A CyPro-managed assurance service

CAF Assessment for Government and Defence

CyPro runs your gap analysis against the NCSC Cyber Assessment Framework, defines the remediation plan and roadmap, and works alongside your team implementing the controls that close the gaps. It is the consultancy route to CAF, GovAssure, MOD Secure by Design and IT Health Check readiness for UK government, defence and CNI suppliers, with indicative fixed-scope pricing published on the page while the rest of the field stays quote-only.

  • Partner-delivered, CyPro-managed
  • Indicative fixed-scope pricing, published
  • NCSC CAF, GovAssure and MOD Secure by Design
  • Government, defence and CNI suppliers
defence supply chain under cyber attack, the risk a CAF assessment measures

CyPro's clients include

az
bgi
british gas
cigna
deloitte
euroclear
jpm
kpmg
lme
m & g
ns & i
royal london
rsa
schroders
shell
ubs
virgin trains
william hill

What we assess against

Government and defence cyber assurance, managed end to end

Five routes into a single managed service, each with its scope defined and its indicative price printed before you enquire.

What is a CAF assessment?

A CAF assessment measures your organisation against the NCSC Cyber Assessment Framework: its four objectives and fourteen principles, at either the baseline or enhanced profile set for your sector. Government departments and their arm's length bodies reach it through GovAssure, the Cabinet Office programme built on the CAF, while MOD suppliers meet a related bar through MOD Secure by Design. We run the gap analysis against the profile that applies to you, then hand back a prioritised plan to close the distance, with the indicative cost published up front. The work is delivered by CyPro, and any formal external assessment or audit stays outside it; see how the engagement runs.

Why this service

A managed assessment, priced in the open

clear published pricing for CAF and government assurance

Prices on the page, not behind a quote

Every ranking provider in this market is quote-only. We publish indicative fixed-scope from prices for CAF, GovAssure, MOD Secure by Design and ITHC engagements, so you can size the work before the first call.

physical and logical access control for CAF and government assurance

One team, gap analysis through to fixed

The consultants who run your gap analysis are the ones who write the remediation plan and help your team implement it. No handover between an assessment supplier and a remediation supplier, and no report that lands on your desk with nobody left to help you act on it.

expert incident response for CAF and government assurance

Built for government and defence buyers

This is a specialist service for UK government departments and arm's length bodies, MOD suppliers and delivery teams, and CNI operators. The framework you must meet decides the scope, not a generic checklist.

securing the supply chain for CAF and government assurance

Mapped to your framework obligation

We work to the exact bar that applies to you: the baseline or enhanced CAF profile for your sector, the GovAssure stage you are at, or the Secure by Design tier for your project. The output is evidence a formal assessor can use when the time comes.

a cyber strategy roadmap for CAF and government assurance

A prioritised plan, not just a score

The gap analysis does not stop at a maturity rating. You receive a ranked plan and a roadmap to close the gap against the profile, written for the people who will do the work, so the finding leads straight to the fix.

managing insider risk for CAF and government assurance

CyPro's bench behind the work

The consultants on your engagement sit beside CyPro's CREST penetration testers and incident responders, so when the gap analysis surfaces work that needs deeper security expertise, the escalation path is already in place.

Your experts hold

  • CIPM
  • CIPP E
  • CISA
  • CISM
  • CISSP
  • CRISC
  • ISO 27001
  • Prince2

How we work

A straight account of what you are buying

No named-client wall and no borrowed logos on the assessment itself. Here is the model, the frameworks we assess against and the pricing that sets this service apart.

expert incident response for CAF and government assurance

Consultancy, delivered by us

We are open about how this works. CyPro runs the internal gap analysis, defines the remediation plan and roadmap, and works alongside your team implementing the controls that close the gaps. What sits outside our scope is any formal external assessment or audit: your own auditor or the reviewer appointed under the scheme does that when you are ready, which is exactly how an ISO 27001 engagement runs.

expert incident response for CAF and government assurance

The frameworks we work to

The NCSC Cyber Assessment Framework, GovAssure for central government, MOD Secure by Design for defence suppliers, and the CHECK-scheme IT Health Check your connection owner requires. Each name describes the scheme we work to, not a CyPro mark.

cross border assurance for CAF and government assurance

Fixed-scope pricing, published up front

The entire ranking field runs a quote-only model. We publish indicative from prices instead: CAF assessment from GBP 9,600, GovAssure from GBP 13,500, MOD Secure by Design from GBP 8,500 and ITHC readiness from GBP 7,200, all fixed-scope.

controlled access for suppliers for CAF and government assurance

Before you ask us

Frequently asked questions

What is a CAF assessment?

A CAF assessment measures your organisation against the NCSC Cyber Assessment Framework: its four objectives and fourteen principles, at either the baseline or enhanced profile set for your sector. It is used across government and critical national infrastructure to show whether your cyber security is proportionate to the risk you carry.

We run the gap analysis against the profile that applies to you, hand back a prioritised plan and roadmap to close the distance, and support your team putting the controls in place. Any formal external assessment or audit sits outside that scope and is commissioned by you when you are ready.

The Cyber Assessment Framework, explained

What is GovAssure?

GovAssure is the Cabinet Office assurance scheme for central government departments and their arm's length bodies. It uses the NCSC Cyber Assessment Framework as its technical standard and runs across five stages, from scoping and a self-assessment to an independent assurance review.

We support you through readiness and the independent assurance stages, with indicative pricing published rather than held behind a quote.

GovAssure support through all five stages

What is MOD Secure by Design?

MOD Secure by Design is the Ministry of Defence approach that requires cyber security to be built into defence projects from the outset, evidenced through a security case and a set of Secure by Design activities across the project lifecycle. It applies to MOD suppliers and delivery teams.

This is the defence programme. It is distinct from the police Secured by Design scheme for physical security, which is spelled differently and covers a different market. We do not blend the two.

Secure by Design assurance for defence suppliers

What is an IT Health Check (ITHC)?

An IT Health Check is an assessment of internet-facing and internal systems required for connections such as the Public Services Network and the pension dashboards programme. Buyers require it to be performed by testers holding NCSC CHECK or CREST accreditation.

Because the formal test must come from accredited testers, it sits outside our scope. Our work is everything around it: assessing the environment internally first, closing what a CHECK test would raise, preparing the scope and evidence your connection owner expects, and helping your team act on the tester's findings.

IT Health Check (ITHC) for public-sector assurance

Rocket above the CAF Assessment call to action

Talk to us about your framework obligation

Find out what a CAF or GovAssure assessment involves for you

The scoping call is free, lasts 45 minutes and is taken by a consultant, not a salesperson. It covers which framework applies to you, the profile or stage you need to meet, and the indicative fixed-scope cost of the consultancy work to get you there.