Cyber Resilience Audit
The Cyber Resilience Audit (CRA) scheme assures companies delivering independent cyber audits, based on the Cyber Assessment Framework (CAF).

Information for Cyber Resilience Audit service providers
About the scheme
These services are primarily delivered to government departments, the wider public sector, and organisations operating in Critical National Infrastructure or specifically-regulated sectors, although organisations outside of these spheres may also buy Cyber Resilience Audits for their own benefit.
All CRA Assured Service Providers are assessed as meeting the NCSC technical standard for CRA and are entitled to use the associated NCSC logo.
How to join the scheme
We are currently updating the scheme standard to transition from Minimum Viable Product phase into Business as Usual operations.
While this work is underway, we are unable to accept new applications for the remainder of 2026. We will announce the dates of the next application cycle in December. Please visit this website for updates and information on how to register when applications reopen.
Please note that future applications will be submitted against the new standard and accompanying documents when it is available, and not the published standard and working practices.
Before conducting an independent audit
As an Assured Service Provider, you are responsible for ensuring that you meet any additional requirements set out by the Scheme Partners and attend any training specific to the sector if it is required by a Scheme Partner.
Scheme documents
Scheme documents are also available from the Downloads section.
Downloads
- 288.62 KB
CRA Application form and terms
Document contains sample application form and the terms and conditions of applying to the CRA scheme.
v1.2 August 2024
- 210.19 KB
CRA Scheme Standard
Defines the standards required for scheme membership. Should be read in conjunction with the CRA Working Practices document and Ecosystem Agreement.
v1.0 of July 2024
- 259.69 KB
CRA Working Practices document
Document sets out the obligations on all Scheme members and must be read in conjunction with the Standard and Ecosystem Agreement.
v1.1 October 2024