A CyPro-managed assurance service
CAF Assessment for Government and Defence
CyPro runs your gap analysis against the NCSC Cyber Assessment Framework, defines the remediation plan and roadmap, and works alongside your team implementing the controls that close the gaps. It is the consultancy route to CAF, GovAssure, MOD Secure by Design and IT Health Check readiness for UK government, defence and CNI suppliers, with indicative fixed-scope pricing published on the page while the rest of the field stays quote-only.
- Partner-delivered, CyPro-managed
- Indicative fixed-scope pricing, published
- NCSC CAF, GovAssure and MOD Secure by Design
- Government, defence and CNI suppliers
CyPro's clients include
What we assess against
Government and defence cyber assurance, managed end to end
Five routes into a single managed service, each with its scope defined and its indicative price printed before you enquire.
The Cyber Assessment Framework, explained
A plain-English guide to the NCSC Cyber Assessment Framework: its four objectives, fourteen principles, the baseline and enhanced profiles, and who has to comply.
GovAssure support
Readiness and independent assurance through all five stages of GovAssure, the Cabinet Office programme that uses the CAF, for central government departments and their arm's length bodies.
MOD Secure by Design
Assurance for MOD suppliers and delivery teams, from Secure by Design activities to the security case and evidence. The defence programme, not the police Secured by Design scheme.
IT Health Check (ITHC)
Getting your environment ready to pass a CHECK-scheme ITHC for PSN, pension dashboards and other public-sector connections, then closing what the test raises.
Assessment pricing, published
Indicative fixed-scope from prices for every engagement, printed on the page while the rest of the field stays quote-only. See what the work costs before you enquire.
What is a CAF assessment?
A CAF assessment measures your organisation against the NCSC Cyber Assessment Framework: its four objectives and fourteen principles, at either the baseline or enhanced profile set for your sector. Government departments and their arm's length bodies reach it through GovAssure, the Cabinet Office programme built on the CAF, while MOD suppliers meet a related bar through MOD Secure by Design. We run the gap analysis against the profile that applies to you, then hand back a prioritised plan to close the distance, with the indicative cost published up front. The work is delivered by CyPro, and any formal external assessment or audit stays outside it; see how the engagement runs.
Why this service
A managed assessment, priced in the open
Prices on the page, not behind a quote
Every ranking provider in this market is quote-only. We publish indicative fixed-scope from prices for CAF, GovAssure, MOD Secure by Design and ITHC engagements, so you can size the work before the first call.
One team, gap analysis through to fixed
The consultants who run your gap analysis are the ones who write the remediation plan and help your team implement it. No handover between an assessment supplier and a remediation supplier, and no report that lands on your desk with nobody left to help you act on it.
Built for government and defence buyers
This is a specialist service for UK government departments and arm's length bodies, MOD suppliers and delivery teams, and CNI operators. The framework you must meet decides the scope, not a generic checklist.
Mapped to your framework obligation
We work to the exact bar that applies to you: the baseline or enhanced CAF profile for your sector, the GovAssure stage you are at, or the Secure by Design tier for your project. The output is evidence a formal assessor can use when the time comes.
A prioritised plan, not just a score
The gap analysis does not stop at a maturity rating. You receive a ranked plan and a roadmap to close the gap against the profile, written for the people who will do the work, so the finding leads straight to the fix.
CyPro's bench behind the work
The consultants on your engagement sit beside CyPro's CREST penetration testers and incident responders, so when the gap analysis surfaces work that needs deeper security expertise, the escalation path is already in place.
Your experts hold
How we work
A straight account of what you are buying
No named-client wall and no borrowed logos on the assessment itself. Here is the model, the frameworks we assess against and the pricing that sets this service apart.
Consultancy, delivered by us
We are open about how this works. CyPro runs the internal gap analysis, defines the remediation plan and roadmap, and works alongside your team implementing the controls that close the gaps. What sits outside our scope is any formal external assessment or audit: your own auditor or the reviewer appointed under the scheme does that when you are ready, which is exactly how an ISO 27001 engagement runs.
The frameworks we work to
The NCSC Cyber Assessment Framework, GovAssure for central government, MOD Secure by Design for defence suppliers, and the CHECK-scheme IT Health Check your connection owner requires. Each name describes the scheme we work to, not a CyPro mark.
Fixed-scope pricing, published up front
The entire ranking field runs a quote-only model. We publish indicative from prices instead: CAF assessment from GBP 9,600, GovAssure from GBP 13,500, MOD Secure by Design from GBP 8,500 and ITHC readiness from GBP 7,200, all fixed-scope.
Before you ask us
Frequently asked questions
What is a CAF assessment?
A CAF assessment measures your organisation against the NCSC Cyber Assessment Framework: its four objectives and fourteen principles, at either the baseline or enhanced profile set for your sector. It is used across government and critical national infrastructure to show whether your cyber security is proportionate to the risk you carry.
We run the gap analysis against the profile that applies to you, hand back a prioritised plan and roadmap to close the distance, and support your team putting the controls in place. Any formal external assessment or audit sits outside that scope and is commissioned by you when you are ready.
What is GovAssure?
GovAssure is the Cabinet Office assurance scheme for central government departments and their arm's length bodies. It uses the NCSC Cyber Assessment Framework as its technical standard and runs across five stages, from scoping and a self-assessment to an independent assurance review.
We support you through readiness and the independent assurance stages, with indicative pricing published rather than held behind a quote.
What is MOD Secure by Design?
MOD Secure by Design is the Ministry of Defence approach that requires cyber security to be built into defence projects from the outset, evidenced through a security case and a set of Secure by Design activities across the project lifecycle. It applies to MOD suppliers and delivery teams.
This is the defence programme. It is distinct from the police Secured by Design scheme for physical security, which is spelled differently and covers a different market. We do not blend the two.
What is an IT Health Check (ITHC)?
An IT Health Check is an assessment of internet-facing and internal systems required for connections such as the Public Services Network and the pension dashboards programme. Buyers require it to be performed by testers holding NCSC CHECK or CREST accreditation.
Because the formal test must come from accredited testers, it sits outside our scope. Our work is everything around it: assessing the environment internally first, closing what a CHECK test would raise, preparing the scope and evidence your connection owner expects, and helping your team act on the tester's findings.
Talk to us about your framework obligation
Find out what a CAF or GovAssure assessment involves for you
The scoping call is free, lasts 45 minutes and is taken by a consultant, not a salesperson. It covers which framework applies to you, the profile or stage you need to meet, and the indicative fixed-scope cost of the consultancy work to get you there.