top of page


NHS Digital Health Compliance Guide
What NHS Compliance Means Developing a successful digital health product is only part of the journey. To be adopted by NHS organisations, suppliers must demonstrate that their software meets a range of requirements covering clinical safety, security, data protection, regulatory compliance and evidence generation. Collectively, these requirements are often referred to as NHS digital health compliance. Rather than being a single certification or approval, NHS compliance is a co


ISO 13485 is the first step for Medical Device Software Compliance
Why ISO 13485 Is Not Enough Alone ISO 13485:2016 is the internationally recognised quality management system (QMS) standard for medical device manufacturers, providing the governance framework needed to develop, manufacture, and maintain compliant medical devices. However, for organisations developing Software as a Medical Device (SaMD), connected medical devices, or AI-enabled technologies, ISO 13485 alone is not enough. A quality management system establishes the processes


ALARP in Digital Health: Understanding Risk Reduction for DCB0129, ISO 14971 and EU MDR
What ALARP Means ALARP stands for As Low As Reasonably Practicable. It is a long-established principle of UK health and safety law that requires organisations to reduce risks until any further reduction would require measures whose cost, time or effort would be grossly disproportionate to the additional safety benefit achieved. The legal foundations of ALARP can be traced to the landmark case Edwards v National Coal Board (1949), which established that deciding whether a cont


Risk Log vs Hazard Log: What's the Difference?
Why the Terminology Matters Many health technology companies already maintain a risk log or risk register to manage project and business risks. Then they begin preparing for NHS deployment under DCB0129 and discover they also need a Hazard Log. At this point, projects often stall because the two documents are mistakenly treated as the same thing. Although both deal with "risk", they serve fundamentally different purposes. A project risk log helps teams manage uncertainties th


What is AMLAS? A Guide to Machine Learning Assurance for Medical Device Manufacturers
What is AMLAS in Plain Terms? AMLAS (Assurance of Machine Learning for use in Autonomous Systems) is an open assurance methodology that helps organisations develop structured safety arguments demonstrating that machine learning (ML) components are sufficiently safe for their intended use. For medical device manufacturers, Software as a Medical Device (SaMD) developers and digital health companies, AMLAS provides a practical framework for assuring AI and machine learning syste


Clinical Risk Management in Digital Health
What Is Clinical Risk Management? Clinical risk management is the structured process of identifying, assessing, controlling and monitoring risks of patient harm arising from health IT systems. Its purpose is to ensure that software, digital services and connected medical technologies support safe clinical care throughout their lifecycle. Unlike cybersecurity or information governance, which potentially have a broader remit, clinical risk management focuses on protecting patie


Cyber Essentials for NHS Suppliers
Cyber Essentials and NHS Suppliers Cyber Essentials has become the baseline cybersecurity certification that many NHS suppliers are expected to achieve as part of procurement, supplier assurance, and wider cybersecurity due diligence activities. Developed with the support of the UK National Cyber Security Centre (NCSC), the scheme focuses on a defined set of technical controls designed to protect organisations against common cyber threats. The certification is relevant to a w


ISO Standards for NHS Healthcare
ISO Standards in the NHS Context ISO standards play an increasingly important role in NHS procurement, assurance, and risk management. Developed by the International Organization for Standardization, they provide internationally recognised frameworks for managing quality, information security, business continuity, risk, and other critical organisational functions. While most ISO standards are voluntary, NHS organisations and procurement teams increasingly rely on them as evid


What is ISO 42001? A Guide for AI Medical Device Manufacturers
ISO 42001 at a Glance Artificial intelligence (AI) is transforming healthcare, from diagnostic imaging to clinical decision support to remote patient monitoring. As AI becomes an integral part of deployed medical technologies, organisations face increasing expectations to demonstrate that their systems are not only innovative, but also safe, transparent and responsibly governed. Published in December 2023, ISO/IEC 42001:2023 is the world's first international standard for an


The DSPT Version Guide: Standards-Based to CAF-Aligned
What Is the DSPT? The Data Security and Protection Toolkit (DSPT) is NHS England's annual online self-assessment that enables organisations to measure and demonstrate their compliance with the National Data Guardian's data security standards. It is a key assurance mechanism used across the health and care sector to assess how organisations protect sensitive information and manage cybersecurity, information governance, and data protection risks. The DSPT is completed by NHS or


ISO 27001 Annex A Controls Explained
ISO 27001 Annex A (sometimes referred to as ISO 27001 Appendix A) is the control reference section of ISO/IEC 27001:2022. It contains the catalogue of information security controls that organisations may select and implement as part of their Information Security Management System (ISMS). The current version of the standard includes 93 Annex A controls, organised into four themes: Organisational Controls, People Controls, Physical Controls, and Technological Controls. Annex A


NHS SOC and STRIDE Threat Modelling
Healthcare organisations face cyber risks at every stage of the technology lifecycle. Some threats can be identified and mitigated before a system is deployed, while others only become visible once systems are operating in live clinical and business environments. This is why two complementary disciplines have become increasingly important: STRIDE threat modelling and the Security Operations Centre (SOC). Two Layers of Healthcare Defence STRIDE threat modelling is a proactive,


EU AI Act & ISO 42001 – Cybersecurity and Governance for AI-Driven Medical Devices
The EU AI Act Will Reshape How You Build, Certify and Maintain Software as a Medical Device The EU Artificial Intelligence Act is the...


NIS2 & Executive Liability – A Critical Priority for Medical Device Manufacturers
NIS2 Is Here. Are You Ready to Be Held Personally Accountable? The NIS2 Directive, in force across the EU from October 2024, introduces...


Digital Technology Assessment Criteria (DTAC)
It is essential that any digital health technologies undergo proper assessment. This ensures they meet quality standards and are safe for use, especially within the NHS or social care settings. This is where the Digital Technology Assessment Criteria (DTAC) comes in. Developed by the NHS, the DTAC assessment is used to evaluate the quality, safety, effectiveness, and suitability of digital technologies. Learn more about the basics of DTAC, and how you can meet the criteri


DCB0160 Clinical Risk Compliance Services
DCB 0160 is the counterpart standard to DCB 0129 . Whereas the former applies to manufacturers of technology, DCB 0160 applies to public...


Data Security and Protection Toolkit Support
Learn more about how we can fully project manage and optimise your annual mandatory NHS Data Security and Protection (Toolkit) returns...


Clinical Safety Officer (CSO)
The Clinical Safety Officer (CSO) is one of the cornerstones of NHS clinical safety compliance . Filling this role is one of the most...
bottom of page
