NCSC For Startups
NCSC For Startups is a UK government program within the National Cyber Security Centre (part of GCHQ) that supports early-stage cyber security companies with access to NCSC guidance, expertise, and entrepreneur community resources.
- Company typePrivate
- Founded2017
- HeadquartersLondon, United Kingdom
- Headcount1–10
- GTM typeB2B and B2C
- OfferingServices
What NCSC For Startups does
NCSC For Startups is a UK government program operating within the National Cyber Security Centre, a non-ministerial department that sits inside GCHQ (Government Communications Headquarters). Established in 2017, the program supports early-stage cyber security companies by providing access to NCSC guidance, industry expertise, and a community of cyber entrepreneurs, while the parent NCSC's broader mission is to make the UK the safest place to live and work online. The entity delivers a portfolio of free cyber security products and services, including the Cyber Essentials certification scheme (delivered through partner IASME), the Cyber Assessment Framework (CAF) for organisations operating essential UK functions, Active Cyber Defence services such as Early Warning notifications and Check Your Email Security, a Vulnerability Disclosure Toolkit built on HackerOne, the SilentGlass plug-and-play hardware device for blocking malicious HDMI/Display Port connections, and a Phishing Reporting and Takedown Service that has processed over 55.7 million reports and removed 250,000 scams across 443,000 URLs as of May 2026.
NCSC For Startups firmographics
Firmographics- Name
- NCSC For Startups
- Legal name
- National Cyber Security Centre
- Website
- https://ncsc.gov.uk
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- NCSC For Startups is a UK government program within the National Cyber Security Centre (part of GCHQ) that supports early-stage cyber security companies with access to NCSC guidance, expertise, and entrepreneur community resources.
- Ownership category
- akta.pro rank
NCSC For Startups industry classification
Industry- Product category
- Government Cyber Security Services
- NAICS
- Professional and Management Development Training (611430), Educational Support Services (61171), Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Educational Services (8200)
- akta.pro primary industry
- Corporate Accelerators & Startup Programs (FSANAHAD)
- akta.pro secondary industries
- Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing) (EDABAFAF), Secure Software & DevOps Awareness (Secure Coding Basics) (EDABAGAN)
Keywords
Where NCSC For Startups is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
NCSC For Startups business model
Business model- GTM type
- B2B and B2C
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure, Marketing or Sales
Revenue model
- Government Funding: NCSC is a UK government organisation funded by public money through GCHQ. All services including guidance, Early Warning, and vulnerability management are provided free of charge to UK organisations and individuals.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free services for all UK audiences |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels8 records
NCSC For Startups product offering
Product offeringCore offering
NCSC For Startups is a UK government program under the National Cyber Security Centre (GCHQ) that supports cyber security innovation and startups. It provides free cyber security guidance, certifications (Cyber Essentials, CAF), Active Cyber Defence services (Early Warning, phishing takedown, vulnerability disclosure), and NCSC-engineered hardware to UK organisations and citizens. The program helps early-stage companies develop secure products while giving them access to NCSC expertise and the cyber entrepreneur community.
Product overview
The NCSC (National Cyber Security Centre) offers a comprehensive portfolio of cyber security products, services, and guidance for organizations of all sizes in the UK. The core offerings include Cyber Essentials (a certification scheme against common threats), the Cyber Assessment Framework (CAF) for systematic security assessment, Active Cyber Defence Services including Early Warning and Check Your Email Security, and the Vulnerability Disclosure Toolkit. The NCSC also provides specialized hardware like SilentGlass, and supports the cyber security ecosystem through programs like NCSC for StartUps and CyberFirst for education. Additional guidance covers vulnerability management, secure system administration, logging and monitoring, and preventing lateral movement.
Differentiator
Problem solved
Functional benefit
Brands
- CyberFirst: Educational programmes, competitions, and bursaries for young people interested in cybersecurity careers
- Cyber Essentials
- Active Cyber Defence
- CYBERUK
- CyberSprinters
- CyberFirst Navigators
Products and services
- Cyber Essentials A government-backed certification scheme protecting organisations against the most common cyber threats by focusing on five essential security controls: secure configuration, boundary firewalls, access control, malware protection, and patch management. Delivered through partner IASME for UK organisations seeking recognised cyber security certification.
