Published: 14th September 2026
Reviewed by: David Small BSc (Hons), MSc, MTOPRA (Founder and CEO)
The 5 areas of NHS DTAC
DTAC evaluates digital health technologies across five principal areas:
- Clinical safety
- Data protection
- Technical security
- Interoperability
- Usability and accessibility
Together, these areas help NHS organisations determine whether appropriate baseline assurance measures are in place before a digital technology is adopted.
For manufacturers seeking NHS market access, this means DTAC readiness needs input from several functions.
Regulatory and quality teams may be involved in clinical safety. Information governance specialists may support data protection. Developers and security teams will provide technical evidence. Product teams may need to demonstrate usability and accessibility.
That cross-functional nature is exactly why DTAC preparation should start early.
New to NHS DTAC Compliance?
Understanding the five areas of DTAC is an important part of preparing digital health technologies for NHS adoption. For a practical overview of the Digital Technology Assessment Criteria, including clinical safety, data protection, technical security, interoperability, and usability and accessibility, read our Complete Guide to NHS DTAC Compliance for Digital Health Manufacturers.
1. Clinical Safety
Clinical safety is one of the most important areas of DTAC because digital technology can directly or indirectly affect patient care.
Software failures, incorrect information, poorly designed workflows, missing alerts or inappropriate outputs can potentially contribute to patient harm.
The manufacturer therefore needs to demonstrate that clinical risks associated with its technology have been systematically identified, assessed, controlled and monitored.
For health IT manufacturers, this brings DCB0129 into consideration.
NHS England describes DCB0129 as the clinical risk management standard for manufacturers of health IT systems. The related DCB0160 standard applies to health organisations responsible for deployment and use.
What good looks like
A manufacturer should be able to demonstrate that clinical safety is integrated into product development rather than considered only when an NHS customer requests evidence.
Depending on applicability, this may include:
- defined clinical risk management responsibilities
- access to an appropriately qualified Clinical Safety Officer
- systematic identification of clinical hazards
- evaluation and control of clinical risks
- a maintained Hazard Log
- a Clinical Risk Management Plan
- a Clinical Safety Case
- a Clinical Safety Case Report
- review of clinical risks when the product changes
DCB0129 specifically establishes requirements intended to promote effective clinical risk management by organisations developing and maintaining health IT systems.
Evidence you may need
Typical evidence can include:
- Clinical Risk Management Plan
- Hazard Log
- Clinical Safety Case
- Clinical Safety Case Report
- clinical risk management procedure
- evidence of Clinical Safety Officer involvement
- DCB0129 compliance evidence where applicable
A common DTAC gap
A manufacturer may already operate a medical device risk management process, particularly where its software is regulated as Software as a Medical Device.
However, this should not automatically be assumed to satisfy NHS clinical safety requirements.
NHS guidance explicitly states that DCB0129 and DCB0160 do not replace medical device regulatory requirements.
The applicability of both frameworks needs to be considered.
Explore DTAC Clinical Safety in More Detail
Clinical safety is one of the five core areas of NHS DTAC. If your digital health technology is being developed or deployed within the NHS, understanding DCB0129 is an important part of demonstrating compliance. Read our Guide to DCB0129 Clinical Safety for NHS DTAC for practical guidance on clinical risk management, hazard assessment, Clinical Safety Officers and the Clinical Safety Case.
2. Data Protection
Digital health technologies frequently process personal and special-category health information.
Manufacturers therefore need to understand exactly what information their product processes and be able to demonstrate appropriate data protection governance.
This goes considerably further than simply having a privacy policy on your website.
What good looks like
A DTAC-ready organisation should understand:
- what personal information is collected
- why each category of information is required
- the lawful basis for processing
- where information is stored
- how long it is retained
- who can access it
- which processors or subprocessors are involved
- whether information is transferred internationally
- how data subject rights are supported
- how incidents and breaches are managed
Data protection should also be incorporated into the design of the technology.
Where processing is likely to result in high risk to individuals, the ICO requires a Data Protection Impact Assessment to be undertaken before the relevant processing begins.
Evidence you may need
Depending on your product and processing activities, evidence might include:
- Privacy Notice
- Data Processing Records
- Data Flow Diagrams
- Data Retention Policy
- Data Protection Policy
- Data Protection Impact Assessment
- processor/subprocessor information
- incident and breach procedures
international transfer documentation
A common DTAC gap
A surprisingly common problem is inconsistency.
The privacy notice describes one processing arrangement. The technical architecture shows another. The contract identifies different subprocessors, while the retention policy specifies a period that does not match the application.
