Public Sector

We've had the pleasure of working with UK and overseas central and local government departments, including Healthcare (NHS and Foundation Trusts), Defence, Education (Universities and colleges), many of the main Civil Service departments, Emergency Services; also public-owned corporations including the BBC, Bank of England, Ordnance Survey, and regulatory bodies such as Ofgem.

We are registered on Crown Commercial Service’s (CCS) Dynamic Purchasing System (RM6219 Training and Learning) and also with numerous tender portals such as Ariba, Coupa and Delta E-Sourcing.

Read more...

Graduate Training Schemes

Framework Training has a strong track record of providing a solid introduction into the working world for technical graduates across myriad industries. We provide the opportunity to learn and gain valuable hands-on experience in a supportive, friendly and sociable training environment.

Attract & retain the brightest new starters

We know it is vital for our clients to invest in the future of their talented grads; not only to provide them with high-quality, professional training essential for their roles, but to embed them within the organisation’s culture and guide them on the right path to a successful career.

After all, your new hires could well be the next leaders and their creative ideas and unique insights are invaluable to your business.

Read more ...

Learning & Development

Our unique portfolio of high-quality technical courses and training programmes are industry-respected. They’re carefully designed so that delegates can seamlessly apply what they’ve learnt back in the workplace. Our team of domain experts, trainers, and support teams know our field — and all things tech — inside out, and we work hard to keep ourselves up to speed with the latest innovations. 

We’re proud to develop and deliver innovative learning solutions that actually work and make a tangible difference to your people and your business, driving through positive lasting change. Our training courses and programmes are human-centred. Everything we do is underpinned by our commitment to continuous improvement and learning and generally making things much better.

Read more...

Corporate & Volume Pricing

Whether you are looking to book multiple places on public scheduled courses (attended remotely or in our training centres in London) or planning private courses for a team within your organisation, we will be happy to discuss preferential pricing which maximise your staff education budget.

Enquire today about:

  • Training programme pricing models  

  • Multi-course voucher schemes

Read more...

Custom Learning Paths

We understand that your team training needs don't always fit into a "one size fits all" mould, and we're very happy to explore ways in which we can tailor a bespoke learning path to fit your learning needs.

Find out about how we can customise everything from short overviews, intensive workshops, and wider training programmes that give you coverage of the most relevant topics based on what your staff need to excel in their roles.

Read more...

Beyond the Checklist: Preparing for the UK Cyber Security and Resilience Bill

The UK Cybersecurity and Resilience Bill is turning best practices into legal requirements. Learn what engineering teams need to do now - from SBOMs to DevSecOps - and how Framework Training's 2026 courses can help you get ready.

May 11th, 2026

Software security has never been more important. For years, elements like Software Bills of Materials (SBOMs), automated vulnerability scanning, and secure-by-design principles were considered "gold standards" for elite engineering teams - but often neglected when the focus was on continuous deployment of new features.

With the introduction of the UK Cyber Security and Resilience Bill (and its EU counterpart, the Cyber Resilience Act), these are no longer optional extras. The defined spectrum of Relevant Managed Service Providers (RMSPs) is widening, too.

If you build, sell, or operate digital services in the UK, regulations will now stipulate that you are responsible for the security of your entire supply chain. This means knowing exactly what is in your code, who wrote your dependencies, and how you plan to fix vulnerabilities when they inevitably appear.

"Compliance used to be a documentation exercise ...in 2026, it’s an engineering exercise. If you can’t sign your images and scan your manifests automatically, you aren't ready for this bill."
- Tom Walker, Technical Director, Framework Training

What the Bill actually requires

The legislation focuses on moving away from "reactive" security and toward demonstrable resilience. Key pillars include:

  • Secure-by-Design by default
    Security can't be a "bolt-on" at the end of a sprint; it must be the foundation of the architecture.

  • Supply Chain Transparency
    You must be able to produce an SBOM (Software Bill of Materials) - essentially a list of ingredients for your software-on demand.

  • Vulnerability Management
    Fixed timelines for patching and reporting are no longer suggestions; they are mandates.

  • Evidence-based Assurance
    Regulators will expect to see logs, audit trails, and cryptographic proof of secure workflows.

Turning legislation into implementation

At Framework Training, we believe the best way to prepare for new legislation isn't to hire more lawyers, but to build better engineering habits. We’ve aligned our 2026 curriculum to address these exact regulatory hurdles.

1. Mastering the Container Supply Chain

Containers are the heartbeat of modern infrastructure, but they are also a primary source of supply chain risk. Our new Docker Security Workshop is designed specifically to address the legislative focus on transparency and provenance.

In this session, we move beyond basic builds to look at image signing, manifest management, and generating CycloneDX/SPDX-compliant SBOMs.


2. Shifting Security Left with DevSecOps

Compliance shouldn't slow down your deployment. The "DevSecOps" mindset integrates automated security gates directly into your CI/CD pipelines, providing the "evidence-based assurance" that regulators demand without sacrificing velocity.


3. Language-Specific Secure Coding

A "one-size-fits-all" security talk isn't enough. The UK Bill emphasises "Secure-by-Design" code, which looks very different in a memory-safe language like Java or Python than it does in a systems-level environment. We provide deep-dive workshops tailored to your specific stack - here are a few examples:

The bottom line

The UK Cyber Security and Resilience Bill is a fundamental step change in national security. For engineering teams, it represents an opportunity to formalise better ways of working. By investing in these skills now, you aren't just checking a compliance box - you’re building a more reliable, more professional, and more resilient business.

Share this post on:

We would love to hear from you

Get in touch

or call us on +44 (0) 20 3137 3920