Cyber Adversary Simulation (CyAS)
Companies assured under the Cyber Adversary Simulation scheme deliver services to test an organisation’s cyber resilience, including their ability to prevent, detect and respond to simulated cyber attacks.
Cyber Adversary Simulation (CyAS) Scheme Working Practices Document
version 1.1, September 2026
Scheme Membership
- This document sets out the obligations on all Cyber Adversary Simulation Scheme members must comply with in order to retain their membership on the scheme. It also sets out how the NCSC and scheme members will work together. You must read it in conjunction with the Standard and the Agreement.
- The Cyber Adversary Simulation Scheme is being launched as a Minimum Viable Product, and we expect it to evolve. Therefore, requirements and obligations on Companies may change. We will take reasonable steps to notify you in advance of such changes, in accordance with the terms of the Agreement.
- By way of example, if the UK Cyber Security Council (UK CSC) launches a Professional Title for Adversary Simulation, and it meets our scheme requirements for proving individual competence, we will alter our scheme Standard accordingly. We recommend that you stay up-to-date with developments in the UK CSC’s Professional Registrations work.
Managing Your Organisation
Communications
- You can contact the Cyber Adversary Simulation Scheme Management team by email at [email protected]. The inbox is normally monitored during standard office hours. Please mark your email ‘CyAS’ in the subject line.
Supplier Portal
- The Supplier Portal is a secure central platform used to administer some NCSC Industry Assurance schemes, including elements of the CyAS scheme. It supports the consistent management, tracking, and recording of scheme activities and their outputs.
- You must maintain enough active Supplier Portal users, with appropriate permissions, to meet the requirements for using the Supplier Portal, as set out in this document.
- You must make requests for new Supplier Portal users by emailing [email protected] including the name and email address of the individual. Once approved, a new user will receive a copy of the latest Supplier Portal user guidance, and an automatic email to set up a MyNCSC account and 2-Step Verification (2SV).
Personnel
- Personnel requirements are laid out in Section A of the Standard and are the minimum requirements for remaining in the Cyber Adversary Simulation Scheme.
- If you change any of the named personnel, you must request an edit to your Company information by emailing the NCSC’s CyAS Scheme Management Team within five working days. We will inform you of the appropriate process to follow depending on the change requested.
- The CyAS Service Technical Lead is accountable for all Engagement Managers, CyAS Lead Operators and CyAS Operators in the Company and for ensuring they meet the standards outlined in Section A of the Standard. CyAS Service Technical Leads must personally sign off all applications.
- You must maintain an accurate and up-to-date organogram of the staff who are regularly involved in your CyAS Service and make it available to the NCSC on request.
Subcontractors
- You may only sub-contract provision of CyAS Services to other Companies that are CyAS Scheme members.
- You are responsible for ensuring that all such sub-contractors remain a member of the CyAS Scheme, that they are entitled to work under the scheme, and that the personnel they deploy must meet the relevant Scheme requirements throughout their deployment.
- To ensure that sub-contracting arrangements are accurately and properly recorded, it is the responsibility of the Company contracted by the Customer to provide the CyAS Services to inform the NCSC when it is sub-contracting such services.
Security
- In accordance with paragraph 8 of the Standard, you must maintain an in-date Cyber Essentials Plus certificate for all the business systems on which information relating to Customers’ engagements is stored and processed. You must provide us with the certificate number on an annual basis and inform us of any changes.
Delivering CyAS Services
Requesting a CyAS reference number and submitting a report
- You must register every CyAS engagement on the Supplier Portal to obtain a reference number. You must obtain before the initial passive reconnaissance takes place.
- You must provide the following information:
- company internal reference;
- client name;
- client sector (Central Government, Public Sector, or CNI);
- start date of the engagement;
- end date of the engagement;
- name of the engagement manager
- name of the primary lead operator; and
- name of any other operators involved in the engagement.
- If these details align with those held on the Supplier Portal, the request will be automatically approved, and a number will be generated. If not, the CyAS Scheme Management Team will endeavour to review the request within three working days. You must respond within three working days to any request for further detail. Failure to do so will result in the request being rejected or cancelled.
- You must upload the CyAS report to the Supplier Portal within thirty days of the end of the engagement.
Buyers’ Guide
- The NCSC has produced a “Buyer’s Guide” which you must supply to all prospective Customers.
- The Buyer’s Guide explains which aspects of your service the NCSC assures, and which aspects are the Customer’s responsibility to check. It also specifies that you have a contractual obligation to submit completed CyAS reports to the NCSC.
- If the classification of the system legitimately does not permit the report to be taken off site, you must arrange for us to have access to the report at the Customer’s premises, if we request it.
