UK Market Entry for Digital Health: The Security and Regulatory Roadmap for NHS-Ready Products
At almost every industry event we've attended this year, the same conversation has come up. A digital health or medical device company, already selling across Europe or the US, tells us they want to bring their product to the UK. When we ask what their plan is, the answer is usually some version of: we're not really sure where to start.
Most of the advice available on UK market entry is commercial and legal: how to register a company, how to find a distributor, how reimbursement works. All of that matters. But for health tech specifically, especially anything aimed at the NHS, there's a second journey that almost nobody is mapping out publicly: the security and data protection route a product has to take before an NHS trust or commissioner will even engage in a serious procurement conversation. That's usually the part that stalls a deal after the commercial groundwork is already done.
We've built this roadmap in practice, working directly with overseas companies going through it. Here's what it actually looks like.
Why the Commercial Route Isn't the Whole Story
Getting a UK entity in place, appointing a distributor, understanding NHS procurement routes: this is necessary work, and there's good advice out there for it. What that advice tends to skip is that NHS buyers, and the frameworks they operate under, will ask for specific security and compliance evidence before a product gets anywhere near a live conversation. Without that evidence in place, commercial readiness doesn't translate into an actual deal. The rest of this article is that evidence roadmap.
The Security Roadmap: Cyber Essentials to DTAC
Cyber Essentials and Cyber Essentials Plus
This is the entry point. Cyber Essentials has been mandatory since February 2025 for a wide range of UK government and NHS contracts under Procurement Policy Note 014, covering any contract involving personal data, technical products, or access to government networks.
Where a contract involves sensitive data or critical services (which most health tech does), Cyber Essentials Plus is the expected standard. From September 2026, G-Cloud 15 will require Cyber Essentials across all supplier lots, with Cyber Essentials Plus specifically required for cloud hosting.
If your company already holds a comparable certification such as ISO 27001 or SOC 2, this stage is rarely a rebuild. It's usually a mapping exercise: taking controls you already have in place and demonstrating how they satisfy the Cyber Essentials requirements, rather than standing up a new security programme from scratch.
CREST-Accredited Penetration Testing
CREST is the UK's accreditation body for penetration testing. Rather than any firm being free to call itself a penetration testing provider, CREST certifies both the companies carrying out the work and the individual testers, against a defined technical standard, through its own exams and audits.
NHS buyers specifically look for penetration testing carried out by a CREST-accredited tester, whether that's a web application, a mobile app, or a physical device, depending on what you've built.
This is where we most often see a specific, narrow gap.
Many companies coming from the EU or US already have penetration testing completed properly, by a competent tester, as part of their existing compliance obligations. That work is still valid. The gap is usually one of recognition rather than quality: most NHS Trusts specifically look for CREST accreditation, and a test carried out under a different scheme, however sound, doesn't carry the same weight in an NHS procurement conversation.
The fix is typically a CREST-accredited test or re-test, so the evidence lines up with what buyers are actually looking for.
NHS DSPT (Data Security and Protection Toolkit)
The DSPT is an online self-assessment that any organisation accessing NHS patient data or systems has to complete every year.
It exists to check suppliers against the National Data Guardian's ten data security standards, a set of expectations covering things like staff training, access controls, incident response, and supply chain management.
In practical terms, it's how the NHS satisfies itself that a supplier can be trusted with patient data before that supplier gets anywhere near a live system.
Since 2025, the DSPT has been rebuilt around the NCSC's Cyber Assessment Framework, the same model used to assess UK critical national infrastructure. So instead of ticking boxes to confirm a control exists, suppliers now need to show evidence that the control actually works, organised across five objectives covering areas such as governance, vulnerability management, monitoring, and incident response, plus a fifth objective specific to the NHS covering the lawful use and sharing of patient data.
Suppliers assessed as higher risk also need an independent audit to validate their self-assessment rather than simply declaring it themselves.
The outcome you're working towards is a "Standards Met" status, and it builds directly on the Cyber Essentials Plus and penetration testing work already in place.
One key detail worth knowing: Cyber Essentials Plus no longer counts as sufficient evidence on its own for the DSPT's multi-factor authentication requirement. Suppliers who assume CE+ covers this automatically need a separate, specific control in place, which is exactly the kind of detail that's easy to miss if you're working from general UK GDPR or security guidance rather than DSPT itself.
DTAC (Digital Technology Assessment Criteria)
NHS England introduced DTAC in 2021 because, before that, every NHS trust and social care organisation assessed new digital products in its own way, at its own pace, on its own paperwork, which made it slow and inconsistent for any supplier trying to sell into more than one part of the NHS.
DTAC replaced that patchwork with a single national assessment: one standard set of questions covering clinical safety, data protection, technical assurance, interoperability, and usability, so any NHS buyer can assess a product against the same benchmark rather than inventing their own.
