RaptorGRC — Offline GRC

BLOG

The UK Cyber Security Council What Chartership Actually Involves

Published 2 August 2026 · By P Larner

Frameworks & Standards#CIISec#professional registration#CPD#ChCSP#chartership#UK Cyber Security Council

The UK Cyber Security Council: What Chartership Actually Involves

Illustration for: The UK Cyber Security Council, What Chartership Actually Involves

Illustration for: The UK Cyber Security Council, What Chartership Actually Involves

Ask a structural engineer to prove they are competent and they show you a title that took years to earn and can be taken away. Ask a cyber security professional and you get a wallet of certifications, most of them multiple choice exams sat once, several expiring only if you forget to pay. That gap is why the Council exists.

I hold Chartered Cyber Security Professional status in the Cyber Security Governance and Risk Management specialism, awarded through CIISec. This post is what the Council is, what the titles mean, which specialisms are genuinely open, what the assessment actually asks of you, what it costs in money and effort, and an honest view of whether it is worth your time.

What the Council actually is

The UK Cyber Security Council is the professional body for the UK’s cyber security sector, established by Royal Charter. It describes its job in three words, which are connect, champion and charter. The part that matters here is the third one.

The Council sets a unified framework of professional and ethical standards, awards titles against them, and holds the UK’s Cyber Security Professional Register. It is impartial and operationally independent, which means it is not selling you training or an exam, and not marking its own homework. That is what separates a professional body from a certification vendor.

Two documents carry that weight. The Standard for Professional Competence and Commitment describes what a professional at each level must do and evidence. The code of ethics is what you agree to be held to, and unlike a certification, a title can be withdrawn.

The four titles

The Council awards four titles, and they differ in expertise, scope and depth of professional development rather than in subject matter.

Title

Post-nominal

Broadly who it is for

Associate Cyber Security Professional

ACSP

Early career, and the only title that is not tied to a specialism

Practitioner Cyber Security Professional

PraCSP

Established practitioners working competently in a specialism

Principal Cyber Security Professional

PriCSP

Senior specialists leading complex work in their field

Chartered Cyber Security Professional

ChCSP

Professional mastery, with influence beyond your own organisation

Diagram of the four professional titles as ascending bars with their post-nominals

Diagram of the four professional titles as ascending bars with their post-nominals

Four titles against one standard, with the post-nominal letters awarded alongside each. Everything above Associate is awarded within a named specialism.

Chartership is not the top of a ladder you climb by staying employed. The higher titles want evidence that you shape practice rather than follow it, exercise judgement where the answer is genuinely uncertain, and develop other people. Time served is not the criterion, and I have watched very experienced people assume that it is.

The practical consequence is that choosing a title is a judgement about the altitude of your work rather than your years in post. If your day is spent operating controls competently, Practitioner describes you honestly. If you are the person the organisation turns to when the answer is not in a framework, aim higher. Applying at the wrong level wastes everybody’s time, and the assessors will say so.

The Standard, and the word most people skip

Almost everyone reads the first half of the Standard’s name and ignores the second. It is the Standard for Professional Competence and Commitment, and the commitment half carries real assessment weight.

Competence is the part practitioners expect. You show underpinning knowledge and understanding, evidenced either through qualifications, meaning certifications, academic learning or work-based courses, or through work-based learning, meaning the knowledge and skills you actually developed on the job. Both routes are legitimate, which matters for the large population of capable people in this field who came in sideways and never collected the letters.

Commitment is where applications quietly fail. It covers continuing development, ethical conduct, and contribution to the profession beyond your own employer. If your last five years contain no mentoring, no writing, no community involvement and no formal development, that is a gap, and it is not one you can fill in the fortnight before you apply.

The Council also points applicants at the STAR structure, meaning situation, task, action and result. Use it even where the form does not demand it, because action and result are the two parts most people skip and the two the assessors are actually reading for.

The eight specialisms, six of which are open

Every title above Associate is awarded in a specialism. The Standard has been contextualised for eight, but only six are open for application today.

  • Cyber Security Governance and Risk Management, monitoring compliance with agreed policy and assessing and managing the resulting risks.
  • Cyber Security Audit and Assurance, verifying that systems and processes meet the security requirements set for them and stay compliant.
  • Secure System Architecture and Design, designing systems to meet security requirements while balancing the functional ones.
  • Security Testing, testing networks, systems and products against their requirements, which most people still call penetration testing.
  • Incident Response, preparing for, handling and following up incidents to limit damage and prevent recurrence.
  • Secure Operations, managing an organisation’s information systems operations in line with agreed security requirements.

Two more, Secure Systems Development and Cyber Security Management, are contextualised but still in pilot and not open to general application. If your discipline is one of those, or is not listed at all, the honest answer today is to register your interest and wait.

