NHS Digital Health Compliance Guide
- Jul 24
- 6 min read
What NHS Compliance Means
Developing a successful digital health product is only part of the journey. To be adopted by NHS organisations, suppliers must demonstrate that their software meets a range of requirements covering clinical safety, security, data protection, regulatory compliance and evidence generation. Collectively, these requirements are often referred to as NHS digital health compliance. Rather than being a single certification or approval, NHS compliance is a connected system of assurance. Depending on your product, this may include:
Clinical safety (DCB0129 and DCB0160)
Digital Technology Assessment Criteria (DTAC)
Software as a Medical Device (SaMD) regulation
Data Security and Protection Toolkit (DSPT)
Cyber Essentials
UK GDPR and data protection
Interoperability requirements
NICE Evidence Standards Framework (ESF)
Understanding how these frameworks fit together is often the biggest challenge for health technology companies. Many organisations treat each requirement as a separate project, when in reality the same evidence frequently supports multiple assurance activities. This guide provides a practical overview of the NHS compliance landscape for health tech founders, product managers, regulatory affairs professionals and quality teams preparing to deploy or sell digital health technologies into the NHS.
DTAC: The NHS Gateway
For most software suppliers, the first compliance hurdle encountered during NHS procurement is the Digital Technology Assessment Criteria (DTAC). Introduced nationally in 2021 by what became NHS England, DTAC provides a consistent assessment framework that NHS organisations use when evaluating digital health technologies before procurement or deployment. While it is not legislation, it has become the de facto entry point for many NHS procurement exercises. DTAC assesses digital health technologies across five core areas:
Clinical Safety
Data Protection
Technical Security
Interoperability
Usability and Accessibility
Together, these areas provide a baseline level of assurance that software products are safe, secure and suitable for use within NHS environments. In 2026, NHS England introduced a significant refresh of the framework. The updated DTAC form includes around 25% fewer questions, removing duplication with the Data Security and Protection Toolkit (DSPT) and the Pre-Acquisition Questionnaire (PAQ) while providing clearer guidance for both suppliers and NHS buyers.
Clinical Safety: DCB0129 and DCB0160
Clinical safety is one of the most important elements of NHS digital health compliance. The NHS clinical risk management standards DCB0129 and DCB0160 establish how organisations should identify, assess and manage risks of patient harm arising from health IT systems. Although often mentioned together, the standards apply to different organisations.
DCB0129 applies to manufacturers and suppliers developing health IT products. It requires organisations to embed clinical risk management throughout the software lifecycle and produce documentation demonstrating that patient safety has been systematically considered.
Typical DCB0129 deliverables include:
Clinical Risk Management Plan
Hazard Log
Clinical Safety Case Report
Appointment of a suitably qualified Clinical Safety Officer (CSO)
DCB0160 applies to NHS organisations deploying digital health technologies into clinical practice. Rather than repeating the manufacturer's work, it focuses on how the software will be implemented safely within the local healthcare environment. The two standards are complementary rather than alternatives. Clinical safety evidence produced by manufacturers under DCB0129 forms an important input into the deploying organisation's DCB0160 activities. This evidence also underpins the Clinical Safety section of DTAC, demonstrating why the various NHS assurance frameworks should be considered together rather than independently.
Software as a Medical Device
Not every digital health product is regulated as a medical device, but many are. Software becomes a Software as a Medical Device (SaMD) when its intended purpose meets the medical device definition set out within UK medical device legislation. This depends primarily on what the software is intended to do rather than the technology used to build it.
Examples may include software that:
supports diagnosis;
recommends treatment;
calculates clinical risk;
analyses medical images;
monitors patients for clinical purposes.
In Great Britain, medical devices are regulated by the Medicines and Healthcare products Regulatory Agency (MHRA) and require UKCA marking before being placed on the market. Several international standards commonly support compliance, including:
ISO 13485 for quality management systems;
IEC 62304 for software lifecycle processes;
ISO 14971 for medical device risk management.
The regulatory landscape continues to evolve through the MHRA's Software and AI as a Medical Device Change Programme, particularly as artificial intelligence becomes increasingly common within healthcare technologies. Importantly, suppliers should not assume their software is or isn’t a medical device without undertaking an appropriate classification exercise.
