TechnologyUK NCSC

Cyber Adversary Simulation (CyAS): scheme documents now available

Alongside the guidance, we have shared the first CyAS scheme documents, including the Scheme Standard and the Working Practices Document. These documents provide an early and transparent view of the standard we will use to assess applicants, including expectations on companies, key role holders, technical delivery, and reporting. As a result, buyers will have a transparent and consistent benchmark for assessing providers, helping them make more informed procurement decisions and giving them greater confidence in the quality of NCSC-assured services.

We have developed the CyAS scheme in partnership with cyber oversight bodies, including regulators and government policy organizations responsible for understanding cyber resilience in their sectors. This collaboration has helped us create a common and widely applicable core standard while allowing potential customer organizations to define additional, specific requirements where needed.

In contrast to some similar standard industry schemes, our CyAS approach is capability-led. We are not expecting providers to simply replay a fixed script of known attacker behaviors. Rather, NCSC-assured CyAS companies will apply an adversarial mindset, use continuous and tailored reconnaissance, and develop bespoke approaches to the objectives agreed with their customer.

Source: UK NCSC (Cyber) (17 September 2026)

Related Articles

Back to top button