Lesson 3 of 5 · 10 min · ends with a checkpoint

The compliance gauntlet, run properly

On this page
4. The compliance gauntlet, run properly5. Procurement, in practice

Module 07 listed the gates. Here is the order to run them in, and the split between what you need at the first meeting and what you need before signature. The organising insight: compliance artefacts are sales assets — every document you can hand over is a week removed from the buyer's timeline, and NHS timelines are what kill small suppliers.

Step 0 — Regulatory status, before anything else

Decide and document whether your product is a medical device under UK rules, what class it is, and its intended use statement. Everything downstream depends on it: marketing claims, evidence expectations, conformity marking, increasingly your DTAC scope. If you cannot answer "is it a device, and what class?" in one sentence, you are not ready to sell. The MHRA's guidance on software and AI as a medical device, and the AI and Digital Regulations Service, are the primary sources (UK device and AI rules remain under reform — check the current position).

Step 1 — DTAC

DTAC — the Digital Technology Assessment Criteria — is the NHS's baseline assessment for digital health technologies, covering clinical safety, data protection, technical security, interoperability, and usability and accessibility. It was refreshed in February 2026, with full transition required by 6 April 2026: roughly 25% fewer questions; de-duplication with the DSPT and pre-acquisition questionnaire; clearer guidance on purpose and scope; removal of the previously mandated clinical safety officer training requirement and of items duplicating device regulation; and scope narrowed, in alignment with NICE, to software-based digital health technologies. Further updates are signalled as the clinical safety standards review progresses (check the current form before quoting its structure).

Complete a DTAC pack proactively and be ready to explain any "no" answers — a candid "no, and here's our roadmap and interim mitigation" scores better with a serious reviewer than a stretched "yes".

Step 2 — Data security and cyber

  • DSPT — the Data Security and Protection Toolkit — is the annual self-assessment for organisations handling NHS patient data, with a 30 June deadline, migrating towards alignment with the NCSC Cyber Assessment Framework: NHS-sector organisations moved first, with other categories including IT suppliers on the assertions-based route for longer (check which version and route applies to you). A "Standards Not Met" status is a live commercial problem, because DSPT compliance is written into NHS contracting.
  • Cyber Essentials / Cyber Essentials Plus. PPN 014, in force from 24 February 2025, applies to central government and NHS bodies and requires suppliers to hold Cyber Essentials or Cyber Essentials Plus — or demonstrate equivalent controls — where a contract involves citizen personal data, government personnel data, or ICT at OFFICIAL. It is deliberately not applied to every contract.
  • The NHS cyber security charter for suppliers, issued in 2025 and updated since, moves expectations from self-declaration towards evidenced controls (check the current version). Expect also to be asked for a penetration test summary, ISO 27001 if you hold it, an ISTPQ or equivalent, and business continuity plans.

Step 3 — Clinical safety

DCB0129 places clinical risk management obligations on the manufacturer: a risk management plan, a hazard log, a clinical safety case report, a named Clinical Safety Officer. DCB0160 is the mirror obligation on the deploying organisation, which cannot complete it without your DCB0129 outputs — so arriving with them removes weeks from the buyer's critical path. Both are under national review: NHS England opened a public consultation on 29 June 2026, running to 11 September 2026, to update them for AI-supported clinical decisions and complex interconnected systems (live as this module is written — check the outcome). That review is also why DTAC's clinical safety section is expected to change again.

Step 4 — Information governance and data protection

You will be asked to support the buyer's DPIA (Data Protection Impact Assessment). Keep a standing pack: a data flow diagram covering every hop, sub-processors and any data leaving the UK; your position on controller/processor roles and the lawful basis under UK GDPR (for health data, also the Article 9 condition); a record of processing activities, retention schedule and deletion/return-on-exit commitments; your data processing agreement and any transfer risk assessment; security certifications, hosting locations and staff vetting.

One development matters especially: the Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025, amends rather than replaces the UK GDPR and Data Protection Act 2018 — and strengthens information standards in health and social care from "have regard to" towards mandatory compliance, meaning specified standards can be enforced on the technology NHS organisations use. The ICO is also due to be reconstituted as an Information Commission (check timing).

Expect interoperability and accessibility questions alongside: HL7 FHIR UK Core profiles, EPR integration, NHS login or NHS Number matching, WCAG 2.2 AA conformance and the Accessible Information Standard.

What to have ready when

Before the first meeting (these get asked in it, and "I'll come back to you" costs a fortnight): regulatory status and intended use in one sentence; completed DTAC pack; current DSPT status; Cyber Essentials Plus or equivalent; a one-page data flow diagram; named Clinical Safety Officer; framework listings; two reference sites; a commercial summary splitting capital and revenue cost.

Before pilot: hazard log and clinical safety case report; draft DPIA content; data processing agreement; penetration test summary; a written evaluation plan.

Before contract: full clinical safety case signed by your CSO; the trust's DCB0160 work supported; completed DPIA signed off by their DPO and, where confidential patient information is involved, the Caldicott Guardian; security assurance closed out; contract terms, service levels, exit and data return agreed; social value response; KPIs.

Field note

Package all of it as a single "assurance dossier" with a contents page and a version number, and send it unprompted after the first meeting. It costs nothing to produce twice, and it moves you in the buyer's mind from "start-up we like" to "supplier we can put in front of our governance". More than one deal has been won by the vendor whose paperwork made the programme manager's life easy.


