NCSC sets out the standard for assured red-team providers
The first Cyber Adversary Simulation scheme documents show what the NCSC will expect of commercial providers when the scheme opens in November, and give buyers a benchmark to hold them to
- The NCSC says adversary simulation suits organizations with mature security processes, particularly larger ones, critical national infrastructure and UK government.
- The scheme covers full-spectrum engagements, which start outside the network, and assumed-breach engagements, which start from a foothold inside it.
- The buyer guidance separates adversary simulation, which tests detection and response, from penetration testing, which looks for technical vulnerabilities.
- The NCSC suggests organizations with small, simple networks may get more value from providers assured under its other schemes.
Buyers planning a red-team engagement should consider waiting for assured providers or writing the scheme standard into their requirements now. First decide whether you need adversary simulation at all: if detection and response are immature, a penetration test or another NCSC-assured service is likely to be better value. If you proceed, budget internal time for the engagement’s length and name who will receive and act on the findings. Providers intending to apply should check their key role holders and reporting against the standard before assessments open.
“We are not expecting providers to simply replay a fixed script of known attacker behaviours.”National Cyber Security Centre, CyAS scheme blog post
The National Cyber Security Centre (NCSC) published the Scheme Standard and Working Practices Document for its assured Cyber Adversary Simulation (CyAS) scheme on 17 September, ahead of a formal launch in November 2026.
Adversary simulation, often called red teaming, tests whether an organization can prevent, detect and respond to a realistic attack. The documents set out what the NCSC expects of applicant companies, their key role holders, technical delivery and reporting, and form the standard against which applicants will be assessed. The NCSC says it built the scheme with regulators and government policy bodies, and that customers can add their own specific requirements on top of the common core.
The approach is capability-led. The provider’s own team is expected to carry out reconnaissance on the customer and build attack plans around objectives agreed with it, rather than lean on a commercially procured threat intelligence product. The NCSC’s companion guidance for buyers says a typical engagement takes 8–12 weeks, and a full-spectrum test can run to about 16 weeks.
The NCSC calls the scheme a ‘minimum viable product’ that it will refine as early engagements report back. It says it will publish more later in 2026 on the launch for buyers and on future opportunities for providers.
