Won Your First NHS Contract? The Penetration Testing DTAC Expects from Health App Teams

Won Your First NHS Contract? The Penetration Testing DTAC Expects from Health App Teams

By EJN Labs · 20 Jul 2026 · 8 min read

DTAC mobile penetration testing is the security evidence NHS buyers expect from health app suppliers completing the Digital Technology Assessment Criteria. DTAC does not name a single mandated test standard, but an independent penetration test of your mobile app and its APIs is the strongest accepted evidence for its cyber security section. A typical mobile app test takes 4 to 6 days and costs £4,800 to £8,400.

Why DTAC mobile penetration testing matters once you win an NHS contract

Winning your first NHS contract changes the security expectations on your app overnight. The Digital Technology Assessment Criteria (DTAC), published by NHS England, is the baseline assessment NHS and social care organisations use before deploying digital health technologies. Where the NHS buyer requires DTAC, completing it is mandatory: your product does not go live until the buying organisation is satisfied.

For mobile digital health apps, the pressure lands hardest on the cyber security section. Your app handles patient-identifiable data on devices you do not control, talks to APIs over networks you do not control, and often integrates with NHS systems such as NHS login or clinical record platforms. NHS procurement teams know this, and they ask for proof that the whole chain has been tested, not just the binary in the app store.

This post covers what DTAC actually asks for, where penetration testing fits, how an engagement runs, and what it costs.

Does DTAC actually require a penetration test?

Here is the honest answer. DTAC’s cyber security section asks suppliers to evidence a set of security controls and assurances, including Cyber Essentials certification, completion of the Data Security and Protection Toolkit where applicable, secure development practice, and evidence that the product has been security tested. It does not prescribe one specific testing methodology in the way PCI DSS does, and you will not find a clause that says a CREST test is compulsory for every product.

In practice, that nuance rarely helps you. NHS buyers review DTAC responses with their own information governance and security teams, and an independent penetration test report is the strongest accepted evidence that your security claims hold up. Many NHS procurement frameworks and individual trusts go further and make a recent penetration test a commercial condition of the contract, independent of the DTAC wording. If you answer the security testing questions with “internal review only” or an automated scanner report, expect follow-up questions, delays, or a conditional pass that requires a test before deployment.

So treat the position clearly: DTAC completion is mandatory where the NHS buyer requires it, and an independent penetration test is strong accepted evidence that is often commercially expected.

What to test in a mobile digital health app

A DTAC-driven test should mirror how an NHS reviewer thinks about your product: the app, the APIs behind it, and the cloud estate holding patient data are one system.

The mobile applications themselves

Mobile application penetration testing covers both iOS and Android builds: insecure local storage of health records or tokens, weak certificate pinning, authentication and session handling, exposure of data through logs, backups and screenshots, and reverse engineering of the app package. Health apps carry special category data under UK GDPR, so anything cached on a lost or shared device matters far more than in a retail app.

The APIs behind the app

Almost every serious finding in health app engagements sits server-side. API penetration testing targets broken object-level authorisation (can patient A read patient B’s records by changing an identifier), weak authentication between app and backend, mass assignment, rate limiting on endpoints that expose clinical data, and integrations with NHS login or third-party identity providers.

The cloud estate holding patient data

Cloud penetration testing reviews the AWS, Azure or GCP environment behind the product: storage bucket permissions, database exposure, secrets management, and whether a compromise of one tenant or component can reach patient data belonging to another. Configuration evidence supports your DTAC data protection answers too.

How a DTAC-driven engagement runs

A well-run engagement follows a predictable path, and knowing it helps you plan around your NHS go-live date.

  1. Scoping. A short call maps your estate: platforms, API endpoints, cloud services, test accounts and any NHS integrations. This fixes the day count and the price before anything starts.
  2. Environment preparation. You provide staging builds, test patient accounts at each permission level, and API documentation. Testing against staging with production-equivalent configuration keeps live patient data out of scope entirely.
  3. Testing. UK-based testers work through the app, API and cloud scope over the agreed days, with a daily check-in and immediate escalation for anything critical.
  4. Reporting. You receive a report with an executive summary written for the NHS reviewer, technical findings with reproduction steps for your developers, and a risk rating per issue.
  5. Retesting. After you fix the findings, a retest confirms the fixes and produces the clean summary letter that goes into your DTAC evidence pack.

