Periculo Blog

NHS DTAC and Cyber Essentials: What Digital Health Suppliers Need to Know

Written by Craig Pepper | Jul 21, 2026 7:00:00 AM

NHS DTAC requires digital health suppliers to hold a current Cyber Essentials or Cyber Essentials Plus certificate as the anchor requirement of its cyber security component.

If you are selling a digital health product into the NHS, you will already know that DTAC, the Digital Technology Assessment Criteria, is the gate you need to get through before a trust, ICB, or commissioning organisation will deploy your product. One of its five components, cyber security, has a specific and unavoidable requirement at its centre: Cyber Essentials.

This post looks specifically at what DTAC expects on Cyber Essentials, where Cyber Essentials Plus comes in, and how to avoid the certification questions that trip up so many digital health suppliers during procurement.

Where Cyber Essentials Sits Within DTAC

DTAC assesses five areas: clinical safety, data protection, cyber security, interoperability, and usability and accessibility. Cyber security is assessed through a mix of technical evidence, and a current Cyber Essentials or Cyber Essentials Plus certificate is the anchor requirement within that section.

Alongside your certificate, NHS buyers will expect to see evidence of an external penetration test, a documented action plan for any findings, multi-factor authentication across your systems, a working patching and vulnerability management process, and secure hosting and cloud configuration. Cyber Essentials proves the baseline; the rest of the evidence shows you can sustain it in practice.

Cyber Essentials or Cyber Essentials Plus?

DTAC's technical security requirement is met at the level of Cyber Essentials, a self-assessed questionnaire, independently verified by a certification body. There is no blanket rule in DTAC that forces every supplier to hold the more rigorous Cyber Essentials Plus, which adds an external vulnerability test and on-site or remote technical assessment.

In practice, though, the picture is more nuanced than "basic CE is always enough":

  • Higher-risk applications, and products handling larger volumes of patient data, are frequently asked for Cyber Essentials Plus by name.
  • Some NHS organisations set their own local expectation that suppliers of business-critical systems hold Cyber Essentials Plus, regardless of what the DTAC form technically mandates.
  • Buyers increasingly treat Cyber Essentials Plus as a signal of genuine security maturity rather than paperwork, which matters when your product is competing against others that already hold it.

Our advice to digital health companies is consistent: treat Cyber Essentials Plus as the target, not the exception. It closes down a question NHS buyers ask often, and it strengthens every other part of your DTAC submission at the same time.

Why NHS Buyers Care About This Specifically

Health and care data is some of the most sensitive information any organisation can hold, and it is a persistent target for attackers. NHS procurement teams are not asking for Cyber Essentials as a box-ticking exercise, they are using it as the fastest, most standardised way to confirm that a supplier has basic technical hygiene in place before any patient data changes hands. It is the same logic behind PPN 014, the government's wider procurement policy requiring Cyber Essentials for contracts touching personal data or government systems: get a recognised baseline in place quickly, then layer additional scrutiny on top where risk warrants it.

Common Ways Suppliers Get Caught Out

  • Leaving certification until a buyer asks for it. Cyber Essentials assessments, and especially Cyber Essentials Plus audits, take time to prepare for properly. Starting only once an NHS buyer requests evidence puts you on the back foot in a live procurement.
  • Certifying the wrong scope. Cyber Essentials applies to the legal entity providing the service, but scope can be restricted to part of it. If your certificate does not actually cover the systems handling NHS data, it will not satisfy the DTAC requirement.
  • Letting certification lapse mid-contract. Cyber Essentials requires annual renewal. A lapsed certificate during a live NHS contract is a compliance gap that buyers will notice.
  • Assuming Cyber Essentials alone is "job done" on cyber security. DTAC's cyber security component also expects penetration testing, MFA, and patching evidence, Cyber Essentials is necessary, but on its own it is not sufficient.

Cyber Essentials, DTAC, and DSPT Together

Cyber Essentials also interacts with the other assurance frameworks inside DTAC. A current Cyber Essentials Plus certificate can be recorded on your NHS Data Security and Protection Toolkit (DSPT) submission, and combined with a "Standards Met" DSPT result, it moves your status to "Standards Exceeded" a detail worth knowing since DSPT is itself embedded inside DTAC's data protection component. We cover this relationship in more detail in a companion post on Cyber Essentials Plus and DSPT.

Getting Ahead of the Requirement

The suppliers who move fastest through NHS procurement are the ones who arrive with Cyber Essentials, or ideally Cyber Essentials Plus, already in place, not the ones scrambling to certify once a trust asks the question. If you know DTAC is coming, start the certification conversation now.

Frequently Asked Questions

Does DTAC require Cyber Essentials Plus, or just Cyber Essentials?

DTAC's technical security component is met at the level of standard Cyber Essentials, verified by a certification body. Cyber Essentials Plus isn't mandatory everywhere, but many NHS buyers request it for higher-risk products or larger volumes of patient data, and it's increasingly treated as the practical target.

What else does DTAC's cyber security section ask for besides Cyber Essentials?

Alongside a Cyber Essentials or Cyber Essentials Plus certificate, NHS buyers expect an external penetration test, a documented remediation plan, multi-factor authentication, an active patching process, and secure cloud hosting evidence.

How does Cyber Essentials Plus help with DSPT as well as DTAC?

A current Cyber Essentials Plus certificate can be recorded on your NHS Data Security and Protection Toolkit (DSPT) profile. Combined with a "Standards Met" DSPT result, it raises your overall status to "Standards Exceeded" and DSPT itself sits inside DTAC's data protection component.

How long does Cyber Essentials Plus certification take before a DTAC submission?

Plan for at least three months before you need evidence, longer if remediation is required first. Certification, and especially the Plus audit, takes real preparation time, so starting only when an NHS buyer asks puts suppliers on the back foot.

Does Cyber Essentials certify the whole company or just the product?

Cyber Essentials certifies the legal entity delivering the service, and scope can be restricted to part of it. If your certificate doesn't actually cover the systems handling NHS data, it won't satisfy the DTAC requirement, so scope needs checking carefully.

How Periculo Helps

We support digital health companies through both the certification and the wider DTAC submission:

  • Cyber Essentials and Cyber Essentials Plus certification, scoped correctly to the systems handling NHS data
  • External, CREST-accredited penetration testing to satisfy DTAC's cyber security evidence requirements
  • NHS DSPT audit support, so your Cyber Essentials Plus certificate carries through to "Standards Exceeded"
  • Full DTAC gap analysis and evidence pack assembly across all five components

Contact Us