Article - NPSA, AACS, CAPSS
August 25, 2026

AACS and CAPSS: what's the difference, and where does NPSA fit in?

They are not the same thing and they do not do the same job.

 

Kris Simons

Kris Simons

Sales Director, ATEC

“NPSA sets the standards. AACS and CAPSS sit beneath it as two separate schemes, and they answer two different questions about the same equipment.”

In this article

Share on:

An overview of NPSA / CAPSS / AACS

NPSA-1

Infrastructure, government sites or other high-value premises will have come across AACS (Automatic Access Control Systems) and CAPSS (Cyber Assurance of Physical Security Systems). The two are often mentioned in the same breath, sometimes almost interchangeably, but they are not the same thing and they do not do the same job.

Both sit beneath the National Protective Security Authority (NPSA), the UK body that sets and evaluates the standards. This article explains:

  • What NPSA is and how AACS and CAPSS fit beneath it
  • What each scheme actually assesses, and the practical difference between them
  • How to work out whether your site needs one, both, or neither
  • How this affects ATEC

NPSA: The umbrella authority

NPSA is the UK’s national technical authority for physical and personnel security. It operates as part of the Security Service, MI5. NPSA was formerly known as the Centre for the Protection of National Infrastructure (CPNI); the organisation and its role are unchanged, only the name has changed.

NPSA produces guidance and runs assurance schemes across a range of protective security topics. Products that meet its standards are listed in the Catalogue of Security Equipment (CSE), a public reference used in procurement and specification. AACS and CAPSS are two of the schemes NPSA runs. Neither sits inside the other. They are separate evaluations, run in parallel, beneath the same authority.

NPSA-2

AACS

AACS assesses whether an access control system performs its core function: reliably identifying authorised users and reliably excluding everyone else.

AACS evaluation covers the physical security performance of the system. That includes how credentials, readers and controllers work together, and how the system withstands attempts at physical tampering or defeat. Products that pass are graded and listed in the CSE

AACS asks whether an access control system can be trusted to control access properly.

CAPSS

Modern physical security systems, including access control and CCTV, run on IT infrastructure. They process data, connect to networks, and in many cases hold some connection to the internet. That makes them a cyber-attack surface as well as a physical one.

CAPSS assesses secure communications, authentication, software integrity, system hardening and resilience against cyber-attack. It was jointly written by NPSA and the National Cyber Security Centre (NCSC). NPSA leads on physical security, NCSC leads on cyber, and CAPSS was developed at the intersection of the two.

CAPSS asks whether a physical security system can withstand a cyber-attack.

The difference, and how the two relate

NPSA-3

AACS and CAPSS assess different layers of the same system. AACS covers whether the system performs its physical security function. CAPSS covers whether that same system can resist a cyber-attack. A system can be strong on one and weak on the other. That is why NPSA runs both as separate schemes rather than one combined standard.

Passing one does not mean a system has passed the other. Each must be checked independently, even where both apply to equipment from the same manufacturer.

Which sites need AACS, CAPSS, or both?

Organisations operating critical national infrastructure, government sites, or other high-consequence environments are increasingly expected to specify NPSA-assured products, and in many cases both AACS and CAPSS assurance together. For sites outside these categories, NPSA’s guidance still provides a useful framework for assessing an existing installation, without requiring formal certification.

Establishing which category a site falls into is a specification decision with real cost and complexity attached. Specifying an NPSA-assured system where the risk profile does not require one is as much a misstep as under-specifying a genuinely high-risk site.

 

NPSA-4

How does NPSA apply to ATEC?

NPSA- Gallagher

We partner with Gallagher Security who’s Command Centre platform and high security controller range have been evaluated under both AACS and CAPSS. Assurance of this kind attaches to specific evaluated configurations, not to a manufacturer or product line as a whole. It refers to particular software versions, controllers and supporting hardware. Specifying “a Gallagher system” and specifying an assured configuration is not the same thing.

That distinction sets the division of responsibility. Assurance sits with the manufacturer, against specific evaluated configurations. The installer establishes what a site requires and deploys a configuration that meets it, working within the boundaries of what has been assured, and alongside whatever other regimes apply to the site. ATEC installs Gallagher systems on this basis, it does not hold NPSA assurance itself. Learn more about Gallagher Security.

Final thoughts

NPSA sets the standards. AACS and CAPSS sit beneath it as two separate schemes, and they answer two different questions about the same equipment. AACS looks at whether an access control system does its job physically, identifying the right people, keeping everyone else out, and holding up against tampering. CAPSS looks at whether that same system survives an attack across the network. Results do not carry across. A product listed under one scheme still has to be checked against the other if both apply to your site.

For most organisations the work starts well before certification, with an honest read of the risk at each site. Critical national infrastructure and government estates will usually have the requirement written into the specification already. Everywhere else, NPSA guidance is still a useful benchmark for reviewing an existing access control or CCTV installation, with no formal assurance needed to make use of it.

What is CAPSS and why does it matter to your organisation?

Why physical security systems should now be considered an IT risk and what CAPSS actually covers, including the seven risk areas it assesses.

Read about CCTV

Multi-sensor cameras, sometimes called multi-lens or multi-head cameras, combine two, three, or four independent image sensors and lenses...
Part 1: What you can sensibly do yourself? DIY or not, the hybrid split, buying cameras, cable specifications and compliance considerations...

Share on: