FAQs

No. Naq  is modular, and the areas you use are set by your subscription. You can start  with a single framework or module and add others as your compliance needs  grow, rather than taking on everything at once.

Yes. Naq  includes a vendor register for the software, services and hardware suppliers  you rely on. Many vendors auto-populate from Naq's verified catalogue, and  you can record business criticality, contract dates and whether a Data  Processing Agreement is in place, with a link to the executed DPA. A vendor's  risk level is derived from the risks linked to it, so gaps are easy to see.  The register tracks vendors and is not a procurement system.

Yes. Naq  has a single register for corrective and preventive actions (CAPA). Each  action records its source, its finding type and a documented root cause, and  moves through a simple lifecycle from open to in progress to closed. You can  add action items with owners and target dates, link a CAPA to the risks,  hazards or incidents it relates to, and see overdue actions surfaced in the  register.

Yes. You  can write a policy in Naq's editor, upload an existing document, or start  from a template in Naq's library. Documents follow a clear approval workflow  with an owner and an approver, and mandatory comments at each step.  Versioning tracks every change, a review date is set at approval, and the  full history is available to download. Approved documents can then serve as  evidence against the controls they support.

Every  record in Naq keeps a full history. Actions are logged in a chronological  activity stream, and any change to a record shows the previous and new value.  Nothing is hard deleted; items are archived so the trail stays intact.  Documents are versioned with their approvals preserved, and every record  carries a clear, human-readable reference such as CTL-001 or RISK-001. When  an auditor asks how something was decided or when it changed, the answer is  already in the record.

Naq  connects your frameworks, requirements, controls and evidence in one chain.  When a control satisfies a requirement, it counts towards every framework  that shares it, so a single policy or piece of evidence can support ISO  27001, Cyber Essentials, NHS DSPT and more at the same time. You map the work  once and see it counted everywhere, which removes the effort of evidencing  each standard on its own.

Naq brings  the frameworks behind DTAC into one platform, including NHS DSPT, DCB 0129  clinical safety, Cyber Essentials and GDPR. The evidence you produce for one  requirement is mapped across every framework it satisfies, so you prove it  once rather than rebuilding it for each submission. A Clinical Safety Officer  is included to support the DCB 0129 element, and every policy, control and  piece of evidence sits in one auditable record. That keeps DTAC manageable  alongside the rest of your compliance, so your team stays focused on the  product.

The NHS provides various online toolkits, resources, and guidelines to help innovators meet DTAC compliance. Industry associations and networks offer advice and support, while health innovation networks and accelerators like the NHS Innovation Accelerator support innovators, particularly in areas like compliance, to accelerate market entry.

Failing to meet DTAC standards doesn’t permanently bar you from achieving compliance or selling to the NHS. You can make the necessary changes highlighted by the procurement team and reapply. However, repeated submissions can lead to delays and increased costs, hindering market entry. Partnering with someone experienced in navigating NHS requirements can streamline the process and reduce the chance of repeated submissions.

Implementing DTAC early in your product lifecycle is crucial. If you aim to sell to the NHS or other organisations following NHS guidelines, consider compliance with DTAC, DSPT, and Cyber Essentials from the outset. Building security measures into your product from the beginning ensures ongoing compliance with GDPR and DSPT, preventing the need for costly and time-consuming retroactive changes.

The cost  of DTAC compliance varies with how much of your evidence is already in place  and whether you handle it internally or bring in support. NHS England does  not set a fixed time or cost. If you are completing it yourself for the first  time, plan for several weeks of focused work across clinical safety, data  protection and technical security. Penetration testing is usually charged as  a day rate, in the region of £1,000 to £2,500 for a CREST-certified tester  depending on scope, and Cyber Essentials certification is priced by  organisation size. If you bring in outside support, costs vary widely with  scope, so ask for a fixed quote.

The time and effort required can vary significantly depending on the complexity of your digital health technology and current compliance status. It typically involves a thorough review, information and evidence gathering, and working through all five pillars of the DTAC. Generally, innovators can comply within 3-6 months.

  1. Clinical Safety: DCB 129 is the clinical risk management standard required by the DTAC , ensuring digital health technologies are safe for clinical use and don’t introduce new clinical risks.
  2. Data Protection: Involves compliance with the GDPR and NHS DSPT, ensuring data is handled securely.
  3. Technical Security: Demonstrates that measures are in place to protect the solution from cyberattacks, requiring evidence such as penetration testing and adherence to Cyber Essentials.
  4. Interoperability: Ensures the technology can seamlessly communicate and exchange data across the NHS, benefiting patient care.
  5. Usability and Accessibility: Ensures the product is compliant with NHS standards for accessibility and usability, creating inclusive products that are easy to use for all patients and users.

