AuditXYZ

Compliance Framework

Public Services Network Code of Connection (PSN CoCo)

The PSN Code of Connection is required for UK organizations connecting to the Public Services Network. This guide covers compliance requirements, IT Health Checks, and the annual submission process.

$20,000–$150,0003–9 monthsAudit Required2024 (ongoing updates to compliance criteria)
Issuing BodyUK Cabinet Office / Government Digital Service (GDS)
First Published2011-01-01
Latest Version2024 (ongoing updates to compliance criteria)
Typical Cost$20,000–$150,000
Typical Timeline3–9 months
Audit RequiredYes
Audit FrequencyAnnual compliance submission including IT Health Check by a CHECK-approved or CREST-certified tester.
Geographyunited-kingdom

PSN CoCo: UK Public Services Network Code of Connection

The Public Services Network (PSN) Code of Connection (CoCo) defines the security requirements that organizations must meet to connect to the UK's PSN — the government network that enables secure data sharing between public sector organizations. PSN connectivity is essential for local authorities, central government departments, NHS organizations, and their technology partners to access government services and share data securely.

What PSN CoCo Is and Who Issues It

The Public Services Network (PSN) is the UK government's secure network infrastructure, enabling public sector organizations to share data and services across organizational boundaries. It connects thousands of public sector sites — local councils, police forces, NHS trusts, government departments, emergency services, and their IT partners — to shared government services including the Government Secure Intranet (GSI) and cross-government data systems.

The Code of Connection is issued by the Cabinet Office, which has policy responsibility for PSN governance. The Crown Commercial Service (CCS) manages the commercial framework around PSN connectivity services, while the Government Digital Service (GDS) oversees the technical standards and compliance criteria. PSN Authority functions have evolved over the programme's lifetime, and organizations should verify current governance arrangements through the official NCSC and Cabinet Office guidance.

PSN CoCo compliance demonstrates that an organization's network environment meets the security baseline required to protect the PSN and other organizations connected to it. Unlike purely commercial security assessments, PSN CoCo is a mandatory prerequisite for connection — no connection is permitted without a current, valid compliance certificate. This makes PSN CoCo unique among security frameworks: it is not a matter of competitive differentiation but of operational necessity for organizations that need PSN connectivity to deliver public sector services.

The compliance criteria have evolved over time, reflecting lessons from security incidents, changes in threat landscape, and developments in security best practice. The current criteria draw on Cyber Essentials requirements and NCSC guidance. Organizations should always check the current criteria at the time of their annual compliance submission rather than relying on prior-year documentation.

Who Needs PSN CoCo Compliance

PSN connectivity is required by a wide range of public sector organizations and their technology partners:

Local government: All local councils in England, Wales, Scotland, and Northern Ireland that share data with central government, access shared services, or provide online services through PSN-connected infrastructure require PSN CoCo compliance. This includes district, borough, county, and unitary authorities.

Central government departments and agencies: Departments operating their own networks connected to the PSN — including HMRC, DWP, DVLA, and hundreds of agencies and arm's-length bodies — must maintain PSN CoCo compliance for their connected network segments.

NHS organizations: NHS trusts, clinical commissioning groups (now integrated care boards), GP practices accessing NHS Spine, and NHS digital services relying on N3/HSCN-PSN connectivity are subject to CoCo requirements.

Police forces and emergency services: Police forces connecting to the Police National Computer (PNC) and other cross-service systems, fire and rescue services, and ambulance trusts require PSN connectivity and thus CoCo compliance.

IT service providers and managed service partners: Technology companies providing managed network services, IT support, cloud hosting, or technical platforms to PSN-connected organizations must ensure their infrastructure meets PSN requirements. This is a frequently misunderstood obligation — the IT service provider, not just the public sector client, must satisfy the CoCo requirements for the infrastructure they manage.

SaaS and cloud providers with PSN integration: Software-as-a-Service providers whose applications need to exchange data with PSN-connected systems, or whose hosting is used by PSN-connected organizations, may need to satisfy PSN technical requirements depending on the nature of the integration.

Key Requirements in Depth

IT Health Check (ITHC)

The cornerstone of PSN CoCo compliance is the annual IT Health Check — a comprehensive penetration test of the organization's network environment conducted by a CHECK-approved tester or CREST-certified penetration testing firm. The ITHC must be conducted by a qualified, approved firm; self-assessments and unaccredited testers are not accepted.

