Cyber Incident Response

Information for Cyber Incident Response service providers
About the Cyber Incident Response (CIR) scheme
The NCSC assures cyber incident response companies which have the capability to investigate cyber attacks and support client organisations which are targets.
The NCSC expects its Cyber Incident Response Assured Service Providers to be able to:
- Understand the capabilities and behaviours of threat actors.
- Determine the extent of an incident on enterprise networks.
- Ensure that the immediate impact is managed as rapidly and effectively as possible.
- Provide suitable recommendations to remediate the compromise and increase security across the victim’s network.
- Produce an incident report including, at minimum: a full description of the scope of the problem, the technical impact, mitigation activities and an assessment of business impact.
- Give an Impact Assessment which can be used by the victim to explain the incident to other parties (partners, regulators or customers).
Cyber Incident Response - Enhanced Level
Service Providers which are assured to the CIR Enhanced Level standard are expected to have the capability to support cyber incident response for organisations which are part of UK central government, the Critical National Infrastructure, or which operate in a regulated sector or more than one country.
Service Providers are expected to have experience in and capability to deal with incidents caused by nation-state backed actors.
CIR Enhanced Level Assured Service Providers may also deliver services at CIR Standard Level. The requirements of CIR Standard Level are a subset of the requirements for CIR Enhanced Level.
Cyber Incident Response - Standard Level
Service Providers which are assured to the standard of the CIR Standard Level are expected to have the capability to support cyber incident response for most private sector organisations, charities, local authorities, smaller public sector organisations and organisations that predominantly operate in the UK.
Service Providers are expected to have the experience and capability to deal with incidents caused by financially motivated criminals (such as business email compromise, ransomware, etc.)
Additional information
Assured Service Providers from either CIR Enhanced Level or Standard Level will be able to assist with most cyber incidents. However, CIR Standard Level companies are not assured by the NCSC to provide services at Enhanced Level unless they have also achieved the technical standard for CIR Enhanced Level.
Client organisations will need to do their own due diligence to decide the suitability of the Assured Service Providers to meet their needs.
As part of their Scheme membership, Assured Service Providers will be required to share with the NCSC limited, non-attributable information about their incident response engagements. We will use this information for trend analysis purposes, to inform future advice and guidance to the UK and to help improve our products and services.
How to join the Cyber Incident Response scheme
If your company would like to apply to become a Cyber Incident Response Assured Service Provider, you will need to submit information to demonstrate your organisation’s compliance with the NCSC’s relevant CIR Technical Standards.
Enhanced Level
If your company would like to apply to be assured to the standard for the CIR Enhanced Level, the Standard, Working Practices and a sample Application Form are available in the Downloads section below.
The following pre-requisites must be in place before an application is accepted:
- All scheme members must hold a valid Cyber Essentials Plus (CE+) certificate for the systems on which they hold and process customer data.
- All new applicants are members of the CIR scheme at Standard Level. Information on how to join the scheme at CIR Standard Level is below, or directly from our Delivery Partners, CREST and IASME
- The proposed Head Consultant must have a UK Cyber Security Council Professional Title for the Incident Response at the Chartered level. Information on the Incident Response specialism and how to apply for the Title will be available from the UK Cyber Security Council's webpage: Become Professionally Registered.
Please send the following to [email protected]:
- Screenshot of your UKCSC Registrant Profile, including membership number and registration date
- Screenshot of your CE+ certificate
Once received and verified, you will be sent an Application Pack.
The application process
The application process for the scheme comprises:
- Part A: Commercial questionnaire and checks
- Part B: Review and validation of the application
- Part C: Assessment Panel of NCSC and Industry SMEs
- Part D: Interview of proposed Head Consultant and Service Owner (as required)
- Part E: Contract signing and onboarding
Applications will only progress to the next part after successful completion of the previous step. Successful applications must pass all stages.
Application attempts are limited to no more than two in any 12-month period.
Assessment Panels will be run 3 times per year or subject to demand. The closing date for the next assessment panel is 25 September 2026 at 1600.
Standard Level
If your company would like to apply to be assured to the standard of the CIR Standard Level, please contact our Delivery Partners CREST or IASME directly.
You must hold a valid Cyber Essentials certificate for the systems on which you hold and process customer data.
Crown Commercial Services Procurement Agreement
The central dedicated procurement route for government and wider public sector procurement buyers to obtain cyber security services is the Crown Commercial Service (CCS) Procurement Agreement for Cyber Security Services. As an Assured Cyber Incident Response Provider you are able to apply to be registered as an NCSC Assured supplier for the service(s) you offer under the scheme.
At the NCSC, we are taking action to remove artificial barriers to entry to all of our Schemes. So, if you spot something which you think unfairly prevents you from applying, please let us know using our feedback form.
Downloads
- 243.35 KB
CIR Enhanced Level - Scheme Standard
Sets out the standards which current and prospective CIR Assured Service Providers are assessed against, in order to become an NCSC-assured CIR Assured Service Provider for Enhanced Level. December 2024.
- 230.5 KB
CIR Working Practices
Sets out certain obligations on all Scheme members and outlines how the NCSC and Scheme members will work together. January 2025.
- 1.44 MB
CIR Standard Level - Scheme Standard
Sets out the standards which current and prospective CIR Assured Service Providers are assessed against, in order to become an NCSC-assured CIR Assured Service Provider for Standard Level. December 2024 update.
- 246.48 KB
CIR Buyer's Guide
Guidance and clarity around the NCSC’s Assured Cyber Incident Response Scheme and is intended for buyers of Cyber Incident Response services
- 373.56 KB
CIR sample application form
Sample CIR Enhanced Level application form.