Most UK public sector organisations connecting to the Public Services Network need a connection compliance certificate, and the first task is practical, not procedural: start the Code of Connection (CoCo), commission a network diagram no older than six months, and book an Independent Health Check (ITHC). Everything else in the process, from evidence packaging to submission, builds on those three items. GOV.UK’s PSN compliance guidance sets out the assurance framework; Specialist companies can support the technical preparation.
TL;DR:
- Organizations must ensure their network diagram is less than six months old and the ITHC report is no older than 12 months to meet submission requirements.
- Applying for multiple certificates simultaneously is possible but requires careful internal checks to confirm whether the network only consumes PSN services or also hosts services for others.
- Boundary protection, network segmentation, and strict patch management are critical technical controls that support a compliant architecture and influence assessor evaluations.
- Buying PSN services without verifying that the supplier maintains up-to-date certificates and evidence can lead to non-compliance despite certified suppliers.
- Recurrent certification failures often relate to outdated diagrams, insufficient test evidence, or operational non-compliance like missed patch windows and unfulfilled remediation plans.
Table of Contents
- Who needs PSN compliance and which certificate applies
- The PSN application checklist: step by step
- What assessors expect in your evidence pack
- Technical controls that support a compliant architecture
- Procurement checks for buyers of PSN-connected services
- Planning the compliance project: testing, verification and timing
- Common pitfalls that delay or rescind certification
- How Re-Solution supports a PSN compliance submission
- What the compliance process gets wrong, and what actually matters
- Getting compliance support from Re-Solution
- Sources
- FAQ
Who needs PSN compliance and which certificate applies
PSN compliance is not a single certificate. GOV.UK’s PSN connectivity service guidance describes three distinct cases, and choosing the wrong one wastes weeks of evidence gathering.
- Connection certificate: for organisations consuming PSN services, such as a local authority linking its network to central government systems.
- Service provision certificate: for organisations offering services to other PSN-connected bodies, for example a shared-services provider hosting applications for several councils.
- Connectivity service certificate: for suppliers of the underlying PSN or GCN transport, governed by a separate Code of Interconnection rather than the standard CoCo.
Some organisations need to apply for connection and service provision in parallel, particularly where a single network both consumes central services and hosts applications for partner bodies. Before committing resource, run a short internal check: does your network only consume PSN services, does it also host services for others, and does any part of your infrastructure carry PSN or GCN traffic on behalf of a third party? The answers determine which code and which certificate lifecycle apply, and mixing them up is the most common reason applications stall before they reach the PSN team.
The PSN application checklist: step by step
GOV.UK’s connection compliance certificate guidance sets out five practical steps, each with its own evidence requirement.
- Complete the Code of Connection (CoCo): work from the current version, CoCo v1.32, rather than an older internal template, since GOV.UK’s CoCo page shows the document has moved from CESG to NCSC references and updated password guidance.
- Produce a network diagram: a PDF, created within six months of submission, showing all connections, security devices, wireless access points and third-party links.
- Commission an ITHC: an independent penetration test covering the connection boundary, with a report no older than 12 months at submission.
- Update contact details: technical, security and management contacts must be current, since the PSN team will use them for surveillance and audit correspondence.
- Submit the package: CoCo, diagram, ITHC report and any remediation action plan (RAP) go to the PSN team together, not piecemeal.
Sign-off typically involves a senior information risk owner or equivalent, since the CoCo is a formal declaration of the organisation’s security posture, not a technical form. Most applications are dealt with in about four weeks once a complete package is submitted, and certificates typically have a validity period of about 12 months, according to GOV.UK’s connection certificate guidance.
Pro Tip: Build the network diagram and the ITHC scope document at the same time: mismatches between what the diagram shows and what the tester actually assessed are a frequent cause of rejected submissions.
What assessors expect in your evidence pack
The PSN team assesses documents, not intentions, so each artefact needs to meet a specific quality bar before it reaches review.
- Network diagrams need a creation date, a clearly marked scope boundary, all external connections, security devices such as firewalls and intrusion detection, wireless access points, and any third-party links, submitted as a PDF less than six months old.
- ITHC reports must cover the declared connection boundary, include findings with severity ratings, and be accompanied by a remediation action plan (RAP) for any unresolved issues, since an ITHC older than 12 months is not accepted.
