DSPT vs DTAC: A Complete Guide to NHS Data Security Compliance for Software Developers
Introduction
When developing software for the NHS or healthcare organisations handling patient data in the UK, understanding the difference between the Data Security and Protection Toolkit (DSPT) and the Data Security Technical Assurance (DTAC) is crucial. These two frameworks work together to ensure comprehensive data security across the NHS ecosystem, but they serve different purposes and apply to different stakeholders.
What is DSPT (Data Security and Protection Toolkit)?
Overview
The Data Security and Protection Toolkit (DSPT) is an online self-assessment tool designed for organisations in health and social care to demonstrate their compliance with UK data security and information governance standards.
Who Needs DSPT?
- NHS organisations (hospitals, trusts, CCGs, etc.)
- NHS contractors and suppliers handling patient data
- Social care organisations processing health data
- Any organisation that has access to NHS patient information
Scope and Focus
DSPT is organisation-wide and covers:
- Policies and procedures for data handling
- Staff awareness and training programs
- Technical security measures
- Incident management processes
- Supplier oversight and management
- Governance structures and accountability
For Software Developers
If your software processes NHS patient data or is deployed in NHS environments, DSPT compliance is mandatory for the organisation using your software. While you may not complete DSPT directly, you’ll need to provide evidence (such as ISO 27001 certifications, secure coding practices documentation, or DTAC compliance certificates) as part of your client’s DSPT assessment.
What is DTAC (Data Security Technical Assurance)?
Overview
Data Security Technical Assurance (DTAC) is a technical assurance framework that assesses IT systems, software applications, and platforms against NHS technical and security standards.
Who Needs DTAC?
- Software suppliers delivering NHS-facing applications
- IT teams developing healthcare systems
- Developers creating software that processes NHS patient data
- Platform providers hosting NHS data or applications
Scope and Focus
DTAC is system-level and focuses on:
- Technical security controls (encryption, authentication, authorisation)
- Identity and access management
- Audit logging and monitoring
- Network security configurations
- Secure software design and architecture
- Data protection mechanisms
- System resilience and availability
For Software Developers
Your software itself must comply with DTAC if it will process or store NHS patient data. DTAC compliance is often a prerequisite to DSPT submission for software suppliers, demonstrating that the system is technically secure and meets NHS standards.
Key Differences: DSPT vs DTAC
| Feature | DSPT | DTAC |
|---|---|---|
| Level | Organization-wide | System/software-level |
| Focus | Policies, governance, staff training, supplier management | Technical documentation, security test results, and architecture diagrams |
| Mandatory for | Technical security controls, architecture, and software design | Software suppliers delivering NHS-facing applications |
| Assessment Type | Self-assessment (audit-ready evidence) | Technical assessment by NHS/approved assessors |
| Timeline | Annual submission required | Required before system deployment |
| Evidence Type | Governance documents, training records, policies | Technical documentation, security test results, architecture diagrams |
The Relationship Between DSPT and DTAC
How They Work Together
- DTAC compliance feeds into DSPT evidence – Your DTAC certificate becomes part of your client’s DSPT submission
- DTAC is evidence for DSPT – If your software is used by NHS organisations, your DTAC compliance demonstrates technical security
- Complementary frameworks – DSPT ensures organisational readiness, while DTAC ensures technical security
The Compliance Journey
Software Development → DTAC Assessment → DTAC Compliance Certificate
↓
NHS Organization → DSPT Self-Assessment → DSPT Compliance (includes DTAC evidence)
Practical Implementation for Software Developers
For DTAC Compliance
- Design with security in mind from the start
- Implement robust authentication and authorisation
- Use strong encryption for data at rest and in transit
- Implement comprehensive logging and monitoring
- Follow secure coding practices (OWASP guidelines)
- Conduct regular security testing and vulnerability assessments
- Maintain detailed technical documentation
For Supporting DSPT
- Provide DTAC compliance certificates to clients
- Document your security practices and policies
- Maintain ISO 27001 or equivalent certifications
- Provide incident response procedures and contact information
- Offer security training materials for end users
- Maintain audit trails and compliance documentation
Common Challenges and Solutions
Challenge 1: Understanding Requirements
Problem: The technical requirements can be complex and extensive. Solution: Work with NHS Digital or approved assessors early in the development process to understand specific requirements for your use case.
Challenge 2: Documentation Overhead
Problem: Both frameworks require extensive documentation. Solution: Implement documentation as part of your development process, not as an afterthought. Use templates and automated documentation tools.
Challenge 3: Ongoing Compliance
Problem: Compliance is not a one-time activity. Solution: Build compliance monitoring into your development lifecycle and maintain regular security assessments.
Best Practices for Software Developers
1. Start Early
- Begin DTAC planning during the design phase
- Engage with NHS assessors early
- Build security requirements into your development process
2. Security by Design
- Implement security controls from the ground up
- Use established security frameworks and standards
- Conduct regular security reviews and testing
3. Documentation Management
- Maintain comprehensive technical documentation
- Keep security policies and procedures up to date
- Document all security-related decisions and changes
4. Continuous Monitoring
- Implement security monitoring and alerting
- Conduct regular vulnerability assessments
- Maintain incident response capabilities
5. Stakeholder Communication
- Keep clients informed of compliance status
- Provide clear documentation for DSPT submissions
- Maintain open communication with NHS assessors
Conclusion
Understanding the distinction between DSPT and DTAC is essential for any software developer working with NHS data. While DSPT focuses on organisational governance and processes, DTAC ensures that the technical implementation meets NHS security standards. Both frameworks work together to create a comprehensive security ecosystem that protects patient data and maintains public trust in the NHS.
For software developers, the key takeaway is that DTAC compliance is your responsibility when building NHS-facing software, while DSPT compliance is your client’s responsibility when using your software. By ensuring your software meets DTAC requirements, you not only protect patient data but also enable your clients to achieve their own DSPT compliance.
Remember: In the healthcare sector, security is not just a technical requirement—it’s a fundamental responsibility to protect patient privacy and maintain the integrity of the healthcare system.







