A CyPro-managed assurance service

CAF Assessment and Cyber Assurance for Government and Defence

CyPro fronts and manages your assessment against the NCSC Cyber Assessment Framework, while an accredited specialist partner performs the technical work. It is the managed route to CAF, GovAssure, MOD Secure by Design and CHECK-accredited IT Health Check assurance for UK government, defence and CNI suppliers, with indicative fixed-scope pricing published on the page while the rest of the field stays quote-only.

  • Partner-delivered, CyPro-managed
  • Indicative fixed-scope pricing, published
  • NCSC CAF, GovAssure and MOD Secure by Design
  • Government, defence and CNI suppliers
cyber security for CAF and government assurance

CyPro's clients include

az
bgi
british gas
cigna
deloitte
euroclear
jpm
kpmg
lme
m & g
ns & i
royal london
rsa
schroders
shell
ubs
virgin trains
william hill

What we assess against

Government and defence cyber assurance, managed end to end

Five routes into a single managed service, each with its scope defined and its indicative price printed before you enquire.

What is a CAF assessment?

A CAF assessment measures your organisation against the NCSC Cyber Assessment Framework: its four objectives and fourteen principles, at either the baseline or enhanced profile set for your sector. Government departments and their arm's length bodies reach it through GovAssure, the Cabinet Office programme built on the CAF, while MOD suppliers meet a related bar through MOD Secure by Design. We run the gap analysis against the profile that applies to you, then hand back a prioritised plan to close the distance, with the indicative cost published up front. The assessment is fronted and managed by CyPro and performed by an accredited delivery partner; see how the engagement runs.

Why this service

A managed assessment, priced in the open

clear published pricing for CAF and government assurance

Prices on the page, not behind a quote

Every ranking provider in this market is quote-only. We publish indicative fixed-scope from prices for CAF, GovAssure, MOD Secure by Design and ITHC engagements, so you can size the work before the first call.

physical and logical access control for CAF and government assurance

Partner-delivered, CyPro-managed

CyPro fronts and manages the engagement end to end; an accredited specialist partner performs the assessment. You get a single managed relationship, with the technical work done by testers who hold the accreditations the framework requires.

expert incident response for CAF and government assurance

Built for government and defence buyers

This is a specialist service for UK government departments and arm's length bodies, MOD suppliers and delivery teams, and CNI operators. The framework you must meet decides the scope, not a generic checklist.

securing the supply chain for CAF and government assurance

Mapped to your framework obligation

We assess against the exact bar that applies to you: the baseline or enhanced CAF profile for your sector, the GovAssure stage you are at, or the Secure by Design tier for your project. The output is evidence your assessor can use.

a cyber strategy roadmap for CAF and government assurance

A prioritised plan, not just a score

The assessment does not stop at a maturity rating. You receive a ranked plan to close the gap against the profile, written for the people who will do the work, so the finding leads straight to the fix.

managing insider risk for CAF and government assurance

CyPro's bench behind the service

The consultants managing your engagement sit beside CyPro's CREST penetration testers and incident responders, so when the assessment surfaces work that needs deeper security expertise, the escalation path is already in place.

Your experts hold

  • CIPM
  • CIPP E
  • CISA
  • CISM
  • CISSP
  • CRISC
  • ISO 27001
  • Prince2

How we work

A straight account of what you are buying

No named-client wall and no borrowed logos on the assessment itself. Here is the model, the frameworks we assess against and the pricing that sets this service apart.

expert incident response for CAF and government assurance

CyPro fronts it, an accredited partner assesses it

We are open about how this works. CyPro manages the engagement, the scoping, the reporting and the relationship; an accredited specialist partner carries out the technical assessment. We do not claim in-house CAF, GovAssure or ITHC delivery, and we never claim an accreditation we do not hold.

expert incident response for CAF and government assurance

The frameworks we assess against

The NCSC Cyber Assessment Framework, GovAssure for central government, MOD Secure by Design for defence suppliers, and IT Health Checks delivered by CHECK and CREST accredited testers. Each name describes the scheme we assess you against, not a CyPro mark.

cross border assurance for CAF and government assurance

Fixed-scope pricing, published up front

The entire ranking field runs a quote-only model. We publish indicative from prices instead: CAF assessment from GBP 6,500, GovAssure from GBP 9,500, MOD Secure by Design from GBP 8,500 and ITHC from GBP 4,500, all fixed-scope and partner-delivered.

controlled access for suppliers for CAF and government assurance

Before you ask us

Frequently asked questions

What is a CAF assessment?

A CAF assessment measures your organisation against the NCSC Cyber Assessment Framework: its four objectives and fourteen principles, at either the baseline or enhanced profile set for your sector. It is used across government and critical national infrastructure to show whether your cyber security is proportionate to the risk you carry.

We run the gap analysis against the profile that applies to you, then hand back a prioritised plan to close the distance. The assessment is fronted and managed by CyPro and performed by an accredited delivery partner.

The Cyber Assessment Framework, explained

What is GovAssure?

GovAssure is the Cabinet Office assurance scheme for central government departments and their arm's length bodies. It uses the NCSC Cyber Assessment Framework as its technical standard and runs across five stages, from scoping and a self-assessment to an independent assurance review.

We support you through readiness and the independent assurance stages, with indicative pricing published rather than held behind a quote.

GovAssure support through all five stages

What is MOD Secure by Design?

MOD Secure by Design is the Ministry of Defence approach that requires cyber security to be built into defence projects from the outset, evidenced through a security case and a set of Secure by Design activities across the project lifecycle. It applies to MOD suppliers and delivery teams.

This is the defence programme. It is distinct from the police Secured by Design scheme for physical security, which is spelled differently and covers a different market. We do not blend the two.

Secure by Design assurance for defence suppliers

What is an IT Health Check (ITHC)?

An IT Health Check is an assessment of internet-facing and internal systems required for connections such as the Public Services Network and the pension dashboards programme. Buyers require it to be performed by testers holding NCSC CHECK or CREST accreditation.

Our delivery partner's CHECK-accredited testers carry out the ITHC, with CyPro managing the scoping, evidence and reporting around it.

IT Health Check (ITHC) for public-sector assurance

Rocket above the CAF Assessment call to action

Talk to us about your framework obligation

Find out what a CAF or GovAssure assessment involves for you

The scoping call is free, lasts 45 minutes and is taken by a consultant, not a salesperson. It covers which framework applies to you, the profile or stage you need to meet, and the indicative fixed-scope cost of a managed, partner-delivered assessment.