Software Security Code of Practice
The Code is a systemic intervention by the UK government, designed to ensure that organisations ‘bake’ security into software from the start. It defines a baseline for cyber security and signals – to both vendors and customers– the controls that organisations should have in place to ensure products and services are resilient to common cyber attacks.

Getting started
Vendors
Vendors should download the Code from the Department of Science, Innovation and Technology (DSIT) website, and explore our resources to help vendors to conform with the Code within their own organisation.
Customers
Customers can use the Code to guide supplier negotiations, and can use our resources to ensure providers are complying with the Code to deliver software that is secure and resilient.

About the Code
The Software Code of Practice has been created by DSIT and the National Cyber Security Centre (NCSC), the UK’s technical authority for cyber security, and is co-sealed by the Canadian Centre for Cyber Security (CCCS). The Code reflects the government’s ongoing focus on codifying minimum standards for technology providers to reduce cyber risk. It is aimed at professionals who are responsible for overseeing the development of ‘commodity’ software, including technical, compliance, and risk experts. For those organisations that require a higher level of assurance in the resilience of their connected products and technology, consider using the NCSC’s Cyber Resilience Testing scheme.
DSIT and NCSC invite you to contribute to the Monitoring and Evaluation of the Software Security Code of Practice. Whether your organisation supplies software or is a customer of software products, your insights are valuable in helping us assess the effectiveness of this policy and guide future steps. Take the survey.