Certification · Last verified

Cyber Resilience Audit scheme

The Cyber Resilience Audit scheme certifies AUDITORS delivering independent cyber audits based on the NCSC's Cyber Assessment Framework. Member auditors are known as Assured Service Providers, and the scheme's directory publishes each one's certified status, run by the National Cyber Security Centre.

Class
Certification
Owner
National Cyber Security Centre (NCSC)
Public register
Not confirmed at our last check
Last verified

What it is

The Cyber Resilience Audit (CRA) scheme is an NCSC assurance scheme whose subject is the auditor, not the audited organisation. In the NCSC's words it "gives consumers confidence in companies that have been assessed as meeting the NCSC standard for delivering independent cyber audits", and it "assures companies delivering independent cyber audits, based on the Cyber Assessment Framework (CAF)". Companies in the scheme are "known as Assured Service Providers (ASP)".

Who owns it

The Cyber Resilience Audit scheme is run by the National Cyber Security Centre (NCSC).

Who asks for it

Buyer-driven. Demand comes from buyers of independent cyber audits: organisations described by the NCSC as "such as Operators of Essentials Services (OES) which are overseen by Cyber Oversight Bodies", and "any organisation seeking an independent audit of their cyber resilience for their own due diligence purposes".

Demand comes from the buyers of CAF-based audits. The NCSC frames the scheme's audience as organisations "such as Operators of Essentials Services (OES) which are overseen by Cyber Oversight Bodies", and also "any organisation seeking an independent audit of their cyber resilience for their own due diligence purposes". No instrument making CRA membership a condition for any specific audit programme was identified in the sources reviewed as of 29 August 2026 — confirm against the NCSC and the commissioning body.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Cyber Resilience Audit scheme." Certifidex, FutureTechnologies. Last verified 29 August 2026. https://certifidex.com/frameworks/ncsc-cra-scheme

All frameworks & audits →