Skip to main content

NCSC IT: There's confidence and then there's SaaS

Raising a cheer for SaaS vendors who respond to our cloud security principles.

Man and woman jumping in the air

This content was last reviewed on 05/03/2025

I don't think it's going too far to say that, at the NCSC, 'we ❤ SaaS.' If you ever want to witness a spontaneous NCSC gurning competition, just tell us you’re going to build and host enterprise services yourself when an entirely serviceable SaaS option already meets your needs.

You’ll get the most impressive expressions if you suggest that your own implementation will be “more secure”, or that the cloud service’s staff can’t be trusted because they “haven’t got UK government clearances”. What matters is that the service you use is suitably secure. This blog post delves into how you can best establish whether this is so.







Written by

Andrew A Cloud Security Research Lead, NCSC