NCSC Annual Review 2025
Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.
Pages
Page 18 of 32
Industry assurance: supporting a thriving cyber security industry

We continue to support the UK’s thriving cyber security industry by leveraging the NCSC brand, so consumers know who and what they can trust.
It works as follows:
-
as the National Technical Authority for cyber security, we set the standard for what constitutes best‑practice
-
we assess industry providers against this standard
-
we license our brand to those who meet the standard, then work in partnership with those assured service providers
We now have a network of around 500 companies offering ‘badged’ services on our behalf, helping UK organisations to prepare for, protect against, detect and respond to cyber threats. Two new initiatives designed to help boost confidence in cyber resilience were announced at the flagship CYBERUK conference earlier this year.
- A new ecosystem of assured Cyber Resilience Test Facilities will allow technology vendors to demonstrate the cyber resilience of their products
- A Cyber Adversary Simulation scheme will help organisations test their defences
Cyber Resilience Test Facilities (CRTFs)
The industry-provided Cyber Resilience Test Facilities (CRTFs) bring the NCSC’s evidence-based method of technology assurance to life using the NCSC’s published approach of Principles Based Assurance. Following their successful participation in last year's pilot, an initial operating capability of three Test Facilities will offer Cyber Resilience Testing for internet-connected products.
The initial service offering assesses connected products against the Cyber Resilience Testing (CRT) Assurance Principles and Claims (APC) standard, assessing resilience to commodity attacks from public facing connections. This standard has been aligned with DSIT’s Software Security Code of Practice.
We continue to work closely with our Test Facilities, including the development of opportunities for training and accreditation for those involved in its delivery. Work is also ongoing to develop the market for this assurance and to support it as it scales up. This will see the ecosystem grow to include, amongst other things, high assurance cyber resilience testing, with the development of additional APCs.
Cyber Adversary Simulation (CyAS)
Companies assured under the CyAS scheme will deliver services to test an organisation’s cyber security, including their ability to prevent, detect and respond to sophisticated simulated cyber attacks (red teaming). We have developed the CyAS scheme in partnership with Cyber Oversight Bodies – cyber regulators and government – who are exploring the use of the scheme in their sectors. It has been designed as a means of providing end-to-end assurance and evidence for any organisation of sufficient maturity and criticality to test their cyber defences. The scheme will launch as a Minimum Viable Product and is expected to evolve as the user community grows.
Cyber Resilience Audit (CRA)
The Cyber Resilience Audit scheme has grown steadily since its launch last year. The NCSC has assured 17 providers to conduct independent CAF-based audits. The scheme has been developed alongside Cyber Oversight Bodies with responsibility for understanding cyber resilience within their sector. This currently includes:
- The Department of Finance, Northern Ireland
- The Department of Health and Social Care and NHS England
- Department for Business and Trade (chemical sector)
- The Office for Nuclear Regulation
GovAssure (the assurance programme that provides assessment of the cyber security of critical systems underpinning government's essential services) announced that it will adopt NCSC's Cyber Resilience Audit scheme for independent assurance reviews from 2026. This move will drive quality CAF-aligned reviews for government organisations under GovAssure.
Assured Cyber Security Consultancy
The NCSC's Assured Cyber Security Consultancy scheme assures companies offering services to organisations with complex or high-risk cyber security requirements. In addition to the long-standing offerings of security architecture, risk management and audit & review, this year we launched a pilot post-quantum cryptography (PQC) offering in order to build market capacity to address this national challenge. There are two offerings under the PQC offering:
- Discovery & Migration Planning: all companies within the pilot will be assured to support organisations in cryptographic discovery exercises, to identify priority services for migration, and to support the development of an initial migration plan.
- Advice: some companies will also be assured to offer direct advice on the use of PQC, in line with the NCSC’s published positions.
Cyber Incident Exercising
The NCSC’s Cyber Incident Exercising scheme has assured 39 providers (a growth of almost 40% since the last Annual Review). The growth is timely, as Government Cyber Security Policy (aimed at lead government departments, their arm’s length bodies and other public organisations) promotes that cyber incident response plans must be exercised at least annually. The scheme assures providers that offer exercising to test organisations' incident response plans in a safe environment and strengthen their incident management processes.
Cyber incident exercises like these aren’t just about following a script – they’re about preparing for the unexpected. When you’ve got the right people in the room, you can identify gaps, challenge assumptions, and make sure the organisation is ready to respond effectively when it really matters.”
Director Digital Security & Engagement, Department of Finance Digital, NI
Cyber Incident Response
Our Cyber Incident Response scheme assures providers under two levels: ‘Standard’ (supporting organisations at risk of common cyber attack) and 'Enhanced' (for the most critical entities likely to be exposed to the most sophisticated threats). Since the launch of the new CIR Standard level, the scheme has grown – by over 25% since last year’s AR – with 46 CIR providers now assured by the NCSC. The NCSC recommends that all UK organisations should use an NCSC-assured Cyber Incident Response provider when dealing with cyber incidents.
CHECK Penetration Testing
The NCSC's CHECK scheme sets standards for penetration testing that government departments, public sector bodies and the UK’s CNI organisations can trust. There are currently 54 companies assured, delivering CHECK penetration testing engagements. Over the past 12 months our assured service providers have carried out over 2,684 penetration tests. As well as ensuring the resilience of some of the most critical sectors, the information gathered through these penetration tests helps the NCSC identify and better understand common vulnerabilities across organisations.
Smart Meter Assurance
Over the past 12 months the NCSC has been finalising the transfer of the Smart Metering CPA scheme to a new owner. This sees the NCSC’s day-to-day involvement in Smart Meter assurance drawing to a close after nearly a decade. In that time, millions of smart meter devices have been certified and deployed to UK homes. The transfer to CyTAL, the new scheme operator, has been a long-term, collaborative process, working alongside the Department for Energy Security and Net Zero (DESNZ), The Smart Energy Code Company, SECAS and our CPA Evaluation Partners. This move aligns with the NCSC’s goal to empower industry and place risk decisions and ownership with those that hold the authority.
Cyber Essentials Certification Bodies
The impact of Cyber Essentials reaches beyond basic cyber resilience, contributing to wider economic growth. Through our Delivery Partner, IASME, we continue to support the UK’s cyber security industry by licensing the assessment process for Cyber Essentials to Certification Bodies across the UK. We now have 402 Certification Bodies employing 934 Assessors.
-
Over 75% of these companies are micro or small businesses.
-
The scheme stimulates company growth, with almost 50% reporting growth – some significantly – since becoming a Certification Body, leading to an increase in the number of trained and practising cyber security experts across regions.
-
Cyber Essentials offers a route into the cyber security profession. Recognising current industry requirement as a bottleneck, we're working with IASME to create an entry-level role linked to tech apprenticeships, providing a basic qualification as an alternative entry point.
| Region | Certification Bodies |
|---|---|
| East Midlands | 23 |
| Eastern | 32 |
| Guernsey | 2 |
| Isle of Man | 3 |
| Jersey | 4 |
| London | 75 |
| North East | 16 |
| North West | 39 |
| Northern Ireland | 5 |
| Scotland | 27 |
| South East | 61 |
| South West | 39 |
| Wales | 13 |
| West Midlands | 41 |
| Yorkshire & The Humber | 21 |
| Republic of Ireland | 1 |