Individually, documents may look reasonable.
Collectively, they tell different stories.
A DTAC readiness review should therefore examine the evidence as a complete system rather than checking documents individually.
3. Technical Security
Healthcare technologies can hold sensitive information, interact with critical infrastructure and become integrated into clinical workflows.
Technical security is therefore a significant part of DTAC assurance.
Manufacturers need to show that appropriate security controls are not only designed into their systems but actively managed.
What good looks like
Security should be embedded throughout the product lifecycle.
Relevant areas can include:
- security governance
- authentication
- access control
- encryption
- vulnerability management
- secure development
- penetration testing
- patch management
- logging and monitoring
- incident response
- backup and recovery
- business continuity
- cloud infrastructure
- third-party security
Vulnerability management is particularly important because security assurance is not static. New vulnerabilities continue to emerge after software has been released.
The UK National Cyber Security Centre recommends maintaining an effective vulnerability management process that includes asset identification, prioritisation, updating, risk ownership and regular review.
Evidence you may need
Examples include:
- Information Security Policy
- penetration testing reports
- vulnerability management procedure
- access-control procedures
- incident response plan
- business continuity plan
- backup and recovery arrangements
- security architecture
- evidence of security monitoring
- secure development procedures
A common DTAC gap
The organisation may actually have good security practices but poor evidence.
Developers may regularly patch systems, restrict permissions and monitor infrastructure without those activities being governed through controlled policies or records.
From an assurance perspective, saying “our developers do this” is considerably weaker than producing objective evidence showing how the process operates.
4. Interoperability
Digital healthcare is an interconnected environment.
Your technology may need to exchange information with NHS systems, electronic patient records, APIs, clinical platforms, diagnostic systems or other third-party technologies.
DTAC therefore considers whether the technology can exchange information appropriately and effectively.
What good looks like
Manufacturers should clearly understand:
- what data enters the system
- what data leaves it
- which systems it connects with
- how those interfaces operate
- which standards and terminologies are used
- how identity and access are managed
- how data integrity is protected
- how integration failures are handled
- which third-party systems the product depends upon
The objective is not merely technical connectivity.
The information being exchanged must remain meaningful, accurate and appropriately controlled.
Evidence you may need
Typical evidence might include:
- interface specifications
- API documentation
- data standards and mappings
- system architecture
- integration diagrams
- data flow diagrams
- interoperability testing
- third-party dependency information
A common DTAC gap
Interoperability is sometimes considered only after an NHS customer asks:
“Can your platform integrate with our existing system?”
At that point, the manufacturer may discover that its original architecture assumed the product would operate independently.
For businesses targeting NHS adoption, interoperability requirements should be considered during product strategy and architecture rather than left entirely to procurement.
5. Usability and Accessibility
The final DTAC area concerns the people actually using the technology.
A digital health product can be clinically valuable, secure and technically sophisticated but still create problems if patients or healthcare professionals cannot use it effectively.
Usability and accessibility therefore need to be considered throughout development.
What good looks like
Manufacturers should be able to demonstrate consideration of:
- user-centred design
- intended users
- different levels of digital literacy
- users with disabilities
- real-world clinical workflows
- usability testing
- accessibility testing
- assistive technologies
- user feedback
- identified usability problems
- resulting improvements
Current NHS digital accessibility guidance requires NHS-facing services within its scope to meet WCAG 2.2, with A and AA criteria forming the relevant baseline for NHS websites and mobile apps.
Accessibility should therefore be considered during design and development rather than tested only when the product is ready for procurement.
Evidence you may need
Evidence can include:
- usability test reports
- accessibility assessment reports
- accessibility conformance evidence
- user research
- usability plans
- accessibility statements
- records of identified issues and remediation
testing involving assistive technologies
A common DTAC gap
Testing the product internally is not necessarily equivalent to demonstrating usability.
Developers and product managers already understand how the technology is supposed to work.
Real users may not.
Evidence generated through representative user research and testing can therefore identify issues that internal teams have overlooked.
DTAC Requirements: What Does Good Evidence Look Like?
A useful way to think about DTAC is:
|
DTAC area |
What you need to demonstrate |
Example evidence |
|
Clinical safety |
Clinical risks are systematically managed |
Hazard Log, Clinical Safety Case, DCB0129 evidence |
|
Data protection |
Personal information is lawfully and appropriately managed |
DPIA, Privacy Notice, data flows, processing records |
|
Technical security |
Systems and information are appropriately protected |
Penetration test, security policies, vulnerability management |
|
Interoperability |
Information can be exchanged appropriately |
API documentation, architecture, standards mappings |
|
Usability & accessibility |
Intended users can access and use the technology effectively |
Usability testing, accessibility assessment, user research |
The important word is evidence.
