DTAC Compliance for Healthcare Websites: The Complete NHS Guide
DTAC is the national baseline for NHS digital health technologies and mandatory for procurement. This guide explains the 5 DTAC criteria and how to achieve full compliance for your NHS healthcare platform.

Your healthcare platform must meet DTAC requirements to access the NHS market and serve patients effectively. DTAC compliance healthcare website is the national baseline criteria for digital health technologies entering and already used in the NHS. This guide explains what DTAC means for your platform, when it applies, and how to achieve compliance with all 5 criteria to ensure patient safety, data security, and interoperability across NHS systems. Based on our healthcare IT experience with NHS platforms, we can help you efficiently navigate the entire DTAC process.
With 25.7 Million distinct users logging into the NHS App in 2025, the scale of DTAC compliant platforms is substantial. DTAC is the national baseline criteria for digital health technologies entering and already used in the NHS.
What Is DTAC and Why Does It Matter for NHS Digital Health?
25.7 Million distinct users logged into the NHS App in 2025, operating under DTAC aligned frameworks. This demonstrates the scale of NHS digital platforms requiring DTAC compliance.
DTAC is the national baseline criteria for digital health technologies entering and already used in the NHS. This establishes DTAC as the mandatory gateway for NHS procurement and deployment.
The NHS Digital Service Standard provides the foundation for digital service delivery. Our NHS-compliant website design and development services help you achieve DTAC certification by addressing all 5 criteria systematically.
The national baseline for NHS digital health
DTAC establishes the minimum requirements that all digital health technologies must meet to enter the NHS ecosystem. This ensures a consistent level of safety, security, and interoperability across all NHS platforms.
Why NHS procurement requires DTAC
Without DTAC compliance, your platform cannot be procured by NHS organisations. This makes DTAC a critical requirement for any healthcare technology vendor targeting the NHS market.
The business case: Market access and trust
Achieving DTAC compliance opens the door to NHS procurement opportunities. It also demonstrates to potential customers that your platform meets rigorous safety and security standards.
Unsure if your healthcare platform meets DTAC requirements? Schedule a review with our compliance team to assess your readiness for NHS procurement.
Is Your Healthcare Platform Ready for NHS Procurement?
Assess your platform against the 5 DTAC criteria including DCB0129 clinical safety and DSPT data protection before starting NHS procurement.
Schedule a DTAC Review →The 5 DTAC Criteria Explained in Practical Terms
The DTAC framework consists of 5 criteria that all digital health technologies must meet. These cover clinical safety, data protection, technical security, interoperability, and usability.
All organisations with access to NHS patient data must maintain DSPT compliance annually. This highlights that DSPT is a non-negotiable component of DTAC's Data Protection criterion.
Criterion 1: Clinical Safety DCB0129
Clinical risk management is essential for any digital health technology. Your platform must have a documented clinical safety process based on DCB0129 standards.
This includes comprehensive hazard identification, risk assessment, and mitigation strategies. For DCB0129 and DCB0160 clinical safety standards (coming soon) guidance, refer to NHS documentation.
In practice, this means conducting thorough clinical risk assessments throughout the development lifecycle. During healthcare implementations, we have found that organisations that start clinical safety documentation early achieve compliance faster. However, many organisations underestimate the documentation requirements and leave it until late in the development process.
Consider this scenario: a platform identifies a potential clinical hazard but fails to document the mitigation strategy. This can result in DTAC assessment failure, even if the hazard is properly addressed.
Criterion 2: Data Protection DSPT plus UK GDPR
Data security and protection are critical for NHS platforms. Your platform must comply with DSPT and UK GDPR requirements for handling patient data.
All organisations with access to NHS patient data must maintain DSPT compliance annually. This highlights that DSPT is a non-negotiable component of DTAC's Data Protection criterion.
