Source · Select Committees · Public Accounts Committee

Recommendation 23

23

GovAssure not designed to assess all critical systems despite improvement goals.

Recommendation
We asked the Cabinet Office how it would increase the scale and pace of GovAssure to assess the cyber resilience of all of government’s critical systems. The Cabinet Office explained that it did not plan to assess 100% 43 C&AG’s Report, paras 14, 15 44 C&AG’s Report, para 19 45 Q 39 46 Q 44 47 Q 45 14 of critical systems through GovAssure.48 This was because GovAssure was one part of a wider system of assurance, which included department’s own cyber experts as the “first line of defence”. The Cabinet Office said that it had designed GovAssure to bring consistency and share best practice, but that government must balance its effort between assurance and frontline cyber security.49 We asked if that meant the Cabinet Office was happy with the current scale and pace of GovAssure. The Cabinet Office told us it wanted to increase the number of systems it assessed and it needed to make GovAssure quicker and easier to complete for departments.50
Government Response

A response document is linked to this report, dated 18 September 2025. Response attribution to this conclusion has not been verified. Read the response document ↗