Blog
Compliance
NHS DTAC v2
July 13, 2026
Approx min read

How to pass an NHS DTAC assessment

An NHS trust or integrated care board wants your digital health product. The clinicians have seen it, the budget is there, and then procurement asks for a completed DTAC before onboarding goes any further. Until that pack lands with the buyer, the deal sits at the assessment gate.

This guide covers the practical route to passing an NHS DTAC assessment: the five areas you complete, the evidence you can reuse from standards you may already hold, and the points where suppliers stall. For what NHS DTAC is and who needs it, read the what is NHS DTAC explainer. The focus here is the how.

What an NHS DTAC assessment asks of you

DTAC is not a certificate you earn once. The buyer, a trust, an integrated care board or a social-care organisation, issues the assessment to you as part of its assurance. You complete the pack with evidence, and the buyer assesses it for its own procurement. There is no pass badge and no central register. Each buyer keeps its own record.

The pack consolidates five areas into one form:

  • C1 Clinical Safety. The clinical risk management evidence, built on DCB 0129 for the manufacturer and DCB 0160 for the deploying organisation.
  • C2 Data Protection. DPIA, lawful basis, ICO registration and data-security assurance.
  • C3 Technical Security. The security controls a buyer expects of a supplier handling health data.
  • C4 Interoperability. How your product exchanges data with NHS systems.
  • D1 Usability and Accessibility. Accessibility conformance and evidence that people can use the product safely.

How to pass an NHS DTAC assessment, step by step

1. Confirm DTAC applies and get the current form

DTAC applies to software-based digital health technologies sold to NHS or social-care organisations. Download the current form directly from the NHS Transformation Directorate. The updated form was published on 24 February 2026 and became mandatory from 6 April 2026, so an older version will be rejected. ``

2. Inventory the evidence you already hold

Before you touch the form, map what you have against the five areas. Much of the answer already exists in frameworks you may hold. Data protection draws on your UK and EU GDPR evidence and your NHS DSPT submission. Technical security draws on ISO 27001 or Cyber Essentials. Clinical safety draws on your DCB 0129 safety case. A supplier who holds those is most of the way through the pack before answering a single DTAC-specific question.

3. Complete C1 Clinical Safety

C1 rests on your DCB 0129 clinical safety case, your Hazard Log, and sign-off from a named Clinical Safety Officer. A supplier who has treated DTAC as a security exercise usually finds this the hardest area, because the safety case cannot be produced overnight.

C1 also carries a signposting question on medical device classification. You state where your product sits and, if it qualifies as a medical device, conformity marking is a separate matter governed by the MHRA under its own regime. DTAC records your position; it does not assess or grant device marking. The clinical-safety evidence DTAC asks for is the DCB 0129 safety case; device conformity is handled separately.

4. Complete C2 Data Protection

C2 covers your DPIA, your documented lawful basis, ICO registration, and where personal data is transferred. Where data moves outside the UK, complete a Transfer Impact Assessment and record the position. Much of the underlying assurance comes from a current DSPT, which defaults to Category 3 for most suppliers.

5. Complete C3 Technical Security

C3 maps onto an ISO 27001 information security management system or Cyber Essentials certification, which supply most of the evidence. The updated form expands on multi-factor authentication and secure development, referencing the Software Security Code of Practice. Document and evidence your access controls and development processes.

6. Complete C4 Interoperability

C4 asks how your product handles NHS Number validation, whether it uses NHS Login where relevant, and how its interfaces are justified. No single external standard supplies this wholesale. This area draws on your own product architecture; document the interfaces and the reasoning behind them.

7. Complete D1 Usability and Accessibility

D1 wants a WCAG 2.2 AA conformance statement backed by real testing, consideration of the Accessible Information Standard, and a User Journey Map. In the updated form D1 is no longer scored, but it is still reviewed and compared across products, and a tested statement carries more weight than an untested claim.