DSPT sits inside DTAC's data protection section: you can't be DTAC compliant without a valid DSPT submission, but a DSPT submission on its own doesn't make you DTAC compliant either.
NHS England refreshed DTAC in 2026, shortening the assessment form and removing questions that duplicated DSPT and other existing processes, which makes the two frameworks work together more cleanly than they used to.
ISO 27001 and SOC 2 as Supporting Evidence
Neither is mandatory for DSPT or DTAC, but both come up repeatedly as supporting evidence within the questions each framework asks.
Entering the UK market holding one or both, gives you a genuine head start here: it's evidence that maps directly onto what DSPT and DTAC are asking for, rather than an additional certification to chase.
How Do I Get My Medical Device Approved in the UK?
If your product qualifies as Software as a Medical Device (SaMD), there's a separate regulatory track running alongside the security roadmap above, not instead of it.
The The Medicines and Healthcare products Regulatory Agency (MHRA) is the UK's medical device regulator, roughly the equivalent of your relationship with a notified body under EU MDR or with the FDA in the US.
Since Brexit, the UK has run its own medical device regime rather than automatically recognising CE marking, so registering with the MHRA and working towards a UKCA mark, the UK's own equivalent of the CE mark, are separate steps from anything already done in Europe or the US.
This covers MHRA registration, UKCA marking, and appointing a UK Responsible Person if you don't have a UK manufacturing presence, the UK's equivalent of the EU Authorised Representative role many companies already have in place.
There are transitional arrangements allowing CE-marked devices to remain on the GB market for a period, and the UK is also introducing international reliance routes that may let manufacturers lean on existing EU, US, or other approvals for a more streamlined path to GB market access.
This is a separate compliance track with its own timeline, worth planning alongside the security roadmap rather than assuming one covers the other.
How Do I Work With the NHS as a European Entity? The Step Most Companies Miss
This is the piece we see missed most often, largely because it doesn't show up in general commercial market-entry advice.
When the UK left the EU, UK GDPR split off from EU GDPR into its own separate legal regime. The two remain close in substance, which is easy to mistake for equivalence, but a company that already has an EU Article 27 representative and an EU DPO in place still needs to make the matching UK appointments separately, since compliance with EU GDPR doesn't extend to UK GDPR automatically.
Under UK GDPR, a company without a UK establishment that processes UK personal data needs to appoint a UK Representative under Article 27. Separately, depending on the scale and nature of the data being processed, which for most health tech involves special category health data at scale, a Data Protection Officer under Article 37 is also likely to be required.
These are two distinct roles, and it's worth being precise about the difference.
A Representative acts on the instruction of the company that appoints them. A DPO is required to act independently of it. Because of that, the same party can't hold both roles for the same client at the same time. In practice, this means a company might use one provider as its UK Representative while another party, whether that's an internal team member or a separate appointment, holds the DPO role, or the other way round, depending on how the business is structured.
Periculo can act as either the UK Representative or the DPO, depending on what a client's structure calls for, which covers this requirement properly rather than glossing over the distinction.
Same Journey, Faster: When You're Not Starting From Zero
The most common client we see going through this already has an established product doing well in Europe or the US, foundational security certifications in place, existing penetration testing, and often an EU GDPR representative already appointed.
For that company, this roadmap is a mapping exercise: taking the controls, certifications, and appointments already live and cross-referencing them against Cyber Essentials, UK GDPR, and DSPT requirements to identify precisely what's missing.
That mapping work is usually what turns UK market entry from a daunting six-month unknown into a clearly scoped, much faster piece of work.
One Partner for the Whole Roadmap
Everything above, Cyber Essentials through to DTAC, the MHRA track for medical devices, and UK Representative or DPO appointment, can be run as five or six separate supplier relationships.
Most companies entering a new market end up doing exactly that: one firm for Cyber Essentials, another for penetration testing, a specialist for DSPT, someone else again for the medical device side, and a further appointment for data protection.
Periculo runs this as one managed service instead.
We map the full roadmap against where a company already stands, then apply the right resource against each stage ourselves: security certification, testing, DSPT and DTAC submission, and UK GDPR representation, all coordinated by one team who already understands how each piece connects to the next.
That coordination is usually where the cost and time actually go when the work is split across separate vendors, since each one only sees their own piece of the picture.
For a company entering the UK for the first time, that means a single point of contact who already knows this route well, rather than five contracts and five separate timelines to get to the same place.
It also tends to work out considerably more cost-effective than assembling and managing that many vendor relationships individually.
Where to Start
This roadmap is what we've built, repeatedly, in direct conversations with digital health and medical device companies working out how to bring an established product into the UK and specifically into the NHS. If you're at the point of asking where to start, that's usually the right moment for a proper scoping conversation rather than trying to map it out alone.
Feel free to get in touch or book a call, and we'll walk through exactly where your product sits on this roadmap.