NHS Compliance: Which Standards Apply to You?
NHS compliance is not a single status, but a set of specialized standards tailored to your platform’s function. We ensure your website meets every clinical, security, and technical requirement from the ground up.
Clinical Verification Layer
Digital Standards Assured
DCB0129 Approved
Clinical Risk Management
FHIR R4 Ready
NHS Interoperability
Why NHS Standards Matter
NHS Digital Standards: Patient Safety and Digital Trust
Compliance with NHS Digital Service Standards is not optional for NHS-funded services. It ensures patient safety, data integrity, and equitable access across all digital touchpoints.
Contractual Requirement
NHS-funded digital services must meet the NHS Digital Service Standard as a contractual condition of procurement. Failure to meet these standards can result in contract termination and reputational damage to your organisation.
Mandatory criteria covering user research, accessibility, security, and clinical safety that all NHS digital services must meet.
Patient Safety First
When a patient navigates an NHS-funded portal, books an appointment, or accesses clinical information digitally, they rely on the organisation to provide a safe, reliable, and inclusive experience. The NHS Digital Service Standard exists to make that expectation legally enforceable.
Clinical Risk
Non-compliant digital services can introduce clinical risk through poor UX, missing accessibility features, or broken data flows.
DCB 0129 Obligations
NHS services must hold a Clinical Risk Management System and a Safety Case Report before going live.
DTAC Assessment
The Digital Technology Assessment Criteria (DTAC) gates access to NHS patient data and app library listing.
NHS digital compliance is not a box-ticking exercise.
It is a commitment to delivering safe, inclusive, and trustworthy services to patients who rely on the NHS every day.
Common Failures
Where NHS digital services fall short
We review NHS-adjacent digital services regularly. These are the most common ways organisations fail DTAC or Digital Service Standard assessments.
No DCB 0129 Safety Case
Launching a digital health service without a Clinical Risk Management System and Safety Case Report is a direct DTAC failure - and a patient safety risk.
Skipping User Research
NHS Digital Service Standard Point 1 requires evidenced user research. Services that skip this fail assessment regardless of how good the technology is.
DTAC Security Evidence Gaps
DTAC requires documented evidence of penetration testing, data flow mapping, and cyber security controls. Many services can't produce these at assessment time.
Failing WCAG 2.2 AA
DTAC mandates WCAG 2.2 AA accessibility. Services that haven't been accessibility-tested regularly fail the automated and manual audit components.
Missing NHS Data Security Toolkit Evidence
Organisations handling NHS patient data must complete the Data Security and Protection Toolkit. Many skip this until procurement forces their hand - too late.
There is no single NHS compliance certificate
Compliance involves five distinct standards, not just one catch-all status. A website may be fully aligned with one requirement while still needing evaluation against others.
NHS Digital Service Standard
A set of design and operational criteria that NHS digital services are assessed against, covering user research, accessibility, security, and iterative delivery. Most relevant if your website is, or links directly into, an NHS-branded digital service.
DTAC (Digital Technology Assessment Criteria)
The national baseline criteria for digital health technologies entering the NHS. It assesses clinical safety, data protection, technical security, interoperability, and usability. Required if your website functions as a health app or clinical platform.
DSPT (Data Security and Protection Toolkit)
An online self-assessment tool that organisations must complete if they have access to NHS patient data and systems. It confirms you are practising good data security and handling personal information correctly.
DCB0129 and DCB0160
Clinical risk management standards. DCB0129 applies to the manufacturer (us) ensuring the software is built safely. DCB0160 applies to the health organisation ensuring it is implemented safely. Required if your website handles clinical decisions or patient care data.
Cyber Essentials & Plus
A government-backed scheme that helps protect organisations against common cyber attacks. Often a prerequisite for holding NHS contracts or completing the DSPT.
Which standards apply to your website?
Not every website needs to meet every standard. Here is a practical framework to determine your obligations based on your website's functionality.
Scenario 1: Brochure & Marketing Sites
Your website provides information about your services, locations, and contact details, but does not collect health data or integrate with clinical systems.
Required
WCAG 2.2 AA Accessibility
Required by law for public sector bodies; strongly recommended for all healthcare sites.
UK GDPR Compliance
Required for basic contact forms, cookies, and analytics.
Not Applicable
DTAC, DSPT, DCB0129
Generally not applicable unless you hold NHS contracts or handle patient data.
Scenario 2: Clinical Platforms & Health Apps
Your website collects patient health data, provides clinical triage, integrates with NHS systems (like the NHS App or PDS), or is sold to NHS trusts as a digital health tool.
Required
DTAC Assessment
Mandatory. You must pass the Digital Technology Assessment Criteria to supply the NHS.
DSPT Registration
Mandatory. You must complete the Data Security and Protection Toolkit annually.
DCB0129 Clinical Risk
Mandatory. You must appoint a Clinical Safety Officer and maintain a Hazard Log.
NHS Service Standard
Highly relevant. Adopting these design patterns ensures usability and faster DTAC approval.
NHS Digital Channels Operate at a National Scale
This massive scale is why rigorous security and compliance standards now apply broadly across the entire digital healthcare ecosystem.
0 million
Monthly NHS App logins, marking a 43% increase over the yearly average.
NHS England Digital, NHS App statistics, November 2025
0 to 33 million
Monthly GP appointments recorded across primary care systems in England.
NHS England Digital, General Practice Appointments data, 2025
0 million+
Monthly prescription orders triggered via the NHS App for patients nationwide.
NHS England Digital, NHS App statistics, 2025
Is your website NHS Digital Standard compliant?
Use this 10-point checklist to evaluate whether your website meets the relevant NHS standards. A single 'No' means there is a gap that needs addressing before procurement or assessment.
Current and accurate DSPT submission reflecting all website data flows.
Full WCAG 2.2 AA compliance with a published accessibility statement.
Active Data Processing Agreements (DPA) with all third-party vendors.
Patient data hosted strictly within the UK or ICO-approved jurisdictions.
DCB0129/DCB0160-compliant Clinical Risk Management and Safety Case.
Documented evidence meeting all Digital Technology Assessment Criteria (DTAC).
Full alignment with Cyber Essentials requirements and security controls.
Strict compliance with official NHS branding and logo usage guidelines.
Documented 72-hour ICO and patient data breach reporting process.
Regular post-DSPT review of all new data flows and third-party integrations.
Frequently Asked Questions
Addressing common misconceptions about NHS approvals, certifications, and responsibilities.
Let's talk about your project
Get in touch with our team to discuss your project or ask any questions.
No. The NHS does not "approve" or "certify" suppliers or websites in a way that allows you to use their logo for marketing. Passing DTAC or completing DSPT means you meet the criteria to supply the NHS, but it does not grant you the right to use the NHS lozenge. Unauthorized use of NHS branding is strictly policed.
Ready to Start Your Healthcare Project?
Let's discuss your goals and show you how we can build a secure, accessible, and high-performing healthcare website.
