Live National Cyber Helpline · 0300 123 2040
Assured Cyber Protection Cyber & insurance briefing

Compliance, Standards and Contracts

Cyber Security Qualifications UK: What Changes in 2026

By the Assured Cyber Protection team · Updated 2026 · Reviewed

Anyone comparing cyber security qualifications in the UK right now is looking at a moving target, because the two structures that used to anchor the answer are both being replaced. The NCSC’s Certified Cyber Professional scheme is shut to new applicants and its last certifications expire in December 2026. The government’s CyberFirst bursary is folding into a broader programme called TechFirst from September 2026. Advice written even eighteen months ago points at doors that are closing.

This page sets out what is actually current: the professional register that now sits at the top, the vendor certifications that get you interviews, the entry routes that do not require a degree, and, for anyone buying security rather than doing it, which letters after a consultant’s name genuinely mean something.

The top of the ladder has moved

For years the answer to “what is the recognised UK cyber security qualification” was the NCSC Certified Cyber Professional scheme, CCP. Government contracts and NCSC assured schemes required a CCP specialism, so it functioned as the national benchmark.

The NCSC has closed CCP to new applicants. Existing certifications and applications already in train stay recognised until the last of them expire in December 2026. Where an NCSC assured scheme previously required a CCP specialism, it now requires a UK Cyber Security Council title instead.

The replacement is the UK Cyber Security Council’s professional registration, which works the way chartered status works in engineering. There are four levels:

Title What it signals
Associate (ACSP) Building knowledge, skills and experience
Practitioner (PraCSP) Applying expertise independently
Principal (PriCSP) Leading teams, projects and specialist practice
Chartered (ChCSP) The full professional standard

Registration is tied to a specialism rather than granted in the abstract. The first chartership titles launched cover Governance and Risk Management, Secure Systems Architecture and Design, and Audit and Assurance, with Security Testing, Incident Response and Secure Operations following.

You do not apply to the Council directly. It licenses assessment bodies, and CREST, CIISec and The Cyber Scheme all act as licensed bodies that assess applications and recommend candidates. The process is an application form, an assessment, then an interview.

The practical implication for a career: if you are pitching for public sector work or work inside an NCSC assured scheme, this register is the one that will be named in the requirement from 2027 onwards. If you hold a CCP certification, plan your transition rather than waiting for it to lapse.

The certifications employers actually filter CVs on

The Council register is a professional standard, not a training course, and it expects experience you may not have yet. Below it sits the ordinary market, which is dominated by a small number of vendor and body certifications:

Entry level. CompTIA Security+ remains the most common first certification on UK job adverts, because it is broad, vendor-neutral and does not assume prior security experience. The NCSC-aligned foundation certifications from BCS and CIISec cover similar ground with a UK framing.

Practitioner and specialist. For offensive security and penetration testing, CREST certifications are the UK reference point and are recognised in the NCSC’s own assured schemes. For defensive and analyst work, the SANS and GIAC certifications carry weight but are expensive, and are usually employer-funded rather than self-funded.

Management. CISSP and CISM are the two that appear in senior job specifications. Both require documented years of relevant experience, so they are mid-career milestones rather than entry qualifications. CISSP in particular is often listed on roles where the actual requirement is “has been doing this for five years”, and the certification is the proxy.

A blunt point worth making: no certification substitutes for demonstrable hands-on work. Employers filling analyst roles consistently value a home lab, documented CTF work or a genuine incident write-up over a second certificate.

Entry routes that do not need a degree

The route into the industry has widened considerably, and the degree is now one option among several.

Apprenticeships. The Level 4 Cyber Security Technologist apprenticeship is the main structured entry point. It is open from age 16 with Level 2 English and maths, runs roughly 80% work and 20% study, is funded for most employers through the Growth and Skills Levy, and pays you while you train. It splits into three pathways: Cyber Security Engineer, Cyber Risk Analyst, and Cyber Defend and Respond. One eligibility catch to note: you generally cannot take it if you already hold a higher-level qualification in a related technical field, such as a computer science degree.

Degree apprenticeships take the same principle to Level 6, giving you a degree without tuition fees, and are competitive to secure.

TechFirst, replacing the CyberFirst bursary. CyberFirst has engaged more than 415,000 young people since 2016. From September 2026, existing CyberFirst bursary holders transition into scholarships under TechFirst, the government’s broader tech skills programme, which offers undergraduate scholarships of £4,000 a year alongside PhD stipend top-ups of up to £10,000 a year. It aims to reach a million secondary school pupils, over 5,000 students in higher study, and more than 2,000 local tech job placements. If you were researching the CyberFirst bursary, TechFirst is now the page to read.

Lateral moves. A large share of working security professionals came from IT support, networking or software development rather than a security-specific start. The transferable ground, how systems, networks and identity actually work, is the part that is hard to teach; the security layer on top is comparatively fast.

Is it worth it? What the demand figures say

The honest picture is more nuanced than the headline shortage stories.

DSIT’s Cyber security skills in the UK labour market report, published in February 2026, put the UK cyber workforce at about 143,000 people, growing around 5% in 2024 against 2% in 2022. But the estimated annual workforce shortfall fell sharply to 3,800 in 2024, down from 11,100 the year before. The raw hiring gap is narrowing.

What has not narrowed is the skills gap inside organisations that already employ people. DSIT found 49% of UK businesses have a basic cyber security skills gap, meaning the person responsible for security is not confident doing fundamental tasks such as configuring a firewall or removing malware, and 30% have an advanced skills gap.

Read those two findings together and the market signal is fairly clear. Entry-level roles are more competitive than the shortage headlines suggest, so a certificate alone will not carry you. Demonstrable competence in the fundamentals is scarcer than the numbers imply, and that is where the leverage sits.

If you are buying security rather than building a career

Most readers of this site are on the other side of the transaction, choosing a consultant, a managed provider or a tester. The qualifications question becomes: which letters mean something?

  • For penetration testing, CREST certification of the individual and the company is the reference standard, and it is what NCSC assured schemes point to. Ask which specific CREST certification the person doing the work holds, not just whether the firm is a member. Our page on penetration testing for UK businesses covers what to specify in the scope.
  • For governance, audit and architecture work, a UK Cyber Security Council title in the matching specialism is the strongest single signal available from 2026 onwards, precisely because it is specialism-tied.
  • For a CCP certification presented to you now, check the expiry. Everything in that scheme lapses by December 2026.
  • For general assurance about a supplier’s own hygiene, certification of the organisation matters more than certification of individuals. That is what Cyber Essentials is for, and it is also the certification most commonly asked for in contracts and by insurers.

Insurers increasingly ask about the qualifications and accreditations behind your security arrangements at renewal, and it feeds into what you are offered. If you are approaching a renewal, our guide to what small business cyber insurance costs in the UK sets out which controls and credentials move the price.

Frequently asked questions

What cyber security qualifications do I need to get a job in the UK? For a first role, CompTIA Security+ or a BCS or CIISec foundation certification is the common baseline, paired with demonstrable hands-on work such as a home lab or documented CTF results. Senior roles list CISSP or CISM, but both require several years of verified experience, so they are milestones rather than entry tickets.

Is the NCSC CCP scheme still running? No, it is closed to new applicants. Existing certifications and applications already underway remain recognised until the last of them expire in December 2026. NCSC assured schemes that required a CCP specialism now require a UK Cyber Security Council title and specialism instead.

How do I get professionally registered with the UK Cyber Security Council? Apply through one of the Council’s licensed assessment bodies, such as CREST, CIISec or The Cyber Scheme. You submit an application form, it is assessed, and successful candidates are interviewed. Registration is granted at Associate, Practitioner, Principal or Chartered level within a named specialism.

Can you get into cyber security without a degree? Yes. The Level 4 Cyber Security Technologist apprenticeship is open from age 16 with Level 2 English and maths, pays you while you train, and is funded for most employers. Lateral moves from IT support, networking or development are also a well-trodden route.

What happened to the CyberFirst bursary? It is being absorbed into TechFirst, the government’s wider tech skills programme. Existing CyberFirst bursary holders transition to TechFirst scholarships from September 2026, worth £4,000 a year for undergraduates.

Is there really a cyber security skills shortage in the UK? Less of a hiring shortage than the headlines suggest. DSIT put the annual workforce shortfall at 3,800 in 2024, down from 11,100 in 2023. The persistent problem is competence within existing teams: 49% of UK businesses have a basic cyber security skills gap.

The Threat Brief

A calm, plain-English security update. Once a week.

New scams, breach lessons, and cyber insurance changes that affect UK businesses, explained without the jargon. No alarmism, no vendor spin.

Unsubscribe anytime. We never share your address.