Cyber Security
UK Government Secure by Design

UK Government Secure by Design
Consultancy

Embed the ten Secure by Design principles throughout governance, digital delivery, architecture, risk management and continuous assurance. We help government organisations and delivery teams implement the UK Government Secure by Design approach across individual services and wider portfolios.

10 mandatory principlesCentral government & ALBs
Support at both levelsOrganisational & project
Security-clearedConsultants

What Secure by Design means in practice

Secure by Design is not a final-stage security review. It integrates cyber security into the delivery of digital services and technical infrastructure from the outset and throughout the service life cycle — so security is designed in, owned, and evidenced as the service evolves.

It changes where and how cyber security decisions are made: instead of relying on a security check shortly before go-live, it asks delivery teams to weigh cyber risk when shaping the business case, selecting technology, designing the service, procuring suppliers, building controls and managing operational change.

The approach is collaborative rather than security-owned. Senior responsible owners, service owners, product and delivery managers, architects, engineers, commercial teams and security professionals all contribute to the security position of the service. The objective is to ensure decisions are proportionate to risk, supported by evidence, and revisited as the service and threat landscape evolve.

What good looks like
Accountable cyber-risk ownership
Responsibility for cyber risk is created and owned, not left to chance.
Risk-driven design decisions
Security decisions are made deliberately and proportionate to real risk.
Evidenced security activities
The right activities happen — and are evidenced as the work is done.
Continuous review as services change
The position is re-assessed when the service or its risks change.

Who Secure by Design applies to

The policy applies at both organisational and service-delivery levels. Departments and arm’s-length bodies need an organisational approach that establishes accountability, governance and supporting processes, while individual delivery teams apply the principles and relevant activities to their services.

Suppliers are not automatically subject to the policy in the same way as departments, but they are often central to implementation. Contracting authorities may require suppliers to provide security evidence, participate in threat and risk activities, implement agreed controls, and support the maintenance of the service’s confidence profile.

Central government departments & ALBs

The ten principles are mandatory when delivering new or significantly changed digital services and technical infrastructure.

Delivery teams

Product, delivery, architecture, engineering, commercial and security teams share responsibility for implementation.

Government suppliers

Suppliers support the contracting authority's implementation through evidence, controls, risk information and technical activities.

The Ten Secure by Design Principles

The principles define the outcomes delivery teams must achieve. The supporting activities can be tailored to the organisation, service and risk profile.

01Create responsibility for cyber security risk
02Source secure technology products
03Adopt a risk-driven approach
04Design usable security controls
05Build in detect and respond security
06Design flexible architectures
07Minimise the attack surface
08Defend in depth
09Embed continuous assurance
10Make changes securely

How Secure by Design is implemented

Organisations should align Secure by Design activities to their own delivery methodology and the phases used by the official self-assessment (discovery, alpha, private beta and public beta or live). The illustrative lifecycle below shows how ownership, risk, controls, evidence and assurance continue from the business case into live operation.

Illustrative delivery lifecycle
1
Business case
Security implications recognised early
2
Design
Threats understood, controls designed
3
Build
Secure patterns and configuration
4
Test
Security testing and fixes
5
Release
Risk-balanced decision to go live
6
Operate
Monitor and re-assess on change
Five continuous threads|OwnershipRiskControlsEvidenceAssurance

Good implementation is continuous, proportionate and evidence-based — activities are tailored to the service’s risk and delivery stage, not applied as a fixed checklist.

Make Secure by Design repeatable across the organisation

Organisational adoption is more than asking individual projects to complete the self-assessment. Departments need to define how Secure by Design fits within existing governance, digital delivery, architecture, commercial, risk-management and assurance processes.

We help organisations determine which services are in scope, define decision rights and escalation routes, assign accountable roles, establish proportionate evidence expectations, and create a consistent route from identified gaps to owned remediation or risk decisions.

Where Secure by Design is being introduced across a portfolio, we also support transition planning, pilot projects, champion networks, reporting arrangements and the development of reusable guidance and templates — building a sustainable capability delivery teams can operate without permanent dependence on external consultants.

Governance & operating model

A Secure by Design operating model and decision rights that fit your existing delivery and assurance governance.

Accountable roles & RACI

Clear ownership across senior risk, service, delivery and security roles, so implementation is explicitly assigned.

Policy & process integration

Secure by Design embedded into business cases, governance gates, procurement, architecture review and definitions of done.

Champions & capability

A champion network and capability development so teams can sustain the approach themselves.

Portfolio reporting

A portfolio view of confidence profiles and gaps, surfacing systemic issues rather than dozens of separate trackers.

