Cyber Resilience Test Facilities
Information for technology vendors
Cyber Resilience Test Facilities (CRFT) aim to provide confidence in the technology and products you sell; this confidence can, in turn, be shared to end users and customers.
To gain this confidence, a CRTF will conduct a thorough assessment of the cyber risks that may impact your product; the outcome will allow you to make decisions on how you might mitigate or tolerate such risks depending on your risk appetite.
How does it work?
All CRTFs have been assured by the NCSC to conduct assessments using Principle Based Assurance (PBA) methodology against the defined Cyber Resilience Testing Assurance Principles and Claims (APC).
As a vendor, you will be expected to work alongside a CRTF to provide the evidence required for the evaluation of your product.
You can find a NCSC assured Cyber Resilience Test Facility to carry out testing on your technology on the Find a provider page.
Once you have chosen a CRTF to work with, you will be asked to provide evidence, from your documentation or testing you have done, to demonstrate how your technology meets the cyber security claims set out within the APC. Find out more about APCs.
How will this help you?
The main outcome of this process is an output report which is delivered by the CRTF directly to the vendor, in accordance with NCSC guidelines. It will provide information on a products resilience against the principles outlined in the Cyber Resilience Testing APC.
Using the information presented in the output report, you may wish to make changes to your product, or you may decide that any risks highlighted are not relevant to your products value to end users. Ultimately, this puts the management and ownership of this risk into the hands of those who will be best positioned to judge the impacts.
Who is this for?
The initial operating capability of CRTFs will be focused primarily on products which have a direct requirement for robust cyber security – for example, tech products that need to be secure, rather than those that are specifically cyber security products.
Further services are under development and will be rolled out to provide a higher level of assurance where cyber security enforcing functionality is paramount to vendors and their customers.