Get a free audit

Field Notes / Offensive Security

The NCSC Has Written Down What an Adversary Simulation Is. Most of What the UK Buys as a Red Team Is Not One.

On 17 September 2026 the NCSC published buyer guidance on adversary simulation, the thing it says is "sometimes known as red teaming". A typical engagement runs 8 to 12 weeks. Before you qualify to buy one you need reviewed risks, established defences and working detection. Here is the bar, quoted, what to buy if you do not clear it, and what the new CyAS scheme will require of the provider who signs your report.

Author
Red Team Partners
Read
11 MIN READ
Filed
21 Sep 2026
A data centre administrator works a console at night, in front of the monitoring and detection an adversary simulation is designed to test.

01 The bar, quoted in full

he NCSC wrote the qualifying conditions as three bullets, and they are worth reading in the original rather than in a vendor's paraphrase. "Adversary simulation is best suited to organisations with a mature understanding of the cyber risks they face. To get the most from adversary simulation, these organisations will: have identified, assessed, and be regularly reviewing their risks; have well-established mitigations and defences in place; have robust network monitoring and detection systems." NCSC adversary simulation guidance

Then the sentence that decides the purchase: "Adversary simulation should verify that your network monitoring and detection teams (whether provided by an internal team or third-party suppliers) can detect unusual activity and respond appropriately." NCSC adversary simulation guidance Read that as a dependency. The exercise grades a detection and response capability. Without one, the grade comes back the same way every time, and you paid 8 to 12 weeks of operator time to learn what a one-week test would have told you.

For everyone else the guidance is direct. "Organisations which fall outside these parameters (perhaps operating relatively small and simple networks, or still developing an understanding of risk) may find more value from the services provided by companies assured under other NCSC-assurance schemes." NCSC adversary simulation guidance It names six: Cyber Essentials, Cyber Advisors, Assured Cyber Security Consultancy, Exercise in a Box, Cyber Incident Exercising, and CHECK penetration testing.

The page addresses system owners and security professionals in medium to large-sized organisations, and calls the testing particularly useful for critical national infrastructure and UK government. Headcount is not the gate. The guidance says the testing is "appropriate for any organisation meeting the above conditions" NCSC adversary simulation guidance . A 90-person fintech with a real SOC clears it. A 4,000-person manufacturer with an unmonitored flat network does not.

02 Eight to twelve weeks, and what fills them

The duration paragraph is the most useful sentence the NCSC has published for a buyer holding two quotes. "A typical adversary simulation engagement will normally take between 8 and 12 weeks to complete, depending on its size and scope, although a full spectrum engagement may last in the region of 16 weeks." NCSC adversary simulation guidance The guidance goes further and warns against the bare minimum: "we encourage organisations to allow sufficient time for thorough testing of real-world adversary tactics, techniques, and procedures."

Three phases fill that time. Prerequisites covers scoping, passive reconnaissance and preparation. Testing covers continual active reconnaissance, initial access, the internal phase and clean up. Reporting closes it CyAS Scheme Standard v1.1 . Scoping is where the money is made or lost, and the NCSC tells you what to aim at: "Objectives should focus on identifying the key functions which, if compromised, would critically impact the ability of the organisation to operate effectively." NCSC adversary simulation guidance Write that list before you take a single call with a provider.

You have jobs of your own. The customer must create some legitimate low-privilege user accounts, as agreed in the scoping section, to be used as a contingency if active testing from outside the perimeter fails NCSC adversary simulation guidance . Scoping also has to record an agreement on appropriate de-chain events, should the simulation stall once the active phases begin CyAS Scheme Standard v1.1 . The NCSC calls using one "a mature approach to testing", because it spends the remaining weeks on the significant risks instead of on a door that will not open NCSC adversary simulation guidance .

