UKCSC Launches Public Consultation on Supply Chain Security Standard
The Council opens a 60-day public comment period on the draft UKCSC-SC-003 framework, welcoming input from all stakeholders.
Read More →The UKCSC develops, maintains, and promotes cybersecurity standards for organisations of all sizes — from SMEs to enterprises.
UKCSC is a newly established, independent, privately operated standards body and is not affiliated with, endorsed by, or part of HM Government, GCHQ, or the National Cyber Security Centre (NCSC). Membership and certification figures will be published here as they are verified.
We exist to define clear, practical, and rigorously assessed cybersecurity standards that any UK organisation can adopt.
We develop pragmatic cybersecurity standards through open consultation, drawing on expertise from industry, academia, and the wider stakeholder community.
View Standards →Our certification schemes validate that organisations and professionals meet the UKCSC's defined security benchmarks.
Explore Certification →Join a growing network of security-conscious organisations. Shape the standards that affect your industry and access exclusive resources.
Join Us →We publish research, threat landscapes, and practical guidance to help organisations understand and manage cyber risk.
Browse Resources →We engage transparently with policy discussions — responding to consultations and contributing practical expertise on cyber legislation.
About Our Work →From annual conferences to regional workshops, our events connect practitioners, policymakers, and organisations across the UK.
See Events →The UKCSC works with industry, academia, and policymakers to develop practical, evidence-based standards. Our governance is transparent and our certifications are vendor-neutral.
Supported by member organisations and certification programmes, with professional financial oversight.
Our standards are built on practical expertise and threat intelligence, not commercial lobbying.
Draft standards are published publicly for a minimum 60-day comment period.
A baseline cybersecurity standard designed specifically for small and medium enterprises, covering the five fundamental controls.
A structured framework for detecting, containing, and recovering from cybersecurity incidents across public and private sector organisations.
Addressing third-party risk with minimum vendor security requirements, audit procedures, and contractual clauses — currently in public consultation.
The Council opens a 60-day public comment period on the draft UKCSC-SC-003 framework, welcoming input from all stakeholders.
Read More →Our research team publishes the annual threat landscape analysis covering key attack vectors, sectors at risk, and emerging trends.
Read More →The UKCSC Certified Practitioner (UKCSC-CP) programme opens its first cohort, offering vendor-neutral certification for working professionals.
Read More →Whether you're an organisation, a security professional, or an academic — there's a place for you in the UKCSC community.