Cyber Resilience Audit
The Cyber Resilience Audit (CRA) scheme assures companies delivering independent cyber audits, based on the Cyber Assessment Framework (CAF).

Information for Cyber Resilience Audit Scheme Partners
The NCSC has worked with Cyber Oversight Bodies to develop the CRA Scheme to assure suppliers to meet their collective requirements. Cyber Oversight Bodies which use the Scheme in their sector are referred to as Scheme Partners.
The NCSC works with Scheme Partners, users and suppliers to continuously improve the scheme.
Role of Scheme Partners
The Scheme Partners may encourage, recommend or require the organisations they oversee to have audits conducted by Suppliers that are members of the CRA Scheme.
Scheme Partners are responsible for:
- defining how the audits are conducted in their sector
- setting additional sector specific requirements
- providing guidance to buyers in their sector regarding any specific additional requirements
It is the buyer’s responsibility to assure themselves that their chosen Suppliers meets the requirements set out by the Scheme Partner.
For more information on the role of Scheme Partners, see the Scheme Working Practices document (also available in the Downloads section)
Information for prospective Scheme Partners
If you are a Cyber Oversight Body and interested in using the scheme in your sector, please contact [email protected] for more information.