments made through the toolkit are reflected in everyday practice.

That may be the most important next step for the sector.

Digital assurance cannot become something a provider does once a year.

It has to become something the organisation continuously knows.


A better question for provider boards

Rather than simply asking:

“Have we done the DSPT?”

boards, owners, responsible individuals and registered managers might increasingly need to ask:

Who owns our digital risk?

Do we know every critical system and supplier we rely upon?

Do we know who currently has privileged access?

Can we continue delivering safe care if our principal system fails tomorrow?

When did we last test that rather than simply document it?

How do we know former employees no longer have access?

How do we assure ourselves about technology suppliers after procurement?

What evidence tells us staff behaviour matches our policies?

Do our senior leaders understand the organisation’s digital dependencies?

And:

Would the answers be available immediately if the registered manager were absent?

That last question is particularly revealing.

Because mature governance should belong to the organisation.

Not to one knowledgeable individual.


The sector should be careful not to create a digital penalty for being small

This may ultimately be the biggest policy question raised by the Care Circle analysis.

The government wants digitised, connected, information-rich care.

That ambition makes sense.

Better information can support safer handovers, better coordination, stronger decision-making and more joined-up care.

But if achieving and maintaining the necessary assurance increasingly requires specialist resource, smaller providers can face a structural disadvantage.

The answer cannot be lower standards for small providers.

People’s information should not receive weaker protection because they happen to receive care from an independent home or local domiciliary-care business.

The alternative is making assurance achievable without requiring every small provider to recreate the infrastructure of a national group.

That means accessible expertise.

Reusable governance resources.

Proportionate processes.

Shared learning.

Better supplier transparency.

Practical support.

Clear accountability.

Technology designed around the realities of care delivery.

And perhaps most importantly, recognising that digital transformation creates a continuing resource requirement after the technology has been purchased.

The licence fee is not the whole cost of digitisation.

Governance has a cost too.


Suppliers have a responsibility in closing the divide

There is an important message here for the technology sector.

A supplier serving adult social care should increasingly ask whether its product reduces or increases the governance burden placed on the provider.

Can permissions be understood easily?

Can access be audited?

Are updates communicated clearly?

Is security responsibility explicit?

Is incident support defined contractually?

Can data be exported?

Are administrators identifiable?

Is multi-factor authentication straightforward?

Does the supplier make evidence available that helps a provider satisfy its own assurance responsibilities?

Are small customers given enough support after implementation?

Can a registered manager understand the risk without needing to become an information-security specialist?

The strongest technology providers will increasingly recognise something important:

a care provider does not simply buy functionality. It inherits responsibility for governing that functionality.

Good suppliers should help make that responsibility manageable.


And commissioners should pay attention too

Commissioning increasingly depends upon data.

Integration depends upon data.

Neighbourhood care depends upon information moving safely between organisations.

Hospital discharge depends upon reliable communication.

Digital care records potentially allow professionals to make better-informed decisions.

But those ambitions rest on thousands of individual provider organisations possessing the governance capability to participate safely.

If smaller providers systematically face greater difficulty achieving current digital assurance, that is therefore not solely a provider problem.

It becomes a system-capacity issue.

The Care Circle Network intelligence suggests the sector should examine digital maturity not just by asking how many services have adopted technology, but also:

which parts of the market have the organisational infrastructure required to govern it confidently?

That is a much harder question.

It may also be the more important one.


The Care Circle view

Adult social care has made substantial progress on digital adoption and data-security assurance.

That achievement should be recognised.

But averages can conceal structure.

Across the 25,093 active care locations in this analysis with an exact DSPT match, the probability of finding a current 2025/26 Standards Met or Standards Exceeded status rises steadily with the scale of the provider organisation.

From 69.5% at single-location providers to 98.2% among the largest groups.

That does not prove smaller providers are less secure.

It does not establish the quality of any individual provider’s cyber controls.

And DSPT status itself should never be treated as a complete measure of cyber resilience.

What it does expose is a question the sector can no longer avoid.

As care becomes more digital, is organisational capacity becoming an increasingly important determinant of who can demonstrate good digital governance?

If so, the response should not be to slow digitisation.

Nor should it be to reduce expectations.

It should be to recognise what successful digital transformation actually requires.

Technology.

Skills.

Time.

Expertise.

Leadership.

Evidence.

Accountability.

And governance.

Because the next digital divide in adult social care may not simply separate organisations that have technology from those that do not.

It may separate organisations with the capacity to govern that technology continuously from those expected to do the same job with far fewer resources.

That is not simply a technology issue.

It is becoming a sector-wide governance issue.


Care Circle Network Intelligence Insight

The finding: Among active adult social care locations with an exact DSPT match, the proportion currently showing 2025/26 Standards Met or Standards Exceeded rises consistently with provider scale:

69.5% — single-location providers
80.1% — 2–4 locations
87.1% — 5–9 locations
91.0% — 10–24 locations
98.2% — 25+ locations

The gap: There is a 28.7 percentage-point difference between locations operated by single-site providers and those operated by the largest groups.

The wider context: Approximately 82% of active provider organisations within the Care Circle Network Provider Intelligence Observatory are independent or single-location providers.

The question for the sector: As digital assurance becomes increasingly fundamental to modern care, how do we maintain the same expectations for safety and governance without allowing organisational scale to determine a provider’s ability to demonstrate them?


About this analysis

This Care Circle Network Intelligence Insight is based on analysis of the Care Circle Network Provider Intelligence Observatory as at 9 August 2026.

The provider-scale analysis uses 25,093 active adult social care locations with an exact CQC ODS-code match to a DSPT record.

For this analysis, current digital assurance means a DSPT record showing 2025/26 Standards Met or Standards Exceeded.

The percentages measure the presence of that current published assurance status. They do not independently assess a provider’s cyber security, data-protection compliance, operational resilience or quality of care, and no conclusion about an individual provider’s security should be drawn from the absence or presence of a particular DSPT status alone.

Provider scale is based on the organisational scale classification held within the Provider Intelligence Observatory.

The Care Circle Network Provider Intelligence Observatory brings together regulatory, organisational, workforce, property, digital and other public-source intelligence to identify structural changes and emerging challenges across adult social care.

Care Circle Network Intelligence Insight
Turning sector information into clearer questions, stronger evidence and better-informed conversations.

CSN Editor
Author: CSN Editor