Glossary · Related frameworks

Cyber Governance Code of Practice

Definition

The Cyber Governance Code of Practice is a voluntary code published by DSIT and the NCSC on 8 April 2025 that sets out the actions boards and directors should take to govern cyber risk. It has five principles: risk management, strategy, people, incident planning and response, and assurance and oversight. It is separate from the Bill.

What does the Cyber Governance Code ask boards to do?

The code sets out the governance actions directors are responsible for, grouped under five principles. It is aimed mainly at medium and large organisations, and is supported by NCSC Cyber Governance Training and the Cyber Security Toolkit for Boards. It does not prescribe technical controls; it asks boards to own the risk and check that management is handling it.

  • Risk management: understand critical assets and set risk appetite.
  • Strategy: align cyber strategy with business strategy and fund it.
  • People: build a cyber security culture and board-level skills.
  • Incident planning and response: make sure a tested plan exists.
  • Assurance and oversight: get regular, independent assurance.

How does it help with the Cyber Security and Resilience Bill?

The Bill places duties on the organisation, not individual directors, but those duties need board sponsorship. Registration with the Information Commission, security duties and incident reporting all require budget and clear decision rights.

Following the code gives boards a documented way to show they understand and oversee cyber risk. That will matter if a regulator investigates after an incident, even though the code itself carries no legal weight under the Bill. Its assurance principle also fits well with the Cyber Assessment Framework, whose governance outcomes regulators already assess.

Common misconceptions

Myth: The Cyber Governance Code is the code of practice created by the Bill.

Reality: It is not. The Bill’s clause 36 code is a separate statutory document, subject to Parliamentary procedure, about compliance measures rather than board governance.

Where it appears in the Bill

  • Clause 36Statutory code of practice for regulated persons, distinct from the voluntary governance code.
  • Clause 37Draft statutory code must be laid before Parliament; either House can reject it within 40 days.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Is the Cyber Governance Code of Practice mandatory?

No. DSIT and the NCSC published it on 8 April 2025 as voluntary guidance for boards and directors. The Cyber Security and Resilience Bill does not make it binding. It is still a useful way for boards of regulated organisations to show they oversee cyber risk, particularly if a regulator later asks how decisions were made.

Does the Cyber Security and Resilience Bill make directors personally liable?

Not as currently drafted. Duties and penalties fall on the regulated organisation. Peers raised executive liability during Lords scrutiny, but it is not in HL Bill 32. Report Stage has not yet been scheduled, so the position could still change before Royal Assent, expected between late 2026 and spring 2027.

Which organisations should use the code?

Any organisation whose board is responsible for digital risk, whether or not it is regulated. It is aimed at medium and large organisations and is especially relevant to boards of operators of essential services, managed service providers and data centres, which will face new statutory duties once the Bill is commenced.

Related guidance

Official sources

More in Related frameworks

Full glossary