- Cyber Assessment Framework (CAF) A collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions. It provides a systematic approach to assessing cyber security posture and is used by critical national infrastructure operators and public sector bodies.
- Early Warning A free service from the NCSC's Active Cyber Defence programme that provides notifications of potential cyber threats on UK organisations' networks by monitoring malicious activity tied to their IP addresses.
- Vulnerability Disclosure Toolkit A toolkit containing essential components to help organisations set up their own vulnerability disclosure process, enabling finders and system owners to work together to report and triage vulnerabilities safely.
- Active Cyber Defence Services A suite of free services including Early Warning, Check Your Email Security (CYES), and website protections designed to help UK organisations automatically defend against common cyber threats.
- Check Your Email Security (CYES) A free online tool that helps organisations check their email security configuration and protects customers by preventing cyber criminals from using their email domain to conduct attacks.
- SilentGlass A world-first NCSC-engineered plug-and-play hardware device that actively blocks any unexpected or malicious HDMI and Display Port connections, securing vulnerable display links.
- Phishing Reporting Services Services enabling UK citizens and organisations to report suspicious emails, texts, websites, and phone calls. As of May 2026, the NCSC has received over 55.7 million reported scams resulting in 250,000 scams removed across 443,000 URLs.
- NCSC for Startups An NCSC programme supporting cyber security innovation and startups, providing access to NCSC guidance, industry expertise, and a community of cyber entrepreneurs to help early-stage companies develop secure products and services.
- Vulnerability Management Collection Comprehensive guidance covering vulnerability management processes, including policies for updating by default, responding to active exploitation, asset identification, triage and prioritisation, and verification processes.
- Logging and Monitoring Part of the 10 Steps to Cyber Security guidance, covering how organisations can collect logs, design systems to detect incidents, and implement security monitoring for active threat detection.
- Secure System Administration Design principles for IT and OT systems to help organisations develop and implement secure system management strategies, protecting high-value systems from unauthorised access.
- Preventing Lateral Movement Guidance for system owners on preventing and detecting lateral movement within enterprise networks, including credential protection, authentication practices, privilege management, and network monitoring.
Quantifiable outcome
- 55.7 million reported scams processed, 250,000 scams removed, 443,000 URLs taken down
Companies that use NCSC For Startups
Customer profileNamed customers3 records
Segments6 records
Ideal customer profiles7 records
NCSC For Startups technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
NCSC For Startups partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered core.
- US Cybersecurity and Infrastructure Security Agency (CISA)coreJoint advisory publication sharing top vulnerabilities routinely exploited by cyber attackers. Part of international Five Eyes intelligence sharing alliance.
- US Federal Bureau of Investigation (FBI)coreJoint cyber security advisories and coordinated vulnerability disclosure for international threats.
- US National Security Agency (NSA)coreJoint technical advisories on vulnerabilities and threat intelligence sharing.
- Australian Signals Directorate's Australian Cyber Security Centre (ACSC)coreFive Eyes alliance partner providing joint cyber security advisories and threat intelligence.
- Canadian Centre for Cyber Security (CCCS)coreJoint vulnerability advisories and coordinated incident response guidance.
- New Zealand National Cyber Security Centre (NCSC-NZ)coreFive Eyes partner for international cyber security cooperation and shared advisories.
- Computer Emergency Response Team New Zealand (CERT NZ)coreJoint cyber security guidance and vulnerability disclosure coordination.
- GCHQcoreNCSC is a part of GCHQ, the UK's signals intelligence and cyber security agency.
- HackerOnecoreThird-party vulnerability disclosure platform enabling security researchers to report vulnerabilities in UK government online services. Reports triaged by NCSC and forwarded to affected government departments.
- IASMEcoreIASME is the NCSC's delivery partner for the Cyber Essentials certification scheme, certifying organisations' cyber security practices.
Scale indicators4 records
Recent moves5 records
Expansion highlights5 records
NCSC For Startups competitors and assessment
Company assessmentDirect peers
- Cybersecurity and Infrastructure Security Agency (CISA): US national cyber and infrastructure security agency. Direct counterpart to NCSC: both are civilian-facing national authorities providing public guidance, vulnerability coordination, threat advisories, and incident response support, and both publish joint Five Eyes advisories.
