Cyber Adversary Simulation (CyAS)
Companies assured under the Cyber Adversary Simulation scheme deliver services to test an organisation’s cyber resilience, including their ability to prevent, detect and respond to simulated cyber attacks.
Cyber Adversary Simulation (CyAS) Scheme Standard
version 1.1, September 2026
About the Cyber Adversary Simulation (CyAS) Scheme
- The Cyber Adversary Simulation (CyAS) Scheme assures Companies providing adversary simulation services aligned to the NCSC’s CyAS methodology to Customers with complex, high-risk or nationally significant requirements.
- You must use and apply the CyAS methodology as the basis for all your engagements with such Customers.
- The following Standard applies to Companies delivering CyAS Services to Customers where one or more of the following apply:
- the Customer is an operator of essential services under the oversight of a statutory regulator, is itself a statutory regulator, or is subject to cyber security oversight exercised by a government department or other formally designated public authority (including a lead government department);
- the Customer is a UK government department, agency or arm’s length body; and/or
- the Customer requires adversary simulation services that align with NCSC advice and guidance.
Scheme Membership Requirements
- This document defines the standards required for membership of the CyAS Scheme. It is split into four sections:
- Your board and/or senior management must support your membership of the CyAS Scheme. As a minimum, the support must ensure CyAS Services continue to meet the Standard.
- You must provide formal confirmation of this commitment in the form of a signed letter. The letter must be issued and signed by a board member or a member of the senior management team and must:
- commit both themselves and your Company to ensuring compliance with the CyAS Scheme; and
- confirm the delegation of appropriate authority to accountable individuals within your Company for ensuring that the mandatory requirements set out in this Standard are met.
- You must read this Standard in conjunction with the Working Practices Document and the Agreement. You must always (unless otherwise approved by the NCSC):
- satisfy all the requirements of this Standard;
- comply with the overarching Ecosystem Agreement;
- work in accordance with the Scheme Working Practices Document; and
- be regularly delivering Cyber Adversary Simulation Services. ‘Regularly’ in this case means that your Company must complete at least one CyAS engagement in any 12-month period. In addition, every named CyAS Engagement Manager and CyAS Lead Operator must take part in the provision of CyAS Services at least once in any 12-month period.
Section A – The Company Standard
Network Security
- You must maintain an in-date Cyber Essentials Plus certification for all the business systems on which information relating to Customer engagements is stored and processed.
Cyber Threat Defence
- You must be able to defend yourselves against an appropriate level of cyber threat as defined in your own risk assessment, using good practice and your own specific or contracted-in skills.
Overall Mandatory Defining Features
Technical competence
- You must be able to deliver the entirety of a Cyber Adversary Simulation in accordance with the methodology set out in Section B.
- You must ensure that the CyAS Team can perform a broad and up-to-date range of attack capabilities, including but not limited to:
- evading detection;
- persistence;
- local privilege escalation;
- remote privilege escalation (e.g. within active directory);
- lateral movement;
- effective phishing techniques;
- active and passive techniques to undertake Reconnaissance; and
- simulated data exfiltration.
- You must ensure that the CyAS Team hold a broad and up-to-date understanding of the latest adversarial capabilities and trends, including the tools, techniques and procedures to be able to deliver a Cyber Adversary Simulation.
- You must have an attacker infrastructure and appropriate tooling, which must include:
- a customisable ‘Command and Control’ (C2) framework tested and safe for use against a diverse set of Customer environments. Note that:
- safeguards must exist within your tooling to ensure the safety of their deployment (e.g. environmental keying to ensure deployment only within the agreed target environment); and
- you must maintain diversity within your C2 framework(s) for the purposes of evading detection; and
- an appropriately hardened attack infrastructure that ensures the security of the Customer’s networks and data during the Cyber Adversary Simulation.
- a customisable ‘Command and Control’ (C2) framework tested and safe for use against a diverse set of Customer environments. Note that:
- You must only acquire third party tools and code from trusted sources in order to ensure the safety of your and your Customer’s infrastructure.
Communication
- You must have members of the CyAS Team who are able to competently brief Customers, from desk level to board level, and communicate at the appropriate technical level for their intended audience. Communication is likely to include, but not be limited to:
- briefings;
- scoping;
- outline plan;
- communications plans;
- timeline evidence of activities conducted;
- report writing; and
- engagements with the Core Customer Team.
Location
- The Company’s CyAS Team must be located in the UK, and the Company must use reasonable endeavours to ensure that any infrastructure it uses to simulate an Attacker as part of its CyAS Services is hosted within the UK.
Regulations & Legislation
- You must ensure all staff have an appropriate understanding of and adherence to UK regulations and legislation relevant to performing Cyber Adversary Simulation tasks (e.g. the Computer Misuse Act 1990).
