As of 1 October 2026. Information only, not legal advice – see the disclaimer.
| Full title | The Pall Mall Process Code of Practice for States (commercial cyber intrusion capabilities) |
|---|---|
| Type | Political commitment (non-binding code of practice) |
| Adopted by | States participating in the Pall Mall Process, launched by France and the United Kingdom |
| Adopted | Published on 4 April 2025 following the Paris conference of the Pall Mall Process (3–4 April 2025); updated list of supporting States 23 October 2025 |
| Legal status | Voluntary and non-binding; according to the October 2025 version, supported by 27 States |
| Official text | UK Government – The Pall Mall Process Code of Practice for States |
| Subject area | Cybersecurity, cybercrime and critical infrastructure; Use of force, intervention and cyber operations |
The Pall Mall Process is an initiative of France and the United Kingdom on the proliferation and irresponsible use of commercial cyber intrusion capabilities, such as commercially available spyware and hacking services. The Code of Practice for States sets out commitments for State action in relation to the development, facilitation, purchase and use of such capabilities, structured around four pillars: accountability, precision, oversight and transparency. The text describes itself as a “voluntary and non-binding” code. A separate set of guidelines for industry has been the subject of a consultation (20 November 2025 – 16 January 2026).
The Code complements the UN framework of responsible State behaviour in the use of ICTs (ict_norms) by addressing the commercial market for intrusion capabilities. According to the October 2025 version, the supporting States are Austria, Belgium, Denmark, Estonia, Finland, France, Germany, Ghana, Greece, Hungary, Italy, Ireland, Japan, Kosovo, Latvia, Luxembourg, Moldova, the Netherlands, Poland, the Republic of Korea, Romania, Slovakia, Slovenia, Sweden, Switzerland, the United Kingdom and the United States.