NCSC assured cyber security consultancy: the six assured schemes and who each is for
“It provides assurance that participating consultancies meet the National Cyber Security Centre’s (NCSC) Standard for delivering high-quality cyber security consultancy in accordance with the NCSC’s advice and guidance.” — NCSC, Assured Cyber Security Consultancy.
Anyone in the UK can call themselves a cyber security consultancy. The National Cyber Security Centre runs assurance schemes that narrow the field for particular jobs: consultancy for high-risk organisations, advice for small ones, penetration testing, incident response, incident exercising and independent audit. This page sets out each one from the NCSC's own pages, and where an ISO 27001 certificate fits — because none of them issues one.
The six assured schemes at a glance
| Scheme | What the NCSC says | Who it is for |
|---|---|---|
| Assured Cyber Security Consultancy (ACSC) | “This scheme assures providers offering independent consultancy services to organisations with complex, high-risk, or nationally significant cyber security requirements.” | Operators of essential services, regulators, government bodies, work aligned to NCSC guidance, elevated threat profiles |
| Cyber Advisor | “The cyber advisor scheme assures organisations to provide general cyber security advice and support to a broad range of UK organisations.” | Small and medium-sized organisations; focused on the Cyber Essentials controls |
| CHECK penetration testing | “CHECK is the scheme under which NCSC assured companies can conduct authorised penetration tests of public sector and CNI systems and networks.” | Central government, public sector bodies, critical national infrastructure |
| Cyber Incident Response (CIR) | “Members of this scheme offer NCSC assured Cyber Incident Response services to a wide range of organisations.” | Any UK organisation that has been the victim of a cyber attack |
| Cyber Incident Exercising (CIE) | “The NCSC’s Cyber Incident Exercising (CIE) scheme gives customers confidence that CIE Assured Service Providers meet NCSC standards for high quality cyber incident exercising.” | Organisations with existing cyber incident response plans |
| Cyber Resilience Audit (CRA) | “The Cyber Resilience Audit (CRA) scheme assures companies delivering independent cyber audits, based on the Cyber Assessment Framework (CAF).” | Organisations overseen by Cyber Oversight Bodies, such as operators of essential services; also any organisation wanting an independent audit for its own due diligence |
The NCSC's assured services page also lists Cyber Essentials, Cyber Adversary Simulation and NCSC Assured Training. Cyber Essentials is a certification of your own controls, not a consultancy scheme; see ISO 27001 vs Cyber Essentials.
Assured Cyber Security Consultancy
The NCSC says the scheme “helps organisations with complex, high-risk, or nationally significant cyber security needs identify trusted, independent consultancy providers.”
The specialist areas
| Area |
|---|
| Risk management |
| Security architecture |
| Cross Domain Advice sub-Offering - in development |
| Audit & Review |
| Post-quantum cryptography - currently in pilot/MVP stage |
When the NCSC says to use one
If you need support in one of those areas “where one of more of the following apply”:
| Criterion |
|---|
| the organisation is an operator of essential services under the oversight of a statutory regulator, is itself a statutory regulator, or is subject to cyber security oversight exercised by a government department or other formally designated public authority (including a lead Government department) |
| the organisation is a UK government department, agency, or arm’s-length body |
| the organisation requires consultancy services that involve interpreting, applying, aligning to, or providing advice in accordance with NCSC advice and guidance; and / or |
| the organisation cyber threat profile is assessed as elevated beyond general, untargeted (“commodity”) cyber threats, including circumstances where the organisation is likely to face targeted, persistent, or a capable adversary. |
How to buy
“Government and public sector buyers can invite supplier to bid for working using the Government Commercial Agency’s (formerly Crown Commercial Service) Dynamic Purchasing System.” The page links to Cyber Security Services 3. For everyone else: “All other customers should contact their chosen Assured Cyber Security Consultancy directly.” The NCSC publishes the list of assured consultancies on its website.
Cyber Advisor: the scheme for smaller organisations
The NCSC points organisations outside high-risk or complex sectors here instead. “The focus of that advice and support is on the implementation of the technical controls set out in Cyber Essentials.”
What each adviser is assessed on
The NCSC says its Cyber Advisors have passed an independent assessment which measured their:
| Assessed |
|---|
| knowledge and understanding of the Cyber Essentials’ technical controls |
| competence in providing practical, hands-on support |
| ability to understand and work with small and medium sized organisations. |
Individual and company
“All Cyber Advisors must work for a company which has met the NCSC’s standards and been accepted as an Assured Service Provider.” So the assurance attaches to both the person and the firm. The scope may widen: “In the future, we will explore whether we can assist small organisations by assuring Cyber Advisors in other areas of cyber security.”
Testing, incidents and audit
CHECK penetration testing
The NCSC defines penetration testing as “a method for gaining assurance in the security of an IT system by attempting to breach some, or all, of that system’s security, using the same tools and techniques as an adversary might.” “While penetration testing can be undertaken by any organisation wanting to test their cyber security, the CHECK scheme has been developed specifically for:” central government departments, public sector bodies and organisations forming the UK's critical national infrastructure.
Cyber Incident Response
“The NCSC recommends that all UK organisations should use an NCSC-assured Cyber Incident Response provider when dealing with cyber incidents.” “The NCSC assures Cyber Incident Response companies at two levels.” — Enhanced Level and Standard Level. Either, the NCSC says, will be able to assist with most cyber incidents.
Cyber Incident Exercising
For organisations that already have a cyber incident response plan. “CIE doesn’t test your cyber defences but helps you to explore and evaluate your response plans, should a cyber incident occur.”
