JVR Consultancy stepped in to help us bring our management system up to speed and were very professional throughout the process. We passed our audit with no issues raised and our RISQS rating was increased to 5 stars. I would highly recommend using JVR for any company looking to gain RISQS accreditation or for assistance with RISQS compliance and Maintenance.
What is the Digital Technology Assessment Criteria (DTAC)?
The Digital Technology Assessment Criteria (DTAC) is a framework introduced by NHS England to ensure that digital health technologies meet the necessary standards for clinical safety, data protection, technical security, interoperability, and usability before being deployed across the NHS.
Book your free consultation today to learn how we can support you with DTAC.
DTAC acts as a baseline requirement for any technology company—whether UK-based or international—looking to supply software, apps, connected medical devices, or digital platforms to NHS Trusts, Integrated Care Boards (ICBs), or other NHS buyers.
By meeting DTAC, suppliers can demonstrate that their digital health product is safe, secure, and effective, providing NHS organisations with the confidence to adopt new technology.
We contacted JVR Consultancy from Germany and straight away we were impressed with their knowledge & way of working. We were assigned a very knowledgeable and extremely competent consultant who walked us through the whole process. They were professional, efficient and with their help we managed to secure the highest pass possible in a very short space of time.
I contacted JVR Consultancy for last-minute support with Achilles certification. They were more than happy to assist, providing their expertise to help fill any gaps we had before our audit submission. Their invaluable support ensured we had best practices in place moving forward.
Speak to us today, call our Head Office:
01628 56 52 56
NHS Data Security and Protection Toolkit (DSPT)
Do you need help to achieve NHS Data Security and Protection Toolkit (DSPT) compliance for your organisation? Look no further than JVR Consultancy for the ultimate solution to your problem.
Medical Devices and Cybersecurity: What You Need to Know
Medical equipment is unquestionably required – they can mean the difference between life and death, yet are they safe from hackers?
Ae you looking for Digital Technology Assessment Criteria (DTAC) Help and Support?
If you are interested in Digital Technology Assessment Criteria (DTAC), or would like to talk to one of our expert consultants simply click the following button to arrange a call back request. In a hurry, call head office today on 01628 56 52 56 and don’t forget to mention our fast track support service.
Why is DTAC Important?
DTAC is not just a tick-box exercise—it’s about ensuring:
- Patient safety
- Data security
- System interoperability
- Accessibility for all users
- Compliance with NHS policies and UK regulations
Failure to meet DTAC may result in delays or rejection during NHS procurement. Conversely, successful completion enhances your credibility, streamlines onboarding, and increases your product’s chances of NHS adoption.
While DTAC is not legally mandatory at the national level, many NHS organisations require it during procurement, and it is increasingly becoming a de facto standard across the sector.

Who Needs to Complete DTAC?
DTAC applies to any supplier whose digital product:
- Is used by NHS staff, patients, or the public
- Processes or stores personal or health data
- Integrates with NHS systems or services
This includes:
- Medical device software and apps
- Patient-facing platforms (e.g., remote monitoring tools)
- Clinical decision support systems
- Health information portals and wearable technology
Whether you’re an EU medical device manufacturer, a digital health startup, or an established technology vendor, you will need to demonstrate DTAC compliance to supply the NHS.
DTAC Information
DTAC is made up of five core areas, each requiring evidence and assurance:
1. Clinical Safety
You must demonstrate compliance with:
- DCB0129 (for manufacturers): Clinical Risk Management in the Manufacture of Health IT Systems
- DCB0160 (for deploying organisations): Risk Management in Deployment and Use
This involves:
- Appointing a Clinical Safety Officer (CSO)
- Producing a Clinical Safety Case Report
- Ensuring clinical input throughout development
📎 Read more on DCB0129 and DCB0160 Standards
2. Data Protection
Your product must comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Evidence includes:
- A Data Protection Impact Assessment (DPIA)
- A transparent Privacy Policy
- Lawful basis for processing patient data
If you process NHS data, you must also register and complete the Data Security and Protection Toolkit (DSPT).
3. Technical Security
Cybersecurity is essential. DTAC requires:
- A valid Cyber Essentials certificate (minimum)
- Evidence of penetration testing aligned with OWASP Top 10 vulnerabilities
- Up-to-date software and secure development practices
Higher-risk applications may require Cyber Essentials Plus and additional evidence of secure design.
📎 Cyber Essentials Support at JVR
4. Interoperability
To ensure your technology works with existing NHS infrastructure, DTAC requires:
- Use of NHS-endorsed data standards, such as:
- FHIR (Fast Healthcare Interoperability Resources)
- OAuth 2.0 for secure authorisation
- TLS 1.2+ for encrypted transmission
- A declaration of your system’s integration capabilities
5. Usability and Accessibility
The technology must be accessible to all users, including those with disabilities. Evidence includes:
- Compliance with WCAG 2.1 accessibility standards
- Proof of user-centred design
- Results from usability testing
This ensures the solution is intuitive and equitable for NHS patients and staff.
At JVR Consultancy, we offer full-service support to help you understand, prepare for, and complete the DTAC process with confidence.
Our DTAC Support Services Include:
- Gap analysis – We review your current documentation and processes against DTAC requirements
- Document preparation – We assist with clinical safety cases, DPIAs, penetration test reports, and more
- Cyber Essentials certification – We guide you through the application or renewal process
- Training & guidance – Our consultants walk your team through DTAC evidence creation
- Procurement support – We liaise with NHS buyers to support your product’s adoption
With years of experience supporting digital health innovators and EU medical device manufacturers, our team—including GDPR and Cyber Security expert Tom Hayes—ensures your technology is DTAC-ready.
📞 Speak to JVR about DTAC Support
- Review Product Scope – Does it use or process health data? Will it be used by NHS staff/patients?
- Undertake a DTAC Gap Analysis – JVR helps you identify missing documentation
- Collect and Prepare Evidence – For all 5 DTAC domains
- Apply for Cyber Essentials – Or Cyber Essentials Plus if higher risk
- Submit to NHS Buyer – Completed DTAC documentation is shared with NHS Trust or ICB as part of
- procurement
- Stay Compliant – DTAC isn’t a one-off. Maintain standards and update documentation regularly.
- Deep understanding of NHS procurement and compliance
- Specialists in supporting EU-based manufacturers and tech suppliers
- Proven track record delivering DTAC, DSPT, UKCA, and Cyber Essentials
- Access to senior consultants with regulatory expertise
- A practical, proactive approach that turns complexity into clarity
Whether you’re launching a digital health app or entering the UK market with connected devices, JVR Consultancy will help ensure your product is compliant, competitive, and ready for NHS procurement.
DTAC can be a hurdle—but with the right support, it becomes a powerful stepping stone to NHS adoption.
📞 Contact JVR Consultancy Today
Let’s make your technology DTAC-ready and NHS-approved.
Related Articles
More reasons to choose JVR Consultancy for Compliance & Risk Management