DCB0129 & DCB0160 · UK NHS clinical safety

Appraise it.
Approve it.
Deploy it.

Options appraisal, business case and both NHS clinical safety standards in one continuous record. For the teams who build digital health software, and the organisations that deploy it.

No credit card required to begin · Email-verified · Live in under 10 minutes

What the platform covers

Frame the problem, then compare every option - including doing nothing.

Write the criteria before you see the options, score the candidates against the same ones, and model the do-nothing baseline properly so the cost of inaction is on the record rather than assumed. Options you reject keep their reasoning, which is exactly what a commissioner or an auditor asks for eighteen months later.

For provider organisations choosing what to adoptFor software teams who need the case their buyer has to make
Mandatory 2FA on every login Aligned to NHS DCB0129 & DCB0160 Free to start - live in 10 minutes Named CSO available as a service
Free 14-day series

Sign up to our 14-day Clinical Safety Series.

A short daily email - 5 minutes a day for 14 days - covering everything a manufacturer or NHS deployer needs to know to navigate DCB0129 and DCB0160 with confidence.

  • Plain-English walkthrough of DCB0129 and DCB0160
  • How to run a hazard workshop that actually finds hazards
  • Templates for intended use, CRMP, ALARP and the safety case
  • No fluff. No hype. Unsubscribe in one click.

We'll only email you the 14-day series and the occasional Trygg.Health update. No spam. Ever.

Thanks - the first lesson is on its way. Check your inbox in a moment.
The problem

The expensive decisions get made before compliance starts.

Most organisations appraise digital options in a spreadsheet somebody built once and a business case template somebody else wrote, then open a hazard log weeks later. By that point the choice has already been made, somewhere nobody can trace.

Compliance starts too late

Nobody can reconstruct why this product was chosen over the two that were rejected, or what those rejected options would have cost.

The consequences are unplanned

A product that clears the front door faster moves the queue further down the pathway, unless somebody modelled that before go-live. Hazards, meanwhile, sit in a spreadsheet drifting from the real product.

The audit trail is broken

The safety case cites an intended use that lives in a business case the platform has never seen, and the DCB0129 work never translates into the deployer's DCB0160 case. Two versions of the truth, one of them stale.

The three stages

Three stages, one continuous record.

Each stage inherits everything the stage before it decided. Nothing is re-typed, and nothing is asserted twice.

Appraise

Frame the operational or clinical problem, compare the candidate solutions including doing nothing, model the workforce and financial position once the change has stabilised, and produce a business case an executive team can act on.

Approve

Turn the chosen solution into a defensible clinical safety case under DCB0129 and DCB0160, with a 208-question guided scope, AI-seeded hazard workshops, 5×5 risk scoring, controls, CRBA and ALARP - and a named Clinical Safety Officer signing every judgement.

Deploy

Freeze the evidence, hand it across on a gated and versioned handshake, map the clinical pathway and interfaces it lands in, and keep the safety case live so a new release or a changed pathway re-opens the assessment rather than escaping it.

The platform

One platform from the problem you identified to the product you deployed.

Trygg.Health turns options appraisal, business case development and the two NHS clinical safety standards into a single guided workflow your whole team can run. Problem, options, benefits, hazards, controls, ALARP, CRBA, documents - all in one place, all linked, all auditable.

  • Options appraisal and business case built in the same record that later carries the safety case, so the intended use and the benefits claimed are stated once.
  • Intended use dictates which questions from our 208-question scoping questionnaire are appropriate, with auto-save and conditional logic.
  • Hazard workshops with AI suggestions, 5×5 risk matrix, and pre/post-control scoring.
  • Auto-generated documents in PDF, Word and Excel - CRMP, hazard log, workshop reports, safety case.
  • Compliance engine tracks 10 mandatory items and gates the safety statement at 100%.
  • Deployment handshake hands a verified safety case from manufacturer (DCB0129) to NHS deployer (DCB0160).
Try it free
Who it's for

Two workflows. One version of the truth.

Trygg.Health understands the full lifecycle - from the manufacturer building software, to the organisation appraising it and putting it into a live clinical pathway. We have done it, from both sides.

DCB0129 · Manufacturers

Ship safe software, faster.

For health tech founders, regulatory leads and clinical safety officers building digital health products that need to land in the NHS.

  • Define your product, intended use and clinical risk management plan in one guided flow
  • 208-question scoping with conditional logic - only answer what's relevant to you
  • Hazard library + GPT-4o suggestions seed your workshop, you keep clinical judgement
  • Auto-generated CRMP, Hazard Log and Clinical Safety Case Report in PDF/Word/Excel
  • Track third-party components and their hazards as part of your safety case
  • Versioned releases - each handshake to a deployer is a frozen, auditable artefact
Start as a manufacturer
Appraise + DCB0160 · Provider organisations

Decide well, then deploy defensibly.

For NHS Trusts, ICBs and independent providers appraising digital options and responsible for deploying third-party products into a live clinical pathway.

