The framework, explained

The NCSC Cyber Assessment Framework (CAF), Explained

The Cyber Assessment Framework is the NCSC's outcome-based way of measuring how well an organisation manages cyber security risk to its essential functions. This is a plain-English guide to its four objectives, 14 principles, profiles and who has to comply.

Outcomes, not a checklist

What the Cyber Assessment Framework is

The Cyber Assessment Framework is published by the National Cyber Security Centre, the UK's technical authority for cyber security. Unlike a tick-box standard, the CAF describes the outcomes a well-run organisation should be able to demonstrate, then asks you to show, with evidence, how far you achieve them. It is designed for organisations whose failure would have a serious impact on people, the economy or national security.

Because it is outcome-based, two organisations can meet the same principle in different ways. That flexibility is the point: the CAF judges whether risk is genuinely managed, not whether a specific product is installed.

Who has to comply

  • Operators of Essential Services (OES) under the NIS Regulations, overseen by their competent authority
  • Central government departments and arm's length bodies, through the GovAssure scheme
  • NHS organisations, through the Data Security and Protection Toolkit (DSPT), which aligns to the CAF
  • Critical national infrastructure operators and their suppliers, where a regulator adopts the CAF

The structure

Four objectives, fourteen principles

The CAF groups everything under four objectives, from managing risk through to recovering from an incident. The 14 principles sit beneath them, each carrying its own contributing outcomes.

Objective A

Managing security risk

Governance, risk management, asset management and supply chain. The foundations: knowing what you have, who is accountable, and how cyber risk is understood and owned across the organisation.

A1 Governance, A2 Risk management, A3 Asset management, A4 Supply chain

Objective B

Protecting against cyber attack

The protective controls: policies and processes, identity and access control, data security, system security, resilient networks and systems, and staff awareness and training.

B1 Service protection, B2 Identity and access, B3 Data security, B4 System security, B5 Resilient networks, B6 Staff awareness

Objective C

Detecting cyber security events

The ability to see what is happening: security monitoring across the systems that matter, and proactively discovering events that monitoring alone would miss.

C1 Security monitoring, C2 Proactive security event discovery

Objective D

Minimising the impact

What happens when something gets through: response and recovery planning that is tested, and a genuine lessons-learned loop so the same weakness is not exploited twice.

D1 Response and recovery planning, D2 Lessons learned

Quick answers

Cyber Assessment Framework questions, answered

What is the Cyber Assessment Framework (CAF)?

The Cyber Assessment Framework is a set of outcome-based cyber security principles published by the National Cyber Security Centre (NCSC). It is used to assess how well an organisation is managing cyber security risk to its essential functions. Rather than a checklist, it defines 14 principles grouped under four objectives, each with contributing outcomes and indicators of good practice against which an organisation is judged.

How many objectives and principles does the CAF have?

The CAF is built on four objectives: A Managing security risk, B Protecting against cyber attack, C Detecting cyber security events, and D Minimising the impact of cyber security incidents. Beneath those sit 14 principles, and beneath each principle a set of contributing outcomes and indicators of good practice.

What is a CAF profile: baseline or enhanced?

A CAF profile sets the target level an organisation needs to achieve for each outcome. A baseline profile is used for most systems; an enhanced profile applies where the impact of failure is highest, raising the bar for several outcomes. Under GovAssure, for example, each in-scope system is assigned a baseline or enhanced profile based on how critical it is.

What changed in CAF v4.0?

CAF v4.0 is the current version, published by the NCSC. Each release refreshes the indicators of good practice to keep pace with the threat landscape and technology, and clarifies outcomes that had proven hard to interpret. Organisations working to an earlier version should confirm which version their regulator or scheme currently requires and re-baseline against v4.0 where needed.

Who has to comply with the CAF?

The CAF is used across several regimes: Operators of Essential Services under the NIS Regulations, central government through GovAssure, and NHS organisations through the DSPT, which aligns to it. If a competent authority or scheme has adopted the CAF for your sector, you will be assessed against it. The NCSC publishes the framework; the regulator or scheme decides how it applies to you.

How does CyPro assess against the CAF?

CyPro fronts and manages a CAF assessment: we scope your essential functions, map your existing controls to the CAF outcomes at the right profile, evidence what is met, and hand you a prioritised plan for the gaps. The specialist assessment work is performed by our accredited delivery partner. The same method underpins our GovAssure, Secure by Design and IT Health Check services.

See how CyPro assesses

Rocket above the CAF Assessment call to action

From understanding to assessment

Find out how CyPro assesses against the CAF

A free 45 minute call covers which regime applies to you, the profile you need to meet and the indicative fixed-scope cost of a managed, partner-delivered CAF assessment, whether that is standalone, GovAssure or Secure by Design.