Cyber Resilience Audit
The Cyber Resilience Audit (CRA) scheme assures companies delivering independent cyber audits, based on the Cyber Assessment Framework (CAF).

Information for Cyber Resilience Audit buyers
If your organisation is considering procuring the services of a CRA Assured Service Provider for independent cyber audits, it is likely to be a result of either:
- Your Cyber Oversight Body has partnered with the NCSC to become a Scheme Partner and is encouraging, recommending or requiring the use of the scheme in their sector.
Or
- Your organisation is looking to carry out due diligence activities to understand their cyber resilience.
Information for buyers
An organisation procuring the services of a CRA Assured Service Provider is referred to as a buyer.
All Cyber Resilience Audit Scheme Assured Service Providers have been assured against the NCSC standard and are considered capable of providing high quality independent audits.
As a result of the assurance requirements a buyer can have confidence that:
- The CRA service is overseen by a Head Consultant who holds a professional registration for the Cyber Audit and Assurance specialism Chartership title, awarded by the UK Cyber Security Council, ensuring quality and competence. For more information see https://www.ukcybersecuritycouncil.org.uk/careers-and-learning/cyber-career-framework/cyber-security-audit-assurance/
- The Team Leader delivering the audit holds a professional registration for the Cyber Audit and Assurance specialism Principal title (as a minimum), awarded by the UK Cyber Security Council, ensuring quality and competence. For more information see https://www.ukcybersecuritycouncil.org.uk/careers-and-learning/cyber-career-framework/cyber-security-audit-assurance/
- The Service Provider operates the service in accordance with the NCSC’s requirements.
- The Head Consultants have all attended CAF training, provided by the NCSC.
More information about the assurance undertaken by the NCSC can be found in the buyer’s guide.
When to use a Cyber Resilience Audit Assured Service Provider
If your organisation is overseen by a Cyber Oversight Body, please check directly with the relevant organisation if, and how, they are using the scheme in their sector.
It is your responsibility to ensure that the chosen suppliers meet any additional sector specific requirements.
While the scheme provides a level of assurance of Service Providers, you are expected to conduct your own commercial due diligence activities.
The early adopters of the scheme can be found on the Scheme Partner pages, along with the Scheme Partner responsibilities, however, you should check with your relevant Cyber Oversight Bodies to understand if there is a future requirement to use the scheme.
Organisations can also use the services of Cyber Resilience Audit Assured Service Providers to carry out independent audits for their own due diligence purposes.
How to select a Cyber Resilience Audit Service Provider
A full list of the CRA Assured Service Providers can be found on the "Find an assured Cyber Resilience Audit provider" page.
You should select an Assured Service Provider appropriate to your needs and against the requirements set out by the Scheme Partners. You should contact your chosen ASP directly, the NCSC is not party to these contracts.
Considerations for government and wider public sector buyers
Government and public sector buyers will be able to use the Crown Commercial Service’s Dynamic Purchasing System to invite Suppliers to bid for work. Full guidance is available on the Crown Commercial Services website - Cyber Security Services 3 - CSS.
Scheme documents
Scheme documents are also available from the Downloads section of this page.
Downloads
- 203.57 KB
CRA Buyer's guide example letter
Example of the letter sent to provide guidance about how the Buyer engages with companies assured under the CRA scheme.
- 210.19 KB
CRA Scheme Standard
Defines the standards required for scheme membership. Should be read in conjunction with the CRA Working Practices document and Ecosystem Agreement.
v1.0 of July 2024
- 259.69 KB
CRA Working Practices document
Document sets out the obligations on all Scheme members and must be read in conjunction with the Standard and Ecosystem Agreement.
v1.1 October 2024
- 288.62 KB
CRA Application form and terms
Document contains sample application form and the terms and conditions of applying to the CRA scheme.
v1.2 August 2024