Cyber Adversary Simulation (CyAS)
Companies assured under the Cyber Adversary Simulation scheme deliver services to test an organisation’s cyber resilience, including their ability to prevent, detect and respond to simulated cyber attacks.
What is the Cyber Adversary Simulation (CyAS) Scheme?
The NCSC scheme will assure commercial organisations providing cyber adversary simulation services which meet our CyAS Standard. They will be known as CyAS Assured Service Providers (ASPs).
Cyber adversary simulation is a technique which provides end-to-end assurance and evidence of real-world cyber resilience. It is particularly suitable and recommended for mature organisations running critical services. It tests an organisation’s cyber resilience, including their ability to prevent, detect and respond to a simulated attack.
The CyAS scheme adopts a capability-led approach, meaning that the provider will use and maintain a suite of tools and capabilities which allows them to achieve a range of objectives, as agreed with the Customer.
The NCSC has developed the scheme in partnership with Cyber Oversight Bodies including cyber regulators and government policy organisations with responsibility for understanding the cyber resilience of organisations within their sector. Cyber Oversight Bodies choosing to use the CyAS scheme in their sector are known as Scheme Partners.
We have designed the scheme so that buyers can use it independently as part of their own cyber resilience activities, or under the direction of their Cyber Oversight Body.
Scheme launch
We are launching the Scheme as a Minimum Viable Product (MVP). We are assessing an initial cohort of applicants over the summer of 2026 and aim to launch to the Buyer community by the end of 2026.
We can now share the Scheme Standard and Scheme Working Practice Documents so that both potential Buyers and prospective Assured Service Providers can better understand the Scheme.
The Scheme Standard sets out the standards required for membership of the CyAS Scheme, including the requirements on the company, the methodology a company must follow, and the reporting requirements.
The Working Practices Document sets out the obligations on Assured Service Providers and outlines how the NCSC and ASPs will work together.
Important:
Both of these documents relate to the MVP scheme. The content is, therefore, subject to change as the scheme develops. We will publish more information about the Scheme, our plans for launching to Buyers, and next steps for prospective future providers. Please keep checking this page for the latest updates.