Description

Department for Science, Innovation and Technology published Software Security Code of Practice

On 7 May 2025, the UK Department for Science, Innovation and Technology (DSIT) published the voluntary Software Security Code of Practice. The Code was developed in partnership with the National Cyber Security Centre (NCSC), the Canadian Centre for Cyber Security, and a group of technical, industry, and academic experts. It sets out 14 principles to establish a consistent baseline of software security and resilience across the market. The principles are grouped under 4 themes, namely secure design and development, build environment security, secure deployment and maintenance, and communication with customers. The Code applies to organisations that develop or sell proprietary software or software services in a business-to-business context. Furthermore, the DSIT has published a self-assessment template and is developing a certification scheme.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
other service provider
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2024-05-15
in consultation

On 15 May 2024, the Department for Science, Innovation, and Technology (DSIT) opened a public consu…

2024-08-09
in consultation

On 9 August 2024, the Department for Science, Innovation, and Technology (DSIT) closes the public c…

2025-05-07
adopted

On 7 May 2025, the UK Department for Science, Innovation and Technology (DSIT) published the volunt…