West Midlands Cyber

Cyber Resilience Test Facilities

Cyber Resilience Test Facilities have begun conducting product assessments. What does risk-based assurance mean for technology companies, buyers and critical supply chains?

Contents

Cyber Resilience Test Facilities: From Assurance Scheme to National Infrastructure

The UK’s Cyber Resilience Test Facilities have crossed an important threshold. What began as a new model for testing the resilience of connected products is now operating as a national assurance mechanism, with vendors able to use NCSC-assured facilities to evaluate products against a common principles-based methodology.

The development matters because it addresses a persistent weakness in technology markets. Buyers routinely need to make decisions about products whose cyber resilience they cannot independently evaluate, while vendors need credible ways to demonstrate security without reducing complex risk to a collection of compliance claims. The National Cyber Security Centre’s Cyber Resilience Testing model attempts to improve that relationship by establishing a structured method through which independent facilities assess evidence, identify weaknesses and report what those findings mean for risk.

The originating analysis, CRTFs Move From Concept to Reality… But the Hard Questions Begin Now, examined the point at which the programme moved from design into operational delivery. The central issue remains highly relevant: proving that Cyber Resilience Test Facilities can conduct assessments is only the first stage. The more difficult task is ensuring that principles-based assurance becomes trusted, interpretable and commercially useful without gradually being reduced to another procurement badge.

For the West Midlands, that distinction has particular significance. The region develops and adopts connected technologies across manufacturing, mobility, engineering and other operational environments where cyber failure can affect physical processes and business continuity. Better technology assurance could therefore contribute not only to cyber security but to industrial resilience, product development and trusted technology adoption.

Key Takeaways

  • Cyber Resilience Test Facilities form a national ecosystem of NCSC-assured facilities designed to evaluate the resilience of connected products using a common Principles Based Assurance methodology.
  • The model is explicitly risk-based rather than a conventional pass-or-fail certification process: facilities evaluate evidence against Assurance Principles and Claims and provide vendors with findings that support risk decisions.
  • The initial Cyber Resilience Testing service concentrates on connected products and resilience against commodity attacks through public-facing interfaces, so its scope should not be confused with universal or high-assurance product certification.
  • Delivering assurance through accredited commercial facilities allows the NCSC methodology to reach more technologies than a centrally delivered assessment model could reasonably support.
  • For the West Midlands, CRTFs create an opportunity to connect product development, industrial adoption and procurement with stronger evidence about cyber resilience, but their value will depend on how effectively buyers and suppliers use the resulting assurance.

The Important Change Is from Compliance to Evidence

Traditional technology assurance can create a deceptively simple relationship between supplier and buyer. A product is assessed against a standard, obtains a certification or label, and the purchaser uses that status as evidence that an appropriate security threshold has been reached.

There are circumstances in which this approach is useful. Common minimum requirements can reduce procurement complexity and give buyers a straightforward mechanism for distinguishing products that have undergone recognised assessment from those that have not.

The weakness appears when the binary result becomes a substitute for understanding risk.

Connected technologies operate in different environments, face different threats and create different consequences when compromised. A device suitable for a low-consequence consumer application cannot automatically be treated as equally appropriate within a sensitive industrial environment simply because both products satisfy the same generic control checklist.

The NCSC’s Principles Based Assurance approach is designed to move the emphasis towards security outcomes and evidence. Within Cyber Resilience Testing, Assurance Principles and Claims define the scope of the evaluation and the claims against which evidence is assessed. The NCSC describes the method as using claims, argument and evidence to determine how effectively a product satisfies the relevant security principles.

The distinction is substantive. Rather than asking only whether a prescribed control exists, the assessment asks what evidence supports a security claim and what remaining risks need to be understood.

That produces richer information, but it also makes assurance more demanding for the people consuming it.

CRTFs Are Not Designed to Produce a Simple Pass or Fail

One of the most important characteristics of the model is that Cyber Resilience Testing does not operate primarily as a binary product-certification mechanism.