- Australian Cyber Security Centre (ACSC): Australian Signals Directorate's civilian cyber arm. Five Eyes partner that mirrors NCSC's role in providing threat advisories, vulnerability disclosure coordination, and cybersecurity guidance to Australian organisations and individuals.
- Canadian Centre for Cyber Security (CCCS): Canada's unified national cyber authority under the Communications Security Establishment. Direct NCSC counterpart providing authoritative cyber guidance, threat intelligence, and incident response coordination for Canadian organisations.
- CERT NZ: New Zealand's Computer Emergency Response Team, partnered with NCSC-NZ. Comparable incident-reporting portal model to NCSC's report.ncsc.gov.uk and similar triage/disclosure workflow.
- NCSC-NZ (New Zealand National Cyber Security Centre): New Zealand's national cyber security centre within the GCSB. Five Eyes peer publishing joint advisories with NCSC and operating a near-identical mandate for civilian cyber defence, guidance, and incident response.
- ANSSI (Agence nationale de la sécurité des systèmes d'information): France's national cybersecurity agency. Comparable role providing national-level cyber guidance, certification frameworks (similar in spirit to Cyber Essentials), threat intelligence, and incident response to French public and private sector.
- BSI (Bundesamt für Sicherheit in der Informationstechnik): Germany's federal cybersecurity authority. Peer agency issuing national cyber guidance, baseline IT protection standards (analogous to Cyber Essentials), and operating a CERT-Bund for incident response.
Broad incumbents
- SANS Institute: Largest private-sector cybersecurity training and certification provider. Closest commercial analogue to NCSC's training stack (CyberFirst/Professional Skills Training), but as a global commercial incumbent rather than a national authority.
Others
- HackerOne: Vulnerability disclosure and bug bounty platform that NCSC integrates with (via the Vulnerability Disclosure Platform). They are an existing technology/integration partner rather than a competitor, but their commercial model around coordinated disclosure is closely adjacent to NCSC's offering.
- IASME: UK-based NCSC delivery partner operating the Cyber Essentials certification scheme on NCSC's behalf. Comparable only insofar as it is the commercial delivery vehicle for one of NCSC's flagship programmes.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
NCSC For Startups social profiles
Digital presenceNCSC For Startups financial estimates
Financial estimateRevenue estimate
Valuation estimate
NCSC For Startups leadership team
Management profileNumber of profiles
Profiles2 records
NCSC For Startups funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
NCSC For Startups M&A and investment
M&A and investmentM&A
Investments25 records
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about NCSC For Startups
What does NCSC For Startups do?
NCSC For Startups is a UK government program under the National Cyber Security Centre (GCHQ) that supports cyber security innovation and startups. It provides free cyber security guidance, certifications (Cyber Essentials, CAF), Active Cyber Defence services (Early Warning, phishing takedown, vulnerability disclosure), and NCSC-engineered hardware to UK organisations and citizens. The program helps early-stage companies develop secure products while giving them access to NCSC expertise and the cyber entrepreneur community.
Is NCSC For Startups a public or private company?
NCSC For Startups is a private company. It is classified as state government owned and is currently operating.
When was NCSC For Startups founded?
NCSC For Startups was founded in 2017. It employs 1 to 10 people.
Where is NCSC For Startups based?
NCSC For Startups is headquartered in London, United Kingdom, in the Europe region.
How does NCSC For Startups make money?
One revenue line is on record: government Funding.
Who are NCSC For Startups's main competitors?
Direct peers on record are Cybersecurity and Infrastructure Security Agency (CISA), Australian Cyber Security Centre (ACSC), Canadian Centre for Cyber Security (CCCS), CERT NZ, NCSC-NZ (New Zealand National Cyber Security Centre), ANSSI (Agence nationale de la sécurité des systèmes d'information) and BSI (Bundesamt für Sicherheit in der Informationstechnik). SANS Institute is listed as a broad incumbent. Others are HackerOne and IASME.
Does NCSC For Startups have an API?
No public API is recorded for NCSC For Startups.
What industry is NCSC For Startups in?
NCSC For Startups's product category is Government Cyber Security Services. Its primary akta.pro industry code is FSANAHAD, Corporate Accelerators & Startup Programs, with a secondary code of EDABAFAF, Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing). Its NAICS code is 611430 and its SIC code is 8200.