Choosing between specialisms is harder than the list suggests, because real careers straddle them. My own work touches architecture, audit and governance in most months. The test that settled it was to ask which specialism describes the decisions I am accountable for rather than the activities I perform. I perform audit work. I am accountable for risk decisions. That pointed at one specialism and made the evidence far easier to write.

Readers of this series will not be surprised where I landed. The governance and risk contextualisation document repays reading even if you never apply, being a decent external description of what competent risk work looks like.

Which Licensed Body, and why the choice matters

You do not apply to the Council directly. Applications go through Licensed Bodies, established professional organisations approved to assess against the Standard and recommend whether a title should be awarded. There are three, and they do not cover the same ground.

Licensed Body

Specialisms covered

Titles offered

CIISec

Governance and Risk Management, Secure Systems Architecture and Design, Audit and Assurance

Associate, Principal, Chartered

The Cyber Scheme

Security Testing, Incident Response, Secure Operations

All four

CREST

Security Testing, Incident Response

All four

Diagram mapping the three licensed bodies to the specialisms and titles they cover

Diagram mapping the three licensed bodies to the specialisms and titles they cover

The route depends on both axes. Two bodies overlap on security testing and incident response, and only one covers the governance and risk route.

Two things fall out of that table, and neither is obvious at first glance. Coverage differs by title as well as by specialism, so a Practitioner application in governance and risk has no route today. And security testing and incident response can be approached through either of two bodies, which means you can choose on process, cost and community rather than by default.

I went through CIISec, the Chartered Institute of Information Security, and everything below describes their process.

How the assessment actually runs

The process has four stages, and the effort is very unevenly distributed across them.

The application form

You map your career against the Standard. This is the stage people underestimate, because the form is not a CV. It asks you to evidence competence and commitment against specific criteria, in your own words, with examples that are yours rather than your team’s.

Budget days rather than an evening. My own first pass took a weekend and was not good enough, mostly because I wrote it as a narrative of programmes I had worked on rather than as evidence against criteria. The second pass took the criteria one at a time and asked what I personally had done that demonstrated each one.

Documentary review

An assessor tests whether the evidence actually supports the claims. Thin examples get found here. “Led risk management for a major programme” carries nothing without what you decided, why, and what happened. Assessors read a great many applications and know when a sentence is doing work and when it is doing decoration.

Professional discussion

An interview, in my case with two Council approved assessors who knew the specialism. This is the most useful part of the process, and the questions go where your written evidence is weakest. Not adversarial, but not a formality either.

Expect to be asked why you did something rather than what you did, and expect a follow-up whenever the first answer stays general. The most uncomfortable question I was asked concerned a decision that had not worked out, which in retrospect was the fairest question in the session.

Final assessment panel

The interview recommendation is moderated by a final panel, which decides. There is an appeals route, and reasonable adjustments are available, both documented rather than buried.

Diagram of the four stage assessment process from application to panel decision

Diagram of the four stage assessment process from application to panel decision

Four stages, run by a Licensed Body rather than by the Council itself. The professional discussion is where thin evidence is found.

What good evidence actually looks like

This is the part I would most like to have read before applying, so here it is with worked examples. The pattern of a weak entry is always the same, which is a claim about a team, in the passive voice, with no decision and no outcome.

Weak evidence

Why it fails

Stronger version

“We implemented ISO 27001 across the organisation.”

No individual contribution, no judgement, no result.

“I argued for scoping certification to the two customer-facing services rather than the whole estate, because the wider scope would have taken eighteen months and delivered no additional customer assurance. The board accepted it and we certified in seven months.”

“Responsible for the risk register.”

Describes a job title, not competence.

“I rebuilt a 140 row register into 18 owned risks, retiring entries nobody had touched in a year. I chose to archive rather than delete, so the reasoning stayed available at audit.”

“Attended various industry conferences.”

Attendance is not contribution.

“I presented our approach to supplier assurance at two sector events and wrote it up afterwards, which prompted a peer organisation to adopt the tiering model.”

“Ensured compliance with GDPR.”

Unfalsifiable and impersonal.

“I challenged a proposed analytics deployment on lawful basis grounds, ran the balancing assessment myself, and recommended a narrower configuration that the data protection officer accepted.”

The right hand column is longer, and that is the point. Chartership evidence is not a summary of your career, it is a small number of decisions described in enough detail that a competent stranger can judge them.

Keeping it once you have it

This is what separates a title from a certificate, and the question I am asked least. Registration is not permanent. Once registered through CIISec you must provide evidence of your continuing professional development every year, and CPD is something you plan, record and report yourself rather than something an employer does to you.

That annual obligation is the whole argument for the model. A certificate earned in 2019 says what you knew in 2019. A title requiring yearly evidence says somebody is still checking. If you do the reading anyway, this costs an hour of record keeping. If you do not, the title lapses, which is precisely the point of having one.