The ITHC typically covers four scopes:

  • External infrastructure testing: Testing the organization's public-facing network boundary from outside the network, assessing internet-accessible systems, firewall configurations, and external access points
  • Internal infrastructure testing: Testing the internal network from an assumed-breach position, assessing lateral movement possibilities, network segmentation effectiveness, and internal system security
  • Wireless network assessment: Testing all wireless networks within scope for encryption standards, rogue access points, and configuration weaknesses
  • Web application testing: For applications connected to or accessible through the PSN environment, testing for OWASP Top 10 vulnerabilities and other web application weaknesses

Following the ITHC, the organization receives a report categorizing findings as Critical, High, Medium, or Low severity. PSN compliance requires that all Critical and High-severity findings be remediated before a compliance certificate can be issued. Medium findings require a remediation plan. Low findings are documented for tracking.

Patch Management

Organizations must demonstrate effective patch management for all systems within the PSN-connected environment. Current patch status must be documented, and a patch management process must be established defining responsibility, frequency, and escalation for critical patches. Systems that cannot be patched (such as legacy systems) must be compensating-controlled and risk-accepted with appropriate justification.

Network Boundary Protection

The organization must demonstrate effective network boundary controls protecting the PSN connection. This includes firewall rules limiting traffic to only what is necessary for business purposes, network segmentation isolating PSN-connected systems from less-trusted zones, and monitoring of traffic crossing the network boundary. Poorly configured firewalls — particularly overly permissive rules — are a common finding in ITHCs.

Access Control and Authentication

Access to PSN-connected systems must be controlled through appropriate authentication mechanisms. Strong passwords at minimum; multi-factor authentication for remote access and privileged accounts. User access must be managed through a defined joiner-mover-leaver process, and regular access reviews must be conducted and documented. Shared or generic accounts are generally prohibited.

Incident Management

Organizations must maintain a documented and tested incident management process for security incidents affecting PSN-connected systems. Reporting obligations require notifying the PSN Authority and potentially NCSC for significant incidents. The incident management process must be exercised periodically and updated based on lessons learned.

Compliance Submission

Annually, organizations must compile a compliance submission documenting how they meet each PSN CoCo criterion, including the ITHC report, evidence of remediation, patch status, and policy documentation. The submission is reviewed by the PSN Authority (or its agent) and, if satisfactory, results in a compliance certificate authorizing continued PSN connection.

The Annual Compliance Cycle

The PSN compliance cycle is annual, driven by the 12-month validity of compliance certificates. Organizations typically follow this pattern:

Months 1–2: Commission and conduct the ITHC. Selecting a CHECK-approved tester early is important as capacity is sometimes constrained, particularly for local government organizations that tend to cluster around the spring.

Months 2–3: Receive ITHC report. Triage findings and prioritize remediation of Critical and High-severity issues. Critical findings require immediate attention; High findings must be remediated before submission.

Months 3–4: Remediate Critical and High findings. Develop remediation plans for Medium findings. Update security documentation to reflect current controls.

Month 4: Compile compliance submission. Review against current PSN CoCo criteria — criteria may have been updated since the prior year. Prepare documentation of policy, process, and technical controls.

Month 5: Submit to PSN Authority for review. Respond to any queries or requests for additional evidence from reviewers.

Months 5–6: Receive compliance certificate. Certificate validity commences from the date of issue.

Organizations that miss their certificate renewal deadline risk losing PSN connectivity until compliance is restored — a potentially serious operational consequence for organizations dependent on PSN for core service delivery.

Costs and Timeline

ActivityTypical CostTimeline
ITHC — small scope (single site)$10,000 – $20,0001–2 weeks
ITHC — medium scope (multiple sites)$15,000 – $40,0002–4 weeks
ITHC — large scope (complex infrastructure)$25,000 – $80,0003–6 weeks
Critical/High finding remediation$10,000 – $50,000+2–6 weeks
Documentation and submission preparation$3,000 – $10,0001–2 weeks
Annual compliance total (simple)$20,000 – $40,0002–3 months
Annual compliance total (complex)$60,000 – $150,0004–9 months

ISO 27001 (50% overlap): ISO 27001 and PSN CoCo both address information security management and technical controls, but serve different purposes. ISO 27001 is a comprehensive management system certification; PSN CoCo is a network connectivity prerequisite. Organizations with ISO 27001 are generally well-positioned for PSN CoCo compliance, as the management system disciplines (risk management, policy documentation, access control, incident management) transfer directly. However, the mandatory ITHC is a specific PSN requirement not covered by ISO 27001 certification.