8. Review internally, submit, then keep the pack current

Review the completed pack against the five areas, then hand it to the buyer. You submit it; the buyer assesses it. Keep the pack in date so the next NHS buyer receives current evidence instead of prompting a fresh document chase.

How long an NHS DTAC assessment takes

DTAC is an assembly job. The timeline is governed by whether the underlying evidence exists, not by the length of the form. A supplier who holds a current DSPT, a DCB 0129 safety case, ISO 27001 or Cyber Essentials, and a tested WCAG 2.2 AA statement can complete the pack quickly. A supplier building those from scratch is gated by the slowest underlying standard, and the clinical safety case is usually it.

The updated form does help. The NHS Transformation Directorate reports roughly a quarter fewer questions and de-duplication against the DSPT and the pre-acquisition questionnaire, so evidence already provided elsewhere is not requested twice. ``

Where teams get stuck

  • No clinical safety case and no named CSO. The single most common hard stop. A supplier treating DTAC as a security review reaches C1 with nothing to submit.
  • DPIA gaps. No DPIA, a stale one, a missing lawful basis, or an undocumented transfer position.
  • No current DSPT. C2 leans on it for data-security assurance, and an expired toolkit weakens the whole area.
  • Untested accessibility. Asserting WCAG 2.2 AA conformance without testing evidence. D1 is reviewed even though it is no longer scored.
  • Rebuilding from scratch every time. Assembling the same evidence separately for each buyer and each framework, instead of proving it once and reusing it.
  • Thin interoperability justification. C4 left under-documented because it draws on product architecture rather than an external certificate.

How Naq assembles your NHS DTAC pack faster

DTAC's five areas map onto evidence a compliance platform can already hold. Naq links C2 to your GDPR and DSPT work, C3 to ISO 27001 and Cyber Essentials, and C1 to DCB 0129, so a control proved once counts across every area it maps to. Of the frameworks Naq covers, DTAC gains the most, because more of its evidence is already sitting in the other standards.

The judgement-heavy areas come with named people. In-house Clinical Safety Officers support C1 and virtual DPOs support C2, included in the platform rather than invoiced separately. Naq's clinical-safety support covers the DCB 0129 safety case and the CSO behind it. Device marking stays with the MHRA under a separate regime. Other providers offer clinical safety support too. Naq treats it as a genuine strength of the approach while making no claim to be the only provider that offers it.

There is no Naq-issued DTAC certificate, because none exists. Naq gets the pack assessment-ready and keeps the five areas current between buyers; you hand the completed pack to the buyer yourself. The AI assistant summarises and checks evidence on demand and is read-only by design, never editing the formal record.

"The Naq platform makes the whole process remarkably seamless to complete, offering intuitive means to easily share our compliance status."

Dr Taz Aldawoud, Founder & CEO, Doc Abode

Frequently asked questions

Is an NHS DTAC assessment pass or fail?

There is no pass badge, no central register and no DTAC certificate. Each buyer assesses your completed pack for its own procurement. A strong, current pack lets a buyer clear the assurance step quickly; a missing or out-of-date one holds the deal at the assessment gate.

Do I need medical device marking to pass an NHS DTAC assessment?

No. DTAC includes a signposting question where you state your product's medical device classification. If your product is a medical device, conformity marking is a separate regime governed by the MHRA. DTAC records your position; it does not assess or grant device marking.

Which evidence can I reuse across a DTAC pack?

Data protection reuses your GDPR evidence and DSPT submission for C2. Technical security reuses ISO 27001 or Cyber Essentials for C3. Clinical safety reuses your DCB 0129 safety case for C1. Holding those first turns most of the DTAC form into an assembly task.

What changed in the updated DTAC form?

The form published on 24 February 2026, mandatory from 6 April 2026, carries roughly a quarter fewer questions and de-duplicates against the DSPT and the pre-acquisition questionnaire. D1 Usability and Accessibility is no longer scored, though it is still reviewed comparatively across products.