- You must ensure that all staff have an appropriate understanding of the regulations and legislation to which the Customer must adhere (e.g. the NCSC’s Cyber Assessment Framework when testing an organisation regulated under the Network and Information Systems Regulations 2018).
Personnel
- You must carry out all of the activities set out below. We have divided them into four categories and given a role title to each. These role titles may not exist in your company, but we do expect there to be a named person who is accountable to the NCSC for ensuring they are carried out.
- business requirements – “CyAS Service Owner”;
- technical oversight and health of your CyAS Service – “CyAS Service Technical Lead”;
- management and nurturing of the relationship between you and the Customer during the individual engagements – “CyAS Engagement Manager”; and
- technical oversight of the individual engagements – “CyAS Lead Operator”.
- You must have a minimum of two CyAS Operators, at least one of which must be a CyAS Lead Operator, and you must maintain those minimum resourcing levels while you are operating as an NCSC Assured Service Provider.
- All CyAS Team personnel (CyAS Lead Operators, CyAS Operators, CyAS Engagement Managers) must be either permanent employees or contractors of the Company and not employed or contracted for CyAS-related work by any other CyAS company.
CyAS Service Owner
- While we do not expect one person to personally deliver all aspects of the CyAS Service, the named CyAS Service Owner must be directly accountable for delivery of the service as a whole. Under the Scheme, the Service Owner must act as the NCSC’s primary contact for all Scheme communications and all onward action. The Service Owner must ensure that the following mandatory tasks are all completed:
- the Company positively contributes to the wider Scheme community. This includes:
- contributing to Scheme improvements;
- taking an active part in community meetings; and
- meeting with the NCSC from time to time, as requested.
- you meet all requirements under the Scheme and comply with the associated Agreement;
- annual Management Information Reports, as defined in the Working Practices Document, are submitted to the NCSC by the end of April each year, for the preceding financial year;
- your quality management processes as they apply to the delivery of their CyAS Service are documented and maintained;
- your processes are reviewed and updated in accordance with the Standard;
- your staff and any contractors involved in the Cyber Adversary Simulation Service adhere to your own documented processes;
- providing your Cyber Essentials Plus certificate number to the NCSC each time it is renewed;
- maintaining accurate records with the NCSC, in particular of new CyAS Lead Operators and Operators;
- ensuring your contract with the Customer includes contractual rights:
- that enable you to provide the NCSC with a copy of all CyAS reports marked OFFICIAL SENSITIVE or below; and
- that require Customers to share CyAS reports classified at SECRET or above with the NCSC, upon NCSC’s request;
- and you shall ensure that the Customer understands these contractual obligations are a condition of receiving CyAS Services; and
- Customer relationships are actively monitored and Customer feedback is sought to provide evidence of Customer satisfaction with your work.
- the Company positively contributes to the wider Scheme community. This includes:
CyAS Service Technical Lead
- The CyAS Service Technical Lead must be directly accountable for the technical quality and health of the CyAS Service. We would normally expect the CyAS Service Technical Lead to be experienced in Cyber Adversary Simulation, but this is not mandatory. However, the individual must have the capacity and capability to act as the NCSC’s primary contact for all technical feedback and questions regarding the technical aspects of the CyAS Service, and any further action required to improve the technical quality of the service. The CyAS Service Technical Lead is accountable for:
- ensuring NCSC feedback on CyAS reports or broader suggestions for improving the CyAS Service are acted upon;
- ensuring the technical quality and standard of delivery of the CyAS Service and maintaining the overall technical capability and effectiveness of the CyAS Team;
- ensuring the quality of reports and that they meet the Standard. While the CyAS Service Technical Lead does not need to personally provide quality control over every CyAS report, they must ensure that you have and adhere to a quality control process that is effective in ensuring the CyAS Service results in high quality and Standard compliant reports;
- ensuring all CyAS Team staff have appropriate professional training and development plans. This may include, but not necessarily be limited to:
- Identifying mentors for inexperienced CyAS Engagement Managers, Lead Operators and Operators;
- Ensuring there is a training lead for the CyAS Team;
- Ensuring CyAS Lead Operators attend at least two NCSC CyAS events per year; and
- ensuring that all CyAS Engagement Manager, Lead Operator and Operator applications to work as part of the CyAS Service meet the requirements of the Standard, before they are passed to the NCSC.
Composition of a CyAS Team
- All CyAS Teams must meet the following requirements:
- comprise only NCSC-registered CyAS Engagement Managers, CyAS Lead Operators and CyAS Operators; and
- comprise the appropriate mix of expertise to undertake the engagement.
CyAS Engagement Manager
- CyAS Engagement Managers must:
- have and be able to provide evidence that they have all of the skills and capabilities defined within the Individual Competency Framework (Section D) as required for the Engagement Manager role; and
- have a proven track record of satisfactory Customer engagement.
