Article

NCSC publishes guidance and scheme documents for Cyber Adversary Simulation scheme

NCSC publishes guidance and scheme documents for Cyber Adversary Simulation scheme
On September 17, 2026, the UK National Cyber Security Centre (NCSC) published guidance and initial scheme documents for its new Cyber Adversary Simulation scheme (CyAS Scheme).  

Adversary simulation 

Adversary simulation (also known as “red-teaming”) systematically tests an organisation’s ability to prevent, detect and respond to simulated cyber attacks. It is intended to show where defences work and where they need improvement (rather than merely producing a pass/fail result or operating as a tick-box exercise). The NCSC describes it as one of the most effective ways for organizations to understand how they would fare against a capable attacker.  

The CyAS Scheme 

The CyAS Scheme is an assurance scheme intended to enable organizations to procure adversary simulation services from commercial providers assured against NCSC standards. Those standards have been developed by reference to other cyber oversight bodies including regulators and government policy organizations.

The CyAS Scheme is intended to approve trusted companies for the purpose of testing particularly high-risk organizations (such as those with complex or nationally significant needs) against realistic cyber attacks. Unlike schemes based on fixed attacker behaviours, the CyAS Scheme is described as being “capability-led”: assured providers must apply an adversarial mindset, use continuous and tailored reconnaissance, and develop bespoke approaches to the agreed objectives. There is no specific script to use.  

The CyAS Scheme Guidance (the Guidance) 

The Guidance is aimed at organizations that want to know if adversary simulation is right for them. It explains more about the nature of adversary simulation (as opposed to penetration testing), the sort of organizations that would benefit from it (i.e. those with a mature understanding of cyber risks faced) and how long it should take (typically between 8 and 12 weeks, depending on the scope of the simulation). The Guidance also sets out adversary simulation best practice and more detail on the method phases (i.e. pre-requisites for the simulation, testing, and reporting).  

The NCSC also published a scheme standard and working practices document. Together, these documents give an initial view of the requirements for CyAS Scheme applicants and members. It is expected that buyers of CyAS services will find these documents useful as a benchmark for assessing providers of CyAS services.  

Scheme standard

The NCSC outlines its rules for the CyAS scheme through the scheme standard. It defines the standards required for CyAS scheme membership in four sections which include, amongst other things:

  • Section A addressing the 'Company' standard (covering network security, cyber defence, communication requirements, technical competence, UK location requirements, regulatory compliance, roles and responsibilities of personnel).
  • Section B addressing the 'Technical' standard (covering the specific CyAS methodology that providers must follow, pre-requisites and active testing).
  • Section C addressing the 'Report Writing' standard (covering the content required in a CyAS report).
  • Section D addressing the 'Individual Competency Framework' (providing individual standards required for key roles, such as the CyAS Engagement Manager).
     

The scheme standard states that the standards apply to members offering services to an organisation that: is an operator of essential services (i.e. critical for national infrastructure or significantly important to the economy or wider society) that is under the oversight of a statutory regulator; is itself a statutory regulator; is otherwise subject to cybersecurity oversight by a government department or designated public authority; is a UK government department, agency or arm’s length body; or otherwise requires CyAS services that align with NCSC advice and guidance. 

Working Practices document

The Working Practices document sets out obligations that CyAS scheme members must adhere to and requirements in relation to the interaction between CyAS scheme members and the NCSC. For example, member obligations relate to:

  • cyber Essentials Plus certification
  • registering engagements and reporting requirements
  • restrictions on subcontracting CyAS services
  • customer information requirements
  • conflicts of interest, ethics and complaints
  • delivery risk mitigation requirements and engagement with the NCSC.

Next steps

The CyAS Scheme is expected to launch as a minimum viable product in November 2026, with the NCSC planning to refine it based on feedback from partners, buyers and providers. 

The announcement blog post is available here, the guidance is available here, and the CyAS Scheme documents are available here.

Related capabilities

subscribe

Interested in this content?

Sign up to receive alerts from the A&O Shearman on data blog.