Open call for evidence

Code of Practice for Software Vendors: call for views

Summary

The government is asking for industry views on a draft code of practice for software vendors to improve the resilience and security of software.

This call for evidence closes at

Call for evidence description

Update: 24 May 2024

The closing date for this call for views has been extended to 11.59pm on 9 August 2024.

As part of the £2.6 billion National Cyber Strategy to protect and promote the UK online, the government is working to improve cyber resilience across the UK economy. This includes improving the resilience and security of software to strengthen digital supply chains.

Following the Government’s call for views on software resilience and security for businesses and organisations, the government has undertaken extensive stakeholder engagement to develop a package of policy interventions. The interventions in this package are designed to prevent common mistakes in software development and distribution, and to improve information sharing between software vendors and their customers. Addressing these issues will reduce the likelihood and impact of software supply chain attacks and other incidents that continue to affect organisations across all sectors of our economy.

The government is now publishing a draft Code of Practice for Software Vendors. This voluntary code of practice sets out the fundamental security and resilience measures that should be expected of all organisations which develop or sell software used by businesses and other organisations. The Code of Practice aims to strengthen the foundations of the many kinds of digital technologies that all sectors of our economy rely on. 

This call for views seeks feedback on the proposed design of the Code of Practice for Software Vendors including input on how it should be implemented.

For more information, please read the press notice

The government is also holding a call for views on AI cyber security which is linked to this call for views on software. Please visit the AI cyber security page for further details.

You can read more about how this Code of Practice for Software Vendors aligns with the Code of Practice for AI Cyber Security on the cyber security codes of practice page.

Documents

Ways to respond

or

Email to:

cyber.resilience.consultations@dsit.gov.uk

Write to:

Call for views on software security - area 4-50
Department for Science, Innovation and Technology
100 Parliament Street
London
SW1A 2BQ

Published 15 May 2024
Last updated 24 May 2024 + show all updates
  1. The closing date for this call for views has been extended to Friday 9 August 2024.

  2. First published.