Logo

Assuric

CQC Compliance for Tech-Enabled Clinical Services

A practical guide to CQC registration for healthtech companies, covering when it applies, what you need to submit, and ongoing compliance requirements.

CQC Compliance for Tech-Enabled Clinical Services

For established healthcare providers, Care Quality Commission (CQC) inspections and ongoing compliance are a familiar part of running a service. For healthtech companies, however, the registration and ongoing work needed to comply with the CQC standards is much less clear.

When software is used to deliver care, it's hard to tell whether CQC registration applies to you at all, and harder still to know what CQC registration and ongoing compliance involves. This guide covers when tech-enabled clinical services need to register with the CQC, what the application involves, and what you need in place afterwards.

When do healthtech companies need CQC registration?

Most healthtech companies don't need to register with CQC. You'll likely have plenty of other compliance work, from medical device regulation (MDR) and information security to NHS DTAC, DSPT and DCB0129. If you're only providing software into the NHS or other health services as part of an established care pathway, and you're not delivering care yourself (a regulated activity), CQC registration most likely isn't needed.

The key thing that decides whether you need CQC registration is whether your service carries out a regulated activity in England. We've written separately on the CQC compliance essentials, covering exactly what the 14 regulated activities are ⤵

Carrying out a regulated activity without being registered is a criminal offence under the Health and Social Care Act 2008, so it's worth getting this question right early. Note that CQC only covers England. If you deliver care in Scotland, Wales or Northern Ireland, you may need to register with Healthcare Improvement Scotland, Healthcare Inspectorate Wales or the RQIA.

Importantly, being a technology company does not put you outside CQC's scope. You might deliver your service entirely online, have no physical clinic, and use software to connect patients with clinicians, and still need to register.

Are you providing healthcare, or providing healthcare technology?

This is the question that resolves most cases.

Technology providers supply software, hardware or a platform to a procuring host healthcare organisation (such as into the NHS or a private healthcare provider). The host healthcare organisation employs the clinicians, makes the clinical decisions and holds responsibility for the patient - meaning the regulated activity is theirs. Your compliance requirements are more likely to span MDR, NHS DTAC, DSPT, DCB0129, UK GDPR and cybersecurity, but not CQC registration.

Tech-enabled healthcare providers use technology to deliver healthcare directly to patients as a provider (i.e. you are acting as the healthcare organisation). The clinicians are yours, the clinical decisions are yours, and the patient is your patient. You're a healthcare provider that happens to be built on software, and CQC registration is very likely to apply.

Questions to ask before deciding whether you need CQC registration

We’ve put together a few questions we’d recommend working through before CQC registration:

  1. Are you providing clinical care directly to patients?
  2. Are clinicians employed or contracted by your organisation?
  3. Is your organisation making clinical decisions or giving clinical advice?
  4. Are you diagnosing or screening patients?
  5. Are you treating a disease, disorder or injury?
  6. Are you prescribing or arranging the supply of medicines?
  7. Are you doing any of the above remotely?
  8. Who holds responsibility for the patient's care if something goes wrong?

The final question is key, as whoever holds clinical accountability is almost always the one who needs to be registered.

Do remote and virtual healthcare services need to register with CQC?

Yes, in most cases. Delivering care remotely doesn't take it out of CQC scope, and CQC publishes specific guidance for online and digital primary care providers because the model is now so common.

Remote services are also where CQC's expectations are least intuitive. A virtual service may still need an infection prevention and control lead. It still needs a medical emergency process. And it carries risks a physical clinic doesn't, starting with verifying who the patient actually is.

Expert tip: For a remote service, your medical emergency policy is really a safety netting and escalation policy. Set out when a clinician calls 999, what they say, and how you capture the patient's exact location mid-consultation. You'll need it if an ambulance is required.

What does CQC registration involve for tech-enabled clinical services?

CQC registration can involve a bit of back and forth with the CQC, but in general the process involves an application, an assessment by the CQC, and usually an interview. Head to this guidance for new providers for more detail on this.

CQC has been rolling out a stricter approach sector by sector during 2026: applications that aren't complete and accurate at submission are returned rather than queried. Submitting early to get in the queue no longer works, so it's worth waiting until your application is genuinely complete.

Here’s a quick overview of some of the things you’ll need to do during the registration process:

1. Identify your regulated activities

List the regulated activities your service carries out, such as Treatment of disease, disorder or injury, Diagnostic and screening procedures, or Nursing care. This determines whether you need to register and what evidence CQC expects.

