If you are building a digital health application, software platform, or connected device destined for the NHS, clearing the compliance hurdle is just as important as the clinical outcomes you deliver. Two of the most critical frameworks you will encounter are the Digital Technology Assessment Criteria (DTAC) and the Data Security and Protection Toolkit (DSPT).
While the two frameworks evaluate different aspects of your organisation's readiness, they converge on one non-negotiable requirement: penetration testing.
Here is a breakdown of what the NHS expects from your technical security assessments, and how you can make sure your product passes without delays.
The Role of Penetration Testing in NHS Compliance
NHS DTAC (Technical Security, Section C3)
DTAC acts as the NHS's baseline due diligence framework for health-tech, and version 2 of the form became mandatory across NHS assessments on 6 April 2026. Under the Technical Security (C3) section, your product must demonstrate resilience against cyber threats. The NHS does not just take your word for it: you are required to provide concrete evidence of an independent penetration test.
Assessors are looking for:
- Annual frequency: Penetration tests must be conducted at least once every 12 months, or whenever significant changes are made to the application or its architecture. A one-off report is weaker evidence than a documented annual cadence.
- Comprehensive scope: A token sample won't cut it. The test must cover your entire solution: web applications, APIs, mobile apps, supporting infrastructure, and cloud environments.
- Standardised reporting: Findings must be mapped to the OWASP Top 10 and severity-scored using the Common Vulnerability Scoring System (CVSS).
- Remediation evidence: Critical and high-severity findings are expected to be fixed and retested, with the retest outcomes traceable to the original issues.
Alongside the test report, C3 also expects a current Cyber Essentials certificate (Cyber Essentials Plus for higher-risk systems handling patient data) and multi-factor authentication on administrator and supplier access.
NHS DSPT
The DSPT is the annual online self-assessment that any organisation handling NHS health and care data must complete. It has changed significantly: Version 8 (2025/26) is aligned to the National Cyber Security Centre's Cyber Assessment Framework (CAF) version 3.4, moving away from the old National Data Guardian standards model. The 2025/26 submission window has now closed, so the focus is on maintaining your evidence continuously and preparing for the 2026/27 cycle.
For IT suppliers this has real teeth. Suppliers now complete assertions that are mapped to CAF profiles, and larger suppliers (50 or more employees and over £10 million turnover) must pass an independent audit of 12 mandatory assertions. Crucially, holding Cyber Essentials Plus or ISO 27001 no longer grants the exemptions suppliers used to rely on. Evidence of recent external penetration testing remains one of the strongest ways to satisfy the technical control requirements and build trust with NHS buyers.
Where Most Vendors Go Wrong
Many health-tech companies fail their initial DTAC submission because they treat penetration testing as a box-ticking exercise. Assessors will reject automated vulnerability scans masquerading as full penetration tests. They look for deep, manual testing (authentication bypass, user enumeration, privilege escalation, business-logic abuse) performed by qualified practitioners, with the raw findings interpreted rather than dumped from a tool.
Furthermore, the NHS strongly prefers testing conducted by qualified practitioners holding industry-recognised credentials, such as those from CREST or The Cyber Scheme, or chartered professional titles like ChCSP (Chartered Cyber Security Professional) awarded through the UK Cyber Security Council.
How Attack Vector Can Help
At Attack Vector, we specialise in the specific nuances of UK healthcare cybersecurity compliance. We don't just run automated tools and hand over a spreadsheet of false positives. Our penetration tests are rigorously mapped to OWASP and CVSS standards, generating the exact evidence formats that DTAC and DSPT assessors demand.
We understand that procurement timelines can be incredibly tight. When an NHS trust wants to pilot your software, you can't afford to wait weeks for security testing.
- Instant pricing: Need to budget for your DTAC compliance? Use the instant quote calculator on our website to get indicative pricing immediately.
- Rapid turnaround: We know that speed is critical. Contact us today, and we guarantee a formal Statement of Work (SoW) in your inbox within 24 hours.
Don't let technical security hold up your NHS deployment. Get your indicative price today, and let's secure your health-tech solution.
Ready to strengthen your security?
Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.