Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 6 of 35

The current state of technology assurance

Today, choosing technologies with the right amount of security for a given context is extremely difficult. Cyber security requirements and advice are hard to understand for most people. In fact, many UK CISOs highlight accurate evaluation of cyber security technology as a real cause for concern. In many cases, there is no accepted source for reliable assurance.

The Commercial Product Assurance (CPA) scheme was the main vehicle used by UK Government to assess commodity security products, from 2014-2019. CPA applied an agreed commodity threat model as the yardstick to assess things like web application firewalls, encryption, smart meters and tokens/readers.

In 2020, recognising that the current approach did not adequately support the broad range of customers that the NCSC now serves, the CPA scheme was closed down (except for Smart Meters). This came swiftly on the heels of the UK ceasing to be a certificate producer under the Common Criteria Recognition Agreement (CCRA), in October 2019.

We continue to run our NCSC CAPS service, which provides assurance for certain technologies used to protect the nation’s most sensitive information.

We have also worked closely with DCMS to develop the Code of Practice for Consumer IoT security. The forthcoming legislation in this area will drive change at scale in the UK for Connected Consumer Devices. We also work alongside CPNI to support Cyber Assurance of Physical Security Systems (CAPSS). Cyber Assurance of Physical Security Systems.

Current UK Assurance schemes

The diagram below illustrates both current government-led schemes and the areas where support is lacking. The new approach described in this paper is designed to address these gaps.

diagram of technology categories detailed in this section

The diagram splits technologies into three broad categories:

1. Commodity technologies (Off-the-shelf devices such as smart phones) bought and used by all kinds of people, from members of the public to defence.

+ The DCMS Code of Practice for Consumer IoT Security provides a standard for smart devices in the home.

- All other users are without an official means of assurance

 

2. Bespoke technologies (such as Smart Meters) bought and used through businesses and government departments for a particular purpose and

+ NCSC Commercial Product Assurance (CPA) scheme for Smart Meters

- Businesses have little support as they look to gain assurance in systems and their underpinning technologies in an enterprise setting. This is worrying as many of these are common targets for cyber criminals.

- Operational Technology (OT) and Industrial Control Systems (ICS) currently have little coverage

 

3. Cryptography and sensitive communications technologies bought and used by government departments to protect the most sensitive information.

+ NCSC CAPS service for High Grade products used by HMG.

Published

Reviewed

Version

1.0