DTAC readiness is much stronger when each answer can be traced to current, controlled and product-specific evidence.
Why a DTAC Readiness Assessment Should Come Before Remediation
When organisations first examine DTAC requirements, there can be a temptation to start writing policies immediately.
That isn’t always the best first step.
You may already have more evidence than you realise.
A company operating an established quality management system, information security framework or regulated medical device development process may already possess documents that support parts of the assessment.
The first task should therefore be to understand the current position.
A structured DTAC readiness assessment can:
- map the requirements against your technology
- identify existing evidence
- evaluate whether that evidence is adequate
- identify missing evidence
- highlight inconsistencies
- prioritise higher-risk gaps
- establish responsibilities
- create a practical remediation roadmap
This can prevent teams from spending resources producing documents that are not needed while overlooking more significant issues.
From DTAC Gap Analysis to DTAC Readiness
Once the gaps are known, remediation can begin.
Some findings may be straightforward.
A procedure may need updating or existing evidence may simply need organising.
Other findings can involve considerably more work.
You may need to conduct penetration testing, develop a clinical safety case, undertake accessibility testing, formalise information governance processes or implement new technical controls.
This is why starting before a live NHS procurement exercise can be so valuable.
The sequence should ideally be:
DTAC requirements → existing evidence → gap assessment → prioritised remediation → evidence development → validation → procurement readiness → ongoing maintenance.
Rather than:
NHS opportunity → DTAC questionnaire → panic.
What Comes After DTAC?
Understanding the five areas of DTAC is an important step towards NHS adoption, but DTAC is only part of the wider procurement journey. Read our Guide to Becoming NHS Procurement Ready to understand how DTAC, clinical safety, regulatory compliance, cybersecurity, interoperability, accessibility and commercial evidence come together to support NHS market access.
How Patient Guard Can Help
Patient Guard supports digital health manufacturers through the complete DTAC readiness journey.
Our DTAC Readiness Assessment establishes your current position by reviewing your technology and existing evidence against the applicable requirements, identifying gaps and creating a prioritised roadmap.
Where additional work is required, our DTAC Accelerator service provides hands-on support to help close those gaps and develop the necessary evidence.
For organisations requiring specialist support, Patient Guard also provides Clinical Safety Compliance Services for DCB0129 and DCB0160, NHS Procurement Ready support and ongoing Compliance Essentials services.
The objective is not simply to help you answer a questionnaire.
It is to help build an evidence base that gives NHS buyers confidence in your technology.
Start With Your DTAC Readiness
If you are preparing a digital health technology for the NHS, you do not need to guess how far away from DTAC readiness you are.
Start by understanding your current position.
A Patient Guard DTAC Readiness Assessment can identify the evidence you already have, the gaps that need addressing and the priorities to focus on before NHS procurement.
Frequently asked questions about NHS DTAC
DTAC covers five principal areas: clinical safety, data protection, technical security, interoperability, and usability and accessibility. NHS England describes these as national baseline criteria for digital health technologies entering NHS and social care.
Evidence depends on the technology, but may include clinical safety documentation, privacy and information governance records, security testing, technical architecture, interoperability documentation, usability research and accessibility testing.
Clinical safety is a core DTAC area. DCB0129 establishes clinical risk management requirements for manufacturers of health IT systems, and applicability should be assessed for the specific digital product.
DCB0160 applies to health organisations deploying and using health IT systems, whereas DCB0129 establishes requirements for manufacturers. Manufacturers nevertheless need to provide appropriate product and clinical safety information to support deployment.
No. NHS guidance specifically states that DCB0129/DCB0160 do not supersede medical-device regulatory requirements, and DTAC addresses areas extending beyond medical-device regulation.