Two shapes exist. Full spectrum includes attempts to gain initial access through external attack surfaces such as phishing campaigns or external portals. Assumed breach starts the team on a target device at an agreed level of access CyAS Scheme Standard v1.1 . The guidance is direct about which to pick. "For organisations with a mature security posture, assumed breach can provide greater value by bypassing the initial access phase and concentrating on the consequences of a successful compromise, specifically whether an attacker can expand their access beyond the initial point of entry and reach high-value targets." NCSC adversary simulation guidance It also names what assumed breach costs you: the exercise will not tell you what information you are making publicly available for an attacker to find. If you already know phishing works on your staff, paying for an initial access phase to prove it again buys you nothing.

03 What to buy if you are not there yet

The same authority wrote the alternative down years ago. A penetration test is "a method for gaining assurance in the security of an IT system by attempting to breach some or all of that system's security, using the same tools and techniques as an adversary might" NCSC penetration testing guidance . The NCSC frames it as validation of your vulnerability management process, and compares it to a financial audit: your people do the daily work, an external party verifies the process holds.

The difference from adversary simulation is one sentence in the new guidance. Adversary simulation "focuses on the efficacy of an organisation's technical controls and detection, whereas penetration testing is more focused on identifying all technical vulnerabilities" NCSC adversary simulation guidance . One asks whether you saw it. The other asks what is open. When nobody has ever looked, the second question is the one with answers in it, and a penetration test is what answers it.

One warning on the shelf life. The NCSC's penetration testing guidance is blunt that a test "can only validate that your organisation's IT systems are not vulnerable to known issues on the day of the test". It adds that a year or more often elapses between tests, so vulnerabilities can exist for long periods without your knowing, if a test is your only means of validating security NCSC penetration testing guidance . That is the argument for continuous penetration testing made by the national technical authority rather than by a vendor.

Cyber Essentials sits on the same list and answers a smaller question again: five controls, assessed on a date. Read what the scheme covers and what it was never designed to stop, and why a scanner returning 900 findings is not a test.

04 Capability-led, not script-led

Buried in the guidance is a design choice that should change how you read every proposal you receive. "The NCSC's approach to adversary simulation differs from most industry frameworks in that it is capability led, where the testing approach is not constrained by attempting to simulate specific threat actors or pre-defined threat scenarios." NCSC adversary simulation guidance The page contrasts this with reliance on commercially-procured threat intelligence and threat scenarios, and gives the reason in one line: "Known and reported TTPs are inherently retrospective and may not fully reflect current adversary tradecraft." NCSC adversary simulation guidance

Plenty of proposals sell the opposite. They name a threat group, promise its playbook, and deliver a technique list from a report published months ago. Your defenders may well stop that playbook, because everybody's tooling was tuned against it when the report landed. An attacker working on you next quarter is not reading it.

The scheme documents carry the same idea into obligations. A CyAS team running a full spectrum engagement "must conduct Reconnaissance against the Customer, using (as a minimum) a combination of active and passive open-source intelligence techniques (OSINT)" CyAS Scheme Standard v1.1 . The NCSC says assured providers will "apply an adversarial mindset, use continuous and tailored reconnaissance, and develop bespoke approaches" NCSC CyAS blog, 17 September 2026 . Reconnaissance runs against your estate as it is this month, which is the whole point. Ask any provider one question and the answer will separate them: what did you find about us before you wrote this proposal?

05 CyAS, and what it means if you resell testing

The guidance arrived alongside the Cyber Adversary Simulation scheme's Scheme Standard and Working Practices Document, both version 1.1, September 2026 CyAS scheme documents . An NCSC blog of the same day states that "when the CyAS scheme formally launches in November 2026, buyers will be able to choose from providers assured against the NCSC's CyAS standard" NCSC CyAS blog, 17 September 2026 , a date IT Pro reported the same week IT Pro, 18 September 2026 . The scheme introduction page is softer, saying the NCSC is assessing an initial cohort and aims to launch to the buyer community by the end of 2026 CyAS scheme introduction . Treat November as the target rather than a guarantee. The NCSC calls the scheme a minimum viable product today. Assured companies will be known as CyAS Assured Service Providers.