Transition & adoption planning

A phased plan to meet the required timescales, with preparation, adoption and operation support.

The result is a consistent organisational approach — rather than every project interpreting the policy independently.

Support individual services throughout delivery

At service level, we work alongside product, delivery, architecture, engineering, commercial and security teams to apply the principles in a way that matches the service’s criticality and risk profile.

Support can begin during discovery or the development of the business case, or it can be introduced later where a project needs to recover from gaps in ownership, risk analysis, architecture, supplier assurance or evidence. We help teams understand what activities are proportionate, produce or review the necessary artefacts, and turn findings into clear decisions and actions.

Our role is not to introduce a parallel security process. We integrate Secure by Design into the team’s existing delivery cadence, governance and tooling — so security work happens alongside service development, rather than immediately before an approval point.

Understand the security landscape

Establish the threats, legal and policy obligations, and risk appetite that shape proportionate decisions.

Threat & risk assessment

Practical threat modelling (STRIDE, attack trees) and security risk assessment grounded in real impact.

Architecture & control design

Proportionate controls connected to the architecture, from identity to data protection and defence in depth.

Supplier & technology assurance

Assess third-party product and supplier risk, and set the security requirements that carry into contracts.

Evidence & decision management

Capture evidence, risk acceptances and decisions in place as the work happens, mapped to the principles.

Continuous review through change

Re-assess as the service changes so the confidence profile reflects reality, not just launch day.

Self-assessment, evidence & confidence profile

The official self-assessment should be maintained as part of normal delivery rather than completed retrospectively. Responses should reflect the current state of the service and be supported by evidence that is relevant, current and proportionate to the question being answered.

We help teams interpret the assessment questions, identify suitable evidence, and distinguish between an activity being started, completed or demonstrated effectively. Where responses produce low or medium confidence, we help translate the underlying gaps into actions with named owners, target dates and appropriate governance oversight.

The confidence profile is a useful indicator of delivery maturity, but it must remain connected to the risks, controls, decisions and evidence behind the answers — and be reviewed whenever the service architecture, supplier arrangements, threat landscape, operating model or risk position changes.

1

Assess

Complete the official questions for the relevant delivery phase.

2

Evidence

Link responses to risks, decisions, threat models, controls, tests and supplier evidence.

3

Act

Turn low and medium confidence into owned actions, and review the assessment when the service changes.

Low
Significant activities or evidence remain incomplete.
Medium
Implementation is progressing, but material gaps remain.
High
The approach is being followed with sufficient supporting evidence.

A high confidence profile demonstrates that the approach is being followed. It does not, by itself, prove that the service is secure — and it is not a risk register or a risk treatment plan.

From a tracker to a managed assurance workflow

E2ERisk provides an optional workflow and evidence layer around the official Secure by Design approach. It lets organisations assign questions and actions to named owners, link supporting evidence directly to assessment responses, record decisions and approvals, and maintain a history of changes as the service evolves.

At portfolio level, it provides visibility of confidence profiles, overdue activities, recurring gaps and dependencies across multiple services — helping you tell where an issue is isolated to one project, and where it points to a broader capability, supplier or governance weakness.

The platform does not introduce a replacement set of principles or an alternative confidence calculation. It helps you operate the official approach more consistently, with stronger traceability.

File-based implementation at scale
Records activity at a point in time
Can drift away from live evidence
Gaps are often found late
Limited portfolio visibility
Managed assurance workflow
Roles and owners are defined
Evidence is linked to decisions and controls
Gaps are surfaced earlier
Re-assessed when the service changes
Supports portfolio oversight

The goal is not to replace the tracker — it is to make it meaningful. Explore the E2ERisk Secure by Design module →

Secure by Design, GovAssure & the CAF

Related, but distinct. Evidence developed through Secure by Design may support GovAssure and relevant CAF outcomes — the processes are separate.

Secure by Design
A delivery approach
Applied throughout service delivery
Produces a confidence profile
GovAssure
A government assurance process
Applied to in-scope critical systems
Produces an assessed assurance position
NCSC CAF
A cyber security assessment framework
Defines outcomes and indicators
Provides the assessment structure

Secure by Design helps delivery teams incorporate effective security practices while a service is being designed, built and operated. GovAssure is a separate assurance process for assessing in-scope critical government systems against the NCSC Cyber Assessment Framework, and the CAF defines the security and resilience outcomes and indicators of good practice.

