Skip to main content

Software Security Code of Practice

For software customers

Customers of software can be assured that suppliers who comply with the Software Security Code of Practice have products and services that are resilient to common cyber attacks.

If you’re responsible for software procurement (including compliance and the assessment of software security risks), you can use a vendor’s Assurance Principles and Claims document to measure how well they are meeting the principles within the Code. This can be used in your supplier negotiations, and to inform security agreements and contracts.


How customers can check suppliers comply with the Software Security Code of Practice

  • 1

    Evaluate the vendor

  • 2

    Assess the claims

  • 3

    Maintain ongoing assurance

    • Request periodic security updates from the vendor.
    • Monitor for vulnerabilities and verify that security controls remain effective.

We invite you to contribute to the Monitoring and Evaluation of the Software Security Code of Practice to assess the effectiveness of this policy and guide future policy decisions. Share your views as a software customer.