
A UK government approach requiring cyber security to be built into digital services from the outset and evidenced throughout their life, rather than assessed once before go-live.
Secure by Design is the UK government approach that requires cyber security to be considered from the very start of a digital or technology programme, and throughout its life, rather than checked once shortly before it goes live. It moves security from a late-stage gate to a continuous part of delivery.
The ten principles are mandatory for central government departments and their arm’s-length bodies delivering new or significantly changed digital services and technical infrastructure. The supporting activities around them are recommended good practice, and are expected to be tailored to the service, its criticality and its risk profile.
Crucially, Secure by Design is a set of principles and expected behaviours — not a certifiable standard. There is no accreditation to obtain, and a high self-assessment score measures confidence in your approach rather than proving that a service is secure.
The principles describe the outcomes delivery teams are expected to achieve. They are deliberately about behaviour and accountability rather than prescribing particular products or controls.
In practice, Secure by Design means security decisions are made alongside design, architecture and procurement decisions rather than after them. Threat modelling informs the architecture, security activities are planned into the delivery approach from the start, and the reasoning behind decisions is captured as the work happens.
Assurance is continuous. Teams maintain a live view of their security position as the service changes, supported by the official self-assessment, instead of producing a point-in-time report that is out of date the moment it is signed off.
Because the approach is applied at both organisational and service level, departments need governance and accountability arrangements in place, while individual delivery teams apply the principles to the service they are building.
The most frequent mistake is treating Secure by Design as a compliance exercise. It is not an accreditation, completing the self-assessment does not produce a pass, and no body issues a Secure by Design certificate.
It is also distinct from Secure by Default, which is narrower: that term describes a product shipping in its most secure configuration without the customer needing to harden it. A Secure by Design product should also be secure by default, but the two are not interchangeable.
Finally, a high confidence score is not evidence that a service is secure. It indicates that the team has followed the expected approach and can evidence its decisions.