The Pall Mall Process has an adopted voluntary code for states, but its separate industry guidelines are still being negotiated. As of 5 October 2026, no final company-facing guidance had been published; a civil-society submission said it was expected in November.
What the Pall Mall Process is trying to address
Launched by the UK and France in February 2024, the Pall Mall Process brings governments, industry and civil society together to address the development, facilitation, purchase and use of commercially available cyber intrusion capabilities. Its founding declaration recognizes that such capabilities can support legitimate and responsible activity, while warning that proliferation and irresponsible use can threaten cyberspace stability, human rights, fundamental freedoms and applicable international law.
The term covers more than a single category of hacking software. The UK National Cyber Security Centre’s 2026 industry consultation lists vulnerability research, exploit development, malware creation, command and control, hacking-as-a-service and access-as-a-service. The supply chain can run between businesses or involve direct sales to government end users, including law-enforcement and intelligence services. These are examples of the consultation’s scope, not a finalized legal definition.
What exists now—and what is still pending
The process has two distinct tracks. The first is an agreed, state-facing code; the second is proposed guidance for organizations in the industry. The April 2025 code does not itself establish the pending company expectations.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
- A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
- FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
- Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
- Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
- Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.
| Question | Code of Practice for States | Industry guidelines |
|---|---|---|
| Who is it for? | States and international organisations supporting the code. | Organizations involved in developing, selling, purchasing and using commercial cyber intrusion capabilities, according to the UK parliamentary record on the negotiations. |
| Status | Launched in April 2025; expressly voluntary and non-binding. | Negotiations began on 21 July 2026; not finalized as of 5 October 2026. |
| What is established? | Four guiding pillars: accountability, precision, oversight and transparency. Its treatment of state activity is subject to domestic legal frameworks, jurisdictional limits and relevance to particular capabilities. | No agreed final provisions were available by 5 October 2026. The pillars and open design questions discussed below are not a substitute for the negotiated text. |
The official Code of Practice says its supporters seek to tackle “the challenges posed by the proliferation and irresponsible use” of commercial cyber intrusion capabilities. Support has grown over time: a UK-France communiqué reported 21 participating governments supporting the code on 4 April 2025; the NCSC’s 2026 consultation introduction later reported 27 states had signed it. Those are dated snapshots from different publishers, not a verified total for 5 October 2026.
Why the voluntary industry rules matter
Tools and services in this market can be used for security work, law enforcement or national security, but the same capabilities can also facilitate intrusion and human-rights abuse. The process is therefore trying to address both legitimate use and the risks of proliferation without treating every capability or use as identical.
Rank #2
- Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
- FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
- Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
- Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
- Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.
A state code and company-facing guidance can influence expectations, but voluntary rules are not a law, treaty or certification. The existing code is explicitly non-binding, and the industry guidelines were still under negotiation at the date above. Their practical value will depend on what they ask organizations to do and whether those expectations can be assessed and acted on.
What negotiators and stakeholders are weighing
A January 2026 CyberScoop account described several unresolved design questions raised in discussion: which actors and activities should be covered, what would encourage organizations to adopt the guidance, how compliance could be measured, and how to address companies with problematic histories. The discussion was held under Chatham House rules, so individual views should not be attributed to participants.
Recommended Free Tools
Rank #3
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Those questions can be used to assess the eventual guidelines, but they are not agreed provisions. Four practical tests are especially relevant:
- Scope: Does the guidance clearly identify covered actors and activities across the supply chain, including researchers, exploit developers and service providers?
- Accountability: Does it set expectations for due diligence, customer scrutiny and responding to misuse in ways that can be assessed?
- Safeguards: Does it translate oversight, precision, transparency and human-rights responsibilities into meaningful practice?
- Adoption and consequences: Does it explain incentives for participation, how adherence will be monitored, and what happens when an organization does not follow the expectations?
These tests reflect the state code’s stated pillars and issues reported in the discussion; they should not be read as a preview of settled industry rules.
Rank #4
- Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
- NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
- FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
- Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
- Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.
What civil-society groups are asking for
A joint civil-society submission published on 17 September 2026 said the guidelines were expected to be finalized in November 2026. It called for a clear minimum baseline and argued that alignment with a voluntary code would not, by itself, demonstrate that a company had fulfilled its human-rights responsibilities. These are the submission’s recommendations, not agreed language in a final code. Because November was still ahead on 5 October, the expected completion date was not confirmation that negotiations had concluded.
The distinction matters for readers judging claims of responsibility: a company’s participation or stated alignment would not alone answer whether its practices adequately address human-rights risks. The eventual text and how organizations apply it will determine what can be meaningfully assessed.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →What to watch next
The next significant milestone is publication of the negotiated industry guidelines. Their wording should clarify who is covered, what responsible practice entails, and whether adoption comes with ways to monitor or respond to non-compliance. Until that text is available, the firmest commitments remain those in the state code, while the scope and force of the company-facing expectations remain unsettled.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