Cyber Essentials (60% overlap): Cyber Essentials defines a baseline security hygiene standard covering firewalls, secure configuration, user access control, malware protection, and patch management — areas directly relevant to PSN CoCo. Holding Cyber Essentials (or Cyber Essentials Plus) certification demonstrates a meaningful security baseline and is a positive indicator in PSN compliance submissions. Cyber Essentials Plus (which includes an independent technical assessment) is particularly well-regarded. However, Cyber Essentials Plus does not substitute for the ITHC, which is broader in scope and more technically detailed.

G-Cloud (complementary): G-Cloud and PSN CoCo serve the same market — UK public sector — but at different levels. G-Cloud enables cloud providers to be procured by public sector buyers. PSN CoCo enables organizations (including those cloud providers) to connect to the PSN. Technology companies that are both G-Cloud listed and PSN-connected need both programmes. See the G-Cloud guide for the procurement framework perspective.

How Automation Helps

PSN CoCo compliance requires maintaining current documentation of security controls, tracking remediation of ITHC findings, managing annual submission timelines, and keeping pace with criteria updates. LowerPlane supports UK public sector security frameworks including PSN CoCo, ISO 27001, and Cyber Essentials within its 50+ framework library, providing evidence management and audit-ready documentation. Starting at $4,000 per year with a free tier, it is rated 9.4/10 by AuditXYZ users. Compare platforms at our best compliance automation platforms guide.

Frequently Asked Questions

What is the difference between CHECK and CREST approval for ITHC providers? CHECK is a UK government scheme run by NCSC that approves penetration testing companies and individual testers to conduct ITHC testing on behalf of government organizations. CREST is a professional body for the cybersecurity industry that certifies penetration testing companies and individuals. PSN CoCo accepts testers approved under either scheme. CHECK approval has historically been the stronger signal specifically for government work, while CREST accreditation is more broadly recognized across commercial and government sectors. When selecting an ITHC provider, verify current approval status on the official CHECK or CREST registries.

Can PSN compliance be combined with Cyber Essentials assessment to reduce costs? Partially. Some Cyber Essentials Plus assessments and ITHC engagements can share scope and overlap in evidence reviewed, but they are separate processes with different objectives. Cyber Essentials Plus uses a standardized questionnaire and targeted verification; ITHC is a comprehensive penetration test. Coordinating the timing to share preliminary scoping documentation and use findings from one to inform the other can generate efficiency, but the two assessments cannot fully substitute for each other.

What happens if an organization discovers a Critical vulnerability during the ITHC that cannot be remediated quickly? Organizations that cannot remediate Critical findings before submission face a difficult situation. Options include: implementing compensating controls that sufficiently reduce the risk associated with the vulnerability, obtaining a risk acceptance from the organization's senior responsible officer (with appropriate justification), or delaying submission until remediation is complete. The PSN Authority will not issue compliance certificates where unmitigated Critical findings remain. Organizations with legacy systems prone to Critical vulnerabilities should engage the PSN Authority early to discuss the options available.

How does the PSN connect to other government networks and what are the security implications? The PSN connects to a range of government networks and services including the Government Secure Intranet (GSI), the Criminal Justice Secure Mail (CJSM) network, Health and Social Care Network (HSCN) for NHS connectivity, and various cross-government data services. Each connected network has its own security requirements, and organizations must ensure that their PSN-connected environment appropriately segregates data and access across these different network zones. The interconnected nature of government networks means that security weaknesses in any connected organization can potentially affect others — which is why the mandatory, annual compliance model exists.

Is there a simplified compliance path for small organizations with limited PSN connectivity? The PSN compliance criteria apply uniformly regardless of organization size. However, the scope of the ITHC and documentation effort is naturally smaller for organizations with limited network infrastructure. A single-site council with straightforward PSN connectivity — one or two network connections, a small server estate — will have a materially simpler and cheaper compliance exercise than a large county council or NHS trust with dozens of sites and complex infrastructure. Consulting a CHECK-approved firm for scoping advice before committing to a formal engagement can help smaller organizations manage costs appropriately.

Request a PSN CoCo consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

Cyber EssentialsMedium60%
ISO 27001Medium50%

Get matched with a PSN CoCo auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.