Decoding the world of cybersecurity

· ·

NCSC sets adversary simulation assurance standard

The NCSC has published the first standards for its assured Cyber Adversary Simulation scheme, creating a procurement benchmark ahead of its planned November launch.

NCSC sets adversary simulation assurance standard
Summary
  • The NCSC has published its CyAS Scheme Standard and Working Practices Document.
  • Providers will be assessed across organisational capability, key personnel, technical delivery, reporting, and working practices.
  • Buyers are expected to gain access to NCSC-assured CyAS providers when the scheme launches in November.

The UK’s National Cyber Security Centre has published the first standards for its Cyber Adversary Simulation scheme, setting out how providers will be assessed before the assured service opens to buyers in November.

The NCSC released the CyAS Scheme Standard and Working Practices Document alongside new guidance on 17 September covering how adversary-simulation engagements should be planned, controlled, delivered, and reported.

Adversary simulation, often described as red teaming, uses controlled offensive activity to test an organisation’s ability to prevent, detect, investigate, and respond to the behaviour of a capable attacker.

The NCSC positions the approach primarily for organisations with mature security processes and technology. Its guidance emphasises that an engagement should generate evidence about how defences work together rather than operate as a pass-or-fail exercise.

The newly published scheme documents describe the baseline against which companies seeking NCSC assurance will be assessed. Requirements cover the provider organisation, key role holders, technical delivery, report writing, individual competence, and operational working practices.

The NCSC developed the scheme with cyber oversight bodies including regulators and government policy organisations responsible for assessing resilience in their sectors. The intention is to establish a common core standard while allowing customers or oversight bodies to impose additional requirements where necessary.

Procurement is a central problem the scheme is intended to address. High-end adversary simulation combines offensive technical skill with planning, operational judgement, safety controls, evidence handling, and reporting. Much of that quality is difficult for a buyer to assess before an engagement begins.

An external assurance benchmark cannot determine whether a particular provider is suitable for every environment, but it can establish whether the company meets a defined government-backed baseline.

The NCSC is also making the model capability-led rather than script-led. It says assured providers will be expected to use an adversarial mindset, continuous and tailored reconnaissance, and approaches designed around the objectives agreed with individual customers rather than simply replaying fixed attacker techniques.

That distinction affects the value of testing as resilience evidence. A predictable exercise can demonstrate that controls respond to a known scenario without necessarily showing what happens when an adversary changes direction, combines weaknesses, or uses an unexpected path through the environment.

Realism also brings risk. Adversary-simulation engagements can interact with production services, identity infrastructure, monitoring systems, employee processes, and sensitive information. Weak scoping or escalation can cause disruption independently of malicious activity.

The new guidance therefore places planning, control, and reporting alongside technical capability. Evidence collected during the exercise also needs to be usable after the technical activity ends, particularly where the work feeds into risk decisions, regulatory assurance, or investment priorities.

The NCSC describes the current CyAS scheme as a minimum viable product and says it expects the standard to evolve as providers and buyers gain experience with it.

When the scheme formally launches in November, buyers will be able to select providers assured against the CyAS standard. The more durable change is the creation of a common benchmark for a service whose quality has historically depended heavily on individual practitioner reputation, provider methodology, and the buyer’s own ability to distinguish sophisticated testing from a conventional penetration test with a different label.

×