- For every Cyber Adversary Simulation, the CyAS Engagement Manager:
- is accountable for the CyAS Services;
- is accountable for managing the relationship between you and the Customer;
- will help scope goals and objectives, ensuring that the key assets targeted are identified and that engagement milestones are agreed;
- is responsible for explaining to the Customer the risk management for each objective and providing input into the legal and ethical considerations for the engagement;
- will work with the Customer Core Team to determine any De-Chaining options that are available and agree the conditions in which they can be used; and
- will maintain communication pathways throughout the lifecycle of the engagement allowing for the triage of live incidents and demonstrating compliance with the NCSC methodology, as outlined in Section B, and approved scope.
CyAS Lead Operator
- CyAS Lead Operators must:
- have and be able to provide evidence that they have all of the skills and capabilities defined within the Individual Competency Framework (Section D) as required for the CyAS Lead Operator role; and
- have a proven track record of satisfactory Customer engagement.
- For every Cyber Adversary Simulation there must be a named primary CyAS Lead Operator who:
- is accountable for the engagement and must ensure the CyAS Team consists of an appropriate mix of expertise and experience to provide CyAS Services;
- is responsible for the behaviour, actions and advice given by their team and must ensure they remain legal and ethical;
- is accountable for their own behaviour, actions and advice given during the Cyber Adversary Simulation;
- is accountable for and must ensure that the entire Cyber Adversary Simulation engagement is conducted in accordance with the NCSC’s methodology (section B);
- must attend the scoping meeting and provide technical input when scoping the engagement;
- must provide technical direction and leadership throughout the engagement;
- must provide technical advice about the ongoing and dynamic risk management of a live engagement and ensure adherence to the agreed scope; and
- is responsible for producing the final report in accordance with the CyAS Report Standards (Section C).
CyAS Operator
- CyAS Operators must:
- have and be able to provide evidence that they have all of the skills and capabilities defined within the Individual Competency Framework (Section D) as required for the CyAS Operator role;
- be competent to use attack tooling and understand the limitations of the tooling; and
- be able to account for all actions they take on the Customer’s estate and ensure those actions remain legal and ethical.
Section B - The Technical Standard
- All Companies must operate according to the CyAS methodology below when providing CyAS Services, which includes the following elements:
- Phase 1 – Pre-requisites:
- Scoping;
- Initial passive reconnaissance; and
- Preparation.
- Phase 2 – Active Testing:
- Continual active reconnaissance;
- Initial access;
- Internal phase; and
- Clean-up.
- Phase 3 – Reporting
- Phase 1 – Pre-requisites:
Phase 1 – Pre-requisites
Scoping
- You must undertake a scoping exercise for each Cyber Adversary Simulation engagement.
- You must agree, formally record, and sign off the scope of the Cyber Adversary Simulation with the Customer. This must include:
- relevant goals and objectives for the Cyber Adversary SimulationExamples;
- a high-level definition of the critical functions of the organisation including relevant network components or services;
- identification and exclusion of non-corporate assets, such as personally owned devices with access to corporate data;
- identification of critical assets, for example definition of Operational Technology boundaries and their associated risks;
- identification of what is out of scope for the Cyber Adversary Simulation, and why it is out of scope;
- identification of, and planned ways to mitigate, risks associated with performing a Cyber Adversary Simulation;
- identification of the Customer’s Core Team. It is recommended that the Core Team should be as small as possible to maintain the validity of the Cyber Adversary Simulation. Core Team members should be people who have authority to make decisions regarding the engagement, for example whether to step in, pause or stop the Cyber Adversary Simulation at any time, if required;
- the Customer’s data handling requirements in respect of their data and vulnerability information;
- the length of time and effort to be allocated to the Active Testing phase, including any time bounding of Reconnaissance and the Initial Access stages;
- a decision as to whether the Cyber Adversary Simulation will run as a Full Spectrum engagement with an Initial Access phase, and for how long, or be conducted on an Assumed Breach basis where internal access is to be enabled by the Customer;
- an agreement on appropriate De-Chain Events, should the Cyber Adversary Simulation stall once the active phases begin;
- formal agreement of how both parties will communicate throughout the life of the Cyber Adversary Simulation. This should include, but is not limited to, cadence of the engagement and handling of notable events (e.g. detections);
- formal agreement about when the Cyber Adversary Simulation can be carried out, for example business hours only. If testing out of business hours is acceptable then communication and escalation channels also need to be available out of hours;
- definition of your operating procedures for clean-up activities and the support available to the Customer after the Cyber Adversary Simulation concludes;
- where applicable, discuss any wireless networks that fall into scope, and/or services and infrastructure provisioned via third parties (e.g. cloud);
- formal agreement of social engineering methodology and boundaries;
- any embargo periods in which testing must be paused; and
- the cost of the Cyber Adversary Simulation.
