faqs

The Cyber Scheme works across professional registration, technical assessment, accreditation, training, mentoring, workforce development and standards assurance. If you are unsure where to start, this page answers some of the most common questions and points you towards the most useful next step.

Some questions are aimed at individuals developing their careers. Others are written for employers, training providers, consultancies and organisations looking for assurance around cyber security competence. If you already know what you need, use the buttons below to move straight to the relevant section.

about the cyber scheme

The Cyber Scheme helps individuals and organisations demonstrate technical cyber security competence through assessment, professional recognition, accreditation, training, mentoring, workforce development and guidance. 

The Cyber Scheme supports professionals, future professionals, employers, consultancies, training organisations and wider stakeholders who need confidence in cyber security capability.

If you are an individual looking for recognition, assessment, training, CPD or career progression, start with the For Professionals section. If you represent an employer, consultancy, training provider or organisation seeking assurance, accreditation or workforce support, start with the For Organisations section. If you are still researching, use the Resource Centre to choose the right route for you.

No. The Cyber Scheme supports people at different stages of their professional journey, including those entering the profession, preparing for assessment, applying for professional registration, developing technical capability or progressing into more senior roles.

It means that professional credibility should be based on evidence, not unsupported assertions. Across the site, competence is positioned as something that should be assessed, recognised, evidenced and maintained through clear standards, practical demonstration and ongoing development.

professional registration

Professional registration provides a structured way for individuals to have their competence, commitment and professional standing recognised against agreed professional standards. It helps practitioners demonstrate where their capability sits within the profession.

The right title depends on your experience, responsibility, evidence and current level of professional competence. The professional registration route should help users understand which title may be appropriate, what evidence may be needed and where to find application support.

The title levels are Associate, Practitioner, Principal and Chartered. Associate is for individuals entering or ready to enter the profession. Practitioner is for professionals applying practical cyber security expertise. Principal is for senior practitioners with recognised expertise in their specialism. Chartered is for experienced professionals able to demonstrate significant competence, responsibility and contribution.

Before starting an application, read the relevant professional standard, identify the title and specialism that best matches your current experience, and gather evidence before writing your application.

Your evidence should be specific, relevant and connected to the competence criteria. Explain your role, the context, what you did, why it mattered and how it demonstrates competence. Avoid relying on generic statements or certificates alone.

Common mistakes include applying at the wrong level, submitting vague evidence, relying only on certificates, describing team activity without explaining your contribution and leaving gaps across the required competence areas.

Yes. CPD is part of maintaining and evidencing professional competence over time. It provides a structured way to record learning, reflect on development and evidence ongoing professional commitment.

Please visit this page for further guidance and information.

taking an assessment with us

Technical assessments provide a structured way to evidence practical capability. They help professionals demonstrate competence and help organisations identify trusted signals of skill.

Use the assessment pathway page here to identify the route that matches your role, experience and objectives. This page includes preparation guidance, booking routes and joining instructions.

The Cyber Scheme Team Member (CSTM) assessment is The Cyber Scheme’s flagship technical assessment for security testing professionals. It is designed to assess both practical and theoretical cyber security knowledge across a broad range of penetration testing and security testing disciplines. The assessment includes practical tasks, technical questioning and reporting activities, providing a realistic measure of professional competence rather than relying solely on written examinations.

A pass in CSTM is recognised across the industry and is a mandatory requirement for the Practitioner-level Professional Title in the Security Testing specialism through the UK Cyber Security Council. It also meets the standard required for certain Cyber Essentials Plus assessor roles. Candidates can access assessment guidance, syllabuses, technical question sets and preparation resources through the Assessment Pathways section.

The Cyber Scheme Team Leader (CSTL) assessment is aimed at experienced security testing professionals who want to demonstrate advanced technical capability and leadership within penetration testing engagements. Available in both Infrastructure (CSTL-INF) and Web Application (CSTL-APP) pathways, the assessment reflects the level of competence expected from senior practitioners leading security testing activities.

CSTL is recognised by the National Cyber Security Centre as meeting the competency level required for CHECK Team Leader roles and supports progression towards Principal-level professional recognition within the Security Testing specialism. Candidates should review the published syllabus, assessment guidance and preparation resources before booking an assessment.