The practical advice is unglamorous. Keep a running note through the year rather than reconstructing it in December, and record the things that actually developed you rather than the things that were easy to log. An hour spent properly reading a regulator’s enforcement notice is worth more than a webinar you had on in the background, and only one of those is honest to claim.

What it was actually like

Four things surprised me, and they are the parts worth passing on.

Say what you did, not what the team did. This is the most useful thing I can hand anyone approaching an application. My first draft was written in the natural voice of somebody who has spent a career in teams, so sentence after sentence began with we. That is the wrong pronoun. The assessors are examining you, not your employer, and what the programme delivered says nothing about your own competence. Rewriting it as what I decided, what I recommended and what I was overruled on felt faintly immodest, and it mattered more than anything else I changed. The Council’s own guidance puts it in four words, think “I” instead of “We”, and that is an instruction rather than a style note.

The evidence burden is about judgement, not activity. Listing frameworks you have implemented gets you nowhere. What the assessors want is a decision you made under uncertainty, the reasoning, and what you would do differently. Every practitioner has these. Very few have written them down.

Commitment is assessed as seriously as competence. Continuing development, ethical conduct and contribution to the profession are half the Standard, not decoration around the technical evidence.

And it changed how I describe my own work. Explaining a risk decision to a competent stranger with no stake in your organisation is a rare exercise, and it exposes the difference between a decision you can justify and one you merely made. I would recommend the process for that alone, which is not what I expected to conclude.

How this compares with older professions

The comparison the Council invites is with engineering, and it deserves examining honestly rather than borrowing uncritically.

Engineering has had chartered status for well over a century, and the title is understood by clients, insurers and courts. That understanding was not designed, it accumulated across decades in which the title became the normal expectation for senior practice. Cyber security is at the very start of that process.

The mechanism, though, is the same one, and the mechanism is what matters. An independent body sets a standard, assesses individuals against it, publishes a register, and can remove people from it. Everything else is time and adoption. Whether cyber security gets there depends less on the Council’s design than on whether enough competent practitioners decide the title is worth holding.

The honest counterarguments

The market has not caught up

Almost nobody advertises for a ChCSP, and plenty of hiring managers have not heard of it. A register also carries weight in proportion to how many competent people are on it, and the Council’s is still small against the UK sector. If your reason for applying is the next job advert, the return is thin today, and early adopters carry that cost. I would rather say so plainly than sell you a title.

It is not cheap in time or money

Assembling evidence properly is days of work. Through CIISec at the time of writing, Practitioner costs £500 plus VAT and Principal and Chartered cost £700 plus VAT, on top of the membership behind them. For someone early in their career, a specific technical qualification may do more for the next eighteen months, and I would say so to anyone who asked.

Coverage is incomplete

Six live specialisms do not describe the whole profession. If you work in identity, in data protection engineering, in operational technology security or in threat intelligence, there is no route contextualised for you today. The Council’s answer is that more are coming, which is true and is also cold comfort if you are ready now.

Certifications are not worthless

The two do different jobs. A certification proves you knew a defined body of knowledge on a given day. A title says an independent panel judged your practice, your ethics and your development against a public standard. The industry needs both, and pretending otherwise is how professional bodies annoy people.

Assessment is a human process

Two assessors and a moderating panel are more robust than a multiple choice exam, and they are still people making judgements about evidence. Consistency across bodies and specialisms is the thing a young register has to earn, and it is reasonable to watch for it rather than assume it.

Who should bother, and how to prepare

The case is strong if your work involves judgement rather than execution, if you already do the development and contribution but have never documented it, or if you sell into government and regulated sectors where evidence of competence wins work. Early in your career, look at Associate or Practitioner instead.

If you decide to go, six months of light preparation beats a heroic fortnight.

  1. Read the Standard and the contextualisation document for your specialism, and mark every criterion where you currently have nothing.
  2. Start a decisions log now. Two paragraphs each time you make a call you had to think about, written the same week, with the reasoning and the outcome.
  3. Fill the commitment gaps deliberately, whether that means mentoring somebody, writing something public, or joining a working group.
  4. Pick the specialism that matches what you are accountable for, then check which Licensed Bodies cover it at the title you want.
  5. Write the application in the first person, then reread it and delete every sentence describing what the team achieved.

The engineer at the start of this post did not get their title because the market demanded it. They got it because their profession decided that competence should be provable to somebody outside the organisation paying for the work. Cyber security is attempting the same thing, later and with more scepticism, and it will only succeed if enough competent people go through it and say honestly what it was worth. This is my contribution to that.

Run your GRC programme in your own network.

RaptorGRC Community Edition is free — every module, offline licence activation, nothing phones home.

Register / Download Contact us
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.