DTAC assesses five assurance areas: clinical safety, data protection, technical security, interoperability, and usability and accessibility. Since 6 April 2026, NHS England has required an updated DTAC form with 25% fewer questions, so your immediate task is gathering named artefacts: DCB0129 documents, DSPT evidence, a recent penetration test report, interoperability specifications, and WCAG results.
TL;DR:
- Suppliers should reuse existing evidence from DSPT v8, pen test reports, and safety documentation, focusing only on identified gaps due to the form's brevity.
- The updated DTAC form emphasizes clearly labeled, cross-referenced evidence, with specific artifact naming conventions to streamline review processes.
- Submission failures often stem from outdated or superficial hazard logs, generic DPIAs, unsupported claims of scope, or expired security tests, which are easily fixable.
- Ongoing DTAC maintenance requires regular updates to hazard logs, DPIAs, security testing, and mapping of evidence to product changes or lifecycle milestones.
- Early involvement of clinical safety officers, security leads, and product managers significantly shortens the pathway from preparation to procurement, especially if existing compliance artifacts are available.
Table of Contents
- What the NHS DTAC checklist actually covers
- What changed in the 2026 DTAC update
- Practical DTAC checklist: evidence to collect by domain
- Common DTAC pitfalls that stall a submission
- Keeping DTAC current through your product lifecycle
- A realistic view on timelines and who to involve early
- Where to find security and evidence examples
- Authoritative pages to read next
- Sources
- FAQ
What the NHS DTAC checklist actually covers
Each of the five DTAC areas maps to an existing standard, which means most suppliers already hold half the evidence they need. They just need to locate it and label it correctly.
Clinical safety rests on DCB0129, with DCB0160 applying where an NHS organisation is deploying the tool into a live clinical pathway. Reviewers want a named Clinical Safety Officer, a maintained hazard log, and a clinical safety case report that shows how risks were identified and controlled, not just listed.
Data protection runs on UK GDPR and the Data Protection Act 2018. You'll need a DPIA scoped specifically to NHS use, evidence of ICO registration, a record of processing activities (ROPA), and alignment with DSPT v8.
Technical security starts at Cyber Essentials as a floor, then layers on penetration testing, multi-factor authentication evidence, and a documented incident response process.
Interoperability covers FHIR/HL7 mapping, correct NHS Number validation, and open API documentation reviewers can actually follow.
Usability and accessibility is judged against WCAG 2.2 AA and the NHS service standard. It's worth knowing this area produces a conformity rating rather than a numeric score, so vague claims of "we're accessible" carry no weight without test evidence attached.
Together, this is the core of the DTAC guidelines every NHS procurement team now checks against before shortlisting a supplier.

What changed in the 2026 DTAC update
The refreshed form retired the previous version outright. From 6 April 2026, procurement teams use only the new DTAC form, which cuts the question count by a significant proportion.
That reduction isn't cosmetic. NHS England removed questions that duplicated what DSPT v8 and standard pre-acquisition questionnaires already ask, so a supplier who previously answered near-identical prompts three times over now answers once. The guidance is explicit that DTAC should overlay existing assurance routes rather than sit as a separate bureaucratic hurdle.
Practically, this means your first move on the new form shouldn't be starting from a blank page. Pull your DSPT submission, your last security questionnaire response, and your DCB0129 pack, and map each answer field against material you already hold. Most suppliers find they're filling genuine gaps in perhaps a third of the fields, not all of them. The remaining effort goes into tightening evidence quality, which reviewers now scrutinise more closely given the shorter form leaves less room for padding around thin answers.

Practical DTAC checklist: evidence to collect by domain
Reviewers work through submissions fast, so evidence that's clearly labelled and cross-referenced gets through faster than a bigger but disorganised pack. Build your evidence around these five clusters.
Clinical safety (C1):
- Named Clinical Safety Officer with signed-off credentials
- Comprehensive hazard log, not a single-page summary
- Clinical safety case report referencing DCB0129
- UKCA or device classification evidence where the product qualifies as a medical device
Data protection (C2):
- DPIA scoped to NHS deployment context, not a generic template
- Current DSPT v8 submission or equivalent evidence
- ROPA covering all NHS-relevant data flows
- Sub-processor list with safeguards for any data transfers outside the UK
Technical security (C3):
- Valid Cyber Essentials certificate
- Penetration test report dated within the last 12 months, with remediation tracked
- MFA evidence on privileged and supplier accounts
- Incident response plan and business continuity records
Interoperability (C4):
- API documentation with sample payloads
- FHIR/HL7 mapping where clinical data is exchanged
- NHS Number validation method described in plain terms
- Security model detail: OAuth flows, TLS versions in use
Usability and accessibility (D1):
- WCAG 2.2 AA test reports from a named tester or third-party auditor
- User research involving people with access needs
- Evidence of NHS service standard alignment
Name every file consistently: domain code, artefact type, date. "C1_HazardLog_v3_2026-02.pdf" tells a reviewer everything before they open it. Cross-reference documents where they overlap, so your DPIA points to the same data flow diagram your interoperability section cites, rather than describing it twice with slightly different wording.
