Skip to main content

Assured Cyber Incident Response scheme – important updates

We’ve updated the CIR 'Enhanced Level' scheme standard and will be ready to accept applications in the new year.
ThinkNeo via Getty Images

Are you a current or aspiring member of the NCSC-assured Cyber Incident Response (CIR) scheme?

First and foremost, I am pleased to let you know that we will be ready to accept applications in the new year from companies wishing to join the Assured Cyber Incident Response scheme. We are telling you now because we have also made some important changes to the scheme’s technical standard, ways of working and pre-qualifying criteria, as well as agreeing a name change.

Renaming the Levels

Cyber Incident Response is offered at two levels - “Level 1” and “Level 2”. However, it has become increasingly clear that these are not helpful labels for either assured organisations or for their customers. Given our desire to reduce opacity and confusion as much as possible, we have been keen to find something better.

As a result, Level 1 is now being renamed ‘Enhanced Level’ and Level 2 becomes ‘Standard Level’. We hope that these, more descriptive, terms will help everyone to quickly understand the criteria against which a scheme member has been assessed and, as a result, what capability they have. There is more information on our website about these differences.

Enhanced Level scheme standard

Again, in the spirit of improving clarity, we have made the following improvements and changes:

  • We have introduced a new pre-requisite for all companies to successfully join, and remain members of, the Cyber Incident Response scheme at the Standard Level*, before applying to join at the Enhanced Level.
  • We require all Enhanced Level applicants to hold a Cyber Essentials Plus certificate for all the systems on which information relating to customers’ engagements is stored and processed.
  • We have changed the qualification requirements for Head Consultants at the Enhanced Level. We will now only accept Head Consultants who hold a UK Cyber Security Council Title in the Incident Response specialism at the 'Chartered' level. Information on the Incident Response specialism and how to apply for the Chartered Title will be available from the UK Cyber Security Council's webpage: Become Professionally Registered. We expect the application process to be open from early January 2025.
  • We have provided clarification of what we mean by an ‘Advanced Persistent Threat’ and made that the foundation stone of any application to join the scheme at the Enhanced Level.
  • We have clarified our position regarding organisations responding to incidents in environments using specialist technologies (such as Operational Technology).
  • One person’s ‘large’ is another person’s ‘average’, so we’ve given definitions and indications of what we mean wherever we have used potentially subjective language.

*Please see the webpages of our Delivery Partners CREST and IASME for more information.

Other updates

In addition, we have taken the opportunity to improve and rationalise the documentation supporting the scheme by:

  • Separating out the scheme standard and requirements, from information about working practices, which apply only once a company has joined the scheme.
  • Rationalising the information captured in the application form to clarify what evidence we require. This should help applicants to focus their evidence and make it easier for the assessors to identify evidence which meets the standard.
  • Updating language and formatting to try to improve accessibility.

All the documents are available from the Information for service providers page. However, if there is more we can do, please let us know.

As always, we are looking forward to receiving applications from aspiring new CIR - Enhanced Level suppliers. Please do get in touch if you have any questions or comments.

Catherine H
Head of Assured Professional Services Schemes, Industry Assurance

Written by

Catherine H Head of Assured Professional Services Schemes, Industry Assurance, NCSC

Published