Assured Cyber Security Consultancy
This scheme assures providers offering independent consultancy services to organisations with complex, high-risk, or nationally significant cyber security requirements.
In this scheme
What is the NCSC Assured Cyber Security Consultancy Scheme?
The NCSC Assured Cyber Security Consultancy (ACSC) Scheme helps organisations with complex, high-risk, or nationally significant cyber security needs identify trusted, independent consultancy providers.
It provides assurance that participating consultancies meet the National Cyber Security Centre's (NCSC) Standard for delivering high-quality cyber security consultancy in accordance with the NCSC's advice and guidance.
Through the scheme, organisations can access expert support across a range of specialist areas including:
- Risk management
- Security architecture
- Cross Domain Advice sub-Offering - in development
- Audit & Review
- Post-quantum cryptography - currently in pilot/MVP stage
Who is it for?
The ACSC Consultancies offer support on a wide and complex range of cyber security challenges. They have been assessed against NCSC standards and are capable of delivering NCSC advice and guidance to meet the Customer needs.
Organisations should consider engaging an assured consultancy if they require support in one of the ACSC specialist areas (risk management, security architecture, audit and review or post-quantum cryptography) where one of more of the following apply:
- the organisation is an operator of essential services under the oversight of a statutory regulator, is itself a statutory regulator, or is subject to cyber security oversight exercised by a government department or other formally designated public authority (including a lead Government department)
- the organisation is a UK government department, agency, or arm’s-length body
- the organisation requires consultancy services that involve interpreting, applying, aligning to, or providing advice in accordance with NCSC advice and guidance; and / or
- the organisation cyber threat profile is assessed as elevated beyond general, untargeted (“commodity”) cyber threats, including circumstances where the organisation is likely to face targeted, persistent, or a capable adversary.
For organisations that do not operate in a high risk or complex sector, our Cyber Advisor scheme provides cyber security advice tailored to organisations more at risk of commodity attack. The focus of that advice and support is on the implementation of the technical controls set out in Cyber Essentials. This approach will improve the cyber security of small organisations and reduce the likelihood of the most commonly experienced cyber attacks.
Applying to join the scheme
For information about joining the Risk Management, Security Architecture or Audit and Review Offering please see the Information for service providers page.
For information for joining the PQC pilot offering, please see the Post-quantum cryptography (PQC) pilot page.
How to contact an Assured Cyber Security Consultancy
You can find a list of all our assured consultancies on the NCSC website.
Government and public sector buyers can invite supplier to bid for working using the Government Commercial Agency’s (formerly Crown Commercial Service) Dynamic Purchasing System. Government Commercial Agency website - Cyber Security Services 3.
All other customers should contact their chosen Assured Cyber Security Consultancy directly.