Logo

Assuric

Framework

NHS DTAC

Seamlessly meet all of the NHS Digital Technology Assessment Criteria requirements

Framework

NHS DTAC
compliance

The Digital Technology Assessment Criteria (DTAC) brings together legislation and best practices in five key areas: clinical safety, data protection, technical security, interoperability and usability and accessibility. By meeting the DTAC standards, both the NHS and patients can have confidence in your product.

Request a demo

NHS DTAC

NHS Digital Technology Assessment Criteria

70%71 tasks
Not started (16)
In progress (5)
Completed (50)

We are trusted by

  • Kanjo
  • Rosenfield
  • VitVio
  • Megi Your Health Assistant
  • Tandem
  • Chequp
  • Rhades
  • Joy
  • ONION AI
  • Heim
  • Think Divergent
  • Theta
  • Healthnix
  • Kanjo
  • Rosenfield
  • VitVio
  • Megi Your Health Assistant
  • Tandem
  • Chequp
  • Rhades
  • Joy
  • ONION AI
  • Heim
  • Think Divergent
  • Theta
  • Healthnix
Product

How Assuric can help

Our platform includes a full DTAC service and we can ensure you pass the NHS DTAC assessment with flying colours, in a fraction of the time it would otherwise take you. Accelerate your compliance journey to meet the five pillars of DTAC:

Clinical Safety

Comply with the mandatory DCB0129 framework by completing deliverable documentation such as your Clinical Risk Management Plan, Clinical Safety Case Report and Hazard Log. Work with our expert Clinical Safety Officers for ad-hoc advice or a fully managed consultancy service.

Clinical Safety

Data Protection

Achieve GDPR compliance and complete the NHS Data Security and Protection Toolkit (DSPT). Complete your Record of Processing Activities, Information Asset Register and NHS Data Protection Impact Assessments. Work with our expert Data Protection Officers, and undertake our Data Protection Training.

Data Protection

Technical Security

Achieve Cyber Essentials (and Cyber Essentials Plus) certification. Book a scoping call with our expert team, establish security controls and get certified.

Technical Security

Interoperability

Understand your interoperability approach to provide a seamless care journey. Work with our team to create your interoperability strategy, and get support with EHR integration and product APIs.

Interoperability

Usability and Accessibility

Ensure your tech meets accessibility guidelines WCAG2.2 AA. Map user journeys, and undergo user acceptance testing. Use our templates to create an Accessibility Statement.

Usability and Accessibility

Map to other frameworks

Use intelligent automation and AI to avoid duplication of work, easily meeting requirements in tandem.

Map to other frameworks
FAQS

Frequently Asked Questions

Get in touch if we haven’t answered your question below, we are always happy to help!

What is the DTAC?

NHS DTAC was introduced in 2021 by NHSX (now part of NHS England), and is a national baseline criteria for digital health technologies, to be used by healthcare organisations to assess suppliers. You can think of it as a larger framework of multiple smaller risk management frameworks, separated into five sections.

What are the five sections of the NHS DTAC?

  • Clinical Safety: complete your DCB0129 with a registered Clinical Safety Officer as per the Health and Social Care Act, 2012
  • Data Protection: become GDPR compliant with the Data Security and Protection Toolkit (DSPT)
  • Technical security: complete your UK Cyber Essentials certification
  • Interoperability: ensure interoperability with existing NHS systems
  • Usability and accessibility: ensure your platform meets the needs of all patients

Is DTAC mandatory?

Yes, the Digital Technology Assessment Criteria (DTAC) is a mandatory requirement for all digital health technologies for procurement by the NHS, and a significant proportion of the DTAC form is made up of legislation.

Is DTAC required for pilots?

Yes, even initial pilots require completion of the DTAC form.

Is DTAC a certification process?

No, the NHS, nor other organisations, can issue DTAC certification, but using our platform will ensure all the requirements are met.

Clinical Safety?

Ensuring clinical safety is essential when introducing new digital health technologies. There are two key standards in the NHS: DCB0129 and DCB0160. Although very similar in content, DCB0129 is for the Manufacturer of Health IT Systems, whereas DCB0160 is for the Health Organisation (such as the NHS Trust where the product will be deployed). To comply with such standards, the clinical safety team must complete a Clinical Risk Management Plan, a Hazard Log and a Clinical Safety Case Report. Clinical safety is a continuous process, and it is important to have monitoring post deployment of the system.

Please contact us for additional advice on completing DCB0129, or on Clinical Safety Officers.

