Mapping of the AI and software security services market
Published 10 July 2026
Executive summary
Background
Pye Tait Consulting was commissioned by the Department for Science, Innovation and Technology (DSIT) to undertake first-of-its-kind primary research with software security and Artificial Intelligence (AI) security providers. The overarching aim was to map the software security and AI security markets to understand what services and tools they offer, their awareness and the extent to which their tools would support the implementation of the principles in the Software Security Code of Practice, AI Security Code of Practice, and the AI security global standard. Specific objectives are listed in Section 1.2.
The rapid digitalisation of the UK economy has brought unprecedented opportunities for growth, innovation and productivity. However, this transformation has also introduced complex cyber security challenges, particularly in the domains of software and AI. The cyber security breaches survey 2025 highlighted that cyber-attacks or breaches had affected 43% of UK businesses in the past year. This underscores the urgent need for robust cyber security measures as adoption of AI and digital technologies accelerates across all sectors.
DSIT and the National Cyber Security Centre (NCSC) have therefore developed the Software Security Code of Practice and taken a leading role in the European Telecommunications Standards Institute (ETSI) to create an AI security global standard, EN 304 223. This global standard builds on NCSC’s guidelines and DSIT’s AI Security Code of Practice and applies to all AI tools, models and systems. The Software Security Code of Practice was co-created with industry and the NCSC to outline the baseline software security principles that software suppliers should take when supplying to businesses, but it can also be used by buyers as a supply chain tool. These documents set out baseline security requirements for software and AI. Organisations in this sector should engage with these to shape their offerings and to encourage their customers to meet core expectations of businesses.
In 2025, DSIT published a market analysis of software and AI security services. Through desk-based research, that study identified 66 AI and 960 software security providers. The subsequent 2026 cyber security sectoral study showed the market had grown to 111 AI and 1,141 software security providers. Those studies have informed the technical approach taken for this survey (see below for more information).
Methodology
Extensive engagement was undertaken to contact all businesses identified in the 2026 cyber security sectoral study,[footnote 1] as well as other firms identified through freely available online sources and databases as potentially being in-scope. This was supplemented with promotion and outreach through email, telephone, social media, and sector press. In total, 1,906 software and 127 AI security providers were contacted to achieve a minimum of 200 software and 50 AI responses (i.e. around half the AI security market and a fifth of the software security market identified via the 2026 cyber security sectoral analysis) through a mixture of telephone and online approaches. The firms contacted included providers identified through the 2026 cyber security sectoral analysis, as well as additional businesses provisionally identified through desk research – of the latter some, on contact, proved not to be in-scope.
Similar survey questionnaires were developed for software and AI security providers and each comprised quantitative and qualitative questions. The surveys, including piloting, were live from November 2025 to January 2026, and engaged with senior representatives within businesses based across the UK (12 of the 250 are based in the USA or Western Europe). Results were validated through desk-based review to cross-reference data and to fill gaps where feasible.
The market mapping revealed a software security sector comprising mainly micro (51%) and small (34%) firms with a minority medium (11%) or large (5%). Responding AI security providers are roughly split between micro (32%), small (28%), and large (30%) companies, with the remainder being medium (10%). These sample spreads, while not statistically representative, are in alignment to a good extent with the size demographics found in the 2026 cyber security sectoral analysis.
Limitations
Respondents were presented with topline summaries of the principles of the Codes of Practice in statement form, however, the Codes of Practice have a greater level of detail beneath this topline that respondents were not presented with, meaning it is possible respondents may have not provided a fully considered response.
The final three themes within the AI Security Code of Practice were grouped to manage respondent burden. However, a consequence of this might be that respondents answered in relation to one theme meaning views on one theme specifically are masked by this grouping.
Strengths and limitations of the research are detailed further in the Appendix.
Key findings
High awareness of the Codes of Practice and AI security global standard
There is a high degree of market awareness and knowledge of the global standard and Codes of Practice. The vast majority of AI security providers (92%) are aware of the AI Security Code of Practice and 86% are aware of the global standard. Four fifths (81%) of software security providers are aware of the Software Security Code of Practice.
Good levels of knowledge of the Codes of Practice and AI security global standard
Providers have a good level of knowledge too, with nearly half (47%) of software security providers holding detailed awareness of the Software Security Code of Practice, and similar proportions of AI security providers noting likewise for the AI Security Code of Practice and global standard (48% and 45% respectively).
Considerable influence of the Codes of Practice and AI security global standard
Around half of the companies currently refer to the documents when creating or selling security services (48% of software security providers and 50% of AI security providers).
Interest and market demand for AI and software security services
Market demand is primarily driven by clients’ desire for protection, including against potential breaches, service disruption, or supply chain attacks (each noted by a large majority of software and AI security providers). Meeting regulatory requirements is also a common driver for client interest (mentioned by over half), as are contractual obligations (mentioned by just under half), with both reasons noted more frequently by larger providers.
Limited interest is typically reported where clients believe existing security measures suffice, or where customers underestimate the likelihood or impact of a breach (as noted by around half of security providers). In these instances, providers perceive that security is often not a priority for clients and suggest their limited understanding and awareness of potential threats contributes to lower interest.
Services and tools currently offered map well across all principles of the Codes of Practice and AI security global standard
Among services offered, there is generally good coverage across all principles within the Codes of Practice and global standard. Coverage within both software and AI markets is strongest for the themes of secure design and secure development, and slightly more limited (but still good) coverage for other themes.
Penetration testing remains the dominant software and AI security service, ranking among the top three services offered across every theme of both Codes of Practice (except for the communication with customers theme). Threat modelling and vulnerability management services are also widely offered across most software security themes (all themes excluding communication with customers) and appear frequently, though less consistently, in relation to AI security. Training, governance and consultancy services are offered by some providers in each area of both Codes of Practice. AI security services tend to be less standardised and, particularly towards the end-of life stage, are more limited or experimental.
Use of AI within current services and tools offered
The study also sought insights into how AI and Machine Learning (ML) is used to deliver software and AI security services and tools. Surveyed software security providers most commonly use AI/ML in Application Security (AppSec) testing (30%), intelligent patch management (24%), and automated incident response or triage (23%), although many (39%) do not use AI/ML.
For AI security providers, AI/ML use is more prevalent, with ‘AppSec testing’, and ‘AI-assisted code scanning or secure development tools’ (both 59%) most common.
Legislation and increased client demand would help drive uptake
To help or encourage expanding their service offering, over half of providers suggest legislative measures would have a notable bearing on this (software: 55%, AI: 51%). Increased client demand is also a major factor – particularly for AI security (70%) but also for software security (33%).
1. Introduction
1.1 Background
1.1.1 The need for secure systems
The rapid digitalisation of the UK economy has created significant opportunities for growth, innovation, and productivity. As organisations across all sectors adopt more software driven and AI-enabled technologies, their reliance on digital systems has increased and with it, their exposure to cyber incidents. The 2025 cyber security breaches survey highlights that cyber-attacks or breaches have affected 43% of UK businesses in the past year, underscoring the urgent need for robust cyber security measures as adoption of AI and digital technologies accelerates across all sectors. This expanding dependence underscores why the actions of technology developers and suppliers matter: the way systems are designed, built, and maintained plays a critical role in shaping the UK’s overall cyber resilience.
To address these risks and support developers and suppliers, the cyber security market has evolved to provide a wide range of tools and services that help organisations embed secure practices into their technologies. These include core software security services such as Application Security (AppSec) testing, secure development lifecycle (SDLC) solutions, penetration testing, and threat modelling, as well as AI-specific services that protect models from manipulation, theft, or misuse. Such tools play an essential role in identifying and mitigating risks throughout the development process, reinforcing ‘security by design’ principles. Software supply chains are heavily reliant on opensource components and distributed environments, which further elevates the importance of solutions such as code reviews, vulnerability assessments, API security tooling, and container and supply chain security services.
Cyber security solutions must continue to keep pace not only with evolving threats, but also with the rapid expansion of the market it serves. The 2025 cyber security sectoral analysis found that, between 2022 and 2024, the number of AI companies in the UK grew by more than 85%, far outstripping the growth of new businesses in the wider economy, and the broader cyber security sector has seen growth of over 10% in terms of employment and revenue. This growth reflects the rapid expansion of cyber security requirements within the wider economy, and the need for comprehensive, effective and trustworthy security provision.
