Answer yes if your organisation conforms to the UK Software Security Code of Practice. State in the notes section whether your organisation has signed up as a Software Security Ambassador or is otherwise a signatory, and describe your progress against the Code's principles. Upload any self-assessment documentation as evidence.
The UK Software Security Code of Practice sets out a voluntary baseline of secure software development and maintenance practices for vendors, covering areas such as secure design and development, third-party component risk, testing before release, and ongoing maintenance and update processes. Signing up, and where relevant becoming a Software Security Ambassador, signals a formal commitment to these practices beyond what's required by general certifications, and (in the case of Ambassadors) a willingness to champion the Code's adoption more widely across your sector.
Review the full text of the Software Security Code of Practice and its accompanying Implementation Guidance, both published on the NCSC website, to understand the 14 principles and the four themes they sit under. Consider these principles against your current software development practices, and formally register your organisation's conformance or ambassador status.
State in the notes section whether you've signed up as a Software Security Ambassador or are otherwise a signatory, describe your progress against the Code's principles, and upload any self-assessment documentation as evidence.