Skip to main content
Lornets

Evidence note

Software Security Code of Practice: Assurance Principles and Claims

Government Guidance2026UK National Cyber Security Centre

What does it cover?

UK government software-assurance guidance decomposing software-security principles into claims that should be supported by appropriate evidence.

Key points

  1. 01The guidance uses assurance claims rather than treating high-level principles as self-evident.
  2. 02It states that claims should be well evidenced.
  3. 03Examples of supporting evidence include documentation, interviews and test results.
  4. 04It provides a practical UK example of claims, argument and evidence reasoning being applied to commercial software assurance.

Why it matters. Lornets interpretation.

Important technical conclusions should be traceable to the claims being assessed and the evidence that supports them. This is strongly aligned with the reasoning behind Lornets' Production Assurance Methodology.

This is the Lornets reading of the source, not a finding of the source itself.

What it does not establish

  1. 01NCSC does not endorse or validate Lornets.
  2. 02Lornets should describe its methodology as informed by established assurance principles rather than claiming formal NCSC alignment unless a specific mapping supports that statement.
  3. 03The guidance focuses on software security rather than the complete Lornets Framework.

Source

Organisation
UK National Cyber Security Centre
Evidence type
Government Guidance
Published
2026
Status
Current

View official guidance

Relevant Lornets framework areas

Framework domains

  • Security & Access Control
  • Delivery & Change Control
  • Reliability & Recoverability

Related evidence

Government Guidance

2022

NIST Secure Software Development Framework v1.1

National Institute of Standards and Technology, SP 800-218, SSDF v1.1

SSDF organises secure-development practices into a structured set of outcomes rather than prescribing one development methodology.

  • Security & Supply Chain
  • Software Quality & Maintainability

Current, revision underway

Read Evidence Note

Government Guidance

2026

Supplier Assurance Questions

UK National Cyber Security Centre

Supplier assurance can include governance, incident recovery, cloud configuration, privileged access, bespoke software security, data handling, testing and certification.

  • Enterprise Assurance
  • Security & Supply Chain
  • Reliability & Operations

Read Evidence Note

Source record

Published
2026
Last verified
2026-08-11
Source status
Current