Cyber Resilience Audit
The Cyber Resilience Audit (CRA) scheme assures companies delivering independent cyber audits, based on the Cyber Assessment Framework (CAF).

Scheme Partners
Current Scheme Partners
Cyber Oversight Bodies which use the Scheme in their sector are referred to as Scheme Partners.
Below is a list of the Scheme Partners who are early adopters and are encouraging, recommending or requiring the organisations they oversee to have audits conducted by Suppliers that are members of the CRA Scheme.
Department for Science, Innovation and Technology (DSIT) - GovAssure
“The GovAssure team has maintained alignment with Cyber Resilience Audit (CRA) since its inception and we fully support the CRA methodology. Since CRA has been modelled from our processes and principles and customised for CRA, we trust that it will be as successful in the regulator sector. Our list of GovAssure suppliers are moving to the CRA scheme and we will continue to share lessons learnt to improve both of our services.”
Department of Finance, Northern Ireland (DOF NI)
“With responsibility for Water, Health, Energy and Transport in Northern Ireland, the NIS Competent Authority welcomes the launch of the Cyber Resilience Audit Scheme. The scheme provides a structured approach with verified audit providers, who will robustly test the organisation’s network and information systems against the CAF. Directing our OES to use the scheme will greatly enhance our ability to perform our oversight of the cyber resilience of the Operators of Essential Service under our remit. The support for the regulatory community from the NCSC is invaluable and strongly enhances our ability to perform our regulatory functions.”
The Department of Health and Social Care (DHSC) and NHS England (NHSE)
“In September 2024, the Data Security and Protection Toolkit (DSPT) changed to align with the Cyber Assessment Framework (CAF). A specific group of health and care organisations have moved to the CAF-aligned DSPT in 2024-2025 and will see a new user interface when they log in to file their submission.
These organisations are:
- NHS trusts and foundation trusts
- Commissioning support units
- Arm’s length bodies of DHSC
- Integrated care boards
Organisations are required to have an independent audit assessment to the agreed CAF-aligned DSPT audit framework – see the summary guide published via DSPT News. As set out in the summary guide, organisations are encouraged to choose an auditor from NCSC’s CRA assured provider list.”
Department for Business and Trade (DBT) – Chemical Sector
“The Department for Business and Trade (DBT) is committed to enhancing the cyber resilience of the UK’s critical national infrastructure (CNI) within the chemical sector, by supporting the adoption of the Cyber Resilience Audit (CRA) scheme. This scheme will enable both DBT and CNI chemical operators to better monitor and understand operators’ cyber resilience. In turn, we anticipate that this will enable operators to manage cyber risks and vulnerabilities in a more informed manner, strengthening the cyber resilience of Operational Technology (OT) systems and facilitating a consistent approach to assurance, in line with Government cyber security strategic objectives.”
Office for Nuclear Regulation (ONR)
“As a non-prescriptive and outcome focused regulator ONR does not mandate use of the CAF. Instead, ONR uses the Security Assessment Principles (SyAPs) to ensure consistency in regulatory judgements. The SyAPs provide a holistic approach to regulation, aligned with our mature nuclear safety regime.
Outcome focussed regulation allows flexibility in approach and encourages innovation to provide effective and robust protection against the modern threat environment. The SyAPs support this flexibility and enable our dutyholders to adopt a variety of frameworks, including the CAF as part of their arrangements.
Where duty holders choose to adopt the CAF, ONR considers the use of independent cyber resilience assessments carried out by CRA scheme commercial providers as relevant good practice when evidencing their arrangements.”
Prospective Scheme Partners
The following Cyber Oversight Bodies are collaborating with the NCSC CRA Scheme and are exploring using the scheme in the future. Please see the individual statements for their respective positions.
OFGEM – NIS Competent Authority for Downstream Gas and Electricity sector
“Ofgem welcomes NCSC’s CRA scheme and recognises the value that the NCSC CRA scheme can bring in supporting consistent and robust approach to cybersecurity across all sectors. As the NIS Competent Authority responsible for assurance in the Downstream Gas and Electricity sector, we are considering how to incorporate the CRA scheme into our Assurance Framework v2 which is currently being developed. In order to ensure that the CRA meets our regulatory goals we intend to work with NCSC to develop our sector specific requirements for the scheme and share these with the industry in due course.”
OFGEM – Digitalisation
“Ofgem are working with DESNZ on the future of the energy sector. Currently there are a number of programmes that require the ability to audit, assess and certificate Cyber Security resilience across the energy sector. Capable Cyber Security is a common requirement for these programmes as outlined in the following consultations and reports:
- Energy Digitalisation Taskforce Report - https://www.ofgem.gov.uk/publications/beis-ofgem-and-innovate-uk-statement-energy-digitalisation-taskforce-report
- Smart, Secure Electricity System Consultation - https://www.gov.uk/government/consultations/delivering-a-smart-and-secure-electricity-system-implementation
- Governance of the Data Sharing Infrastructure - https://www.ofgem.gov.uk/consultation/governance-data-sharing-infrastructure
- Virtual Energy System - https://www.neso.energy/about/our-projects/virtual-energy-system
With each of these major projects that will massively impact and enhance the energy sector there is a primary and fundamental need to ensure the cyber resilience of every participant and at differing levels of organisation and capability. We see the CRA as an opportunity to have in place the appropriate and proportionate levels of accreditation across all potential market participants.”
Department for Energy Security and Net Zero (DESNZ)
“The Department for Energy Security and Net Zero (DESNZ) welcomes and values the NCSC Cyber Resilience Accreditation (CRA) scheme as an exciting new capability in assuring the cyber resilience of the UK energy sector. As the NIS Competent Authority for oil and upstream gas subsectors and joint-Competent Authority for electricity and downstream gas (with Ofgem) we are working with Ofgem and the Health and Safety Executive (HSE) to see how the CRA can complement our existing assurance activities and sector targets.”
Department for Transport (DfT)
“The Department for Transport (DfT) is currently investigating the applicability of the Cyber Resilience Audit (CRA) scheme to its Operators of Essential Service. Should DfT decide to pursue the scheme, utilisation will not start before FY 2025/26.”
Civil Aviation Authority (CAA)
“The UK Civil Aviation Authority (CAA) is currently considering the applicability of the Cyber Resilience Audit (CRA) scheme to its Operators of Essential Service. Should CAA decide to pursue the scheme to provide additional assurance to OES resilience plans, this will not commence before FY 2025/26.”