Healthcare software development in the UK costs more and takes longer than equivalent work in any other sector, and the reason is not that the code is harder. It is that a substantial portion of the budget goes on evidence rather than features: clinical risk documentation, information governance, and assurance paperwork that a buyer will ask for before they will even trial the product.
Teams who have built software elsewhere consistently underestimate this. They price the application, win the work, and then discover that the compliance layer is not a phase at the end but a parallel workstream that has to start on day one, because it constrains architectural decisions that are expensive to revisit.
What actually drives the cost: roughly a quarter to a third of a UK healthcare build goes on clinical safety, information governance and assurance evidence rather than functionality. The determining question is not how complex your application is, but whether it touches patient data, whether it influences a clinical decision, and whether the NHS is the buyer. Each of those adds a distinct and non-optional workstream.
The Three Questions That Set Your Scope
Before anything is estimated, three things need answering, because they decide which regimes apply and the cost difference between the answers is several multiples.
Does it handle patient data? If yes, UK GDPR applies with health data treated as a special category, and if the NHS is involved you will need to complete the Data Security and Protection Toolkit . The Toolkit is an annual self-assessment against a defined set of standards, and its current version is built on the National Cyber Security Centre’s Cyber Assessment Framework rather than the older standalone standards. This is a genuine engineering constraint, not a form-filling exercise, because it reaches into access control, audit logging, encryption and supplier management.
Does it influence a clinical decision? If yes, clinical risk management applies, and this is the workstream most often missed. DCB0129 is the standard for manufacturers of health IT systems and DCB0160 is the counterpart for the organisations deploying them. Both are currently under national review , with a public consultation that opened on 29 June 2026 and runs to 11 September 2026, so the detail may shift. What will not shift is the requirement itself, or the need for a named clinical safety officer with appropriate clinical background to own the hazard log and sign off the safety case.
Is it a medical device? Software can be, and the MHRA publishes guidance on software and AI as a medical device . If your product diagnoses, monitors, predicts or treats, it may fall under the medical device regime and require conformity assessment through a UK Approved Body, which is a separate cost and a separate calendar measured in months rather than weeks. Getting this classification wrong in either direction is expensive, and it is worth paying for a regulatory opinion early rather than discovering it during procurement.
DTAC, and What Changed in 2026
If you are selling into the NHS, the Digital Technology Assessment Criteria is the gate you will meet first. It bundles clinical safety, data protection, technical security, interoperability and usability into a single assessment that NHS organisations use to evaluate suppliers.
NHS England published an updated form on 24 February 2026, and organisations were required to move to it by 6 April 2026, after which the previous version was no longer accepted. The refresh was a simplification. The form carries roughly a quarter fewer questions, largely by removing duplication with the Data Security and Protection Toolkit and the Pre-Acquisition Questionnaire, and the requirement that the named clinical safety officer must have completed specific NHS Digital training no longer stands. The five assessment areas themselves are unchanged, with the requirements inside them modernised.
The important thing for anyone budgeting a build is that DTAC is not something you complete afterwards. It asks for evidence that has to have been generated during development. A supplier who starts thinking about it when the first NHS trust asks will spend two to three months retrofitting documentation, and some of the answers will require code changes.
The Medical Device Question
For anything approaching software as a medical device, the UK position is still in motion and worth understanding before you commit to a market strategy.
Great Britain currently recognises CE-marked devices under transitional arrangements, with deadlines of 30 June 2028 for devices certified under the older directives and 30 June 2030 for those certified under the EU medical device and in vitro diagnostic regulations. Around nine in ten devices on the Great Britain market carry CE marking rather than UKCA. In February 2026 the MHRA opened a consultation proposing to extend the first deadline to 31 December 2028 and to make recognition of EU-compliant CE-marked devices indefinite by removing the 2030 sunset entirely. That consultation closed in April 2026 and the outcome is expected later in the year.
The practical read for a UK product team is that the direction of travel favours alignment rather than divergence, but nothing is settled. If your route to market depends on which marking you pursue, that decision should be revisited when the consultation outcome lands rather than fixed now. Note also that UK Approved Bodies are a distinct list from EU Notified Bodies, and capacity at both has been a persistent bottleneck.
What It Costs
UK build costs follow the same structure as other custom software, with a compliance premium layered on.
A focused tool with a narrow scope, no clinical decision support and no NHS procurement route sits in the £15,000 to £35,000 range. Think of a private clinic booking and records front end, or a patient-facing portal that integrates with an existing practice management system.
A substantial application with real integration work, information governance and a DTAC submission runs £35,000 to £75,000. This is the common band for a product intended to be sold to NHS trusts or to a group of private providers, and the compliance workstream is a meaningful fraction of it.
