← Back to blog

NHS DTAC Requirements: Release Checklist UK Teams Need by 6 April 2026

September 14, 2026
NHS DTAC Requirements: Release Checklist UK Teams Need by 6 April 2026

DTAC is the NHS baseline assessment for digital health technologies, and it covers five areas: clinical safety, data protection, technical security, interoperability, and usability and accessibility. Suppliers must move to NHS England's updated DTAC form before 6 April 2026. The first practical step is scoping your product against the clinical safety decision tree and building a versioned evidence pack that maps to each question.


TL;DR:

  • Suppliers should map every DTAC question to specific, version-controlled evidence files to ensure clarity and quick updates during review.
  • The 2026 DTAC update reduces question volume by 25% and aligns questions more closely with NICE definitions, requiring re-mapping of all existing answers.
  • Evidence packs must include detailed documentation such as risk management logs, security test summaries, API specifications, and conformance reports, all tied to release versions.
  • DTAC must be integrated into the development lifecycle, with early focus on clinical safety, interoperability, and security to avoid last-minute compliance gaps.
  • Many NHS Trusts treat DTAC as a procurement gate, so providing current, well-documented evidence accelerates contract negotiations and avoids delays.

Pocketapp
Build A DTAC Ready Health App
Pocketapp designs, develops, and deploys user focused mobile applications for healthcare and other regulated sectors.
Discuss your app project

Table of Contents

What are the NHS DTAC requirements across each core area?

Every DTAC submission gets assessed against the same five domains, and reviewers expect specific evidence for each one, not general assurances. NHS England Digital's guidance sets out exactly what "good" looks like in each area.

  • Clinical safety. Run your product through the clinical safety decision tree first. It determines whether your tool counts as a medical device and whether DCB0129 clinical risk management applies. Skip this step and everything downstream gets misaligned.
  • Data protection. You'll need a Data Protection Impact Assessment, a published privacy notice, evidence of ICO registration, and, where personal data leaves the UK, an international transfer risk assessment.
  • Technical security. Reviewers want alignment with the Software Security Code of Practice, proof of multi factor authentication on privileged accounts, and a recent penetration test summary rather than a policy document alone.
  • Interoperability. Show how your APIs work, your approach to NHS Login where relevant, and how you verify NHS Numbers against PDS.
  • Usability and accessibility. Evidence should map to WCAG 2.2 AA and the Accessible Information Standard. This section is reviewed comparatively rather than scored pass or fail, so context and honest gaps matter more than a perfect checklist.

The 2026 DTAC refresh: what changed and what to do before 6 April

NHS England didn't just tweak the wording. The updated form cuts question volume by 25% and strips out duplication with the Data Security and Protection Toolkit and the Pre-Acquisition Questionnaire, so suppliers stop answering near-identical questions three times over.

DTAC form reduction and duplication overview

The refresh also introduces a new clinical safety decision tree that aligns more closely with the NICE definition of digital health technologies, and it can automatically flag when a PAQ submission is also required. If your product touches clinical decision making even indirectly, that tree is worth working through properly rather than guessing.

Three actions before the deadline:

  1. Retire your old DTAC form and any evidence templates built around it.
  2. Download the updated form and guidance, and re-map every existing answer to the new question set.
  3. Notify your procurement contacts at NHS Trusts or integrated care boards that your evidence pack is transitioning, so nothing stalls mid-review.

How do you complete and submit the DTAC form?

Getting through DTAC assessment without repeated clarification requests comes down to sequencing. Reviewers reject submissions far more often for missing evidence links than for genuine non-compliance.

  1. Scope the product. Run it through the clinical safety decision tree, record the outcome, and note the exact product version this scoping applies to. Versioning matters because a later release can change your answer.
  2. Map every DTAC question to a named artefact and owner. A vague "we have security policies" answer gets sent back. A reference to a specific pen-test report, dated and version-stamped, does not.
  3. Assemble the evidence pack. This typically includes your DPIA, a clinical risk log, security test summaries, API documentation with an interoperability rationale, and accessibility conformance reports.
  4. Submit through your assurance route. Larger contracts often go through a Standardised Health Technology Group or a similar local adopter process, described in Digital NHS's assurance guidance. Expect clarification requests, and build in time for at least one revision cycle before contract signature.

Pro Tip: Keep a single spreadsheet that lists every DTAC question, the evidence file that answers it, the file's version number, and the date it was last checked. When a Trust asks for an update six months later, you update one row instead of rebuilding the whole pack.

