The UKCSC develops, maintains, and promotes cybersecurity standards for organisations of all sizes — from SMEs to enterprises.
UKCSC is an independent standards body focused on practical, evidence-led cybersecurity standards and certification. Membership and certification figures are published here as they are verified.
We exist to define clear, practical, and rigorously assessed cybersecurity standards that any UK organisation can adopt.
We develop pragmatic cybersecurity standards through open consultation, drawing on expertise from industry, academia, and the wider stakeholder community.
View Standards →Our certification schemes validate that organisations and professionals meet the UKCSC's defined security benchmarks.
Explore Certification →Join a growing network of security-conscious organisations. Shape the standards that affect your industry and access exclusive resources.
Join Us →We publish research, threat landscapes, and practical guidance to help organisations understand and manage cyber risk.
Browse Resources →We engage transparently with policy discussions — responding to consultations and contributing practical expertise on cyber legislation.
About Our Work →From annual conferences to regional workshops, our events connect practitioners, policymakers, and organisations across the UK.
See Events →The UKCSC works with industry, academia, and policymakers to develop practical, evidence-based standards. Our governance is transparent and our certifications are vendor-neutral.
Supported by member organisations and certification programmes, with professional financial oversight.
Our standards are built on practical expertise and threat intelligence, not commercial lobbying.
Draft standards are published publicly for a minimum 60-day comment period.
A baseline cybersecurity standard designed specifically for small and medium enterprises, covering the five fundamental controls.
A structured framework for detecting, containing, and recovering from cybersecurity incidents across public and private sector organisations.
Addressing third-party risk with minimum vendor security requirements, audit procedures, and contractual clauses — currently under internal expert review.
Whether you're an organisation, a security professional, or an academic — there's a place for you in the UKCSC community.