By EJN Labs · 15 Sep 2026 · 7 min read
NHS buyers commissioning a new app typically expect two things: a CREST-accredited penetration test report covering the build, its APIs and its cloud environment, and evidence that ties into your DTAC submission. Separately, UK GDPR Article 32(1)(d) requires a process for regularly testing your security measures, though it does not name penetration testing as the method. One well-scoped engagement usually answers both.
Why do NHS buyers ask app builders for penetration testing and UK GDPR evidence?
NHS buyers ask because your app inherits their clinical and information governance risk once it touches patient data. A procurement or governance lead cannot verify your codebase directly, so an independent penetration test report becomes the evidence they file to show due diligence was done.
That risk shows up early in the buying cycle. Digital health procurement in the NHS routinely runs supplier security questions alongside clinical safety and information governance checks, and an app that cannot produce a recent report stalls at that stage regardless of how good the product is. Getting this evidence ready before you are asked shortens the process rather than lengthening it.
What do DTAC and UK GDPR actually require from your app?
DTAC is a buyer requirement, not law: NHS bodies use DTAC to assess digital products before adoption, and its cyber security section expects evidence that penetration testing has been carried out. UK GDPR Article 32(1)(d) separately requires regular testing of your security measures, without naming a method.
NHS organisations are expected to assess digital products against the criteria before procurement, but DTAC itself does not name a specific testing standard or provider type, so an app builder has to interpret what counts as sufficient evidence; Cyber Essentials certification is also expected wherever the product handles patient data. Article 32(1)(d) works the same way: the duty is to test regularly, not to commission any one named product. Suppliers who also hold data-sharing agreements with NHS trusts often meet a third framework here too, the NHS Data Security and Protection Toolkit, which places its own annual test requirement under a separate standard.
What does DTAC-compatible reporting actually include?
DTAC-compatible reporting means a penetration test report an assessor can map onto the cyber security criteria: dated within 12 months, scoped to the application, APIs and cloud environment holding patient data, delivered by a CREST-accredited firm, with high or critical findings shown as verified fixes.
First-time NHS suppliers commonly underestimate the scope point. A report that only covers the marketing website says nothing about the patient-facing application or the API layer moving clinical data, and in our experience an assessor reading it asks for the missing coverage before the submission can move forward.
- The application itself. Authentication, session handling and role separation between patients, clinicians and administrators, since NHS apps typically carry more than one user type.
- The API layer. API penetration testing for object-level authorisation, the flaw class most likely to let one patient reach another patient’s record.
- The mobile client, where one exists. Mobile application testing for local storage, certificate handling and what a lost or compromised device exposes.
- The cloud environment. Storage configuration, identity and access management, and separation between production data and any test or staging copy.
Our longer guide to a DTAC-compatible penetration test report sets out how each finding should be written so an assessor can trace it back to the relevant criterion, and our breakdown of DTAC technical security expectations covers the criteria themselves in more depth.
How does a penetration test for an NHS-bound app get scoped and run?
Scoping starts with a short call covering the application, its user roles, the APIs it calls and where patient data is stored, from which we fix a day count and price. Testing then runs against a staging build wherever one exists, so synthetic rather than real patient records sit in the test environment.
High and critical findings are flagged the same day rather than held for the final report, so remediation can start before testing even finishes. A retest confirms fixes, and the final report maps each finding to severity and to the DTAC criterion it evidences, ready to sit inside your submission pack.
What does penetration testing cost before an NHS procurement deadline?
Day rates for CREST-accredited UK testing typically sit between £1,100 and £1,400. A single web application with its core API usually takes 4 to 6 days, so £4,400 to £8,400. Adding a mobile client or a fuller cloud review takes most NHS-bound apps to 6 to 9 days, £6,600 to £12,600.
Scope is what moves the number, not the NHS name on the buyer. A multi-role clinician and patient app with several API integrations costs more to test properly than a single-page booking form, and a short scoping call is the only reliable way to reach an exact figure.
| Scope | Typical effort | Typical UK cost |
|---|---|---|
| Single web application plus core API | 4 to 6 days | £4,400 to £8,400 |
| Web application, mobile client and API | 6 to 9 days | £6,600 to £12,600 |
| Full estate: app, mobile, API and cloud | 8 to 12 days | £8,800 to £16,800 |
| Retest after remediation | 1 to 2 days | £1,100 to £2,800 |
These are typical UK ranges rather than a quote for your build. Our guide to penetration testing costs in the UK covers how day counts and rates combine more generally, and a fixed price for your specific app comes from scoping.
How EJN Labs approaches penetration testing for NHS app builders
EJN Labs is a UK-based, CREST-accredited penetration testing firm, also certified to ISO 27001 and Cyber Essentials Plus. All testing is delivered by UK-based testers, and every NHS-bound engagement starts from the data flow: where patient data enters the app, which APIs move it, and which roles can reach it.
That approach is what catches the authorisation flaw between a patient account and a clinician account, the finding class a checklist-driven scan usually misses and an NHS assessor often asks about. Reports are written so a non-technical information governance lead can map each finding to the DTAC criterion or GDPR obligation it evidences, and a retest confirms fixes before your submission goes in.
Frequently Asked Questions
Does the NHS legally require app builders to run a penetration test?
No single NHS instrument makes penetration testing a legal duty. DTAC is a buyer assessment, not legislation, and NHS organisations use it to judge whether a supplier’s evidence is credible before adoption. UK GDPR Article 32(1)(d) does impose a legal duty to test your security measures regularly, just not by name.
What penetration testing evidence do NHS buyers ask app builders to submit?
NHS buyers typically ask for a report from a CREST-accredited firm, dated within the last 12 months, covering the application, its APIs and its cloud environment, with high and critical findings shown as fixed and retested. Many also ask whether the test was internal or carried out by a third party.
How does NHS DSPT relate to DTAC penetration testing evidence?
DSPT and DTAC are separate but overlapping asks. NHS DSPT, the toolkit NHS suppliers and trusts complete annually, places a penetration test under its IT protection standard; DTAC applies specifically when a digital product is being assessed for adoption. Suppliers handling NHS data commonly end up completing both.
How long does it take to get a DTAC-ready pen test report?
Application and API engagements typically run one to two weeks of testing, with the report following within a few working days. Add time for remediation and a retest before your submission deadline: starting the process four to six weeks ahead of when the report is due leaves a comfortable margin.
What happens if a penetration test finds critical issues before our NHS deadline?
You fix the issue and we retest it once resolved, so the final report shows it as remediated rather than open. In our experience critical findings are the exception rather than the rule, but when one appears, we flag it the same day so remediation can start immediately, well before the report is finalised.
Get your NHS-bound app tested before the next submission deadline
If you are building software that NHS organisations will buy, we can scope a fixed-price penetration test around your application, APIs and cloud environment, mapped to what your DTAC submission and UK GDPR evidence file need. Get a CREST pentesting quote and we will come back with a scope and price built around your product.
Related research: our guide to NHS DTAC penetration testing covers the framework criterion by criterion, our piece on UK GDPR Article 32 for health and care providers looks at the same duty from a wider provider angle, and our UK GDPR evidence packs for mobile agencies guide covers the same evidence question outside the NHS context.




Leave a Reply