National Cyber Security Centre
- Company typePrivate
- Founded2016
- HeadquartersLondon, United Kingdom
- Headcount501–1,000
- GTM typeB2B
- OfferingServices
National Cyber Security Centre firmographics
Firmographics- Name
- National Cyber Security Centre
- Legal name
- National Cyber Security Centre
- Website
- https://ncsc.gov.uk
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 501–1,000 employees
- Ownership category
- akta.pro rank
National Cyber Security Centre industry classification
Industry- Product category
- National Cyber Security Authority
- NAICS
- National Security (928110), National Security and International Affairs (9281), International Affairs (92812)
- akta.pro primary industry
- Cyber Defense & Information Security (National Security) (BPAIAHAE)
- akta.pro secondary industries
- Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC), Grid Cyber Risk Management, Governance, Compliance & Audit (NERC CIP/IEC 62443) (EUADANAC), Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF)
Keywords
Where National Cyber Security Centre is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
National Cyber Security Centre business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure, Others
Revenue model
- Government Funding: NCSC operates as part of GCHQ and is funded by the UK government to provide free cyber security services to the public, businesses, and critical national infrastructure operators. As a government agency, its services are publicly funded and provided at no direct cost to end users.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Other | Free services for all UK organizations and citizens |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels8 records
National Cyber Security Centre product offering
Product offeringCore offering
The National Cyber Security Centre is the UK's national technical authority on cyber security, providing authoritative guidance, threat intelligence, and incident response to UK government departments, critical national infrastructure operators, businesses, and the public. It delivers government-backed products and services including Cyber Essentials certification, the Cyber Assessment Framework (CAF), the Early Warning Service, the Share and Defend programme with ISPs, the Vulnerability Monitoring Service, the Cyber Resilience Audit scheme, the CyberFirst education programme, the Cyber Action Toolkit, and the NCSC-engineered SilentGlass hardware device, all provided free of charge under UK government funding.
Product overview
The National Cyber Security Centre (NCSC) is the UK's technical authority on cybersecurity, operating as part of GCHQ. Rather than a commercial product company, NCSC provides government cybersecurity guidance, certification schemes, and advisory services. Its product portfolio includes SilentGlass (hardware cybersecurity device for HDMI/DisplayPort protection), Cyber Essentials (government-backed certification scheme), Cyber Assessment Framework (CAF guidance framework for critical infrastructure organizations), Early Warning Service (free threat alerts), Share and Defend (malicious site blocking with ISPs), Cyber Resilience Audit Scheme (assurance for independent cyber auditors), CyberFirst (education programmes), Cyber Action Toolkit (free small business guidance), and Vulnerability Monitoring Service (public sector monitoring). NCSC recommends passkeys as the primary authentication method over passwords.
Differentiator
Problem solved
Functional benefit
Brands
- Cyber Essentials: UK government-backed cybersecurity certification scheme administered by IASME and backed by NCSC to help organizations protect against common cyber threats.
- SilentGlass
- Cyber Assessment Framework (CAF)
- CyberFirst
- CYBERUK
- Early Warning Service
Products and services
- SilentGlass A plug-and-play hardware cybersecurity device developed by NCSC that actively blocks malicious HDMI and DisplayPort connections, protecting against cyberattacks targeting monitors and display screens. Targets organisations with advanced security requirements including government departments, critical infrastructure operators, and businesses supporting hybrid work. The device is licensed to Goldilock Labs for global manufacture and sale, manufactured at the Sony UK Technology Centre.
- Cyber Essentials UK government-backed cybersecurity certification scheme administered by IASME on behalf of NCSC. Protects organisations against the most common cyber threats by setting baseline technical controls. Version 3.3 makes multi-factor authentication mandatory on all cloud services. Suitable for organisations of all sizes.
- Cyber Assessment Framework (CAF) A collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions. Version 4.0 supports both internal assessments and external oversight bodies for compliance with the NIS Regulations.
- Early Warning Service A free Active Cyber Defence service that provides email alerts to UK organisations tailored to cyber threats affecting their IP addresses, by analysing multiple threat intelligence feeds and sharing data with internet service providers. Sign-up takes approximately five minutes.
- Share and Defend Active Cyber Defence programme that shares real-time data on fraudulent and malicious websites with internet service providers, enabling automatic blocking of fake shops, phishing sites, and malicious links. Operates at ISP level with BT, EE, VodafoneThree, and PXC to protect 46 million mobile phone users and 12 million fixed-line internet subscribers.
- Cyber Resilience Audit (CRA) Scheme NCSC scheme that assures companies delivering independent cyber audits based on the Cyber Assessment Framework. Provides confidence that service providers meet NCSC technical standards for conducting CAF-based audits, initially supporting nationally critical sectors.
- CyberFirst
- Cyber Action Toolkit
- Vulnerability Monitoring Service (VMS)
Quantifiable outcome
- Over 200 cyber incidents affecting critical national infrastructure managed in year to May 2026
- +3 more outcomes
Companies that use National Cyber Security Centre
Customer profileNamed customers6 records
Segments5 records
Ideal customer profiles5 records
National Cyber Security Centre technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability5 records
Feature4 records
National Cyber Security Centre partnerships and signals
Strategic signalPartnerships
17 partnerships are on record, tiered flagship and core.
