GOVCybersecurity Governance
align security roles, policy, risk appetite and oversight with organisational objectives
Professional assessment of cybersecurity governance, risk treatment, control assurance, identity and access, incident response, resilience and security ethics.
Assesses cybersecurity governance and risk competence including governance, risk treatment, security controls, identity and access management, incident response, resilience and professional ethics.
These are example professional profiles; final eligibility is determined by the active scheme requirements.
Route A: relevant qualification + professional experience · Route B: professional experience · Route C: portfolio / evidence route. The active scheme determines which routes are available and what evidence is sufficient.
Assessment is distributed across the following competency domains according to the scheme weighting.
GOValign security roles, policy, risk appetite and oversight with organisational objectives
RISKidentify, analyse, prioritise and treat cyber risks using defined criteria
CTRLselect, implement and test proportionate preventive, detective and corrective controls
IAMapply identity lifecycle, least privilege and privileged-access controls
IRdetect, contain, recover and learn from security events using controlled response plans
ETHprotect confidentiality, act within authority and report material concerns
Certification depends on eligibility and successful completion of all required assessment components, not payment or course attendance alone.
Component pass: ≥ 65%
Component pass: ≥ 70%
Component pass: ≥ 70%
≥ 70%
The same exam rules apply to all candidates while question forms are assembled randomly from the controlled blueprint and published competency domains.
Approved active items are mapped to competency domains and difficulty, with selection weighted to the scheme domains.
Every attempt is randomised; the system does not rely on a fixed 20-question form that can simply be memorised.
Pass thresholds: knowledge 65%, ethics 70%, practical 70% and weighted overall 70%, with every required component passed.
The UKG model operates through defined certification schemes, impartiality controls, documented assessment and an independently governed, auditable certification decision.
One clear route from registration through credential issue and online verification.
Review scope, fee and application status, then start from the official certification page.
Complete the candidate account, legal identity and contact details in the secure portal.
Upload CV, experience, qualifications or portfolio evidence under the applicable eligibility route.
Once the application can proceed, the fee and controlled assessment access are handled.
Complete the controlled examination mapped to the active blueprint and competency domains.
Complete a practical case or work product scored against a controlled rubric.
When all components and thresholds are complete, the case enters the controlled certification-decision stage; exceptions are routed to authorised review.
After a Certified decision, the credential and supporting documents are issued and linked to live verification.
A4 credential with unique ID, issue/expiry dates, status and QR verification.
Controlled record of competency domains and assessment component outcomes.
Formal confirmation of the credential and current online status.
Summary of assessment method, thresholds and recorded result.
Scope, competency model, validity, maintenance and recertification rules.
Supporting documents linking the candidate, application, assessment and credential.
The published fee covers the UKG application and eligibility workflow, controlled examination access, practical assessment, certification-decision workflow and the standard digital credential document set if the candidate is certified. Taxes, retakes or exceptional third-party verification may be charged separately where applicable.
Start with the basic details below, then complete identity and evidence securely in the candidate portal.
Standard validity is 36 months. Maintenance and recertification follow the scheme requirements and credential lifecycle status.
Every issued credential carries a unique credential ID and live verification record. The current online status is the authoritative reference.
A UKG credential records successful completion of a defined professional certification scheme and presents the competencies assessed and current credential status. Each receiving organisation determines how it will use or recognise the credential under its own requirements.