UK NCSC publishes adversary simulation guidance and first CyAS scheme documents ahead of November 2026 launch
The UK NCSC has released guidance on adversary simulation engagements together with the first Cyber Adversary Simulation (CyAS) scheme documents, with the capability-led scheme due to formally launch in November 2026.
According to two NCSC reports dated 2026-09-17 (which are consistent with each other), the UK NCSC published guidance on adversary simulation engagements and released the first Cyber Adversary Simulation (CyAS) scheme documents. The guidance describes two adversary simulation approaches: full spectrum, which starts outside the network with an end-to-end attack, and assumed breach, which starts from an internal foothold and bypasses initial access to test lateral movement to high-value targets. The preferred methodology spans three phases — prerequisites (scoping, passive reconnaissance, preparation), testing (active reconnaissance, initial access, internal phase, cleanup), and reporting — and distinguishes adversary simulation from penetration testing, stressing customer-defined objectives and minimal information sharing. The first CyAS scheme documents comprise the Scheme Standard and the Working Practices Document, covering planning, controlling, delivering, and reporting of engagements. The capability-led scheme, developed with cyber oversight bodies, will formally launch in November 2026 and will assess companies seeking NCSC-assured provider status. NCSC describes the current version as a minimum viable product to be refined with feedback from buyers and providers, and the standard requires tailored reconnaissance and bespoke approaches rather than fixed attack scripts.
- NCSC reports dated 2026-09-17 announce UK NCSC adversary simulation guidance and the first Cyber Adversary Simulation (CyAS) scheme documents.
- Two adversary simulation approaches are described: full spectrum (starting outside the network with an end-to-end attack) and assumed breach (starting from an internal foothold).
- The preferred methodology spans three phases: prerequisites (scoping, passive reconnaissance, preparation), testing (active reconnaissance, initial access, internal phase, cleanup), and reporting.
- Assumed breach bypasses initial access to test lateral movement to high-value targets.
- The guidance distinguishes adversary simulation from penetration testing in required information sharing, and stresses customer-defined objectives and minimal information sharing.
- The first CyAS scheme documents are the Scheme Standard and the Working Practices Document, covering planning, controlling, delivering, and reporting of adversary simulation engagements.
- CyAS is a capability-led scheme developed with cyber oversight bodies; it will formally launch in November 2026 and assess companies seeking NCSC-assured provider status.
- The capability-led standard requires tailored reconnaissance and bespoke approaches, not fixed attack scripts.
Coverage timelineoldest first · each row is one article
- · 5h agoAdversary simulation: what you need to know
NCSC UK· 22
UK NCSC publishes guidance on adversary simulation, comparing full spectrum and assumed breach approaches across prerequisites, testing, and reporting phases.
- · 5h agoCyber Adversary Simulation (CyAS): scheme documents now available
NCSC UK· 25
NCSC published adversary simulation guidance and the first Cyber Adversary Simulation (CyAS) scheme documents ahead of the scheme's November 2026 launch.