- National Physical Laboratory (NPL)flagshipNPL leads the £10 million National Quantum Standards Network, with NCSC participating as a core partner alongside BSI, UKRI's National Quantum Computing Centre, and UKQuantum to establish technical and cybersecurity standards for quantum technologies.
- British Standards Institution (BSI)flagshipBSI is a strategic partner in the National Quantum Standards Network, working with NCSC and other partners to develop internationally recognized performance benchmarks for quantum hardware and software architectures.
- UKRI National Quantum Computing CentreflagshipUKRI's NQCC participates in the National Quantum Standards Network to help the UK lead global quantum standards-setting decisions as part of the £2 billion National Quantum Strategy.
- UKQuantumflagshipUKQuantum consortium is a strategic partner in the National Quantum Standards Network, bringing together the quantum sector to oversee standards ranging from laser linewidths to energy efficiency and security requirements.
- Goldilock LabscoreGoldilock Labs has been licensed by NCSC to manufacture and globally sell SilentGlass, the world's first NCSC-engineered cybersecurity device that blocks malicious HDMI and DisplayPort connections. The device was previously deployed on Government estates and manufactured in partnership with Sony UK Technology Centre.
- Sony UK Technology CentrecoreSony UK Technology Centre partnered with NCSC to manufacture SilentGlass, producing the hardware device at their UK facility. This partnership represents successful government IP commercialization of cybersecurity technology.
- BT Group (including EE)coreBT and EE are core partners in the Share and Defend programme, sharing real-time intelligence on malicious websites with NCSC to enable automatic blocking across their network of 46 million mobile users and 12 million fixed line subscribers. The programme has blocked nearly 1 billion attempts to access malicious websites.
- VodafoneThreecoreVodafoneThree participates in the Share and Defend programme alongside BT and EE, contributing to the most extensive cyber defense programme in the world by sharing threat intelligence on fraudulent and malicious websites.
- PXCcorePXC is a partner in the Share and Defend programme, collaborating with NCSC and other ISPs to expand coverage beyond current partners and protect more UK internet users from malicious websites.
- Arqit QuantumcoreArqit has been selected by NCSC to participate in its Post-Quantum Cryptography Pilot under the Assured Cyber Security Consultancy Scheme. The partnership validates Arqit's methodology for cryptographic discovery and migration planning as part of UK quantum-safe encryption readiness.
- Department for Energy Security and Net Zero (DESNZ)flagshipDESNZ jointly developed the Energy Sector Cyber Security Strategy with NCSC, Ofgem, and NESO as 'Quad Partners', structured around five pillars covering threat understanding, resilience uplift, incident response, regulatory compliance, and cyber security culture.
- OfgemflagshipOfgem is a Quad Partner in developing the Energy Sector Cyber Security Strategy alongside NCSC, DESNZ, and NESO, addressing rising cyber threats to the UK's electricity, gas, and oil infrastructure.
- National Energy System Operator (NESO)flagshipNESO participates as Quad Partner in developing the Energy Sector Cyber Security Strategy, coordinating with NCSC, DESNZ, and Ofgem to ensure security and support transition to net zero energy.
- IASMEcoreIASME is the delivery partner for Cyber Essentials certification, administering the government-backed cybersecurity scheme on behalf of NCSC. The partnership provides baseline security certification accessible to organizations of all sizes.
- Five Eyes Intelligence Alliance (CISA, ASD, CCCS, NCSC NZ)coreNCSC participates in the Five Eyes intelligence-sharing alliance with US (CISA), Australia (ASD), Canada (CCCS), and New Zealand (NCSC NZ) to coordinate cyber defense, publish joint advisories, and share threat intelligence on nation-state actors.
- FBI (United States)coreFBI collaborates with NCSC on cyber investigations, joint advisories on threat actors (APT28, Volt Typhoon, Flax Typhoon), and international cybercrime response including the Jaguar Land Rover investigation.
- NSA (United States)coreNSA works with NCSC on joint cyber security advisories, particularly regarding Chinese threat actors (Volt Typhoon, Flax Typhoon) and edge device vulnerabilities, coordinating responses to covert networks of compromised devices.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
National Cyber Security Centre competitors and assessment
Company assessmentBroad incumbents
- National Security Agency (NSA) — Cybersecurity Directorate: The US signals intelligence and cybersecurity agency. NSA's Cybersecurity Directorate provides threat advisories, vulnerability management, and classified intelligence-derived guidance — sharing with NCSC under Five Eyes. Broader intelligence mission makes it an incumbent rather than a direct peer.
- European Union Agency for Cybersecurity (ENISA): The EU's cybersecurity agency, coordinating cyber resilience across member states. Overlaps with NCSC's pan-European normative role (NIS2, Cyber Resilience Act) but operates at supranational level rather than as a single national authority.
