An independent body dedicated to raising cybersecurity standards across the United Kingdom.
The UK Cybersecurity Standards Council was founded on a simple premise: that effective cybersecurity standards should be developed transparently and with the genuine input of those they affect.
The UKCSC has no regulatory power and no products to sell. Our sole purpose is to create standards and guidance that organisations can actually use — practical, evidence-based, and freely available.
We believe a more secure UK benefits everyone. That is why our core standards are published under open licences and our governance is fully transparent.
Define and promote practical cybersecurity standards for UK organisations
A UK where every organisation operates with a verifiable, minimum standard of cyber security
Supported by member organisations and certification programmes, with professional financial oversight
All draft standards published openly; governance decisions recorded for members
A group of security practitioners, academics, and industry representatives convene to explore the need for a UK standards body dedicated to practical cybersecurity guidance.
UKCSC is registered as a UK company in England & Wales. First Council elected, governance charter adopted.
UKCSC-CS-001 (Cyber Essentials for SMEs) released following a 90-day public consultation.
First UKCSC certification cohort begins. First annual governance review completed.
Supply Chain Security and Incident Response standards in progress.
The UKCSC is governed by an elected Council with strict conflict-of-interest rules and clear accountability to members and stakeholders.
The governing Council is elected by members every two years, with no individual serving more than two consecutive terms. Elections are administered by an external party.
All Council members must declare conflicts of interest and recuse themselves from relevant decisions. Declarations are recorded and available to members on request.
Council meeting minutes are recorded and shared with members. Decisions and rationales are documented for member review.
Annual accounts are externally audited. Financial oversight is managed by the Council with independent review.
Every standard goes through at minimum a 60-day public consultation. All responses are published unless the respondent requests anonymity.
Each standard is reviewed at least every three years, or sooner if material changes in the threat landscape require it.
The UKCSC is directed by an elected Council of cybersecurity, legal, governance, and industry professionals, supported by a small secretariat.
Council members are elected by the membership and serve in an unremunerated capacity. Declarations of interest are recorded and available to members on request.
A small operational team supports standards development, certification delivery, and member services.
Clear governance, declared interests, and standards decisions recorded for members.
Free from vendor influence and commercial bias.
Standards that work for a sole trader as well as a FTSE 100 company.
Every standard is grounded in research, not opinion or commercial interest.