Data Security and Data Protection
Alongside clinical safety, NHS organisations expect suppliers to demonstrate robust data protection and cybersecurity practices. The Data Security and Protection Toolkit (DSPT) is the NHS's annual assessment framework that exists in two formats currently. For IT suppliers, requirements are aligned with the National Data Guardian's data security standards whilst for healthcare providers there has been a shift to to the NCSC CAF Indicators of Good Practice methodology. Irrespective of this, the majority of organisations processing NHS data will need to complete and maintain an up-to-date DSPT submission including submitting to a 3rd party audit depending on an organisation’s size or category. Technical security expectations within DTAC also commonly include:
Cyber Essentials certification, demonstrating a baseline level of cyber hygiene.
Independent penetration testing, typically undertaken within the previous 12 months.
Secure software development and vulnerability management practices.
Appropriate access controls and authentication.
Data protection remains equally important.
Suppliers should ensure they have:
Information Commissioner's Office (ICO) registration where required.
Appropriate UK GDPR compliance processes.
A completed Data Protection Impact Assessment (DPIA) where personal data processing is undertaken.
Strong governance across these areas not only supports DTAC submissions but also provides assurance to NHS customers that sensitive patient information is being handled appropriately.
Proving Value: NICE Evidence Standards
Meeting regulatory and compliance requirements does not automatically demonstrate that a product improves patient care. The NICE Evidence Standards Framework (ESF) helps developers understand the level of evidence expected for digital health technologies based on their function and potential clinical risk. Published in 2022, the framework defines evidence tiers that reflect how a technology influences healthcare decisions. Products with greater clinical impact generally require stronger evidence demonstrating safety, effectiveness and real-world benefit.
The ESF is not a regulatory approval process and does not replace the requirements of organisations such as the MHRA or the Care Quality Commission (CQC). Instead, it addresses a different question:
Does this technology deliver meaningful value within healthcare?
For suppliers seeking NHS adoption, this distinction is important. Successful procurement depends not only on demonstrating compliance, but also on showing that a product delivers measurable benefits for patients, clinicians and healthcare organisations.
NHS Compliance FAQ
What is DTAC and is it mandatory?
DTAC is NHS England's national assessment framework for digital health technologies. While it is not legislation, many NHS organisations require suppliers to complete a DTAC assessment before procurement, making it a practical requirement for many digital health companies.
What is the difference between DCB0129 and DCB0160?
DCB0129 applies to organisations developing health IT systems, while DCB0160 applies to organisations deploying those systems into healthcare environments. Together they ensure clinical risks are managed throughout both development and implementation.
Is my software a medical device?
It depends on the software's intended purpose. Products used for diagnosis, treatment decisions, patient monitoring or similar clinical functions may fall within medical device regulation. A structured classification assessment should be completed before making regulatory decisions.
Do I need a Clinical Safety Officer?
If your product falls within the scope of DCB0129 or DCB0160, a suitably qualified Clinical Safety Officer is expected to oversee the clinical risk management process and support the production of clinical safety documentation. It is an explicit requirement of the two clinical safety standards.
How long does NHS compliance take?
There is no single answer. The timescale depends on product maturity, regulatory classification and the evidence already available. Organisations that build compliance into product development from an early stage typically progress through procurement much more efficiently than those attempting to generate evidence retrospectively.
Where to Start
NHS digital health compliance is most effective when approached as an integrated programme rather than a collection of separate assessments.
A practical sequence is to:
Classify your product and determine whether medical device regulation applies.
Establish clinical safety processes under DCB0129 where required.
Build strong data protection and cybersecurity foundations.
Assemble the evidence required for a DTAC submission.
Generate appropriate clinical and economic evidence to support NHS adoption.
One of the most common mistakes suppliers make is treating DTAC as a one-off procurement form. In reality, DTAC reflects the quality of your wider compliance programme. As products evolve through new releases, security updates and feature enhancements, the supporting evidence should evolve with them.
At AbedGraham, we help digital health companies navigate the full NHS compliance landscape from clinical safety and medical device regulation to cybersecurity, DTAC readiness and evidence generation so that compliance becomes an enabler of NHS adoption rather than a barrier.
Book a discovery call to discuss your product and build a practical roadmap for NHS deployment.


Comments