Regional players
- Japan's National Center of Incident Readiness and Strategy for Cybersecurity (NISC): Japan's national cybersecurity policy coordination center under the Cabinet Secretariat. Performs analogous government cybersecurity strategy and incident coordination functions for Japan but with a more strategic/policy emphasis than NCSC's operational incident response profile.
Direct peers
- Cybersecurity and Infrastructure Security Agency (CISA): The US national cybersecurity authority and NCSC's closest Five Eyes counterpart. CISA performs the same operational mission — critical infrastructure protection, incident response, threat advisories, and public-sector cyber guidance — and coordinates with NCSC on joint advisories (Volt Typhoon, Flax Typhoon), making it the most directly comparable peer.
- Canadian Centre for Cyber Security (CCCS): Canada's unified national cyber authority under the Communications Security Establishment. CCCS provides near-identical functions to NCSC — threat assessment, incident response, IT security guidance for government and critical infrastructure — and is a direct Five Eyes coordination partner.
- Bundesamt für Sicherheit in der Informationstechnik (BSI): Germany's federal cybersecurity authority, a close functional counterpart providing IT baseline protection, certification schemes (ISO 27001, BSI-Grundschutz), and critical infrastructure oversight. Comparable scope and regulatory weight to NCSC within the EU.
- Agence Nationale de la Sécurité des Systèmes d'Information (ANSSI): France's national cybersecurity authority under the SGDSN. ANSSI combines regulatory authority (security visas, certifications like CSPN), incident response (CERT-FR), and critical infrastructure protection — a structurally equivalent role to NCSC in continental Europe.
- Israel National Cyber Directorate (INCD): Israel's national cybersecurity authority combining operational CERT-IL functions, threat intelligence, critical infrastructure protection, and capacity building. Structurally equivalent to NCSC and widely regarded as a global benchmark for national cyber authorities.
- National Cyber Security Centre New Zealand (NCSC NZ): New Zealand's national computer emergency response team within the Government Communications Security Bureau. Operates a near-identical mission and product portfolio to NCSC UK (CERT functions, threat advisories, critical infrastructure guidance) and shares the NCSC brand identity.
- Australian Signals Directorate (ASD) — Australian Cyber Security Centre (ACSC): Australia's national cybersecurity authority within ASD. ACSC publishes the Essential Eight maturity model and Shares threat intelligence with NCSC under Five Eyes, operating the equivalent mix of public guidance, incident response, and critical-infrastructure protection that defines NCSC.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat6 records
Key risks1 record
Key highlights7 records
Customer concentration
National Cyber Security Centre social profiles
Digital presenceNational Cyber Security Centre financial estimates
Financial estimateRevenue estimate
Valuation estimate
National Cyber Security Centre leadership team
Management profileNumber of profiles
Profiles8 records
National Cyber Security Centre funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
National Cyber Security Centre M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about National Cyber Security Centre
What does National Cyber Security Centre do?
The National Cyber Security Centre is the UK's national technical authority on cyber security, providing authoritative guidance, threat intelligence, and incident response to UK government departments, critical national infrastructure operators, businesses, and the public. It delivers government-backed products and services including Cyber Essentials certification, the Cyber Assessment Framework (CAF), the Early Warning Service, the Share and Defend programme with ISPs, the Vulnerability Monitoring Service, the Cyber Resilience Audit scheme, the CyberFirst education programme, the Cyber Action Toolkit, and the NCSC-engineered SilentGlass hardware device, all provided free of charge under UK government funding.
Is National Cyber Security Centre a public or private company?
National Cyber Security Centre is a private company. It is classified as state government owned and is currently operating.
When was National Cyber Security Centre founded?
National Cyber Security Centre was founded in 2016. It employs 501 to 1,000 people.
Where is National Cyber Security Centre based?
National Cyber Security Centre is headquartered in London, United Kingdom, in the Europe region.
How does National Cyber Security Centre make money?
One revenue line is on record: government Funding.
Who are National Cyber Security Centre's main competitors?
Broad incumbents on record are National Security Agency (NSA) — Cybersecurity Directorate and European Union Agency for Cybersecurity (ENISA). Japan's National Center of Incident Readiness and Strategy for Cybersecurity (NISC) is listed as a regional player. Direct peers are Cybersecurity and Infrastructure Security Agency (CISA), Canadian Centre for Cyber Security (CCCS), Bundesamt für Sicherheit in der Informationstechnik (BSI), Agence Nationale de la Sécurité des Systèmes d'Information (ANSSI), Israel National Cyber Directorate (INCD), National Cyber Security Centre New Zealand (NCSC NZ) and Australian Signals Directorate (ASD) — Australian Cyber Security Centre (ACSC).
Does National Cyber Security Centre have an API?
No public API is recorded for National Cyber Security Centre.
What industry is National Cyber Security Centre in?
National Cyber Security Centre's product category is National Cyber Security Authority. Its primary akta.pro industry code is BPAIAHAE, Cyber Defense & Information Security (National Security), with a secondary code of HDADAJAC, Critical Infrastructure Protection (CIP) & NERC-CIP Compliance. Its NAICS code is 928110.