NHS DTAC 2026: What Startups Need to Pass v2
NHS DTAC 2026 changed on 6 April. A practical startup guide to passing DTAC v2: the five pillars, where startups fail, and a clear 10-week submission plan.
Tristan Derry · 28 June 2026 · 6 min read
DTAC v2 changed in April 2026 and most startups have not noticed
NHS England replaced the DTAC form on 6 April 2026. The new version cuts roughly 25% of the questions, removes the NHS-specific Clinical Safety Officer training requirement, and adds a decision tree that forces you to answer whether your product is a medical device before you can answer anything else (HTN Health Tech News). If you saved an NHS DTAC checklist before April, throw it away.
Three changes matter most. Scope now aligns with NICE's Evidence Standards Framework, so the clinical evidence you submit has to match the tier your product sits in. The Pre-Acquisition Questionnaire and DSPT overlap is gone, so duplicated answers look careless rather than thorough.
The third change is structural. The clinical safety section runs directly off the new decision tree, so you cannot fudge whether you are a medical device. Either DCB0129 applies and you sign a safety case, or it does not and you say so on the record.
The opinion most consultants will not give you: DTAC is now a procurement document
DTAC has always been an assurance framework, not a regulator. In v2, NHS England has pushed the integration burden from buyer to supplier and made the pack itself the artefact of trust. That changes how you should write it.
Your reader at the trust is not grading you for technical accuracy. They are using your DTAC pack to defend a buying decision to their own digital, IG, and clinical safety leads. A clean pack is a procurement weapon, and a messy one stalls the conversation for a full governance cycle.
Write your DTAC pack like a board paper. Every section should answer one question: why is buying you safer than the status quo of doing nothing.
The five DTAC pillars and what "good" actually looks like
Clinical safety
If your product is clinical IT, DCB0129 applies and you need a Hazard Log and a Clinical Safety Case Report signed by a registered CSO. The CSO no longer needs NHS-specific training under v2, but you still have to demonstrate equivalent competence in writing.
In practice the bar has gone up, not down. Trusts know the formal training requirement was relaxed and they are asking sharper questions about the CSO's real-world experience. Pick someone who has owned a safety case before, not someone who has only attended a course.
Data protection
You need a current DPIA, a documented lawful basis, and a DSPT submission at the level the trust expects. If you process special category clinical data, you almost always need Article 9(2)(h) for direct care plus an appropriate Article 6 basis. Consent is rarely the right answer inside an NHS care pathway.
A buyer should find your lawful basis in under thirty seconds. If they cannot, the pack goes to the bottom of the queue.
Technical security
Cyber Essentials is the floor. A pen test within the last twelve months is now stated explicitly in v2, alongside evidence that priority vulnerabilities have been remediated. Bring the certificate, the test summary, and a one-page remediation log to every conversation.
Interoperability
You now have to justify your API and data standard choices against NHS-recognised guidance. FHIR UK Core is the default expectation for new clinical data exchange. If you have reason to use something else, put it in writing before the trust has to ask.
Usability and accessibility
WCAG 2.2 AA evidence, real user testing notes, and a public accessibility statement are the minimum. Lab screenshots do not count. A 45-minute session with two NHS users on real ward hardware beats any glossy consultancy audit.
Where startups fail DTAC
The most common failure is treating DTAC as a paperwork sprint at the end of a sales cycle. By then your evidence is stale, your CSO has not seen the last three releases, and your DPIA does not match what the product actually does. The trust asks for revisions, you scramble, and the next digital governance meeting bumps you a quarter.
A concrete failure pattern: a UK ambient-scribe vendor in late 2025 entered a trust pilot with a strong product and no Clinical Safety Case Report, on the argument that the tool was "decision support only". The trust's CSO disagreed under DCB0160 review and blocked deployment. By the time the safety case was rebuilt, a competitor with a less impressive product and a complete DTAC pack had signed the contract.
The fix is structural. Build the pack alongside the product. Every release should ship with an updated Hazard Log, a refreshed DPIA where data flows changed, and a current pen test summary at a defensible cadence.
What a passing DTAC submission actually looks like
A startup example. A small UK diagnostic startup we have worked with submits a single PDF index that links to a current Clinical Safety Case Report under DCB0129, a quarterly-refreshed DPIA, Cyber Essentials Plus, a pen test report from the last 90 days, a FHIR UK Core integration brief, and a WCAG 2.2 AA audit signed by an external tester. Fourteen documents, one shared folder, one reviewer can clear it in an afternoon. They have closed three NHS deals in the last twelve months and none stalled at DTAC.
An NHS example. Guy's and St Thomas' has been publishing what they want from suppliers up front, including a preferred order of evidence and a named contact for each pillar. Suppliers who match that order get faster reviews. The lesson generalises across trusts: ask the buyer how they want to receive the pack before you build it.
A failure example. A consumer mental health app tried to enter an ICB pilot in 2024 listing "Article 6(1)(a) consent" as the lawful basis for processing clinical notes inside a referral pathway. The ICB's IG lead spotted it on first review because direct care needs an Article 9 condition. The pilot paused for six weeks while the basis was redone, and the founders burned trust they did not need to spend.
A 10-week DTAC plan for a seed-stage startup
Weeks 1 to 2: classify your product using the new decision tree and lock down whether DCB0129 applies. Confirm whether your CSO is internal or contracted, and write a one-page competence note that a sceptical trust could read and trust.
Weeks 3 to 5: run the DPIA from scratch against current data flows, achieve Cyber Essentials if you do not have it, and book a pen test. Schedule an accessibility audit in parallel, because external testers take longer than founders expect.
Weeks 6 to 8: write the Clinical Safety Case Report, build the Hazard Log, complete the DSPT at the right level, and draft an interoperability statement against FHIR UK Core. Weeks 9 to 10: assemble a single PDF index, get internal sign-off, and run a dry submission with a friendly NHS contact before the real one. Pre-submission reviews with NHS-side experts regularly surface material issues that would otherwise have killed the deal (Orbion case studies).
Bottom line
DTAC v2 is a shorter form and a higher bar. The shorter form punishes vague answers, and the higher bar rewards startups that built their evidence as they built their product. If you have not refreshed your pack since 6 April 2026, do it before your next NHS sales conversation.
Orbion Connect matches healthtech companies with NHS clinical, regulatory, and safety experts who can pressure-test a DTAC pack before a trust sees it. Learn how we work on the about page.
Need clinical expertise for your healthtech product?
Orbion Connect matches healthtech teams with vetted clinicians in days. Find the right experts to validate, build, and de-risk your product.
Find an Expert