Technology vendors work with a CRTF to provide documentation and other evidence demonstrating how their product meets the claims contained within the relevant Assurance Principles and Claims. The facility assesses that evidence, identifies gaps and produces a standardised output report. The vendor can then use the findings to determine whether identified risks should be mitigated or tolerated according to the product’s circumstances and risk appetite.

This preserves information that a simple certification outcome can obscure.

A product may perform strongly against most security principles while containing a weakness that matters considerably in one deployment context and relatively little in another. A risk-based report allows the vendor and ultimately the customer to make a more informed judgement about that distinction.

The challenge is commercial interpretation.

Procurement processes often favour simple answers because buyers need to compare suppliers efficiently. A certificate, rating or recognised mark can be incorporated into tender requirements relatively easily. A report requiring professional judgement is harder to standardise across a large procurement function.

The long-term success of CRTFs will therefore depend partly on whether the market develops sufficient capability to consume the assurance they produce. If purchasers treat a completed assessment as equivalent to a generic approval mark, much of the informational value of principles-based assurance will be lost even if the underlying evaluation remains rigorous.

Distributed Delivery Is Central to the Model

The architecture of the CRTF programme is as significant as the assessment methodology itself.

Rather than attempting to conduct every product evaluation centrally, the NCSC has established requirements through which commercial organisations can become assured Cyber Resilience Test Facilities. Facilities need trained personnel capable of applying Principles Based Assurance, must conduct a trial evaluation supporting accreditation against ISO/IEC 17020, and enter an assurance agreement with the NCSC.

The result is intended to be a national ecosystem of independently delivered but consistently governed assurance.

This addresses a straightforward scaling problem. The number and variety of connected products in the economy are too large for meaningful product assurance to depend on a single central assessment organisation. By establishing the methodology and assuring providers capable of applying it, the NCSC can extend the reach of its approach through industry.

The model resembles infrastructure more than a conventional government testing service. National capability establishes the rules and assurance architecture, while accredited commercial capacity performs much of the delivery.

That makes consistency critical. Distributed assurance succeeds only if buyers can have reasonable confidence that assessments conducted by different facilities are comparable in quality and interpretation. Accreditation, training, standardised outputs and continuing oversight are therefore fundamental to the credibility of the ecosystem rather than administrative details surrounding it.

The Initial Scope Is Important but Deliberately Limited

The emergence of a national testing ecosystem could easily lead to overstatement about what CRTFs currently demonstrate.

The initial Cyber Resilience Testing service is focused primarily on internet-connected products with a direct requirement for robust cyber security. The NCSC describes the assessment as evaluating resilience against commodity attacks from public-facing interfaces. The Cyber Resilience Testing Assurance Principles and Claims have also been aligned with the Government’s Software Security Code of Practice.

That is a useful assurance problem to address, but it is not equivalent to proving that a product is secure under every conceivable threat or suitable for every environment.

Threat models matter. A product expected to resist commodity internet attacks faces a different assurance requirement from technology intended for a highly sensitive government system, a safety-critical industrial environment or infrastructure exposed to sophisticated state capabilities.

The distinction should remain visible as CRTF adoption increases. A credible assurance ecosystem needs multiple levels and forms of evidence appropriate to different consequences and threat environments.

The NCSC itself indicates that further CRTF services are being developed, including services capable of providing higher levels of assurance where security-enforcing functionality is particularly important.

The strategic opportunity is therefore not to turn the initial CRT service into a universal security label, but to develop a coherent assurance architecture in which buyers can identify what has been tested, against which threat model and to what level of confidence.

Product Assurance Is Becoming Part of Supply-Chain Resilience

The economic importance of the scheme becomes clearer when technology assurance is considered as part of supply-chain risk.

Businesses increasingly depend on products and services whose internal security properties they cannot directly inspect. A manufacturer may purchase connected equipment containing embedded software, communications components and remote-management functionality developed by several suppliers. A technology business may incorporate third-party components into a wider product. Critical services may depend on connected devices acquired through procurement processes in which buyers have limited technical evidence beyond supplier claims.

The NCSC’s stated vision for CRTFs is a national ecosystem capable of giving buyers greater confidence in the cyber resilience of connected products. It expects the resulting assessments to support better risk-management decisions while encouraging stronger security practice among technology vendors.

