Alignment with the UK NCSC
Software Security Code of Practice

The Software Security Code of Practice is a voluntary framework published by the UK Department for Science, Innovation and Technology (DSIT) and the National Cyber Security Centre (NCSC), which outlines 14 principles across four themes designed to help software vendors mitigate supply chain attacks and embed security-by-design from the ground up.

Because Canonical builds and distributes the open source Ubuntu platform, it qualifies primarily as a "software developer and distributor". We have been building and shipping open source software for over 20 years, and the security practices we’ve developed over that time align well with the 14 principles laid out in the Code. This page explains how.


See how the four main themes of the framework map to Canonical solutions

  • Theme 1: Secure design and development

    1.1 Established secure development framework

    Canonical utilizes well-established code quality management practices, such as the Main Inclusion Review and Stable Release Updates processes for auditing and maintaining software packages, alongside a modern Secure Software Development Lifecycle that aligns with the NIST SP800-218 Secure Software Development Framework.


  • 1.2 Software composition & third-party risk assessment

    Canonical’s security team explicitly monitors third-party vulnerabilities across the whole Ubuntu Archive (covering both the Main and Universe repositories) to assess risks linked to the ingestion of outside components.


  • 1.3 Pre-distribution testing process

    Every software update and security patch undergoes comprehensive regression testing before being pushed to production mirrors, fulfilling the mandate to test software and updates thoroughly before distribution.


  • 1.4 Secure by design and secure by default

    Canonical treats security as an embedded core fundamental rather than a follow-up activity. Ubuntu enforces mandatory compiler-level protections, kernel-level application hardening, and isolation mechanisms like AppArmor out of the box. Furthermore, the unattended-upgrades feature is enabled by default on installations to automate security coverage without user intervention.


How Canonical supports organizations in adopting the practice

If your organization is trying to satisfy the UK Government's voluntary Code of Practice (or prepare for the upcoming certification scheme), Canonical acts as a trusted source of open source code.

Securing your software supply chain

Instead of manually tracking and patching thousands of open-source libraries (which is heavily emphasized in Themes 1 and 3), subscribing to Ubuntu Pro offloads CVE management entirely to Canonical for up to 15 years, establishing an instant, verifiable compliance baseline.


Available in all software stacks

Ubuntu Pro covers the whole open source ecosystem, and can be deployed on desktops, on servers, in the cloud or on-premises, as well as in containers and Kubernetes. Ubuntu Pro is also available for edge devices with Ubuntu Core, our immutable Ubuntu OS designed for IoT and edge deployments. One subscription for any environment.


Centralized estate auditing via Landscape

For organizations requiring clear internal monitoring or evidence to fill out the UK government's self-assessment form, Canonical's Landscape tool acts as a single pane of glass to automate patch deployment, manage staged updates, and run system audits across all data centers, cloud instances, and IoT devices.


Aligning with the EU Cyber Resilience Act

Many organizations will be operating in the EU as well, and the UK’s Code of Practice is influenced by the EU’s CRA. Canonical is fully aligned with the CRA Annex requirements, enabling you to meet both sets of security standards at the same time.


Resources

Building new revenue streams: 3 strategic cloud opportunities for telcos in 2026

PWC claimed the ‘fundamental challenge’ behind slowing growth is that telecom’s ‘core products and services’ are ‘becoming commodities.’ The way forward lies...

Canonical Ubuntu and Ubuntu Pro now available on AWS European Sovereign Cloud

Canonical announced it is a launch partner for the AWS European Sovereign Cloud, with Ubuntu and Ubuntu Pro now available. This new independent cloud for Europe enables organizations to run...

What is geopatriation?

Geopatriation refers to the relocation of workloads and applications from global cloud hyperscalers to regional or national alternatives due to geopolitical uncertainty.

54% of European enterprises want long term open source support: how Ubuntu Pro + Support delivers

Europe’s open source ecosystem is at a turning point. The Linux Foundation’s Open Source as Europe’s Strategic Advantage: Trends, Barriers, and Priorities for the European Open Source...


Get coverage with Ubuntu Pro

Ubuntu Pro provides the essential building blocks for building a securely designed software stack and aligns with the UK NCSC Security Code of Practice. Talk to us about securing your open-source software supply chain with Ubuntu Pro.