Press release
19 Aug 2026  | London, United Kingdom

EY teams in the UK receive National Cyber Security Centre accreditation

Press contact

  • EY UK teams have received NCSC accreditation for Audit and Review and Risk Management cyber security consulting services.
  • The accreditation helps organisations identify providers that meet NCSC standards for independent cyber security advice.
  • The newly accredited services complement existing Cyber Incident Exercising and Cyber Resilience Audit credentials.

EY teams in the UK have been accredited as an Assured Cyber Security Consultancy by the UK’s National Cyber Security Centre (NCSC), reinforcing their position as a trusted provider of independently assured cyber security advice.

The NCSC Assured Cyber Security Consultancy (ACSC) scheme helps organisations identify consultancies that meet the NCSC’s standards for high‑quality, independent cyber security expertise.

It is designed to support organisations with complex or high‑risk cyber security requirements, including government, the wider public sector, Critical National Infrastructure (CNI) and regulated industries, by recognising consultancies that apply NCSC guidance alongside established industry frameworks.

The NCSC accreditation awarded to EY in the UK covers:

  • Audit & Review
  • Risk Management

These accreditations complement existing NCSC recognition held by EY in the UK for:

  • Cyber Incident Exercising
  • Cyber Resilience Audit

Rick Hemsley, EY UK & Ireland Cybersecurity Consulting Leader, commented: “This accreditation reflects the maturity, consistency and quality of our cybersecurity consulting capabilities. It provides additional confidence to clients seeking independently assured cyber expertise in the UK market, particularly those operating in complex, highly regulated and public sector environments.

“As organisations face evolving regulatory requirements, increasing resilience expectations and the rapid adoption of technologies such as AI, the cyber risk landscape continues to grow in complexity. Together, these NCSC-assured services reinforce our role as a trusted adviser in helping organisations manage cyber risk, enhance resilience and securely embrace innovation, in line with NCSC guidance and expectations.”

Lucy Rosemont, EY UK & Ireland Technology Consulting Leader, added: “As our clients navigate an increasingly complex landscape of evolving cyber threats, alongside the opportunities and challenges presented by AI, we remain focused on investing in the strength and capability of our exceptional cybersecurity team. This accreditation reflects our commitment to maintaining the highest standards of expertise and service, providing our clients with the confidence that they are working with industry-leading specialists who can help them manage risk, build resilience and embrace innovation securely. We are delighted to continue growing our thriving Cybersecurity practice and the important role it plays in supporting our clients' success."

Notes to editors:

About the accreditation

  • Cyber Resilience Audit: Ernst & Young LLP has been assessed as meeting the NCSC standard and are now an Assured Service Provider for the NCSC Cyber Resilience Audit scheme. Cyber Resilience Audit (CRA) companies provide independent audits against defined cyber security standards, initially based on the Cyber Assessment Framework (CAF

  • Audit & Review: Ernst & Young LLP has been assessed as meeting the NCSC standard and are now an Assured Cyber Security Consultancy provider for the Audit and Review Offering. ACSC Audit and Review companies apply NCSC advice and guidance, alongside other recognised methodologies and frameworks as appropriate, to provide expert advice and guidance to Senior Information Risk Owners (SIROs) and business managers.

  • Risk Management: Ernst & Young LLP has been assessed as meeting the NCSC standard and are now an Assured Cyber Security Consultancy provider for the Risk Management Offering. ACSC Risk Management companies apply NCSC cyber security risk management advice and guidance, alongside other recognised methodologies and frameworks as appropriate to meet the Customer’s business needs, objectives and governance structures.

  • Cyber Incident Exercising: Ernst & Young LLP has been assessed as meeting the NCSC standard and are now an Assured Service Provider for the NCSC Cyber Incident Exercising (CIE) scheme. Cyber Incident Exercising (CIE) companies develop and deliver controlled, scenario-based cyber incident exercises that enable organisations to practise, evaluate and improve their cyber incident response plans in a safe and structured environment.

Related News