This changes assurance from an internal engineering question into a market mechanism.

Where buyers value credible evidence, vendors have a commercial incentive to produce it. Where assessment reveals weaknesses, vendors can improve products before those weaknesses become customer incidents. Where procurement teams understand the evidence, they can distinguish between technologies according to actual risk rather than relying solely on supplier assertions.

The potential benefit is a stronger technology supply chain in which security information travels with products more effectively.

The limitation is equally clear. Assurance has economic value only where customers recognise and use it. A technically rigorous scheme that procurement teams neither request nor understand can remain marginal regardless of the quality of its methodology.

The West Midlands Has a Strong Industrial Interest in Better Assurance

The implications are particularly relevant to the West Midlands because connected technology is increasingly embedded within industrial activity.

Modern manufacturing environments combine enterprise IT with production equipment, industrial control systems, sensors, remote maintenance technologies, cloud services and interconnected supply chains. Products entering those environments can create dependencies that persist for years, sometimes considerably longer than conventional enterprise software.

The consequences of poor technology assurance are correspondingly different. A vulnerable connected product may not simply expose information; it can create an access route into operational environments, complicate maintenance, increase downtime risk or become difficult to replace once embedded within production.

Industrial buyers therefore have an interest in understanding product resilience before deployment rather than discovering security characteristics only after integration.

CRTFs potentially strengthen that decision process by giving technology vendors a recognised mechanism for generating independent evidence about their products. The relevance should not be overstated, however. The initial CRT service is not a comprehensive assessment of every industrial or operational-technology threat scenario, and organisations remain responsible for evaluating whether the scope of an assessment is appropriate to their deployment.

For the West Midlands, the more interesting long-term opportunity lies in connecting national assurance methodology with regional product development and industrial adoption. Technology companies could use structured assurance during product development, while industrial customers could use the resulting evidence as part of broader procurement and engineering decisions.

That creates a potential bridge between cyber resilience and industrial innovation rather than treating security assessment as something performed only after a product has been completed.

Assurance Can Improve Product Development, Not Just Procurement

The vendor side of the CRTF model deserves equal attention.

An assurance report is useful to customers, but the process can also provide structured feedback to product developers. Where evidence does not support a particular security claim, the resulting gap can inform design changes, additional testing or clearer documentation.

This creates an important difference between meaningful assurance and certification theatre. If the principal objective is simply obtaining a marketable badge, assessment becomes an obstacle to be passed as efficiently as possible. If the objective is producing better evidence about resilience, findings can become part of the engineering process.

The NCSC explicitly makes the resulting report available to the vendor so that identified risks can inform decisions about mitigation or acceptance.

For smaller technology companies, this could be particularly valuable. Early-stage businesses frequently need to establish credibility with larger customers but may not possess an established assurance function or extensive history of deployment. Independent assessment can provide evidence that is difficult for the vendor to establish through assertion alone.

There is nevertheless a commercial tension. Assurance costs money and requires engineering time. If customers do not value the resulting evidence, smaller vendors may rationally prioritise other forms of product development.

Adoption therefore depends on demand as well as supply. Buyers, investors, government programmes and larger supply-chain organisations all influence whether assurance becomes economically worthwhile.

The Assurance Market Needs Informed Buyers

The central challenge for principles-based assurance is that richer evidence requires more sophisticated consumption.

A pass-or-fail result is easy to communicate. A risk-based assessment asks the buyer to understand what was tested, which claims were examined, what evidence was available, where weaknesses remain and whether those weaknesses matter in the intended deployment.

Not every procurement team will possess that expertise internally.

This creates the possibility of a new interpretation layer within the assurance market. Security architects, risk professionals, specialist consultancies and technically capable procurement functions may increasingly need to help organisations translate assessment results into purchasing decisions.

That should not be viewed as a defect in the CRTF model. Cyber risk is genuinely contextual, and removing that context merely to make procurement simpler can produce false confidence.

The design challenge is to make the evidence sufficiently structured that it remains usable without stripping away the distinctions that make it meaningful.

