NHS procurement
DTAC readiness, prepared properly
The Digital Technology Assessment Criteria is the baseline NHS organisations use to assess digital health products. Most suppliers do not stall on capability — they stall on evidence that is missing, stale or inconsistent between documents.
The basics
What DTAC is — and is not
DTAC brings together, in one place, the baseline questions an NHS organisation wants answered before it takes on a digital health product: is it clinically safe, is the data handled lawfully, is it technically secure, does it interoperate, and can people actually use it.
It is best understood as an aggregator rather than a new standard. Each domain points at obligations that already exist elsewhere — clinical risk management standards, UK data protection law, security good practice, accessibility requirements. DTAC asks you to evidence them coherently in one pack.
That framing matters, because it explains the two most common mistakes. The first is treating DTAC as a form-filling exercise to be done at the end; the underlying evidence takes far longer to produce than the form takes to complete. The second is assuming completion is a national certification. It is not: the assessing organisation makes its own decision, and another organisation may ask again.
Who is asked to complete it
Typically suppliers of digital health products being considered for use in an NHS or NHS- commissioned setting. Exactly when it is requested varies by buyer, procurement route and care setting, so confirm expectations early with the organisation you are talking to rather than assuming.
Before you start
Fix your product scope
Decide precisely which product, version and configuration the pack describes. Ambiguity here undermines every domain.
Write the intended use first
Almost every other answer depends on it, and it is the anchor for clinical safety.
Find your weakest domain
It is usually clinical safety. Start there, because it has the longest lead time.
Assign owners
Each domain needs a named owner who can answer follow-up questions in a review call.
Check currency
Evidence older than your last significant release will be questioned.
The five areas
What each DTAC domain expects
Requirements are set by the assessing organisation and change over time. Treat the lists below as an orientation, then confirm current criteria against the official DTAC materials and your buyer.
Clinical safety
Routes back to the NHS clinical risk management standards. This is the domain where suppliers most often have the least to show.
- A named Clinical Safety Officer with appropriate registration and competence
- A clinical risk management plan that is actually followed
- A hazard log with product-specific hazards, controls and residual risk
- A clinical safety case report matching the version being deployed
Data protection
Whether your handling of personal and special category data is lawful, documented and controlled.
- A DPIA that reflects the real data flows, not a template
- Lawful basis and, for health data, the additional condition relied on
- Retention schedule, sub-processor list and transfer arrangements
- ICO registration and a reachable data protection contact
Technical security
Whether the product is built, hosted and maintained with proportionate security controls.
- A recent penetration test report with a remediation plan
- Secure development practice and vulnerability management
- Access control, logging, encryption in transit and at rest
- Business continuity, backup and incident response arrangements
Interoperability
How your product exchanges data with the wider NHS estate, and on what standards.
- The standards supported and the versions implemented
- API and integration documentation a customer's team can act on
- How identifiers, coding and terminology are handled
- What happens when an interface is unavailable or returns stale data
Usability and accessibility
Evidence that the product has been designed and tested with the people who will actually use it.
- An accessibility statement and WCAG conformance testing evidence
- User research and usability testing with representative users
- Known accessibility limitations, stated honestly, with a roadmap
- Consideration of the clinical environment the product is used in
Consistency across all five
The sixth, unwritten domain. Reviewers read the pack as a whole. If the safety case describes a product with clinician review built in, the DPIA describes automated processing without it, and the product description mentions a module neither covers, confidence collapses.
Before submitting, read all five domains in one sitting and check that they describe the same product, the same version and the same data flows.
Organising the work
Track evidence by domain and owner
Suppliers who get through assessment quickly tend to run something like this internally: one row per domain, a named owner, and an honest status.
Illustrative DTAC evidence matrix
Educational illustration only. This is not an NHS assessment, an official DTAC tool or a submission — it shows how suppliers typically track evidence ownership and readiness. Select a status to see how the tracker changes.
| Domain | Typical evidence | Typical owner | Status |
|---|---|---|---|
| Clinical safety | Clinical risk management plan, hazard log, clinical safety case report, named Clinical Safety Officer | Clinical Safety Officer | |
| Data protection | DPIA, records of processing, lawful basis, retention schedule, sub-processor list, ICO registration | DPO / privacy lead | |
| Technical security | Penetration test report and remediation plan, secure development policy, vulnerability management, business continuity | CTO / security lead | |
| Interoperability | Standards supported, integration and API documentation, messaging and coding standards used | Engineering lead | |
| Usability and accessibility | Accessibility statement, WCAG conformance testing, user research and usability testing evidence | Product / design lead |
Our approach
A structured route to a submission you can defend
- 1
Gap assessment
We review your current evidence against each DTAC domain and record what is missing, weak, inconsistent or out of date — with reasons, not just red flags.
- 2
Prioritised remediation plan
A sequenced plan with owners and realistic effort estimates, focused first on what actually blocks procurement.
- 3
Evidence preparation
Hands-on support producing or strengthening the clinical safety and governance artefacts, including hazard workshops where needed.
- 4
Coherence review
A final read of the whole pack as a reviewer would read it, checking that all five domains describe the same product.
- 5
Maintenance
Change triage so the pack stays current as you ship, rather than decaying until the next buyer asks.
What we do not do
We do not approve, certify or accredit your product, and we cannot guarantee the outcome of any NHS assessment. Those decisions rest with the assessing organisation.
We also will not write claims you cannot substantiate. An evidence pack that overstates maturity fails slowly and expensively, usually at the point where a clinical safety team asks a follow-up question.
What we can do is make sure what you present is complete, current, internally consistent and honest about residual risk.
FAQ
DTAC questions we are asked
Keep going
Related reading
DCB0129 for suppliers
The clinical safety work behind DTAC's hardest domain.
Safety cases and hazard logs
How to produce clinical safety evidence a reviewer will accept.
AI clinical safety
The questions DTAC does not fully cover for AI-enabled products.
DCB0160 for deploying organisations
What your NHS customer has to do once they take the product on.