  • Appraise the options against the problem you identified, including the option of doing nothing
  • Model the workforce and financial position after the change has stabilised, not on day one
  • Produce a business case generated from the appraisal rather than written up separately
  • Receive a verified DCB0129 handshake from the manufacturer - no chasing emails
  • Map your clinical pathways, system interfaces and IT infrastructure in structured fields
  • Identify and score deployment-specific hazards distinct from the product hazards
  • Run your own workshops with the same hazard library and 5×5 matrix
  • Generate your DCB0160 safety case for sign-off without reformatting Word docs
  • Maintain post-deployment monitoring and re-issue when the product version changes
Start as a deployer
How it works

From the problem to the deployed product in five steps.

Each step builds on the last. No retyping, no re-versioning Word documents, and no "where's the latest hazard log?" messages.

Frame the problem

Start from the operational or clinical problem, not from the product a supplier is selling.

Appraise the options

Compare the candidates, including doing nothing, and model the workforce and financial impact.

Produce the business case

A structured case generated from the appraisal, ready for an executive team to act on.

Scope and workshop

208 questions with conditional logic, then a hazard workshop with AI suggestions and 5×5 scoring.

Approve and hand off

Generate the documents, gate the safety statement at 100%, then a versioned handshake into deployment.

What's inside

Everything your safety case needs.

Eleven modules built for the realities of running clinical safety inside a fast-moving health tech team.

Roles & access

Manufacturer, CSO, Deployment CSO and Superuser - each with the right level of access.

Product workflows

Two parallel paths for DCB0129 (dev) and DCB0160 (deployment) with shared lifecycle phases.

Scoping questionnaire

208 questions with auto-save, conditional logic and per-component sub-questions.

Hazard management

Workshop prep, AI suggestions, identification, scoring, controls and residual risk - all in one place.

5×5 risk matrix

Colour-coded clinical risk visualisation - green, amber, red - for severity × likelihood.

CRBA & ALARP

Clinical Risk Benefit Analysis and "As Low As Reasonably Practicable" assessments - only when needed.

Document generation

CRMP, Hazard Log, Workshop Reports and Safety Case as PDF, Word and Excel - versioned.

Compliance engine

10-item checklist gates the safety statement until 100% - no surprises at sign-off.

Deployment handshake

5-point eligibility check, then a versioned, frozen artefact handed to the deployer.

Personnel management

Assign team members to products with roles. UI alerts when no one is set for a workshop.

Deployment scope

Clinical pathways, system interfaces and IT infrastructure - granular CRUD for the real world.

Contact & feedback

Built-in feedback and contact loops so issues never disappear into a support inbox.

Powered by GPT-4o

AI that helps you find the hazards you'd miss.

Trygg.Health uses AI to pattern-match against a curated hazard library, draft your intended-use statement, and flag safety-critical features in your questionnaire answers - so your workshop starts at "review and refine," not "blank page."

Clinical judgement stays with your CSO. AI just stops you missing the obvious.

Try the AI workflow
Hazard suggestions for: Remote vital-signs monitor (paediatric)
HZ-001 · Incorrect SpO₂ reading displayed due to poor sensor contact (severity 4 · likelihood 3)
HZ-002 · Delayed alert delivery in low-bandwidth conditions (severity 4 · likelihood 2)
HZ-003 · Misinterpretation of paediatric vs adult thresholds (severity 5 · likelihood 2)
HZ-004 · Patient ID mismatch on multi-bed ward deployment (severity 5 · likelihood 1)
Document outputs

Every artefact a regulator or NHS Trust will ask for.

Generate the documents directly from your live data. No re-typing. No version drift. Re-export any time the product changes.

PDF

Clinical Risk Management Plan

Your CRMP - the spine of your safety case. Personnel, scope and methodology, exported on demand.

XLSX

Hazard Log

Every hazard, control, residual risk and ALARP statement - straight to Excel for review.

DOCX

Workshop Report

Workshop attendees, decisions, scoring rationale and outputs - ready to circulate.

PDF

Clinical Safety Case Report

The headline DCB0129 / DCB0160 deliverable - current with the latest product version.

PDF

Summary Safety Statement

Executive-friendly summary, gated by a 100% compliance check before it becomes available.

DOCX

CRBA & ALARP records

Conditional outputs - only generated when residual risk requires them.

XLSX

Deployment scope register

Clinical pathways, interfaces and IT infrastructure mapped for DCB0160 deployers.

PDF

Handshake artefact

Versioned, frozen package handed from manufacturer to NHS deployer - auditable end-to-end.

Security & trust

Built for data that has to be right.

Clinical safety data is sensitive. Trygg.Health is built with the assumption that the wrong person should never see, edit or delete it.

Mandatory 2FA

Every login requires a fresh email-verified 6-digit code. No exceptions, no opt-out.

Per-user data isolation

Every database query is scoped to the owning user. Superuser access is logged and limited.

Cascading safe delete

Account deletion cascades cleanly across 31 tables in a single transaction - no orphan data.

Versioned handshakes

Every deployment package is frozen and timestamped - re-issue cleanly when the product evolves.