What the Standard demands of a provider is concrete, and most of it is a question you can put to any supplier today. The CyAS team must be located in the UK, and the company must use reasonable endeavours to host its attacker infrastructure in the UK too. It must hold an in-date Cyber Essentials Plus certification for every business system where customer engagement information is stored and processed. At least two CyAS Operators, one of them a designated Lead Operator. A customisable command and control framework, tested and safe for use against a diverse set of customer environments. Demonstrated capability in evading detection, persistence, local and remote privilege escalation, lateral movement and phishing CyAS Scheme Standard v1.1 .

Reporting gets the same treatment. Findings must map back to the NCSC Cyber Assessment Framework. The report carries an executive summary for a non-technical reader, a technical walkthrough with diagrams, ratings from Critical to Informational, and appendices. Personal data sits behind anonymised references such as USER-1 and HOSTNAME-A. A Lead Operator from the engagement writes the report, and the primary Lead Operator signs it off. Both names appear in it CyAS Scheme Standard v1.1 . Note what the Standard never asks for: an external certification. It assesses individuals against its own competency framework instead. CREST and CyAS are separate regimes, and no provider can trade one for the other.

Our own position, stated plainly: no company can point to CyAS assurance today, because the NCSC is still assessing its first cohort and the scheme has not launched. We hold no CyAS mark and we will not imply one. What we can tell you is what the published Standard asks for, and which of those things a provider can evidence to you this month.

Five questions to ask any provider before the scheme launches
  • Where is the team located, and where is the attacker infrastructure hosted? The Standard requires UK for the team and reasonable endeavours for the infrastructure.
  • Do you hold Cyber Essentials Plus for the systems that store and process my engagement data? CyAS requires it of the provider, on every system that holds your engagement information.
  • Who writes the report and who signs it? The Standard requires a Lead Operator from the engagement to write it, the primary Lead Operator to sign it off, and both names to appear in it.
  • Do your findings map to the NCSC Cyber Assessment Framework? CyAS reporting requires that mapping, and it is the format a UK regulator already reads.
  • What reconnaissance did you run against us before writing this proposal, and what did you find? Capability-led testing starts here, and the answer separates operators from resellers.

If you came looking for a red team this quarter, start by testing the sentence that qualifies you: someone authenticated at 03:00 from an unfamiliar address, and somebody saw it. Answer that honestly and the purchase decides itself. Get a free audit and we will tell you which of the two you should be buying, with the reasoning written down. If you sell testing to your own clients and want to know what the scheme changes for your supply chain, tell us what you buy and an operator replies within two working days.

References

Sources

  1. NCSC. Adversary simulation: what you need to know. Published 17 September 2026. ncsc.gov.uk
  2. NCSC. Cyber Adversary Simulation (CyAS) scheme documents now available. Blog by Catherine H, Head of Assured Professional Services Schemes, 17 September 2026. ncsc.gov.uk
  3. NCSC. Cyber Adversary Simulation (CyAS) scheme: introduction. ncsc.gov.uk
  4. NCSC. CyAS Scheme Standard, version 1.1, September 2026. ncsc.gov.uk
  5. NCSC. CyAS Working Practices Document, version 1.1, September 2026. ncsc.gov.uk
  6. NCSC. CyAS scheme documents index. ncsc.gov.uk
  7. NCSC. Penetration testing guidance. Published 8 August 2017, last reviewed 10 January 2022. ncsc.gov.uk
  8. NCSC. CHECK scheme: introduction. ncsc.gov.uk
  9. DSIT. Cyber Security Breaches Survey 2025/2026. Official statistics, 30 April 2026. Base: 2,112 UK businesses, 1,085 charities, 577 education institutions. gov.uk
  10. Emma Woollacott. NCSC issues advice on cyber adversary simulation. IT Pro, 18 September 2026. itpro.com