Cyber Advisor is a Government-backed scheme designed to help organisations identify trusted cyber security professionals who can provide guidance on implementing Cyber Essentials. The Cyber Scheme delivers the assessment that enables candidates to demonstrate the knowledge, practical skills and advisory capability required to support organisations through Cyber Essentials implementation.

The assessment focuses not only on technical understanding but also on the ability to provide practical, proportionate and effective advice to organisations. Successful candidates can demonstrate that they understand the Cyber Essentials controls and can help organisations implement them confidently and effectively.

VA+ (Vulnerability Assessment Plus) is a respected industry certification developed by The Cyber Scheme in collaboration with the National Cyber Security Centre and IASME. It validates the practical skills required to conduct effective vulnerability assessments and identify security weaknesses in a structured and professional manner.

VA+ is recognised across the cyber security industry and is a requirement for Cyber Essentials Plus assessors who do not already hold a Lead Assessor qualification. Candidates can access preparation materials, training opportunities and booking information through the Assessment Pathways section.

Cyber Scheme Foundation Level (CSFL) is an entry-level assessment designed for individuals who are beginning their journey into technical cyber security. It provides a practical foundation in core security concepts and helps candidates demonstrate that they have the knowledge and potential expected of an entry-level cyber security practitioner.

CSFL is particularly suitable for students, graduates, career changers and those who are building technical skills before progressing towards more advanced assessments, training programmes or professional registration pathways. It forms part of The Cyber Scheme’s wider career development and assessment framework.

Preparation requirements vary depending on the assessment being taken, but all candidates should begin by reviewing the published syllabus, assessment objectives and supporting guidance. The Cyber Scheme provides preparation materials, technical question sets, joining instructions and additional resources to help candidates understand what will be assessed and how the assessment process works.

Candidates are encouraged to identify any knowledge gaps early, gain practical experience wherever possible and familiarise themselves with the assessment format before booking. The recommended pathway is to choose the appropriate assessment, review the available resources, undertake any necessary preparation or training, attend the assessment and then use the results to plan the next stage of professional development.

Yes. The Cyber Scheme is committed to making its assessments and training opportunities as accessible as possible. If you require reasonable adjustments because of a disability, health condition or specific learning requirement, you should contact the team as early as possible before your assessment or course date.

Requests are considered on a case-by-case basis and suitable arrangements will be explored wherever appropriate. Candidates are encouraged to discuss their requirements in advance so that any adjustments can be implemented smoothly and without affecting the integrity of the assessment.

Training, mentoring and career development

Yes. The Cyber Scheme provides a range of training courses, mentoring programmes and practical development opportunities designed to help individuals build technical cyber security capability. Training is not viewed as an end in itself, but as part of a wider professional development journey that helps practitioners gain the knowledge, practical skills and experience needed to demonstrate competence through assessment and professional recognition.

Training is available at different levels, from foundation-level development for those entering the profession through to advanced practitioner mentoring for experienced testers. Courses and mentoring programmes are designed to support candidates preparing for assessments, developing specialist expertise and progressing throughout their careers.

Training and assessment serve different but complementary purposes. Training helps candidates develop knowledge, practical skills and confidence, while assessment provides an independent way to demonstrate and validate that competence.

The Cyber Scheme’s training and mentoring programmes are designed to help candidates identify knowledge gaps, strengthen practical capability and prepare for technical assessments. Assessments then provide formal recognition that an individual has demonstrated the required level of competence against recognised standards. Together, training, assessment and professional recognition create a structured pathway for career progression.

Yes. The Cyber Scheme offers mentoring and advanced practitioner development alongside its training and assessment portfolio. Mentoring is intended to help individuals deepen technical skills, prepare for assessments and support their ongoing professional development.

Depending on experience level and career goals, candidates can access structured training, advanced mentoring, assessment preparation support and guidance from experienced practitioners. Information on available mentoring opportunities, joining instructions and progression routes can be found within the Training and Mentoring section

If you are new to cyber security, the best starting point is to focus on building practical technical skills and understanding the pathways available within the profession. The Cyber Scheme supports individuals at different stages of their careers, including those entering the sector for the first time.

Foundation-level routes such as CSFL provide an introduction to essential technical concepts and practical skills, helping candidates demonstrate readiness for entry-level opportunities. From there, individuals can progress through further training, mentoring, assessment and professional registration pathways as their experience develops. The Career Development and Resource Centre sections are designed to help individuals understand available routes and identify the next appropriate step.

