Every supplier pitching digital tools to your practice will wave acronyms at you. Here is what the three that matter actually mean, in the order your ICB will ask about them.
DTAC: the entry ticket
The Digital Technology Assessment Criteria is the NHS's baseline check for digital health tools. It bundles five assessments into one: clinical safety, data protection, technical security, interoperability, and usability and accessibility. It is not a certificate a supplier wins once and frames. It is a pack of evidence your commissioners can read. When a supplier says "DTAC ready", the useful follow-up is: send me the pack. A serious supplier sends it the same day.
DCB0129: the safety case
DCB0129 is the clinical risk management standard for manufacturers of health IT. Complying with it means the supplier maintains a clinical safety case and a hazard log, and, crucially, employs a named Clinical Safety Officer: a registered clinician trained in clinical risk who signs releases and can block them. For anything that speaks to patients, this is the difference between a general-purpose bot and a system engineered for healthcare. Ask for the CSO's name. If there is no name, there is no standard.
DSPT: the annual data promise
The Data Security and Protection Toolkit is the NHS's yearly self-assessment against the National Data Guardian's standards. Suppliers who touch patient data publish their status on a public register, which means you can check it yourself in two minutes rather than taking a slide's word for it.
The questions to ask any supplier
Four questions sort the credible from the confident: Can I see your DTAC pack? Who is your named Clinical Safety Officer? What is your DSPT status on the register? And where, by contract, does patient data live? Our own answers are on the trust page, and we will walk your IG lead through them on a demo.
This guide is general information for practice managers, not legal or regulatory advice.