DTAC v2 Lands in April 2026: The Penetration Testing NHS Buyers Must Check

DTAC v2 Lands in April 2026: The Penetration Testing NHS Buyers Must Check

By EJN Labs · 11 Aug 2026 · 9 min read

From 6 April 2026, NHS buyers assess digital health products against DTAC v2, and its technical security section sets out the security evidence they ask suppliers to provide. Check that DTAC penetration testing evidence is recent (within 12 months), covers the web application, APIs and cloud infrastructure that handle patient data, was carried out by a CREST-accredited firm, and that high or critical findings show verified remediation. Typical UK engagements cost £4,800 to £16,800.

Why DTAC penetration testing evidence matters more from April 2026

DTAC penetration testing evidence matters more from April 2026 because that is when version 2 of the Digital Technology Assessment Criteria applies. DTAC, published by NHS England, is the baseline assessment NHS and social care organisations use before adopting a digital health product.

If you buy digital health technology for the NHS, that timing makes the penetration test report one of the most consequential documents in your procurement pack.

For CCIOs, CTOs, information governance leads and clinical safety officers, the practical question is not whether DTAC applies. It is whether the penetration test report a supplier hands over actually proves anything. This post is the buyer’s checklist: what to ask for and where suppliers most often fall short. For the framework itself, criterion by criterion, see our full guide to NHS DTAC penetration testing, which remains the definitive reference.

What DTAC actually requires, honestly stated

Version 2.0 of the DTAC form, in use from 6 April 2026, requires suppliers to evidence, among other things, Cyber Essentials certification at question C3.1 and, at question C3.3, the summary report of an external penetration test of an internet-facing product covering the OWASP Top 10 from within the previous 12 months, with no vulnerability scoring 7.0 or above on CVSS. Suppliers that have signed the Cyber Security Charter for Suppliers to the NHS answer yes at C3.2 and skip the rest of section C3. It is an assessment framework rather than a statute, but NHS England asks health and care organisations to review digital technologies against it before procurement.

In practice suppliers cannot sell into most NHS settings without passing. Penetration testing is the recognised technical evidence route for the security testing element, and application, API, cloud and infrastructure testing all count towards it.

Two honest caveats. First, DTAC does not name a specific testing standard, provider type or clause-level methodology, so we will not pretend it does. It asks for credible evidence that the technology has been security tested and that findings are managed. Second, the burden sits with the supplier, but the risk sits with you: if a product is compromised after go-live, it is the buying organisation’s patients and clinicians that are affected. That makes v2’s arrival the right trigger to tighten evidence checks now, while contracts are being renewed, rather than after the new criteria are in force.

Where a supplier’s product touches patient data, clinical workflows or NHS infrastructure, the scope of that evidence should reflect the whole estate, not just the marketing website. Our note on DTAC technical security expectations breaks down how the cyber security criteria map to specific test types.

The five checks NHS buyers should run on supplier evidence

  • Recency. A test older than 12 months, or older than the last major release, tells you about a product that no longer exists. Ask for the test date and the version tested.
  • Scope match. The report should name the web application, the APIs, the mobile clients and the cloud environment that will actually process your patients’ data. A test of a demo environment or a single public website is a red flag.
  • Accreditation. Was the test delivered by a CREST-accredited firm with UK-based testers? Accreditation gives you an external assurance chain; an unattributed internal scan does not.
  • Findings and remediation. A clean report with zero findings on a complex clinical system deserves suspicion. Look for high and critical findings with documented, retested fixes.
  • Report quality. The report should be written so an assessor can map it to the DTAC criteria. We cover exactly what that looks like in our guide to a DTAC-compatible penetration test report.

For a broader pre-engagement framework, our penetration testing checklist covers the questions to settle before any test is commissioned.

What a DTAC-driven engagement should cover

Cover every layer of the product estate: the clinician-facing web application, the patient mobile app, the APIs connecting to NHS or third-party systems, and the cloud environment holding the data. DTAC evidence is only as strong as its weakest layer.

Digital health products are rarely a single application, which is why the estate view matters, and each layer fails in different ways.

  • Web application testing against authentication, authorisation and session handling, because role separation between clinicians, administrators and patients is where health apps most often break.
  • API penetration testing for the integration layer, including object-level authorisation flaws that expose one patient’s record to another authenticated user.
  • Mobile application testing where a patient-facing app stores tokens or cached clinical data on the device.
  • Cloud penetration testing of the hosting environment: storage exposure, identity and access management, and segregation between production and non-production data.
  • External infrastructure testing of everything the internet can reach, which is the minimum DTAC has always implied.