Taken together, these trends highlight the vital role of software and AI security in sustaining the UK’s competitiveness, resilience, and economic security. Ensuring that cyber security providers follow best practice and offer comprehensive coverage of all cyber security needs is therefore central to maintaining a secure and innovative digital ecosystem.
1.1.2 Ensuring baseline security
The Department for Science, Innovation and Technology (DSIT) has developed Codes of Practice to set clear expectations for cyber security. These voluntary Codes use ‘principles’ to set out the recommended baseline response to a given set of cyber security risks. The Codes of Practice stem from the UK government’s long-standing advocacy for a “secure by design” approach. This involves ensuring security is a key component of product and service design, proactively focusing on risk-mitigation throughout the lifecycle of the product or services, and instilling confidence in users, whilst encouraging the adoption of secure technologies.
As part of this, DSIT has published the Software Security Code of Practice and the AI Security Code of Practice. The former comprises 14 principles under the four themes.
- Secure design and development
- Build environment security
- Secure deployment and maintenance
- Communication with customers
Meanwhile, the AI Security Code of Practice comprises 13 principles grouped under five themes.
- Secure design
- Secure development
- Secure deployment
- Secure maintenance
- Secure end of life
DSIT and the National Cyber Security Centre (NCSC) have also taken a leading role in the European Telecommunications Standards Institute (ETSI) to create an AI security global standard, EN 304 223. This standard builds on two internationally grounded documents: the aforementioned Code of Practice on AI security which underwent extensive global consultation in 2024 (and which will shortly be updated to reflect the ETSI standard for consistency), and the NCSC/CISA Guidelines for Secure AI System Development.
The Codes of Practice and global standard are aimed at various audiences including suppliers, buyers, and cyber security services, to set out baseline security principles to help secure systems and the organisations which develop and deploy them.
To better understand the extent to which the UK security services market serves AI and software developers, DSIT commissioned a 2025 market analysis of software and AI security services. Through desk-based research, the 2025 market analysis identified 66 AI and 960 software security providers. The subsequent 2026 cyber security sectoral study showed the market had grown to 111 AI and 1,141 software security providers.[footnote 2] The 2026 research identified 108 specialist software security providers and 1,033 firms which offer support for software security as part of a broader offering.
DSIT is now taking forward various levers to support industry with its adoption of its security requirements. To help inform this, DSIT commissioned Pye Tait Consulting to undertake this research to understand if there were particular gaps or areas in the security services market where future support could be best targeted.
1.2 Aims and objectives
The overarching aim of this research was to map the software security and AI security markets to understand what services and tools they offer, their awareness and the extent to which these tools would support the implementation of the principles in the Codes of Practice and the AI security global standard. Specific objectives were as follows.
-
Examine levels of awareness of the Codes of Practice and AI security global standard amongst software and AI security service providers (see section 2).
-
Identify the nature and extent of any gaps in the AI security and software security services market based on the requirements in the AI security global standard and Software Security Code of Practice (see sections 4.1.1 and 4.2.1).
-
Determine themes in terms of common tools and approaches used by AI and software security companies to address particular security controls (see sections 4.1.2 and 4.2.2).
-
Explore levels of interest and market demand in certain services (section 3).
-
Understand the costs of the services and tools that can be used to adhere to the Codes of Practice and AI security global standard (see section 4.3).
-
Identify how AI is being used in the provision of these cyber security services (see sections 4.1.3 and 4.2.3).
1.3 Methodology
1.3.1 Survey design and piloting
Related, but distinct, survey questionnaires were developed for software and AI security providers and each comprised quantitative and qualitative questions. These were designed jointly between Pye Tait Consulting and DSIT and were informed by scoping interviews with key stakeholders. The two questionnaires were very similar in design and tailored to reflect the content of the respective Codes of Practice and global standard. Questions explored providers’ current security service and tool offerings (aligning questions to the principles within the Code, but not mentioning the Code at this stage), before seeking awareness of the Code (prompted) and its envisaged influence and impact.
Once finalised, the surveys were hosted in SNAP XMP and initial piloting was undertaken with 12 software security providers between 18th and 20th November 2025. Following feedback, the questionnaire was refined and finalised. The surveys were live from 26th November 2025 to 30th January 2026.
1.3.2 Promotion and engagement
Extensive engagement was undertaken to contact all businesses identified in the 2026 cyber security sectoral analysis. This was supplemented with outreach to other firms identified as potentially being in-scope (obtained from freely available online sources and databases) and the research was open to any business that self-reported to be in-scope. Extensive promotion and outreach were conducted through email, telephone, social media, and sector press.
Some 1,906 software and 127 AI security providers were contacted to achieve a minimum of 200 software and 50 AI responses (i.e. around half the AI market identified via the 2026 cyber security sectoral analysis) through a mixture of telephone and online approaches, with participation on a voluntary basis. The firms contacted included providers identified through the 2026 cyber security sectoral analysis, as well as additional businesses provisionally identified through desk research – of the latter some, on contact, proved not to be in-scope.
The preceding 2026 cyber security sectoral analysis suggests the software and AI security populations are relatively small relative to the wider economy (1,141 and 111 businesses, respectively) meaning the surveys achieved indicative response rates of 18% and 45%, respectively.
Interviews were predominantly conducted with a Director of the business (e.g. Managing Directors, Commercial Directors, Directors of AI and Cyber Security), a member of the C-suite (including CEOs and CTOs) or with a senior Manager or Head of team within the developer or cyber security team.
Further details on the piloting, engagement, sampling and analysis approach are contained in the Appendix, along with known strengths and limitations.
1.3.3 Validation
The study was the first of its kind to undertake primary research with software security and AI security firms, building on the secondary market analyses previously undertaken. With businesses self-reporting security service provision and business demographics, all information gathered was cross-referenced against secondary sources including Companies House, businesses’ own websites, and the dataset from the preceding 2026 cyber security sectoral analysis, to fill any gaps in the dataset where possible and to update the 2026 cyber security sectoral analysis with first-hand information where appropriate. Further detail on the validation is available in the Appendix. The clean, final datasets were then taken forward for analysis.
1.3.4 Notes to the reader
Businesses that contributed to the research are referred to as ‘providers’ or ‘respondents’. Note that not all respondents answered all survey questions, and some questions were only asked to respondents who had answered previous questions in a certain way. Any numbers and percentages quoted relate to the particular survey question being discussed, not to the overall total number of research respondents.
Some charts and tables in this report may not add to 100% due to rounding.
Statistical testing was undertaken to identify differences by respondent sub-group (by size, region, and awareness of Code of Practice) – this was only conducted for the software security survey; it was not undertaken for AI security providers due to the small achieved sample, reflective of the limited population. However, significance testing has not been included in this report – as a first-of-its-kind study, the aim here is to provide an indication of the coverage of provision within a nascent sector, such that DSIT can understand gaps and determine which levers are required. Analytical outputs were provided to DSIT for information purposes.
Sub-group differences are discussed in the report where there is a notable variation between different categories of respondent. This is only reported for the software security survey – sub-group sample sizes for the AI security survey are too small to permit comparison.
1.4 Respondent profile
1.4.1 Company size
Just over half (51%) of surveyed software security providers are micro firms, directly employing fewer than 10 staff. Around one third (34%) are small with between 10 and 49 staff, with a minority medium (11%) or large (5%).
Responding AI security providers are roughly split between micro firms directly employing fewer than 10 staff (32%), small (28%), and large (30%) companies, with the remainder being medium (10%).
These sample spreads, while not statistically representative, are in alignment to a good extent with the size demographics found in the preceding 2026 cyber security sectoral analysis.
Table 1 Respondent profile by company size
| Size-band | Software counts | Software % | AI counts | AI % |
|---|---|---|---|---|
| Sole trader (0 employees) | 5 | 3% | 2 | 4% |
| Micro (1 to 9 employees) | 96 | 48% | 14 | 28% |
| Small (10 to 49 employees) | 68 | 34% | 14 | 28% |
| Medium (50 to 249 employees) | 21 | 11% | 5 | 10% |
| Large (250+ employees) | 10 | 5% | 15 | 30% |
| Total | 200 | 100% | 50 | 100% |
Source: Pye Tait Consulting 2026.
