Cyber Resilience Test Facilities
About Cyber Resilience Test Facilities (CRTF)
As the cyber risk continues to grow, organisations need greater understanding and increased confidence in the resilience of their connected products, services and technology.
To meet this need the NCSC has developed a new UK assurance methodology to enable vendors to demonstrate the cyber resilience of their connected products and services in a structured and consistent way. This will also enable industry and government services to independently audit and assess those products and services in a consistent way.
To deliver this new assurance methodology NCSC is setting up Cyber Resilience Test Facilities (CRTFs) that will deliver assurance for a wide range of internet connected products and services. The CRTFs delivering this new service will conduct these evaluations against the Principles Based Assurance (PBA) methodology, as part of a wider NCSC transition away from compliance-based assurance schemes. This will enable consumers to have confidence in the cyber resilience of the connected products and services they purchase whilst at the same time extending the reach of NCSC by harnessing industry to deliver assurance for a much wider range of cyber products than is possible today.
The initial service offering assesses products against the Cyber Resilience Testing (CRT) Assurance Principles and Claims (APC) standard. This standard has been aligned with Software Security Code of Practice.
The service will be delivered through a national ecosystem of CRTFs that have been assured by the NCSC to conduct this third-party evaluation.
Focus on risk, not compliance
The NCSC’s new approach to Technology Assurance is Principles Based Assurance (PBA) - an approach that puts the focus on risk outcomes.
Cyber Resilience Testing is the application of PBA to gain confidence in a product’s cyber resilience against attacks from its public interfaces – usually the internet.
To enable evidence and assessment against principles, the NCSC has created a set of artefacts called Assurance Principles & Claims (APCs). CRTFs can be employed by technology vendors to independently verify the resilience of a product against these APCs to enable the vendor to demonstrate the cyber resilience of their products in a structured, accessible and consistent way.
CRTF Vision Statement
A national ecosystem of assured test facilities to provide buyers with confidence in the cyber resilience of the connected products they purchase.
In addition to identifying risks and the implications to vendors and customers - allowing better risk management decisions to be taken by organisations and businesses - CRTFs will:
- Boost confidence in the technology supply chain through enabling better decision-making.
- Enhance the wider UK resilience to cyber threats through the development of deeper understanding of risks.
- Promote best practice amongst technology vendors by encouraging further engagement and understanding of cyber risk across the market.