Home/Blog/Healthcare Security
Healthcare Security

NHS DSPT and DTAC Penetration Testing: What Health-Tech Vendors Need

If you sell software, platforms or connected digital services into the NHS, two assurance conversations keep returning: the Digital Technology Assessment Criteria (DTAC) for the product, and the Data Security and Protection Toolkit (DSPT) for the organisation handling health and care data. They are not the same process. They do overlap on one practical point buyers care about: independent technical security evidence, which usually means a recent penetration test your engineers can remediate against and your procurement contacts can read.

This post is for health-tech vendors and digital suppliers. It explains how DTAC and DSPT differ, what assessors and NHS buyers typically look for in testing evidence, where vendors fail submissions, and how to brief a UK testing partner without over-claiming what a pentest can guarantee.

Key points

  • DTAC assesses the digital health product; DSPT assesses organisational data security and protection practice.
  • DTAC technical security expects Cyber Essentials evidence plus an independent penetration test within the last 12 months for internet-accessible products, with findings rated CVSS 7.0 or above mitigated.
  • DSPT for IT suppliers remains a non-CAF assertion model with mandatory independent audit areas, and an annual penetration test is still required; CAF-aligned DSPT applies to other organisation types.
  • Automated scans alone rarely satisfy serious NHS due diligence.
  • Attack Vector provides testing and reporting evidence; it does not certify DTAC or complete your DSPT for you.

Context: two gates, one delivery calendar

NHS buyers move on procurement timelines. Clinical champions want a pilot. Information governance and cyber teams want evidence. Your board wants revenue. The friction appears when testing is treated as a last-minute PDF purchase rather than part of release planning.

Keep the frameworks straight:

  • DTAC is the baseline assessment framework NHS organisations use when assuring digital health technology products across clinical safety, data protection, technical security, interoperability and usability.
  • DSPT is the annual online toolkit organisations complete to demonstrate data security and protection practice when handling NHS health and care data.

Many vendors need a coherent story for both across the year. Product testing supports DTAC and buyer questionnaires. Organisational controls and toolkit evidence support DSPT. Penetration testing often appears in both conversations for different reasons.

DTAC technical security: what vendors should prepare

NHS England refreshed the DTAC form in February 2026 after industry engagement. The updated form reduces question volume (about a 25% reduction), removes duplication with processes such as the DSPT and the Pre-Acquisition Questionnaire, clarifies scope alignment with NICE around software-based digital health technologies, and retires the previous form for use from 6 April 2026 onwards.

Technical security is where many suppliers stall, because evidence cannot be invented overnight. In practice, buyers and assessors look for:

  • Confirmation that independent penetration testing has been carried out on the product
  • Testing performed within the last 12 months for internet-accessible products
  • Coverage that matches the real solution: web application, APIs, mobile clients and supporting infrastructure or cloud edges as relevant
  • Findings expressed against recognised application security practice (OWASP Top 10 language is widely expected)
  • Severity and remediation narrative engineers can use
  • Evidence that findings rated CVSS 7.0 or above have been mitigated, usually confirmed by retest

Alongside testing, technical security conversations typically also involve Cyber Essentials certification evidence, stronger multi-factor authentication expectations for privileged and supplier access, secure development declarations (including alignment to the DSIT/NCSC Software Security Code of Practice where the form asks), and incident or continuity artefacts elsewhere in the pack.

DTAC is required in practice for NHS use and procurement assurance. It is not a product “certification” Attack Vector can award. Independent testing is evidence inside someone else’s assessment.

For a service-shaped view of scoping and deliverables, see NHS DTAC penetration testing.

DSPT for IT suppliers: what changed and what did not

DSPT Version 8 for 2025/26 tightened evidence expectations across the health and care ecosystem. Important nuance for vendors:

  • CAF-aligned DSPT applies to NHS trusts and foundation trusts, ICBs, CSUs, DHSC arm’s length bodies, designated Operators of Essential Services, and nominated genomics organisations, with independent assessment arrangements described by NHS England Digital.
  • IT suppliers for 2025/26 complete a non-CAF aligned DSPT assessment (assertion-and-evidence style), while still facing independent audit of mandated assertions. An annual penetration test is still required. NHS England’s DSPT audit notice for 2025/26 lists 12 mandatory assertions for IT suppliers (covering governance, identity and privileged access, incident reporting and response, patching and vulnerability management, protection of sensitive systems, firewall management, and supplier mapping, among others).
  • The submission deadline remains 30 June each cycle. The 2026/27 toolkit (version 9) went live on 4 September 2026, with a submission deadline of 30 June 2027. Check whether supplier requirements changed for your submission. After a cycle closes, evidence still needs continuous maintenance for the next year and for buyer due diligence between submissions.