Additional Sector-Specific Requirements
- We expect a number of Scheme Partners to source suppliers from the CyAS Scheme. Membership of the Scheme does not guarantee you will be able to conduct Cyber Adversary Simulations in all sectors. A Scheme Partner may define additional sector-specific requirements which you must meet in order to conduct a CyAS in that sector. Sector-specific requirements may include, by way of example only, specialist sector-specific knowledge, or evidence of working in environments where specialist or bespoke technologies are used, such as Operational Technologies and Industrial Control Systems.
- In addition to satisfying the NCSC’s requirements for membership of the Scheme, Companies wishing to bid for work with Scheme Partners or in specific sectors must meet whatever additional requirements are levied, and work in accordance with those requirements.
Professional Standards
Conflicts of Interest
- You will seek to avoid any situation that may give rise to a conflict of interest between you, the Customer, and the Scheme Partner. Examples of potential conflicts of interest include (but are not limited to):
- a Company conducting a CyAS for a Customer for whom they have implemented or consulted on any of the elements covered in the scope of the CyAS; and / or
- a Company with a financial or personal interest in products or services covered under the scope of the CyAS.
- You must notify the relevant Customer or Scheme Partner if you become aware or suspect an actual or potential conflict of interest.
Ethical Behaviour
- You must have and abide by a Code of Ethics, which mirrors the spirit of the UK Cyber Security Council’s Ethical Declaration and the UK Cyber Security Council's Guiding Principles for Individuals.
- You must uphold the highest standards of professionalism, integrity, and ethical conduct in all aspects of your operations. This responsibility extends beyond ‘technical’ teams to all individuals involved in delivering the assured service, including in areas as diverse as client interactions, business development, and commercial/procurement activities.
- You will adopt an ethical approach to meeting Customers’ and, where applicable, Scheme Partners’ needs.
- Where the output or outcome requested by the Customer or the Scheme Partner does not meet your understanding of the Customer’s or Scheme Partner’s needs, you must fully explain why and seek a resolution.
- A failure to uphold such standards, and any behaviour or actions deemed unethical or which risk bringing our schemes or the NCSC into disrepute, may result in your Company being removed from the scheme.
Complaints
- In accordance with the Agreement, you must have a process for receiving and notifying us of any Customer complaints. You must report these complaints (suitably anonymised where appropriate, and to manage data protection obligations) to us and relevant Scheme Partner as soon as reasonably practicable.
- It is expected that in the first instance, the relevant Scheme Partner will investigate any complaints or issues and only involve us where it relates to your continuing ability to fulfil the responsibilities and obligations that relate to the Scheme.
Maintaining Scheme Membership
Ongoing Membership Validation
- Before the end of April every year you must submit;
- an annual Management Information Report detailing the work of the previous financial year (i.e. beginning of April to end of March). We will provide a template for you to complete. You must maintain records to support the completion of this report; and
- an up-to-date organogram covering all who support delivery of your CyAS Service, identifying the names and roles.
- We regularly review CyAS reports submitted against the Standard and provide appropriate feedback to the CyAS Service Technical Lead and Service Owner.
- We may proactively seek feedback from Customers on the quality of the CyAS Service received and the Customer’s satisfaction. In the event of poor feedback or complaints, we will engage with you to seek improvements and resolution, in accordance with the terms in the Agreement.
- On a rolling basis, we reserve the right to carry out commercial due diligence checks.
- As a minimum, every three years, you must submit a revalidated letter of support from a suitably senior member of your Company (as set out in the Standard).
- If at any time while you are a member of the Scheme, we assess that you no longer meet the Scheme requirements, we may instigate the delivery risk mitigation process (see paragraph 40 below).
Delivery Risk Mitigation Plan
- Should we identify a failure to meet the Scheme requirements, we may notify you that a delivery risk mitigation plan (a “Mitigation Plan”) is required. Within 20 working days of such notification, and on behalf of the Company, the Service Owner must develop and present to the NCSC a draft Mitigation Plan for approval that, in light of the failure to meet the requirements of the Standard, details steps that you will take to mitigate and minimise the risk:
- of damage to the reputation of the CyAS Scheme or wider NCSC; and
- to customers who receive CyAS Services.
- Should we inform you in writing that we are satisfied with a draft Mitigation Plan submitted in accordance with paragraph 40, the Mitigation Plan shall become final and you shall act in accordance with it. Should we not be satisfied with a draft Mitigation Plan you present, we shall explain our reasons in writing and give you a further 10 working days to submit a revised draft Mitigation Plan to the NCSC. If, on submission of a third draft Mitigation Plan, we remain unsatisfied with the plan and view that unacceptable risks remained unmitigated, we may withdraw your Company’s Scheme membership.
- While you are not expected to set out in the Mitigation Plan how you will address any failure that the NCSC has identified, you must ensure that these are remedied within six months of NCSC notification (the “Remediation Period”) in accordance with paragraph 40 above.
