
The email arrives from someone in procurement or digital, with the Digital Technology Assessment Criteria attached and a request for evidence. From that point the timeline belongs to the buying organisation.
That is the fact suppliers find hardest to work with. NHS England is explicit that digital health technologies being considered by NHS or social care organisations should be assessed against the DTAC by the organisation buying the product, whatever the procurement route. The trust sets the pace. You control how quickly you respond and very little else.
NHS England published an updated form in February 2026. The previous version should not be used from 6 April 2026 onwards, so a response assembled from an old template is a problem before anyone reads the content.
The new form carries around a quarter fewer questions and has been de-duplicated against other processes, including the Data Security and Protection Toolkit and the pre-acquisition questionnaire. Scope now follows the NICE definition of digital health technologies, covering standalone software and software used together with hardware, and leaving out hardware devices and embedded operational software such as firmware.
The de-duplication is the useful part commercially. Where you have already done the DSPT properly, some of what the DTAC asks for is evidence you hold, in a form somebody has already reviewed.
DTAC covers five areas: clinical safety, data protection, technical security, interoperability, and usability and accessibility.
Your evidence against those criteria is reviewed by subject matter experts inside the buying organisation. NHS England publishes a table of the expected accountable officer and subject matter expert roles and states that people with the relevant expertise should be involved, using the clinical safety section as its example.
For a supplier, that structure explains a pattern that otherwise looks like disorganisation. The response does not get read by one person in one sitting. It gets distributed, and it comes back at the pace of whichever specialist is hardest to get time with. A gap in one section does not hold up the others, which is why partial questions arrive weeks apart.
It also means a weak section has a specific reviewer attached to it, and that reviewer has a professional view about what adequate looks like.
Clinical safety and data protection both require named people, and both are checked.
The DTAC requires a nominated Clinical Safety Officer. That person has to be a clinician, hold current registration with a professional body and be trained in clinical risk management. NHS England accepts that the role can be undertaken by an outsourced third party, which matters for suppliers without a clinician on the payroll.
On data protection, risk assessments, mitigations, access controls and system level security policies have to be signed off by your Data Protection Officer.
Neither is something to arrange after the assessment arrives. A trust asking who your Clinical Safety Officer is expects a name, a registration and a training record, and the answer "we are recruiting one" reads as a project that has not started.
Four places, all avoidable.
Answering from the old form. The February 2026 version is the one in circulation, and a response on the previous template gets returned.
Treating the clinical safety section as documentation. It is the section reviewed by a clinician, and hazard logs assembled to satisfy a form read differently to ones produced by an actual clinical risk process. See the DCB 0129 framework page for what sits underneath it.
Answering the DSPT and the DTAC as separate exercises. The form has been de-duplicated against the toolkit deliberately, so evidence prepared for one should carry, and preparing it twice produces two versions that can disagree.
Waiting for the trust to chase. The assessment sits with several reviewers, and the supplier who responds to a section query the same week is the one whose file keeps moving.
For the framework detail, see the NHS DTAC and NHS DSPT pages. If your DSPT status is the weaker part of the picture, DSPT Standards Not Met and what happens after the deadline covers the improvement plan route.
Naq covers the NHS DTAC, the NHS DSPT and DCB 0129 in one place, alongside ISO 27001, Cyber Essentials and GDPR, so the evidence behind an assessment is held once and counted everywhere it applies.
Included in the platform are in-house Clinical Safety Officers and virtual Data Protection Officers, which answers the two named-role requirements the DTAC checks. Controls sit against the requirements they satisfy with evidence attached, so when a trust's reviewer asks about one section you can retrieve what supports it. Every change is recorded on the activity stream with previous and new values, and PDFs can be edited in place, so a document that needs a correction mid-assessment does not turn into a new version circulating by email.
If a trust has sent you a DTAC and you are working out what you can evidence today, book a fifteen-minute demo.