← Back to blogRegulation

NHS Digital Safety Crisis: 70% Untested Before Sept 11

A new BMJ study shows 70% of NHS digital health tools lack DCB0129/DCB0160 assurance. What healthtech founders and clinical safety experts must do now.

Tristan Derry · 28 August 2026 · 7 min read

The £10bn digital NHS is running on tools nobody has signed off

A follow-up study published in BMJ Innovations this month found that of 14,848 digital health technologies deployed across 239 NHS trusts and integrated care boards in England, only 17.3% are fully assured against the mandatory DCB0129 and DCB0160 clinical safety standards, and 70.1% have no documented assurance at all (BMJ Group summary, August 2026). The authors warn the government's 10 Year Health Plan risks "propagating patient harm at unprecedented scale" if it accelerates rollout on this compliance base (Medscape coverage, 20 August 2026). The NHS England consultation on the future of DCB0129 and DCB0160 closes on 11 September, so you have two weeks to shape the rulebook that governs whether your product ships and whether your career pivot is worth planning around.

Note on timing: the follow-up analysis and its headline coverage broke on 18 August, ten days ago rather than seven, but the September consultation deadline and the £10bn AI rollout make this the story that matters this week.

What the study actually found

The original cross-sectional study, published in JMIR, sent a freedom of information notice to 239 NHS organisations in early 2025 and got responses from 204 of them (85.4%), covering nearly 15,000 deployed digital health technologies (JMIR, 2025). Only 13 of those 204 organisations (6.4%) reported full DCB0129 and DCB0160 compliance across their estate. The follow-up in August 2026 layered previously unpublished Clinical Safety Officer workforce data on top and asked why.

The workforce numbers explain most of it. NHS trusts reported an average of 1.3 full-time-equivalent Clinical Safety Officer capacity across their entire digital estate, and integrated care boards reported 0.4 FTE (News Medical, 18 August 2026). Thematic analysis of the free-text responses identified four reinforcing drivers of non-compliance: poor understanding of the standards, immature governance infrastructure, ineffective assurance processes, and the treatment of the CSO role as an ancillary duty absorbed into an existing job rather than a professionalised post.

NHS England's own consultation on DCB0129 and DCB0160, launched on 29 June, asks explicitly whether the standards should be replaced, whether they should extend to medical devices, and whether cybersecurity requirements should be built in (NHS England Citizen Space). It closes 11 September 2026.

Orbion's read on it

The bottleneck for NHS digital transformation is no longer the technology or even the money. It is the enforcement layer, which has been chronically under-resourced for a decade and is now the only thing standing between a £10bn AI rollout and the patient safety headline the health secretary cannot survive. Expect the consultation to end with harder teeth on both standards, not softer ones, and expect procurement gates to start policing evidence rather than accepting attestation.

The consensus interpretation frames this as an NHS problem, and it is not. It is a market signal for anyone selling into the NHS or building a career around clinical AI. When a regulator publishes numbers this bad in the same summer it launches ambient voice at scale, the political cost of the next avoidable incident lands on the vendor as much as on the trust. Assurance quality moves from a compliance line item to a competitive moat.

The vendors who will win the next 18 months of NHS budget are the ones who can walk into a procurement meeting with a live safety case, a named registered CSO, a hazard log tied to real deployment data, and a post-market surveillance plan that a trust can plug into its own DCB0160 process without extra work. Everyone else will lose to them on evaluation scores even when the underlying product is better.

What this means for healthtech founders and operators

You have five moves to make in the next two weeks.

First, audit your DCB0129 safety case as it actually exists today, not as it appeared in the sales deck. If your hazard log has not been reviewed since your last release, or if your CSO is a contractor who signed the initial case and has not been engaged since, you are one FOI request away from being cited in the next version of this study.

Second, get a named, registered Clinical Safety Officer on your cap table or payroll now, before the consultation closes and demand spikes. Fractional CSO day rates in London have already moved from around £650 to over £900 in the last twelve months, and the follow-up study's call for a "professionalised CSO workforce" will accelerate that trend.