- Test plans and scripts need enough detail for the PSN team to understand what was actually tested, and the PSN governance obligations guidance confirms the PSN team retains the right to review these documents before certification.
- Independent verification statements must confirm who ran the tests, that the results were independently checked, and that the report was shared with the PSN team as a condition of certification, not as an optional extra.
A diagram that shows a planned future state rather than the network as built is one of the most common reasons for a first-review rejection. Assessors expect the artefact to describe what exists on the day of submission, and organisations that keep diagrams under version control, tied to change records, tend to avoid this problem entirely. Re-Solution’s network assurance guidance covers the artefact standards IT teams need before an ITHC is booked.
Pro Tip: Ask your ITHC supplier to date-stamp the report cover page and cross-reference it to the diagram version it tested, so an assessor can match the two documents in seconds.
Technical controls that support a compliant architecture
PSN certification depends on demonstrable technical controls at the connection boundary, not just paperwork. GOV.UK’s PSN compliance guidance describes PSN as a controlled ‘walled garden’, because the security posture of one connected organisation can affect every other member.
- Boundary protection: place firewalls at every external connection point, apply deny-by-default rules, and restrict management interfaces to dedicated, authenticated access paths.
- Segmentation: separate OFFICIAL data flows from general corporate traffic, since clear segmentation gives assessors a concrete boundary to test rather than a flat, undifferentiated network.
- Patch management: apply security patches within defined windows according to severity levels, with patch timelines based on best practice standards, and keep configuration records under version control so CoCo artefacts stay traceable to actual device states.
- Dedicated connectivity: consider private circuits or dedicated links for PSN traffic where shared internet paths would complicate the boundary you need to defend.
PSN uses a controlled ‘walled garden’ approach because the security of one connected user can affect other users and the network. That single principle explains why assessors focus so heavily on boundary controls and segmentation evidence rather than general good practice statements.
Re-Solution’s Network Access Controller guide sets out practical NAC configurations that support this kind of segmentation on Cisco infrastructure.
Procurement checks for buyers of PSN-connected services
Buying a PSN-connected service does not transfer compliance responsibility entirely to the supplier. GOV.UK’s guidance on accessing or providing PSN services makes clear that supply agreements must contain specific clauses, and buyers who skip this step can find themselves non-compliant despite a fully certified supplier.
- Check the published list: confirm the service actually appears on the list of PSN-compliant services before signing anything.
- Insert the prescribed clauses: PSN standard terms and conditions require supply agreements to obligate both supplier and customer to maintain their respective certificates throughout the contract.
- Request supplier evidence: ask for ISO 27001 certification where relevant, recent surveillance or audit reports, and a data residency statement, since service provision guidance expects PSN services to be stored and managed within the UK, EU, EEA or a country with an equivalent data protection treaty.
- Ask for a take-on guide: a supplier should be able to describe, in writing, how a new customer’s connection is provisioned, tested and handed over.
Verification means checking the certificate is current, matches the specific service being bought, and has not lapsed since the supplier’s last surveillance review. Re-Solution’s outsourced network management checks cover the same territory for buyers assessing a managed network supplier.
Planning the compliance project: testing, verification and timing
Independent verification is a formal requirement for connectivity service applicants, not a discretionary quality step. The PSN governance obligations guidance states that test results must be independently verified and accompanied by a written report to the PSN team, and the PSN team retains review rights over test plans before they are executed.
- Expect around four weeks for most PSN applications once the package is complete, and plan for a certificate that runs for 12 months from issue.
- Budget for third-party testing early, since ITHC and independent verification providers need lead time to schedule, particularly ahead of financial year-end deadlines common across the public sector.
- Build in contingency: PSN team review cycles can extend beyond four weeks if diagrams or test evidence need revision, so treat that figure as a planning baseline, not a guarantee.
- Set acceptance criteria upfront for what a test report must contain, so a supplier or internal team knows what “done” looks like before testing starts.
Certificates run on a 12-month cycle, which means compliance is a recurring project, not a one-off milestone.
Common pitfalls that delay or rescind certification
Most delays trace back to a small number of recurring problems, and each has a straightforward fix.
Outdated or conceptual network diagrams are the most frequent cause of rejection. A diagram showing planned changes rather than the live network fails review immediately, so keep diagrams under change control and regenerate them ahead of every submission rather than reusing an old file.
Insufficient test evidence, or an ITHC missing a clear remediation action plan, stalls applications at the review stage. Assessors need to see not just findings but a credible plan to close them.