5. Procurement, in practice

The regime, at durable-structure level

The Procurement Act 2023 has governed most UK public procurement of goods and services since 24 February 2025. What matters commercially:

  • One platform. A central digital platform, surfaced as Find a Tender, carries notices across the contract lifecycle; suppliers register core details once and reuse them. Contracts Finder remains live largely for procurements begun under the old rules (check current status).
  • Two competitive procedures. The open procedure — single-stage, anyone can bid — and the competitive flexible procedure, a multi-stage process the authority designs itself: shortlisting, negotiation, demonstrations, dialogue, in any sequence. That is a real change for health tech, making demos and negotiation part of a compliant process.
  • Most Advantageous Tender. Award is against criteria published in advance — so the published weightings are the deal, readable before you decide whether to bid.
  • Transparency across the lifecycle. Pipeline, preliminary market engagement, tender, transparency, contract award, contract details and contract performance notices. Larger contracts must publish KPIs and performance against them (the Act sets value thresholds — check current figures).
  • A separate NHS regime for services. The Provider Selection Regime, in force since 1 January 2024, governs how NHS healthcare services are commissioned and must not be used to buy goods or non-healthcare services alone. Software is not procured under the PSR — knowing that distinction cleanly is a fast credibility marker.

Thresholds, and how a framework call-off actually runs

From 1 January 2026 the goods and services thresholds were revised: £135,018 for central government authorities — including NHS trusts and foundation trusts — and £207,720 for sub-central authorities, both inclusive of VAT and calculated on total contract value including extensions and options (check these; thresholds are revised roughly every two years). So a £45,000-a-year contract over three years plus a one-year extension is a £180,000-plus procurement. Sizing a first deal deliberately below a threshold is legitimate; slicing a large requirement to avoid one is not, and buyers know it.

Frameworks remain the workhorse: G-Cloud (Crown Commercial Service — the standard route for public-sector SaaS; check which iteration is live), NHS Shared Business Services frameworks, NHS England's Health Systems Support Framework for analytics, integration and population health management, NHS Supply Chain for products and devices, and the regional NHS procurement hubs.

  1. The buyer confirms the framework and lot covers the requirement and is still live.
  2. They decide between direct award and further competition — some frameworks permit direct award where the requirement matches a catalogue entry on unchanged terms; others require a mini-competition. Procurement decides this on legal advice, not your champion.
  3. Direct award: the buyer documents the rationale, applies the framework's award criteria, agrees the order form and call-off terms, issues a purchase order — weeks, not months, but only if governance has already approved the spend. Mini-competition: a specification and criteria go to capable suppliers on the lot, usually with a two-to-four-week window, then scoring and award under the framework's rules. Either way the required notices are published and the framework's call-off terms take effect.

Your negotiating room on terms is much smaller under a framework, because they were agreed when it was let — read the call-off terms before you sell. Outside frameworks, direct award is possible only on specific legal grounds, published via a transparency notice; treat any customer who says they will "just direct award it" with polite scepticism until procurement confirms the ground.

Reading and answering a tender

Read the pack in this order, before writing a word: (1) the evaluation methodology — quality/price split, weighting per question, scoring scale, any pass/fail requirements, any minimum quality threshold below which price is not opened; (2) the draft contract — an unacceptable liability cap, indemnity or IP clause must be raised as a clarification before the deadline, because after submission is too late; (3) the pricing schedule; (4) the specification, last, because you now know how it will be marked.

How evaluators actually score. A panel of three to six scores independently, then moderates to a consensus against a published descriptor — typically 0 for no response rising to full marks for one that fully meets the requirement with convincing evidence. They score the answer in front of them, not their impression of your company, and are often not permitted to credit knowledge held from outside the bid. So: answer the question asked, in its own words, using a heading for each part of it. Evidence over adjectives: "robust" and "market-leading" score nothing, while "deployed at four acute trusts; median integration eleven weeks; hazard log with 34 hazards all mitigated to acceptable; DSPT Standards Met, June 2026" scores. One point per paragraph, point first. Use the word count — 300 words against a 1,000-word limit is unclaimed marks. Assume no prior knowledge. And answer the social value question properly.

The errors that get bids disqualified, roughly by frequency: late submission by any margin; a missing mandatory document; exceeding a word or page limit; altering the pricing template; a blank mandatory field; an unsigned form of tender; failing a pass/fail question; contacting the buyer outside the clarification process; disclosing price inside a quality response. All unforced, all fatal regardless of product quality.

Social value, standstill and debriefs

Two social value regimes sit alongside each other. In the NHS, a minimum 10% weighting for net zero and social value has applied since April 2022 under NHS England's guidance, with an NHS Social Value Playbook published in July 2025; buyers may weight higher. In central government, the social value model in PPN 002 became mandatory for in-scope organisations from 1 October 2025, also with a 10% minimum. (Check both — the regimes are related but not identical.) Expect carbon reduction plan obligations on larger NHS contracts too, and have an evidenced offer tied to the buyer's geography rather than a generic corporate responsibility page.

The authority then publishes a contract award notice and gives each assessed bidder an assessment summary explaining the scoring, followed by a standstill of at least eight working days during which the contract cannot be signed and an unsuccessful bidder can challenge. Use it: read the summary, ask for a debrief, record which questions scored badly.

Field note

Read three real ITT packs end to end before you ever write one — they are published, and anyone can download them. Nothing else teaches you as quickly how much of the decision is made by the weightings table on page four, or how much of a "quality" score is really an administrative competence test. "I've read the last three ITTs this buyer published and here's what they weight" is a sentence almost no candidate can say, including experienced ones.


Checkpoint 3 · answer to continue reading
Question 1 of 3
You are bidding into a mini-competition. The quality question asks you to describe your integration approach, including standards supported, in up to 800 words. What does the module say is the highest-scoring way to answer?