References
This guide is based on official NHS England guidance, standards and digital service guidance relating to the Digital Technology Assessment Criteria (DTAC), clinical safety, data protection, technical security, interoperability, usability and accessibility for digital health technologies used within NHS and social care settings.
| Organisation | Reference | Why it's relevant |
|---|---|---|
| NHS England | Digital Technology Assessment Criteria (DTAC): Guidance for Buyers and Suppliers | Provides the principal NHS guidance on the Digital Technology Assessment Criteria. DTAC provides a national baseline for assessing digital health technologies and supports NHS and social care organisations when considering the assurance of digital technology products. |
| NHS England | Medical Devices and Digital Tools | Provides NHS England guidance relating to medical devices and digital health tools, including considerations relevant to the implementation and use of digital technologies within NHS healthcare environments. |
| NHS England | Principles for Using Digital Technologies in Mental Health Inpatient Treatment and Care | Defines DTAC as a set of criteria used when introducing new digital health technology and identifies the national minimum standards covering clinical safety, data protection, technical security, interoperability, usability and accessibility. |
| NHS England Digital | Clinical Risk Management Standards | Provides the NHS framework for clinical risk management of health IT systems and explains the roles of DCB0129 and DCB0160. DCB0129 applies to manufacturers of health IT systems, while DCB0160 applies to health organisations deploying and using those systems. |
| NHS England Digital | DCB0129: Clinical Risk Management – its Application in the Manufacture of Health IT Systems | Defines clinical risk management requirements for organisations responsible for developing and maintaining health IT systems. It is particularly relevant to digital health manufacturers preparing clinical safety evidence for DTAC. |
| NHS England Digital | DCB0160: Clinical Risk Management – its Application in the Deployment and Use of Health IT Systems | Defines clinical risk management requirements for health and care organisations responsible for the deployment, use, maintenance or decommissioning of health IT systems. |
| NHS England | National Review of Clinical Risk Management Standards DCB0129 and DCB0160: Supporting Information | Provides current information on NHS England's review of DCB0129 and DCB0160 and explains their respective responsibilities. DCB0129 establishes clinical risk management requirements for manufacturers of health IT systems, while DCB0160 establishes requirements for care organisations deploying and using health IT systems. |
| NHS England Digital Service Manual | What All NHS Services Need to Do About Accessibility | Sets out NHS accessibility requirements for digital services, including WCAG 2.2 Level AA, compatibility with commonly used assistive technologies, inclusion of people with access needs in user research and publication of an accessibility statement. |
| NHS England Digital Service Manual | Accessibility | Provides NHS guidance on designing, developing and testing accessible digital services. The NHS Digital Service Manual reflects WCAG 2.2 and provides guidance covering accessibility across product development, user research, content, design, development and testing. |
DTAC readiness should not be treated as a one-time exercise. Digital health manufacturers should maintain their supporting evidence as their technology, clinical use, data processing activities, security environment, integrations and applicable NHS requirements evolve.
David Small BSc (Hons), MSc, MTOPRA
Reviewed by
David Small, BSc (Hons), MSc, MTOPRA
Founder & CEO |
20+ years in medical device regulatory affairs, MDR/IVDR compliance and quality systems.
Patient Guards Recent Posts

How to Become NHS Procurement Ready: From DTAC to NHS Market Access
Preparing to sell digital health technology to the NHS requires more than completing DTAC. This guide explains how manufacturers can build a procurement-ready position by aligning regulatory compliance, clinical safety, data protection, cybersecurity, interoperability, accessibility and commercial evidence for NHS market access.

DCB0129 and Clinical Safety: What Digital Health Manufacturers Need for NHS DTAC
For digital health manufacturers preparing to enter the NHS, clinical safety can be one of the most important—and sometimes misunderstood—parts of DTAC.
It is not enough to demonstrate that your software works.
Manufacturers need to consider what could happen if the technology fails, produces incorrect information, presents information incorrectly, contributes to a workflow error or is used in circumstances that could expose patients to harm.
This is where clinical risk management and DCB0129 become particularly important.
NHS England identifies DCB0129 as the clinical risk management standard for manufacturers of health IT systems. Its counterpart, DCB0160, applies to health organisations deploying and using health IT systems. NHS England states that compliance with these standards is required under the Health and Social Care Act 2012.
For manufacturers working towards NHS DTAC readiness, understanding the distinction—and having the right clinical safety evidence—is essential.

DTAC Requirements Explained: The 5 Areas Digital Health Manufacturers Need to Get Right
If your digital health technology is heading towards the NHS, understanding the Digital Technology Assessment Criteria (DTAC) should be part of your market-access planning.
But one of the biggest mistakes manufacturers can make is treating DTAC as simply another questionnaire to complete.
The questions are only part of the process.
Behind your answers needs to be evidence showing that your technology and organisation have appropriate arrangements for clinical safety, data protection, technical security, interoperability, and usability and accessibility.
These five areas form the core of NHS DTAC. NHS England describes DTAC as national baseline criteria for digital health technologies entering NHS and social care.
For digital health manufacturers, the practical question is therefore not simply:
“Can we complete the DTAC assessment?”
