Blog HealthcareNHSBuying

NHS procurement for immersive training: DTAC, DSPT and the rest

What an NHS buyer actually has to clear before a VR training platform goes live in 2026, which standards apply to staff-only training, and three myths worth dropping.

George Bellwood Node XR

 · 9 min read

An empty NHS meeting room early in the morning, with papers and a water jug on the table and one chair pushed back

Most immersive training projects in the NHS do not fail on clinical content. They stall in the gap between an education team who have found something useful and an information governance team who have never assessed anything like it. The assessment itself is not hard, but several of the rules changed in 2026, and a supplier quoting the old ones is a warning sign rather than a reassurance.

Key takeaway: For staff-only training, the real list is shorter than it looks. DTAC version 2, a DSPT submission from the supplier, a DPIA, Cyber Essentials and WCAG 2.2 AA. Clinical risk standards usually do not apply, and UK-only data residency is not a national requirement, whatever a previous bid told you.

DTAC, and the version trap

The Digital Technology Assessment Criteria is NHS England’s baseline assessment for digital health technologies. It covers five assessed areas: clinical safety, data protection, technical security, interoperability, and usability and accessibility, sitting alongside a company information section and a non-assessed value proposition (NHS England).

Two things about it in 2026.

The form changed. NHS England introduced an updated DTAC on 24 February 2026, and states that “the previous version of the DTAC form should not be used from 6 April 2026 onwards”. Version 2.0 carries roughly 25% fewer questions and has been de-duplicated against the DSPT, so you are no longer answering the same security questions twice (NHS Innovation Service). If a supplier hands you a completed v1 form, it is out of date.

It applies to staff tools, not just patient apps. The scope covers software “designed to be used by care recipients, clinicians, or staff”. A staff training platform is in.

Worth knowing for the business case: DTAC is not law. NHS England’s own developer guidance says “Although not legally required, it’s an essential activity”, while placing the duty on the buyer, who “must ensure any DHT products they use or recommend for use meet all national standards and requirements” (NHS England digital regulations). In practice that means individual trusts decide, and they mostly decide yes.

One housekeeping note: the site hosting DTAC stopped being updated on 31 March 2026 and now redirects to digital.nhs.uk, so older bookmarks and any links in a 2024 bid document will bounce.

DSPT, and which version your supplier is on

The Data Security and Protection Toolkit is the annual self-assessment that every organisation with access to NHS patient data and systems must complete (NHS England).

Since September 2024 it has run on two tracks. NHS trusts, ICBs, arm’s length bodies and similar are assessed against the National Cyber Security Centre’s Cyber Assessment Framework, with 47 contributing outcomes scored as achieved, partially achieved or not achieved. IT suppliers, GPs, dentists, local authorities, universities and social care remain on the older assertion-based version (DSPT).

So when you ask a training supplier for their DSPT, expect the supplier track, not the CAF one. That is correct, not a shortfall. The 2025-26 round closed on 30 June 2026; version 9, covering 2026-27, published on 8 September 2026.

DPIA: almost certainly yes

Article 35(1) of the UK GDPR requires a DPIA where processing is “likely to result in a high risk to the rights and freedoms of natural persons”. Beyond the automatic triggers in Article 35(3), the ICO lists further UK triggers including innovative technology, biometric data, and tracking of location or behaviour, and says that “in most cases, a combination of two of these factors indicates the need for a DPIA” (ICO).

An immersive training platform that records where learners looked hits innovative technology and behavioural tracking without breaking a sweat. Assume a DPIA, do it early, and ask the supplier for a template they have already been through elsewhere.

Clinical risk standards: usually out of scope, and worth saying so

This is where most time gets wasted, because the words “clinical” and “safety” appear together and everyone assumes the heaviest standard applies.

DCB0129 and DCB0160 are clinical risk management standards, published under section 250 of the Health and Social Care Act 2012, which makes compliance mandatory for products in scope. DCB0129 applies to manufacturers, DCB0160 to the deploying organisation (NHS England).

The scope test is the part to read. NHS England’s step-by-step guidance turns on whether the product “is used to influence, support, manage the real-time or near-real-time direct care of patients/service users” (NHS England). A training simulator used by staff, which holds no patient record and touches no live care episode, sits outside that. The DTAC itself accepts this: question C1.1 asks whether your product falls within the mandated scope of DCB0129, and “no” is a legitimate answer with a reason.

Adopting the standards voluntarily is still good practice, particularly if scenarios will be used for assessed competence. But do not let a project spend three months appointing a clinical safety officer for something the standard does not cover.

One caveat: both standards are under national review, with a consultation that closed on 11 September 2026 (NHS England). They remain in force, but expect movement.

