The government's cyber security standard lets a department exempt its own arm's-length bodies from independent assurance checks altogether. No guidance published anywhere, including an update from two weeks ago, explains what would justify that choice.
Estimated reading time: 6 minutes
In short. The Cyber Security Standard says a department sponsoring arm's-length bodies "shall... define the extent to which the GovAssure cyber assurance process will be implemented for their ALBs, either through the complete GovAssure process, partial implementation, or exemption" [1] (clause 4.2.b). Nothing in the Standard, the GovAssure guidance hub [3], or the dedicated guide for supporting ALBs through the process, current version updated 7 September 2026 [2], explains what would justify choosing exemption over the other two options. Arm's-length bodies include executive agencies [6], a category that includes the DVLA, which holds records for 53 million drivers [5]. Two documented mistakes: four stars.
A government department deciding that one of its arm's-length bodies does not need independent cyber assurance this year does not have to explain that decision against any published test, because none exists. The rule that hands over the decision sits in the Cyber Security Standard, the Government Cyber Unit's current rulebook for how government organisations protect their systems, published 15 April 2024 and last updated 8 July 2025 [1]. It is a short document, eleven numbered requirements long, and most of it is unambiguous: organisations "shall meet or exceed" the security outcomes in NCSC's Cyber Assessment Framework for critical systems, and "shall assure" those systems "using the GovAssure cyber assurance process" [1] (clauses 3.2, 3.4). GovAssure itself is described on its own hub page as the scheme for "assessing government critical systems" against the CAF, mandatory for systems classed as government-sector critical national infrastructure [4].
The clause that hands over the decision
The certainty stops at arm's-length bodies. Clause 4.2 of the Standard says: "Where a government department has responsibility for arm's length bodies (ALBs), the department shall" carry out two duties. The first, 4.2.a, is to take "a threat-driven, risk-based approach" when applying CAF profiles within ALBs. The second, 4.2.b, is the one that matters here: the department shall "define the extent to which the GovAssure cyber assurance process will be implemented for their ALBs, either through the complete GovAssure process, partial implementation, or exemption" [1] (clause 4.2.b). Three options, one of which is opting out entirely, and the clause that creates them sets no test, threshold or example for choosing between them. It reads as a grant of discretion, not a standard.
The guidance that never explains it
If the Standard itself is silent, the practical guidance built to support departments through GovAssure might reasonably be expected to fill the gap. It does not. The GovAssure guidance hub lists exactly two dedicated sub-guides: one on running a stage 4 peer review, and one titled "Supporting arm's length bodies", aimed at Lead Government Departments overseeing their ALBs through the process [3]. That second guide, authored by the Government Cyber Unit and last updated 7 September 2026, two weeks before this piece, tells departments they should decide which ALBs are "in scope for each year of GovAssure" based on "your knowledge of your ALB landscape", "the criticality of your ALBs' services and systems", and "which ALBs have been through GovAssure in previous years" [2]. Those are three self-assessed, unverifiable factors for a different question: which ALBs a department chooses to put through GovAssure at all that year. The guide never uses the words "exempt", "exemption", "partial" or "criteria" once in its full text, and does not mention clause 4.2.b or the three-way choice it creates. Nor did the guide's original text: the same document as first published, dated 10 September 2025, contains none of those words either [7]. The gap between the Standard's exemption clause and any explanation of it has existed, unremarked, since before either document reached its current form.
How large "arm's-length body" can mean
The Standard treats ALBs as a single undifferentiated category, but the Cabinet Office's own Public Bodies Handbook is clear that the term covers organisations of very different sizes: executive agencies are one of the categories that count as an ALB, described as "clearly designated units of a government department, administratively distinct, but legally part of it" [6]. The DVLA is one such executive agency, sponsored by the Department for Transport. On its own GOV.UK page it describes itself as "maintaining accurate records for more than 53 million drivers in Great Britain and 48 million vehicles across the United Kingdom", and says it "collected more than £9 billion" in Vehicle Excise Duty in the 2025-26 financial year [5]. Nothing in this piece finds that the DVLA has been exempted from GovAssure, partially assessed, or treated any particular way; no such record is published. The point the Standard's own structure makes is different and simpler: the same undocumented, self-determined choice between complete assurance, partial assurance or none at all applies whether the ALB in question is a small advisory body or one holding driving records for most of the adult population of Great Britain, because clause 4.2.b draws no distinction by scale.
