LOADING…
Platform  /  Datasheets  /  Secure by Design Control Plane
Secure by Design mandate

Secure by Design,under control.

The first purpose-built control plane for the UK Government Secure by Design mandate - from intake to SRO sign-off. One live record per project, evidence-mapped and audit-ready, in your own sovereign tenant.

All datasheets
10 principlesEvidence -backedHIGH confidence profile
HIGH

A HIGH confidence profile - built on evidence, not asserted - demonstrates that a service has been delivered in line with the Secure by Design mandate’s ten principles. Run that continuous-assurance approach on an emailed spreadsheet spread across ten systems and you cannot show that adherence: to an auditor, an internal assurance reviewer, or yourself.

The challenge

A mandate run on an emailed spreadsheet.

The Secure by Design mandate asks for a HIGH confidence profile built on evidence. The official self-assessment tracker is fine for a single project, but across a portfolio the real evidence scatters across SharePoint, Teams, Jira and inboxes, and the file falls out of date. The two columns below contrast that fragmented, assert-it-at-the-gate reality with one live record where gap-to-HIGH is always visible.

The problem
The official tracker maintained by hand, project by project
The truth lives in ten places - SharePoint, Teams, Jira, inboxes
HIGH confidence asserted, never actually proven
The governance pack built by hand the night before the gate
The control plane
One live Secure by Design record per project
Evidence mapped to every activity, carried across phases
Gap-to-HIGH visible at all times
The governance pack generated from the live record in one click
What it does

Not features - outcomes.

Everything the mandate needs sits in one place - the policy model, the lifecycle, evidence, workflow, the confidence calculator, the pack generator and an audit record - so Secure by Design is something you run, not just something you record.

Tracker engine

One live source of truth for Secure by Design confidence, per project and across the portfolio.

Evidence mapping

Every answer linked to the evidence behind it - graded, reusable and carried across phases.

Gap tracker

A missing-information panel and a gap-to-HIGH list, so nothing surfaces late at the gate.

RASCI ownership

A named owner on every activity - completion is somebody’s job, not nobody’s.

SRO sign-off

Executives sign off against a live, auditable record they can actually defend.

Governance pack

The governance pack builds itself from the live record - no midnight assembly.

At a glance

The numbers that matter.

The Secure by Design mandate comes down to a few hard facts: ten mandatory principles, every central-government department and ALB in scope, and one bar - HIGH confidence - that you have to evidence rather than assert. The control plane holds a single live record per project against exactly those numbers.

10
mandatory principles
ALL
departments & ALBs in scope
1
live record per project
HIGH
the confidence profile to evidence
How it works

Intake to sign-off, then continuous.

The control plane carries a project from a short intake through to SRO sign-off, then keeps the profile live rather than freezing it at the gate. The six phases below show confidence re-scoring as evidence lands, quality states separating a draft from proof, and the governance pack generating itself at the gate.

01
Intake
Short onboarding
Adoption is the point
02
Assess
Confidence re-scores
As evidence lands
03
Evidence
Mapped to activities
Carried across phases
04
Review
Quality states
A draft is not proof
05
Gate
SRO sign-off
Pack generated
06
Continuous
Live profile
Never out of date
Where it fits

Built for the mandate.

The control plane is built around the UK Government Secure by Design mandate first, then maps the same evidence across the frameworks that sit beside it. The list below ties the ten principles to NCSC CAF v4.0, ISO 27001:2022 secure-development controls, the NIST SSDF and OFFICIAL-SENSITIVE handling - so one record satisfies them all.

Gov Secure by DesignAll 10 mandatory principles, native
Digital Assurance PlaybookCheck initiatives follow your Secure by Design approach
NCSC CAF v4.0Secure configuration and assurance outcomes
ISO 27001:2022A.8.25-A.8.28 secure development
NIST SSDFSecure software development practices
OFFICIAL-SENSITIVEClassification handling and RBAC from day one
What you get

Proof, not assertion.

You get the artefacts that let an SRO actually defend a sign-off, not a spreadsheet rebuilt the night before the gate. A portfolio control plane with CISO, SRO and DPO lenses, a one-click governance pack assembled from the live record, and an append-only audit record where every answer, N/A justification, sign-off and export is logged.

Portfolio control plane

Every project, its phase and its confidence on one screen - CISO, SRO and DPO lenses.

One-click governance pack

The governance pack assembled from the live record, on demand.

Append-only audit record

Every answer, N/A justification, sign-off and export logged and defensible.

Next step

Your next gate should not hinge on a spreadsheet kept up by hand.

A 30-minute walkthrough on your projects - live gap-to-HIGH dashboards, no slides.

All datasheets →