No. Naq is modular, and the areas you use are set by your subscription. You can start with a single framework or module and add others as your compliance needs grow, rather than taking on everything at once.
Yes. Naq includes a vendor register for the software, services and hardware suppliers you rely on. Many vendors auto-populate from Naq's verified catalogue, and you can record business criticality, contract dates and whether a Data Processing Agreement is in place, with a link to the executed DPA. A vendor's risk level is derived from the risks linked to it, so gaps are easy to see. The register tracks vendors and is not a procurement system.
Yes. Naq has a single register for corrective and preventive actions (CAPA). Each action records its source, its finding type and a documented root cause, and moves through a simple lifecycle from open to in progress to closed. You can add action items with owners and target dates, link a CAPA to the risks, hazards or incidents it relates to, and see overdue actions surfaced in the register.
Yes. You can write a policy in Naq's editor, upload an existing document, or start from a template in Naq's library. Documents follow a clear approval workflow with an owner and an approver, and mandatory comments at each step. Versioning tracks every change, a review date is set at approval, and the full history is available to download. Approved documents can then serve as evidence against the controls they support.
Every record in Naq keeps a full history. Actions are logged in a chronological activity stream, and any change to a record shows the previous and new value. Nothing is hard deleted; items are archived so the trail stays intact. Documents are versioned with their approvals preserved, and every record carries a clear, human-readable reference such as CTL-001 or RISK-001. When an auditor asks how something was decided or when it changed, the answer is already in the record.
Naq connects your frameworks, requirements, controls and evidence in one chain. When a control satisfies a requirement, it counts towards every framework that shares it, so a single policy or piece of evidence can support ISO 27001, Cyber Essentials, NHS DSPT and more at the same time. You map the work once and see it counted everywhere, which removes the effort of evidencing each standard on its own.
Naq brings the frameworks behind DTAC into one platform, including NHS DSPT, DCB 0129 clinical safety, Cyber Essentials and GDPR. The evidence you produce for one requirement is mapped across every framework it satisfies, so you prove it once rather than rebuilding it for each submission. A Clinical Safety Officer is included to support the DCB 0129 element, and every policy, control and piece of evidence sits in one auditable record. That keeps DTAC manageable alongside the rest of your compliance, so your team stays focused on the product.
The NHS provides various online toolkits, resources, and guidelines to help innovators meet DTAC compliance. Industry associations and networks offer advice and support, while health innovation networks and accelerators like the NHS Innovation Accelerator support innovators, particularly in areas like compliance, to accelerate market entry.
Failing to meet DTAC standards doesn’t permanently bar you from achieving compliance or selling to the NHS. You can make the necessary changes highlighted by the procurement team and reapply. However, repeated submissions can lead to delays and increased costs, hindering market entry. Partnering with someone experienced in navigating NHS requirements can streamline the process and reduce the chance of repeated submissions.
Implementing DTAC early in your product lifecycle is crucial. If you aim to sell to the NHS or other organisations following NHS guidelines, consider compliance with DTAC, DSPT, and Cyber Essentials from the outset. Building security measures into your product from the beginning ensures ongoing compliance with GDPR and DSPT, preventing the need for costly and time-consuming retroactive changes.
The cost of DTAC compliance varies with how much of your evidence is already in place and whether you handle it internally or bring in support. NHS England does not set a fixed time or cost. If you are completing it yourself for the first time, plan for several weeks of focused work across clinical safety, data protection and technical security. Penetration testing is usually charged as a day rate, in the region of £1,000 to £2,500 for a CREST-certified tester depending on scope, and Cyber Essentials certification is priced by organisation size. If you bring in outside support, costs vary widely with scope, so ask for a fixed quote.
The time and effort required can vary significantly depending on the complexity of your digital health technology and current compliance status. It typically involves a thorough review, information and evidence gathering, and working through all five pillars of the DTAC. Generally, innovators can comply within 3-6 months.
DTAC applies to digital health technologies intended for use within the NHS. This includes software, apps, and platforms that handle patient data, support clinical decisions, or provide digital health services.