Pricing

Start free. One price when you're serious.

A free tier to test the workflow on a single product, one paid tier that includes everything, and a named Clinical Safety Officer on tap if you would rather not appoint one internally.

Starter

For founders just beginning
£0/ month

Test-drive the scoping questionnaire and hazard workflow on a single product.

  • 1 product
  • Full questionnaire & hazard workshop
  • PDF document export
  • Email support
Start free

CSO-as-a-Service

Named CSO included
Custom

Everything in Access, plus a Named Clinical Safety Officer to facilitate workshops and sign off your safety case.

  • Named CSO from Trygg.Health
  • Workshop facilitation
  • Safety case sign-off
  • Quarterly review
  • Trust onboarding support
Talk to us
About us

Built by people who've lived this problem.

Trygg Health was founded by clinicians who have built and deployed digital health software inside the NHS. We made the platform we wished we'd had.

Luke Kellaway

Luke Kellaway

Co-founder · Strategy

Driven by a passion for digital innovation and clinical safety, Luke co-founded Trygg Health with Simon. Over 15 years in healthcare and HealthTech, with strategic leadership at C-suite and board level steering Trygg from a strategy perspective.

Luke excels at transforming healthcare ideas into market-ready solutions and scaling them for broad impact, forging partnerships with NHS commissioners, patients, elite sports, and corporate stakeholders.

Simon Smith

Simon Smith

Co-founder · Clinical Safety Lead

Over the past five years, Simon has designed and deployed software for the NHS, meeting clinical safety standards and streamlining care pathways. He balances pragmatic development with complex regulatory demands across the full software lifecycle.

His expertise covers Clinical Safety Officer duties, DCB0129, DCB0160, Software as a Medical Device, and quality/risk management systems (ISO 13485, ISO 14971). Nearly 30 years in clinical practice and 13 years in leadership across radiology, medicines management and surgical pathways.

Questions, answered

FAQ

Does Trygg.Health help before the compliance work starts?

Yes, and that is the part most tools skip. Before any hazard log is opened you can frame the problem you are actually solving, appraise the candidate solutions against it including the option of doing nothing, model the workforce and financial position once the change has stabilised, and generate a business case from that appraisal. Because it lives in the same record that later carries the safety case, the intended use and the benefits claimed are stated once rather than asserted twice in two documents that drift apart.

Why does the appraisal stage matter commercially?

A product that clears the front door faster often just moves the queue further down the pathway, and infrastructure cost that falls out of one budget has to be reinvested somewhere. If those consequences are modelled before go-live, finance and operations are given a decision rather than a request to fund an experiment, which is usually the difference between a business case that moves and one that stalls for a quarter.

What is DCB0129 and why does it matter?

DCB0129 is the NHS clinical safety standard for manufacturers of health IT software. If you build digital health software intended to be deployed in the NHS, you need a clinical risk management process - including a Clinical Safety Officer, a hazard log, and a Clinical Safety Case Report - that conforms to it. Trygg.Health implements that process end-to-end.

What is DCB0160 and how is it different?

DCB0160 is the matching standard for the deploying organisation - typically an NHS Trust or ICB. It governs how the deploying CSO assures safe deployment of a third-party product into a specific clinical pathway and IT environment. Our deployment handshake makes the manufacturer-to-deployer transition seamless.

Do I need a Clinical Safety Officer (CSO)?

Yes - both DCB0129 and DCB0160 require a named CSO, and they must be a registered healthcare professional. If you don't have one in-house, our CSO-as-a-Service tier provides a Named CSO from Trygg.Health to facilitate workshops and sign off your safety case.

How long does a typical safety case take in Trygg.Health?

Most teams move from sign-up to a draft Clinical Safety Case Report in 1-3 weeks, depending on product complexity. The 208-question scope, AI hazard suggestions and auto-generated documents collapse the work that traditionally takes 2-6 months.

Can I migrate an existing safety case in?

Yes. You can paste your intended-use statement, upload your existing hazard log, and use Trygg.Health to keep it living from that point forward. Existing artefacts can be referenced in the document repository.

Where is my data stored?

Data is stored in PostgreSQL (Neon) with per-user isolation enforced at the query layer. Every login requires email-verified 2FA. We do not share your data with any third party except where you explicitly trigger it (e.g. AI hazard suggestions through OpenAI).

Is the AI making clinical decisions?

No. The AI suggests hazards and drafts language. Your Clinical Safety Officer always reviews, scores and signs off. AI proposes, the clinical team reviews, the CSO decides, and your organisation signs off.

Does using Trygg.Health make my organisation compliant?

No, and any supplier telling you otherwise is worth a second look. The platform structures the work, seeds hazard suggestions, scores and versions every record, generates the documents, and stops a safety statement being issued before the mandatory items are complete. Clinical judgement, the named Clinical Safety Officer's sign-off, the decision on whether residual risk is acceptable, and organisational accountability for what gets deployed all remain with you.

Appraise it. Approve it. Deploy it.

Start free on a single product, or talk to us about Access for your organisation.