Cibernetica.io

Testing

DTAC Penetration Testing

Testing evidence for the technical security section of your DTAC.

If an NHS organisation has asked you to complete a DTAC, you are usually working to a procurement deadline and being asked for evidence you may not currently hold. The technical security section typically requires an independent penetration test. This page covers that specific piece.

What the DTAC asks for, and where testing fits

The Digital Technology Assessment Criteria is the framework NHS organisations use when procuring digital health technologies. It covers clinical safety, data protection, technical security, interoperability, and usability and accessibility. Suppliers complete it and submit evidence; the procuring organisation reviews it. There is no certificate and no expiry — it is an assessment applied at the point of procurement. Penetration testing evidences part of the technical security section. What is expected is an independent test of the product, with a report showing findings and how they were remediated. A test showing serious unresolved issues is not automatically fatal, but an unremediated critical finding with no plan attached generally is. Some NHS organisations specify that testing be performed by a CREST-approved provider, and some do not. Where CREST is specified, we match accordingly. Where it is not, other credentials — OSCP-certified testers, CHECK-approved firms, or established testing practices — are commonly acceptable, and can be a better fit for scope and budget. Worth confirming what your specific procuring organisation requires before commissioning, since the two routes differ in cost. Cibernetica matches you with testers for this component. Completing the DTAC itself, including the clinical safety and data protection sections, remains yours.

Who needs it

  • Digital health suppliers asked to complete a DTAC as part of an NHS procurement
  • Health technology companies bidding for NHS work for the first time
  • Suppliers whose existing test report is out of date or does not cover the product in scope
  • Companies told specifically that a CREST-approved test is required

What you get

Scoping against what was actually asked

Which product, which environments, and whether the procuring organisation has specified CREST — established before quotes, so the test you buy is the test they will accept.

Matching on credential where it matters

CREST-approved providers where that has been specified. Where it has not, testers matched on relevant experience and cost rather than on a credential nobody required.

A report you can submit

Output in a form suitable for evidencing, including remediation status — a raw findings list without remediation evidence rarely satisfies a reviewer.

Frequently asked questions

Is DTAC a certification?

Not quite, although it is commonly described that way. DTAC is an assessment framework NHS organisations apply when procuring digital health technologies. You complete it and submit evidence; the procuring organisation reviews it as part of their decision. There is no certificate issued and no renewal date, though individual organisations may ask for updated evidence at intervals.

Does the test have to be CREST-approved?

It depends on the procuring organisation. Some specify CREST explicitly; many accept independent testing from providers with other credentials, such as OSCP-certified testers or CHECK-approved firms. Confirm what your specific NHS organisation requires before commissioning, because CREST-approved testing generally costs more and there is no benefit to buying it where it was not asked for.

What if the test finds serious issues?

Findings are expected — a report with none tends to raise more questions than it settles. What matters is remediation: fixing what was found and evidencing the fix, ideally through a retest. Agree retesting as part of the original engagement rather than discovering it is a separate cost later.

Does this cover the whole DTAC?

No. Penetration testing evidences part of the technical security section only. The clinical safety, data protection, interoperability, and usability sections are separate and remain your responsibility to complete. If you need support across the wider submission, that is a different engagement and worth scoping separately.