Suppliers treat the [Digital Technology Assessment Criteria](https://transform.england.nhs.uk/key-tools-and-info/digital-technology-assessment-criteria-dtac/) as a form to fill in at the end. Read forwards it is a form. Read as a specification it is the clearest statement the NHS has published of what a well-designed digital product looks like.
What DTAC actually is
Five domains, one evidence pack and the acceptance letter that unlocks NHS commercial engagement. Every domain maps to an artefact the delivery plan should have produced anyway.
The domain that everybody underrates
Technical assurance. Not because it is the hardest, but because it is where the platform-versus-app decision lands. A product that has not settled its hosting, integration and interoperability position is answering that domain with intent rather than evidence.
DSPT is not just annual - it is a design constraint
The [Data Security and Protection Toolkit](https://www.dsptoolkit.nhs.uk/) categorisation shapes what can be committed to during the bid. A Standards Met with Improvements status is workable, but only if the response carries a dated remediation plan rather than silence.
Reading DTAC backwards
Start from what a completed DTAC pack looks like and work back. That determines what the delivery plan has to include and it does so before the delivery plan is priced.
The evidence pack that survives review
Named accountable executive, documented penetration test dates, current DSPT and a data flow diagram that matches the DPIA. If the diagram and the DPIA disagree, the reviewer will find it.
Strategist so-what
Claim. DTAC read as a design brief produces a better product and a faster pass.
Implication. Assemble the evidence pack during the bid and submission becomes confirmation rather than construction.