Summary
- The government says 18 of 72 critical systems referenced in the NAO's cyber resilience report have been formally reassessed.
- GovAssure operates in annual tranches, meaning systems can remain in remediation without immediately undergoing another assessment.
- The figure lands alongside a £210 million Government Cyber Action Plan intended to address persistent weaknesses in public-sector resilience.
The UK government says 18 of the 72 critical systems highlighted in a National Audit Office assessment of cyber resilience have since been formally reassessed, as departments continue remediation work across the wider estate.
The UK government said the systems were originally assessed through GovAssure, its cyber assurance programme for critical government technology. The figure was disclosed in response to a parliamentary question asking how many systems identified as having significant resilience gaps had subsequently been reviewed again.
Ian Murray, answering for the Department for Digital, Culture, Media and Sport on 10 September, said: “Of the 72 assessed systems referenced in the report, 18 have been reassessed since publication.”
The answer does not mean the remaining 54 systems have received no remediation. GovAssure assesses critical systems in annual tranches, with Critical National Infrastructure systems prioritised, and departments work through Targeted Improvement Plans after an assessment. The government said systems may therefore be undergoing remediation without being immediately reassessed the following year.
The distinction between remediation activity and formal reassessment is central to interpreting the figure. A reassessment provides evidence about whether controls have improved after weaknesses were identified; an improvement plan records intended or ongoing work but does not by itself demonstrate that the resulting system meets the required resilience outcome.
The National Audit Office’s January 2025 Government cyber resilience report concluded that resilience levels were lower than government had previously estimated and that departments had significant gaps in controls fundamental to cybersecurity.
It also warned about the condition of ageing legacy systems. The NAO said resilience across hundreds of legacy IT systems was likely to be worse and that departments lacked fully funded remediation plans for half of the vulnerable systems it examined. The report concluded that government would miss its then-target of making critical functions resilient to cyber attack by 2025.
The government has since replaced that policy framework with the Government Cyber Action Plan, published in January 2026 and backed by more than £210 million. The programme sets expectations for cyber resilience across public services and includes a Government Cyber Unit intended to coordinate risk management and incident response.
The action plan itself acknowledges the scale of the problem. It describes cyber risk to the public sector as critically high and cites widespread low maturity in fundamental controls identified through GovAssure, including asset management, protective monitoring, and response planning. It also estimates that 28% of the government technology estate consists of legacy technology.
That creates an assurance problem extending beyond the number of systems patched or projects funded. Central government needs sufficient evidence to establish whether remediation changes the security position of systems delivering essential functions, particularly where ageing technology, complex dependencies, and skills shortages make replacement difficult.
GovAssure was designed partly to improve that evidence base by applying a common approach to assessing critical systems against the government’s Cyber Assessment Framework. Annual tranches allow departments to sequence work across large estates, but they also mean headline reassessment numbers can move more slowly than remediation activity underneath them.
The latest parliamentary answer does not provide a breakdown of the 18 reassessed systems, their departments, how many have closed previously identified gaps, or the status of improvement plans covering the other 54. Nor does it establish how many of the systems are associated with Critical National Infrastructure functions.
Those omissions limit how far the reassessment figure can be used as a measure of actual resilience. Formal assurance is only one stage of the process, but without comparable follow-up results it is difficult to judge from public information how quickly the weaknesses identified by the NAO are being reduced.
The £210 million Cyber Action Plan represents a larger central intervention than existed when the NAO conducted its work, including new coordination, vulnerability management, and accountability measures. The next test will be whether those programmes produce measurable improvements across the systems already known to carry significant gaps, rather than simply expanding the machinery used to assess them.