Data Protection?

Data protection is an important component of DTAC. To comply companies must ensure they are compliant with GDPR by registering with the ICO and appointing a Data Protection Officer and Senior Information Risk Owner. Companies must complete key documentation, including a privacy notice, Information Asset Register and a Record of Processing Activities (also known as an Article 30 register). You must have a valid legal basis under GDPR Article 6 in order to process any personal data, and additional justification under Article 9 if the data includes Special Category Data (such as health data). A Data Protection Impact Assessment must also be completed for any Special Category Data.

For NHS procurement, companies must complete the Digital Security Protection Toolkit, which includes GDPR compliance and Cyber Essentials compliance. This also involves an external penetration test (which we can provide).

Please contact us for any additional advice on Data Protection.

Technical Security?

To comply with the technical security aspect of DTAC, a company must complete UK Cyber Essentials, which involves a self assessment of your company’s technical security. For procurement, it is recommended to complete Cyber Essentials Plus, which involves both a self assessment and an External Audit. For NHS procurement, companies must complete the Digital Security Protection Toolkit, which includes GDPR compliance and Cyber Essentials compliance. This also involves an external penetration test (which we can provide).

Contact us for further advice on Technical Security.

Interoperability?

To provide a seamless care journey, it is important that relevant technologies in the health and social care system are interoperable, in terms of hardware, software and the data contained within. Those technologies that need to interface within clinical record systems must also be interoperable. Application Programme Interfaces (APIs) should follow the Government Digital Services Open API Best Practices, be documented and freely available and third parties should have reasonable access in order to integrate technologies.

While some NHS trusts may request implementation of interoperability to enable a pilot of your innovation, simply having the strategy with awareness and proof of readiness to integrate is sufficient to pass the DTAC . The key part of this strategy is that it must be clear and understandable for the assessors at the NHS trust.

For more advice on interoperability, please contact us.

Usability and Accessibility?

Usability and accessibility is about ensuring everyone can access the services they need, regardless of background, identity or circumstances. It is important to make sure people with different physical, mental health, social, cultural or learning needs can use your digital health technology, whether it's for the public or staff. This includes people who do not have access to the internet or lack the skills or confidence to use it. An essential part of this is creating a User Journey Map, while meeting accessibility standards including WCAG2.2 AA and the 2018 accessibility regulations.

testimonials

What Our Customers Say

Compliance is complex, but our AI tools simplify it. Discover features to stay ahead of regulations.

Kelly Klifa
Heim

Kelly Klifa

CEO at Heim

Assuric has been transformative for Heim as we looked to achieve DCB0129 and DTAC compliance. The platform is easy to use, and the AI tools and automated reminders make previously dreaded compliance tasks a breeze. Paul and Matt supported us every step of the way.

Katie Baker
Tandem

Katie Baker

Director UK & Ireland at Tandem

Assuric has been fantastic in helping us quickly and safely navigate regulatory compliance in the UK. From completing Cybersecurity requirements to DSPT, DCB0129, and DTAC, the team was supportive, extremely knowledgeable, and the platform made everything quick and straightforward. A separate regulatory company we consulted at the beginning even remarked on how quickly we achieved compliance!

Maks Kozarzewski
VitVio

Maks Kozarzewski

COO at VitVio

We couldn't speak highly enough of both the Assuric team and the platform itself, which is incredibly easy to use, and with the skill and hardworking nature of the Assuric team. They've been a key component in accelerating our progress and deployments!

Maja Mazur
Healthnix

Maja Mazur

CEO at Healthnix

Assuric has been such a blessing in getting our DTAC and GDPR compliance done - completing all the documentation and deciding what needs to be done whilst running the business is very hard, but the team really helped us through that. The platform is easy to use, helps keep track of things and it even allows us to coordinate all the team training easily. Highly recommend them!

Dean Mawson
DPM

Dean Mawson

Clinical Director at DPM

Assuric streamlines the process of achieving and maintaining compliance with DCB0129 standards for digital health technologies. The user-friendly interface simplifies collaboration across multidisciplinary teams, while the built-in templates and workflows save significant time and effort during compliance projects. Assuric’s ability to centralise documentation and provide real-time visibility into project progress is particularly beneficial for Clinical Safety Officers and digital project teams, enhancing both efficiency and assurance.

Blog

Latest articles from the team

View all

Make your life easier
and talk to us to simplify compliance

Goodbye manual processes, hello automation. Let Assuric manage compliance and security, so you can focus on growth.

CTA Image