For analytical purposes, sole traders are included within the micro sub-group, and medium/large employers are merged.
Figure 1 Respondent profile by grouped company size
Base: 200 (software) and 50 (AI) businesses. Source: Pye Tait Consulting 2026.
1.4.2 Region
Surveyed providers are based or headquartered across the UK, with most responses from those based in London and the North West. Of the 12 respondents based outside the UK, 10 have headquarters in the USA and two elsewhere in Europe – these companies, while based overseas – have a Limited operation in the UK.
Table 2 Respondent profile by region
| Region | Software counts | Software % | AI counts | AI % |
|---|---|---|---|---|
| East of England | 8 | 4% | 2 | 4% |
| East Midlands | 10 | 5% | 3 | 6% |
| London | 58 | 29% | 19 | 38% |
| North East | 9 | 5% | 2 | 4% |
| North West | 25 | 13% | 4 | 8% |
| South East | 16 | 8% | 2 | 4% |
| South West | 17 | 9% | 2 | 4% |
| West Midlands | 10 | 5% | 3 | 6% |
| Yorkshire and the Humber | 24 | 12% | 3 | 6% |
| Northern Ireland | 6 | 3% | 2 | 4% |
| Scotland | 8 | 4% | - | 0% |
| Wales | 4 | 2% | 1 | 2% |
| Based outside of UK | 5 | 3% | 7 | 14% |
| Total | 200 | 100% | 50 | 100% |
Source: Pye Tait Consulting 2026.
For analytical purposes, regions are grouped into four categories.
- North England – comprising North East, North West, Yorkshire and the Humber
- Central England – comprising East of England, East Midlands, West Midlands
- South England – comprising London, South East, South West
- Devolved nations and beyond – comprising Northern Ireland, Scotland, Wales, Based outside of UK
Figure 2 Respondent profile by grouped region
Base: 200 (software) and 50 (AI) businesses. Source: Pye Tait Consulting 2026.
1.4.3 Software security provision
Of the 200 software security firms, around seven in ten (141, 71%) say they provide specialist software security (i.e. the firms have a clear specialisation in areas including AppSec testing and tooling, Secure Development lifecycle solutions, software vulnerability assessments, DevSecOps implementation, code and API security, and container and supply chain security solutions).
Meanwhile about three in five (125, 63%) self-report offering wider software security where firms offer support for software security as part of a broader offering, including the ability to provide AppSec capabilities as part of wider security services, code review, vulnerability assessment, and broader software security testing for clients.
These findings indicate that some businesses offer both specialist and wider software security provision.
For comparison, the preceding 2026 cyber security sectoral analysis had used the same definitions to split software providers into specialist and wider software providers, but did so on a mutually exclusive basis. Of the 1,141 software security firms identified, just 108 (9%) were specialist providers.
This mapping study would thus indicate that a much higher proportion of the market feel they are able to offer these specialist services – the self-reported figure is likely to be closer to the true proportion of the population offering specialist provision (compared to the 2026 cyber security sectoral analysis figure) as this is based on first-hand engagement with businesses.
1.5 Report structure
The remainder of this report is split into four sections.
- Section 2 outlines providers’ awareness, and perceived influence of, the Codes of Practice and AI security global standard.
- Section 3 discusses the interest and market demand for software and AI security services.
- Section 4 details the services and tools currently offered, including cost models and costs to clients.
- Section 5 draws together the findings in a Conclusion.
2. Awareness and influence of government initiatives
This section discusses software security and AI security providers’ awareness of the respective Codes of Practice and the AI security global standard, along with views on the anticipated influence and impact of these guidelines for providers on the services they offer.
2.1 Awareness of the Codes of Practice and AI security global standard
Over four in five responding organisations are aware of their respective Code of Practice and (for AI security market respondents) the AI security global standard. Further, around half say they hold detailed awareness of all aspects of these documents.
The vast majority of AI security providers (92%) are aware of the AI Security Code of Practice and 86% are aware of the global standard.
Meanwhile, 81% of software security providers are aware of the Software Security Code of Practice. Awareness is higher among companies based in England (ranging from 82% to 84% per grouped region) compared to those based in devolved nations and beyond (65%).
Overall, this reflects a high degree of market awareness and knowledge for all three documents.
Figure 3 Awareness of Codes of Practice and AI security global standard
Software security providers only asked about Software Security Code of Practice. AI security providers only asked about AI Security Code of Practice and AI security global standard. Base numbers shown in brackets. Source: Pye Tait Consulting 2026.
In addition, the documents are already being well-used. Nearly a fifth (19%) of software security providers say they refer to the Software Security Code of Practice during client engagement, with similar proportions of AI security providers noting likewise for the AI Security Code of Practice (16%) and the global standard (14%).
2.1.1 How businesses became aware
Businesses which were aware of their respective Code of Practice or the AI security global standard were asked from where they first heard about it. Most of those aware of the Software Security Code of Practice learned of this from NCSC (76%) and half had heard from DSIT, while two in five (38%) had heard from a professional or industry body. Fewer micro software security firms (68%) had heard of this Code of Practice from NCSC compared to small, or medium/large businesses (both 85%).
Just over half of those aware of the AI Security Code of Practice had heard of this from DSIT (56%) or from NCSC (53%), while around two in five of those aware of the AI security global standard had heard of this from these same two sources (41% and 44%, respectively).
Figure 4 Where respondents first heard about the Code of Practice and AI security global standard (among those aware)
Software security providers only asked in relation Software Security Code of Practice. AI security providers only asked in relation to AI Security Code of Practice and AI security global standard. Base numbers shown in brackets (multiple responses permitted). Source: Pye Tait Consulting 2026.
2.2 Influence and impact of the Codes of Practice and AI security global standard
Those providers aware of their respective Code of Practice or the AI security global standard were asked to rate the extent to which they expect it will influence the way they (or their developers) design, develop or market software or AI security tools and services, on a scale from 1 (no influence) to 10 (highly influential).
For both software and AI security providers, the average (mean) ratings are 6.0 and 6.1, respectively. The most common (modal) score is eight among software security providers, and five for AI security providers. Scores tend to be distributed slightly more towards the middle and upper end of the scale, indicating that businesses perceive these guidelines will have a moderate influence on the way they operate.
Medium/large software security firms anticipate a slightly greater influence (average 6.6) than micro companies (average 5.8) – explanation for scores and anticipated implications are outlined below.
Figure 5 Anticipated influence of Codes of Practice and AI security global standard on services and tools (among those aware)
1 = no influence. 10 = highly influential. Software security providers only asked about Software Security Code of Practice. AI security providers only asked about AI Security Code of Practice and AI security global standard. Base numbers shown in brackets. Source: Pye Tait Consulting 2026.
Respondents were asked to explain their answer, and scores were grouped into three bands to outline themes among different groups, with largely similar trends seen across both software security and AI security responses.
High influence (rating 8-10)
Many express a distinctly positive outlook and suggest the Codes of Practice have potential to raise industry standards, improve risk management, and enhance the quality of services delivered to customers. They describe their respective Code of Practice as an important reference point for shaping provision to align their services to emerging national guidance and are anticipated to strengthen market expectations and support consistency.
A strong influence or impact is anticipated where organisations already align with structured frameworks, established standards, or responsible governance practices. Many providers emphasise that the Codes of Practice are reinforcing behaviours that their services already facilitate, whether that is through NCSC best practice, international standards, or internal procedures that mirror the principles within the Codes of Practice. The Codes of Practice act less as a catalyst for change and more as a validation of existing approaches to service offerings.
Some influence (rating 4-7)
Most respondents offer a moderate rating, and typically perceive the Codes of Practice as helpful, useful, or a solid foundation, but not transformative. Some emphasise that influence will depend on internal structures, customer expectations, or the specific nature of the services they develop. Others call for stronger communication and awareness-building so that the Codes of Practice gain wider traction, suggesting that without clearer messaging, influence may remain modest.
