Assured Cyber Security Consultancy
This scheme assures providers offering independent consultancy services to organisations with complex, high-risk, or nationally significant cyber security requirements.
In this scheme
Information for ACSC service providers
About the scheme
The Assured Cyber Security Consultancy (ACSC) Scheme provides confidence in organisations delivering cyber security consultancy services within defined ACSC offerings. It is designed to support customers with complex, high-risk, or nationally significant cyber security requirements by ensuring that consultancy services meet consistent standards of quality and expertise.
Assured Service Providers deliver consultancy in one or more of the following Offerings, for more information on the individual offerings please see the links below:
- Risk management
- Security architecture
- Cross Domain Advice - in development
- Audit and Review
- Post-quantum cryptography - currently in pilot/MVP stage
As an Assured Service Provider you must:
- meet the ACSC Scheme standard, and work in accordance with the ACSC working practices, also available on the Scheme documents page
- apply NCSC advice and guidance as appropriate, to deliver Consultancy to meet your Customer’s needs
- apply the requirements set out in the ACSC Scheme Standard where one or more of the following apply:
- the Customer is an operator of essential services under the oversight of a statutory regulator, is itself a statutory regulator, or is subject to cyber security oversight exercised by a government department or other formally designated public authority (including a lead Government department)
- the Customer is a UK government department, agency or arm’s-length body
- the Customer requires consultancy services that involve interpreting, applying, aligning to, or providing advice in accordance with NCSC advice and guidance; and / or
- the consultancy engagement relates to a customer whose cyber threat profile is assessed as elevated beyond general, untargeted (“commodity”) cyber threats, including circumstances where the organisation is likely to face targeted, persistent, or capable adversary.
ACSC Assured Service Providers
If your application to join is successful, we will add you to our list of ACSC Assured Service Providers, found on the website.
ACSC Assured Service Providers are also eligible to be listed and bid for work on the Government Commercial Agency’s (formerly Crown Commercial Service) Dynamic Purchasing System used by Government and public sector buyers. Full guidance is available on the Government Commercial Agency website - Cyber Security Services 3.
How to join the scheme
Before applying to join the Scheme, you must meet the following pre-requisites:
- Have a letter of commitment from a board member or member of your senior management team that must:
- Commit both themselves and the Company to ensuring complaiance with the ACSC Scheme; and
- Confirm the delegation of appropriate authority to accountable individuals within the Company for ensuring that the mandatory requirements set out in this Standard are met.
- Have individuals who are prepared to be accountable for the service and its technical quality. The accountable individual for the technical quality must hold the title of Chartered Cyber Security Professional (ChCSP) awarded by the UK Cyber Security Council in the relevant specialism.
- Have a Consultant/ Consultants who hold and maintains the title of Chartered Cyber Security Professional awarded by the UK Cyber Security Council, relevant specialism, and a positioned within the Consultancy Team to lead engagements. For more information see The UK Cyber Security Council website
- The Consultants holding the title of Chartered Cyber Security Professional (ChCSP), awarded by the UK Cyber Security Council, must be able to demonstrate that they are sufficiently skilled and experienced in the implementation of the NCSC advice and guidance to lead their organisation, their processes, and their staff, in delivering NCSC advice.
- You must have and maintain an in-date Cyber Essentials Plus certificate for all the systems on which information relating to Customers’ engagements is stored and processed.
You can find the Scheme Documents on the Scheme Documents page.
The application window and process
Application windows
The scheme will open for applications during application windows the dates for which will be published here.
Applications to join the scheme, add additional Consultants or add additional Offerings can only be submitted during an application window and must follow the application process stated below.
The next application window is:
- Pre-Submission Briefing - 16th September 2026
- Closing date for cohort - 2nd October 2026
Applications submitted out of these dates will be rejected
Please register your details on the Assured Consultancy Pre-Application Brief registration Form by 9th September 2026 (opens MS Office Form).
This cohort is for application for Risk Management, Security Architecture, and Audit and Review Offerings. Please see the PQC Pilot page for information on PQC applications.
Process
Full details of the application process are set out in the Application Terms and Form.
The application process for the scheme has four main parts:
Stage 1: Attendance at a mandatory Pre-Submission Briefing
Your proposed Accountable Technical Individual must attend a mandatory pre-submission briefing.
You must then submit the application pack by the deadline, including the application form, commercial onboarding questionnaire and supporting evidence.
Stage 2: Due dilligence and commercial checks
At this stage, we will assess whether your Company and application meet all the criteria to progress to the technical assessment stage.
Stage 3: Technical assessment
At this stage, all individuals who hold the title of Chartered Cyber Security Professional, awarded by the UK Cyber Security Council, and whom the Company nominates in support of an Offering, must participate in and pass an individual NCSC Focused Interview conducted by NCSC experts.
The interview focuses on gaining an understanding of the candidate’s experience of providing consultancy based upon NCSC advice and guidance, and how this advice is delivered with the Company’s methodologies, frameworks and processes. During the NCSC-Focused Interview, on behalf of their Company, candidates will be expected to:
- meet the requirements set out the Offering Specific Annexe of the SchemeStandard; and
- demonstrate familiarity with and application of NCSC advice and guidance in real world scenarios
Stage 4: Contract signing and onboarding
If your application is successful, you will sign the contract and begin onboarding.
Important notes:
You need to submit a separate application form for each service you want to offer. You can apply for more services later, even after you've joined the scheme.
Applications will only progress to the next part after successful completion of the previous step. Successful applications must pass all parts.
If your application is unsuccessful, we will provide feedback. At the NCSC's sole discretion, we may permit you to re-submit your application within an agreed timeframe.
At the NCSC, we are taking action to remove artificial barriers to entry to all of our Schemes. So, if you spot something which you think unfairly prevents you from applying, please let us know.