NHS DTAC requires digital health suppliers to hold a current Cyber Essentials or Cyber Essentials Plus certificate as the anchor requirement of its cyber security component.
If you are selling a digital health product into the NHS, you will already know that DTAC, the Digital Technology Assessment Criteria, is the gate you need to get through before a trust, ICB, or commissioning organisation will deploy your product. One of its five components, cyber security, has a specific and unavoidable requirement at its centre: Cyber Essentials.
This post looks specifically at what DTAC expects on Cyber Essentials, where Cyber Essentials Plus comes in, and how to avoid the certification questions that trip up so many digital health suppliers during procurement.
DTAC assesses five areas: clinical safety, data protection, cyber security, interoperability, and usability and accessibility. Cyber security is assessed through a mix of technical evidence, and a current Cyber Essentials or Cyber Essentials Plus certificate is the anchor requirement within that section.
Alongside your certificate, NHS buyers will expect to see evidence of an external penetration test, a documented action plan for any findings, multi-factor authentication across your systems, a working patching and vulnerability management process, and secure hosting and cloud configuration. Cyber Essentials proves the baseline; the rest of the evidence shows you can sustain it in practice.
DTAC's technical security requirement is met at the level of Cyber Essentials, a self-assessed questionnaire, independently verified by a certification body. There is no blanket rule in DTAC that forces every supplier to hold the more rigorous Cyber Essentials Plus, which adds an external vulnerability test and on-site or remote technical assessment.
In practice, though, the picture is more nuanced than "basic CE is always enough":
Our advice to digital health companies is consistent: treat Cyber Essentials Plus as the target, not the exception. It closes down a question NHS buyers ask often, and it strengthens every other part of your DTAC submission at the same time.
Health and care data is some of the most sensitive information any organisation can hold, and it is a persistent target for attackers. NHS procurement teams are not asking for Cyber Essentials as a box-ticking exercise, they are using it as the fastest, most standardised way to confirm that a supplier has basic technical hygiene in place before any patient data changes hands. It is the same logic behind PPN 014, the government's wider procurement policy requiring Cyber Essentials for contracts touching personal data or government systems: get a recognised baseline in place quickly, then layer additional scrutiny on top where risk warrants it.
Cyber Essentials also interacts with the other assurance frameworks inside DTAC. A current Cyber Essentials Plus certificate can be recorded on your NHS Data Security and Protection Toolkit (DSPT) submission, and combined with a "Standards Met" DSPT result, it moves your status to "Standards Exceeded" a detail worth knowing since DSPT is itself embedded inside DTAC's data protection component. We cover this relationship in more detail in a companion post on Cyber Essentials Plus and DSPT.
The suppliers who move fastest through NHS procurement are the ones who arrive with Cyber Essentials, or ideally Cyber Essentials Plus, already in place, not the ones scrambling to certify once a trust asks the question. If you know DTAC is coming, start the certification conversation now.
DTAC's technical security component is met at the level of standard Cyber Essentials, verified by a certification body. Cyber Essentials Plus isn't mandatory everywhere, but many NHS buyers request it for higher-risk products or larger volumes of patient data, and it's increasingly treated as the practical target.
Alongside a Cyber Essentials or Cyber Essentials Plus certificate, NHS buyers expect an external penetration test, a documented remediation plan, multi-factor authentication, an active patching process, and secure cloud hosting evidence.
A current Cyber Essentials Plus certificate can be recorded on your NHS Data Security and Protection Toolkit (DSPT) profile. Combined with a "Standards Met" DSPT result, it raises your overall status to "Standards Exceeded" and DSPT itself sits inside DTAC's data protection component.
Plan for at least three months before you need evidence, longer if remediation is required first. Certification, and especially the Plus audit, takes real preparation time, so starting only when an NHS buyer asks puts suppliers on the back foot.
Cyber Essentials certifies the legal entity delivering the service, and scope can be restricted to part of it. If your certificate doesn't actually cover the systems handling NHS data, it won't satisfy the DTAC requirement, so scope needs checking carefully.
We support digital health companies through both the certification and the wider DTAC submission: