
REGULATION — NCSC CAF
The Cyber Assessment Framework is the NCSC's outcome-based standard for cyber resilience — used across NIS-regulated essential services and by government through GovAssure.
WHAT IT IS
The CAF asks you to evidence outcomes rather than tick a checklist. It sets four top-level objectives, and beneath them sit 14 principles — each with contributing outcomes and Indicators of Good Practice that describe what good actually looks like.
Every outcome is assessed as Achieved, Partially achieved or Not achieved, usually against a target profile set by the relevant regulator or oversight body. The framework is applied across NIS-regulated essential services and, for government, through GovAssure.
THE FOUR OBJECTIVES
| Objective | Focus |
|---|---|
| A — Managing security risk | Governance, risk management, asset and supply-chain understanding that underpins everything else. |
| B — Protecting against cyber attack | The proportionate measures that keep systems and data safe from compromise. |
| C — Detecting cyber security events | Monitoring and security event detection that surfaces problems while they can still be contained. |
| D — Minimising the impact of incidents | Response and recovery that limits harm and gets essential services back on their feet. |
WHERE FIRMS TRIP
HOW WE HELP
01
We rate each outcome the way an assessor would — Achieved, Partially, Not achieved — and record why, so the picture holds up to challenge.
02
The proof behind each outcome, mapped to the contributing outcomes and IGPs, closing the gap between the policy and what actually happens.
03
The "Not achieved" outcomes ordered by risk, so the board knows what gets fixed first and why — and can stand behind the plan.
The CAF rewards firms that can show their work.
Start a conversation