Yes. The Cyber Scheme provides a range of resources aimed at individuals beginning their cyber security careers. These include foundation-level learning opportunities, career development guidance, mentoring support, assessment preparation resources and information about professional registration pathways.

The Resource Centre brings together guidance, FAQs, downloads, webinars and supporting materials to help candidates understand career options, prepare for assessments, develop technical capability and plan their professional progression. Early-career professionals can also access information on training, mentoring and entry-level assessment routes.

Training helps individuals develop knowledge and skills, but completing training alone does not necessarily demonstrate competence. Competence is demonstrated through the ability to apply knowledge and skills effectively in practice and, where appropriate, through formal assessment and professional recognition.

The Cyber Scheme places particular emphasis on independent assessment as a means of validating capability. Training supports development, mentoring supports progression, and assessment provides evidence that competence has been demonstrated against recognised standards. Together, these elements help individuals build credible and recognised professional capability.

Accreditation

Accreditation provides a structured route for organisations to demonstrate commitment to recognised professional competence and standards. It is intended to make credible capability easier to recognise by allowing organisations to evidence standards rather than simply state them.

The Accredited Company Programme recognises organisations that invest in verified professional competence and can evidence alignment with recognised standards. It is designed to provide assurance to buyers, employers and stakeholders.

It is for consultancies and organisations employing individuals with relevant professional titles or recognised competence who want to demonstrate organisational credibility.

Training Centre Accreditation is a route for training providers seeking to evidence standards, quality and alignment with recognised expectations.

Accreditation assesses whether an organisation can demonstrate a genuine commitment to quality, professional competence and recognised standards. Rather than relying on self-declared capability, accreditation requires organisations to provide evidence that they operate in a structured, consistent and professional manner.

Depending on the accreditation route, this evidence may include information about governance, staff competence, quality processes, professional development, customer service, continuous improvement and the way services or training are delivered. The objective is not simply to assess what an organisation says it does, but to provide independent assurance that appropriate standards are being applied in practice.

Accreditation helps customers, learners, partners and stakeholders understand that an organisation has been assessed against recognised criteria and has demonstrated a commitment to maintaining those standards over time. It also encourages continual improvement by requiring organisations to review and strengthen their processes on an ongoing basis.

Choosing a cyber security provider, training organisation or professional services partner can be difficult. Buyers and employers are often presented with similar claims of expertise but may have limited information on which to base decisions.

Accreditation provides an independent indicator that an organisation has demonstrated its commitment to recognised standards, professional competence and quality assurance. This gives buyers greater confidence that they are working with organisations that have been assessed against an established framework rather than relying solely on marketing claims or self-certification.

For employers, accreditation can also provide reassurance that prospective partners, suppliers and training providers take professional standards seriously and have processes in place to support quality, consistency and continual improvement.

No. Accreditation is not limited to consultancies or organisations delivering cyber security services. The Cyber Scheme provides accreditation routes for both organisations delivering cyber security services and organisations delivering cyber security training.

The accreditation framework is designed to support a wide range of organisations that want to demonstrate their commitment to recognised standards, quality and professional competence. This includes consultancies, training providers, employers investing in workforce capability and organisations seeking greater assurance and credibility within the cyber security profession.

By recognising different types of organisations, accreditation helps strengthen trust, consistency and confidence across the wider cyber security ecosystem.

Comprehensive guidance is available through the Resource Centre and Accreditation sections of the website. These resources explain what accreditation is, who it is intended for, the available accreditation routes and the benefits of becoming accredited.

Visitors can access information covering eligibility requirements, evidence expectations, the accreditation process, frequently asked questions and ongoing responsibilities after accreditation has been achieved. Additional guidance, supporting resources and practical information are also available to help organisations understand which accreditation route is most appropriate for their circumstances and how to prepare their application.

Workforce development and employer guidance

The Cyber Scheme helps employers make more informed decisions about hiring, developing and retaining cyber security talent. Through professional registration, technical assessment, accreditation and workforce development services, employers can better understand what good cyber security competence looks like and how capability can be evidenced against recognised standards.

