For software customers
Customers of software can be assured that suppliers who comply with the Software Security Code of Practice have products and services that are resilient to common cyber attacks.

If you’re responsible for software procurement (including compliance and the assessment of software security risks), you can use a vendor’s Assurance Principles and Claims document to measure how well they are meeting the principles within the Code. This can be used in your supplier negotiations, and to inform security agreements and contracts.
How customers can check suppliers comply with the Software Security Code of Practice
- 1
Evaluate the vendor
- Read the Code of Practice to understand its purpose, principles, and requirements for software vendors.
- Request the vendor’s Assurance Principles & Claims document, which provides evidence of how a vendor complies with the Code.
- Read the Code of Practice to understand its purpose, principles, and requirements for software vendors.
- 2
Assess the claims
- Cross-check the vendors compliance with the Code using the Assurance Principles & Claims document.
- If a higher level of assurance is required, customers should consider using the NCSC’s Cyber Resilience Testing scheme which can provide third-party, independent assurance of connected products and technology.
- Cross-check the vendors compliance with the Code using the Assurance Principles & Claims document.
- 3
Maintain ongoing assurance
- Request periodic security updates from the vendor.
- Monitor for vulnerabilities and verify that security controls remain effective.
- Request periodic security updates from the vendor.
We invite you to contribute to the Monitoring and Evaluation of the Software Security Code of Practice to assess the effectiveness of this policy and guide future policy decisions. Share your views as a software customer.