- The duration of a CyAS should be proportionate to the size, nature, and complexity of the scoped targets. To ensure meaningful outcomes, organisations are encouraged to allow sufficient time for thorough testing of real-world adversary tactics, techniques, and procedures, rather than setting the assessment period at the bare minimum.
- Unless otherwise agreed, you must approach the Cyber Adversary Simulation in such a way that they evade detection and, as a minimum, are testing the Customer’s defences.
- A scoping meeting must take place between you and the Customer, and you must ask the Customer to include:
- at least one senior Customer representative – you must ask them to articulate the business and/or cyber security risks the Customer is most concerned about and explain how these potentially affect the delivery of the Essential Service. You must ask the Customer to make clear any intolerable business impacts relevant to the Cyber Adversary Simulation;
- Customer technical representative(s) knowledgeable about the target system(s) – you must ask them to outline the boundaries of the Customer’s technical infrastructure; and
- As a minimum, the scoping should be attended and led by the CyAS Engagement Manager and primary CyAS Lead Operator.
Special requirements
- In addition, you must agree with the Customer all access arrangements, including any security implications.
- You must make the Customer aware that no Cyber Adversary Simulation is without risk and ensure that the Customer has business continuity plans in place. Any accidental damage or straying out of bounds must be recorded and documented, with the customer being made aware as soon as the breach is identified.
- During the Cyber Adversary Simulation, if it becomes apparent that the Customer is already compromised, you must escalate this to the Customer as soon as it is identified. You must make the Customer aware that a Cyber Adversary Simulation does not include physical attacks to gain access to a Customer’s network.
- If the Customer asks for a test which you know is unsuitable (that is, it will not help the Customer understand real risks within their estate), you must explain this to the Customer and suggest an alternative way forward. If the Customer wishes to continue regardless, you must record the advice given and the Customer's decision in the CyAS report.
- You must make the Customer aware of the likelihood of overlap between the reconnaissance and initial access phases. As a result, it is unlikely that the Cyber Adversary Simulation will follow a strictly linear form. Rather, it is likely that you will need to make multiple initial access attempts. You are responsible for managing such overlaps and attempts but must agree an approach with the Customer during the scoping phase.
- You must keep a detailed log of all actions and activities for the duration of the Cyber Adversary Simulation engagement.
Reconnaissance
- If conducting a Full Spectrum engagement, you must conduct Reconnaissance against the Customer, using (as a minimum) a combination of active and passive open-source intelligence techniques (OSINT). To inform scoping discussions the initial reconnaissance phases should be passive, but as the test begins then active reconnaissance must be conducted to identify potential compromise avenues that could be exploited to deliver the agreed objectives.
- By way of example only, passive open-source intelligence may include:
- using online databases;
- search engines;
- looking up IP/DNS registrations;
- certificate information;
- relevant social media; and/or
- code repositories.
- By way of example only, active Reconnaissance may include:
- port scanning;
- vulnerability scanning;
- visiting the Customer’s websites; and/or
- surveying available online services.
- You must make it clear to the Customer that the process is non-linear and that it is possible that they may revisit the reconnaissance phase during later stages of the Cyber Adversary Simulation.
- You must use Passive reconnaissance alongside scoping outputs to inform an initial set of access options which will form part of an initial outline plan. It is expected that this plan will be developed and refined as the testing progresses into Phase 2 – Active Testing.
Preparation
The Company
- You must fully prepare any required capability that can be reasonably foreseen ahead of the active phase of the Cyber Adversary Simulation. This must include attacker infrastructure and tooling (for example C2 frameworks).
- You must only acquire tools and code from trusted sources and must have processes in place to be sure that their capability is safe.
- You must secure the infrastructure used during a Cyber Adversary Simulation, both from network access, and data controlling perspectives. This must include secure storage of information, network segregation and restricted to required personnel.
- You must agree with the Customer the period of time between the scoping phase and the start of the engagement.
The Customer
- Before the Cyber Adversary Simulation start date, you must ask the Customer to confirm that:
- the Customer Core Team is available and can be contacted for the duration of the Cyber Adversary Simulation, both in and out-of-hours as appropriate;
- any technical preparation is complete (e.g. in the case of an Assumed Breach, the target device and any accounts to be used are tested and available); and
- any proposed mitigations identified during scoping are in place.
Phase 2 – Active Testing
- You must not Deliberately Damage systems and must take all reasonable precautions to minimise accidental damage.
- You and the Customer Core Team must formally agree and document any changes made to the agreed scope to facilitate the Cyber Adversary Simulation.