For accredited organisations, support extends beyond assurance and assessment. Accredited companies can also engage with workforce development initiatives designed to strengthen cyber talent pipelines. This includes opportunities to connect with candidates who have completed assessments, mentoring and practical preparation programmes, helping organisations identify capable individuals who are ready to progress into cyber security roles.

The Cyber Scheme is not a recruitment agency, but it does help employers improve recruitment outcomes by providing access to structured talent development pathways and employer-ready candidates. Through assessment, mentoring and professional development programmes, candidates can develop practical capability before entering the recruitment process, helping employers engage with individuals who have already demonstrated commitment to their professional development.

Accredited companies may also benefit from opportunities to engage with candidate cohorts emerging from The Cyber Scheme’s development programmes. This can include early access to candidates who have completed assessments, mentoring and practical preparation activities, helping organisations identify potential talent before it reaches the wider market.

Cyber security is a broad profession with many different specialisms, qualifications, certifications and career pathways. Candidates may have very different backgrounds, training histories and levels of practical experience, making direct comparisons difficult.

Employers are often faced with the challenge of distinguishing between qualifications, understanding what different certifications actually demonstrate and assessing whether an individual can apply their knowledge effectively in practice. Evaluating cyber security capability therefore requires more than reviewing a CV; it involves understanding how competence is demonstrated, assessed and maintained throughout a professional career.

There is no single indicator that proves competence, which is why employers should consider multiple sources of evidence when evaluating candidates or suppliers. Useful indicators can include technical assessments, professional registration, continuing professional development, practical experience, recognised qualifications and participation in accredited programmes.

Each of these measures provides a different perspective on capability. Technical assessments can demonstrate practical skill, professional registration can demonstrate recognised competence against professional standards, and CPD can show a commitment to ongoing professional development. Taken together, these signals help build a more complete picture of an individual’s capability.

Yes. The Cyber Scheme supports workforce development by helping organisations understand current capability, identify development opportunities and create structured progression pathways for their teams.

Support may include skills gap analysis, assessment preparation, technical training, mentoring, professional registration guidance and continuing professional development. The objective is to help organisations build stronger technical capability over time while ensuring employees have access to recognised development and progression opportunities.

Skills gap analysis is a structured process that helps organisations understand the capability that already exists within a team and identify areas where further development may be beneficial. By comparing current skills against organisational requirements, employers can make more informed decisions about recruitment, training, assessment and workforce planning.

The process can help highlight strengths, identify potential development priorities and support investment decisions. It also provides a stronger foundation for professional development, allowing organisations to target support where it will have the greatest impact.

No. Training is one part of workforce development, but effective workforce development involves a much broader approach. Organisations need to understand current capability, identify future requirements and provide opportunities for professional growth and progression.

This can include professional registration, technical assessments, mentoring, continuing professional development, practical experience and structured career pathways alongside formal training. A comprehensive workforce development strategy helps organisations build competence, confidence and resilience across their teams rather than simply increasing training attendance.

Professional registration gives employers a recognised framework for understanding competence within the cyber security profession. It provides assurance that an individual has demonstrated capability against established professional standards and has committed to maintaining and developing that competence over time.

Employers can use professional registration to support recruitment decisions, career progression discussions, workforce planning and succession planning. It can also help organisations build clearer development pathways by providing recognised milestones for professional growth.

Accreditation provides an additional level of assurance when selecting organisations to deliver cyber security services, training or workforce development support. Accredited providers have demonstrated their commitment to recognised standards, quality processes and professional competence, giving customers greater confidence in the services they receive.

When comparing providers, employers can use accreditation as one of several indicators of credibility and professionalism. Accreditation helps distinguish organisations that have been independently assessed against recognised standards from those relying solely on self-declared claims, making procurement and supplier selection decisions easier and more informed.

standards and assurance

Standards and Assurance brings together the principles, frameworks and processes that help make cyber security competence visible, measurable and trusted. It explains how professional standards, technical assessments, accreditation, professional registration and organisational assurance work together to provide confidence in capability, both for individuals and organisations.

This section acts as the foundation for much of The Cyber Scheme’s work. It helps visitors understand not only the services available, but also the standards and evidence that sit behind them. Whether someone is applying for professional recognition, preparing for an assessment, seeking accreditation or evaluating a provider, the Standards and Assurance section provides the context that explains why these measures matter.