Secure by Design provides an example controls taxonomy based on CAF 4.0, which can help teams align service controls and evidence with relevant CAF outcomes. That alignment reduces duplication and improves evidence reuse — but it does not make the processes interchangeable. A high Secure by Design confidence profile is not a GovAssure result, and completing the self-assessment does not constitute a complete CAF assessment.

How you can engage us

Three primary ways to start, plus flexible options where you need them.

Readiness & adoption

For organisations establishing Secure by Design across a portfolio.

You receive
Current-state assessment
Applicability & scope model
Operating model & RACI
Adoption roadmap
Governance integration & reporting model

Project implementation

For delivery teams applying the principles to a live service.

You receive
Supported self-assessment
Activity & evidence plan
Threat & risk outputs
Control recommendations
Gap & action register + confidence-profile review

Independent health check

For projects needing a review before internal assurance.

You receive
Evidence-quality review
Challenge of assessment responses
Confidence-profile validation
Unresolved-risk findings
Prioritised remediation report

Embedded specialist

Ongoing architecture, risk and delivery-team support through the service life cycle.

Tailored advisory

Focused advisory support shaped around a specific decision, gap or assurance milestone.

Why E2E Security Consulting

Secure by Design requires more than familiarity with a checklist. It requires practitioners who understand government delivery, security architecture, cyber-risk ownership, organisational assurance and the practical constraints faced by multidisciplinary teams.

Our consultants bring experience from UK government and regulated environments, where security decisions must be technically sound, proportionate and defensible to senior risk owners and independent assurance. We support both sides of the problem — establishing the organisational model, and working directly with delivery teams to apply it to real services.

Security-cleared consultants
Experienced practitioners cleared to work on sensitive government services.
Government & regulated-sector experience
Delivery within GDS delivery methods, departmental assurance and cross-government governance requirements.
Integrated architecture, risk & assurance
One team connecting technical design, cyber-risk decisions, evidence and independent assurance expectations.
Support at both adoption levels
From establishing the organisational model to embedding directly within an individual service team.
E2ERisk workflow platform
A supporting platform available where a portfolio needs more than a spreadsheet.
Cyber Essentials Plus certified
We hold Cyber Essentials and Cyber Essentials Plus ourselves.

Secure by Design, answered

Is “NCSC Secure by Design” the official name?
No. “NCSC Secure by Design” is a common search term, but the ten-principle framework is officially the UK Government Secure by Design approach — a cross-government policy, not an NCSC-owned standard. It was developed by the Department for Science, Innovation and Technology (DSIT) and a cross-government working group, with the Government Security Group (GSG), the National Cyber Security Centre (NCSC) and industry. NCSC contributed expertise and publishes complementary secure design guidance, and its Cyber Assessment Framework underpins the Secure by Design example controls taxonomy.
Is Secure by Design mandatory?
The ten principles are mandatory, under the government Cyber Security Standard, for all central government departments and their arm's-length bodies (ALBs) delivering new or significantly changed digital services and technical infrastructure. The supporting activities are recommended good practice and can be tailored. Suppliers follow the specific requirements set by their contracting department.
What is the official self-assessment?
The self-assessment is the official tracker — a Microsoft Excel or Google Sheets template, kept as a managed asset — that delivery teams complete as evidence they are meeting the principles. It aligns questions to the principles across the delivery phases, is maintained throughout delivery, highlights activities that need attention, and supports continuous assurance discussions. It does not replace an organisation's existing security assurance.
What is a confidence profile?
The self-assessment produces a low, medium or high confidence profile for each delivery phase, using a weighted algorithm — so a service can reach high confidence without every answer being “Yes”. A high confidence profile shows the team is following the approach; it does not, on its own, mean the service is secure, and it is not a risk register, a risk treatment plan or a risk management report.
Does Secure by Design replace security assurance?
No. Government guidance is explicit that Secure by Design is not itself an assurance process. Its self-assessment is designed to facilitate lightweight, continuous assurance discussions within delivery, and complements — rather than replaces — an organisation's existing security assurance and risk-management arrangements.
How does it relate to GovAssure and the CAF?
Secure by Design is a delivery approach; GovAssure is a separate government assurance process that assesses in-scope critical systems against the NCSC Cyber Assessment Framework (CAF). Secure by Design provides an example controls taxonomy based on CAF 4.0, so evidence can be aligned to relevant CAF outcomes — but completing Secure by Design does not, on its own, produce a GovAssure assessment or a complete CAF assessment.

Embed Secure by Design into delivery — not just documentation

Whether you are standing up organisational adoption across a portfolio or supporting a single delivery team, we help you meet the ten principles, evidence the official self-assessment, and build continuous assurance into how you already govern and manage risk.