What a software supplier to NHS trusts needs to do to be compliant
An annual Category 2 DSPT with independent assessment, a DTAC with every trust you sell to, DCB 0129 to pair with each trust's DCB 0160, Cyber Essentials Plus and an annual pen test. Tenders routinely add ISO 27001, and diagnostic products bring UKCA and MHRA.
Reviewed 5 July 2026 · Neil Chandarana, founder, Highguard
Every requirement for an NHS trust software supplier, in plain English.
DSPT, Category 2, now independently assessed
- Category 2, CAF-aligned, 12 mandatory assertions
- Independent assessment from 2025-26
- Publish annually by 30 June
Suppliers that process NHS patient data or connect to national systems complete the Category 2 toolkit, aligned to the Cyber Assessment Framework with twelve mandatory assertions. From the 2025-26 year this tier requires an independent assessment rather than pure self-assessment, with publication due by 30 June each year. The first audit cycle ran in the first half of 2026, so assessors' expectations are now set and known.
Sources: DSPT Toolkit · DSPT Toolkit
DTAC, with every trust
- Assessed per trust, no passporting
- Refreshed February 2026
- Most trusts re-review annually
There is no passporting. Each trust runs its own DTAC review across clinical safety, data protection, security, interoperability and usability, and most re-review annually. The February 2026 refresh cut the form by about a quarter, removed questions the DSPT already answers, and added explicit guidance for pilots and multi-organisation rollouts. Trusts also expect DPIA support alongside it: processing details, data flows and sub-processor lists ready to hand. Ten trusts means ten assessments; the work compounds unless the evidence behind it is kept current in one place.
Sources: NHS England · HTN
DCB 0129, paired with the trust's DCB 0160
- Supplier holds DCB 0129, trust holds DCB 0160
- Named CSO, hazard log, safety case
- Deployment blocked without both
You hold DCB 0129 as the manufacturer: a named registered-clinician Clinical Safety Officer, hazard log and clinical safety case. The trust holds DCB 0160 for deployment and needs your artefacts to complete it. Trusts cannot deploy clinical software without both sides in place, so a missing safety case blocks go-live, not just procurement.
Sources: NHS Digital · NHS England
Cyber Essentials Plus
- Driven by PPN 014
- NHS Supply Chain mandates CE Plus since Sept 2025
- Renewed annually
Effectively mandatory. Government procurement policy (PPN 014) pushes certification through public-sector contracts, and NHS Supply Chain has mandated Cyber Essentials Plus for relevant suppliers since September 2025, with a valid Plus certificate waiving parts of its own security questionnaire. The Plus level is independently audited, so it has to reflect how your systems are actually configured, not how the policy says they are.
Sources: NHS Supply Chain
ISO 27001 and annual penetration testing
- ISO 27001 expected in tenders
- External pen test annually, OWASP Top 10
ISO 27001 is not a legal requirement, but trust tenders routinely demand it and treating it as optional narrows your pipeline. Done properly, your DSPT evidence covers a meaningful share of it, which is the argument for holding both in one evidence base. An annual external penetration test covering the OWASP Top 10 is the standing expectation, and DTAC wants it less than twelve months old.
Sources: DSPT Toolkit · NHS England
UKCA and MHRA, for diagnostic or decision-support software
- Applies to diagnostic and decision-support software
- Class IIa and above needs a UK Approved Body
If the product diagnoses, triages or supports clinical decisions, it is likely software as a medical device: MHRA registration and UKCA marking, with Class IIa and above requiring a UK Approved Body. CE-marked devices under the EU MDR remain accepted in Great Britain until mid-2030, which buys transition time but not exemption. Classification determines timelines measured in months, so settle it before the tender that depends on it.
Sources: GOV.UK (MHRA)
NHS trust supplier compliance as you grow.
First pilot
DSPT published, DCB 0129 with a named CSO, Cyber Essentials, and one DTAC completed for the pilot trust. The minimum credible set.
Multi-trust
Cyber Essentials Plus, ISO 27001 pressure from tenders, a per-trust DTAC pipeline and annual pen tests. This is where evidence reuse starts paying for itself.
National and frameworks
The independently assessed DSPT tier, framework listings, and device registration where the product qualifies. Compliance becomes a standing function, not a project.
NHS trust supplier compliance, asked and answered.
What do we need before we can sell software to an NHS trust?
As a baseline: a published DSPT, a completed DTAC with that trust, DCB 0129 clinical risk management with a named Clinical Safety Officer, and Cyber Essentials. Most trusts also expect a recent penetration test, and many tenders ask for ISO 27001.
Is Cyber Essentials Plus mandatory for NHS suppliers?
Close to it. Procurement policy note PPN 014 drives it through public contracts and NHS Supply Chain has mandated Cyber Essentials Plus for relevant suppliers since September 2025. Treat it as a requirement.
Does passing DTAC with one trust cover the others?
No. There is no passporting, and each trust assesses independently, with most re-reviewing annually. The evidence is reusable even though the assessment is not.
Do we need ISO 27001 to win NHS tenders?
It is not mandated, but it is routinely demanded in trust tenders and its absence costs marks or disqualifies. Your DSPT evidence covers a meaningful share of it if both are done properly.
When does our software count as a medical device?
When it diagnoses, triages or otherwise informs clinical decisions. That triggers MHRA registration and UKCA marking, and Class IIa and above needs a UK Approved Body review.
Why this list keeps getting longer.
Somewhere along the way, compliance stopped being about security and became about admin. Portals, spreadsheets, evidence uploaded again and again, policy templates nobody reads.
The result is organisations that are certified but not secure. Teams that are busy but not protected.
It should not work like this. Compliance should be a side effect of good practice. Evidence of the work you already do, not a second job on top of it.
That is why Highguard exists. We are your compliance department. Specialists and AI agents do the work on this page, and you approve every word before anything is submitted.
Every engagement starts with an audit. In your first week you get a report of where you are compliant and where you are exposed, specific to your organisation.
Talk to us →Talk to us.
Book a 15-minute call. We'll show you where you stand and how fast we can get you certified.