Most NHS buyers will ask a simple question before they even look at your features: are you DTAC-ready? If the answer is no, your deal stalls. If the answer is (a truthful!) yes, backed by evidence, you move faster.
This week’s Monday Masterclass breaks down something we often get asked about by our mentees, the DTAC (Digital Technology Assessment Criteria). Its a plain English, no fluff explanation and shows you how to prepare without grinding product to a halt. We’ll cover what DTAC is, who needs it, when to get started, the five core areas, common pitfalls, and where to get help.
What DTAC is and why it matters
DTAC is the NHS’s national baseline for vetting digital technologies at procurement. It tells buyers and users that a product meets minimum standards in clinical safety, data protection, technical security, interoperability, and usability/accessibility. For suppliers, it sets clear expectations for entry into the NHS and social care. Useful official link here: NHS Transformation Directorate
Assessments are typically run locally by the NHS organisation that’s buying or renewing your product. You complete the official DTAC question set and provide evidence; the buyer reviews it as part of due diligence. This applies regardless of procurement route, including pilots.
The punchline: if you want NHS adoption at any meaningful scale, you should plan to meet DTAC early. It’s not a badge for marketing; it’s the buyer’s checklist.
Who needs DTAC?
Short answer: any digital tech used in NHS or social care. That includes patient-facing apps, staff tools, portals, AI and decision support software, and connected devices with software components. If you have multiple products, each one is assessed. Even if you’re not a regulated medical device, you’ll still be expected to meet DTAC across all five areas.
When to start
Start early. You cannot bolt on clinical safety, GDPR practice, or cyber hygiene a week before procurement. NHS guidance is explicit: DTAC is used at procurement and renewal, so arrive prepared. Use your next sprint to do a gap analysis, then tackle the highest-risk gaps first. Regions are even running DTAC readiness workshops; innovators report these save painful rework later.
We coach founders to map DTAC into their Now → Next → Later plan:
- Now (0–3 months): gap analysis, assign owners, start clinical safety and privacy work, schedule pen test.
- Next (3–12 months): complete artefacts and run a small real-world test of your safety and security controls.
- Later (12–24+ months): keep the pack current as you scale and add integrations or new risk.
The five DTAC areas, in practical terms
Think of DTAC as five evidence folders. You will be asked questions and you need to attach proof.
1) Clinical safety (DCB0129/0160)
Your product must not introduce unacceptable clinical risk. Expect to show:
- Clinical Risk Management Plan
- Hazard Log with mitigations
- Clinical Safety Case Report, signed by a qualified Clinical Safety Officer (CSO)
If you don’t have an in-house CSO, you can appoint a trained clinician externally. For provider organisations implementing your tool, DCB0160 mirrors the developer duty under DCB0129. Useful article from ORCHA here
Founder tip: schedule a half-day hazard workshop with your clinical champion. Capture failure modes, mitigations, and residual risks. It’s faster than trying to write it solo.
2) Data protection (UK GDPR)
You’ll need to show data protection by design: lawful basis, privacy notices, DPIA, records of processing, and supplier controls. A key NHS ask is completion of the Data Security and Protection Toolkit (DSPT) annually if you access NHS data/systems (we’ll cover this in another post soon – subscribe at the bottom of the page if you don’t want to miss it!).
Founder tip: do the DPIA early. It forces clarity on data flows, roles (controller/processor), and risk mitigations. You’ll reuse it in information governance reviews.
3) Technical security
Buyers look for evidence that your system is secure and resilient. Common asks:
- Recent penetration test and remediation summary
- Access controls and audit logging
- Encryption in transit/at rest
- Cyber Essentials (Plus is even better for credibility)
Treat this as living practice, not a one-off certificate.
Founder tip: book the pen test before you think you’re ready. The findings will shape your backlog, and NHS buyers often ask for a current report.
4) Interoperability
Show you can plug into NHS systems safely. At minimum, document what you support now and your roadmap: e.g. FHIR-based APIs, NHS number where appropriate, export capabilities, and any target EPR integrations. Early adopters may accept a staged plan if your trajectory is credible.
Founder tip: publish a short integration guide on your docs site. Even if basic, it calms assessor nerves.
5) Usability and accessibility
Demonstrate user-centred design and accessibility (e.g. WCAG 2.1 AA) with user research notes, task success rates, and an accessibility statement. This area is often rated rather than hard pass/fail, but poor UX can surface as a safety risk.
Founder tip: run a quick accessibility audit and fix the easy wins: keyboard navigation, focus order, colour contrast, alt text.
FAQs we hear from founders
Do we get a national “DTAC certificate”?
No central certificate exists. DTAC is a standard question set and evidence pack assessed by each buyer. Some third parties offer pre-assessments you can share, but the NHS organisation still does its own assurance. Keep your own DTAC pack current and reusable.
Does DTAC apply to pilots and proofs-of-concept?
Yes. NHS buyers are asked to assess products against DTAC regardless of procurement route, including pilots. Expect at least a proportionate check before live use.
We’re not a medical device. Do we still need DTAC?
Yes. DTAC applies to all digital health technologies used in NHS/social care, device or not. If you are a device, you’ll also be asked to evidence your regulatory status.
Who can I ask questions?
NHS England maintains clear guidance for developers and shares a contact for queries: england.dtac@nhs.net.