Operational non-compliance after certification is just as common as pre-certification failure: missed patch windows, supply agreements that never had the prescribed PSN clauses added, and remediation plans that were filed but never actioned all put a live certificate at risk of rescindment.
Pro Tip: Treat the ITHC and diagram as living documents tied to your change management process, not as one-off deliverables produced only when a certificate is due for renewal.
How Re-Solution supports a PSN compliance submission
Re-Solution works through a defined sequence for organisations preparing a PSN submission: audit the existing network, remediate the gaps that surface, coordinate the ITHC, package the evidence, and support submission to the PSN team. As a Cisco partner with over 35 years of experience in network infrastructure, Re-Solution builds the assessor-ready artefacts, including the current network diagram, a remediation action plan, and coordination with independent verification testers, that GOV.UK’s process requires. Organisations using Cisco ISE for access control can draw on Re-Solution’s experience configuring segmentation and boundary controls that map directly to PSN evidence expectations. Re-Solution’s network infrastructure checklist sets out the same artefact list in template form for teams preparing their own submission.
What the compliance process gets wrong, and what actually matters
The conventional advice treats PSN compliance as a paperwork exercise: fill in the CoCo, attach a diagram, wait for a certificate. That framing undersells the real work, which is architectural. An organisation with genuine boundary segmentation and disciplined patch management will sail through an ITHC that a poorly segmented network fails outright, no matter how well the CoCo form is completed.

The most overrated part of the process is the submission itself, since the PSN team’s four-week review is fast once a package is complete. The underrated part is diagram and configuration discipline between certificate renewals. Organisations that treat the 12-month cycle as a recurring compliance rhythm, rather than a deadline that appears once a year, avoid the scramble of producing a fresh diagram and rebooking an ITHC under time pressure.
Readers should prioritise the network architecture work first: segmentation, boundary controls and patch discipline. The documentation follows naturally once the network itself reflects what a diagram is supposed to show.
— Jacob
Getting compliance support from Re-Solution
Preparing a PSN submission alongside day-to-day network operations stretches most internal IT teams thin, particularly where an ITHC, a remediation plan and a fresh network diagram all need to land at the same time. Re-Solution’s Network Audits identify the gaps an assessor would flag before they reach a submission, and the accompanying Professional Services work covers the CoCo preparation, diagram production and ITHC coordination described throughout this guide.
For organisations that want ongoing compliance maintained rather than re-earned every 12 months, Network As A Service builds patch management, configuration control and boundary monitoring into a managed contract, so the artefacts a PSN renewal needs are already current when the certificate comes up for review. Get in touch through Re-Solution’s services page to scope a PSN compliance project.
Sources
FAQ
What is PSN compliance in simple terms?
PSN compliance is the process of demonstrating that an organisation’s security policies, controls and connection boundary meet the standard needed to interact safely with the Public Services Network. It is an assurance case around a defined connection, not a certification of individual devices, as set out in GOV.UK’s PSN compliance guidance.
How long does a PSN certificate last?
A PSN connection certificate is normally valid for 12 months from issue, after which the organisation must reapply with updated evidence. This applies to connection compliance certificates and to connectivity service certificates alike.
How old can the network diagram and ITHC be?
The network diagram submitted with a PSN connection application must be a PDF created less than six months before submission, and the ITHC report must be no older than 12 months. Both requirements come from GOV.UK’s connection certificate guidance, and submitting an outdated version of either is a common reason for rejection.
Do I need independent verification for my PSN application?
Independent verification of test results is a mandatory condition for many connectivity service applicants, requiring a written report to the PSN team confirming the results were independently checked. This requirement is set out in PSN governance obligations for connectivity services, and applicants should factor testing lead times into their project plan.
What should I check before buying a PSN-connected service?
Confirm the service appears on the published list of PSN-compliant services, and check the supply agreement includes the prescribed clauses requiring both supplier and customer to maintain their PSN certificates. GOV.UK’s guidance on accessing or providing PSN services sets out these procurement obligations in detail.
Recommended
- Pass Cyber Essentials Plus in 6–12 Weeks: UK NCSC Pre Audit Checklist
- Cybersecurity compliance basics: 2026 guide for IT teams
- PCI network segmentation: how to make it count for assessors
- Network infrastructure checklist: optimise compliance







