Insight · Governance
Insights · UK
DSPT, DTAC, DCB0129 and DCB0160: How NHS HealthTech Governance Fits Together
- Author
- Michael Abtar
- Clinical safety review
- Himanshu Desai
- Last reviewed
- 2026-10-03
- Next review
- 2027-04-03
The short answer
This article focuses on NHS requirements in England. Scotland, Wales and Northern Ireland operate their own health-data and assurance arrangements, which are not covered here.
The four requirements answer different questions. The DSPT asks whether an organisation handles NHS data securely. DTAC asks whether a digital product is fit for NHS adoption. DCB0129 asks whether the manufacturer has managed the clinical risk of its health IT system. DCB0160 asks whether the deploying health organisation has managed the clinical risk of putting it into use.
Buyers increasingly expect all of them to tell one consistent story. Treated as separate paperwork exercises, they generate duplication and contradictions; treated as one governance system, they reinforce each other.
DSPT: organisational data security
The Data Security and Protection Toolkit is NHS England's annual online self-assessment against the National Data Guardian's data security standards. Organisations with access to NHS patient data and systems are expected to complete it, and NHS buyers in England commonly ask suppliers for their current status.
NHS England has been aligning parts of the toolkit with the NCSC Cyber Assessment Framework for some organisation types; check which version applies to you each year.
It assesses the organisation rather than a specific product: leadership accountability, staff training, access control, incident management, business continuity and supplier management.
DTAC: product readiness for the NHS
The Digital Technology Assessment Criteria give NHS and adult social care organisations in England a common baseline for assessing software-based digital health technologies. NHS England refreshed the DTAC form and guidance in early 2026, with full transition to the new form by 6 April 2026; it reduced duplication with the DSPT and the medical-device pre-acquisition questionnaire. DTAC covers clinical safety, data protection, technical security, interoperability, and usability and accessibility.
DTAC does not replace other approvals, such as medical-device requirements or ICO registration, and it draws on evidence from them. The clinical safety section expects DCB0129 compliance, and the data protection section draws on matters such as DSPT status, DPIAs and the named data protection lead.
DCB0129 and DCB0160: clinical risk management
DCB0129 and DCB0160 are information standards published under the Health and Social Care Act 2012 and apply to health IT used in health and care in England. DCB0129 applies to manufacturers of health IT systems. It requires a clinical risk management system, a named Clinical Safety Officer, a hazard log, and a clinical safety case report maintained across the product's life.
DCB0160 is its counterpart for health and care organisations deploying those systems. It expects the deploying organisation to assess the clinical risk of its own implementation, drawing on the manufacturer's safety case, again under a Clinical Safety Officer.
Under both standards the Clinical Safety Officer must be a suitably qualified and experienced clinician holding current registration with a professional body. NHS England has said both standards are under review, so check the current versions before relying on detail.
The two standards are designed to interlock: a supplier with weak DCB0129 evidence makes its customers' DCB0160 work harder, and often slows procurement.
Where they overlap — and where suppliers get caught out
Common friction points include a DTAC submission that describes controls the DSPT assessment does not evidence; a hazard log that has not been updated after product changes; DPIAs that do not match the actual data flows; and no single owner for keeping the evidence current between NHS submissions.
A practical approach is one governed evidence base — policies, data flow maps, DPIAs, the hazard log and safety case, security testing and supplier records — with each NHS submission drawing on it rather than recreating it.
What good assurance looks like
Good assurance is current, owned and consistent: one accountable lead, evidence refreshed when the product or organisation changes, and submissions that cross-reference rather than contradict each other.
When to seek support
Independent support is most useful before a first NHS procurement, after significant product change, when a buyer challenges your evidence, or when no one internally owns clinical safety and data protection together.
Questions for your leadership team
Is our DSPT status current and consistent with what we tell buyers in DTAC? Do we have a suitably qualified Clinical Safety Officer and a live hazard log? Are product changes triggering clinical safety and privacy review? Could we hand an NHS buyer a coherent evidence pack today?
Sources
- Data Security and Protection Toolkit — NHS England (accessed 2026-10-03)
- Digital Technology Assessment Criteria (DTAC) — NHS England (accessed 2026-10-03)
- DCB0129 and DCB0160 clinical risk management standards — NHS England (accessed 2026-10-03)
General guidance, not legal advice.
