Skip to content

NHS procurement

DTAC readiness, prepared properly

The Digital Technology Assessment Criteria is the baseline NHS organisations use to assess digital health products. Most suppliers do not stall on capability — they stall on evidence that is missing, stale or inconsistent between documents.

Last reviewed: Guidance in this area changes. We re-check the primary sources when we review a page.

The basics

What DTAC is — and is not

DTAC brings together, in one place, the baseline questions an NHS organisation wants answered before it takes on a digital health product: is it clinically safe, is the data handled lawfully, is it technically secure, does it interoperate, and can people actually use it.

It is best understood as an aggregator rather than a new standard. Each domain points at obligations that already exist elsewhere — clinical risk management standards, UK data protection law, security good practice, accessibility requirements. DTAC asks you to evidence them coherently in one pack.

That framing matters, because it explains the two most common mistakes. The first is treating DTAC as a form-filling exercise to be done at the end; the underlying evidence takes far longer to produce than the form takes to complete. The second is assuming completion is a national certification. It is not: the assessing organisation makes its own decision, and another organisation may ask again.

Who is asked to complete it

Typically suppliers of digital health products being considered for use in an NHS or NHS- commissioned setting. Exactly when it is requested varies by buyer, procurement route and care setting, so confirm expectations early with the organisation you are talking to rather than assuming.

Before you start

  • Fix your product scope

    Decide precisely which product, version and configuration the pack describes. Ambiguity here undermines every domain.

  • Write the intended use first

    Almost every other answer depends on it, and it is the anchor for clinical safety.

  • Find your weakest domain

    It is usually clinical safety. Start there, because it has the longest lead time.

  • Assign owners

    Each domain needs a named owner who can answer follow-up questions in a review call.

  • Check currency

    Evidence older than your last significant release will be questioned.

The five areas

What each DTAC domain expects

Requirements are set by the assessing organisation and change over time. Treat the lists below as an orientation, then confirm current criteria against the official DTAC materials and your buyer.

Clinical safety

Routes back to the NHS clinical risk management standards. This is the domain where suppliers most often have the least to show.

  • A named Clinical Safety Officer with appropriate registration and competence
  • A clinical risk management plan that is actually followed
  • A hazard log with product-specific hazards, controls and residual risk
  • A clinical safety case report matching the version being deployed

Data protection

Whether your handling of personal and special category data is lawful, documented and controlled.

  • A DPIA that reflects the real data flows, not a template
  • Lawful basis and, for health data, the additional condition relied on
  • Retention schedule, sub-processor list and transfer arrangements
  • ICO registration and a reachable data protection contact

Technical security

Whether the product is built, hosted and maintained with proportionate security controls.

  • A recent penetration test report with a remediation plan
  • Secure development practice and vulnerability management
  • Access control, logging, encryption in transit and at rest
  • Business continuity, backup and incident response arrangements

Interoperability

How your product exchanges data with the wider NHS estate, and on what standards.

  • The standards supported and the versions implemented
  • API and integration documentation a customer's team can act on
  • How identifiers, coding and terminology are handled
  • What happens when an interface is unavailable or returns stale data

Usability and accessibility

Evidence that the product has been designed and tested with the people who will actually use it.

  • An accessibility statement and WCAG conformance testing evidence
  • User research and usability testing with representative users
  • Known accessibility limitations, stated honestly, with a roadmap
  • Consideration of the clinical environment the product is used in

Consistency across all five

The sixth, unwritten domain. Reviewers read the pack as a whole. If the safety case describes a product with clinician review built in, the DPIA describes automated processing without it, and the product description mentions a module neither covers, confidence collapses.

Before submitting, read all five domains in one sitting and check that they describe the same product, the same version and the same data flows.

Organising the work

Track evidence by domain and owner

Suppliers who get through assessment quickly tend to run something like this internally: one row per domain, a named owner, and an honest status.

Illustrative DTAC evidence matrix

Educational illustration only. This is not an NHS assessment, an official DTAC tool or a submission — it shows how suppliers typically track evidence ownership and readiness. Select a status to see how the tracker changes.

DomainTypical evidenceTypical ownerStatus
Clinical safetyClinical risk management plan, hazard log, clinical safety case report, named Clinical Safety OfficerClinical Safety Officer
Data protectionDPIA, records of processing, lawful basis, retention schedule, sub-processor list, ICO registrationDPO / privacy lead
Technical securityPenetration test report and remediation plan, secure development policy, vulnerability management, business continuityCTO / security lead
InteroperabilityStandards supported, integration and API documentation, messaging and coding standards usedEngineering lead
Usability and accessibilityAccessibility statement, WCAG conformance testing, user research and usability testing evidenceProduct / design lead

Our approach

A structured route to a submission you can defend

  1. 1

    Gap assessment

    We review your current evidence against each DTAC domain and record what is missing, weak, inconsistent or out of date — with reasons, not just red flags.

  2. 2

    Prioritised remediation plan

    A sequenced plan with owners and realistic effort estimates, focused first on what actually blocks procurement.

  3. 3

    Evidence preparation

    Hands-on support producing or strengthening the clinical safety and governance artefacts, including hazard workshops where needed.

  4. 4

    Coherence review

    A final read of the whole pack as a reviewer would read it, checking that all five domains describe the same product.

  5. 5

    Maintenance

    Change triage so the pack stays current as you ship, rather than decaying until the next buyer asks.

What we do not do

We do not approve, certify or accredit your product, and we cannot guarantee the outcome of any NHS assessment. Those decisions rest with the assessing organisation.

We also will not write claims you cannot substantiate. An evidence pack that overstates maturity fails slowly and expensively, usually at the point where a clinical safety team asks a follow-up question.

What we can do is make sure what you present is complete, current, internally consistent and honest about residual risk.

FAQ

DTAC questions we are asked

Next step

Find out where your DTAC evidence stands

Take the structured NHS readiness check, or talk it through with a clinician who has read a lot of these packs.