Skip to main content

One small step for Cyber Resilience Test Facilities, one giant leap for technology assurance

CRTFs are helping organisations to make informed, risk-based decisions on the adoption of technology products.
Moor Studio via Getty Images

At CYBERUK 2025, we announced the NCSC’s new Cyber Resilience Test Facilities (CRTFs), a national network of assured facilities to help technology vendors demonstrate the cyber resilience of their products, and some services.

We’re pleased to announce that the first products to go through CRTFs have now had their reports issued. This demonstrates that we can successfully delegate scalable assurance activities to UK industry in a consistent and structured way, using NCSC-approved standards and techniques.

The use of transparent standards creates a much more predictable, repeatable and economically viable way to gain trust in products than previous assurance approaches.  More importantly, this principles-based approach to assurance – which focuses on risk rather than compliance – provides useful advice both to vendors and customers to improve product development, integration, and risk management.

All products assessed via CRTFs are issued a report that provides information on their performance against relevant principles, detailing the risks and putting the management and ownership of these risks into the hands of those who will be best positioned to judge the impacts.

Crucially, using this process there is no ‘pass’ or ‘fail'. Rather, the report allows the customer to evaluate the individual areas assessed in order to make a more-informed, risk-based decision to guide development, usage, or acquisition of the product. For example, in the summary report of a sample Cyber Resilience Test assessment shown below, a number of risks (indicated by AMBER) have been identified. The full report explains the causes or reasons behind each issue in more detail, allowing the customer to evaluate the risks more fully.

Sample summary table of CRTF evaluation results AMBER or GREEN rating is provided against the Principle in the relevant APC standard

This is just the start of our mission to enable cyber security assurance at scale across the UK. In addition to increasing  the number of industry partners, the number of products engaged with CRTF for assessment, and the breadth of Assurance Principles and Claims (APCs), we have identified the following challenges which we are actively working through:

  • How can we enable High Assurance at scale?

  • How can we include diverse technology requirements such as TEMPEST or operational technologies?  

  • How do we enable tailored assurances for highly specialist equipment?  

  • How do we use this approach with other standards and international markets?

We are transforming our Assured Sanitisation Service (CAS-S) into a modern service delivered through CRTFs. CAS-S has provided trusted assurance for over a decade, enabling clients of sanitisation service providers to confirm that their data is securely processed using NCSC standards. CAS-S closed at the start of January 2026, and no longer accepts new evaluations. Instead, a new NCSC Sanitisation Service will be delivered exclusively by CRTFs (we’ve already published the APC for this service).

We established CRTFs to help consumers of technology to better understand the cyber security of the products they are procuring in order to make informed, risk-based decisions about the technologies that empower their organisations. We’d encourage all technology vendors to use the CRTFs to provide confidence in their products. This confidence can, in turn, be shared to end users and customers. You can find out more by browsing our CRTF pages for technology vendors.

If you’re interested in becoming a Cyber Resilience Testing Facility, you can find the requirements on our pages for CRTFs.

Sean D, NCSC CTO Cyber Growth

Written by

Sean D NCSC CTO Cyber Growth

Published

Part of blog