This includes encryption, access controls, and proper data handling procedures. As a result, organisations must implement comprehensive data protection measures. While building patient portals, we ensure all data flows are mapped and protected according to DSPT requirements.
For example, patient data must be encrypted both in transit and at rest. Access controls must be granular and based on the principle of least privilege.
Criterion 3: Technical Security
Technical security requires penetration testing, Cyber Essentials certification, and secure development practices. These measures protect against cyber threats and data breaches.
In practice, this means implementing multiple layers of security controls. Across recent compliance projects, we have observed that organisations with mature security programmes pass DTAC assessments more consistently.
Consider this scenario: a platform without adequate security controls could expose patient data to unauthorized access. This would violate DTAC requirements and NHS trust. Regular vulnerability scanning and prompt patching are also essential.
Criterion 4: Interoperability
Interoperability ensures your platform can exchange data with other NHS systems. This requires compliance with FHIR R4 standards and NHS API integration.
Over 5.1 Million prescription orders were triggered digitally via the NHS App in October 2025 alone. This proves the critical role of interoperable platforms in clinical workflows.
In practice, this means using standard data formats and APIs that are compatible with NHS systems. Based on our healthcare IT experience, platforms that adopt FHIR R4 early have smoother DTAC assessments.
For example, a platform that can effectively exchange patient records with NHS systems demonstrates strong interoperability. This is essential for integrated care pathways.
Criterion 5: Usability and Accessibility
WCAG 2.2 AA minimum compliance is required for accessibility. Your platform must also follow user centred design principles and inclusive access requirements.
In practice, this means conducting accessibility testing with real users, including those with disabilities. During healthcare implementations, we ensure all user interfaces meet WCAG 2.2 AA standards.
For example, screen reader compatibility, keyboard navigation, and sufficient color contrast are all essential. Accessibility should be considered from the earliest design stages, not added as an afterthought.
Does DTAC Apply to Your Platform? A Simple Decision Tree
Not all healthcare platforms require DTAC compliance. The requirement depends on the platform type and its intended use within the NHS.
Patient-facing apps: DTAC required
Any platform that directly interacts with patients requires DTAC compliance. This includes appointment booking systems, patient portals, and telehealth applications.
Internal clinical systems: DTAC required
Clinical systems used by healthcare professionals within NHS organisations also require DTAC compliance. These systems handle patient data and support clinical workflows.
Marketing websites: DTAC not required
Standard marketing websites that do not handle patient data or support clinical workflows do not require DTAC compliance. However, they must still meet other NHS standards.
Administrative tools: Case-by-case assessment
Administrative tools may or may not require DTAC depending on their functionality and data access. A thorough assessment is needed for each specific case.
DTAC vs. DSPT vs. DCB0129: How They Work Together
Understanding how these frameworks relate is essential for NHS compliance. Each serves a different but complementary purpose in the NHS digital ecosystem.
The NHS Digital Service Standard for healthcare websites provides additional guidance. DSPT compliance for healthcare platforms covers data protection requirements.
DTAC: The overarching framework
DTAC provides a comprehensive framework for digital health technology assessment. It encompasses all 5 criteria including clinical safety, data protection, and interoperability.
DSPT: Data protection compliance
DSPT focuses specifically on data security and protection. All organisations with access to NHS patient data must maintain DSPT compliance annually.
DCB0129: Clinical safety standard
DCB0129 provides the specific standards for clinical safety. It is one component of DTAC's Clinical Safety criterion.
How they overlap and complement
These frameworks work together to ensure comprehensive compliance. DTAC provides the overall structure, while DSPT and DCB0129 provide detailed requirements for specific areas.
Common DTAC Pitfalls and How to Avoid Them
Many organisations struggle with DTAC compliance due to common pitfalls. Understanding these can help you avoid costly mistakes and delays.
Incomplete clinical safety documentation
Incomplete or missing clinical safety documentation is a frequent cause of DTAC assessment failure. Organizations must maintain comprehensive records of their clinical risk management processes.