Some were uncertain as to whether the Codes of Practice introduce new material or simply summarise existing guidance. Others point to potential ambiguity in the requirements of the Codes of Practice, noting that high-level language does not always provide the specificity needed for implementation.
A few providers, particularly in the AI space, highlight the fluid and fast-evolving nature of standards, explaining that customer needs and competitive or technical realities may outweigh the influence of broad guidance documents. At the same time, there is an appetite among some for more enforcement or clearer expectations, suggesting a belief that the Codes of Practice could become more influential with stronger backing.
Limited to no influence (rating 1-3)
Some respondents offering a lower score express a degree of scepticism toward the potential impact of the Codes of Practice. A few perceive little value, arguing that businesses already “have their own ways of working” or that the Codes of Practice do not go far enough to shape advanced security practices.
Others anticipate low influence due to external factors including a lack of customer demand, reliance on globally recognised standards, or adherence to existing frameworks such as OWASP[footnote 3] that already dictate their operations. Some feel that other guidance will take precedence, for example that international standards will take precedence where they have an overseas client base. A few AI security providers cite limited awareness or understanding of the Code of Practice as a reason for their lower score.
2.2.1 Standards, legislation and guidelines followed
Software security providers were asked what standards or best practice guidelines they refer to when creating or selling their services or tools. Most mentioned guidance from NCSC (56%) while just under half (48%) mentioned the Software Security Code of Practice – this was an unprompted response to a question that was asked before seeking explicit awareness of the Code of Practice, and thus confirms that there is good knowledge and spontaneous awareness of the Code of Practice.
Medium/large companies were often more likely to mention each best practice or set of guidelines than micro or small businesses, indicating that these bigger firms draw on a wider range of levers to inform their products and services.
Figure 6 Guidelines currently referred to when creating or selling software security services
Base: 198 software security providers (multiple responses permitted). Source: Pye Tait Consulting 2026.
Nine businesses mentioned other sources they refer to – two highlighted EU standards, and two mentioned OWASP best practice guidelines specifically, while individual firms referenced CREST, ENISA, Ministry of Defence, PCI Security Standards Council, and US regulations.
When AI security providers were asked a similar question, a similar pattern emerged. Most (58%) commonly referred to NCSC guidance or their own internal processes (54%). Around half – again unprompted and prior to explicit discussion – mentioned the AI Security Code of Practice (50%) or the AI security global standard (48%), again indicating good spontaneous awareness within the market of these guidelines.
Figure 7 Guidelines currently referred to when creating or selling AI security services
Base: 50 AI security providers (multiple responses permitted). Source: Pye Tait Consulting 2026.
Other sources referred to included specific references to OWASP best practice guidelines (five), ISO42001 (two), and US regulations (two).
3. Interest and market demand for AI and software security services
This section discusses customers’ interest in software security and AI security services from providers’ point of view, including perceptions of why clients are showing higher or lower interest in services linked to specific themes within the Codes of Practice.
3.1 Levels of customer interest
Thinking back over the past six to 12 months, providers were asked to rate, on a scale from 1 (very low) to 10 (very high), the extent to which current and potential clients have shown an interest in or expressed concern about services or practices relating to each of the overarching themes within the respective Codes of Practice (at this point, the Codes of Practice nor the AI security global standard had not been mentioned to the respondent).[footnote 4]
For software security, the most common (modal) score for each theme is seven, while the average (mean) ranges from 5.8 to 6.2. This indicates that there is reasonable, but not extensive, interest or concern from customers in relation to each strand.
Medium/large firms typically scored higher than small or micro firms, indicating that those businesses had seen – perhaps due to the scale of their operations – a slightly increased appetite from customers for these services.
Table 3 Client interest in services relating to Software Security Code of Practice themes
| Theme | Base | Mode | Mean |
|---|---|---|---|
| Secure design and development | 183 | 7 | 6.2 |
| Build environment security | 169 | 7 | 5.8 |
| Secure deployment and maintenance | 167 | 7 | 5.9 |
| Communication with customers | 152 | 7 | 5.8 |
Source: Pye Tait Consulting 2026.
For AI security, the most common (modal) score is either six or seven, while the average (mean) rating is slightly higher, ranging from 6.2 to 7.2. This demonstrates a slightly increased level of interest or concern from (potential) clients.
Table 4 Client interest in services relating to AI Security Code of Practice themes
| Theme | Base | Mode | Mean |
|---|---|---|---|
| Secure design | 47 | 7 | 6.9 |
| Secure development | 41 | 7 | 7.2 |
| Secure deployment, maintenance, and end of life | 37 | 6 | 6.2 |
Source: Pye Tait Consulting 2026.
3.2 Reasons for greater interest
Respondents scoring an eight or above to the preceding question(s), for each theme, were asked why current and potential clients were expressing greater interest in these services.
For software security providers, most commonly across all themes this was linked to customers’ desire to protect against data breaches, service disruptions, or supply chain attacks. Other reasons commonly highlighted, albeit to a lesser extent, included to meet regulatory requirements, financial risk reduction, or regular maintenance. This indicates that customers are primarily focused on safeguarding, but also have obligations to maintain.
Figure 8 Reasons for greater interest in software security services (asked of those rating 8 or above)
Base numbers shown in brackets (multiple responses permitted). Source: Pye Tait Consulting 2026.
Compared to micro and small software security providers, their medium/large counterparts more frequently report customers showing greater interest due to regulatory requirements, for procurement or contractual obligations, or to meet non-regulatory compliance requirements. This suggests that larger providers are seeing greater engagement from clients that are seeking more rigorous and process-driven security to meet onward obligations, whether to their own clients or to fulfil accreditation criteria or for other reasons.
Among AI security providers, reasons for greater interest largely mirror those of software security providers, with most commonly explaining that interest is driven by customers’ desire to protect against data breaches. Protection against service disruptions, or supply chain attacks, or to meet regulatory requirements were also mentioned frequently. This is displayed graphically, but responses should be interpreted with caution due to small sample sizes.
Figure 9 Reasons for greater interest in AI security services (asked of those rating 8 or above)
Base numbers shown in brackets (multiple responses permitted). Source: Pye Tait Consulting 2026.
Across both surveys, ‘other’ reasons for greater interest in security services most typically focused on the customers’ need to maintain the reputation of their business. Several discussed how some customers were becoming more conscious of the need to build in security from the outset to improve functionality and increase safety.
Secure design and secure development are areas over the last three years where we have seen significant growth in companies recruiting. Businesses are increasingly keen to get security in at inception rather than try and improve later down the line.
– Software security provider, Small, London
3.3 Reasons for lower interest
Where respondents scored a five or below to the preceding question(s) relating to client interest shown in such services, they were asked why (potential) clients were expressing lower interest in these services.
For software security providers, most commonly referenced how clients believe their existing security measures are sufficient, or that customers underestimate the likelihood or impact of a security breach – resulting in limited interest in software security provision. A lack of regulatory or contractual pressure, unclear value to the business and this aspect being a lower organisational priority are all secondary reasons cited for lower interest.
Figure 10 Reasons for lower interest in software security services (asked of those rating 5 or below)
Base numbers shown in brackets (multiple responses permitted). Source: Pye Tait Consulting 2026.
Among AI security providers, reasons for lower customer interest in services are most commonly linked to this not being an organisational priority for the client, businesses underestimating the likelihood or impact of a breach, or a perception that existing measures suffice. Findings here should be treated with caution due to low sample sizes. Responses should be treated with caution due to low sample sizes.
Figure 11 Reasons for lower interest in AI security services (asked of those rating 5 or below)
Base numbers shown in brackets (multiple responses permitted). Source: Pye Tait Consulting 2026.
In terms of other reasons for lower customer interest, most typically discussed how customers can be poorly informed on security matters and thus hold limited awareness or understanding of potential threats and the need for protection. Some mentioned that interest is sometimes more limited when it is driven by cycles of contractual obligations within customers’ businesses.
4. Services and tools currently offered
This section outlines the nature and extent of coverage of the most popular software security and AI security services provided, mapped against the principles within the respective Codes of Practice. It describes the types of services provided, and the extent to which AI and Machine Learning tools are used within these, before outlining the reasons why providers do not offer some services, and what might help drive uptake in future. A discussion of the cost models deployed for services, and estimated costs to customers, concludes this section.
