The framework, explained
The NCSC Cyber Assessment Framework (CAF), Explained
The Cyber Assessment Framework is the NCSC's outcome-based way of measuring how well an organisation manages cyber security risk to its essential functions. This is a plain-English guide to its four objectives, 14 principles, profiles and who has to comply.
Outcomes, not a checklist
What the Cyber Assessment Framework is
The Cyber Assessment Framework is published by the National Cyber Security Centre, the UK's technical authority for cyber security. Unlike a tick-box standard, the CAF describes the outcomes a well-run organisation should be able to demonstrate, then asks you to show, with evidence, how far you achieve them. It is designed for organisations whose failure would have a serious impact on people, the economy or national security.
Because it is outcome-based, two organisations can meet the same principle in different ways. That flexibility is the point: the CAF judges whether risk is genuinely managed, not whether a specific product is installed.
Who has to comply
- Operators of Essential Services (OES) under the NIS Regulations, overseen by their competent authority
- Central government departments and arm's length bodies, through the GovAssure scheme
- NHS organisations, through the Data Security and Protection Toolkit (DSPT), which aligns to the CAF
- Critical national infrastructure operators and their suppliers, where a regulator adopts the CAF
The structure
Four objectives, fourteen principles
The CAF groups everything under four objectives, from managing risk through to recovering from an incident. The 14 principles sit beneath them, each carrying its own contributing outcomes.
Objective A
Managing security risk
Governance, risk management, asset management and supply chain. The foundations: knowing what you have, who is accountable, and how cyber risk is understood and owned across the organisation.
A1 Governance, A2 Risk management, A3 Asset management, A4 Supply chain
Objective B
Protecting against cyber attack
The protective controls: policies and processes, identity and access control, data security, system security, resilient networks and systems, and staff awareness and training.
B1 Service protection, B2 Identity and access, B3 Data security, B4 System security, B5 Resilient networks, B6 Staff awareness
Objective C
Detecting cyber security events
The ability to see what is happening: security monitoring across the systems that matter, and proactively discovering events that monitoring alone would miss.
C1 Security monitoring, C2 Proactive security event discovery
Objective D
Minimising the impact
What happens when something gets through: response and recovery planning that is tested, and a genuine lessons-learned loop so the same weakness is not exploited twice.
D1 Response and recovery planning, D2 Lessons learned
Quick answers
Cyber Assessment Framework questions, answered
What is the Cyber Assessment Framework (CAF)?
The Cyber Assessment Framework is a set of outcome-based cyber security principles published by the National Cyber Security Centre (NCSC). It is used to assess how well an organisation is managing cyber security risk to its essential functions. Rather than a checklist, it defines 14 principles grouped under four objectives, each with contributing outcomes and indicators of good practice against which an organisation is judged.
How many objectives and principles does the CAF have?
The CAF is built on four objectives: A Managing security risk, B Protecting against cyber attack, C Detecting cyber security events, and D Minimising the impact of cyber security incidents. Beneath those sit 14 principles, and beneath each principle a set of contributing outcomes and indicators of good practice.
What is a CAF profile: baseline or enhanced?
A CAF profile sets the target level an organisation needs to achieve for each outcome. A baseline profile is used for most systems; an enhanced profile applies where the impact of failure is highest, raising the bar for several outcomes. Under GovAssure, for example, each in-scope system is assigned a baseline or enhanced profile based on how critical it is.
What changed in CAF v4.0?
CAF v4.0 is the current version, published by the NCSC. Each release refreshes the indicators of good practice to keep pace with the threat landscape and technology, and clarifies outcomes that had proven hard to interpret. Organisations working to an earlier version should confirm which version their regulator or scheme currently requires and re-baseline against v4.0 where needed.
Who has to comply with the CAF?
The CAF is used across several regimes: Operators of Essential Services under the NIS Regulations, central government through GovAssure, and NHS organisations through the DSPT, which aligns to it. If a competent authority or scheme has adopted the CAF for your sector, you will be assessed against it. The NCSC publishes the framework; the regulator or scheme decides how it applies to you.
How does CyPro assess against the CAF?
CyPro fronts and manages a CAF assessment: we scope your essential functions, map your existing controls to the CAF outcomes at the right profile, evidence what is met, and hand you a prioritised plan for the gaps. The specialist assessment work is performed by our accredited delivery partner. The same method underpins our GovAssure, Secure by Design and IT Health Check services.
From understanding to assessment
Find out how CyPro assesses against the CAF
A free 45 minute call covers which regime applies to you, the profile you need to meet and the indicative fixed-scope cost of a managed, partner-delivered CAF assessment, whether that is standalone, GovAssure or Secure by Design.