- You and Customer Core Team must maintain contact at an agreed cadence during the Cyber Adversary Simulation; the CyAS Lead Operator must be present (virtually or physically) for the duration of the Cyber Adversary Simulation.
- You must comply with the data handling requirements agreed during scoping.
- You must keep a timeline noting relevant elements of the Cyber Adversary Simulation so that, during the de-brief, the Customer can understand what activities took place and what was logged, detected, or not detected at the various time points.
- The timeline must include:
- the date/time an activity took place;
- the event which happened with relevant details, for example if a file was uploaded, what was the file and where was it uploaded to; and
- if appropriate, the hostname which is relevant to the event as well as the relevant process, ideally with the process ID (PID).
Initial Access
- You and Customer must agree the amount of time you will spend attempting to gain initial access to the Customer’s network without assistance.
- By way of example only, initial access approaches may include:
- Phishing; and/or
- Exploitation of a vulnerability in an external network perimeter device which leads to further access.
- You must agree with the Customer if pivoting from Full Spectrum to using a De-Chain event for initial access.
- It is recommended that you and the Customer agree how to allocate time during Active Testing between Initial Access and the Internal Phase. They must strike a balance between gaining sufficient confidence in external controls and enabling learning against wider testing objectives. Such objectives may include testing the effectiveness of internal controls to combat an Attacker with a foothold in the Customer network.
Internal Phase
- As agreed during scoping, you must continually develop the testing approach to progress towards the goals objectives agreed with the Customer.
- You must adhere to the boundary points as defined during scoping and any limitations around adversarial activity as set by the Customer.
- You must determine the relevant attack methodologies which will best achieve the objectives agreed during scoping. By way of example only, these may include:
- evading detection;
- persistence;
- local privilege escalation;
- remote privilege escalation (e.g. within active directory);
- lateral movement;
- internal phishing; and/or
- simulated data exfiltration.
- You must document all changes made to the Customer’s system during the Cyber Adversary Simulation.
- If you achieve an objective without detection, you must agree with the Customer on how to proceed.
- In the event of detection, you must record the activity, at what point the detection occurred, and the Customer’s response.
- If/when detection has occurred, you must proceed as agreed with the Customer during the scoping phase.
- If the entire scope of the Cyber Adversary Simulation is achieved, you and the Customer may wish to consider other attack methods, approaches or additional objectives. For example:
- raising the noise level and identifying the point at which the Customer’s defensive teams can detect your presence within a network;
- identifying alternative attack methodologies; and/or
- working together with the Customer’s defensive team in a collaborative fashion to tune detection capability, educate defensive teams and raise awareness of threat techniques.
- It is recommended that the Customer considers using the De-Chain Event agreed during the scoping meeting to assist you if the Cyber Adversary Simulation stalls.
- Objectives must only be marked as completed when both you and the Customer agree that they have been met. In the event of a disagreement, the disagreement must be detailed in the report.
- You must present initial findings at a wash-up meeting with the Customer and meet any Customer requirement for further meetings following the internal phase.
Clean-up
- As far as possible, you must remove from the Customer’s system all artefacts created during the adversary simulation. You must make the Customer aware of their responsibility to verify that the clean-up has taken place and/or to act to clean up any outstanding artefacts.
- You must notify the Customer about any changes they have made and provide information on how to reverse the changes.
- You must be available to respond to the Customer for an agreed period after the engagement has finished to clarify any residual clean-up activities.
- After the Customer has confirmed receipt of the report, you must erase all data or transfer the data to a secure internal repository for a period in line with regulatory and legal requirements, including data protection laws. You must complete this work within a reasonable period, as agreed by both parties.
Section C – The Report Writing Standard
- All CyAS reports must be structured in such a way that the Customer can plan their remediation, and must adhere to the following overall standards:
- the CyAS Assured Service Provider logo must be clearly displayed;
- the title page must include the name and dates of the Cyber Adversary Simulation;
- the report may be written either by the primary CyAS Lead Operator or by a CyAS Lead Operator who was part of the Cyber Adversary Simulation team. In both cases, the primary CyAS Lead Operator must sign off the report. The name of the author and the primary CyAS Lead Operator must be in the report;
- the report must not contain any sensitive data (as determined by the Customer), passwords or any personally identifiable information (outside of the name of the author and the primary CyAS Lead Operator);
- wherever there is the probability of distress to an individual (for example, because access was achieved through social engineering), you must redact all information in the report which identifies users directly or by association (for example, a client machine). Instead, the report must reference individuals in a neutral way (for example, USER-1, HOSTNAME-A). Alongside the report, the author must prepare a separate glossary or mapping document for internal Customer use only, which identifies the anonymised individuals and other elements in the report; and
- the author must always use neutral language, for example ‘allow/deny list’ rather than ‘whitelist/blacklist’.