A common supplier gotcha is that Cyber Essentials Plus has not provided equivalence for the toolkit’s MFA evidence item since October 2023. Treat MFA as something you evidence directly. ISO 27001 can still help where certificate scope genuinely covers health and care data processing, but it does not erase NHS-specific requirements.

Penetration testing is not a magic “pass DSPT” button. It is one of the strongest ways to support technical outcomes around protecting systems from exploitation of known vulnerabilities, managing vulnerabilities, and demonstrating that network and application defences have been challenged. For trust-side DSPT context, see penetration testing in the NHS DSPT. For the regulation-change angle, see DSPT v8 and DTAC v2 penetration testing evidence.

Where health-tech vendors go wrong

  1. Scan-as-pentest - submitting automated vulnerability output without manual validation of exploitability or business impact.
  2. Token scope - testing a marketing site while the authenticated clinical or admin product stays out of scope.
  3. Stale reports - a two-year-old test when buyers ask what happened in the last 12 months.
  4. No remediation trail - Critical and High findings still open when a trust asks for closure evidence.
  5. Framework confusion - assuming a DSPT submission letter substitutes for DTAC product evidence, or the reverse.
  6. Buying on badges alone - choosing a supplier without checking who will test and how the report will read to a non-specialist NHS reviewer.

NHS buyers prefer testing by competent practitioners with recognised professional credentials. Attack Vector lead consulting credentials include Cyber Scheme Team Leader (CSTL), from The Cyber Scheme, and Chartered Cyber Security Professional (ChCSP), the UK Cyber Security Council's chartered title.

What a useful evidence pack looks like

A vendor-ready pack usually includes:

  • Written scope matching the product architecture and data flows shown to the NHS buyer
  • Rules of engagement and test window notes
  • Executive summary suitable for IG and procurement readers
  • Technical findings with evidence, severity and remediation guidance
  • Mapping notes to OWASP categories where relevant
  • Retest results for agreed priority findings
  • Clear statement of exclusions (third-party SaaS you cannot test, out-of-scope environments)

Attack Vector identifies security weaknesses so you can prioritise remediation. We do not remediate your systems as part of the test fee, and we do not claim to “pass DTAC” on your behalf.

What weak evidence costs vendors

The commercial risk is delayed revenue. A trust ready to pilot can stall for weeks when security evidence is thin. The safety risk is worse: shipping into care settings with unvalidated weaknesses in authentication, authorisation, APIs or supporting infrastructure. Treat testing as release-gating for NHS-bound products, not as a brochure exercise.

What testing evidence does not prove

  • DTAC and DSPT are NHS England / health and care assurance processes. Attack Vector provides independent testing evidence; it does not certify products or complete toolkit submissions.
  • Requirements and form wording evolve. Confirm the live DTAC form and your DSPT organisation type guidance for the cycle you are in.
  • IT suppliers are on a non-CAF DSPT path for 2025/26 per NHS England Digital; do not copy trust CAF outcome language blindly into a supplier submission.
  • No pentest guarantees procurement success.
  • From £1,500 applies to tightly defined scopes; multi-surface health products usually need a fuller day count.

If a buyer deadline is driving scope, try the instant quote calculator or email [email protected]. For NHS-specific service framing, use NHS DTAC penetration testing. Pricing context sits in the UK cost guide.

FAQ

Do we need both DTAC and DSPT as a health-tech vendor?

Often yes in practice: DTAC for the product assurance path into NHS use, and DSPT if your organisation handles NHS health and care data and must complete the toolkit. Confirm with your IG lead and the buying organisation’s due diligence list.

Is penetration testing legally mandatory for DTAC?

DTAC is an assessment framework used in NHS assurance and procurement. Technical security asks for testing evidence in practice for relevant internet-accessible products. It is required commercially more than it is a standalone criminal statute. Treat buyer expectations as real constraints.

Will Cyber Essentials alone satisfy technical security?

Usually no. Cyber Essentials (and Cyber Essentials Plus where risk justifies it) sits alongside penetration testing and other controls. They answer different questions.

How recent should our pentest be?

Test at least annually, and again after significant product or architecture change. DTAC expects testing within the last 12 months for internet-accessible products, with findings rated CVSS 7.0 or above mitigated.

Can we use staging instead of production?

Often yes if staging is representative. Document parity gaps. Some buyers care that production configuration and integrations were considered. Agree environment choice in scoping and state it in the report.

Suggested Resources

#dtac#dspt#nhs#health-tech#penetration-testing

Ready to strengthen your security?

Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.