Third, respond to the NHS England consultation before 11 September (consultation portal). If cybersecurity requirements land inside DCB0129, your ISO 27001 and DTAC positions need to be rewritten. Vendors who do not engage now will be governed by the responses of vendors who did.

Fourth, revisit your investor narrative. The Series B/C gap in UK digital health that the mid-market currently laments is partly a story about safety maturity: buyers who cannot verify assurance drag procurement cycles, which drag ARR, which drag valuations. Bring a CSO into your next board meeting.

Fifth, if you sell into trusts, offer a DCB0160 evidence pack alongside your DCB0129 case. Trust digital teams are drowning in deployment assurance work with 0.4 to 1.3 FTE capacity. Suppliers who make the buyer's job easier will close deals faster than suppliers with better tech.

What this means for healthcare experts

The professionalisation of the CSO role is the single biggest sell-side opportunity in UK healthtech this year, and it is not restricted to doctors.

If you are a clinical safety officer, digital nurse, informatics pharmacist, biomedical scientist, clinical scientist, or allied health professional with digital experience, you are now the scarce resource in a market with a fixed regulatory deadline. NHS trusts alone report an average 1.3 FTE of CSO capacity against thousands of technologies, and vendors selling into them need parity on the supplier side. Take the NHS Digital-recognised CSO training if you have not already, and put it on your LinkedIn headline.

If you are a GMC-registered doctor, remember the GMC's private practice and conflict of interest rules still apply to industry advisory work, and NHS whole-time contract holders need to check MPT arrangements before taking paid CSO retainers (Orbion, GMC rules). If you are NMC-registered, the Code applies to your industry work the same way it applies to clinical work, so your professional identity does not stop at the front door of a startup. HCPC-registered AHPs, clinical scientists, and biomedical scientists face the same principle under HCPC's standards of conduct.

If you are considering advisory work in this space, three questions to ask any vendor who approaches you: who is your current named CSO and how many hours do they work, when was your hazard log last updated against production data, and how are you responding to the DCB0129/DCB0160 consultation. A vendor who cannot answer all three is not ready for your name on their cap table.

If you are a health economist or NICE evaluator, note that the 27 August EQ-5D-5L switch in NICE reference-case analyses lands in the same fortnight as this safety story (NICE consultation on the value set). Vendors who need HTA and safety assurance in parallel are looking for expert help stitching the two workstreams together.

If you are a clinical safety lead in a trust, the follow-up study has just given you the evidence base to fight for a properly resourced digital safety function. Use it.

The wider pattern

Look at the last twelve months in UK healthtech and this study is not an outlier, it is the inflection point. MHRA published its draft 2026 amendment tightening SaMD classification and PCCP oversight, NHS England put ambient voice at the centre of a £10bn plan, NICE opened its Technology Appraisals programme to digital tools, and the National Commission on AI in Healthcare recommended lifecycle-based regulation with clearer liability rules. Every one of those moves increases the assurance work required per product deployed.

The compliance workforce has not grown to match. That gap is what this week's coverage has finally put a number on, and it is the gap that will decide which vendors and which experts capture the next wave of NHS budget.

What to do this week

Founders: run the five-move checklist above, and file your consultation response by Wednesday 10 September so you have a day of slack before the deadline. If you do not have a CSO, get a fractional one signed by end of next week.

Experts: read the follow-up study (BMJ Group), submit your own consultation response before 11 September, and update your LinkedIn to include DCB0129/DCB0160 experience if you have any real hours to show. If you are considering the CSO track, book the NHS Digital-recognised course this week.

Everyone: watch what NHS England signals about enforcement in the consultation response. That is the number that will price the next twelve months of UK digital health.

Need clinical expertise for your healthtech product?

Orbion Connect matches healthtech teams with vetted clinicians in days. Find the right experts to validate, build, and de-risk your product.

Find an Expert