Cyber Resilience Test Facilities
Assurance Principles and Claims documents
Assurance Principles and Claims (APC) documents
An APC document is the key artefact for any assurance service using the NCSC Principles Based Assurance (PBA) method. The APC plays the role of a standard in traditional compliance-based assurance activity, defining the scope of the assurance activity and the information needed for an assessment.
The APC is a collection of Principles and Claims. The principles define the scope of the assurance activity setting out an ideal state that a product can be measured against. To assist with this measurement each principle is deconstructed into a set of claims (using a claims-argument-evidence method) that are designed to be easily evidenced.
How to use APCs to do Assurance
APCs are available from the download section of this page and can be used by anyone for self-assessment (or continuous improvement) of the cyber security properties of any product, system or service covered by an APC.
The published APCs are:
- Cyber Resilience Testing (CRT): Assessing the cyber resilience of connected products against commodity attacks in a structured and consistent way.
- Sanitisation: Assurance of secure processing services for Electronic Storage Media at end of life or for re-use.