Following a pilot the CCP scheme is changing. The new scheme commences on Tuesday 4 May 2021. The existing scheme closed for new applications on 28 February 2021.

Please note: NCSC will honour the expiry date on certifications already awarded. No-one will be required to hold both a role and a specialism certification for the same cyber security activity. Revalidations (the submission of CPD evidence) at the 18 month point for existing CCP certifications will continue as normal until September 2022.

If you have any queries, please contact ccpsupport@bcs.uk.


How do the existing and new CCP schemes compare?

To support you with your decision on how to proceed with the new CCP we have compared the two schemes.

Existing scheme New scheme
Roles based Specialism based
Three levels:
  • Lead Practitioner
  • Senior Practitioner
  • Practitioner
Two levels:
  • Certified Cyber Professional
  • Associate Cyber Professional
  • No equivalent
6 skills based roles 1 specialism to launch first - Risk Management

Reflect your expertise at Associate Cyber Professional Level or Certified Cyber Professional Level in Risk Management by submitting your application. This application enables you to:

Take your place on the public CCP register and gain wider recognition for your competence and experience

Validate your cyber security credentials and your role in protecting your organisation’s assets

Take up a year’s free BCS membership when you become certified (offer available to non-members only)

Join a community of practitioners raising standards and building the reputation of the UK’s cyber profession

What is the National Cyber Security Centre?

National Cyber Security Centre logoA part of GCHQ, the NCSC is the UK’s technical authority for cyber incidents and threats, working collaboratively with other law enforcement, defence, the UK’s intelligence and security agencies and international partners to help make the UK the safest place to live and work online.

Which level should I apply for?

Identify the competence level that’s right for you depending on your level of responsibility and influence in the workplace.

Associate Cyber Professional


Apply for this level if you work independently on complex projects and normally lead a team of IA professionals - or you lead or oversee the work of other IA professionals.

Certified Cyber Professional


Are you a highly-experienced cyber professional working at a senior level in your organisation? Choose this level if you provide leadership and / or advice on complex, strategic IA issues.

What’s involved in the application process from 4 May 2021?

To apply for CCP, you will need to ensure you have one of the following foundational pre-requisites:

  • An NCSC accredited degree
  • CISSP
  • Full membership of CIISec

Please note that no exemptions can be granted for the above.

A case study will be required as part of each application (exemplars will be available for review). Applications will undergo a review with our assessors, and subject to a successful review, applicants will be requested to attend an interview.

The (online) interview will consider an applicant’s general consultancy skills and their technical abilities against the specialism. The duration of the interview is approximately 2 hours.

I’m ready to apply

The online application form will open from 4 May 2021.

When will my certification expire?

Your CCP certification is valid for three years subject to revalidation.

To revalidate you’re required to provide an up-to-date CV and CPD evidence demonstrating that you’re maintaining your skills in your certified specialism / level. If it’s deemed that you no longer meet the role headline statement for your specialism, as set out by the NCSC, your certification will be withdrawn.


Get in touch

We’re here to help with any queries you have about becoming a Certified Cyber Professional.

Call us on +44 1793 417 722 or email ccpsupport@bcs.uk

We take customer feedback very seriously and always act promptly to investigate any appeals:

BCS CCP appeals policy
BCS CCP complaints policy