The headline change: NHS England introduced a revised DTAC form with 25% fewer questions. The previous form should not be used for assessments from 6 April 2026 onwards.
What is DTAC?
The Digital Technology Assessment Criteria is the NHS assessment framework used by care commissioners and providers when assuring software-based digital health technology. It gives buyers and suppliers a shared structure for evidence, but it is not a universal certificate issued once for every future deployment.
NHS England groups DTAC into five areas:
- Clinical safety
- Data protection
- Technical security
- Interoperability
- Usability and accessibility
What changed in 2026?
Following its 2024 review and engagement with industry, NHS England published a simplified form and clearer guidance. The new form reduces duplication with processes such as the Data Security and Protection Toolkit and the pre-acquisition questionnaire, and confirms scope alignment with NICE around software-based digital health technologies.
For suppliers, “shorter” should mean less repetitive administration, not less assurance. Answers still need evidence that is current, product-specific and consistent across the submission.
Where does DCB0129 fit?
Clinical safety is one of DTAC’s five sections. A supplier of relevant health IT should expect to evidence its DCB0129 clinical risk management work: governance, Clinical Safety Officer, hazard management and a Clinical Safety Case Report for the assessed product and version.
DTAC does not replace DCB0129 or DCB0160. NHS England explicitly says DTAC applies alongside other required approvals and checks. Depending on the product, those may also include medical-device requirements, Information Commissioner registration, the Data Security and Protection Toolkit or other procurement assurance.
A practical evidence pack
Before a buyer sends its spreadsheet or portal link, build an indexed evidence pack with named owners and review dates:
- Clinical safety: DCB0129 documents, CSO evidence, hazard log, current safety case and release mapping.
- Data protection: data-flow map, controller/processor position, DPIA support, retention, sub-processors and international transfers.
- Technical security: architecture, access controls, vulnerability management, penetration testing, incident response and patching.
- Interoperability: standards used, API or interface documentation, identity and coding decisions, and testing evidence.
- Usability and accessibility: user research, supported users and settings, accessibility statement, testing and known limitations.
Three mistakes that slow assessment
Contradictory answers
If the architecture diagram, privacy answer and security response describe different data flows, reviewers have to stop and reconcile them. One source of truth is faster than five polished but inconsistent documents.
Generic policies without product evidence
A corporate policy may show governance, but reviewers also need evidence that the assessed product and release follow it.
Leaving clinical safety until the form arrives
A mature DCB0129 file is produced through development. It is difficult to reconstruct credible hazard analysis, control decisions and verification evidence at the end of procurement.
Use the current form
NHS England advises downloading the DTAC form at the point of use so the latest version is used. This matters in 2026 because older templates remain in circulation even though the previous version should no longer be used for new assessments after 6 April.