4.1 Software security services currently offered
4.1.1 Extent current offering meets Software Security Code of Practice principles
Software security providers were asked about the extent to which the software security services and tools they provide help their customers meet certain requirements. These requirements were designed in the survey to align directly to the principles within the Software Security Code of Practice, although this was not brought to respondents’ attention so as to gauge existing practices without potentially introducing desirability bias.
From responses received, there appears to be generally good coverage across all principles within the Code of Practice. Coverage within the software security market is strongest for the theme of secure design and development, and slightly more limited (but still good) coverage for the theme of communication with customers.
On a per principle basis, there is strongest coverage in terms of the services provided which help customers to:
- manage risks linked to third party software components (with 82% saying this is a primary aim of a service they offer),
- follow secure by design and secure by default principles (79%),
- implement a vulnerability disclosure process (77%), and
- report vulnerabilities (77%).
Gaps in coverage are fairly limited (on average fewer than 10% say they do not offer services that align to each principle at all), but principles of note in this respect include:
- providing one year’s notice to customers of end-of-support (17% say this is not offered at all as part of a service they provide),
- control and log changes to the build environment (12%), and
- share information about incidents with customers (10%).
Businesses aware of the Code of Practice indicate that they offer services whose primary purpose aligns to the principle in question for most (but not all) principles to a slightly greater extent that those which are unaware of the Code of Practice. While not any indication of causality, this weak correlation may begin to suggest that the Code of Practice is more strongly associated with best practice behaviours.
Figure 12 Extent to which software security services provided help customers meet certain requirements[footnote 5]
Base numbers shown in brackets. Source: Pye Tait Consulting 2026.
4.1.2 Software security services commonly offered
For each Code of Practice theme, respondents were asked to share up to three of the most popular services they provide to customers.
Penetration testing is the most common service and especially under the theme of secure design and development. This offers a bedrock of assurance work, often complemented by smaller sets of more specialised offensive exercises such as red teaming or tool assisted testing. Threat modelling is discussed regularly (albeit to a lesser extent) signalling that a meaningful subset of organisations is now integrating structured early-stage architectural risk analysis. Alongside these, vulnerability assessment is also widely referenced, forming a common pillar within development workflows and post-deployment assurance. Training (discussed generally, with a couple highlighting specific training programmes such as NIST cyber guidance and penetration testing), cloud security, and patch management surface in smaller but still notable quantities, revealing the continued reliance on core cyber hygiene practices even within advanced development environments.
Beyond these central practices, providers highlighted a wide spectrum of supplementary or adjacent services. Some described secure development as part of wider IT or infrastructure offerings, blending activities such as configuration management, endpoint hardening, or general technical support. Others provide bespoke consultancy, governance advice, or integration work that indirectly supports secure development. The frequency and diversity of these service descriptions suggest that while some providers maintain sophisticated, tool-driven secure development portfolios, others adopt broader interpretations that merge security with general technology support.
Within build environment security, vulnerability assessment is commonly cited, reflecting its centrality to securing source code, dependencies, container configurations, and Continuous Integration and Continuous Delivery or Deployment (CI/CD) pipelines. Penetration testing is also referenced to an extent by providers who apply this to build pipelines and repositories. Training, architectural analysis, and operational controls such as auditing or firewalls are also mentioned, indicating varying interpretations of what constitutes build security. Several services mentioned fall outside of typical build focused services such as IT operations, cloud platform management, or governance support.
Under the theme of secure deployment and maintenance, many providers rely heavily on continuous vulnerability assessment to monitor deployed systems, while cloud security appears as a growing and highly relevant service in modern deployment models. Some supplement these with periodic penetration testing to validate post-release resilience. In smaller quantities, activities such as training, patch management, threat modelling, and risk assessment are mentioned and contribute to a more holistic deployment phase posture. Several again reference broader IT and advisory work, ranging from network configuration to general operational support, indicating that these providers view secure deployment as embedded in wider infrastructure and governance ecosystems.
Customer communication practices remain relatively simple across the sector. Email is mentioned by many as the principal communication channel, being the main means for sharing updates, alerts, and guidance. A smaller number use structured platforms such as compliance dashboards, ticketing systems, or automated alerting tools, reflecting a more mature communications infrastructure – these are more often found in larger providers while smaller ones lean more heavily on informal or consultancy-based communication, and only a handful reference portals or AI-driven communication tools.
Provider size also appears to influence service offering: smaller firms tend to focus more narrowly on foundational services like penetration testing and basic threat analysis, while larger organisations report increasingly diverse portfolios incorporating DevSecOps practices, cloud native security tooling, and broader governance and incident management capabilities. Larger organisations also tend to employ more specialised tools, for example associated with cloud platforms or commercial security ecosystems, while smaller firms focus predominantly on more fundamental techniques.
4.1.3 Use of AI/ML tools within software security services
Respondents were asked what (if any) AI or Machine Learning (ML) tools they use in the software security services they provide. Three in ten (30%) report using AppSec testing – a means of assessing software for vulnerabilities, with AI/ML being used within these tools to automate code scanning, enhance detection accuracy, and support secure development workflows. Just under a quarter use intelligent patch management (24%) or automated incident response or triage (23%). Around two in five (39%) do not use any AI or ML tools.
In terms of ‘other’ tools mentioned, five say they use the AI that is already embedded within the tools provided. Most listed specific individual AI tools – examples cited included (but were not limited to) Azure, Claude Code, Da Vinci, Grok, Protect A.
While roughly the same proportion of firms of all sizes do not use AI/ML tools, more medium/large firms use AppSec testing (43%) than small (26%) and micro (29%) businesses, and a similar pattern is visible for other tools such as automated incident response or triage. This suggests that larger businesses are further forward on their journey to implement AI or ML security features within their services.
Figure 13 AI/ML tools used in software security services offered
Base: 188 software security providers (multiple responses permitted). Source: Pye Tait Consulting 2026.
4.1.4 Reasons for not offering software security services
Where software security providers said they do not offer services relating to a particular principle, or only provide limited services, they were asked the reasons for this, per Code of Practice theme.
While there is some variation by theme, respondents most commonly explained that they offer limited or no service as they do not operate in that particular sector, that there is low demand from (potential) clients, that it is not an organisational priority, or that they feel that aspect does not require a specific service or tool.
Of ‘other’ responses, most say that they act as consultants and as such their role is more advisory to identify vulnerabilities and to guide customers on required protection.
Figure 14 Reasons for software security providers not offering certain services
Base numbers shown in brackets (multiple responses permitted per theme). Source: Pye Tait Consulting 2026.
4.1.5 What might help increase software security provision
When asked what non-financial support (if any) might help or encourage them to offer more software security services than they currently do, over half (55%) of software security providers said that legislative measures would drive this. Meanwhile, a third (33%) also said that substantially increased demand from clients would encourage this, and over a fifth (22%) also referenced available training for staff to expand their skillset.
Of ‘other’ reasons, several suggested that raising awareness of the need for software security among the wider business population would help to drive engagement and thus uptake of services. Additional individual suggestions include introducing certification for software security or linking penetration testing to insurance costs to help drive down premiums and incentivise uptake.
This would appear to suggest that businesses would be open to adapting and flexing their offering, depending on changes within the wider landscape, should circumstances dictate, to broaden their offering.
Figure 15 Factors that might encourage increased software security provision
Base: 193 software security providers (multiple responses permitted). Source: Pye Tait Consulting 2026.
4.2 AI security services currently offered
4.2.1 Extent current offering meets AI Security Code of Practice principles
AI security providers were asked about the extent to which the cyber security for AI services and tools they provide help their customers meet certain requirements. These requirements align directly to the principles within the AI Security Code of Practice and the AI security global standard, although this was not brought to respondents’ attention so as to gauge existing practices without potentially introducing desirability bias.
Similar to software security provision, albeit to a slightly lesser extent, there appears to be generally moderate to good coverage across all principles within the AI Security Code of Practice. Coverage within the AI security market is strongest for the themes of secure design and secure development, and slightly more limited (but not poor) coverage for the grouped themes of secure deployment, maintenance, and end of life.