2. Work out who needs to register

You’ll need a registered provider, Nominated Individual (NI) and Registered Manager (RM). The NI is a senior person (usually a director) who supervises the regulated activity on the provider's behalf, while the RM is responsible for its day-to-day management.

Expert tip: The Registered Manager application must be submitted alongside the provider application, so line up your RM (and their DBS) before you start. The service cannot be run without an RM in place.

3. Assemble your application

Prepare your provider application, Statement of Purpose, RM application, financial viability statement, insurance details, ICO registration and DBS evidence. Online primary care providers may also need to provide additional information on areas such as prescribing, identity verification and platform security.

Expert tip: Make sure your Statement of Purpose aligns with the rest of your application.

4. Prepare your policies and supporting evidence

New providers must submit consent and governance/quality assurance policies with their application. These should be specific to your service; the CQC has a clear list of what you need to put together depending on the service you provide.

Expert tip: Don’t rely on generic templates. Explain where a requirement doesn’t apply to your service rather than leaving gaps.

5. Complete the assessment and interview

CQC will assess your application and usually interview the Registered Manager to test their competence, experience, leadership and understanding of your governance arrangements.

Expert tip: Your RM should be able to explain your governance approach without simply reading from your policies.

What policies do healthtech providers usually need?

Unfortunately, there's no single official list, as the list of policies you need depends on the service you're offering.

For a remote clinical service, expect scrutiny on consent, safeguarding, governance, medicines management, records management, complaints, duty of candour, recruitment and training.

There are three remote-specific things that catch people out:

  • Safeguarding contacts - your policy needs local authority safeguarding contacts for every area you serve, not just your registered address, because referrals go by where the patient lives, not where the provider is geographically registered as a location.
  • Lone working - note that this isn't only about home visits. It covers clinicians working remotely and alone: check-in arrangements, escalation if someone is unreachable, and handling abusive calls.
  • Remote prescribing - your medicines policy should cover identity verification, limits on controlled and high-risk drugs, your formulary restrictions, and how you notify the patient's own GP, including what happens if they don't consent to that.

What happens after CQC registration?

Ongoing obligations include:

  • Maintaining governance arrangements, with evidence they're running
  • Monitoring quality and safety, including audit and patient feedback
  • Managing incidents, complaints and duty of candour, with learning shared
  • Keeping policies current and dated, with named reviewers
  • Maintaining staff competency, training and supervision records
  • Submitting statutory notifications, including changes to your Statement of Purpose
  • Completing the Provider Information Return (PIR) when requested

Expert tip: Governance without dated minutes is unevidenced. The same goes for audits. One that found something and shows closed actions is more convincing than one with no findings, which reads as box-ticking.

How does CQC fit with other healthtech compliance requirements?

CQC doesn't replace any of the other requirements, and if you're selling into the NHS while delivering regulated care you're probably managing several other compliance requirements.

As a clinical service you should also be aware of your data protection and information security requirements (together, information governance), including UK GDPR and recognised cyber security frameworks such as Cyber Essentials. And if you're deploying your own clinical software to deliver care for NHS patients, you'll typically need to meet both DCB0129 (as the manufacturer) and DCB0160 (as the organisation deploying it).

How Assuric helps with CQC compliance

As your service grows you'll be managing clinical safety, data protection, cybersecurity and quality management, alongside clinical governance, often for the same evidence, in several different places. And that's where Assuric comes in.

→ CQC registration mapped into clear tasks. The platform breaks registration requirements and ongoing compliance work into simple tasks, with expert guidance and tips attached to each one.

→ A complete policy set. Policies and templates built for tech-enabled / digital service providers, then tailored to your specific set up.

→ One source of truth across all compliance frameworks. CQC alongside QMS, DTAC, DSPT, DCB0129/0160, GDPR, Cyber Essentials and ISO standards, with duplicated evidence handled once rather than framework by framework.

→ Live registers, logs and audits. Clinical risk, information security risk, incidents, complaints and audits in a system that shows they're current, rather than a folder that shows they existed.

→ Evidence and documentation support. We can help you put together all required policies and other documentation needed for registration

→ People training and management. Use Assuric to manage all people compliance and records, from collecting DBS checks and right to work information, to the completion of statutory and mandatory training.

Still working out whether CQC registration applies to your service? Get in touch or book a demo to find out more about how Assuric can help.


Make your life easier
and talk to us to simplify compliance

Goodbye manual processes, hello automation. Let Assuric manage compliance and security, so you can focus on growth.

CTA Image