Alignment with the UK NCSC Software Security Code of Practice
The Software Security Code of Practice is a voluntary framework published by the UK Department for Science, Innovation and Technology (DSIT) and the National Cyber Security Centre (NCSC), which outlines 14 principles across four themes designed to help software vendors mitigate supply chain attacks and embed security-by-design from the ground up.
Because Canonical builds and distributes the open source Ubuntu platform, it qualifies primarily as a "software developer and distributor". We have been building and shipping open source software for over 20 years, and the security practices we’ve developed over that time align well with the 14 principles laid out in the Code. This page explains how.
See how the four main themes of the framework map to Canonical solutions
-
Theme 1: Secure design and development
1.1 Established secure development framework
Canonical utilizes well-established code quality management practices, such as the Main Inclusion Review and Stable Release Updates processes for auditing and maintaining software packages, alongside a modern Secure Software Development Lifecycle that aligns with the NIST SP800-218 Secure Software Development Framework.
-
1.2 Software composition & third-party risk assessment
Canonical’s security team explicitly monitors third-party vulnerabilities across the whole Ubuntu Archive (covering both the Main and Universe repositories) to assess risks linked to the ingestion of outside components.
-
1.3 Pre-distribution testing process
Every software update and security patch undergoes comprehensive regression testing before being pushed to production mirrors, fulfilling the mandate to test software and updates thoroughly before distribution.
-
1.4 Secure by design and secure by default
Canonical treats security as an embedded core fundamental rather than a follow-up activity. Ubuntu enforces mandatory compiler-level protections, kernel-level application hardening, and isolation mechanisms like AppArmor out of the box. Furthermore, the unattended-upgrades feature is enabled by default on installations to automate security coverage without user intervention.
-
Theme 2: Build environment security
2.1 Protect build environment against unauthorized access
Canonical’s Launchpad build system adheres to a strict principle of least privilege to protect the environment against unauthorized access. Engineers lack direct access to production instances. Crucially, Launchpad utilizes an isolated ephemeral VM model for builds: every virtual machine is torn down and restarted from a clean image at the conclusion of each build, preventing persistent cross-build contamination.
-
2.2 Control and log changes to build environment
Restrictive network setups isolate untrusted builders, satisfying the call to control changes to the build environment. All non-trivial code and infrastructure alterations require multi-peer reviews before entering production.
-
Theme 3: Secure deployment and maintenance
3.1 Secure software distribution
Ubuntu software is distributed via Canonical servers and third-party mirrors utilizing strong cryptographic integrity protections. Packages are cryptographically validated on the client-side to mitigate supply chain tampering and provide a complete chain of trust.
-
3.2 Effective vulnerability disclosure process
Canonical governs vulnerability disclosures via the official Ubuntu Security Disclosure Policy and strictly adheres to Coordinated Vulnerability Disclosure (CVD) frameworks, satisfying the recommendation to implement and publish an effective vulnerability disclosure process.
-
3.3 Proactive component vulnerability management
Canonical maps its entire software estate into a multi-layered risk model (from critical foundations like the kernel down to the broader application ecosystem) and tracks known bugs via the public Ubuntu CVE Tracker to proactively detect, prioritize, and ultimately fix, vulnerabilities.
-
3.4 Vulnerability reporting to relevant parties
The Canonical security team routinely collaborates with security researchers, upstream open source maintainers, and industry groups, actively managing fixes under closed embargoes until public disclosure. You can read Canonical’s Disclosure Policy here.
-
3.5 Timely security updates, patches, and notifications
Canonical’s security team works directly with upstream projects and communities to backport vulnerability fixes to the supported stable Ubuntu releases. The patching process has been underway for over 20 years, we patch all critical, high and selected medium CVEs within a timely manner.
-
Theme 4: Communication with customers
4.1 Specify support and maintenance levels
Canonical provides explicit, highly publicized maintenance commitments: standard Ubuntu LTS releases offer 5 years of standard security maintenance, which is extended to 10 years (for both Main and Universe archives) under Ubuntu Pro, and up to 15 years with the Legacy add-on, specifying the exact level of support provided.
-
4.2 Provide at least 1 year’s notice for end of support
Because Ubuntu operates on a predictable, fixed-schedule LTS release cadence (every 2 years) with known 5-, 10-, or 15-year lifespans, customers essentially receive years of notice before software reaches end of support.
-
4.3 Disseminate information on notable incidents
Every security resolution is documented and published via Ubuntu Security Notices (USNs) to make information available about notable incidents that may cause a significant impact. Canonical also publishes vulnerability feeds using open data standards like OVAL, OSV, and VEX. High-impact CVEs are individually described in the Vulnerability knowledge base.
How Canonical supports organizations in adopting the practice
If your organization is trying to satisfy the UK Government's voluntary Code of Practice (or prepare for the upcoming certification scheme), Canonical acts as a trusted source of open source code.
Securing your software supply chain
Instead of manually tracking and patching thousands of open-source libraries (which is heavily emphasized in Themes 1 and 3), subscribing to Ubuntu Pro offloads CVE management entirely to Canonical for up to 15 years, establishing an instant, verifiable compliance baseline.
Available in all software stacks
Ubuntu Pro covers the whole open source ecosystem, and can be deployed on desktops, on servers, in the cloud or on-premises, as well as in containers and Kubernetes. Ubuntu Pro is also available for edge devices with Ubuntu Core, our immutable Ubuntu OS designed for IoT and edge deployments. One subscription for any environment.
Centralized estate auditing via Landscape
For organizations requiring clear internal monitoring or evidence to fill out the UK government's self-assessment form, Canonical's Landscape tool acts as a single pane of glass to automate patch deployment, manage staged updates, and run system audits across all data centers, cloud instances, and IoT devices.
Aligning with the EU Cyber Resilience Act
Many organizations will be operating in the EU as well, and the UK’s Code of Practice is influenced by the EU’s CRA. Canonical is fully aligned with the CRA Annex requirements, enabling you to meet both sets of security standards at the same time.
Resources
Building new revenue streams: 3 strategic cloud opportunities for telcos in 2026
PWC claimed the ‘fundamental challenge’ behind slowing growth is that telecom’s ‘core products and services’ are ‘becoming commodities.’ The way forward lies...
Canonical Ubuntu and Ubuntu Pro now available on AWS European Sovereign Cloud
Canonical announced it is a launch partner for the AWS European Sovereign Cloud, with Ubuntu and Ubuntu Pro now available. This new independent cloud for Europe enables organizations to run...
What is geopatriation?
Geopatriation refers to the relocation of workloads and applications from global cloud hyperscalers to regional or national alternatives due to geopolitical uncertainty.
54% of European enterprises want long term open source support: how Ubuntu Pro + Support delivers
Europe’s open source ecosystem is at a turning point. The Linux Foundation’s Open Source as Europe’s Strategic Advantage: Trends, Barriers, and Priorities for the European Open Source...
Get coverage with Ubuntu Pro
Ubuntu Pro provides the essential building blocks for building a securely designed software stack and aligns with the UK NCSC Security Code of Practice. Talk to us about securing your open-source software supply chain with Ubuntu Pro.