Automation

DSPT vs DTAC: A Complete Guide to NHS Data Security Compliance for Software Developers

NHS DTAC

Introduction

When developing software for the NHS or healthcare organisations handling patient data in the UK, understanding the difference between the Data Security and Protection Toolkit (DSPT) and the Data Security Technical Assurance (DTAC) is crucial. These two frameworks work together to ensure comprehensive data security across the NHS ecosystem, but they serve different purposes and apply to different stakeholders.

What is DSPT (Data Security and Protection Toolkit)?

Overview

The Data Security and Protection Toolkit (DSPT) is an online self-assessment tool designed for organisations in health and social care to demonstrate their compliance with UK data security and information governance standards.

Who Needs DSPT?

  • NHS organisations (hospitals, trusts, CCGs, etc.)
  • NHS contractors and suppliers handling patient data
  • Social care organisations processing health data
  • Any organisation that has access to NHS patient information

Scope and Focus

DSPT is organisation-wide and covers:

  • Policies and procedures for data handling
  • Staff awareness and training programs
  • Technical security measures
  • Incident management processes
  • Supplier oversight and management
  • Governance structures and accountability

For Software Developers

If your software processes NHS patient data or is deployed in NHS environments, DSPT compliance is mandatory for the organisation using your software. While you may not complete DSPT directly, you’ll need to provide evidence (such as ISO 27001 certifications, secure coding practices documentation, or DTAC compliance certificates) as part of your client’s DSPT assessment.

What is DTAC (Data Security Technical Assurance)?

Overview

Data Security Technical Assurance (DTAC) is a technical assurance framework that assesses IT systems, software applications, and platforms against NHS technical and security standards.

Who Needs DTAC?

  • Software suppliers delivering NHS-facing applications
  • IT teams developing healthcare systems
  • Developers creating software that processes NHS patient data
  • Platform providers hosting NHS data or applications

Scope and Focus

DTAC is system-level and focuses on:

  • Technical security controls (encryption, authentication, authorisation)
  • Identity and access management
  • Audit logging and monitoring
  • Network security configurations
  • Secure software design and architecture
  • Data protection mechanisms
  • System resilience and availability

For Software Developers

Your software itself must comply with DTAC if it will process or store NHS patient data. DTAC compliance is often a prerequisite to DSPT submission for software suppliers, demonstrating that the system is technically secure and meets NHS standards.

Key Differences: DSPT vs DTAC

FeatureDSPTDTAC
LevelOrganization-wideSystem/software-level
FocusPolicies, governance, staff training, supplier managementTechnical documentation, security test results, and architecture diagrams
Mandatory forTechnical security controls, architecture, and software designSoftware suppliers delivering NHS-facing applications
Assessment TypeSelf-assessment (audit-ready evidence)Technical assessment by NHS/approved assessors
TimelineAnnual submission requiredRequired before system deployment
Evidence TypeGovernance documents, training records, policiesTechnical documentation, security test results, architecture diagrams

The Relationship Between DSPT and DTAC

How They Work Together

  1. DTAC compliance feeds into DSPT evidence – Your DTAC certificate becomes part of your client’s DSPT submission
  2. DTAC is evidence for DSPT – If your software is used by NHS organisations, your DTAC compliance demonstrates technical security
  3. Complementary frameworks – DSPT ensures organisational readiness, while DTAC ensures technical security

The Compliance Journey

Software Development → DTAC Assessment → DTAC Compliance Certificate
                                                      ↓
NHS Organization → DSPT Self-Assessment → DSPT Compliance (includes DTAC evidence)

Practical Implementation for Software Developers

For DTAC Compliance

  1. Design with security in mind from the start
  2. Implement robust authentication and authorisation
  3. Use strong encryption for data at rest and in transit
  4. Implement comprehensive logging and monitoring
  5. Follow secure coding practices (OWASP guidelines)
  6. Conduct regular security testing and vulnerability assessments
  7. Maintain detailed technical documentation

For Supporting DSPT

  1. Provide DTAC compliance certificates to clients
  2. Document your security practices and policies
  3. Maintain ISO 27001 or equivalent certifications
  4. Provide incident response procedures and contact information
  5. Offer security training materials for end users
  6. Maintain audit trails and compliance documentation

Common Challenges and Solutions

Challenge 1: Understanding Requirements

Problem: The technical requirements can be complex and extensive. Solution: Work with NHS Digital or approved assessors early in the development process to understand specific requirements for your use case.

Challenge 2: Documentation Overhead

Problem: Both frameworks require extensive documentation. Solution: Implement documentation as part of your development process, not as an afterthought. Use templates and automated documentation tools.

Challenge 3: Ongoing Compliance

Problem: Compliance is not a one-time activity. Solution: Build compliance monitoring into your development lifecycle and maintain regular security assessments.

Best Practices for Software Developers

1. Start Early

  • Begin DTAC planning during the design phase
  • Engage with NHS assessors early
  • Build security requirements into your development process

2. Security by Design

  • Implement security controls from the ground up
  • Use established security frameworks and standards
  • Conduct regular security reviews and testing

3. Documentation Management

  • Maintain comprehensive technical documentation
  • Keep security policies and procedures up to date
  • Document all security-related decisions and changes

4. Continuous Monitoring

  • Implement security monitoring and alerting
  • Conduct regular vulnerability assessments
  • Maintain incident response capabilities

5. Stakeholder Communication

  • Keep clients informed of compliance status
  • Provide clear documentation for DSPT submissions
  • Maintain open communication with NHS assessors

Conclusion

Understanding the distinction between DSPT and DTAC is essential for any software developer working with NHS data. While DSPT focuses on organisational governance and processes, DTAC ensures that the technical implementation meets NHS security standards. Both frameworks work together to create a comprehensive security ecosystem that protects patient data and maintains public trust in the NHS.

For software developers, the key takeaway is that DTAC compliance is your responsibility when building NHS-facing software, while DSPT compliance is your client’s responsibility when using your software. By ensuring your software meets DTAC requirements, you not only protect patient data but also enable your clients to achieve their own DSPT compliance.

Remember: In the healthcare sector, security is not just a technical requirement—it’s a fundamental responsibility to protect patient privacy and maintain the integrity of the healthcare system.

References