A good place to start with DTAC is with the clinical risk management element. Setting up clinical risk management processes from the very start of your product’s life cycle is crucial. Next, focus on formulating your information security and privacy policies and procedures to ensure that information security risks are addressed early, and technical security measures are integrated from the beginning.
Completing DTAC isn’t a “one-off” process; it’s an ongoing compliance requirement. It is assessed at the point of procurement by the NHS and should be implemented from the start of a digital health product’s lifecycle. Digital health technologies should undergo a DTAC assessment whenever there are significant updates or changes to the technology. Continuous evaluation is crucial to maintaining compliance and ensuring patient safety.
DTAC assesses digital health technologies to identify potential risks or shortcomings, safeguarding patients from unsafe or ineffective solutions and ensuring they receive reliable, high-quality care. For example, DTAC requires manufacturers or innovators to appoint a clinical safety officer who understands clinical risk and can assess products against potential clinical hazards that may impact patients.
DTAC enhances patient safety and improves healthcare outcomes. If a digital health product lacks in any of the five areas that DTAC assesses, there’s an increased risk of negative outcomes such as cyberattacks, data breaches, clinical incidents, or exclusion of patients with certain accessibility needs. DTAC provides a standardised assessment framework, ensuring that all digital health technologies used within the NHS meet rigorous criteria.
DTAC stands for Digital Technology Assessment Criteria. The DTAC is a vital framework used by the NHS to evaluate digital health innovations based on five key criteria: Clinical Safety, Data Protection, Technical Security, Interoperability, and Usability and Accessibility. It ensures that digital technology procured by the NHS is secure, technically sound, clinically safe, and accessible for everyone.
The DSPT has three compliance levels:
Approaching Standards: You’ve met some requirements and are working towards full compliance.
Standards Met: You’ve met all required criteria.
Standards Exceeded: You’ve gone above and beyond, often due to additional certifications like ISO 27001 or Cyber Essentials Plus.
Failure to meet the standards will be reflected in the publicly accessible DSPT database, indicating your organisation's compliance status for the year. Likewise, your status will also be reflected in the database if you meet or exceed standards.
Two challenging aspects for innovators are:
In a cloud-first world, cybersecurity is foundational to all other forms of compliance. NHS suppliers, eHealth and social care providers, and any organisation managing NHS data must comply with DSPT. Meeting DSPT standards ensures that an organisation handles data securely, adheres to legal and regulatory requirements, and plays a vital role in maintaining trust and safeguarding patient data within the NHS ecosystem.
Yes, Article 25 of the UK GDPR mandates data protection by design and by default, meaning data protection measures should be integrated from the beginning of business processes, systems, and product development. For organisations working with the NHS, it's advisable to build these requirements into your product from the start, including cybersecurity measures like encryption and regular security testing, to ensure your product is secure and compliant.
Submitting the DSPT is free. However, achieving compliance may require investment in security measures, staff training, and possibly external consultancy. Costs vary widely. Penetration testing is usually charged as a day rate, in the region of £1,000 to £2,500 for a CREST-certified tester depending on scope. Cyber Essentials certification runs from £300 to £500 plus VAT depending on your size, and Cyber Essentials Plus, which adds a hands-on technical audit, costs more. External consultancy fees can range from a few thousand to tens of thousands of pounds.
The time and effort required depend on the size, complexity, and existing security maturity of your organisation. Starting from scratch may take around 200 hours to implement the standard's requirements, more for complex organisations or products. It's important to continuously maintain and update your policies, controls, and processes throughout the year, not just for the deadline.
Begin by familiarising yourself with the DSPT criteria, which can be downloaded from the NHS website. Conduct a gap analysis to assess your current security measures, identify areas where you need external help, and create a timeline for implementing necessary changes. Regularly review your progress and adjust as new requirements emerge.
You submit the DSPT once a year, with a deadline of 30 June. For the current 2025-26 year, that means completing your submission by 30 June 2026. Maintaining DSPT compliance is an ongoing process that needs year-round attention, and the toolkit changes each year to address evolving threats, so it is important to stay up to date and keep meeting new requirements.
