DTAC Compliance Guide: A Step-by-Step SaMD Development Framework
As a Software as a Medical Device (SaMD) developer and QMS provider, Yoctobe supports NHS Trusts in achieving DTAC compliance by providing compliant software development and ISO-ready eQMS infrastructure. This guide outlines Yoctobe’s role in supporting NHS Trust DTAC compliance throughout the development lifecycle.
Key Point: NHS Trusts act as the Legal Manufacturer and submit DTAC evidence directly to the NHS DTAC platform. Yoctobe provides the technical development, QMS infrastructure, and evidence templates that NHS Trusts use to complete their DTAC submissions.
Workflow: NHS Trust → Uses Yoctobe’s software & templates → Submits to DTAC platform
Overview of DTAC Requirements
DTAC consists of five core components:
- Section A: Company information (non-assessed)
- Section B: Value proposition (non-assessed)
- Section C: Technical assessment (C1-C4)
- Section D: Usability and accessibility (scored)
Phase 1: NHS Trust Onboarding and QMS Setup
Step 1: NHS Trust Company Information Templates
Timeline: Before development begins DTAC Section: A1-A11 (Company information – non-assessed)
Yoctobe’s Role:
- Company Information Templates
- Provide DTAC Section A templates for NHS Trust to complete
- Document NHS Trust details in eQMS
- Maintain NHS Trust contact information and credentials
Step 2: Regulatory Assessment Templates
Timeline: Early in development DTAC Section: A10-A11 (CQC assessment if applicable)
Yoctobe’s Role:
- Medical Device Classification Templates
- Provide MHRA registration templates for NHS Trust
- Document MHRA registration status in eQMS
- CQC Assessment Templates (if applicable)
- Provide CQC assessment templates for NHS Trust
- Document CQC compliance status in eQMS
Phase 2: Development Planning
Step 3: Clinical Safety Framework (C1)
Timeline: Throughout development DTAC Section: C1.1-C1.4 (Clinical safety – assessed) Who Submits: NHS Trust doctors (Clinical Safety Officers)
Yoctobe’s Role:
- DCB0129 Compliance Implementation
- Implement DCB0129-compliant clinical risk management system in eQMS
- Create clinical risk management governance templates for NHS Trust
- Develop clinical safety competence and training programs
- Support regular audits and reviews
- DCB0160 Compliance Implementation
- Implement DCB0160-compliant medical device software management system
- Create software lifecycle management templates for NHS Trust
- Develop software safety management procedures
- Support software risk management activities
- Clinical Safety Documentation Templates
- Provide Clinical Safety Case Report templates (C1.1.2)
- Provide Hazard Log templates (C1.1.2)
- Document clinical risk management activities in eQMS
- Provide residual risk identification templates
- Third-Party Product Assessment Templates
- Provide third-party product assessment templates (C1.4.1)
- Provide conformity certificate validation templates
- Document third-party compliance in eQMS
Step 4: Data Protection Framework (C2)
Timeline: Throughout development DTAC Section: C2.1-C2.5 (Data protection – assessed) Who Submits: NHS Trust Data Protection Officer
Yoctobe’s Role:
- DSPT Documentation Templates
- Provide DSPT assessment templates (C2.3.1)
- Document DSPT compliance status in eQMS
- DPIA Documentation Templates
- Provide DPIA templates (C2.3.2)
- Document data processing operations in eQMS
- Provide risk assessment and mitigation templates
- Data Storage and Processing Infrastructure
- Provide UK-based AWS cloud infrastructure (ISO 27001, Cyber Essentials Plus)
- Ensure data residency within UK jurisdiction (C2.5)
- Implement encryption at rest (AES-256) and in transit (TLS 1.2+)
- Document data transfer arrangements and safeguards
- Risk Assessment Documentation Templates
- Provide risk assessment templates (C2.4)
- Document system-level security policies
- Provide access control documentation templates
Phase 3: Technical Development
Step 5: Technical Security Implementation (C3)
Timeline: Throughout development DTAC Section: C3.1-C3.6 (Technical security – assessed) Who Submits: NHS Trust IT Security Team
Yoctobe’s Role:
- Cyber Essentials Documentation Templates
- Document certification status in eQMS
- Provide Cyber Essentials templates (C3.1)
- Penetration Testing
- Coordinate external penetration testing including OWASP Top 10 vulnerabilities (C3.2)
- Ensure no vulnerabilities score 7.0 or above on CVSS
- Document testing results and remediation in eQMS
- Address all identified vulnerabilities in software
- Code Security Review
- Implement internal code security review process (C3.3)
- Document security review process and findings in eQMS
- Address all identified security issues in software
- Provide security review reports to NHS Trust
- Multi-Factor Authentication (MFA)
- Implement MFA for all privileged accounts in software (C3.4)
- Document MFA implementation and policies
- Ensure MFA is enforced across all administrative access
- Logging and Monitoring
- Implement comprehensive audit trails in software (C3.5)
- Define clear logging and reporting requirements
- Document logging policies and procedures
- Ensure all access is logged and monitored
- Load Testing
- Perform comprehensive load testing of software (C3.6)
- Document load testing results and performance metrics
- Ensure system can handle expected user loads
- Provide performance reports to NHS Trust
Step 6: Interoperability Implementation (C4)
Timeline: Throughout development DTAC Section: C4.1-C4.4 (Interoperability – assessed) Who Submits: NHS Trust IT Integration Team
Yoctobe’s Role:
- API Development
- Develop APIs following Government Digital Services Open API Best Practice (C4.1)
- Implement healthcare data interoperability standards (HL7/FHIR)
- Document APIs and make them freely available
- Ensure third parties have reasonable access for integration
- NHS Number Integration
- Implement NHS Login integration requirements (C4.2)