How the engagement runs

The engagement runs in four steps: scoping, testing, reporting and retest. A short scoping call enumerates applications, APIs, user roles and cloud accounts, producing a fixed day count and price, and the shape is the same whether you are a trust validating a supplier or a founder preparing an NHS bid.

Testing runs against an agreed environment, ideally a staging system seeded with synthetic patient data, so no real records are placed at risk, and high or critical findings are flagged the day they are found. Reporting maps each finding to severity and to the DTAC cyber security criteria, and a free retest confirms remediation so the final evidence shows closure.

What it costs and how scope drives the price

UK penetration testing is priced by the day, and reputable firms charge £1,100 to £1,400 per tester day. Scope drives everything: the number of applications, API endpoints, user roles and cloud accounts determines the day count. Typical DTAC-driven engagements look like this:

EngagementTypical effortTypical UK cost
Web application penetration test4 to 6 days£4,400 to £8,400
API penetration test3 to 5 days£3,300 to £7,000
Cloud configuration review2 to 4 days£2,200 to £5,600
External infrastructure test2 to 3 days£2,200 to £4,200
Combined application, API and cloud8 to 12 days£8,800 to £16,800

These are typical UK ranges rather than quotes; an exact price needs a short scoping call. For a breakdown of what moves the number, see our guide to penetration testing costs in the UK.

How EJN Labs approaches DTAC v2 readiness

EJN Labs is a UK CREST-accredited penetration testing firm, and we hold Cyber Essentials Plus and ISO 27001 ourselves, so we sit on the same side of the assurance table our health and care clients do. When we scope a digital health product, we start from the data flows rather than the URL list: where patient data enters, which APIs move it, which cloud services store it, and which user roles can reach it. That is how we catch the authorisation flaws between patient, clinician and administrator roles that a checkbox-driven test misses, and why our reports map cleanly to the criteria an NHS assessor will read. All testing is delivered by UK-based testers, and remediation retests are included. If you are comparing firms, our guide to choosing the best UK penetration testing provider sets out the questions worth asking any of us.

Frequently Asked Questions

Does DTAC v2 make penetration testing mandatory from April 2026?

No, not in the statutory sense, because DTAC is an assessment framework rather than legislation. Its cyber security section still treats penetration testing as the primary evidence route for security testing of externally facing systems, so suppliers without credible testing evidence will struggle to pass from April 2026.

The pressure comes from procurement: NHS organisations are expected to assess digital health technologies against DTAC before buying, which is what turns the framework’s expectations into a commercial requirement.

What should NHS buyers check in a supplier’s penetration test report?

Check five things, starting with recency and scope: the test should be within 12 months and cover the current release, the scope should name the actual application, APIs and cloud environment that will hold patient data, and the work should have been delivered by a CREST-accredited firm.

The remaining two checks concern outcomes: high and critical findings should show documented, retested remediation, and the report should be written so an assessor can map it to the DTAC cyber security criteria.

What does a DTAC penetration test cost in the UK?

Expect £4,400 to £8,400 for a web application test, £3,300 to £7,000 for an API test, and £8,800 to £16,800 for a combined application, API and cloud engagement. UK firms charge £1,100 to £1,400 per tester day, and scope sets the day count.

In day terms, a web application test typically takes 4 to 6 days, an API test 3 to 5 days, and the combined engagement 8 to 12 days. An exact price needs a short scoping call.

Can testing be done without exposing real patient data?

Yes, testing can and should run without exposing real patient data. The standard approach is a production-like staging environment seeded with synthetic patient records, which lets testers find authentication, authorisation and data-handling flaws without any real patient data being touched.

Where production testing is unavoidable, it is tightly scoped, agreed in writing and run with read-only constraints wherever possible.

How often should digital health suppliers retest for DTAC?

Retest annually as a baseline, and after any major release or architectural change, such as a new API integration, a cloud migration or a new patient-facing feature. NHS buyers increasingly treat evidence older than 12 months as stale, so the annual cycle is the practical floor.

Aligning the retest cycle with your release calendar keeps assessment evidence current without paying for unnecessary testing.

Get DTAC-ready evidence before April 2026

Whether you are an NHS buyer who needs supplier evidence validated or a digital health supplier who needs a test that will stand up to assessment, the window before DTAC v2 lands is the right time to act. Tell us what the product touches and we will return a fixed scope and price. Get a CREST penetration testing quote from our UK-based team.

Leave a Reply

Your email address will not be published. Required fields are marked *