Cyber Resilience Audit
The Cyber Resilience Audit (CRA) scheme assures companies delivering independent cyber audits, based on the Cyber Assessment Framework (CAF).

Find NCSC assured provider to deliver independent cyber security audits.
What is the Cyber Resilience Audit scheme?
The Cyber Resilience Audit scheme gives consumers confidence in companies that have been assessed as meeting the NCSC standard for delivering independent cyber audits.
The Cyber Resilience Audit scheme members will undertake independent cyber audits on behalf of a Cyber Oversight Body.
The scheme is initially a Minimum Viable Product; therefore, the initial independent audits will be against Cyber Assessment Framework (CAF) but, flexible enough to be used to audit against any Cyber Security Standard.
How does the scheme work?
The NCSC assessed that scheme members, known as Assured Service Providers (ASP), can provide independent audit services which meet the Cyber Resilience Audit scheme standard.
Cyber Oversight Bodies (such as cyber regulators or government policy organisations with responsibility for understanding cyber resilience of organisations within the sector) that use the scheme in their sector are referred to as Scheme Partners.
Scheme Partners may encourage, recommend or require the organisations they oversee to have audits conducted by CRA Assured Service Providers. More information about Scheme Partners can be found on the Scheme Partners page.
Buyers then procure the services of the CRA ASP, ensuring that all Scheme Partner requirements are met ahead of the independent audit.
The output from audits will help Scheme Partners to understand the level of cyber resilience of individual organisations in their sector and contributes to a more accurate picture of cyber resilience at both a sector and national level.
Who is it for?
The scheme is aimed at organisations such as Operators of Essentials Services (OES) which are overseen by Cyber Oversight Bodies and could be encouraged, recommended or required to undertake an independent cyber audit.
However, CRA can equally be useful for any organisation seeking an independent audit of their cyber resilience for their own due diligence purposes.
For more information, please visit the Information for buyers pages.