- Best for
- Health-tech & NHS software suppliers
- Usual driver
- DTAC v2 technical security
- Needs
- Cyber Essentials + annual pentest
- Also relevant
- DSPT
DTAC is where NHS procurement stalls
The Digital Technology Assessment Criteria (DTAC) is the baseline NHS buyers apply before they'll adopt a digital health product, and DTAC v2 became mandatory across NHS assessments in April 2026. Its technical-security section asks for evidence you can't produce overnight:
- C3.1 — Cyber Essentials. A current certificate, validated against the IASME database. Cyber Essentials Plus is expected for higher-risk or business-critical systems.
- C3.2 — penetration testing. Evidence of an external, manual penetration test of your product, plus how often you test. NHS buyers expect an annual cadence and a re-test of Critical and High findings.
- C3.3 — who tested it. Whether testing was internal or third-party — an independent, accredited tester carries far more weight in due diligence.
- Plus the rest: MFA, a secure development lifecycle, vulnerability management and secure hosting.
Both halves from one team
Most suppliers end up juggling a certification body for Cyber Essentials and a separate firm for the pentest. We're a certified IASME assessor and a CREST-accredited penetration tester, so the certificate and the test report come from one relationship — scoped together, aligned to what DTAC assessors actually look for (findings mapped to the OWASP Top 10 and scored with CVSS).
Don't forget the DSPT
If you also process NHS patient data or use NHS systems, you'll likely need the Data Security and Protection Toolkit alongside DTAC. We handle both so your NHS due-diligence pack is complete.
Common questions
What does DTAC actually require for security?
A current Cyber Essentials certificate (CE Plus for higher-risk systems), evidence of an external manual penetration test with a documented action plan, an annual testing cadence, MFA, a secure development lifecycle and vulnerability management. DTAC v2 became mandatory across NHS assessments in April 2026.
How often do we need to pen test for the NHS?
At least annually, and again after any significant change to your application, with a re-test of Critical and High findings. We confirm the right cadence for your product during scoping.
Do we need Cyber Essentials or Cyber Essentials Plus?
DTAC expects a current Cyber Essentials certificate, and Cyber Essentials Plus for higher-risk or business-critical systems handling patient data. We check which your buyer requires before you invest.
Can you do the certification and the pen test together?
Yes — that's the point. We're an IASME assessor and a CREST tester, so we scope both together and give you one aligned evidence pack for DTAC, rather than stitching two suppliers' outputs together.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day