Midnyte

NHS

What do I need to sell software to the NHS?

There is an industry selling “DTAC compliance” to health startups. Read NHS England’s own pages and a different picture appears: the thing people treat as the gate is the least binding part of this, and the parts that genuinely carry weight are the ones nobody leads with.

DTAC is not a certification

The Digital Technology Assessment Criteria is an assessment framework for NHS and adult social care buyers to use when assuring a product. Three things follow from how NHS England words it, and all three are worth knowing before you pay anyone:

NHS England also states that DTAC “applies alongside, but does not replace, other required approvals”. That is the whole shape of it: a wrapper around other people’s rules, not a rule of its own.

The current form dates from February 2026, with about a quarter of the questions removed and scope narrowed to software-based digital health technologies. It covers five areas: clinical safety, data protection, technical security, interoperability, and usability and accessibility. If a page tells you there are six, it has split the last one in two.

So why does everyone ask for it

Because the trust buying from you carries the duty, and the form is how they discharge it. In practice you will complete it for every deployment. The distinction matters for a different reason: it tells you where to spend. You cannot buy your way past DTAC, and the components it points at are where the real work is.

The part that does carry legal force

DCB0129 — clinical risk management in the manufacture of health IT systems — is yours. DCB0160 is the deploying organisation’s equivalent. Both are information standards under section 250 of the Health and Social Care Act 2012.

Here is a nuance almost nobody gets right, including one of NHS England’s own pages.

Standard publishedDuty
From 7 July 2025“Must comply”, under the amended section 250(6A)
Before 7 July 2025 — which includes DCB0129 and DCB0160, both from 2018“Have regard to”, the older duty, expressly preserved

The amendment that introduced the stricter duty was commenced in July 2025, but the commencing instrument contains a saving provision: for any information standard already in effect immediately before that date, the Act has effect as if the amendment had not been brought into force. DCB0129 and DCB0160 date from 2018, so they sit inside the saving. NHS England’s own 2026 review page confirms it — bodies exercising a health and care function “must continue to have regard to the standards”.

You will also find an NHS England Digital page, last edited in 2024, stating that compliance is mandatory under the 2012 Act. It predates both the amendment and the saving. Both pages are official and they disagree, which is worth knowing if someone waves one at you.

None of which is an argument for skipping it. “Have regard to” is a real duty, every trust will ask for your safety case, and the standard requires specific artefacts: a Clinical Safety Case Report at each lifecycle phase, with an issued Hazard Log accompanying each one.

The requirement that stops software companies

DCB0129 section 2.3, the Clinical Safety Officer
A registered clinician

“MUST be a suitably qualified and experienced clinician”, “MUST hold a current registration with an appropriate professional body” and “MUST be knowledgeable in risk management and its application to clinical domains”.

This is the one that catches people. You cannot appoint your CTO. You need a registered clinician — NHS England names the GMC and NMC as examples — with training in clinical risk management, and you need them before your safety case means anything.

Worth knowing: the standard names no specific course, no certificate and no licensing body. The only published competence tests are “knowledgeable in risk management” and NHS England’s “sufficient training”. So you are hiring judgement, not a qualification, and the usual answer for a small company is a contract CSO. NHS England publishes no fee schedule for that, so budget from quotes rather than from anything you read.

Is it a medical device?

The trigger is intended purpose, not how clever the software is. The regulations cover software intended for diagnosis, prevention, monitoring, treatment or alleviation of disease, among other purposes — and the MHRA says intended purpose is construed objectively, from your labelling, instructions, promotional material and technical documentation.

Which means your marketing can classify your product. A symptom tracker that “helps you spot early signs” is making a claim. The same software described as a diary is not.

If it is a device, in outline: registration with the MHRA before it goes on the Great Britain market, a UK Responsible Person if you are not UK-based, and UKCA marking — self-certified only for the lowest-risk classes, otherwise through a UK Approved Body. The registration fee from 1 April 2026 is £300 a year per Level 2 GMDN category. CE-marked devices continue to be accepted in GB on a timetable running to 2028 or 2030 depending on the route.

And being a medical device exempts you from nothing else. DCB0129 says in terms that it applies to all health IT systems “including those that are also controlled by medical device regulations”, and NHS England says DTAC is not an alternative to medical device regulation. Where a product is both, expect to do both.

What nobody publishes

The honest sequence, if you are starting: work out whether you are a medical device first, because that changes everything downstream. Get a Clinical Safety Officer engaged early, because a safety case assembled retrospectively is both worse and more expensive. Complete the Data Security and Protection Toolkit if you will touch NHS systems or patient data. The DTAC form is the last thing you fill in, not the first.

Sources. DTAC status, scope, the five areas and third-party certification: NHS England, Digital Technology Assessment Criteria and its how-it-works and conduct-an-assessment pages, last edited 21 September 2026. DCB0129 requirements and the Clinical Safety Officer: DCB0129 Amd 24/2018 specification v4.2, sections 1.1, 2.3, 3.3.3 and 3.5.3. The duty position: section 250 of the Health and Social Care Act 2012 as amended by section 95 of the Health and Care Act 2022, commenced by SI 2025/807, whose regulation 3 preserves the earlier duty for standards already in effect; and NHS England’s national review of DCB0129 and DCB0160. Medical devices: the Medical Devices Regulations 2002 regulation 2(1), MHRA guidance on intended purpose for software as a medical device, and GOV.UK guidance on registering medical devices, last updated 20 July 2026. All retrieved 9 October 2026. This is a description of published material, not regulatory or legal advice.

Building something for health?

The clinical safety work is the part that surprises people, and it is cheapest to do while you are still designing. Tell me what the product does and I will tell you what it pulls in.

Start here →