← Back to news
NCSC (UK)17 Sept 2026 · 2 min read

NCSC publishes initial documents for Cyber Adversary Simulation assurance scheme

The UK National Cyber Security Centre (NCSC) has released guidance and initial scheme documents for its planned Cyber Adversary Simulation (CyAS) assurance programme, which is due to launch in Novembe...

The UK National Cyber Security Centre (NCSC) has released guidance and initial scheme documents for its planned Cyber Adversary Simulation (CyAS) assurance programme, which is due to launch in November 2026.

Cyber adversary simulation involves controlled testing intended to measure how well an organisation can resist, identify and handle activity that resembles a real-world cyber intrusion. The NCSC said the approach is most relevant to organisations with established security capabilities that want to test their processes, technologies and response teams under realistic conditions.

The newly published guidance sets out the NCSC's view of effective adversary simulation. It stresses that engagements should provide evidence of defensive strengths and gaps rather than produce a simple pass-or-fail result. Testing should examine an organisation's ability to prevent malicious activity, detect it early, investigate alerts, and escalate incidents appropriately.

The guidance also addresses the planning, governance, delivery and reporting of engagements. These controls are intended to ensure that testing of production systems and sensitive environments is conducted safely while still generating useful findings on cyber resilience.

Provider requirements

Documents released ahead of the scheme launch include a Scheme Standard and a Working Practices Document. They describe the criteria prospective NCSC-assured providers will be assessed against, covering organisational expectations, personnel in key roles, technical delivery methods and reporting.

According to the NCSC, the scheme is designed to give customers a more consistent way to assess providers and to support procurement decisions. The agency developed the initiative with regulators and public-sector policy bodies involved in cyber resilience oversight.

  • Providers will be expected to tailor work to agreed customer objectives.
  • Engagements should use reconnaissance and an adversarial approach rather than follow a fixed attack script.
  • Customers may add sector- or organisation-specific requirements to the scheme's core standard.

The NCSC described CyAS as a capability-led programme, distinguishing it from assessment models focused on replaying predefined attacker techniques. It said the initial version is a minimum viable product and will be adjusted based on experience from early engagements and feedback from customers, providers and partners.

Organisations can review the guidance and scheme documents before the formal launch, when buyers are expected to be able to select providers assessed against the CyAS standard.

Share this article:TwitterLinkedIn