Implementing Secure by Design
All central government departments and arm's length bodies (ALBs) must incorporate effective security practices and meet the Secure by Design policy when delivering and building digital services and technical infrastructure.
This is particularly important for new services and those undergoing significant changes. The Digital Assurance Playbook, which replaced the digital and technology spend control approval process on 1 April 2026, says:
You should check that initiatives are following your organisation’s Secure by Design approach.
Initiatives should be engaging early with your organisation’s security professionals and factoring in appropriate cyber security considerations as early as practicable.
Affected organisations have been separated into two groups which determine their implementation timescales:
- Group 1 – ministerial departments, ALBs managing government Critical National Infrastructure (CNI) and organisations managing priority government services.
- Group 2 – all remaining ALBs and other central government organisations.
Implementation schedule
The cross-government Secure by Design team in the Government Cyber Unit (GCU) is working with organisations to discuss their specific implementation schedule and establish what assistance may be required.
Organisations are encouraged to implement Secure by Design as soon as possible.
The implementation plan was developed in collaboration with security and digital leaders, including the chief digital information officers (CDIOs) who are accountable for the adoption of Secure by Design in their organisations.
Secure by Design is a journey for continuous improvement, not a compliance process. It is essential for government organisations to begin the transition early and make positive changes towards achieving the required cyber security maturity.
Guide to adopting Secure by Design
We've developed a detailed walkthrough for stakeholders in public sector organisations involved in the adoption of Secure by Design. It outlines key phases and milestones that should be considered at each stage.
Download a Secure by Design preparation checklist
Use this template to assess whether your organisation is currently meeting the requirements of Secure by Design and identify where improvements are needed.
Guidance for commercial teams
Commercial and procurement teams play a vital role in ensuring that cyber security is embedded into government digital and technology procurements from the outset. Secure by Design should be a core consideration throughout the procurement life cycle, from defining requirements and evaluating suppliers to contract management and service delivery.
To help commercial and procurement teams achieve this, the Cabinet Office has published a set of modular security schedules with Secure by Design requirements. These clearly define security expectations in tender documents, where applicable.
Secure by Design requirements are incorporated into the 3 following modular security schedules:
- supplier-led schedules
- buyer-led schedules
- developer schedules
You’ll find a Secure by Design evaluation table at the end of these security schedules. The supplier must complete this table if the buyer requires them to meet Secure by Design principles.
This table helps standardise Secure by Design requirements across contracts and ensures suppliers understand their security obligations. Suppliers can use the table to cross reference how they meet the Secure by Design principles within their security management plans.
It’s the responsibility of the buyer to:
- make sure the contract is assessed against the scope and requirements of Secure by Design
- determine whether Secure by Design requirements should be included in the contract
Principle 8 of the AI Playbook for the UK Government advises working with commercial colleagues early on for projects which involve AI.
By embedding Secure by Design principles in procurement, commercial teams help ensure that cyber security is not just an afterthought but an integral part of government digital services and technology investments.