DTAC applies to digital health technologies intended for use within the NHS. This includes software, apps, and platforms that handle patient data, support clinical decisions, or provide digital health services.

A good place to start with DTAC is with the clinical risk management element. Setting up clinical risk management processes from the very start of your product’s life cycle is crucial. Next, focus on formulating your information security and privacy policies and procedures to ensure that information security risks are addressed early, and technical security measures are integrated from the beginning.

Completing DTAC isn’t a “one-off” process; it’s an ongoing compliance requirement. It is assessed at the point of procurement by the NHS and should be implemented from the start of a digital health product’s lifecycle. Digital health technologies should undergo a DTAC assessment whenever there are significant updates or changes to the technology. Continuous evaluation is crucial to maintaining compliance and ensuring patient safety.

DTAC assesses digital health technologies to identify potential risks or shortcomings, safeguarding patients from unsafe or ineffective solutions and ensuring they receive reliable, high-quality care. For example, DTAC requires manufacturers or innovators to appoint a clinical safety officer who understands clinical risk and can assess products against potential clinical hazards that may impact patients.

DTAC enhances patient safety and improves healthcare outcomes. If a digital health product lacks in any of the five areas that DTAC assesses, there’s an increased risk of negative outcomes such as cyberattacks, data breaches, clinical incidents, or exclusion of patients with certain accessibility needs. DTAC provides a standardised assessment framework, ensuring that all digital health technologies used within the NHS meet rigorous criteria.

DTAC  stands for Digital Technology Assessment Criteria. The DTAC is a vital  framework used by the NHS to evaluate digital health innovations based on  five key criteria: Clinical Safety, Data Protection, Technical Security,  Interoperability, and Usability and Accessibility. It ensures that digital  technology procured by the NHS is secure, technically sound, clinically safe,  and accessible for everyone.

The DSPT has three compliance levels:

Approaching Standards: You’ve met some requirements and are working  towards full compliance.

Standards Met: You’ve met all required criteria.

Standards Exceeded: You’ve gone above and beyond, often due to additional  certifications like ISO 27001 or Cyber Essentials Plus.

Failure to meet the  standards will be reflected in the publicly accessible DSPT database,  indicating your organisation's compliance status for the year. Likewise, your  status will also be reflected in the database if you meet or exceed  standards.

Two challenging aspects for innovators are:

  1. Supplier Management: DSPT requires organisations to verify their suppliers' security certifications and compliance with relevant data protection standards, often through due diligence questionnaires.
  2. DPIA (Data Protection Impact Assessments): DPIAs are a requirement under GDPR, requiring organisations to assess risks to individuals' rights and freedoms when processing data. The detailed documentation and continuous review required for DPIAs can be time-consuming and complex, especially for those new to the process.

In a cloud-first world, cybersecurity is foundational to all other forms of compliance. NHS suppliers, eHealth and social care providers, and any organisation managing NHS data must comply with DSPT. Meeting DSPT standards ensures that an organisation handles data securely, adheres to legal and regulatory requirements, and plays a vital role in maintaining trust and safeguarding patient data within the NHS ecosystem.

Yes, Article 25 of the UK GDPR mandates data protection by design and by default, meaning data protection measures should be integrated from the beginning of business processes, systems, and product development. For organisations working with the NHS, it's advisable to build these requirements into your product from the start, including cybersecurity measures like encryption and regular security testing, to ensure your product is secure and compliant.

Submitting  the DSPT is free. However, achieving compliance may require investment in  security measures, staff training, and possibly external consultancy. Costs  vary widely. Penetration testing is usually charged as a day rate, in the  region of £1,000 to £2,500 for a CREST-certified tester depending on scope.  Cyber Essentials certification runs from £300 to £500 plus VAT depending on  your size, and Cyber Essentials Plus, which adds a hands-on technical audit,  costs more. External consultancy fees can range from a few thousand to tens  of thousands of pounds.

The time and effort required depend on the size, complexity, and existing security maturity of your organisation. Starting from scratch may take around 200 hours to implement the standard's requirements, more for complex organisations or products. It's important to continuously maintain and update your policies, controls, and processes throughout the year, not just for the deadline.

Begin by familiarising yourself with the DSPT criteria, which can be downloaded from the NHS website. Conduct a gap analysis to assess your current security measures, identify areas where you need external help, and create a timeline for implementing necessary changes. Regularly review your progress and adjust as new requirements emerge.

You submit  the DSPT once a year, with a deadline of 30 June. For the current 2025-26  year, that means completing your submission by 30 June 2026. Maintaining DSPT  compliance is an ongoing process that needs year-round attention, and the  toolkit changes each year to address evolving threats, so it is important to  stay up to date and keep meeting new requirements.

