Skip to content
David Despres AI

Service · Security

Software Security Code of Practice support

Turn the UK Software Security Code of Practice into a practical improvement plan for the software your business develops, maintains or buys.

For software teams and businesses working with suppliers

The government’s voluntary code sets out 14 principles for software vendors. I help you establish what is relevant to your work, review current practices and organise the next steps. Businesses buying software can use the discussion to prepare clearer questions for suppliers.

Make responsibilities and gaps visible

A scoped review can examine how changes are approved, access to development tools is managed, dependencies are maintained, releases are checked and security issues are reported. We map available evidence to the official code and identify where further investigation is needed.

The aim is a usable action plan, with named owners and priorities, rather than a claim that a checklist proves a product is secure.

A practical improvement backlog

  • A defined software or supplier-review scope.
  • A record of current practices and supporting documents.
  • A prioritised gap and action register.
  • Agreed improvements to documentation and working processes.
  • A handover with ownership and review dates.

Advisory support, with specialist work agreed separately

This service is support with a voluntary code, not a government-issued certificate or an assertion of government approval. Penetration testing, formal assurance and legal advice are not included in a process review; any specialist requirement is identified separately.

If your immediate goal is business IT certification, see Cyber Essentials preparation. The two services address different needs.

Next step

Discuss your readiness

Explain your goal, the systems involved and your timescale. We will agree the review and the next steps.