Executive summary
- The report must contain an Executive Summary directed at a non-technical, senior audience.
- The Executive Summary must include a summary of:
- how the Cyber Adversary Simulation was performed and how it met the requirements of the scope agreed with the Customer;
- the Customer’s overall security posture and the most significant risks identified;
- the key technical findings and statement of their impacts, written in business language for a non-technical audience; and
- the key recommendations relevant to the Customer's environment, context and any relevant restrictions.
- As a minimum the report must also include the following content:
- table of Contents;
- introduction, scope, objectives/scenarios, limitations;
- technical walkthrough;
- vulnerability reporting, listed either as “Critical”, “High”, “Medium”, “Low” or “Informational”, and a mapping back to NCSC’s Cyber Assessment Framework (CAF); and
- appendices.
Technical Walkthrough
- The report must contain a description of the attack paths taken from initial access to the end objective. Diagrams should be included wherever helpful.
- It is acceptable to link to external resources to provide more details on an issue highlighted in a finding, however, a base level of content describing the issue in the actual report is still required. Providing no detail on an issue and simply providing external links is not acceptable.
Vulnerability reporting
- All vulnerabilities must be accurately identified and described. You must:
- positively confirm the presence of a vulnerability whenever possible and minimise generalisations;
- describe the potential impact of all identified vulnerabilities, as appropriate to the Customer's environment, context and any relevant restrictions;
- assess the severity of a vulnerability as described in paragraph 85 and explain any reduction in severity rating;
- clearly identify hosts affected by each vulnerability, including relevant TCP or UDP port numbers where applicable. Where the list is too long or complex for inclusion in the main body of the report, you must list the affected hosts in an appendix; and
- group together vulnerabilities falling into the same type or class.
Severity ratings
- Cyber Adversary Simulation reports must state the level of risk as CRITICAL, HIGH, MEDIUM, LOW or INFORMATIONAL. You must determine the level of risk by combining your knowledge of the severity with the impact on the Customer if that vulnerability were exploited, and your knowledge of mitigations or other controls in place.
Vulnerability recommendations
- You must provide a solution for each vulnerability identified. You must:
- be accurate;
- refer to existing controls and describe them in procedural form wherever possible;
- provide resources containing further information on a vulnerability;
- be impartial and not favour the products of any particular vendor, paying attention to value for money;
- be relevant to the Customer’s environment, context and any relevant restrictions;
- avoid blanket recommendations; and
- provide alternative, appropriate recommendations if the full solution cannot be implemented within a reasonable timeframe.
Appendices
- You must use appendices and supplementary documents where it makes sense to do so, for example the engagement timeline. The appendices must be provided in such a way that allows the Customer to ingest it easily.
- You must include all Reconnaissance findings as an appendix.
Section D - The Individual Competency Framework
CyAS Engagement Manager
| Competency Area | Competency Description |
|---|---|
| Communication Management | Ensure clear communications both pre-agreed and ad-hoc including out of band channels are setup and maintained. Identify, plan, and agree communications strategy for the engagement. |
| Legal and Compliance awareness | Awareness of legislation relating to adversary simulation and specific regulatory requirements. |
| Planning and Delivery | Able to support the technical delivery of an engagement through:
Determining when to make use of additional resource. |
| Planning and Delivery | Identify, plan, and agree contingencies for deliverables, and rules for their use. |
| Planning and Delivery | Able to account for all actions they take within a client estate. |
| Quality Management | Able to conduct quality assurance for all report deliverables. |
| Risk Management | Identify, plan, and agree risk mitigation strategies for objectives. Identify, plan, and agree risk thresholds for objectives. |
| Risk Management | Able to design and manage authorisation process for risk threshold changes to the scope of the engagement. |
| Risk Management | Able to identify business and operational impact of lateral movement into other components of the target estate and provide guidance to the customer on how to de-risk that activity. |
| Risk Management | Able to coordinate the timely disclosure of risk, critical vulnerabilities and recommend when to make use of contingencies. |
| Risk Management | Ensure that the engagement does not breach rules of engagement, agreed risk thresholds or break the law. Work with the Customer Core Team to agree test progression once agreed milestones are secured and document these decisions. Maintaining Customer Core Team visibility of the Scope. |
| Risk Management | Able to adapt test plan and execute contingencies in response to the disclosure of critical vulnerabilities mid-objective. |
| Scope Management | Ensure engagement timetable and resources are sufficient for delivery of agreed engagement. |
| Scope Management | Assist with the generation of objectives; validating them to ensure that they are legally and ethically possible. |
| Scope Management | Able to identify high value targets within the target organisation and codify them as objectives within proposed scenarios with sufficient safeguards. |
