Cyber Security
Cyber Security Glossary

Secure by Design

A UK government approach requiring cyber security to be built into digital services from the outset and evidenced throughout their life, rather than assessed once before go-live.

What it is
A set of ten mandatory principles and supporting activities
Applies to
UK central government departments and their arm’s-length bodies
Owned by
UK government (DSIT and the Government Security Group, with NCSC input)
Is it a certification?
No — there is no pass mark and no accreditation

Secure by Design is the UK government approach that requires cyber security to be considered from the very start of a digital or technology programme, and throughout its life, rather than checked once shortly before it goes live. It moves security from a late-stage gate to a continuous part of delivery.

The ten principles are mandatory for central government departments and their arm’s-length bodies delivering new or significantly changed digital services and technical infrastructure. The supporting activities around them are recommended good practice, and are expected to be tailored to the service, its criticality and its risk profile.

Crucially, Secure by Design is a set of principles and expected behaviours — not a certifiable standard. There is no accreditation to obtain, and a high self-assessment score measures confidence in your approach rather than proving that a service is secure.

The ten principles

The principles describe the outcomes delivery teams are expected to achieve. They are deliberately about behaviour and accountability rather than prescribing particular products or controls.

  1. Create responsibility for cyber security riskNamed individuals own cyber risk for the service, so decisions have an accountable owner rather than falling between delivery and security teams.
  2. Source secure technology productsSecurity expectations apply to what you buy as well as what you build, because bought-in components carry risk into the service.
  3. Adopt a risk-driven approachSecurity effort is proportionate to the actual risk the service carries, rather than applying the same controls uniformly regardless of consequence.
  4. Design usable security controlsControls are designed so the people using them can work effectively, because controls that obstruct delivery are routinely bypassed.
  5. Build in detect and respond securityThe service is designed on the assumption that something will eventually go wrong, with the logging and monitoring needed to see it and act.
  6. Design flexible architecturesArchitectures can adapt as threats and requirements change, so security improvements do not require rebuilding the service.
  7. Minimise the attack surfaceUnnecessary components, interfaces and privileges are removed, because every exposed element is another route in for an attacker.
  8. Defend in depthMultiple independent layers of control are used, so the failure of any single measure does not expose the whole service.
  9. Embed continuous assuranceConfidence in the service is maintained and re-evidenced over time, rather than captured once in a report that immediately begins to age.
  10. Make changes securelyChanges are made in a way that preserves the security of the service, so that ongoing delivery does not quietly erode it.

What it means in delivery

In practice, Secure by Design means security decisions are made alongside design, architecture and procurement decisions rather than after them. Threat modelling informs the architecture, security activities are planned into the delivery approach from the start, and the reasoning behind decisions is captured as the work happens.

Assurance is continuous. Teams maintain a live view of their security position as the service changes, supported by the official self-assessment, instead of producing a point-in-time report that is out of date the moment it is signed off.

Because the approach is applied at both organisational and service level, departments need governance and accountability arrangements in place, while individual delivery teams apply the principles to the service they are building.

Common misconceptions

The most frequent mistake is treating Secure by Design as a compliance exercise. It is not an accreditation, completing the self-assessment does not produce a pass, and no body issues a Secure by Design certificate.

It is also distinct from Secure by Default, which is narrower: that term describes a product shipping in its most secure configuration without the customer needing to harden it. A Secure by Design product should also be secure by default, but the two are not interchangeable.

Finally, a high confidence score is not evidence that a service is secure. It indicates that the team has followed the expected approach and can evidence its decisions.

Secure by Design, answered

Is Secure by Design mandatory?
The ten principles are mandatory for UK central government departments and their arm’s-length bodies delivering new or significantly changed digital services and technical infrastructure. Suppliers are not mandated directly, but follow the specific requirements set by their contracting department, and are increasingly asked to evidence how they support it.
Is there a Secure by Design certification?
No. It is a set of principles, not a certifiable standard. There is no accreditation body and no pass mark, so anyone offering "Secure by Design certification" is describing their own product rather than a recognised scheme.
What is the difference between Secure by Design and Secure by Default?
Secure by Design concerns how a service is designed, built and run across its whole life. Secure by Default is narrower and means a product arrives already in its most secure configuration, without the customer needing to change settings. They complement each other.
How does Secure by Design relate to GovAssure and the CAF?
They are related but separate. Secure by Design shapes how a service is delivered, whereas GovAssure is an assurance process assessing in-scope government systems against the NCSC Cyber Assessment Framework. Evidence created through Secure by Design can support a CAF assessment, but a Secure by Design self-assessment does not produce a GovAssure result.
Does a high confidence score mean the service is secure?
No. The confidence profile reflects how well the team has followed the approach and evidenced its decisions. It is a measure of confidence in the process, not proof of the security of the service itself.

Related terms

Authoritative sources

How we help

We help departments and delivery teams adopt Secure by Design in practice — establishing ownership, making risk-driven decisions, and building evidence that holds up as the service changes.