Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 10 of 35

Building a dynamic assurance model

Transforming our approach to Technology Assurance in the UK is not going to happen overnight, nor can the NCSC do it alone. This will require active collaboration between a number of stakeholders including Government departments, standards bodies, vendors and security assessors. It will also necessitate a more supporting role for the NCSC, as we move to enable more people to perform assurance activities.

The assurance ecosystem

As well as putting in place the artefacts and infrastructure we need, the ecosystem in which the new model for technology assurance operates will require updating. From the way in which people consume assurance statements and manage their system risks, through to the need for incentives and complementary procurement processes.

Building the NCSC’s new model for Technology Assurance requires a mixture of short (0-2 years), medium (2-5 years), and long-term (5-20 years) endeavours, as the diagram below makes clear.

assurance model journey diagram

International market

We will seek to put in place the necessary infrastructure and governance processes that enable international equivalency agreements with existing schemes, where they are required.

For instance, for the Code of Practice for Consumer IoT Security, DCMS and the NCSC have worked together to influence the development of the internationally recognised ETSI standards (EN 303 645 & TS 103 701).

Technology is global, its market and its use cannot be constrained to a UK context. For the prosperity of the UK, it is essential that we reduce the friction which assurance regimes introduce. A high functioning assurance process will help the UK brand to project technical credibility internationally.

Published

Reviewed

Version

1.0