The DSPT is fundamental to patient safety in two ways:

  1. It ensures that suppliers and those handling health and social care data have the necessary security controls to reduce the risk of cyberattacks and data breaches.
  2. By implementing the data protection requirements of the NHS DSPT, organisations can guarantee that patients' rights as data subjects are respected, including transparency in data usage and ensuring that only necessary data is collected and kept secure.

Penetration tests, or ethical hacking, are critical for verifying your organisation's security. There are three types of penetration tests required by the NHS, depending on your risk profile:

  1. Infrastructure Pen Testing: Ensures attackers cannot access your IT network, servers, and computers.
  2. Application/Product Testing: Protects web applications, online pharmacies, websites, etc., from unauthorised access and modification.
  3. API Security Testing: Ensures that APIs used in NHS operations are secure and cannot be exploited by hackers.

GDPR is a  legal requirement; non-compliance is illegal. The UK GDPR sets the standard  for data protection across the UK, and the DSPT incorporates GDPR  requirements to ensure organisations meet legal standards of data privacy and  security. This includes practices like data minimisation, strong access  controls, and ensuring the rights of data subjects are protected. Most health  innovators must also meet additional GDPR requirements for processing special  categories of data.

The DSPT  is now aligned to the National Cyber Security Centre's Cyber Assessment  Framework (CAF). The current version, DSPT v8, covers the 2025-26 year and  was released on 18 September 2025, mapping to CAF version 3.4. There are two  versions. Larger NHS organisations, such as trusts, integrated care boards,  arm's length bodies and commissioning support units, complete the CAF-aligned  DSPT and must back it with an independent assessment. IT suppliers and  smaller organisations, including GP practices, pharmacies, dentists and  social care providers, complete the standards-based version. Both go through  the same toolkit, and the deadline is 30 June each year.

No, DTAC is focused on specific technical products being implemented in an NHS organisation, while DSPT is concerned with the overall security and privacy status of your company. However, DSPT covers essential measures such as data protection, technical security, incident management, staff training, and information governance.

It's straightforward. If you supply anything to the NHS that processes any form of data, including usernames and email addresses, you need to meet the DSPT requirements. To confirm your need for DSPT, you can visit the relevant NHS resources.

The DSPT  is crucial because it ensures that patient data is handled securely,  protecting patient privacy and trust. In their 2023 to 2030 cyber security  strategy, the Department of Health and Social Care and NHS England identified  ransomware as the most significant threat to the sector, and set the goal of  every health and care organisation reaching cyber resilience by 2030. The  DSPT enables NHS suppliers and the NHS itself to maintain a strong  cybersecurity posture.

The 10 standards are mandatory standards for all health and social care providers, including their suppliers. They are divided into three overarching pillars: people, processes, and technology. These standards cover fundamental cybersecurity measures, such as training, business continuity planning, access controls, monitoring, and continuous improvement.

The DSPT stands for the Data Security and Protection Toolkit. Previously known as the Information Governance (IG) Toolkit, it's an online assessment tool that allows organisations to measure their performance against the National Data Guardian’s 10 data security standards. It verifies compliance with cybersecurity and privacy requirements. The NHS uses it to ensure that organisations handle data securely and meet their legal obligations. The DSPT assesses compliance across several key areas, including data protection, confidentiality, information security, staff training, incident management, and technical security.

Naq supports:

GDPR (UK and EU)

Cyber Essentials

Cyber Essentials Plus

NHS DSPT

NHS DTAC

DCB 0129

ISO 27001

ISO 9001

Custom frameworks, plus multiple instances of the same framework

Naq is  built for startups, SMEs, enterprises and government suppliers that need to  meet demanding compliance standards without the cost and complexity that  usually comes with them. Whether you are laying your first foundations or  consolidating several standards into one platform, Naq scales with you and  keeps every framework in a single, auditable place.

Naq’s platform automates the creation of policies, procedures, and training essential for compliance with your chosen standards and streamlines the collection and management of your compliance evidence. Additionally, Naq acts as your organisation's compliance hub, enabling you to manage all compliance-related processes from one single platform. Automate risk assessments, generate Data Protection Impact Assessments (DPIAs), train your team, and manage audit findings to build and enhance your quality management system (QMS) - all through Naq.

Naq is an  automated compliance platform that helps regulated SMEs across the UK and  Europe achieve and maintain compliance from one place. It covers the  frameworks these organisations are most often asked for, including GDPR,  Cyber Essentials and Cyber Essentials Plus, NHS DSPT, NHS DTAC, DCB 0129, ISO  27001 and ISO 9001, plus custom frameworks. Manage policies, controls,  evidence, risk, clinical safety and training in a single platform, with every  action logged and auditable, and prove each requirement once across every  framework it satisfies.