assessment pathways

Take the next step with technical qualifications from The Cyber Scheme

The Cyber Scheme assessments are industry leading, and a true measure of ‘what good looks like’, with both written and practical elements, an interview, and detailed reporting. Use this page to understand available assessment routes, what each route is designed to evidence and how to prepare.

For security testing practitioners requiring recognised technical assessment.

A technical entry point to professional registration at practitioner level in the security testing specialism, and also recognised by IASME as a pathway for Lead Assessor (Cyber Essentials) roles.

In-person and remote training is available for this assessment – find out more here.

For infrastructure specialists requiring recognised technical assessment.

An entry point to Principal professional registration in the security testing specialism, designed for senior practitioners assessing networks, infrastructure and enterprise environments.

Advanced Mentoring is available for this assessment – find out more here.

For web application and software security specialists requiring recognised technical assessment.

An entry point to Principal professional registration in the security testing specialism, focused on the assessment of web applications, APIs and modern software platforms.

Advanced Mentoring is available for this assessment – find out more here.

The VA+ (Vulnerability Assessment Plus) exam developed by The Cyber Scheme, NCSC and IASME is a useful and well respected standard, and is also a requirement for all Cyber Essentials Plus (CE+) assessors that do not have a Lead Assessor qualification. Book your exam directly with us. 

We offer training for this exam – find out more here.

Creating Advisors assured by NCSC, able to advise on and implement appropriate measures.

The Cyber Advisor Scheme helps businesses find service providers capable of providing appropriate guidance on implementing Cyber Essentials.

We are the only Assessment Provider of the Cyber Advisor scheme, and deliver assessments nationwide.

CSRTM (Cyber Scheme Red Team Manager) is an innovative assessment aimed at recognising the core competency of a Red Team Manager, including negotiation techniques, communication skills, the ability to set and change direction and technical tradecraft. 

This assessment is automatically mapped to Chartered professional registration in Security Testing.

For aspiring cyber security practitioners seeking recognised entry-level technical assessment.

An ideal starting point for individuals beginning a career in technical cyber security, providing hands-on skills, practical knowledge and a mapped pathway to Associate professional recognition.

This assessment forms part of a training course; find out more here.

Assessments as a requirement for a Professional Title

A Professional Title is more than just a post-nominal. It is a measure of your professional competency, gained knowledge and ongoing career development. 

If you are a consultant working on Government schemes (including the CHECK scheme), you may need a professional title in order to continue to operate. If you have any questions about this, please contact NCSC directly.

Find out more and start your application here.

“This was my first interaction with The Cyber Scheme and it was a very positive experience. The booking was easy, the communication from the staff was great and any queries were quickly answered and resolved. On the day the assessors were very clear on the rules, scoping and expectations. The scoping and interview aspects were handled really well, and it is reassuring to know that the assessors understand what is required and have a higher level of technical knowledge than the candidates.”

FAQs

Technical assessments provide a structured way to evidence practical capability. They help professionals demonstrate competence and help organisations identify trusted signals of skill.

Use the assessment pathway page here to identify the route that matches your role, experience and objectives. This page includes preparation guidance, booking routes and joining instructions.

The Cyber Scheme Team Member (CSTM) assessment is The Cyber Scheme’s flagship technical assessment for security testing professionals. It is designed to assess both practical and theoretical cyber security knowledge across a broad range of penetration testing and security testing disciplines. The assessment includes practical tasks, technical questioning and reporting activities, providing a realistic measure of professional competence rather than relying solely on written examinations.

A pass in CSTM is recognised across the industry and is a mandatory requirement for the Practitioner-level Professional Title in the Security Testing specialism through the UK Cyber Security Council. It also meets the standard required for certain Cyber Essentials Plus assessor roles. Candidates can access assessment guidance, syllabuses, technical question sets and preparation resources through the Assessment Pathways section.

The Cyber Scheme Team Leader (CSTL) assessment is aimed at experienced security testing professionals who want to demonstrate advanced technical capability and leadership within penetration testing engagements. Available in both Infrastructure (CSTL-INF) and Web Application (CSTL-APP) pathways, the assessment reflects the level of competence expected from senior practitioners leading security testing activities.

CSTL is recognised by the National Cyber Security Centre as meeting the competency level required for CHECK Team Leader roles and supports progression towards Principal-level professional recognition within the Security Testing specialism. Candidates should review the published syllabus, assessment guidance and preparation resources before booking an assessment.

Cyber Advisor is a Government-backed scheme designed to help organisations identify trusted cyber security professionals who can provide guidance on implementing Cyber Essentials. The Cyber Scheme delivers the assessment that enables candidates to demonstrate the knowledge, practical skills and advisory capability required to support organisations through Cyber Essentials implementation.

The assessment focuses not only on technical understanding but also on the ability to provide practical, proportionate and effective advice to organisations. Successful candidates can demonstrate that they understand the Cyber Essentials controls and can help organisations implement them confidently and effectively.

VA+ (Vulnerability Assessment Plus) is a respected industry certification developed by The Cyber Scheme in collaboration with the National Cyber Security Centre and IASME. It validates the practical skills required to conduct effective vulnerability assessments and identify security weaknesses in a structured and professional manner.

VA+ is recognised across the cyber security industry and is a requirement for Cyber Essentials Plus assessors who do not already hold a Lead Assessor qualification. Candidates can access preparation materials, training opportunities and booking information through the Assessment Pathways section.

Cyber Scheme Foundation Level (CSFL) is an entry-level assessment designed for individuals who are beginning their journey into technical cyber security. It provides a practical foundation in core security concepts and helps candidates demonstrate that they have the knowledge and potential expected of an entry-level cyber security practitioner.

CSFL is particularly suitable for students, graduates, career changers and those who are building technical skills before progressing towards more advanced assessments, training programmes or professional registration pathways. It forms part of The Cyber Scheme’s wider career development and assessment framework.

Preparation requirements vary depending on the assessment being taken, but all candidates should begin by reviewing the published syllabus, assessment objectives and supporting guidance. The Cyber Scheme provides preparation materials, technical question sets, joining instructions and additional resources to help candidates understand what will be assessed and how the assessment process works.

Candidates are encouraged to identify any knowledge gaps early, gain practical experience wherever possible and familiarise themselves with the assessment format before booking. The recommended pathway is to choose the appropriate assessment, review the available resources, undertake any necessary preparation or training, attend the assessment and then use the results to plan the next stage of professional development.

Yes. The Cyber Scheme is committed to making its assessments and training opportunities as accessible as possible. If you require reasonable adjustments because of a disability, health condition or specific learning requirement, you should contact the team as early as possible before your assessment or course date.

Requests are considered on a case-by-case basis and suitable arrangements will be explored wherever appropriate. Candidates are encouraged to discuss their requirements in advance so that any adjustments can be implemented smoothly and without affecting the integrity of the assessment.

We offer comprehensive training for a selection of our exams – find out more here.

The Cyber Scheme is now an Approved ELCAS Provider

ELCAS provides financial support to eligible armed forces members for higher-level learning, offering up to £2,000 annually over three claim years.

All of our assessments, including our CSFL Foundation Level and our flagship Technical Assessment, Cyber Scheme Team Member (CSTM), as well as our training programmes from entry to advanced level are now fully ELCAS-eligible. These certifications provide pathways to high-demand cyber careers and meet strict government standards for assurance schemes including CHECK and Cyber Essentials.

Provider ID: 13341. Please click here for more details.

Practical Information for in-person assessments