Cyber Resilience Audit

Book a free no obligation informal chat
What is a Cyber Resilience Audit?
A Cyber Resilience Audit (CRA) is an independent audit against a defined cyber security standard. The NCSC scheme assures the companies providing these audits, initially using the Cyber Assessment Framework (CAF) . The CAF examines resilience across four objectives: managing risk, protecting against attacks, detecting events and minimising incident impact.
When to commission an audit
An audit may support your own due diligence or be encouraged, recommended or required by a Cyber Oversight Body using the CRA scheme. Check how your sector applies the scheme before commissioning work. NCSC assurance does not replace your commercial due diligence; confirm that a provider meets your needs and any additional sector requirements.

Risk Management Strategy
This area examines governance, risk management, asset knowledge and supply-chain risks. It helps leaders consider whether responsibilities and decisions support the security of essential functions, and where clearer ownership or better evidence is needed.

Cyber Attack Resilience
This area covers protection policies, access controls, data and system security, resilient infrastructure and staff awareness. For managers, the focus is whether protective measures support essential functions and where improvements should be prioritised.

Detection and Response Capabilities
The detection objective considers security monitoring and threat hunting. Leaders need to understand whether the organisation can recognise suspicious activity affecting essential functions and provide the information needed for an effective response.

Contingency and Continuity Strategies
The incident-impact objective addresses response and recovery planning and lessons learned. It helps management examine preparedness for disruption, recovery responsibilities and how experience informs future improvements.
How Oxford Systems Can Help
Oxford Integrated Systems Limited is an Assured Service Provider for the NCSC Cyber Resilience Audit scheme. The NCSC listing confirms that Oxford Systems currently meets the scheme standard and lists its operating region as the whole of the UK.
Discuss your audit objectives, the functions to be assessed and any sector requirements with our team. An independent audit can help your leadership understand strengths and gaps and decide where further action is needed.
What provider assurance means for buyers
The NCSC buyer guidance requires the Head Consultant to hold UK Cyber Security Council Chartered registration in Cyber Audit and Assurance. The audit Team Leader must hold at least Principal registration in the same specialism. Head Consultants also attend NCSC CAF training. The service must operate in accordance with NCSC requirements.
You contract directly with your chosen provider and agree the price with them. The NCSC is not a party to that contract. Provider assurance is distinct from the findings of an audit of your organisation.
Read the NCSC information for buyers
Agreeing the scope and audit team
The Working Practices document expects the provider and customer to agree the skills required in the audit team once the scope is agreed, taking account of any Scheme Partner direction. The Head Consultant is accountable for the team and its compliance with the scheme personnel requirements.
For a useful engagement, identify the essential functions, systems, dependencies and organisational boundaries you want assessed. Discuss who will provide evidence and answer questions, then agree the outputs, timescales and reporting arrangements in the engagement. This preparation helps ensure the audit addresses the decisions your management team needs to make.
Sector requirements and oversight
Scheme membership does not automatically qualify a provider to conduct audits in every sector. Scheme Partners may set additional requirements and define how audits are carried out. Providers must understand and follow those directions before performing the relevant audit under the scheme.
Raise your sector and oversight arrangements at the start of the discussion. Confirm any required audit approach, team expertise and reporting process before finalising the engagement, so that the work is suitable for its intended purpose.

Independence, ethics and accountability
The Working Practices require providers to seek to avoid conflicts of interest and notify the relevant Scheme Partner of actual or suspected conflicts. Previous implementation or consultancy work within the audit scope, or financial and personal interests connected with the customer, can create such conflicts. Discuss these matters before appointing an auditor.
Scheme members must maintain an ethical approach and a code of ethics reflecting the UK Cyber Security Council principles. Where requested outputs do not meet the understood need, the provider must explain this to the customer and, where applicable, the Scheme Partner.
Providers must have a complaints process and report relevant customer complaints to the NCSC and Scheme Partner, anonymising information where appropriate. The scheme also allows customer feedback and requires annual management information from providers. Ask how concerns will be raised and handled during your engagement.
Official NCSC guidance
The buyer guidance explains how to select and engage an assured provider. The Working Practices document sets out scheme membership obligations and should be read alongside the Scheme Standard and Ecosystem Agreement.
