Skip to content
HIPAA-Compliant AgencyBAA Signed Before PHINHS Digital StandardsWCAG 2.2 AA
HIPAA-Compliant AgencyBAA Signed Before PHINHS Digital StandardsWCAG 2.2 AA

NHS Compliance: Which Standards Apply to You?

NHS compliance is not a single status, but a set of specialized standards tailored to your platform’s function. We ensure your website meets every clinical, security, and technical requirement from the ground up.

NHS Digital Service StandardDSPT (Data Security)DCB0129 & DCB0160
NHS Digital Service • Safe
NHS

Clinical Verification Layer

NHS Number★★★-★★★-★★★★
DemographicsPDS Synced ✓
Clinical CodesSNOMED CT
IdentityNHS Login Verified

Digital Standards Assured

DCB0129 Clinical Safety Assurance
DSPT Data Protection Compliant
Interoperability (HL7 / FHIR R4)
WCAG 2.2 AA Accessibility Met

DCB0129 Approved

Clinical Risk Management

FHIR R4 Ready

NHS Interoperability

Why NHS Standards Matter

NHS Digital Standards: Patient Safety and Digital Trust

Compliance with NHS Digital Service Standards is not optional for NHS-funded services. It ensures patient safety, data integrity, and equitable access across all digital touchpoints.

Contractual Requirement

NHS-funded digital services must meet the NHS Digital Service Standard as a contractual condition of procurement. Failure to meet these standards can result in contract termination and reputational damage to your organisation.

14 Standards

Mandatory criteria covering user research, accessibility, security, and clinical safety that all NHS digital services must meet.

Patient Safety First

When a patient navigates an NHS-funded portal, books an appointment, or accesses clinical information digitally, they rely on the organisation to provide a safe, reliable, and inclusive experience. The NHS Digital Service Standard exists to make that expectation legally enforceable.

Clinical Risk

Non-compliant digital services can introduce clinical risk through poor UX, missing accessibility features, or broken data flows.

DCB 0129 Obligations

NHS services must hold a Clinical Risk Management System and a Safety Case Report before going live.

DTAC Assessment

The Digital Technology Assessment Criteria (DTAC) gates access to NHS patient data and app library listing.

NHS digital compliance is not a box-ticking exercise.

It is a commitment to delivering safe, inclusive, and trustworthy services to patients who rely on the NHS every day.

Common Failures

Where NHS digital services fall short

We review NHS-adjacent digital services regularly. These are the most common ways organisations fail DTAC or Digital Service Standard assessments.

Start Here

There is no single NHS compliance certificate

Compliance involves five distinct standards, not just one catch-all status. A website may be fully aligned with one requirement while still needing evaluation against others.

01

NHS Digital Service Standard

A set of design and operational criteria that NHS digital services are assessed against, covering user research, accessibility, security, and iterative delivery. Most relevant if your website is, or links directly into, an NHS-branded digital service.

02

DTAC (Digital Technology Assessment Criteria)

The national baseline criteria for digital health technologies entering the NHS. It assesses clinical safety, data protection, technical security, interoperability, and usability. Required if your website functions as a health app or clinical platform.

03

DSPT (Data Security and Protection Toolkit)

An online self-assessment tool that organisations must complete if they have access to NHS patient data and systems. It confirms you are practising good data security and handling personal information correctly.

04

DCB0129 and DCB0160

Clinical risk management standards. DCB0129 applies to the manufacturer (us) ensuring the software is built safely. DCB0160 applies to the health organisation ensuring it is implemented safely. Required if your website handles clinical decisions or patient care data.

05

Cyber Essentials & Plus

A government-backed scheme that helps protect organisations against common cyber attacks. Often a prerequisite for holding NHS contracts or completing the DSPT.

Decision Framework

Which standards apply to your website?

Not every website needs to meet every standard. Here is a practical framework to determine your obligations based on your website's functionality.

01

Scenario 1: Brochure & Marketing Sites

Your website provides information about your services, locations, and contact details, but does not collect health data or integrate with clinical systems.

Required

WCAG 2.2 AA Accessibility

Required by law for public sector bodies; strongly recommended for all healthcare sites.

UK GDPR Compliance

Required for basic contact forms, cookies, and analytics.

Not Applicable

DTAC, DSPT, DCB0129

Generally not applicable unless you hold NHS contracts or handle patient data.

02

Scenario 2: Clinical Platforms & Health Apps

Your website collects patient health data, provides clinical triage, integrates with NHS systems (like the NHS App or PDS), or is sold to NHS trusts as a digital health tool.

Required

DTAC Assessment

Mandatory. You must pass the Digital Technology Assessment Criteria to supply the NHS.

DSPT Registration

Mandatory. You must complete the Data Security and Protection Toolkit annually.

DCB0129 Clinical Risk

Mandatory. You must appoint a Clinical Safety Officer and maintain a Hazard Log.

NHS Service Standard

Highly relevant. Adopting these design patterns ensures usability and faster DTAC approval.

Scale Of NHS Digital

NHS Digital Channels Operate at a National Scale

This massive scale is why rigorous security and compliance standards now apply broadly across the entire digital healthcare ecosystem.

0 million

Monthly NHS App logins, marking a 43% increase over the yearly average.

NHS England Digital, NHS App statistics, November 2025

0 to 33 million

Monthly GP appointments recorded across primary care systems in England.

NHS England Digital, General Practice Appointments data, 2025

0 million+

Monthly prescription orders triggered via the NHS App for patients nationwide.

NHS England Digital, NHS App statistics, 2025

Self-Assessment Checklist

Is your website NHS Digital Standard compliant?

Use this 10-point checklist to evaluate whether your website meets the relevant NHS standards. A single 'No' means there is a gap that needs addressing before procurement or assessment.

01

Current and accurate DSPT submission reflecting all website data flows.

02

Full WCAG 2.2 AA compliance with a published accessibility statement.

03

Active Data Processing Agreements (DPA) with all third-party vendors.

04

Patient data hosted strictly within the UK or ICO-approved jurisdictions.

05

DCB0129/DCB0160-compliant Clinical Risk Management and Safety Case.

06

Documented evidence meeting all Digital Technology Assessment Criteria (DTAC).

07

Full alignment with Cyber Essentials requirements and security controls.

08

Strict compliance with official NHS branding and logo usage guidelines.

09

Documented 72-hour ICO and patient data breach reporting process.

10

Regular post-DSPT review of all new data flows and third-party integrations.

FAQ's

Frequently Asked Questions

Addressing common misconceptions about NHS approvals, certifications, and responsibilities.

Let's talk about your project

Get in touch with our team to discuss your project or ask any questions.

No. The NHS does not "approve" or "certify" suppliers or websites in a way that allows you to use their logo for marketing. Passing DTAC or completing DSPT means you meet the criteria to supply the NHS, but it does not grant you the right to use the NHS lozenge. Unauthorized use of NHS branding is strictly policed.

Ready to Start Your Healthcare Project?

Let's discuss your goals and show you how we can build a secure, accessible, and high-performing healthcare website.

Healthcare projects portfolio brief - HIPAA & NHS Compliant Web Development