Cyber Resilience Audit (CRA) scheme launches for assured CAF-based audits
NCSC-assured CRA service now offering Cyber Assessment Framework based audits and more applications invited from potential service providers.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

In August, I had the pleasure of letting you know that we were ready to accept applications from companies to become NCSC-assured Cyber Resilience Audit (CRA) service providers. This announcement was the result of months of committed collaboration and effort from colleagues across the NCSC, wider government and cyber oversight bodies.
This month, I’m delighted to say that organisations are now able to buy CRA services from the initial - but growing - list of NCSC assured providers who can conduct independent Cyber Assessment Framework (CAF) based audits.
Most, if not all, of these companies will also list themselves on Crown Commercial Services CSS3 framework.
These companies have all met the minimum requirements for scheme membership and are now eligible to put themselves forward to conduct audits in specific sectors – providing they meet any additional requirements laid down by the relevant oversight body.
At this stage, the following oversight bodies are early adopters of the Cyber Resilience Audit scheme, with others expected to follow:
If you are an organisation in sectors overseen by these bodies, they will let you know directly what their expectations are regarding auditing your CAF returns, and whether they are making specific arrangements to enable you to buy from assured providers.
This is just the beginning - we expect more oversight bodies to develop their independent CAF audit programmes and will announce those in due course. We will also work with oversight bodies to monitor and develop the scheme and use the outputs to better understand the resilience of the UK as a whole.
We continue to accept applications from potential providers. The scheme standard and associated documentation are all available from our website.
As always, we remain determined that companies of any size can apply to join any of our schemes. We particularly welcome companies located in or serving geographically remote or under-represented areas. Similarly, if your company is working hard to address issues of under-representation in the cyber security workforce, we’d love to see your application.
We are taking action to remove artificial barriers to entry to all our schemes. So, if you spot something which you think unfairly prevents you from applying, please let us know.