Figure 16 Extent to which AI security services provided help customers meet certain requirements[footnote 6]
Base numbers shown in brackets. Source: Pye Tait Consulting 2026.
On a per principle basis, there is strongest coverage in terms of the services provided which help customers to:
- evaluate threats and manage risks to their AI system (with 78% saying this is a primary aim of a service they offer),
- conduct appropriate testing and evaluation (77%), and
- secure their infrastructure (72%).
Self-reported gaps are very limited under the theme of secure design but are slightly more extensive for the other themes. Principles of note where there is more limited coverage include:
- ensuring proper data and model disposal (27% say this is not offered at all as part of a service they provide),
- communication processes associated with end-users and affected entities (16%), and
- maintaining regular security updates, patches and mitigations (16%).
4.2.2 AI security services commonly offered
For each Code of Practice (or global standard) theme, respondents were asked to share up to three of the most popular services they provide to customers.
Penetration testing stands out as the most frequently mentioned activity, commonly appearing across all themes. In the AI context, this work often includes AI-specific variants such as adversarial testing, red team exercises targeting model behaviour, or evaluations of ML related attack surfaces. These activities represent an emerging discipline where organisations adapt traditional offensive testing to the unique properties of AI systems.
Around this core, other services appear in more modest but still meaningful quantities. Governance and training feature prominently under the theme of secure design, reflecting the importance of policy frameworks, responsible AI processes, and capability building in organisations working with AI systems. Architectural guidance, vulnerability assessment, and threat modelling are cited, albeit less frequently, and continue to shape secure design and secure development practices for AI systems. Additionally, a few referenced data protection and privacy work, indicating a growing appreciation of data-centric risks in AI.
Across the secure development theme, the mix of services remains limited. Penetration testing again dominates, while threat modelling, Microsoft based tooling, and various forms of risk assessment or code scanning appear occasionally. Providers seem to be developing (or experimenting with) bespoke AI-specific assurance methods, often referenced as custom evaluation frameworks, tailored risk analyses, or internal tooling rather than standardised industry practices. This suggests that secure AI development is still maturing and lacks the degree of methodological consensus found in software security.
Within the grouped theme of secure deployment, maintenance, and end of life, there is an even more fragmented picture. No single service is listed by more than a handful of providers, indicating a lack of widely adopted standards. Some mention adversarial testing, risk assessment, ML specific monitoring or evaluation practices, or traditional vulnerability scanning. Others contribute isolated controls such as patching, endpoint security, governance, or compliance related tooling. Many instead described bespoke or experimental monitoring approaches, general IT operational support, or responsible AI lifecycle management, highlighting the ongoing evolution of best practices for deployed AI systems.
Differences by organisation size are particularly pronounced in the AI domain. Larger providers tend to offer a broader range of AI-specific security services, spanning adversarial testing, architectural design, governance, and risk management. Smaller providers, however, typically report only one or two AI related capabilities (most often penetration testing) and offer limited evidence of advanced or specialised AI security services. This disparity underscores the emerging and uneven nature of AI security across the sector.
Overall, AI security remains a rapidly developing field, characterised by significant experimentation, uneven service availability, and a heavy reliance on adapted security practices. While traditional methods like penetration testing and threat modelling continue to anchor the ecosystem, many providers are still determining how best to secure the full AI lifecycle, particularly in deployment and end of life stages.
4.2.3 Use of AI/ML tools within AI security services
Respondents were asked what (if any) AI or ML tools they use in the AI security services they provide. Just under three in five (59%) report using AppSec testing, or AI-assisted code scanning or secure development tools. Around half use static code analysis, generative AI tools for security tasks (both 52%), or AI-enhanced endpoint protection (50%). ‘Other’ responses typically referenced specific tools, or outlined the purpose of such tools they might use (e.g. for identify security).
Figure 17 AI/ML tools used in AI security services offered
Base: 46 AI security providers (multiple responses permitted). Source: Pye Tait Consulting 2026.
4.2.4 Reasons for not offering AI security services
Where AI security providers said they do not offer services relating to a particular principle, or only provide limited services, they were asked the reasons for this, per Code of Practice (or global standard) theme.
While there is some variation by theme, respondents most commonly report that they offer limited or no service as it is not an organisational priority, they do not operate in that particular sector, or state that there is low demand from (potential) clients. No respondents cited the financial cost or time to the business as barriers (these are thus not shown on the chart).
A few mentioned ‘other’ reasons for not offering services – typically related to their role as consultants to identify vulnerabilities and advising on appropriate mitigations. A couple also reflected how AI is still a nascent sector and that their work is still in proof-of-concept phase.
Figure 18 Reasons for AI security providers not offering certain services
Base numbers shown in brackets (multiple responses permitted per theme). Source: Pye Tait Consulting 2026.
4.2.5 What might help increase AI security provision
When asked what non-financial support (if any) might help or encourage them to offer more AI security services than they currently do, seven in ten (71%) discussed how substantially increased demand from (potential) clients would drive this, while half (51%) say that legislative measures would have this effect.
Other individual suggestions for what might drive uptake included prescribing the Code of Practice during procurement (similar to ISO or Cyber Essentials requirements), or if cyber insurers were to demand certain requirements.
This would appear to suggest businesses are fairly flexible in their offering and would be open to adapting their provision should circumstances change, to broaden their market offering.
Figure 19 Factors that might encourage increased AI security provision
Base: 47 AI security providers (multiple responses permitted). Source: Pye Tait Consulting 2026.
4.3 Cost models and costs to clients
4.3.1 Cost models
Respondents were asked to describe the cost model they use with clients, in relation to the most popular services they offer.
Of all the software security services explicitly mentioned, around half deploy an annual subscription model (53%), while one in six services (17%) require a one-off payment. Pay-per-usage, and consultancy and training models are also each used for around 10% of services discussed. A similar pattern is seen across services when breaking this down by Code of Practice theme.
Figure 20 Cost models used by software security providers
Base number of services per theme shown in brackets. Source: Pye Tait Consulting 2026.
The most common cost model for AI security services, used for around a third of services discussed (35%), is an annual subscription. Just under one in five use a consulting and training model (19%). A similar trend is seen across services when examining this by Code of Practice (or global standard) theme.
Figure 21 Cost models used by AI security providers
Base number of services per theme shown in brackets. Source: Pye Tait Consulting 2026.
This picture, however, is somewhat simplistic and masks the more nuanced approach that providers take to costing their services, which is determined by a variety of factors as outlined in respondents’ contextual comments on cost models they deploy. Across both markets, providers describe a diverse mix of ‘other’ cost models, and the need for flexibility, as standard costing models would otherwise, not uncommonly, be inappropriate.
In sharing further context, providers commonly discuss the need for flexible or case-by-case pricing, and how this is essential due to differences in client size, bespoke requirements, project complexity, and scope. For software security, this flexibility often appears as hybrid models combining subscriptions with one-off fees, while for AI security it reflects highly tailored engagements where costs and models depend heavily on client-specific needs and the novelty or exploratory nature of AI security work.
Several software and AI security providers, when discussing their approach to pricing in general, mention their monthly or subscription-based cost models. These include recurring monthly fees, modular subscription tiers, security bundles, or managed-service packages. For software security, subscriptions appear across all Code of Practice themes, while AI security providers describe them as most useful for ongoing monitoring or support.
Several providers describe time-based or effort-based pricing, including the use of day rates, hourly rates, fixed-fee assessments, and project-based billing in their comments on cost models. These costing models are particularly common for discrete technical tasks, consultancy-driven work, or short-term interventions. Software respondents often associate these structures with assessments or targeted engagements, while for AI this time-based pricing suits technically complex or evolving AI security tasks where scope may be uncertain.
Some providers also reference mixed or combined costing models in their additional comments, where clients may choose between monthly, annual, one-off, or blended structures. These models offer adaptability and allow firms to cater to varied client preferences, organisational maturity levels, or differing assurance needs.
A small group of providers mention structured or productised packages. These include essential or advanced security packs, combined assessment/reporting bundles, or modular build-your-own offerings. This is most common for software security firms, but the idea of offering semi-standardised bundles is present in a few early-stage AI costing models.
