Digital Technology Assessment Criteria (DTAC)

By CHASE Team

Last edited: September 9, 2026

The Digital Technology Assessment Criteria (DTAC) is the national baseline that NHS and social care organisations in England use when assessing digital health technologies before buying or deploying them. It gives commissioners a consistent set of questions and gives suppliers a single, predictable format instead of a different assessment from every trust.

DTAC is an assurance and procurement tool, not a regulatory approval. It does not replace UKCA or CE marking, and completing it does not make a product a lawful medical device if it was not one already. Equally, being a regulated device does not exempt a supplier from DTAC, because the criteria cover areas regulation does not, such as NHS interoperability standards.

The five core areas

  • Clinical safety: evidence of compliance with the clinical risk management standard for health IT manufacturers, including a named clinical safety officer, hazard log and clinical safety case report.
  • Data protection: UK GDPR compliance, a data protection impact assessment, lawful basis, transparency and completion of the Data Security and Protection Toolkit.
  • Technical assurance: security testing including penetration testing, secure development practice, resilience and business continuity.
  • Interoperability: use of open standards and NHS technical standards, including HL7 FHIR and NHS Number use where relevant.
  • Usability and accessibility: conformance with accessibility requirements and evidence of user research and testing.

How it is scored

Sections are completed by the supplier and reviewed by the buying organisation. Some questions are mandatory pass or fail, while the usability and accessibility section produces a score that informs the decision rather than blocking it outright. Buyers may add their own local requirements on top.

Preparing well

The most common cause of delay is treating DTAC as paperwork to assemble at the end of a sales cycle. The evidence it asks for, particularly the clinical safety case and the data protection impact assessment, takes time to produce properly and is difficult to fabricate retrospectively. Suppliers who build this documentation alongside development can typically respond to a DTAC request in days rather than months.