| Stakeholder Management | Ensure clear escalation paths, including contact details, for the engagement exist for both customer and delivery team, including out of hours if necessary. |
| Stakeholder Management | Provide guidance to assist the customer in identifying key stakeholders for engagement. |
| Stakeholder Management | Manage customer and Scheme Partner expectations of engagement. |
| Stakeholder Management | Able to document confirmation of agreed engagement actions, including those made on out of band channels. |
| Stakeholder Management | Able to proactively gather evidence and use it to brief key stakeholders. |
| Stakeholder Management | Maintain regular contact with key stakeholders. Provide clear briefings of engagement progress to non-technical stakeholders. Author and present briefings to senior stakeholders. |
| Technical Communication | Able to communicate technical information about identified vulnerabilities into language suitable for a non-technical audience. |
| Technical Communication | Able to identify critical vulnerabilities which present significant risk to Customer organisations and communicate them in a timely manner. |
| Technical Communication | Able to author and deliver management or executive summaries of the engagement for senior stakeholders. |
| Technical Communication | Able to identify business failings that are the root cause for technical issues. Able to evaluate proposed remediation actions against root causes. |
CyAS Lead Operator
The CyAS Lead Operator role must be able to perform all tasks expected of a CyAS Operator as well as the following:
| Competency Area | Competency Description |
|---|---|
| Initial Access | Able to develop, document and create assets for use during the Cyber Adversary Simulation engagement. |
| Initial Access | Able to design, implement and execute initial access approaches and a back-up strategy if De-Chaining is necessary. |
| Initial Access | Able to identify and triage initial access position, then progress towards objectives. |
| Legal & Compliance Awareness | Understanding of legislation and regulatory obligations relating to adversary simulation. |
| Reconnaissance/Discovery | Identify and exploit cloud resources. |
| Reconnaissance/Discovery | Able to enumerate authentication methods, including where multi factor authentication (MFA) is enabled. |
| Reconnaissance/Discovery | Able to enumerate logical network segregation and identify purpose of segregation. |
| Resource Development | Able to procure, deploy and secure attack infrastructure. |
| Scope Definition | Able to elicit and validate high value targets within the target organisation and codify them as objectives within proposed scenarios. |
| Technical Communication | Able to provide technical input into post engagement executive briefing in appropriate language. |
CyAS Operator
| Competency Area | Competency Description |
|---|---|
| Clean-up | Able to create and document restoration steps for any changes made during the engagement. |
| Collection/Exfiltration | Able to consolidate and collate (and sanitise if necessary) data, ready for exfiltration if required. |
| Credential Access | Able to identify, secure and use credentials within the target environment. |
| Defence Evasion | Able to evade common end-point security software. |
| Discovery | Perform on-host triage to determine position in network, products in use and routes towards achieving test objectives. |
| Execution | Capable of operating on multiple C2 tool chains. |
| Lateral Movement | Able to move laterally across estate within same OS family. |
| Legal & Compliance Awareness | Awareness of legislation and regulatory requirements relating to adversary simulation. |
| Non-Repudiation | Able to account for and evidence all actions that were taken within a Customer’s estate and the rationale behind these actions. |
| Persistence | Able to ensure the selected implant is persistent across Operating System (OS) reboots. |
| Privilege Escalation | Able to privilege escalate and relaunch C2 within a higher privilege context. |
| Reconnaissance | Capable of enriching existing data using Open-source intelligence (OSINT) techniques. |
| Reconnaissance | Able to select and execute tools with sufficient situational awareness so as not to compromise C2 infrastructure. |
| Reconnaissance | Able to identify host operating systems and approaches to gaining further footholds through privilege escalation or lateral movement. |
| Scope Awareness | Able to identify and avoid systems that are out of scope. |
Examples of scoping goals and objectives
Example goal 1: An actor attempts to deploy ransomware across a network
Example objectives 1:
- Gain initial access to the network.
- Reach a position with the relevant access where ransomware could be deployed across a significant amount of the network.
Example goal 2: A hostile threat actor attempts to access operational technology (OT)
Example objectives 2:
- Gain initial access to the enterprise network and identify how to connect to the OT network.
- Prove access/connectivity to the OT network and proceed no further.
Document information
Version history
| Date | Version | Change history details | POC |
|---|---|---|---|
| 17/03/2026 | 1.0 | Initial Release | CyAS Scheme Management Team |
| September 2026 | 1.1 | Update to document review cycle from Oct – Dec to an annual review. Minor updates to the definition table. Style and formatting updates throughout. Update to Service Owner section clarifying annual report and CE+ certificate submission requirements. Additional paragraphs 1,2 & 3 providing additional context to the Scheme. Additional paragraphs 5 & 6 covering board/senior management commitment. Addition of Cyber Threat Defence paragraph 9, aligning requirements with other Schemes. | CyAS Scheme Management Team |
We will review this document annually
Document owner
National Cyber Security Centre (NCSC). All material is UK Crown Copyright ©.