If you want to prepare your team before scoping, our penetration testing checklist walks through what to have ready before day one.

What it costs and how scope drives the price

Penetration testing is priced by effort. UK day rates for CREST-accredited firms typically run £1,200 to £1,400, and the number of days is driven by how much estate you put in scope. Typical ranges for health app teams look like this:

ScopeTypical effortTypical UK price range
Mobile app only (iOS and Android)4 to 6 days£4,800 to £8,400
Mobile app plus backend APIs6 to 9 days£7,200 to £12,600
App, APIs and cloud configuration review8 to 12 days£9,600 to £16,800

Scope drives everything: the number of screens and user roles in the app, the number of API endpoints, and how many cloud services hold patient data. A single-role wellness app sits at the bottom of these ranges; a multi-role clinical app with NHS login integration sits at the top. These are typical UK ranges rather than a quotation, and our guide to penetration testing costs in the UK breaks down the drivers in more detail. For an exact figure, use the quote form and we will scope it properly.

How EJN Labs approaches DTAC-driven health app testing

EJN Labs is a CREST-accredited UK penetration testing firm, and we hold Cyber Essentials Plus and ISO 27001 ourselves, so we sit on the same side of these assessments as you do. When we scope a health app estate, we start from the data flow rather than the asset list: where patient-identifiable data enters the app, which APIs move it, where it rests in the cloud, and which third parties touch it. That flow becomes the scope, which is exactly how an NHS information governance reviewer will read your architecture.

All testing is delivered by UK-based testers, which matters for NHS buyers with data residency and personnel expectations. We write the executive summary for the person assessing your DTAC response, not for your developers, and retesting with a clean summary letter is built into the engagement, because the letter is the artefact your NHS buyer actually files.

Frequently Asked Questions

Is a penetration test mandatory for DTAC?

DTAC itself does not name a single mandated testing standard. It asks suppliers to evidence security controls and security testing, alongside requirements such as Cyber Essentials. However, NHS buyers routinely treat an independent penetration test as the strongest acceptable evidence, and many make a recent test a commercial condition of the contract. Practically, most health app suppliers need one to pass review without delays.

What does DTAC mobile penetration testing cost?

Testing a mobile health app on iOS and Android typically takes 4 to 6 days at UK day rates of £1,200 to £1,400, so £4,800 to £8,400. Adding backend APIs takes it to 6 to 9 days, £7,200 to £12,600. App, APIs and cloud together typically run 8 to 12 days, £9,600 to £16,800. Exact pricing depends on scope, confirmed at scoping.

What should be in scope for an NHS health app test?

At minimum, both mobile builds and the APIs they call, because most serious findings in health apps are server-side authorisation flaws that expose one patient’s data to another. If your product stores patient data in AWS, Azure or GCP, include a cloud configuration review. Integrations such as NHS login or clinical system connections should also be exercised, since NHS reviewers focus on them.

Will testing put patient data at risk?

No, if it is scoped properly. Testing runs against a staging environment with production-equivalent configuration and synthetic test patient accounts, so no live patient data is touched. Where a production check is unavoidable, it is agreed in writing, limited to non-destructive verification, and carried out under a signed authorisation. A reputable firm will insist on this structure rather than test blind against live clinical data.

How often does an NHS supplier need to retest?

Annual testing is the working norm NHS buyers expect, and most contracts and frameworks are reviewed on that cycle. You should also retest after significant changes: a new integration with NHS systems, a major release that changes authentication or data handling, or a change of cloud architecture. Time-boxed evidence ages quickly, and a report older than twelve months will usually draw buyer questions.

Get DTAC-ready before your NHS reviewer asks

If you have just won an NHS contract, the cheapest time to test is before the DTAC review, not after a buyer challenge with a go-live date at risk. Start with the CREST penetration testing quote form and we will come back with a fixed scope, price and a plan that fits your deployment timeline.

Leave a Reply

Your email address will not be published. Required fields are marked *