In practice, this means documenting all hazard logs, risk assessments, and mitigation strategies. However, documentation must be thorough and up to date.
Weak data protection measures
Weak data protection measures can result in DTAC non compliance. Organizations must implement effective security controls and data handling procedures.
As a result, regular security audits and penetration testing are essential. One common issue is treating data protection as a one-time activity rather than an ongoing process.
Poor interoperability with NHS systems
Poor interoperability can prevent your platform from integrating with NHS systems. This requires compliance with FHIR R4 standards and NHS API integration.
Consider this scenario: a platform that cannot exchange data with NHS systems will fail DTAC assessment. This limits its usefulness in the NHS ecosystem.
Accessibility non compliance
Failing to meet WCAG 2.2 AA standards results in DTAC non compliance. Accessibility must be built into the platform from the beginning, not added later.
Did You Know ?
DTAC is the national baseline criteria for digital health technologies entering and already used in the NHS. It applies to patient-facing apps, requires 5 criteria including DCB0129 clinical safety, and is mandatory for NHS procurement of any digital health platform.
Your Step-by-Step DTAC Compliance Roadmap
Achieving DTAC compliance requires a systematic approach. This roadmap provides the essential steps for success.
Gap analysis against 5 criteria
Conduct a thorough gap analysis against all 5 DTAC criteria. This identifies areas where your platform currently falls short of requirements.
In practice, this means reviewing each criterion and assessing your current compliance level. However, be honest about gaps to develop an effective remediation plan.
Clinical safety documentation
Develop comprehensive clinical safety documentation based on DCB0129 standards. This includes hazard logs, risk assessments, and mitigation strategies.
As a result, your documentation must demonstrate a thorough and systematic approach to clinical risk management.
Security and interoperability testing
Conduct penetration testing and interoperability testing. These verify that your platform meets DTAC technical security and interoperability requirements.
Consider this scenario: a platform that passes all tests demonstrates its readiness for NHS deployment. This builds confidence with potential NHS customers.
DSPT completion and maintenance
Complete DSPT assessment and maintain annual compliance. This is a mandatory requirement for all organisations with access to NHS patient data.
Conclusion
25.7 Million distinct users logged into the NHS App in 2025, operating under DTAC aligned frameworks. With 62.3 Million logins in November 2025, the scale of DTAC compliant platforms is substantial. The 43% surge in logins demonstrates growing demand for compliant digital health services.
DTAC provides a comprehensive framework for ensuring safety, security, and interoperability across all NHS digital platforms.
However, achieving DTAC compliance is not just about meeting requirements. It is about building trust with NHS organisations and patients. Based on our healthcare IT experience, platforms that achieve DTAC compliance gain significant market advantages.
Need Expert Help Achieving DTAC Compliance?
Build a roadmap for full DTAC certification with Qrolic Health's NHS compliance specialists.
Contact Our NHS Compliance Team →Frequently Asked Questions
Qrolic Health Technical Team
Updated for 2026 Compliance GuidanceBased on our healthcare web development experience, this guide explains DTAC requirements, clinical safety, data protection, security, interoperability, and accessibility for NHS digital health platforms.
Insights for modern healthcare teams
Practical articles on compliance, UX, websites, SEO, and patient acquisition from healthcare specialists.

HIPAA OCR Enforcement: What Healthcare Websites Learned in 2024
Track HIPAA OCR enforcement in 2024: $9.9M in tracking pixel fines, 55% of penalties hit small practices. Learn violation patterns and how to avoid costly fines.

WCAG 2.2 New Criteria for Healthcare Websites: 9 Changes
WCAG 2.2 new criteria for healthcare websites explained with patient portal examples, accessibility requirements, and practical guidance for healthcare teams.
Ready to Start Your Healthcare Project?
Let's discuss your goals and show you how we can build a secure, accessible, and high-performing healthcare website.
