Trust in healthtech: DTAC, DCB0129 and buyer confidence

Breaking into the NHS is as much about managing clinical risk as it is about superior software. For founders and security leaders, navigating the triad of DTAC, DCB0129, and ISO 27001 is the difference between a stalled pilot and a national rollout. This guide outlines how to build a trust framework that satisfies procurement officers and clinical safety leads alike.

Michael McCarroll 16 min read Updated June 2026

The New Reality of Healthtech Procurement

The NHS is shifting from a 'wild west' of health apps toward a strictly regulated ecosystem governed by the Digital Technology Assessment Criteria (DTAC). This framework isn't just a tick-box exercise; it is a consolidated standard covering clinical safety, data protection, technical security, interoperability, and usability. If you cannot produce a credible DTAC submission, your product will effectively be blocked from NHS procurement lists.

The DTAC serves as a gatekeeper that forces vendors to prove their maturity before they even reach a purchasing desk. Procurement teams are no longer taking your word for it—they require artifact-based evidence. This means your internal GRC (Governance, Risk, and Compliance) functions must be ready to export logs, policies, and certificates on demand. Understanding that DTAC is the 'how' and ISO/DCB standards are the 'what' is the first step in your market strategy.

Deconstructing the DTAC Framework

DTAC is structured into five core components, each requiring a specific set of evidence. The technical security section is where most firms stumble, as it requires a current DSPT (Data Security and Protection Toolkit) submission and evidence of independent penetration testing. Without these, your DTAC score will drop to zero in the eyes of a Trust’s Chief Information Officer.

You must view DTAC as an ongoing commitment rather than a one-time hurdle. Every major update to your software requires a review of your DTAC submission to ensure your clinical hazard log and security controls still reflect the reality of the live environment. This is why a central repository for compliance evidence is not a luxury, but a fundamental business requirement for healthtech scale-ups.

  • Section 1: Clinical Safety (DCB0129 compliance)
  • Section 2: Data Protection (DPIAs and DSPT completion)
  • Section 3: Technical Security (Penetration testing and ISO 27001)
  • Section 4: Interoperability (FHIR standards and API documentation)
  • Section 5: Usability and Accessibility (WCAG 2.1 compliance)

DCB0129: Managing Clinical Risk as a Business Asset

While ISO 27001 keeps data safe, DCB0129 ensures that your software doesn't inadvertently harm or kill a patient. This standard is mandatory for any organisation manufacturing health IT software for the NHS. Compliance requires you to appoint a Clinical Safety Officer (CSO) who is a registered clinician and to produce three key documents: a Clinical Safety Case Report, a Hazard Log, and a Clinical Risk Management Plan.

The Hazard Log is a living document that identifies potential failure points—such as a delayed notification or a data mismatch—and assigns a risk score based on severity and likelihood. For a founder, this means integrating clinical safety into the Agile sprint process. You cannot 'bolt on' DCB0129 at the end of development; it must be part of your requirements gathering and QA testing from day one.

A key tip for speed is to align your DCB0129 risk assessments with your ISO 27001 risk register. While the impact categories differ (clinical harm vs. data breach), the underlying assets and infrastructure are often the same. Managing these in parallel reduces the administrative burden on your engineering team and prevents conflicting remediation strategies.

ISO 27001: The Foundation of Trust

ISO 27001 is the most recognised security certification in healthtech, and for good reason. It provides the heavy lifting for the 'Technical Security' and 'Data Protection' sections of the DTAC. When an NHS Trust sees an ISO 27001 certificate from a UKAS-accredited body, it significantly reduces the amount of due diligence they need to perform on your internal operations.

However, having the certificate is only half the battle. You must be able to demonstrate that your Information Security Management System (ISMS) actually functions. This means showing clear evidence of quarterly access reviews, vulnerability scans, and management review minutes where security is discussed. In healthtech, your ISMS should be the platform upon which your clinical safety and data protection activities sit.

  • A 24-month roadmap for security improvements.
  • Evidence of robust supplier management (especially for cloud hosting).
  • Documented incident response plans with specific NHS reporting timelines.
  • A clear Statement of Applicability (SoA) that includes Annex A controls for health data.

Leveraging Compliance to Win Business

Winning NHS contracts requires shifting your mindset from being a 'vendor' to becoming a 'partner'. This means transparency. When building your trust center or responding to tenders, proactively offer your DTAC summary and your DCB0129 Clinical Safety Case Report. This level of openness immediately differentiates you from competitors who are still trying to figure out what a CSO does.

Buyer confidence is built on the consistency of your evidence. If your security policy says you have MFA enabled for all staff, but your DTAC submission suggests it is 'planned', you lose credibility instantly. Building trust in healthtech is a long-game; it involves proving to clinicians that your tool improves outcomes while proving to IT heads that it won't be the source of their next major data incident.

Accelerate Your NHS Market Entry with Data-Driven Trust

Our platform automates the evidence gathering for DTAC and ISO 27001, mapping your controls to clinical safety requirements so you can stop wrestling with spreadsheets and start closing NHS contracts.

ISO-STANDARD.app ships a ready-to-adopt Healthtech workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Frequently asked questions

Is DTAC a mandatory legal requirement for all healthtech vendors?
The DTAC is a self-assessment, but it is heavily scrutinised by NHS commissioning bodies. If your submission lacks evidence for DCB0129 or presents a weak ISO 27001 Statement of Applicability, you will likely be rejected during the procurement phase. It essentially functions as a ‘licence to play’ within the NHS ecosystem.
How does DCB0129 differ from ISO 27001?
DCB0129 specifically addresses clinical risk—the risk of patient harm—while ISO 27001 addresses data risk. However, they overlap in areas like software development lifecycles and incident management. A well-implemented ISO 27001 system provides the operational 'rigour' that makes your Clinical Safety Case Report much more credible to a Clinical Safety Officer.
Can our CTO act as the Clinical Safety Officer (CSO)?
A CSO must be a registered clinician (e.g., a doctor or nurse) with relevant experience and specific training in clinical risk management. While they can be an external consultant for the vendor, they must be formally appointed and take responsibility for the Clinical Safety Case Report and Hazard Log.
What is the typical timeline for achieving DTAC compliance?
For most startups, the initial DTAC and DCB0129 assessment takes 3 to 6 months. This depends heavily on whether you already have a mature Information Security Management System (ISMS) in place. If you are starting from zero, the timeline is often dictated by the time it takes to conduct clinical risk workshops and document the hazard log.
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →