CyberzSOC

Publication detail
← Back to advisories & guidance

Software Security Code of Practice - Assurance Principles and Claims (APCs) ↗ source

May 7, 2025 NCSC Guidance

Summary

Helps vendors measure how well they meet the Software Security Code of Practice, and suggests remedial actions should they fall short. This document allows technical staff to self-assess their own software practices against the Software Security Code of Practice, a set of outcomes that – if met – means the vendor can claim that their software has achieved a baseline of software security and resilience. This document considers each principle within the four themes in the Code, and breaks them down into a set of individual claims that describe a way to fully meet the associated principle. If all these claims are well-evidenced, then a vendor can claim in good faith that they are meeting the principle. The type of evidence can vary but examples include document inspection, interviewing individuals, or auditing test plans and results. Vendors requiring independent audit of compliance with the code should contact any NCSC-approved cyber resilience test facility.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.