The Cyber Scheme works to help raise standards across the cyber security profession by supporting the development, assessment and recognition of technical competence. Through professional registration, technical assessments, accreditation and workforce development, it helps individuals and organisations demonstrate capability against recognised benchmarks.

The role of The Cyber Scheme is not simply to deliver assessments or programmes, but to contribute to a profession where competence can be evidenced, recognised and trusted. By helping create clear pathways for development and recognition, The Cyber Scheme supports greater consistency, transparency and confidence across the cyber security sector.

Professional standards provide a shared framework for understanding competence. They help individuals understand what is expected at different stages of their careers and help employers, customers and stakeholders interpret capability more consistently.

Without recognised standards, it can be difficult to compare qualifications, experience and professional achievements. Professional standards create a common language for competence, helping the profession move beyond assumptions and towards evidence-based recognition. They support career progression, professional development and greater confidence in the capability of cyber security practitioners.

Assessment standards help ensure that competence is evaluated consistently, fairly and against clearly defined expectations. They provide a structured way to measure technical knowledge, practical capability and professional judgement, allowing individuals to demonstrate their skills through recognised assessment processes.

By applying consistent assessment standards, organisations, employers and stakeholders can have greater confidence that successful candidates have met an agreed level of competence. Assessment therefore plays an important role in making capability more visible, measurable and trustworthy.

Accreditation standards provide a framework for assessing the quality, professionalism and credibility of organisations. They help establish confidence that an organisation operates according to recognised principles, maintains appropriate processes and demonstrates a commitment to continual improvement.

For customers, employers and stakeholders, accreditation provides independent assurance that an organisation has been assessed against defined criteria rather than relying solely on self-declared claims. This helps strengthen trust, supports informed decision-making and encourages higher standards across the wider cyber security profession.

booking support and accessibility

All assessments can be booked through the Assessment Pathways section of the website. The first step is to identify the assessment that best matches your experience, role and professional objectives. Each assessment page provides information about the assessment itself, who it is designed for, preparation guidance, joining instructions and any supporting resources that may help you prepare.

Once you have selected the appropriate assessment, you can access the relevant booking information and available dates. Candidates are encouraged to review the assessment requirements and preparation materials before booking so they understand the format, expectations and any prerequisites that may apply.

Professional registration applications begin with understanding the available professional titles and identifying which level best reflects your experience, responsibility and current competence. The Professional Registration section explains the available pathways, eligibility requirements and the evidence needed to support an application.

Before applying, candidates should review the relevant professional standard, gather supporting evidence and ensure they understand the competence requirements for their chosen title. Application guidance and supporting resources are available throughout the Professional Registration area to help applicants prepare a strong submission and understand the process from application through to assessment and award.

Organisations interested in accreditation should begin by reviewing the accreditation routes available and determining which pathway is most appropriate for their activities. The website provides guidance for both organisations delivering cyber security services and those delivering cyber security training.

The accreditation process typically involves understanding the accreditation requirements, confirming eligibility, preparing supporting evidence and submitting an application for review. Guidance is available to help organisations understand what evidence may be required, how the assessment process works and what responsibilities accompany accreditation once it has been achieved. Organisations considering accreditation are encouraged to review the available resources before starting an application.

If you are unsure which service, programme, assessment or accreditation route is right for you, please get in touch with The Cyber Scheme team. We understand that visitors may be exploring professional registration, assessments, accreditation, training, workforce development or career progression opportunities and may not immediately know which route best matches their circumstances.

The team can help direct you towards the most appropriate information, resources or support. Contact details can be found throughout the website and in the footer.

Yes. The Cyber Scheme is committed to making its information, services and resources as accessible as possible. Accessibility information can be accessed through the website footer and dedicated accessibility pages, where users can find information about accessibility commitments, available support and how to raise any accessibility-related concerns.

If you experience difficulties accessing content, using website features or participating in assessments, training or events, you are encouraged to contact the team. The Cyber Scheme welcomes feedback and will always seek to understand and address accessibility requirements wherever possible.

still not sure where to go?

If you are looking for a formal route into professional registration, assessment, accreditation, training or workforce development, start with the section that best describes what you are trying to achieve. If you are looking for supporting guidance, templates, articles or downloads, use the Resource Centre or Library.
If you are still unsure, contact the team and we will help direct you to the most relevant information.