VerbatimParliament, as it happens

Electronic Government: Cybercrime

Asked by James McMurdockIndependentDepartment for Science, Innovation and TechnologyTabled Answered 12 January 2026UIN 102629

The question

To ask the Secretary of State for Science, Innovation and Technology, what assessment she has made of the adequacy of One Login’s compliance with a) Secure by Design and b) the Cyber Assessment Framework.

Answered by Ian Murray

GOV.UK One Login is engaging appropriately with the Secure by Design (SbD) assessment process, and SbD principles are already embedded into the service.

GOV.UK One Login was assessed using GovAssure in 2024, the cyber security scheme for assessing government critical systems using the National Cyber Security Centre’s (NCSC) Cyber Assessment Framework (CAF) as part of the Government Cyber Security Strategy 2022-2030. GovAssure has multiple phases, which includes an assurance review by an independent assessor. The GOV.UK One Login programme works closely with NCSC to align with the requirements of the CAF.

Verbatim has judged this answer against the question that was actually asked — answered, partly answered, or evaded. Sign in to see the verdict →

Open this question in Verbatim →

Every written question, searchable

155,000 questions tabled since the election, with the answer each department gave — and the ones still unanswered, with the clock running. Free to search.

Search written questions →Read on Verbatim