Pro Tip: Build one master evidence index with a row per artefact, its version, owner, and expiry date. Reviewers spend less time chasing you for updates, and you spend less time hunting for the current pen test report six months from now.
Common DTAC pitfalls that stall a submission
Most rejected or delayed submissions fail for the same handful of reasons, and nearly all are fixable without a full resubmission.
- Single-page hazard logs. A hazard log with three entries reads as unfinished work, not a low-risk product. Reviewers expect ongoing risk identification, not a one-off exercise.
- Out-of-date penetration tests. A test from 18 months ago signals your security posture may have drifted since. Annual testing, tied to the OWASP Top 10, is the expected baseline.
- Thin DPIAs. Generic templates that never mention NHS-specific data flows get flagged immediately.
- Unsupported "out of scope" claims. Marking a DTAC question as not applicable without written justification is one of the fastest ways to trigger reviewer follow-up questions.
For quick wins: within 7 days, refresh your evidence index and flag anything expired. Within 30 days, commission a new pen test if yours is over a year old. Within 90 days, rebuild any DPIA that reads as boilerplate rather than NHS-specific analysis.
Keeping DTAC current through your product lifecycle
DTAC isn't a one-off form you complete and file away. NHS guidance treats it as ongoing evidence that needs updating as your product and its use change.
Reassessment gets triggered by new clinical features, a change in how the tool is used within a care pathway, or simply a procurement cycle or contract renewal coming round. Buyers increasingly expect current evidence, not a snapshot from your original submission two years earlier.
Build this into routine practice rather than scrambling each time:
- Version your hazard log continuously, don't rewrite it from scratch per submission
- Schedule DPIA reviews annually or whenever data flows change materially
- Run penetration tests on a fixed annual cycle, not reactively
- Map DSPT, Cyber Essentials and any ISO 27001 artefacts directly onto DTAC fields so you're never duplicating documentation work
Pro Tip: Assign one person to own the evidence index full time, even part time. Products that treat DTAC as a shared, nobody's-job responsibility are the ones that show up to procurement with expired certificates.
A realistic view on timelines and who to involve early
Suppliers who already hold current Cyber Essentials, a DSPT v8 submission, DCB0129 artefacts and a recent pen test are often only weeks from a strong DTAC submission. Starting from nothing typically takes three to six months. Bring in your Clinical Safety Officer, DPO, security lead and product manager at the outset, not once the form is half-finished. An external assessor can shorten the path considerably when internal capacity or clinical safety expertise is thin.
— Prasant
Where to find security and evidence examples
A well-designed platform that includes evidence categories NHS reviewers require from the start can serve as a useful reference point rather than a theoretical example. Its security page sets out how UK GDPR compliance, privacy safeguards and accessibility controls, including dark mode and adjustable fonts, are documented in practice.
![]()
For carers and professional care teams managing medication schedules, such infrastructure can support features like drug interaction checks, condition-specific guidance, and multi-patient management, which align with DTAC's clinical safety and interoperability considerations. If you're a supplier looking for a concrete example of how privacy, accessibility, and multi-patient data handling get documented for NHS-facing evidence, or you'd like to discuss a partnership around medication safety tooling, get in touch through Thedailydosetracker and start the conversation.
Authoritative pages to read next
- Updated DTAC form and guidance
- Using the Digital Technology Assessment Criteria
- DCB0129 clinical risk management guidance
- NHS service manual, WCAG 2.2 guidance
- Security controls mapping for health tech
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
Sources
- Updated NHS England Digital Technology Assessment Criteria (DTAC) form and guidance
- Using the Digital Technology Assessment Criteria (DTAC)
FAQ
What is a DTAC in the NHS?
DTAC, the Digital Technology Assessment Criteria, is the NHS assurance framework suppliers must meet before a digital health tool can be adopted, covering clinical safety, data protection, technical security, interoperability and accessibility.
What does DTAC stand for in the NHS?
DTAC stands for Digital Technology Assessment Criteria, the baseline standard NHS buyers use to evaluate any digital health product before procurement.
What are the NHS data protection guidelines for DTAC?
DTAC's data protection domain requires compliance with UK GDPR and the Data Protection Act 2018, evidenced through a scoped DPIA, ICO registration, a record of processing activities, and alignment with DSPT v8.
What is the NHS five-step framework in DTAC?
DTAC is structured around five assessment areas rather than a numbered "five-step" process: clinical safety, data protection, technical security, interoperability, and usability and accessibility, each mapped to a distinct set of standards and evidence.
Do I need a new DTAC form after April 2026?
Yes. Since 6 April 2026, NHS procurement processes require the updated DTAC form, which has 25% fewer questions than the previous version.