Cyber Essentials, and what changed in April 2026

Cyber Essentials is an NCSC scheme delivered by IASME. The base certification is a verified self-assessment; Cyber Essentials Plus adds “a technical audit of your IT systems to verify that the controls are in place”, covering a representative set of user devices, all internet gateways and all internet-facing servers (IASME). Both last twelve months.

The scheme changed materially in 2026. A new question set, named Danzell, published on 13 February 2026 under Requirements for IT Infrastructure v3.3, applying to applications registered from late April 2026. The headline change is that multi-factor authentication on cloud services is now mandatory wherever available, and its absence is an automatic fail (IASME).

What NHS documentation actually requires is worth a precise note. DTAC section C3.1 asks for Cyber Essentials Certification. We could not find a national NHS requirement for Cyber Essentials Plus, despite how often bids assert one. Individual trusts frequently ask for it, and plenty of suppliers hold it, but check what your own trust requires rather than inheriting the assumption. Node XR publishes its Cyber Essentials Plus position on the security page.

Buying routes, which also changed

Three things a 2024-era procurement note will get wrong.

Crown Commercial Service no longer exists under that name. It became the Government Commercial Agency on 1 April 2026, and the old domain redirects (GCA).

G-Cloud 14 ends on 28 October 2026. G-Cloud 15 started on 6 August 2026 as an open framework under the Procurement Act 2023, reopening to new suppliers at 18 and 36 months, with lots covering infrastructure software, other software as a service, and cloud support (GCA).

The Procurement Act 2023 itself came into force on 24 February 2025, so it is current law rather than an upcoming change (gov.uk).

One clarification that saves arguments: the NHS Standard Contract governs the commissioning of healthcare services, not a trust’s purchase of a software licence. A training platform normally comes through a framework or the trust’s own contracting route.

The data residency myth

Plenty of bids state that NHS data must stay in the UK. NHS England’s own guidance says otherwise, and says it clearly: “NHS and social care organisations can safely locate health and care data, including confidential patient information, in the public cloud including solutions that make use of data off-shoring”, provided it sits in “the UK, EEA, or countries deemed by the UK to have adequate protections for the rights of data subjects” (NHS England).

The conditions are a documented risk assessment with the SIRO satisfied and input from the DPO and Caldicott Guardian. The DTAC records data location as an answer, not a pass or fail.

UK residency is still a perfectly reasonable thing to ask for, and we host in the UK on AWS for exactly that reason. It is just not a rule, and treating it as one rules out options unnecessarily.

Accessibility, and the honest bit

The Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018 apply to NHS trusts as bodies governed by public law. NHS England’s service manual is explicit about what that means and who it binds: services must “meet at least level AA of the Web Content Accessibility Guidelines (WCAG 2.2)”, publish an accessibility statement, and, critically, “External suppliers contracted to the NHS must also make sure their work meets the same standard” (NHS service manual). Intranet and extranet applications are covered too.

Here is the part suppliers should say out loud rather than paper over. WCAG 2.2 was written for web and mobile interfaces, not for head-mounted immersive ones. Nobody can claim clean WCAG conformance for a scene viewed inside a headset, because the success criteria do not map. What a supplier can and should evidence is an equivalent non-VR route: the same scenario, the same assessment, in a browser, keyboard navigable, with captions and adjustable text. That is the practical answer, and it is also the reason browser-first delivery matters more in the NHS than anywhere else. We cover the deployment side in do you need headsets for VR training.

A realistic checklist

ItemWho does itUsual answer for staff training
DTAC v2.0 formSupplier completes, trust assessesRequired in practice
DSPTSupplier, on the supplier trackRequired
DPIATrust, with supplier inputAlmost always required
DCB0129 / DCB0160Supplier / trustUsually out of mandated scope, state why
Cyber EssentialsSupplierRequired by DTAC C3.1; Plus is trust preference
WCAG 2.2 AASupplierRequired, with a non-VR equivalent route
Data locationTrust records, SIRO signsUK or adequacy country, documented

The short answer

For an NHS staff training platform in 2026, expect DTAC version 2.0, a supplier DSPT on the assertion-based track, a DPIA, Cyber Essentials with the new April 2026 question set, and WCAG 2.2 AA with a browser route that does not need a headset. Expect the clinical risk standards not to apply, and say so early with the scope test in writing. And do not accept UK-only data residency as a rule when it is a choice.

The trust and security pages carry our current documentation, and the FAQ answers the questions IG teams ask first.

Share this article

See Node XR in action.

Book a 30-minute guided walkthrough with our team. No commitment.