It is:
“Can we demonstrate that our product meets the requirements?”
This guide looks at each of the five DTAC areas, the types of evidence manufacturers should consider and some of the common gaps that can delay NHS readiness.
Patient Guards Related Services
Need Training?
Do you need training on Quality Management Systems or EU MDR/ EU IVDR? then check out our training courses.
Posted on Google![]()
Nafiul Shelim2 days agoTrustindex verifies that the original source of the review is Google.
I worked with Eleanor Shackleton, from Patient Guard, for the purpose of MDR, CE and UKCA marking. Her diligence, and knowledge in clinical and regulatory requirements for medical device software was critical for us. Would highly recommendPosted on Google![]()
Jay Verma27 days agoTrustindex verifies that the original source of the review is Google.
I found Patient Guard Ltd to be an exceptional partner. Their assessment was thorough, their guidance clear, and their support instrumental in helping us achieve our objectives. Steve and Ellie, in particular, were outstanding in steering us through the MHRA Class I medical device registration process.Posted on Google![]()
Munna P80 days agoTrustindex verifies that the original source of the review is Google.
Working with the Patient Guard team has been a great experience throughout our MHRA and ISO 13485 documentation journey. Their expertise, structured approach, and practical guidance helped our team build a robust quality management system while keeping us aligned with regulatory expectations. The collaboration was professional, responsive, and focused on finding solutions rather than simply identifying issues. A special thank you to Alex and Steve for their outstanding coordination, responsiveness, and continuous support throughout the project. They were always approachable, provided valuable feedback, and worked closely with our team to resolve challenges efficiently. Their commitment made a significant difference in keeping our documentation effort on track. I highly recommend Patient Guard to any healthcare or MedTech organization looking for experienced regulatory and quality system partners for MHRA, ISO 13485, and broader medical device compliance initiatives. Thank you again to the entire Patient Guard team for being such reliable partners.Posted on Google![]()
Peter Reeve107 days agoTrustindex verifies that the original source of the review is Google.
STEPPER design, manufacture & distribute eyewear across the globe. With the increasingly complex landscape concerning the placing of Mecial Devices onto the market, we realised we needed professional guidance. We found Patient Guard via a simple internet search and are delighted we did! They provide a pragmatic solution to our needs, are totally reliable & always available to answer our (often simplistic) questions. They are highly efficient & responsive to what is a changing picture in our world and nothing is too much trouble. We have a much better understanding of regulatory affairs and our responsibilities as manufacturers & distributors and they support us in navigating the requirements in different territories. Updating our Declaration of Conformity, ensuring our labelling is compliant and acting as our PRRC are the key areas of their service for us.Posted on Google![]()
Derek Timm107 days agoTrustindex verifies that the original source of the review is Google.
For those companıes lookıng to comply to ISO standards and ın partıcular ISO13485 whıch to be honest ıs a nıghtmare I would strongly suggest goıng to the professıonals as ındeed we dıd by joınıng forces wıth Patıent Guard Ltd The staff are fantastıc nothıng ıs too much trouble and as a medıcal supply company we sımply cannot lıve wıthout them Thanks ın partıcular to Alex and Steve for all the hard work and our best regards from Dan Medıca South LımıtedPosted on Google![]()
BMSCriticalCare144 days agoTrustindex verifies that the original source of the review is Google.
Great service, very helpful and always willing to answer any questions we have,Posted on Google![]()
Thomson Software815 days agoTrustindex verifies that the original source of the review is Google.
Alex Lewis of PatientGuard guided us through the ISO13485 process in a thorough, systematic and efficient manner. He was friendly, patient and willing to go the extra mile. Excellent service.Posted on Google![]()
Hannah Maddison918 days agoTrustindex verifies that the original source of the review is Google.
Fantastic, knowledgeable team that are always there to help. My appointments have always been booked in very promptly and have always ended with all my queries resolved. I have found the team very flexible and their breadth of knowledge is second to none. Patient Guard are without doubt my go-to for all the regulatory aspects of my medical device role.Posted on Google![]()
Richard Crow953 days agoTrustindex verifies that the original source of the review is Google.
Patientguard are an excellent source of Medical regulatory compliance advice, we have taken advantage of their various services from their EU Rep service, to helping with Technical Files all the way through to using their ISO Templates to implement our ISO 13485 system.Posted on Google![]()
George Kitching956 days agoTrustindex verifies that the original source of the review is Google.
David Small and PatientGuard have been extremely helpful and supportive in assisting us with producing and updating our Technical File and Appendices for MDR certification.Verified by TrustindexTrustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more