Software Code of Practice: building a secure digital future

There are many things commercial enterprises can do to make their technology products more secure. But in reality, we know cyber security is just one of multiple risks that modern businesses have to juggle.
As we explained in the NCSC 2024 Annual Review, technology markets do not incentivise organisations to develop software that is ‘secure by default’. Many standard cyber security features (such as multi-factor authentication or single sign-on) are often deemed ‘premium add-ons', rather than being a fundamental component of the offering.
Understandably, organisations will prioritise growth and profit rather than the security and resilience of their products and services. When the importance of cyber security is recognised, we know from research that software developers are not necessarily security experts, and may find it hard to efficiently build software that is secure using tools that are often inaccessible and complicated.
The UK government want to build a future where products are secure, private, resilient, and accessible to all. This is why the National Cyber Security Centre (NCSC) and the Department of Science, Innovation and Technology (DSIT) have developed a voluntary Software Security Code of Practice, which was launched on 7 May at the CYBERUK event.
‘The Code’ marks the first step in establishing clear expectations for a market baseline with regards to cyber security. It signals – to both software vendors and their customers – what can reasonably be expected from software suppliers and defines the minimum set of actions that should be in place to ensure products and services are resilient to a cyber attack from a commodity threat¹. We have tested the efficacy of each of the actions, ensuring they are proportionate to both the vulnerabilities they mitigate and the likely budget available (given that the 98% of the UK’s private-sector comprises of small businesses).
The Code provides a framework to help organisations measure their progress, identify improvements, and provide tangible evidence of their commitment to security. It includes practical guidance to make clear to vendors what is required to ‘bake’ cyber security into all stages of the development life cycle. Doing this addresses cyber security problems at the root cause and prevents costly redesigns later on.
For customer organisations, knowing their software provider has followed the Code provides confidence the software has been created using reasonable security measures and good practices. Customers can require their provider to assert they meet the Code of Practice, but should they want more confidence they can ask for independent testing. For this reason, the Code is launched in partnership with a new assurance process that allows for a formal assessment of the resilience of connected products that have software elements.
Alternatively, vendors can self-assess against the Software Security Assurance Principles & Claims document, which will help vendors measure how well they are meeting the principles of the Code (and suggests remedial actions should they fall short).
Standards to reduce cyber risk
The Code stems from the UK government’s advocacy for a ‘secure by design’ approach to technology development, ensuring that security becomes a priority for technology providers. It builds on the 2022 Product Security and Telecommunications Infrastructure (PSTI) Act, which mandates that manufacturers, importers and distributors of Internet of Things (IoT) devices must comply with baseline security requirements, so UK consumers can trust that these products are designed and built with security in mind. Alongside the codes of practice for the Cyber Security of AI and for App Stores, the Software Security Code of Practice reflects the government’s ongoing focus on codifying minimum standards for technology providers to reduce cyber risk.
We know that executive and organisational behaviours are driven by several factors, and that no single intervention or incentive is likely to achieve the behaviour change in software vendors we’re aiming for. However, the launch of the Software Security Code of Practice represents the first step to address the market incentives and behaviours for secure software. This will need to be a collaboration across international boundaries to have real, global, impact, which is why the UK actively supports other international secure by design initiatives.
In the meantime, we encourage vendors of all sizes to:
- Download the Code of Practice and explore how it can help your organisation.
- Get started and download the guidance most relevant to your role.
Ollie Whitehouse
Chief Technology Officer (CTO) at NCSC
Rod Latham
Director for Cyber Security and Digital Identity at DSIT
¹Attacks using tools and techniques that are openly available on the internet, requiring limited technical capabilities.


