The Cyber Scheme banner image depicting telecommunications spy satellites

Application Guidance for Professional Registration

There are four professional registration titles aligned to the Council’s Standard of Professional Competence and Commitment. Please familiarise yourself with the standard to help you decide which level you should be applying for. Click on the tabs below for a summary of each level. Please note Associate Level is not specialism-specific.

The UK Cyber Security Council’s titles align to the RQF and other frameworks. For candidates, this describes the approximate level of knowledge required; for example, a Chartered professional should have cyber security knowledge equivalent to a Level 7 qualification e.g. a master’s degree.

Candidates do not need a master’s degree and can demonstrate knowledge gained in other ways, e.g. on the job, self-guided learning, certifications, other degrees or a combination thereof. Cyber security knowledge is only one element of the requirements. Candidates must also demonstrate experience of cyber security and the competencies shown below.

A Registered Cyber Security Professional will be able to demonstrate competence and commitment in all the areas below and provide appropriate evidence.

"It is recommended you provide plenty of detail as to why you should be chartered, showing evidence of your skills and competencies wherever possible".

Application Form

We recommend following the STAR technique, a proven method of answering tricky situational questions systematically while providing all the essential details.

The STAR technique is a method of answering questions that is comprised of four steps:

Situation

Describe the situation and when it took place.

Task

Explain the task and what was the goal.

Action

Provide details about the action you took to attain this.

Result

Conclude with the result of your action.

Professional History

You are expected to cover your complete professional history as well as your current work in industry. Start with your most recent post and work backwards over a 10-year period. Mention your individual  achievements, tasks, and actions, talk about yourself rather than team efforts.

  • Indicate the size and complexity of any projects or tasks you describe
  • Give an extended description of your current role
  • Explain any acronyms or abbreviations the first time you use them.

Education History

The application form also asks for your education history, such as professional qualifications, apprenticeships, and degrees.

Additional information required

You will be given the opportunity to detail any papers you have contributed to; this can include articles published in recognised journals, in-house publications, conference and seminar presentations, and any other contribution to industry, national and international bodies.

You are then asked to provide evidence of your competence mapped to the Standard of Professional Competence & Commitment (UK CSC SPCC). Using the STAR model will also prove beneficial here.

Finally, you will also be asked to provide referees; professionals who are familiar with your technical knowledge and work-based experience.

Once your application has been approved you will be invited to attend an interview (professional discussion), which takes place remotely and lasts for approx. one hour.

The interview will be conducted by an Assessor holding a professional title of at least the level being assessed.

(Security Testing only; you must have completed an appropriate exam within the last three years – see below).

Final Assessment

Following the application, examination and interview, a Final Assessment review will take place before Professional Registration can be awarded. The Final Assessment Assessors are responsible for holistically reviewing all the evidence from each stage and will take recommendations from assessors and interviewers as necessary. 

Obtaining a Professional Title with The Cyber Scheme - applicants tell all

Security Testing specialism only

Depending on which category of chartership you are applying for, different exams map to the required skill level. The CHECK Scheme examination standard has been mapped against the UK Cyber Security Council Standard for Professional Competence and Commitment (UKCSC SPCC) and approved as a means of testing technical knowledge requirements.

For registrants applying through The Cyber Scheme, this means:

  • For Chartered Title, applicants are required to pass or hold a qualifying certificate – The Cyber Scheme’s CSTL exam (App or Inf) or Cyber Scheme Red Team Manager (CSRTM) exam, and be able to demonstrate significant delivery experience at Team Leader level to proceed with their application. Note: We recognise equivalent exams from other organisations where they are recognised by the Council.
  • For Principal Title applications, registrants are required to pass or hold The Cyber Scheme’s CSTL exam (App or Inf), or equivalent exams from other organisations. 
  • For Practitioner Title applications, registrants are required to pass or hold The Cyber Scheme’s CSTM exam, or equivalent exams from other organisations. 
  • The Associate Title is not specialism-specific but can be the first step on the ladder to Practitioner in Security Testing. Please click here for further details.

Existing CTM and CTL certificate holders

Please be aware that for Security Testing specialism, you must hold a valid certificate (CSTM/CSTL or equivalent) at the point of submission of your professional title application form. We recommend that you have at least 6 months left on your certificate at this point of submission.