Every UK government department is bound by a mandatory rulebook that names one exact cyber security standard they must meet. The government withdrew that standard in 2023; the rulebook naming it has not been touched since 2021.
Estimated reading time: 5 minutes
In short. Government Functional Standard GovS 007: Security binds every government department and arm's length body with a mandatory clause: organisations "shall meet the standards prescribed by HM Government" for cyber security, citing reference [2] in its own annex [2]. Reference [2] is the Minimum Cyber Security Standard (2018) [2]. GOV.UK's own page for that standard has carried a live withdrawal banner since 3 July 2023 [3]. GovS 007 itself has not been revised since 13 September 2021, and its own reference list tells readers to check for updated versions, an instruction its own authors appear not to have followed for the standard they cite. Two documented mistakes: four stars.
GovS 007: Security is not a piece of optional best-practice advice. It is one of the government's functional standards, the suite that "promotes consistent and coherent ways of working across government" and binds "permanent secretaries, directors general and chief executive officers of arm's length bodies" [2]. Its own glossary defines "shall" as "a requirement: a mandatory element" [2], and the standard uses that word to bind every department's cyber security to a named external document. The document it names has been dead for three years.
A mandatory clause pointing at a cancelled standard
Section 6.3, Cyber security, states: "Organisations that handle government data and information shall meet the standards prescribed by HM Government [2]" (page 14) [2]. Annex A, the reference list, identifies reference 2 as "Government Security Group, Minimum Cyber Security Standard (2018)" (page 20) [2].
Fetch that document's own GOV.UK page directly and its title has changed to "[Withdrawn] Minimum Cyber Security Standard", carrying a notification banner: "This publication was withdrawn on 3 July 2023. The updated Cyber Standard is available" [3], linking to the Cyber Security Standard now hosted on security.gov.uk [4]. That successor page, itself still labelled "Beta" more than three years after the standard it replaced was cancelled, is not named anywhere in GovS 007.
GovS 007's own Annex A carries an instruction that anticipates exactly this problem: "All references are correct at the time of publication, users should check for updated versions" (page 20) [2]. GovS 007 was last revised on 13 September 2021 [1], nearly two years before its own cited cyber security reference was cancelled, and it has not been touched since. A civil servant reading section 6.3 today and following its mandatory clause to the letter would open reference [2] and land on a page whose title begins with the word "Withdrawn".
The rulebook that told itself to check has not checked
GovS 007 sits inside a suite of fourteen functional standards, GovS 001 through GovS 015 (the collection skips GovS 012) [5]. Every one of them has been revised more recently than GovS 007's 2021 date, with a single exception. GovS 002 (Project Delivery) was updated 17 September 2025, GovS 004 (Property) 1 April 2026, GovS 005 (Digital) 22 April 2026, GovS 008 (Commercial) 14 May 2026, and even GovS 006 (Finance), the next-oldest of the group after Security, was revised in May 2023, still two years newer than Security [5]. Only GovS 013, Counter Fraud, dated 31 August 2021, predates GovS 007 by a fortnight [5]. Of fourteen cross-government standards, the two left unrevised the longest both happen to be the ones a department would reach for after a fraud loss or a security breach.
GovS 007 itself tells organisations to follow several of the more recently updated siblings: GovS 003 (People), GovS 004 (Property), GovS 005 (Digital), GovS 008 (Commercial) and GovS 010 (Analysis) are all listed as "directly necessary for the use of this standard" (page 3) [2]. Each of those has had at least one refresh since Security's last edit; Security has had none.
Credit where due
The document's actual content, where it is current, is not sloppy. Its accountability chain is precise and traceable: the Prime Minister to the Cabinet Secretary to Permanent Secretaries and Accounting Officers, each named with a specific duty rather than a vague gesture at "leadership" [2]. Annex C is transparent about where it deliberately leaves room for judgement, stating plainly that terms like "important" and "appropriate" are "deliberately left open, so that organisations can apply their own values based on their particular circumstances" [2], rather than hiding vague drafting behind false precision. The incident management and learning-from-experience sections require lessons to be recorded and fed back into practice, not merely filed [2]. None of that is what has gone wrong here. What has gone wrong is narrower and more mechanical: the standard has not been kept in step with the one document it names as the baseline for cyber security compliance across the whole of government.
The claims, tested
| The claim | What the evidence shows | Verdict |
|---|---|---|
| GovS 007: "Organisations that handle government data and information shall meet the standards prescribed by HM Government [2]", where [2] is the Minimum Cyber Security Standard (2018) (pages 14, 20) [2] | GOV.UK's own page for that standard: "[Withdrawn] Minimum Cyber Security Standard... withdrawn on 3 July 2023. The updated Cyber Standard is available" [3] | A mandatory clause names a document GOV.UK has marked cancelled for three years |
| GovS 007's own Annex A: "All references are correct at the time of publication, users should check for updated versions" (page 20) [2] | GovS 007 has not been revised since 13 September 2021; every sibling standard bar one (GovS 013, Counter Fraud) has been updated more recently, several within the last year [5] | The check the document asks readers to make was not made on the document itself |
Two documented mistakes. (1) GovS 007's mandatory cyber security clause (page 14) tells every government department and arm's length body it "shall meet the standards prescribed by HM Government", citing the Minimum Cyber Security Standard (2018) as reference 2; GOV.UK's own page for that standard has carried a withdrawal banner since 3 July 2023, naming a replacement GovS 007 does not mention. (2) GovS 007's own reference list tells readers to "check for updated versions"; GovS 007 has not itself been revised since 13 September 2021, making it the joint-oldest of fourteen functional standards in its own suite, tied with Counter Fraud, and two years staler than its next-oldest sibling. Rated four stars out of five.
Sources
- Government Functional Standard GovS 007: Security (GOV.UK publication page, Cabinet Office, published 30 July 2020, updated 13 September 2021)
- GovS 007: Security (PDF, version 2.0, 28 pages, issue date 13 September 2021)
- [Withdrawn] Minimum Cyber Security Standard (GOV.UK, Cabinet Office, published 25 June 2018, withdrawn 3 July 2023)
- The Cyber Security Standard (UK Government Security)
- Functional Standards (GOV.UK collection, Cabinet Office)