Don’t do SECURITY. Do business SECURELY.

Software Security Code of Practice published

A new UK code sets baseline security expectations for software vendors.

The UK Government and NCSC have published the Software Security Code of Practice, setting baseline expectations for organisations that develop and sell software.

The Code is organised into four themes:

  • Secure design and development
  • Build environment security
  • Secure deployment and maintenance, including vulnerability disclosure and timely security updates
  • Communication with customers, including support periods and incident notification

Vendors can self-assess against the Code, and customers can use it as a procurement requirement when buying software.

For software companies, alignment with the Code complements ISO/IEC 27001 secure development controls and prepares the ground for regulation such as the EU Cyber Resilience Act.

Source: Software Security Code of Practice (GOV.UK)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights