NCSC confirms CAS(T) closure
In July 2019, the Department for Digital, Culture, Media and Sport (DCMS) published the results of the UK Telecoms Supply Chain Review. In response to the Review’s findings, government announced the establishment of “a new, robust security framework for the UK telecoms sector, marking a significant shift from the current model”. The foundation for the framework will be a new set of Telecoms Security Requirements (TSR). The TSR will provide clarity to industry on what is expected in terms of network security.
In anticipation of this, the NCSC undertook a review of its Telecoms Assurance Scheme known as CAS(T). Following a period of consultation, CAS(T) formally closed on 31st January 2020.
The NCSC no longer supports the CAS(T) Standard. The technical aspects of the standard do not align to the evolving telecommunications landscape and will quickly become out-of-date, without NCSC maintenance. Therefore, whilst it will remain available on the NCSC website for historic purposes, the NCSC does not recommend its continued use.
CAS(T) Certificates provided evidence that an NCSC Certified Lab had determined that the Certified telecoms service met the conditions of the CAS(T) requirements it tested at that time. However, with the scheme's closure Certificates will not be maintained on an ongoing basis and annual audits to verify the Service is still committed to the Standard will not proceed. Any changes the operators make to the services will not be audited.
The NCSC therefore recommends that consumers and purchasers of telecoms services should review their security requirements such that they are not requiring CAS(T) certification. Should they choose to not follow this recommendation, they should be aware of the risk of non-maintained Certificates.
We have published a set of Frequently Asked Questions below.
The information within the CAS Service Requirement for Telecommunications, Security Procedures Telecommunication Systems and Services and the Good Practice Guide Audit Handbook for CESG Assured Service (Telecoms) are commonly known and referred to as the CAS(T) ‘standard’.
Following CAS(T)'s closure the NCSC will no longer support the standard. The technical aspects of the standard are unlikely to remain aligned to the evolving telecommunications landscape and will quickly become out-of-date without NCSC maintenance.
Therefore the NCSC does not recommend that anyone continues to use the standard.
Those organisations that continue to use the CAS(T) standard after the closure of the CAS(T) scheme to manage aspects of their cyber security, will do so at their own risk and the NCSC will have no involvement.
The NCSC has terminated its contracts with the labs from January 2020. All scheme audits will therefore stop.
Following scheme closure on 31st January the NCSC will not support CAS(T) surveillance audits.
Under the conditions of the CAS(T) scheme, certificate holders were required to report any significant certificate scope or network changes to their Lab.
Now the scheme has closed, the holders of existing certificates will have no way of doing so. To the extent that end-customers continue to rely on CAS(T) certificates as part of their security requirement (contrary to the NCSC advice above), the end-customer should ask the certificate holder to warrant that no significant certificate scope or network changes have been made since they obtained the certificate.
Certificate holders should be aware that any such changes will invalidate their certificates.
CAS(T) certificates evidence that an NCSC Certified Lab determined that the telecoms service, defined by the Certificate scope, met the conditions of the CAS(T) technical requirements against which they have been evaluated, at the time of evaluation.
The CAS(T) scheme audits have now stopped. Certificates will not be maintained, and any changes the operators make to the services will therefore not be audited.
Some operators may only have completed the critical security checks that are undertaken in the first assessment and may not complete all the other mandatory tests that are undertaken at the end of year one and year two audits. NCSC therefore recommends that procurers and consumers of Telecoms services should review their security requirements such that they are not requiring CAS(T) certificates, nor exclusively dependent on CAS(T) certificates as an indicator of good security practice.
It is intended that the new Telecoms Security Requirements (TSRs) that were announced following the DCMS Supply Chain Review, will provide clarity to industry and customers on what is expected in terms of network security.
The NCSC have no plans to launch a new scheme at this time.
No; CAS(T) was designed for a different requirement and for different customers (see the blog on CAS(T)'s history for more).
The NCSC recommends that end-user customers should review and amend their security requirements to remove the requirement for CAS(T) certificates and consider alternative functional requirements instead.


