We use some essential cookies to make this website work.
We’d like to set additional cookies to understand how you use GOV.UK, remember your settings and improve government services.
We also use cookies set by other sites to help us deliver content from their services.
You have accepted additional cookies. You can change your cookie settings at any time.
You have rejected additional cookies. You can change your cookie settings at any time.
Departments, agencies and public bodies
News stories, speeches, letters and notices
Detailed guidance, regulations and rules
Reports, analysis and official statistics
Consultations and strategy
Data, Freedom of Information releases and corporate reports
Find out the benefits of getting and using a .gov.uk domain
The supplier assurance questionnaire (SAQ) allows suppliers to demonstrate compliance with the controls required by a contract and its Cyber Risk Profile.
Requirements for organisations wanting to provide or consume digital identity products and services.
Guidance on how to report a security vulnerability on any Ministry of Defence service or system, such as the websites of the Royal Air Force, British Army and Royal Navy.
This note explains how to use the Cyber Essentials scheme, which aims to reduce cyber security risk in government supply chains.
This publication explores the fundamentals, threats, operations and functions of cyber.
This guidance, also known as Good Practice Guide (GPG) 44, will help you choose an authenticator that will give you the level of protection that’s most suitable for users accessing your service.
Detail on the first globally-applicable industry standard on internet-connected consumer devices.
The Government's Code of Practice for Consumer Internet of Things (IoT) Security for manufacturers, with guidance for consumers on smart devices at home.
Guidance for organisations certified against the UK digital identity and attributes trust framework as an 'attribute service provider'.
Lessons learnt from the 'Secure by Design' approach adopted by MOD which ensures security is designed into any project delivering capabilities or services.
The 1.0 version of the supplementary code for digital right to work checks
This treaty was presented to Parliament in December 2025.
This guidance gives information to Competent Authorities established under the Network and Information Systems Regulations of 2018 (NIS Regulations).
First published during the 2016 to 2019 May Conservative government
Guidance on how to report a security vulnerability on a Department for Work and Pensions (DWP) system.
Guidance on how to report a security vulnerability on any Foreign, Commonwealth, and Development Office service or system.
A guide for organisations interested in being an 'attribute service provider' certified against the UK digital identity and attributes trust framework.
A specification to help DVS and relying parties organise and exchange information in a consistent way to enable interoperability
Guidance on creating, binding, scoring and sharing attributes for organisations certified against the UK digital verification services trust framework as an attribute service provider, or interested in understanding more abo…
A simple guide to understanding and describing the trustworthiness of autonomous systems and associated artificial intelligence (AI) algorithms.
Do not include personal or financial information like your National Insurance number or credit card details.
To help us improve GOV.UK, we’d like to know more about your visit today. Please fill in this survey (opens in a new tab and requires JavaScript).