Wavenet, one of the UK’s leading managed service and security providers, today announced it has been assessed as meeting the NCSC standard and are now an Assured Service Provider for the NCSC Cyber Resilience Audit scheme.
Cyber Resilience Audit (CRA) companies provide independent audits against defined cyber security standards, initially based on the Cyber Assessment Framework (CAF).
This achievement reflects Wavenet’s continued investment in high-quality, standards-aligned cyber advisory and assurance services, enabling customers to assess and enhance their resilience against evolving cyber threats.
The Cyber Resilience Audit (CRA) scheme, developed and assured by the UK’s National Cyber Security Centre (NCSC), provides organisations with an independent, structured evaluation of their cyber resilience against the NCSC Cyber Assessment Framework (CAF). It is widely adopted across sectors including government, critical national infrastructure, healthcare and financial services.
By achieving Assured Service Provider status, Wavenet has demonstrated its capability to deliver CRA engagements to the rigorous standards required by the NCSC, providing customers with:
-
Independent, structured assurance aligned to the NCSC Cyber Assessment Framework (CAF)
-
Audit-ready outputs suitable for regulatory and stakeholder scrutiny
-
Clear, prioritised recommendations to improve cyber resilience and risk posture
-
Consistency and quality assurance through NCSC-recognised methodologies
Paul Colwell, Chief Information Security Officer at Wavenet, said: “Achieving NCSC Assured Service Provider status for Cyber Resilience Audit is a significant milestone for Wavenet and reflects the maturity of our cyber resilience and assurance capabilities.
"Our customers increasingly require not just technical security services, but independent, regulator-aligned assurance that stands up to scrutiny. This recognition reinforces our ability to deliver high-quality, audit-ready assessments aligned to the CAF and broader UK regulatory expectations.”
This accreditation builds on Wavenet’s broader AI, Security and Resilience portfolio, which supports organisations in aligning to leading standards and frameworks, including:
- NCSC Cyber Assessment Framework (CAF)
- NCSC Assured Supplier for Cyber Incident Exercising
- ISO/IEC 27001 and ISO 22301
- Cyber Essentials and IASME frameworks
As cyber threats continue to increase in scale and sophistication, organisations (particularly those in regulated sectors) are under growing pressure to evidence resilience, manage risk effectively, and demonstrate compliance with national and international frameworks. Wavenet’s recognition under the NCSC CRA scheme ensures customers can access trusted, independent assurance to support these objectives.