====== Pall Mall Process Code of Practice for States (2025) ====== //As of 1 October 2026. Information only, not legal advice – see the [[about:disclaimer|disclaimer]].// ^ Full title | The Pall Mall Process Code of Practice for States (commercial cyber intrusion capabilities) | ^ Type | Political commitment (non-binding code of practice) | ^ Adopted by | States participating in the Pall Mall Process, launched by France and the United Kingdom | ^ Adopted | Published on 4 April 2025 following the Paris conference of the Pall Mall Process (3–4 April 2025); updated list of supporting States 23 October 2025 | ^ Legal status | Voluntary and non-binding; according to the October 2025 version, supported by 27 States | ^ Official text | [[https://www.gov.uk/government/publications/the-pall-mall-process-code-of-practice-for-states|UK Government – The Pall Mall Process Code of Practice for States]] | ^ Subject area | Cybersecurity, cybercrime and critical infrastructure; Use of force, intervention and cyber operations | ===== Overview ===== The Pall Mall Process is an initiative of France and the United Kingdom on the proliferation and irresponsible use of commercial cyber intrusion capabilities, such as commercially available spyware and hacking services. The Code of Practice for States sets out commitments for State action in relation to the development, facilitation, purchase and use of such capabilities, structured around four pillars: accountability, precision, oversight and transparency. The text describes itself as a "voluntary and non-binding" code. A separate set of guidelines for industry has been the subject of a consultation (20 November 2025 – 16 January 2026). ===== Provisions relevant to the cyber and information sphere ===== * **Accountability** – commitments regarding State conduct when developing, facilitating, purchasing or using commercial cyber intrusion capabilities. * **Precision** – commitments concerning the targeted and lawful use of such capabilities. * **Oversight** – commitments concerning domestic legal frameworks and oversight mechanisms. * **Transparency** – commitments concerning transparency towards the public and other States. ===== Application to cyber and information operations ===== The Code complements the UN framework of responsible State behaviour in the use of ICTs ([[law:un:ict_norms]]) by addressing the commercial market for intrusion capabilities. According to the October 2025 version, the supporting States are Austria, Belgium, Denmark, Estonia, Finland, France, Germany, Ghana, Greece, Hungary, Italy, Ireland, Japan, Kosovo, Latvia, Luxembourg, Moldova, the Netherlands, Poland, the Republic of Korea, Romania, Slovakia, Slovenia, Sweden, Switzerland, the United Kingdom and the United States. ===== Recent developments ===== * 2025-04-04: Code of Practice for States published after the Paris conference (UK Government). * 2025-10-23: Belgium added as a supporting State (UK Government). * 2025-11-20 to 2026-01-16: UK and France consult on industry practices for commercial cyber intrusion capabilities (UK Government). ===== Related entries ===== * [[law:un:ict_norms]] * [[law:soft:paris_call]] * [[law:hr:iccpr]] * [[law:coe:budapest]] ===== Sources ===== * [[https://www.gov.uk/government/publications/the-pall-mall-process-code-of-practice-for-states|UK Government, The Pall Mall Process Code of Practice for States (last updated 23 October 2025)]], accessed 2026-10-01 * [[https://assets.publishing.service.gov.uk/media/68f902996a52e8a2726dc2f6/The-Pall-Mall-Process-Code-of-Practice-for-States-October-update.pdf|Code of Practice for States, October 2025 version (PDF)]], accessed 2026-10-01 * [[https://www.gov.uk/government/news/uk-and-france-seek-views-on-commercial-cyber-intrusion-industry-practices|UK Government, UK and France seek views on commercial cyber intrusion industry practices]], accessed 2026-10-01 ===== Change log ===== * 2026-10-01: Entry created.