A few AI security providers also say their approach to costing is still in development as their service(s) is still at proof-of-concept stage.
4.3.2 Cost to clients
Providers were asked to estimate the average annual cost for one customer for each of the most popular services they had mentioned. A ‘customer’ in this situation was defined as one client organisation, which may involve a system-wide licence and/or multiple users/licences within that one organisation.
Costs for software security services tend to sit towards the lower end of the available scale for estimation, with nearly two in five (39%) services reported to cost below £5,000 per year. A small minority (7%) of services attract an estimated annual cost of £50,000 or above. Meanwhile, one in five (22%) were unable to provide an estimate – all respondents were able to provide further comments, and the nuances of costing are discussed below.
Figure 22 Estimated average annual cost for one customer for each software security service
Base: 875 services across 187 software security providers. Source: Pye Tait Consulting 2026.
Estimated annual costs for AI security services tend to sit at the extremes of the scale. Over a third (35%) of services have zero associated cost for clients, while a slightly greater proportion (37%) attract an annual fee of £50,000 or above.
Figure 23 Estimated average annual cost for one customer for each AI security service
Base: 236 services across 48 AI security providers. Source: Pye Tait Consulting 2026.
4.3.3 Approach to costing across AI and software security markets
This hides what is, in reality, a much more nuanced approach to costing which varies substantially depending on scale, complexity, and bespoke client needs. While many providers offer an estimate for a typical customer, they also note that an ‘average’ customer does not exist and that they will use a wide range of different prices, thus reflecting significant variation in costing and signalling a lack of standardisation and the influence of bespoke work.
Generally, costs scale with the size of the organisation and/or environment. Many providers emphasise that costs vary according to user numbers, endpoints, devices, workloads, or enterprise footprint. This pattern is especially dominant across the themes of secure design, build security, secure development, and secure deployment, where per-user, per-device, or per-endpoint pricing models recur regularly.
Client requirements and project scope also have a substantial bearing on costs, where bespoke requirements, Statements of Work, and specific security needs form the central cost drivers. This is particularly common for AI security services, but for both markets firms repeatedly note that costs depend heavily on what the client is trying to achieve, the depth of work required, and the level of assurance or reporting expected.
Several highlight how technical complexity, breadth of testing, and number of applications or modules are major contributors to cost. The scope of penetration testing, complexity of build environments, and required certifications may also impact this.
The use of consultancy style pricing, typically day-rate or time and materials billing, is discussed by several providers. This is largely with reference to work relating to specialised governance, architecture reviews, ML Operations security, or lifecycle analysis work.
A small number of AI security providers mention being in the early stages of commercialising their services and as such unable to offer costing information, reflecting the relative nascency of AI security as a commercial discipline.
5. Conclusions
This survey has effectively mapped a significant proportion of the AI and software security services market. The report’s findings will help inform the development of future services and provide clarity to industry that security services are being offered to support uptake of the Codes of Practice and global standard. The report will also support DSIT with its ongoing work to create levers to support industry with their implementation of the documents. Below are set out a few key findings to highlight the state of the market.
-
There is a wide variety of services and tools already available or emerging to help developers and deployers meet the principles of the Codes of Practice and global standard. This suggests that the cyber security market is already responding to the market need for stronger AI and software security in supply chains.
-
These services and tools can cater to a wide variety of clients, with largely flexible pricing structures and a wide variety of costings to cater to different resource levels. This suggests that cost is less likely to be a significant barrier to entry for smaller organisations developing AI and/or software.
-
There is strong awareness of the Codes of Practice and global standard and the practices and processes they recommend in the cyber security market, but broader uptake through supply chains could be improved by targeting awareness-raising activities, incentives, and/or enforcement levers towards technology producers and their customers. This in turn would likely stimulate greater demand for security services and tools.
Appendix: Further methodological information
This appendix contains further detail on the piloting, engagement, sampling and analysis approach, along with known strengths and limitations.
Survey pilot and testing
The software security survey questionnaire was initially piloted using Computer Assisted Telephone Interviewing (CATI). For this stage, the questions were appended with a series of feedback questions to gather respondents’ views on the clarity of questions and response options, and ease of participation. In the main, respondents reported the survey to be clear and easy to understand.
However, on the back of feedback from initial interviews, some changes were made. These predominantly related the flow of the questionnaire to provide both respondents and interviewers with a more natural conversation. Pilot interviews also indicated the level of detail which respondents were happy to go into when discussing services and tools, without comprising interview length and participation and, on the basis of this feedback, the approach to those questions was confirmed.
Changes were implemented in the software survey, and equivalent updates were made to the draft AI survey, before the full fieldwork went live using a mixed-methods approach of CATI and online.
Contacts and promotion
Upon commission, the 2026 cyber security sectoral study was ongoing, and the companies identified at that point were shared with Pye Tait Consulting. Pye Tait Consulting contacted all those businesses (1,195 software and 85 AI security providers) to participate in the research through a CATI-led approach.
Pye Tait supplemented these contacts with details of potential software security and AI security providers obtained from freely available online sources and databases. Of additional contacts, a sizeable proportion were out of scope of the study. Contacts from different sources were merged and de-duplicated prior to engagement.
The research was promoted by DSIT in its cyber security newsletter. In addition, a letter of endorsement signed by a senior DSIT official was circulated to several industry bodies to raise awareness of the research, who were asked to promote the research among their member organisations. Further, DSIT drew on its network to help raise awareness of the research. Providers could either respond online or register interest in a call-back.
Several businesses were unavailable to participate at the time fieldwork was live or suitable individuals were unable to be reached directly. To maximise participation, companies were called back at different times and days of the week; web submission forms, emails, and social media were used to raise awareness; and appointments were offered out of hours as necessary. Participation was on a voluntary basis – no incentive was provided.
Despite the challenges of engagement, the full survey target was reached.
Sampling strategy
Sampling approach
Prior to this study, DSIT’s 2025 market analysis established an understanding of the size and shape of the software and AI security sector. As an emerging sector, AI and software security is hard to define using traditional Standard Industrial Classification (SIC) codes, and thus the 2025 market analysis was used as the sampling frame from which to derive a preliminary sampling approach.
This study stratified the population by sector and – for software only – service provision, region, and business size in line with the findings from DSIT’s 2025 market analysis study.That research identified 960 software and 66 AI security firms. The 2026 cyber security sectoral analysis (ongoing during this study) subsequently identified that the markets were expanding, and so this study sought to gather views from 200 and 50 of each, respectively.
For software security providers, 960 firms had initially been identified through the 2025 market analysis, including 93 specialist providers. Of the 200 total responses being targeted, a sub-target was to achieve at least 20 with specialist providers i.e. those with a clear specialisation in software security, compared to businesses with wider software security provision which offer support on this as part of a broader offering.
The small sample size for the AI security sector and the fact that a high response rate was being targeted meant that strict quotas were impractical, and instead quota achievement was sought on a best-efforts basis.
The sampling approach sought to achieve a representative sample to ensure that any future policy is grounded in a robust evidence base. Applying representative quotas based on the total known population of software security providers (960) generated the indicative sampling targets shown in the tables below.
Achieved sample
Completions were closely monitored during fieldwork to ensure a spread of responses (by size and region).
As a first of its kind study, a key priority for the research was to gather views from a substantial proportion of the population. Due to the small population and the limited fieldwork period, it was envisaged that software regional and size targets would be sought on a best-efforts basis, and that the fieldwork may have to take a pragmatic approach to ensure the overall targets of 200 software and 50 AI security providers could be achieved.
The tables below illustrate the target and actual samples achieved.
Table 5 Target and achieved software security survey samples by company size
| Size-band | Target sample | % of target sample | Achieved sample | Achieved/target % |
|---|---|---|---|---|
| Micro (0 to 9 employees) | 101 | 51% | 101 | 100% |
| Small (10 to 49 employees) | 49 | 24% | 68 | 139% |
| Medium (50 to 249 employees) | 34 | 17% | 21 | 62% |
| Large (250+ employees) | 16 | 8% | 10 | 63% |
| Total | 200 | 100% | 200 | 100% |
Source: Pye Tait Consulting 2026.