Evidence and version control: what to keep in your repository

A DTAC evidence pack that lives in scattered emails and shared drives falls apart the moment a reviewer asks a follow-up question. Structure it like a release artefact instead.

  • Clinical safety file or risk management log, referencing DCB0129 where the decision tree confirms it applies.
  • DPIA, privacy notice, and proof of ICO registration, plus an international transfer assessment if data leaves the UK.
  • Penetration test summary, a mapping against the Software Security Code of Practice, and your MFA policy documentation.
  • API specifications, a statement of your NHS Login approach, and any relevant standards mapping.
  • Accessibility conformance reports against WCAG 2.2 AA and evidence of Accessible Information Standard compliance.
  • A version log that ties every DTAC answer to a specific release number and date.

Mapping DTAC answers to named files and release numbers rather than general claims is what separates a fast approval from a stalled one. Suppliers holding recognised security or supply chain charters can sometimes streamline the technical security checks, since reviewers accept that certification as partial evidence rather than starting from zero.

Does DTAC replace DSPT, PAQ, UKCA or ICO registration?

No. DTAC sits alongside these checks rather than instead of them. NHS England Digital's own guidance is explicit that a product may still need medical device certification (UKCA marking) and separate ICO registration regardless of DTAC status.

Where the 2026 form helps is reducing duplicate paperwork:

  • Your Data Security and Protection Toolkit submission commonly satisfies much of the DTAC data protection and technical security evidence.
  • Your PAQ answers on organisational assurance often overlap with DTAC's governance questions.
  • UKCA certification and ICO registration remain entirely separate obligations. DTAC references them but cannot substitute for either.

Embedding DTAC into your SDLC: practitioner tips

Treating DTAC as a form to fill in at the end of development is the single most common mistake developers make. Build clinical safety thinking into discovery instead, and DCB0129 stops being a last-minute scramble. Our own breakdown of embedding DCB0129 into the SDLC covers this in more depth.

  • Keep a versioned evidence repository so every release ships with a current, traceable DTAC artefact set, not a static document from launch day.
  • Automate an evidence refresh step in your release pipeline, since product updates commonly trigger revalidation.
  • If you're behind schedule, a short, focused DTAC readiness engagement usually closes gaps faster than trying to retrofit compliance across an entire roadmap at once.
  • Review NHS Login integration requirements early if your interoperability answer depends on it.

Why DTAC now works like a procurement gate

Legal commentators are blunt about this: DTAC is framed as best practice, but many NHS Trusts treat it as a hard procurement threshold rather than a nice-to-have. A supplier that shows up to a procurement conversation with current, version-mapped evidence moves faster through contract negotiation than one still assembling documents. Build DTAC into your product roadmap and release cadence, not your legal team's to-do list the week before a tender closes.

— Paul

How Pocketapp helps suppliers get DTAC-ready

Preparing DTAC evidence touches nearly every part of a product build, from clinical safety scoping at discovery through to API design and accessibility testing before release. Pocketapp works across all of it: mobile app development with clinical safety and DCB0129 considerations built into the SDLC from day one, secure architecture aligned with NHS technical security expectations, and interoperability work covering NHS Login and NHS Number verification.

Pocketapp

If your team is racing the 6 April 2026 transition deadline, a focused DTAC readiness review is usually the fastest way to find gaps before a Trust does. Pocketapp can scope that review alongside an evidence-pack sprint, mapping each DTAC question to a concrete artefact and owner so your submission goes in clean the first time. Get in touch through our app design or development pages to discuss where your product currently sits against the five DTAC areas.

Where to check the official DTAC guidance

Sources

FAQ

What is a DTAC in the NHS?

The Digital Technology Assessment Criteria is NHS England's baseline assessment for digital health products, covering clinical safety, data protection, technical security, interoperability, and usability and accessibility.

Does DTAC replace other approvals like DSPT or UKCA?

No. DTAC works alongside DSPT, PAQ, UKCA certification and ICO registration rather than replacing any of them, though the 2026 form reduces duplicate questions with DSPT and PAQ.

What are the NHS data protection guidelines within DTAC?

Suppliers must provide a Data Protection Impact Assessment, a published privacy notice, proof of ICO registration, and an international transfer assessment where data leaves the UK.

What are the NHS data security standards DTAC checks?

DTAC's technical security section checks alignment with the Software Security Code of Practice, multi factor authentication on privileged access, and a current penetration test summary.

How often does a DTAC submission need updating?

Product updates commonly trigger revalidation, so suppliers should refresh their evidence pack with every meaningful release rather than treating DTAC as a one-off exercise.