- We will re-assess you once the Remediation Period has passed. If you meet the Standard, no further action will be taken. However, if you still do not meet the Standard, we may take further action up to and including removal of the Company from the Scheme.
- Unless we inform you otherwise, you may remain part of the CyAS Scheme for the duration of the Remediation Period (maximum of six months).
Social Values and Scheme ‘Give Back’
- We expect all CyAS companies to actively engage with us and with each other on a regular basis. As a minimum, all Engagement Managers and CyAS Lead Operators must attend a minimum of two NCSC Scheme events per year. Other engagements include, but are not limited to:
- providing a technical speaker (e.g. a CyAS Lead Operator, Service Technical Lead or other expert within the company) to deliver a presentation at a minimum of one community event in any two-year period;
- participating in Scheme-specific workshops and discussions, convened by the NCSC or another relevant party;
- providing expert input to upcoming or proposed NCSC guidance;
- liaising with NCSC in-house experts on the delivery of specific advice and guidance to third party Customers;
- actively promoting NCSC advice and guidance in the wider industry community and to Customers; and
- responding to NCSC emails or requests for information with regards to the Scheme.
Document information
Version history
| Date | Version | Change history details | POC |
|---|---|---|---|
| 17/03/2026 | 1.0 | Initial Release | CyAS Scheme Management Team |
| Sept 2026 | 1.1 | Update to document review cycle from Oct – Dec to the documents will be reviewed annually. Minor updates to the definition table. Style and formatting updates throughout. Updates to Subcontractor section. Addition of Supplier Portal section and report registration and submission section. Update to Ongoing Membership Validation section with further detail on annual submission requirement. Replacement of Remediation section with Delivery Risk Mitigation Plan section. Update to Social Values and Scheme “Give Back” section with more detail. Update to Security section to require details of CE+ certificate to be sent to the NCSC annually. Update to Ethical Behaviour section with additional paragraphs on expected standards and implications if they are not met. | CyAS Scheme Management Team |
We will review this document annually
Document owner
National Cyber Security Centre (NCSC). All material is UK Crown Copyright ©.
Abbreviations and definitions
The following capitalised terms shall, unless the context requires otherwise, have the following meaning:
| Term | Definition |
|---|---|
| Agreement | means the “Ecosystem Agreement” between the NCSC and Company that the Company must enter into before it can provide CyAS Services, as may be amended from time to time |
| Company | means the organisation which is, or is applying to become, a Scheme member and “Companies” shall be interpreted accordingly |
| Customer | means the organisation which contracts with the Company for the provision of CyAS Services |
| Cyber Adversary Simulation (CyAS) | means a simulated cyber attack, carried out in accordance with the NCSC methodology for CyAS Services, as set out in Section B of the Standard |
| CyAS Engagement Manager | means an NCSC-approved Company staff member appointed to manage the relationship between the Company and the Customer during CyAS engagement(s) |
| CyAS Services | means cyber adversary simulation services provided by the Company that comply with the Standard and which systematically test the cyber defences of an organisation against realistic cyber attack, and “Service” shall be construed accordingly |
| CyAS Service Owner | means the person in the Company with overall accountability for the provision of CyAS Services |
| CyAS Service Technical Lead | means the person in the Company accountable for the technical delivery of CyAS Services |
| CyAS Lead Operator | means an NCSC-approved Company staff member appointed as a team leader to lead teams during delivery of CyAS Services |
| CyAS Operator | means an NCSC-approved Company staff member appointed to assist the CyAS Lead Operator with the delivery of the CyAS Services |
| CyAS Team | means the team of individuals at the Company carrying out the CyAS Services |
| Cyber Oversight Body | means an entity responsible for understanding the extent to which all the organisations within their sector are successfully managing cyber risks, such as a cyber regulator or government policy organisation; |
| Industrial Control Systems | systems, often in the field of critical national infrastructure, which control and respond to physical feedback |
| Mitigation Plan | has the meaning given to it in paragraph 40 |
| NCSC | means the National Cyber Security Centre |
| Operational Technology | means technology that interfaces with the physical world and includes industrial control systems (ICS), supervisory control and data acquisition (SCADA) and distributed control systems (DCS) |
| Remediation Period | has the meaning given to it in paragraph 42 |
| Scheme | means the NCSC Cyber Adversary Simulation Scheme |
| Scheme Partner | means a “Cyber Oversight Body” that chooses to use the Scheme in their sector |
| Standard | means the document setting out the standards which must be met to be part of the Scheme, titled ‘Cyber Adversary Simulation (CyAS) Scheme – Scheme Standard’ |
| We/Us/Our | means the “NCSC” |
| Working Practices Document | means this document |
| You/Your | means the Company |