The claims, tested
| The document's own words | What the evidence actually shows | Verdict |
|---|---|---|
| A sponsoring department "shall... define the extent to which the GovAssure cyber assurance process will be implemented for their ALBs, either through the complete GovAssure process, partial implementation, or exemption" [1] (clause 4.2.b) | No published document, including the clause itself, states any test, threshold or example for choosing between the three options | An unqualified grant of discretion with no way to check whether it was used well |
| The GovAssure guidance hub exists to "help government organisations to complete GovAssure" [3] | Its only ALB-specific guide addresses which ALBs are "in scope" each year, not the Standard's complete/partial/exemption choice, and never mentions exemption or criteria [2] | The guidance answers an adjacent question, not the one the Standard actually creates |
| The ALB support guide was "last updated: 7 September 2026" [2] | The original 10 September 2025 version of the same guide contains no mention of exemption or criteria either [7] | A year of updates to the guide has not touched the gap |
The mistakes, counted
The Cyber Security Standard creates a three-way discretion over ALB cyber assurance with no published criteria for exercising it (1). Clause 4.2.b lets a department choose "the complete GovAssure process, partial implementation, or exemption" for each of its arm's-length bodies [1], and no part of the Standard states what should drive that choice.
None of the guidance built to support the decision explains it either (2). The GovAssure guidance hub's only ALB-specific guide, current as of 7 September 2026, addresses a different question, which ALBs are in scope for GovAssure that year, using self-assessed factors, and never defines "partial implementation" or sets a bar for "exemption" [2]; the guide's original September 2025 text has the identical gap [7].
Credit where due
GovAssure itself is a serious, structured scheme, not a paper exercise: it runs through five defined stages, uses the NCSC's own Cyber Assessment Framework as its yardstick, and its stage 4 reviews can require an independent assurance reviewer from NCSC's Cyber Resilience Audit scheme, procured through the Government Commercial Agency rather than chosen informally [2]. The supporting ALB guide, for the part of the process it does cover, is detailed and practical: it sets a recommended fortnightly check-in cadence between Lead Government Departments and their ALBs and walks through each of the five stages in turn [2]. And the Standard's core requirements for departments' own critical systems, unlike the ALB exemption clause, are written as hard, checkable "shall" rules rather than vague discretion [1] (clauses 3.2, 3.4).
Verdict
Four stars, from two documented mistakes. GovAssure and the Cyber Security Standard are, for a department's own systems, a real and reasonably rigorous assurance regime, backed by an independent audit scheme and a structured five-stage process. But the moment responsibility passes to an arm's-length body, the Standard hands the sponsoring department an unexplained choice between full checks, partial checks, or none, and a year of guidance updates, including one from a fortnight before this piece, has not produced a single sentence describing when exemption is the right call. Arm's-length bodies are not uniformly small: the category includes bodies on the scale of the DVLA, which alone holds driving records for the majority of Great Britain's adult population. Whether any large ALB has actually been exempted is not something the published record allows a reader to check, which is itself the gap this piece has found.
Sources
- The Cyber Security Standard, UK Government Security, Government Cyber Unit, published 15 April 2024, updated 8 July 2025
- Supporting arm's length bodies, UK Government Security, Government Cyber Unit, published 25 November 2025, updated 7 September 2026
- GovAssure guidance, UK Government Security, Government Security Group, updated 7 September 2026
- GovAssure, UK Government Security, Government Cyber Unit, updated 15 September 2026
- Driver and Vehicle Licensing Agency: about us, GOV.UK, published 12 May 2014, updated 31 July 2026
- Setting up a new arm's-length body (ALB): guidance for departments, GOV.UK, Cabinet Office, Public Bodies Handbook Part 2.1
- 2025-09-10 GovAssure guide to supporting arm's length bodies, UK Government Security, Government Cyber Unit, 10 September 2025