- Implement appropriate security measures for NHS number handling
- Document NHS number integration process
- Electronic Health Record (EHR) Integration
- Implement read/write operations with EHRs using industry standards (C4.3)
- Use OAuth 2.0, TLS 1.2, and other secure interoperability standards
- Document integration capabilities and security measures
- Wearable Device Compliance (if applicable)
- Ensure compliance with ISO/IEEE 11073 Personal Health Data (PHD) Standards (C4.4)
- Document wearable device integration capabilities
- Implement appropriate data exchange protocols
Phase 4: Usability and Accessibility
Step 7: User Experience Development (D1)
Timeline: Throughout development DTAC Section: D1.1-D1.12 (Usability and accessibility – scored) Who Submits: NHS Trust Clinical Team
Yoctobe’s Role:
- User Research and Engagement Templates
- Provide user research templates (D1.1)
- Document user needs and requirements in eQMS
- Implement user feedback mechanisms in software
- User Journey Mapping Templates
- Provide user journey mapping templates (D1.2)
- Ensure software solves whole user problems
- Document how product fits into user pathways
- User Acceptance Testing Templates
- Provide user acceptance testing templates (D1.3)
- Document testing results and improvements in eQMS
- Implement usability validation in software
- Accessibility Compliance
- Implement WCAG 2.1 Level AA compliance in software (D1.4)
- Provide accessibility statement templates
- Implement alternatives for non-accessible content
- Team Development Templates
- Provide multidisciplinary team templates (D1.5)
- Support agile development methodologies (D1.6)
- Provide continuous improvement templates (D1.7)
- Provide success metrics and performance tracking templates (D1.8)
- Service Level Agreement Templates
- Provide SLA templates (D1.11)
- Implement performance reporting in software (99.9% uptime target)
- Document service availability and performance metrics (D1.12)
- Provide regular performance reports to NHS Trust
Phase 5: Compliance Documentation
Step 8: Evidence Preparation Templates
Timeline: Throughout development and before submission Where Evidence is Submitted: NHS DTAC Platform (https://www.dsptoolkit.nhs.uk/)
Yoctobe’s Role:
- Company Information Templates (Section A)
- Provide templates for company registration details (A1-A11)
- Document CQC reports (if applicable) in eQMS
- Clinical Safety Evidence Templates (Section C1)
- Provide DCB0129 Clinical Risk Management System documentation templates (C1.1.1)
- Provide DCB0160 Medical Device Software Management documentation templates
- Provide Clinical Safety Case Report templates (C1.1.2)
- Provide Hazard Log templates (C1.1.2)
- Document MHRA registration and certificates in eQMS (C1.3)
- Provide third-party conformity certificate templates (C1.4.1)
- Data Protection Evidence Templates (Section C2)
- Provide ICO registration templates (C2.1)
- Provide DSPT compliance templates (C2.3.1)
- Provide Data Protection Impact Assessment templates (C2.3.2)
- Document data storage and processing arrangements (C2.5)
- Technical Security Evidence Templates (Section C3)
- Provide Cyber Essentials certification templates (C3.1)
- Coordinate penetration testing and document results (C3.2)
- Provide code security review documentation (C3.3)
- Document MFA implementation in software (C3.4)
- Provide logging and monitoring policy templates (C3.5)
- Document load testing results (C3.6)
- Interoperability Evidence Templates (Section C4)
- Provide API documentation and standards compliance evidence (C4.1)
- Document NHS Login integration capabilities (C4.2)
- Document EHR integration capabilities (C4.3)
- Provide wearable device compliance documentation (C4.4)
- Usability and Accessibility Evidence Templates (Section D1)
- Provide user research documentation templates (D1.1)
- Provide user journey mapping templates (D1.2)
- Provide user acceptance testing templates and results (D1.3)
- Provide accessibility statement templates and compliance documentation (D1.4)
- Provide team structure and methodology templates (D1.5-D1.8)
- Provide service level agreement templates and performance reporting (D1.11-D1.12)
Phase 6: Ongoing Compliance
Step 9: Maintenance and Updates Support
Timeline: Ongoing after initial compliance
Yoctobe’s Role:
- Regular Assessments Documentation
- Provide DSPT compliance templates
- Provide Cyber Essentials certification templates
- Coordinate regular penetration testing
- Provide DCB0129 and DCB0160 clinical safety documentation update templates
- Continuous Improvement
- Monitor and address security vulnerabilities in software
- Provide risk assessment and mitigation update templates
- Implement user engagement and feedback mechanisms in software
- Implement accessibility improvements in software
- Documentation Updates
- Maintain eQMS with current compliance documentation
- Provide policy and procedure update templates
- Maintain audit trails and evidence in eQMS
- Document any changes or improvements
Implementation Timeline
Recommended Schedule:
- Months 1-2: Client onboarding and QMS setup
- Months 3-6: Clinical safety framework and data protection support
- Months 7-12: Technical development with security implementation
- Months 13-15: Usability development and accessibility compliance support
- Months 16-18: Documentation preparation and evidence gathering support
- Months 19-20: Client DTAC submission and assessment support
- Ongoing: Compliance maintenance and updates support
Key Success Factors
- Start Early: Begin compliance planning during product design
- Document Everything: Maintain comprehensive documentation in eQMS
- Engage Experts: Work with qualified clinical and technical experts
- Regular Reviews: Conduct regular compliance reviews and updates
- User Focus: Maintain strong focus on user needs and accessibility
- Security First: Implement security by design principles
- Continuous Improvement: Maintain ongoing compliance and improvement







