Secure by Design — Customer Guide¶
Last updated: 2026-05-21 (Plan 145 v1)
What is Secure by Design, and why does it matter to you?¶
Secure by Design is the UK central government framework for building security into digital programmes from the start. It is mandatory for UK central government departments, arm's-length bodies (ALBs) and suppliers delivering digital programmes that pass through HMG spend control. Without a Confidence Profile and supporting evidence, the spend-control panel sends the programme back. The quickest way to take pressure off your team is to keep the Confidence Profile current and the supporting evidence reviewable on demand — so the panel approval lands on the first submission.
What Secure by Design-specific features does Secruna ship?¶
- Confidence Profile generator — drafts the spend-control Confidence Profile from your inventory and connector evidence.
- Rule book v1 — rules at
frameworks/secure_by_design/v1/covering the Secure by Design principles. - Principle-by-principle evidence map — every principle shown as Met, Partial or Unmet with the signal behind it.
- Remediation list — gaps sorted by impact on the Confidence Profile.
- Cross-framework signal share — shared with NCSC CAF where controls overlap.
Limitations (v1)¶
- No GDS spend-control portal integration. Secruna exports the Confidence Profile as PDF / CSV. The department uploads it to the spend-control portal.
- Departmental policy customisation is operator-managed. Where a department adds local policy on top of Secure by Design, the operator captures the local additions in the platform.
- No automatic CCS Digital Outcomes coverage. Procurement framework alignment is out of v1 scope.
What Secure by Design is¶
Secure by Design is owned by the Government Security Group and the Central Digital and Data Office (CDDO). It applies to UK central government departments, ALBs and any supplier delivering a digital programme that goes through HMG spend control. Reference material lives at https://www.security.gov.uk/policy-and-guidance/secure-by-design/.
The framework covers a set of principles a programme must demonstrably meet — including secure architecture, secure operation, identity, data protection, supply-chain assurance and incident response. The output is a Confidence Profile shown to the spend- control panel.
What Secruna covers¶
The v1 rule book covers:
- Secure architecture — defence-in-depth posture, segmentation, threat-modelling record.
- Secure operation — patching cadence, logging coverage, monitoring posture.
- Identity and access — MFA enforcement, privileged access, joiner / mover / leaver.
- Data protection — encryption posture, data-classification coverage, retention policy.
- Supply-chain assurance — vendor inventory, vendor security attestations.
- Incident response — IR plan, tabletop record, reporting workflow.
- Confidence Profile assembly — pulls each principle's evidence into the spend-control Confidence Profile.
Using the Confidence Profile¶
The Confidence Profile is generated from the dashboard under Exports → Secure by Design Confidence Profile (org_admin role required). The file is a PDF / CSV per programme:
- Cover — programme name, department / ALB, generation timestamp.
- §1. Programme summary — counts of principles at each verdict.
- §2. Per-principle evidence — one row per principle with the verdict and a short evidence summary.
- §3. Remediation list — Partial / Unmet principles surfaced separately.
- §4. Audit trail — last 90 days of activity.
Filename: secruna-secure-by-design-{programme_slug}-{date}.pdf.
What Secruna does NOT cover¶
- GDS spend-control portal submission. Department-managed.
- HMG accreditation processes for SECRET / TOP SECRET systems. Out of platform scope.
- CCS framework alignment. Procurement-led.
Frequently asked¶
Q. We are a supplier delivering into a department. Does the Confidence Profile sit with us or with the department? Both. The supplier prepares the evidence for the part of the programme they deliver. The department aggregates and submits. Secruna supports both views — supplier-side and department-side — behind a separate tenant.
Q. What is the relationship to NCSC CAF? The CAF is the cyber assurance framework; Secure by Design is the spend-control gate. The two share several controls and Secruna reuses evidence across both packs.