Home/Blog/Healthcare Security
Healthcare Security

DSPT Version 8 and DTAC Version 2: Why Penetration Testing Still Matters

Supplying digital health technology to the NHS means dealing with strict compliance checks. NHS England has updated both the Data Security and Protection Toolkit (DSPT) and the Digital Technology Assessment Criteria (DTAC).

These latest iterations move away from simple self-assessments and focus heavily on verifiable evidence. The details below outline what has changed in the latest cycles and why targeted penetration testing remains exactly what you need to pass.

DSPT Version 8: A Focus on Proof

The DSPT Version 8 represents a major shift in how the NHS assesses data security. Although the submission deadline for the 2025/26 cycle has now passed (30 June 2026), maintaining these standards is a continuous requirement, and organisations must actively prepare for the upcoming 2026/27 cycle.

  • CAF Alignment: The toolkit is now aligned with the National Cyber Security Centre's Cyber Assessment Framework (CAF) version 3.4 for designated organisations. This shifts the focus to an outcome-based evaluation.
  • No More Blanket Exemptions: Previously, holding ISO 27001 or Cyber Essentials Plus allowed organisations to bypass whole sections of the toolkit. Those exemptions have been scrapped for CAF-aligned organisations. You must now complete the entire assessment and supply direct evidence of your controls.
  • Mandatory Independent Audits: Larger IT suppliers, known as Category 1 and 2 organisations, are now required to undergo a mandatory independent audit as part of their submission. Assessors look for hard proof supporting your security declarations across key areas like network defence.

DTAC Version 2: Shorter but Stricter

NHS England released DTAC Version 2 on 24 February 2026, and the previous version was officially retired on 6 April 2026. While the new form is designed to be less repetitive, it demands solid proof from your technical teams.

  • Reduced Duplication: The new form has about 25% fewer questions. Questions that duplicated the DSPT or the Pre-Acquisition Questionnaire (PAQ) have been removed to save time.
  • Clearer Scope: The criteria now explicitly align with the NICE definition of digital health technologies. This confirms that DTAC focuses on software-based products rather than pure hardware or embedded firmware.
  • Secure Development Rules: You must now formally declare adherence to the DSIT/NCSC Software Security Code of Practice. This proves that security was considered throughout the design and build phases.
  • Stricter MFA Checks: The updated form introduces stronger multi-factor authentication (MFA) requirements, particularly for privileged supplier access and remote administrator accounts.
  • Revised Clinical Safety Training: The requirement for the named Clinical Safety Officer (CSO) to have completed specific training provided by NHS Digital has been removed, though you must still have a suitably qualified and competent CSO under DCB0129 standards.

Why Penetration Testing Remains a Firm Requirement

While the updates streamline the admin process, technical security remains a core, non-negotiable section of DTAC.

Under the DSPT, IT departments must demonstrate robust network defences, and guidance expects regular penetration testing to evaluate firewall effectiveness and system security. You cannot simply commission a test and file the report away. Both frameworks operate on an evidence-based model. You must prove that you actively manage vulnerabilities and that you have fixed any high-risk flaws the testers uncovered.

Meeting the Standard with Attack Vector

Passing these updated assessments requires more than an automated scan. You need a security partner who understands the specific hurdles of NHS compliance.

Attack Vector offers penetration testing services designed specifically to meet the DTAC standard. We start with accurate scoping, ensuring we test the exact architectural and data-flow elements that NHS assessors care about.

Following the assessment, we deliver a DTAC-compliant pentest report. This document maps our technical findings directly to NHS requirements, providing the clear evidence and remediation steps you need to satisfy auditors and get your product into the hands of clinicians.

For an instant and customised DSPT penetration test quote, use our instant quote calculator.

#dspt#dtac#nhs#penetration-testing

Ready to strengthen your security?

Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.