Abbreviations and definitions
The following capitalised terms shall, unless the context requires otherwise, have the following meaning:
| Term | Definition |
|---|---|
| Active Testing | means the period during a CyAS in which the CyAS Operators actively assess the target environment drawing on the information obtained through reconnaissance to holistically assess the organisations resilience to attack |
| Agreement | means the “Ecosystem Agreement” between the NCSC and Company that the Company must enter into before it can provide CyAS Services, as may be amended from time to time |
| Assumed Breach | means an approach which prioritises the testing of internal systems and processes during a Cyber Adversary Simulation, by enabling the CyAS Team’s access onto a target device with an agreed level of access (e.g. standard corporate laptop with standard user account) |
| Attack Path | means the route followed by the Company during the Active Testing phase of a CyAS to achieve one or more objectives |
| Attacker | means a malicious actor who seeks to take advantage of weaknesses in a system, application, or network to achieve goals unintended by the computer system/network owner |
| Company | means the organisation which is, or is applying to become, a member of the Scheme, and “Companies” shall be interpreted accordingly |
| Customer Core Team | means the personnel assigned by the Customer to engage with the CyAS Team. As a minimum this should include technical, risk and data owner representatives |
| Customer | means an organisation which contracts with the Company for CyAS Services |
| Cyber Adversary Simulation (CyAS) | means a simulated cyber-attack, carried out in accordance with the NCSC methodology for CyAS Services, as set out in Section B |
| Cyber Assessment Framework (CAF) | means the tool created by the NCSC which helps an organisation to achieve and demonstrate an appropriate level of cyber resilience in relation to certain specified essential functions performed by that organisation |
| CyAS Engagement Manager | means an NCSC-approved Company staff member or contractor appointed to manage the relationship between the Company and the Customer during CyAS engagement(s) |
| CyAS Services | means cyber adversary simulation services provided by the Company that comply with the Standard and which systematically test the cyber defences of an organisation against realistic cyber attack, and “Service” shall be construed accordingly |
| CyAS Service Owner | means the person in the Company with overall accountability for the provision of CyAS Services |
| CyAS Service Technical Lead | means the person in the Company accountable for the technical delivery of CyAS Services |
| CyAS Lead Operator | means an NCSC-approved Company staff member or contractor appointed as a team leader to lead teams during delivery of CyAS Services |
| CyAS Operator | means an NCSC-approved Company staff member or contractor appointed to assist the CyAS Lead Operator with the delivery of the CyAS Services |
| CyAS Team | means the team of individuals at the Company supporting delivery of the CyAS Services |
| Cyber Oversight Body | means an entity responsible for understanding the extent to which all the organisations within their sector are successfully managing cyber risks, such as a cyber regulator or government policy organisation |
| Deliberately Damage | means intentionally causing harm outside of the scope of the CyAS Services agreed with the Customer |
| De-Chain Event/De-Chaining | means events and actions agreed between the Customer and the Company, which help the Company to make progress if a Cyber Adversary Simulation stalls. These could include facilitating access or privileges within the Customer network that allow the Company to progress with their objectives |
| Essential Service | means services that are critical to the national infrastructure (e.g. water, energy, transport) or significantly important to the economy and wider society like health services and digital infrastructure |
| Full Spectrum | means CyAS engagements that include attempts to gain initial access to a Customer’s enterprise IT network through external attack services, such as phishing campaigns or external portals |
| Initial Access | means the period during which the CyAS Operators evaluate and actively overcome preventative security controls of the target environment in order to gain an initial foothold |
| Internal Phase | means the period during which continual active reconnaissance and internal activities are conducted to progress towards the agreed objectives |
| NCSC | means the National Cyber Security Centre |
| OSINT | means the act of conducting reconnaissance involving the collection and analysis of publicly available information to map an organisation's digital footprint, identify vulnerabilities, and uncover attack vectors. It is used to simulate how adversaries gather intelligence on employees, technology stacks and physical locations |
| Reconnaissance | means the process of gathering information about the target system, network, or organisation to understand its structure, weaknesses, and defensive measures |
| Scheme | means the NCSC Cyber Adversary Simulation Scheme |
| Scheme Partner | means a Cyber Oversight Body that chooses to use the Scheme in their sector |
| Standard | means the standards which must be met to be part of the Scheme as set out in this document |
| We/Us/Our | means the NCSC |
| Working Practices Document | means the document setting out required working practices in relation to the Scheme titled ‘Cyber Adversary Simulation (CyAS) Scheme – Working Practices’ as may be amended from time to time |
| You/Your | means the Company |


