UK Gambling Commission — Cyber Resilience Requirements
The UK Gambling Commission's cyber resilience requirements, set out in the Licence Conditions and Codes of Practice (LCCP), mandate that all licensed gambling operators implement appropriate cybersecurity measures. Key requirements include protection of player data, system integrity for fair gaming, financial transaction security, and incident reporting. The Commission's Remote Technical Standards set specific technical security requirements for online gambling systems. Operators must meet these as a condition of their licence.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (27)
AML
| Code | Title |
|---|---|
| UKGC-RTS-8 | Anti Money Laundering Technical Controls |
Annual Security Audit Requirements
| Code | Title |
|---|---|
| RTS Audit-1 | Third-party annual security audit |
| RTS Audit-2 | Audit scope aligned with ISO 27001 |
| RTS Audit-3 | Submission of audit reports |
| RTS Audit-4 | New licensee initial audit |
Audit Cadence
| Code | Title |
|---|---|
| UKGC-RTS-2 | Annual Security Audit Cycle |
Authentication
| Code | Title |
|---|---|
| UKGC-RTS-5 | Customer Authentication and Account Protection |
Customer Display
| Code | Title |
|---|---|
| UKGC-RTS-15 | Display of Net Position to Customer |
Customer Funds
| Code | Title |
|---|---|
| UKGC-RTS-6 | Customer Funds Protection and Segregation |
Game Integrity
| Code | Title |
|---|---|
| UKGC-RTS-4 | Game RNG and Outcome Verification |
Geo Compliance
| Code | Title |
|---|---|
| UKGC-RTS-11 | Geo-location and Jurisdictional Compliance |
Governance
| Code | Title |
|---|---|
| UKGC-RTS-17 | Personal Management Licence Accountability |
Incident Reporting
| Code | Title |
|---|---|
| UKGC-RTS-13 | Incident Reporting to the Commission |
Logging
| Code | Title |
|---|---|
| UKGC-RTS-7 | Critical Event Logging |
Marketing
| Code | Title |
|---|---|
| UKGC-RTS-18 | Marketing Compliance and Affiliate Oversight |
Payments
| Code | Title |
|---|---|
| UKGC-RTS-19 | Alternative Payment Method Controls |
RTS Section 1 — Introduction and Scope
| Code | Title |
|---|---|
| RTS 1.1 | Scope of technical standards |
| RTS 1.2 | Critical systems definition |
| RTS 1.3 | Applicability to licensees |
RTS Section 4 — Security Requirements (Organisational Controls)
| Code | Title |
|---|---|
| RTS 4.1 | Information security policies |
| RTS 4.2 | Organisation of information security |
| RTS 4.3 | Access management and identity controls |
| RTS 4.4 | Supplier relationship security |
| RTS 4.5 | Incident management |
| RTS 4.6 | Independent review and audit |
RTS Section 4 — Security Requirements (People Controls)
| Code | Title |
|---|---|
| RTS 4.10 | Security event reporting |
| RTS 4.7 | Security awareness training |
| RTS 4.8 | Employment screening and termination |
| RTS 4.9 | Remote working security |
RTS Section 4 — Security Requirements (Physical Controls)
| Code | Title |
|---|---|
| RTS 4.11 | Equipment protection |
| RTS 4.12 | Storage media handling |
| RTS 4.13 | Secure disposal practices |
RTS Section 4 — Security Requirements (Technological Controls)
| Code | Title |
|---|---|
| RTS 4.14 | User device and endpoint security |
| RTS 4.15 | Privileged access management |
| RTS 4.16 | Authentication mechanisms |
| RTS 4.17 | Malware protection |
| RTS 4.18 | Backup and recovery |
| RTS 4.19 | Logging and monitoring |
| RTS 4.20 | Cryptography |
| RTS 4.21 | Secure development and change management |
| RTS 4.22 | Network security |
Regulatory Reporting
| Code | Title |
|---|---|
| UKGC-RTS-20 | Annual Assurance Statement and Regulatory Returns |
Resilience
| Code | Title |
|---|---|
| UKGC-RTS-14 | Data Backup and Recovery |
Safer Gambling
| Code | Title |
|---|---|
| UKGC-RTS-9 | Safer Gambling Technical Controls |
Security Audit
| Code | Title |
|---|---|
| UKGC-RTS-1 | Security Audit Scheme Compliance |
Security Requirements
QKD module and network security
Security Testing
| Code | Title |
|---|---|
| UKGC-RTS-10 | Penetration Testing Requirements |
System Integrity
| Code | Title |
|---|---|
| UKGC-RTS-3 | Gambling System Integrity Controls |
Third Party Risk
| Code | Title |
|---|---|
| UKGC-RTS-12 | Third Party Game Supplier Assurance |
Vulnerability Management
| Code | Title |
|---|---|
| UKGC-RTS-16 | Vulnerability Management Programme |
Your Compliance Coverage
If you comply with UK Gambling Commission — Cyber Resilience Requirements, you already cover:
NIST SP 800-82 Rev 3 — Guide to OT Security
35%
17 controls mapped
Compare →ASD Information Security Manual (ISM)
35%
17 controls mapped
Compare →TISAX — Trusted Information Security Assessment Exchange
35%
17 controls mapped
Compare →+ 620 more: AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) (31%), CFTC System Safeguards (17 CFR 37, 38, 39, 49) (31%)
See all 623 mapped frameworks ↓Maps to 623 other frameworks
Frequently Asked Questions
What is UK Gambling Commission — Cyber Resilience Requirements?
UK Gambling Commission — Cyber Resilience Requirements is a compliance framework from United Kingdom (Gambling Commission) with 27 domains and 49 controls. The UK Gambling Commission's cyber resilience requirements, set out in the Licence Conditions and Codes of Practice (LCCP), mandate that all licensed gambling operators implement appropriate cybersecurity measures. Key requirements include protection of player data, system integrity for fair gaming, financial transaction security, and incident reporting. The Commission's Remote Technical Standards set specific technical security requirements for online gambling systems. Operators must meet these as a condition of their licence. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does UK Gambling Commission — Cyber Resilience Requirements have?
UK Gambling Commission — Cyber Resilience Requirements has 49 controls organised across 27 domains. The largest domains are RTS Section 4 — Security Requirements (Technological Controls) (9 controls), RTS Section 4 — Security Requirements (Organisational Controls) (6 controls), Annual Security Audit Requirements (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does UK Gambling Commission — Cyber Resilience Requirements map to?
UK Gambling Commission — Cyber Resilience Requirements maps to 623 other compliance frameworks. The top mapping partners are NIST SP 800-82 Rev 3 — Guide to OT Security (35% coverage), ASD Information Security Manual (ISM) (35% coverage), TISAX — Trusted Information Security Assessment Exchange (35% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with UK Gambling Commission — Cyber Resilience Requirements compliance?
Start your UK Gambling Commission — Cyber Resilience Requirements compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UK Gambling Commission — Cyber Resilience Requirements requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 49 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required