Skip to main content

Evidence note

Software Security Code of Practice: Assurance Principles and Claims

Government Guidance2026UK National Cyber Security Centre

What does it cover?

UK government software-assurance guidance decomposing software-security principles into claims that should be supported by appropriate evidence.

Key points

  1. 1The guidance uses assurance claims rather than treating high-level principles as self-evident.
  2. 2It states that claims should be well evidenced.
  3. 3Examples of supporting evidence include documentation, interviews and test results.
  4. 4It provides a practical UK example of claims, argument and evidence reasoning being applied to commercial software assurance.

Why it matters. Lornets interpretation.

Important technical conclusions should be traceable to the claims being assessed and the evidence that supports them. This is strongly aligned with the reasoning behind Lornets' Production Assurance Methodology.

This is the Lornets reading of the source, not a finding of the source itself.

What it does not establish

  1. 1NCSC does not endorse or validate Lornets.
  2. 2Lornets should describe its methodology as informed by established assurance principles rather than claiming formal NCSC alignment unless a specific mapping supports that statement.
  3. 3The guidance focuses on software security rather than the complete Lornets Framework.

Source

Organisation
UK National Cyber Security Centre
Evidence type
Government Guidance
Published
2026
Status
Current

View official guidance

Relevant Lornets framework areas

Framework domains

  • Security & Access Control
  • Delivery & Change Control
  • Reliability & Recoverability

Related evidence

Last verified 2026-08-11

2022

Technical Standard

ISO/IEC/IEEE 15026-2:2022 - Assurance Case

Assurance cases provide a structured way of connecting technical claims, arguments, evidence and assumptions.

ISO / IEC / IEEE

  • Software Quality & Maintainability
  • Reliability & Operations

2022

Government Guidance

NIST Secure Software Development Framework v1.1

SSDF organises secure-development practices into a structured set of outcomes rather than prescribing one development methodology.

Current, revision underway

National Institute of Standards and Technology, SP 800-218, SSDF v1.1

  • Security & Supply Chain
  • Software Quality & Maintainability

2026

Government Guidance

Supplier Assurance Questions

Supplier assurance can include governance, incident recovery, cloud configuration, privileged access, bespoke software security, data handling, testing and certification.

UK National Cyber Security Centre

  • Enterprise Assurance
  • Security & Supply Chain