The NCSC’s standardised Assurance Principles and Claims and output-report requirements are important in this respect because they create a common language across facilities.

Over time, the maturity of the ecosystem may therefore be judged as much by the quality of buyer interpretation as by the number of assessments completed.

Assurance Infrastructure Needs Coherence

As the CRTF model develops, another question becomes increasingly important: how it relates to the wider UK technology-assurance landscape.

Different technologies and threat environments require different levels of confidence. Principles-based product testing, penetration testing, high-assurance evaluation, regulatory requirements and sector-specific assessment can all address legitimate but distinct problems.

The risk is fragmentation.

If vendors encounter multiple overlapping schemes whose relationship is unclear, assurance can become expensive and repetitive. If buyers cannot distinguish between the confidence provided by different assessments, they may either demand unnecessary evidence or place excessive reliance on a scheme whose scope does not match their risk.

A mature national assurance architecture should therefore make progression visible. Buyers need to understand what level of evidence is proportionate to their environment, while vendors should be able to reuse credible evidence where requirements overlap rather than repeatedly proving equivalent claims through unrelated processes.

CRTFs offer a potentially important foundation because the underlying Principles Based Assurance model is designed around security outcomes rather than an immutable checklist. That creates scope for different Assurance Principles and Claims to address different assurance problems while retaining a common methodological architecture.

The success of that approach will depend on governance as the ecosystem expands. More assurance is not automatically better assurance if proliferation makes the overall system harder to interpret.

The Regional Opportunity Is Capability, Not a New Badge

For the West Midlands, the appropriate response is not to create a competing regional assurance scheme.

The value of CRTFs comes partly from their national consistency. Vendors should not have to satisfy different product-assurance models simply because customers are located in different parts of the country.

The regional opportunity lies instead in capability surrounding the national system.

Technology companies need to understand when assurance could improve product development or customer confidence. Industrial buyers need support interpreting evidence and determining which level of assurance is appropriate to operational risk. Universities and technical organisations can contribute specialist expertise, research and testing capability. Cyber companies can help translate assessment findings into engineering improvements.

Regional programmes can also help create demand by connecting vendors seeking validation with industrial organisations facing genuine technology-assurance problems.

This is particularly important for smaller firms. The economic value of assurance becomes much clearer when it is connected to a customer, procurement opportunity or product-development requirement rather than presented as an abstract exercise in security maturity.

The West Midlands therefore has an opportunity to treat technology assurance as part of the infrastructure supporting industrial innovation: a mechanism through which new technology can move towards adoption with stronger evidence about the risks it introduces.

The Harder Phase Begins After the Scheme Works

The transition of Cyber Resilience Test Facilities into operational delivery is an important milestone because it demonstrates that principles-based technology assurance can be delivered through an NCSC-governed commercial ecosystem. The model now has assured facilities, a defined methodology, standardised Assurance Principles and Claims, and a route through which technology vendors can obtain independent assessments.

The harder questions concern what happens next.

The scheme needs sufficient consistency that assessments conducted across different facilities retain market confidence. Buyers need enough understanding to use risk-based reports rather than reducing them to binary signals. Vendors need commercial reasons to invest in assessment and respond to findings. Different levels of UK technology assurance need to develop coherently rather than becoming a collection of overlapping schemes.

Those are not secondary implementation details. They determine whether CRTFs become genuine assurance infrastructure or simply another mechanism that exists within the cyber ecosystem without materially changing purchasing and engineering decisions.

For the West Midlands, the strongest opportunity lies in the former outcome. A region whose economy depends heavily on engineering, manufacturing and increasingly connected technology has a direct interest in improving the evidence on which technology is designed, selected and deployed.

The objective should therefore be more demanding than increasing the number of products that undergo assessment. It should be to create a market in which credible cyber-resilience evidence influences product development, procurement and technology adoption.

If that happens, Cyber Resilience Test Facilities will have achieved something more significant than creating another assurance scheme. They will have helped establish an infrastructure through which cyber risk becomes more visible before technology is embedded within the systems on which businesses and the wider economy depend.