Beyond £75,000 you are in enterprise territory, with clinical safety documentation, formal risk management, interoperability against national standards and often a conformity assessment route. Products in this band routinely reach £250,000 and above, and the timeline is driven by assurance rather than engineering.
Day rates track the wider market at £75 to £150 an hour depending on seniority, but healthcare projects carry two roles that general projects do not. A clinical safety officer is a specialist appointment, usually part time, and an information governance lead is either a hire or a retained consultant. Budget for both from the start. Our custom software development cost guide breaks down how the underlying build hours are usually distributed.
Where Healthcare Software Development Projects Fail
Rarely on the code. The recurring failures are structural and predictable.
Compliance treated as a phase. Teams schedule it after the build and find that decisions about data residency, audit logging and access control have already been made in ways the assurance process will not accept. Reversing those is expensive.
No clinical safety officer until procurement asks. The hazard log is meant to be a living record built alongside development. Reconstructing one retrospectively produces a document that is obviously reconstructed, and experienced NHS reviewers spot it immediately.
Integration assumed to be simple. Connecting to existing clinical systems is usually the longest pole in the schedule, and access to a test environment can take longer to arrange than the integration takes to write. This is worth confirming before the contract is signed, not after.
Security treated as a checklist. Health data is a high-value target and the assurance regimes reflect that. Penetration testing should be scheduled and budgeted, not discovered. Our guidance on website security audits covers the baseline, though clinical systems warrant a deeper engagement than a standard commercial application.
Choosing a Vendor
The differentiator is not whether an agency has built healthcare software before. It is whether they have taken a product through an assurance process and can show you the artefacts.
Ask to see a redacted hazard log and a clinical safety case. A vendor who has done this will have them. A vendor who has not will describe the process in general terms and change the subject.
Ask who their clinical safety officer is and whether that person is on staff or engaged per project. Either answer is acceptable. Not having one is not.
Ask about DTAC specifically, and whether they have worked with the version introduced in February 2026. The refresh was recent enough that a vendor still describing the old form is telling you when they last did this.
Ask how they would handle the medical device classification question for your product. You are not looking for a definitive answer, which would be a warning sign in itself. You are looking for evidence that they know the question exists and know when to bring in a regulatory specialist. Our guide to choosing a software development agency covers the commercial due diligence that applies to any build.
Getting the Scope Right Before You Commit
The most expensive mistake in this sector is committing to a fixed price against a scope that has not yet established which regimes apply. The classification questions at the top of this article change the cost by a factor of five, and they can be answered in a short discovery engagement rather than guessed at.
Mecanik builds compliance-constrained applications through our software development team, with information governance and security assurance handled by the same people who write the code rather than bolted on by a separate firm. If you are scoping a healthcare product and are not yet certain which of the three questions applies to you, that is the conversation worth having first.
Related reading: Custom Software Development UK - The Complete Buyer’s Guide , AI Agents for Business: What They Cost and Where They Fail , How to Build a Web App in 2026 - The UK Developer’s Guide and Medical & Healthcare Website Development UK 2026 .
Frequently Asked Questions
What makes healthcare software development more expensive in the UK? Roughly a quarter to a third of the budget goes on clinical safety documentation, information governance and assurance evidence rather than functionality. These are parallel workstreams that constrain architecture from day one, not phases that can be added at the end.
What is DTAC and when does it apply? The Digital Technology Assessment Criteria is the assessment NHS organisations use to evaluate digital suppliers, covering clinical safety, data protection, technical security, interoperability and usability. NHS England published an updated form on 24 February 2026 which became the only accepted version from 6 April 2026, carrying around a quarter fewer questions than its predecessor.
Do I need a clinical safety officer? If your software influences a clinical decision, yes. DCB0129 applies to manufacturers of health IT systems and DCB0160 to the organisations deploying them, and both require a named clinical safety officer with a suitable clinical background to own the hazard log and sign the safety case. Both standards are under national review, with a consultation running from 29 June to 11 September 2026.
Is my software a medical device? It may be if it diagnoses, monitors, predicts or treats. That classification triggers conformity assessment through a UK Approved Body, which adds months and cost. Great Britain currently recognises CE-marked devices under transitional deadlines of 30 June 2028 and 30 June 2030, and an MHRA consultation that closed in April 2026 proposed extending the first and making recognition of EU-compliant devices indefinite.
How much does NHS-ready healthcare software cost? A narrow tool with no clinical decision support runs £15,000 to £35,000. A substantial application with integration, information governance and a DTAC submission runs £35,000 to £75,000. Enterprise products with formal clinical risk management and conformity assessment start at £75,000 and routinely exceed £250,000.
Comments