Certification · Last verified
Cyber Resilience Audit scheme
The Cyber Resilience Audit scheme certifies AUDITORS delivering independent cyber audits based on the NCSC's Cyber Assessment Framework. Member auditors are known as Assured Service Providers, and the scheme's directory publishes each one's certified status, run by the National Cyber Security Centre.
- Class
- Certification
- Owner
- National Cyber Security Centre (NCSC)
- Public register
- Not confirmed at our last check
- Last verified
What it is
The Cyber Resilience Audit (CRA) scheme is an NCSC assurance scheme whose subject is the auditor, not the audited organisation. In the NCSC's words it "gives consumers confidence in companies that have been assessed as meeting the NCSC standard for delivering independent cyber audits", and it "assures companies delivering independent cyber audits, based on the Cyber Assessment Framework (CAF)". Companies in the scheme are "known as Assured Service Providers (ASP)".
Who owns it
The Cyber Resilience Audit scheme is run by the National Cyber Security Centre (NCSC).
Who asks for it
Buyer-driven. Demand comes from buyers of independent cyber audits: organisations described by the NCSC as "such as Operators of Essentials Services (OES) which are overseen by Cyber Oversight Bodies", and "any organisation seeking an independent audit of their cyber resilience for their own due diligence purposes".
Demand comes from the buyers of CAF-based audits. The NCSC frames the scheme's audience as organisations "such as Operators of Essentials Services (OES) which are overseen by Cyber Oversight Bodies", and also "any organisation seeking an independent audit of their cyber resilience for their own due diligence purposes". No instrument making CRA membership a condition for any specific audit programme was identified in the sources reviewed as of 29 August 2026 — confirm against the NCSC and the commissioning body.
Sources
- NCSC — Cyber Resilience Audit scheme (scheme owner) ↗ — accessed
- NCSC — Find an assured CRA provider ↗ — accessed
- NCSC — CRA: information for service providers ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.