Common pitfalls (and how to dodge them)
- Treating DTAC as paperwork at the end
Teams try to “fill in the form” a week before a procurement board. They then discover they need a DPIA, a pen test, a safety case, and evidence of user testing. Start months earlier and build the artefacts as you build the product. Regional workshops and DTAC readiness tools exist to help you do this efficiently. - No Clinical Safety Officer
Without a CSO, your hazard log and safety case will lack credibility. Engage a trained CSO (internal or external) to run DCB0129 properly. - Thin cyber story
“Hosted on AWS” is not a security posture. NHS buyers expect pen tests, patching cadence, incident response, and ideally Cyber Essentials. Build the basics now; it pays off across customers. - Interoperability as an afterthought
Even if you don’t integrate today, you need a plan that matches NHS reality. Document standards you target and how data can be safely exchanged. - Accessibility gap
WCAG failures create risk and block adoption. Run an audit and publish an accessibility statement with your improvement plan.
A simple, staged plan to get DTAC-ready
Week 0–1: Kick-off and gap analysis
- Download the latest DTAC form and list evidence you already have.
- Assign owners: Clinical safety, Data protection, Security, Interop, UX/access.
- Book a pen test; pencil in a DPIA workshop.
Week 2–6: Close the critical gaps
- Run your hazard identification session; draft the safety case with your CSO.
- Complete your DPIA and update privacy notices; register/confirm with ICO; begin or update your DSPT submission if you access NHS data.
- Implement quick security wins from an initial scan; prepare for the pen test.
Week 7–10: Evidence and assurance
- Execute pen test; fix high/critical findings; capture remediation notes.
- Write your interoperability note and publish a basic integration guide.
- Conduct a short usability/accessibility study; record findings and fixes.
Week 11+: Package and maintain
- Assemble your DTAC pack: filled question set, links to documents, dates, owners.
- Put renewals on a calendar: DSPT yearly, pen test yearly, Cyber Essentials yearly, CSO review each release.
If you prefer a supported route, several reputable teams provide structured help and templates, and NHS innovation bodies run hands-on sessions. We’ve seen early-stage companies shave months off procurement by doing a guided readiness run before the first pilot.
What good looks like in your evidence pack
Use these headings and keep each artefact to the point.
Clinical safety
- Risk Management Plan
- Hazard Log (with severity, likelihood, mitigation)
- Safety Case Report signed by the CSO
- Training records for the CSO (and DCB0129 awareness for the team)
Data protection
- DPIA with data flows
- Records of Processing and supplier DPAs
- Privacy Notices and Subject Rights process
- DSPT status and action plan if applicable
Technical security
- Pen test report summary and remediation evidence
- Architecture diagram; authentication and logging overview
- Certificates/policies (e.g. Cyber Essentials; incident response)
Interoperability
- Current interfaces and export formats
- Standards roadmap (e.g. FHIR resources you support)
- Any live or planned NHS integrations
Usability & accessibility
- User research summary and issues addressed
- Accessibility audit results; accessibility statement
- Key user tasks and success metrics
Where to get help (see references below)
- Official NHS pages: DTAC overview, how it’s used, and the downloadable question set. Developer guidance also links out to good-practice resources, and you can email england.dtac@nhs.net with specific questions.
- Regional support: Academic Health Science Networks run DTAC readiness sessions with NHS England’s DTAC team and peer innovators. Worth attending for live Q&A and templates.
- Practical write-ups: Clear, founder-friendly explainers and checklists are available from experienced UK suppliers and assurance firms; useful to sense-check your approach.
How this fits your Now → Next → Later roadmap
DTAC is not paperwork after product. It’s part of product. Build it into your Now → Next → Later plan: foundational safety and privacy now, demonstrable controls in a real-world pilot next, and a maintained, re-usable evidence pack later as you scale across sites.
Done well, DTAC becomes a trust asset. It speeds procurement, reduces surprises, and signals to clinicians and IT that you take safety and governance seriously.
Tiny next step
Open a doc and list your DTAC owners: CSO, DPO/IG lead, Security lead, Interop lead, UX/access lead. Book a 60-minute kick-off and decide what you’ll evidence in the next four weeks.
Want more like this?
Found this article useful? Subscribe using the form below to get more masterclasses right in your inbox.
You’ll also get our highly rated medtech founders starter pack for free!
If you get stuck with compliance drop us a line here and we can connect you with one of our experts in clinical safety and regulations (paid service).
References
- NHS England. Digital Technology Assessment Criteria (DTAC) — overview and downloads. Updated 2025. NHS Transformation Directorate
- NHS England. How to use the DTAC — guidance for buyers and developers; pilots included. 2025. NHS Transformation Directorate
- NHS England Digital Regulations Toolkit. Using the DTAC — developer-focused guidance and contact details. 2024–2025. AI Digital Regulations Service
- NHS England / NHS Digital. Data Security and Protection Toolkit (DSPT) — who must complete and when. Updated Jan 2025. NHS England Digital
- ORCHA. Top 5 FAQs — DTAC clinical safety (DCB0129) — practical CSO and documentation advice. Jul 2023. ORCHA
- Health Innovation North East & North Cumbria. DTAC experts share insights with innovators — workshop and readiness tool. Dec 2023. Health Innovation NENC
- Naq Cyber. Cracking DTAC — founder-oriented guide on what to prepare and why. Aug 2025. naqcyber.com
Educational only. Not legal or regulatory advice. Always check current NHS guidance for your specific product and pathway.