Cyber Resilience Audit
“The scheme is initially a Minimum Viable Product; therefore, the initial independent audits will be against Cyber Assessment Framework (CAF) but, flexible enough to be used to audit against any Cyber Security Standard.” Oversight bodies that use it are Scheme Partners, and “Scheme Partners may encourage, recommend or require the organisations they oversee to have audits conducted by CRA Assured Service Providers.” “However, CRA can equally be useful for any organisation seeking an independent audit of their cyber resilience for their own due diligence purposes.”
Where ISO 27001 certification fits (our reading)
None of the six schemes certifies an information security management system. An ISO/IEC 27001 certificate is issued by a certification body operating to ISO/IEC 17021-1 — in the UK, accredited by UKAS. A consultancy's work, assured or not, is what that standard calls management system consultancy: “participation in establishing, implementing or maintaining a management system”.
Keep the consultant and the certifier apart
ISO/IEC 17021-1 clause 5.2.7: “Where a client has received management systems consultancy from a body that has a relationship with a certification body, this is a significant threat to impartiality. A recognized mitigation of this threat is that the certification body shall not certify the management system for a minimum of two years following the end of the consultancy.” That applies to an NCSC-assured consultancy as much as to any other. The questions to ask are on the consultants page.
Audit is not certification
A Cyber Resilience Audit is “flexible enough to be used to audit against any Cyber Security Standard”, but it is an NCSC-assured audit, not an accredited certification audit. If a customer asks for an ISO 27001 certificate, a CRA report is not one.
Which scheme fits which job (our reading)
| The job | Scheme | Note |
|---|---|---|
| You need ISO/IEC 27001 implemented | None of the six certifies it | Any consultancy; the certificate comes from an accredited certification body |
| A small business wants help with the Cyber Essentials controls | Cyber Advisor | The NCSC built it for small and medium-sized organisations |
| A regulator, government body or operator of essential services needs advice | Assured Cyber Security Consultancy | The NCSC lists these among its criteria |
| Penetration testing of public sector or CNI systems | CHECK | Other organisations can commission testing without it |
| You have been attacked | Cyber Incident Response | The NCSC recommends it for all UK organisations |
| You want to rehearse your incident response plan | Cyber Incident Exercising | Needs an existing plan |
| An oversight body wants an independent audit against the CAF | Cyber Resilience Audit | Also open to anyone wanting one for due diligence |
We do not consult, test, audit or certify, and are paid the same fixed fee per enquiry whichever firm you use. We do not list or rank providers; the NCSC publishes its own lists. Scheme descriptions are quoted from ncsc.gov.uk; the matching table is our reading.
Where this fits
- ISO 27001 consultants
- Information security consultant
- ISO 27001 vs Cyber Essentials
- Certification bodies
Common questions
What is an NCSC assured cyber security consultancy?
A provider in the NCSC's Assured Cyber Security Consultancy scheme. The NCSC: “It provides assurance that participating consultancies meet the National Cyber Security Centre’s (NCSC) Standard for delivering high-quality cyber security consultancy in accordance with the NCSC’s advice and guidance.” The scheme covers risk management, security architecture, audit and review, and post-quantum cryptography (in pilot).
Do I need an NCSC assured consultancy?
The NCSC suggests one where you are an operator of essential services or a regulator, a UK government body, need advice that applies NCSC guidance, or face a threat beyond commodity attacks. “For organisations that do not operate in a high risk or complex sector, our Cyber Advisor scheme provides cyber security advice tailored to organisations more at risk of commodity attack.”
What is an NCSC Cyber Advisor?
An adviser assured by the NCSC to give small and medium-sized organisations practical help. “The focus of that advice and support is on the implementation of the technical controls set out in Cyber Essentials.” “All Cyber Advisors must work for a company which has met the NCSC’s standards and been accepted as an Assured Service Provider.”
How do public sector bodies buy NCSC assured consultancy?
“Government and public sector buyers can invite supplier to bid for working using the Government Commercial Agency’s (formerly Crown Commercial Service) Dynamic Purchasing System.” The NCSC links to Cyber Security Services 3. “All other customers should contact their chosen Assured Cyber Security Consultancy directly.”
Does an NCSC assured consultancy give ISO 27001 certification?
No. None of the NCSC's assured schemes certifies an ISO/IEC 27001 management system. That certificate comes from a certification body accredited against ISO/IEC 17021-1, and in the UK accredited by UKAS. A consultancy can help you implement the standard; it cannot certify you.
Is CHECK required for a penetration test?
Only in the sectors it was built for. “While penetration testing can be undertaken by any organisation wanting to test their cyber security, the CHECK scheme has been developed specifically for:” central government departments, public sector bodies and critical national infrastructure. Other organisations can use the NCSC's guidance on commissioning a penetration test.
What is the Cyber Resilience Audit scheme?
An NCSC scheme for independent audits against the Cyber Assessment Framework. “The scheme is initially a Minimum Viable Product; therefore, the initial independent audits will be against Cyber Assessment Framework (CAF) but, flexible enough to be used to audit against any Cyber Security Standard.” “However, CRA can equally be useful for any organisation seeking an independent audit of their cyber resilience for their own due diligence purposes.”
Sources cited on this page
- NCSC, Assured services
- NCSC, Assured Cyber Security Consultancy — introduction
- NCSC, Cyber Advisor scheme
- NCSC, CHECK penetration testing — introduction
- NCSC, Cyber Incident Response — introduction
- NCSC, Cyber Incident Exercising — introduction
- NCSC, Cyber Resilience Audit — introduction
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Need ISO 27001 help as well as NCSC-assured advice?
Say what the customer or regulator asked for and your deadline.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.