The DSPT is fundamental to patient safety in two ways:
Penetration tests, or ethical hacking, are critical for verifying your organisation's security. There are three types of penetration tests required by the NHS, depending on your risk profile:
GDPR is a legal requirement; non-compliance is illegal. The UK GDPR sets the standard for data protection across the UK, and the DSPT incorporates GDPR requirements to ensure organisations meet legal standards of data privacy and security. This includes practices like data minimisation, strong access controls, and ensuring the rights of data subjects are protected. Most health innovators must also meet additional GDPR requirements for processing special categories of data.
The DSPT is now aligned to the National Cyber Security Centre's Cyber Assessment Framework (CAF). The current version, DSPT v8, covers the 2025-26 year and was released on 18 September 2025, mapping to CAF version 3.4. There are two versions. Larger NHS organisations, such as trusts, integrated care boards, arm's length bodies and commissioning support units, complete the CAF-aligned DSPT and must back it with an independent assessment. IT suppliers and smaller organisations, including GP practices, pharmacies, dentists and social care providers, complete the standards-based version. Both go through the same toolkit, and the deadline is 30 June each year.
No, DTAC is focused on specific technical products being implemented in an NHS organisation, while DSPT is concerned with the overall security and privacy status of your company. However, DSPT covers essential measures such as data protection, technical security, incident management, staff training, and information governance.
It's straightforward. If you supply anything to the NHS that processes any form of data, including usernames and email addresses, you need to meet the DSPT requirements. To confirm your need for DSPT, you can visit the relevant NHS resources.
The DSPT is crucial because it ensures that patient data is handled securely, protecting patient privacy and trust. In their 2023 to 2030 cyber security strategy, the Department of Health and Social Care and NHS England identified ransomware as the most significant threat to the sector, and set the goal of every health and care organisation reaching cyber resilience by 2030. The DSPT enables NHS suppliers and the NHS itself to maintain a strong cybersecurity posture.
The 10 standards are mandatory standards for all health and social care providers, including their suppliers. They are divided into three overarching pillars: people, processes, and technology. These standards cover fundamental cybersecurity measures, such as training, business continuity planning, access controls, monitoring, and continuous improvement.
The DSPT stands for the Data Security and Protection Toolkit. Previously known as the Information Governance (IG) Toolkit, it's an online assessment tool that allows organisations to measure their performance against the National Data Guardian’s 10 data security standards. It verifies compliance with cybersecurity and privacy requirements. The NHS uses it to ensure that organisations handle data securely and meet their legal obligations. The DSPT assesses compliance across several key areas, including data protection, confidentiality, information security, staff training, incident management, and technical security.
Naq supports:
GDPR (UK and EU)
Cyber Essentials
Cyber Essentials Plus
NHS DSPT
NHS DTAC
DCB 0129
ISO 27001
ISO 9001
Custom frameworks, plus multiple instances of the same framework
Naq is built for startups, SMEs, enterprises and government suppliers that need to meet demanding compliance standards without the cost and complexity that usually comes with them. Whether you are laying your first foundations or consolidating several standards into one platform, Naq scales with you and keeps every framework in a single, auditable place.
Naq’s platform automates the creation of policies, procedures, and training essential for compliance with your chosen standards and streamlines the collection and management of your compliance evidence. Additionally, Naq acts as your organisation's compliance hub, enabling you to manage all compliance-related processes from one single platform. Automate risk assessments, generate Data Protection Impact Assessments (DPIAs), train your team, and manage audit findings to build and enhance your quality management system (QMS) - all through Naq.
Naq is an automated compliance platform that helps regulated SMEs across the UK and Europe achieve and maintain compliance from one place. It covers the frameworks these organisations are most often asked for, including GDPR, Cyber Essentials and Cyber Essentials Plus, NHS DSPT, NHS DTAC, DCB 0129, ISO 27001 and ISO 9001, plus custom frameworks. Manage policies, controls, evidence, risk, clinical safety and training in a single platform, with every action logged and auditable, and prove each requirement once across every framework it satisfies.