Assured Cyber Security Consultancy
This scheme assures providers offering independent consultancy services to organisations with complex, high-risk, or nationally significant cyber security requirements.
In this scheme
Information for ACSC buyers
Cyber security is a broad and complex discipline, so it is important to choose the right provider to meet your requirements. Our Assured Cyber Security Consultancy scheme assures providers offering independent consultancy services to organisations with complex, high-risk or nationally significant cyber security requirements.
The ACSC Scheme is for you if you are:
- an Operator of Essential Services regulated under relevant legislation, or a statutory regulator, or otherwise subject to cyber security oversight by a government department or designated public authority (including a Lead Government Department).
- a UK government department, agency, or arm’s length body.
- require consultancy services that involve interpreting, applying, or aligning to NCSC advice and guidance.
- have an engagement with an elevated cyber threat profile, including those likely to face targeted, persistent, or capability-based adversary activity beyond general, untargeted (“commodity”) threats.
About the Assured Cyber Security Consultancy scheme
The NCSC has assessed that the consultancies in this scheme meet our Scheme Standard and are able to provide specialist advice in one or more of the following Offerings:
- Risk management
- Security architecture
- Cross Domain Advice - in development
- Audit and Review
- Post-quantum cryptography - currently in pilot/MVP stage
The consultancy (known as an Assured Service Provider) operates the service:
- in accordance with the NCSC’s requirements set out in the Scheme Standard, including the Consultancy lifecycle and the Consultancy Team requirements.
- using the NCSC’s advice and guidance, where appropriate.
How do I choose an Assured Cyber Security Consultancy provider that’s right for me?
It is important to carefully consider your requirements and to define them clearly.
As a minimum, you must think about, and carry out due diligence on:
- The type of expertise you need: Security Architecture, Risk Management, or Audit & Review.
- Whether the consultancy has experience in your sector.
- The scope of consultancy you need – is it topic specific or across a range of areas? Does the consultancy offer enough depth and breadth?
- Whether you need your consultancy to have cyber security expertise in a particular technology, eg web applications, networks, operating systems.
- Whether security clearances are required. If security clearances are required, please stipulate this in any invitation to tender.
The Cyber Buyer's Guide (also available from the Scheme Documents page) contains further guidance and clarity around the Assured Cyber Security Consultancy Scheme: Risk Management, Security Architecture and Audit and Review Offerings.
It can also be difficult for small organisations to know who to turn to for reliable cyber security advice. Our Cyber Advisor scheme provides small and medium sized organisations with reliable advice and practical support to improve basic cyber security and reduce the likelihood of the most commonly experienced cyber attacks.
How to contact an Assured Cyber Security Consultancy
You can find a list of all our Assured Cyber Security Consultancies on the website.
Government and public sector buyers can invite supplier to bid for working using the Government Commercial Agency’s (formerly Crown Commercial Service) Dynamic Purchasing System. Government Commercial Agency website - Cyber Security Services 3.
CNI customers should contact their chosen Assured Cyber Security Consultancy directly.