Table 6 Target and achieved software security survey samples by region
| Region | Target sample | % of target sample | Achieved sample | Achieved/target % |
|---|---|---|---|---|
| East of England | 14 | 7% | 8 | 57% |
| East Midlands | 6 | 3% | 10 | 167% |
| London | 79 | 40% | 58 | 73% |
| North East | 4 | 2% | 9 | 225% |
| North West | 16 | 8% | 25 | 156% |
| South East | 31 | 16% | 16 | 52% |
| South West | 15 | 8% | 17 | 113% |
| West Midlands | 12 | 6% | 10 | 83% |
| Yorkshire and the Humber | 9 | 5% | 24 | 267% |
| Northern Ireland | 3 | 2% | 6 | 200% |
| Scotland | 9 | 5% | 8 | 89% |
| Wales | 3 | 2% | 4 | 133% |
| Based outside of UK | 0 | 0% | 5 | - |
| Total | 200 | 100% | 200 | 100% |
Source: Pye Tait Consulting 2026.
The achieved sample indicates a strong skew towards micro and small companies. This aligns with the findings of the 2025 market analysis and is typical of the ‘normal’ structure of sector business populations.
The survey data were not weighted prior to analysis. To be able to employ weighting accurately, it is necessary to know the precise characteristics of the population. The preceding 2025 market analysis and 2026 cyber security sectoral analysis provide a good indication of the sector profile. However, given the rapidly expanding nature of the software and AI security sectors (as indicated by the year-on-year population growth), the decision was taken not to apply weighting.
Analysis
Following fieldwork close, all survey data were cleaned and validated. This involved checking for any blank, out-of-scope, or duplicate submissions (e.g. via online and CATI routes) and post-coding any responses as required. Open-ended questions were reviewed to redact any information which might identify individuals or organisations prior to sharing the datafile with DSIT.
The validation process involved reviewing all survey responses to identify anomalies, and then to verify business characteristics and costing information against client data and public sources (such as websites and Companies House). Details of services, costs and organisational details were cross-checked and all amendments logged.
Based on the achieved sample, cross-tabulations were reviewed and agreed with DSIT to ensure that sub-group sample cells were of sufficient size to provide meaningful onward analysis and comparison, i.e. that there was a large enough base. Any limitations and interpretations are flagged in the report to readers.
For the software security survey, a derived variable was created, based on the number of staff directly employed by each organisation, to segment firms into size categories.
- Micro (including sole traders and micro companies (0 to 9))
- Small (10 to 49)
- Medium/Large (50+)
A second derived variable was created to group software security respondents by region.
- North (North East, North West, Yorkshire and the Humber)
- Central (East of England, East Midlands, West Midlands)
- South (London, South East, South West)
- Devolved nations and beyond (Northern Ireland, Scotland, Wales, Based outside of the UK)
Finally, a derived variable was created for the software security survey to split respondents into two groups, depending on whether or not they were aware of the Software Security Code of Practice.
Statistical testing was applied, including z‑tests on percentages and t‑tests on means, to assess whether differences between groups were statistically significant. All comparisons were tested at the 95% confidence level to ensure that observed variations were robust and meaningful.
These analytical outputs were provided to DSIT, but have not been included in this report. As a first-of-its-kind study, the aim here is to provide an indication of the coverage of provision within a nascent sector, such that DSIT can understand gaps and determine which levers are required.
Strengths and limitations
While there have been various studies focusing wholly or in part on the software security and AI security sectors in recent years, these have largely been secondary, desk-based studies and lacking insight directly from the sector itself. For example, recent studies including the 2025 market analysis and 2026 cyber security sectoral analysis have provided approximate estimates for the profile of this emerging sector, and sector-specific issues have been subsumed within broader reports.
By contrast, this commission is a first-of-its-kind study in that it is the first to directly gather insight via primary research from software security and AI security providers, and to examine the nature and extent of coverage of service provision. Particular strengths of the study include the following.
- Gathering feedback from c.50% and c.20% of the total estimated populations of AI security and software security providers, respectively, means that findings are credible and grounded in substantial evidence.
- The inclusion of software security and AI security providers of all sizes, from all UK nations and English regions, including those with a significant global presence, means the study has captured the breadth of the market.
- A data collection approach predominantly conducted by telephone, supplemented with vital outreach and engagement through established networks, was key to ensuring that a sufficient sample size could be achieved.
- This study has, for the first time, provided insights into the level of awareness and understanding of the Codes of Practice (and AI security global standard) among providers – both spontaneous and prompted.
- A detailed view of the nature and extent of coverage of existing provision, along with current gaps, and indications of what might help drive increased service provision, has been obtained, which will help both sector awareness of coverage and gaps, and DSIT’s onward decision-making and levers to consider.
- The study has, for the first time, provided insight into the cost models and estimated costs associated with software security and AI security services.
- Subsequent validation post-survey acted to strengthen the quality and completeness of the data.
- This first wave of primary research has revealed that the sector does go beyond the businesses identified the preceding 2025 market analysis, and that the market may be larger than initially thought (and/or is growing). Further, the larger proportion of software security providers self-reporting they offer specialist provision demonstrates the potential limitations of the preceding, desk-based 2025 market analysis.
At the same time, while the survey aims to produce the most accurate and reliable data possible with the resources available, it should be acknowledged that there are inevitable limitations of the data, as with any survey project. The following might be considered the main limitations.
- A notable challenge is designing a methodology that accurately captures the financial cost of services for customers, given that the survey findings necessarily depend on self-reported costs from organisations. Cost is of course a sensitive topic for discussion and hence costing bands were used with a view to boost response volumes, but this dilutes the accuracy of data obtained. This is compounded by the fact that respondents very frequently highlighted the substantial range in costing to customers, which often varies on a case-by-case depending on various factors.
- This research predominantly focused on software security and AI security providers based or headquartered in the UK, with 12 of the 250 completions from overseas countries, all of which are based in the USA and Western Europe. There will be other providers in those and other countries who will have a substantial UK market presence. This research did engage with providers both based overseas and with substantial overseas presence to attempt to address this limitation.
- When asked about the extent to which the services offered by providers meet certain requirements, the requirements presented in statement form to respondents aligned directly to the principles within the respective Codes of Practice – however, these statements were topline summaries of the principles, and the Codes of Practice have a greater level of detail beneath this topline in the Code of Practice that respondents were not presented with. Without being presented with this additional information, it is possible that respondents may have not provided a fully considered response. However, this approach was necessary to ensure that all principles could be discussed, while not over-burdening respondents, to maximise engagement rates.
- The final three themes within the AI Security Code of Practice were grouped to manage respondent burden as there are only one or two principles under each theme. However, a consequence of this might be that respondents have answered in relation to one theme meaning views on one theme specifically are masked by this grouping.
- Software security and AI security providers may be inclined to give answers that reflect favourably on them in research with government clients or may be less inclined to take part because of the client (although there is no direct evidence of this here). The study made a concerted effort to overcome this in the administration of the survey by making it clear to respondents that their answers will be confidential and reported on anonymously.
A report prepared by:
Pye Tait Consulting
Registered in England, Company No: 04001365, VAT No: 755 8312 14
Postal and registered office address:
5 Merus Court, Meridian Business Park, Leicester, LE19 1RJ
Tel: 01423 509 433
email (enquiries related to this report): t.wilson@pyetait.com
email (general enquiries): info@pyetait.com
website: www.pyetait.com
Pye Tait Consulting is part of the EMB-Group.
Pye Tait Consulting is a member of:
-
The 2026 cyber security sectoral study was conducted in parallel to this research, and the report will be published shortly. ↩
-
The 2026 cyber security sectoral study was conducted in parallel to this research, and the report will be published shortly. ↩
-
The Open Web Application Security Project, an international non-profit organisation dedicated to web application security. ↩
-
It should be noted that the final three themes within the AI Security Code of Practice have been grouped to manage respondent burden as there are only one or two principles under each theme. ↩
-
These requirements are the topline statement summaries of the principles, and readers should note that there is a greater level of detail beneath this topline in the Code of Practice that respondents were not presented with. ↩
-
These requirements are the topline statement summaries of the principles, and readers should note that there is a greater level of detail beneath this topline in the Code of Practice that respondents were not presented with. ↩