Asked and answered
Frequently asked questions
The questions government, defence and CNI suppliers bring to us before an assessment, answered plainly. Anything the list leaves open, put to us on the scoping call and you will have a direct answer.
What is a CAF assessment?
A CAF assessment measures an organisation against the NCSC Cyber Assessment Framework: a structured review of how well you manage cyber risk, protect systems, detect events and limit the impact of incidents. The output is a profile showing where you meet the required outcomes and where the gaps are, with a prioritised plan to close them.
CyPro delivers that work: we run the gap analysis against the profile that applies to you, write the prioritised remediation plan and roadmap, and support your team implementing the controls that close the gaps. Where a formal external assessment or audit is required on top, that sits with your own auditor or the assurance provider appointed under the scheme, once you are ready for it.
What is the Cyber Assessment Framework?
The Cyber Assessment Framework (CAF) is the National Cyber Security Centre's framework for assessing the cyber resilience of organisations that run essential functions, such as operators of essential services under the NIS Regulations and public-sector bodies. It is outcome-based rather than a checklist: it describes what good cyber security looks like and lets the assessor judge how far you achieve it.
The CAF is organised into 4 top-level objectives, from managing security risk through to minimising the impact of incidents, each broken down into principles and contributing outcomes with indicators of good practice.
How many principles does the NCSC CAF use?
The NCSC Cyber Assessment Framework uses 14 principles, grouped under its 4 objectives: managing security risk, protecting against cyber attack, detecting cyber security events, and minimising the impact of cyber security incidents.
Each principle sets out a security outcome to achieve rather than a control to tick off, and every principle is supported by contributing outcomes and indicators of good practice that an assessment scores against.
What is GovAssure?
GovAssure is the UK government's cyber security assurance scheme for central government, run by the Government Security Group. It uses the NCSC Cyber Assessment Framework as its baseline and takes a department through a staged process: scoping the systems in scope, assessing them against the CAF, an independent assurance review of that assessment, and an agreed improvement plan.
We deliver the readiness work through those stages: scoping support, the CAF self-assessment and the evidence behind it, then the Targeted Improvement Plan and the work to close what it identifies. The Independent Assurance Review is carried out by the reviewer appointed under the scheme rather than by us, so that formal stage stays outside our scope. GovAssure is a government scheme we work to, not a CyPro accreditation or mark.
Who needs a GovAssure assessment?
GovAssure applies to central government departments and their arm's length bodies. Since it was rolled out in 2023 it is the route through which those organisations demonstrate the cyber resilience of their most important systems, assessed against the NCSC Cyber Assessment Framework.
Suppliers and delivery teams working on those systems are often drawn into the same evidence, so if you support a department's critical services it is worth understanding where you sit in its GovAssure scope. A scoping call is the quickest way to find out.
What is MOD Secure by Design?
MOD Secure by Design is the Ministry of Defence's approach to building cyber security into projects from the outset, rather than assessing it once at the end. It puts a continuous responsibility on delivery teams and their suppliers to identify risks, maintain a security case and evidence their decisions across the life of a project.
This is the MOD defence scheme, which is distinct from the police 'Secured by Design' initiative for physical security of buildings and products. We support defence suppliers and delivery teams against the MOD scheme: CyPro builds the security case with you, prepares the evidence and gets your delivery team ready for each review point. The formal judgement at a review gate is the MOD's or its appointed assurer's, not ours.
What is an IT Health Check (ITHC)?
An IT Health Check (ITHC) is a security assessment of the systems and networks an organisation uses to connect to public-sector infrastructure, such as the Public Services Network, and other government-connected services. It combines vulnerability assessment and penetration testing to show whether the environment is safe to connect and where it needs remediation.
The formal test has to be carried out by testers accredited under the NCSC CHECK scheme, or the equivalent CREST route, so that test itself sits outside our scope. What we do is get you ready to pass it: an internal assessment of the environment first, the remediation to close what a CHECK test would raise, the scope and evidence the connection owner expects, and support turning the tester's findings into fixes your team can complete.
Is the DSPT mandatory?
The Data Security and Protection Toolkit (DSPT) is an annual online self-assessment published by NHS England. It is mandatory for organisations that have access to NHS patient data and systems, which includes NHS bodies and many of their suppliers and adult social care providers.
The DSPT and the Cyber Assessment Framework are aligned, so evidence gathered for a CAF-based review often supports a DSPT submission. We publish a plain explainer of the DSPT on our resources page for organisations weighing up where it fits; it is background information, not a service we sell.
How much does a CAF assessment cost?
Indicative fixed-scope pricing is published on our pricing page, starting from £7,200. The figure for your organisation depends on the scope drivers for the framework in question: organisation size, whether the CAF baseline or enhanced profile applies, and the number of systems or IP ranges in scope.
Work in this sector is almost always priced on application. We break from that by publishing indicative 'from' prices for CAF assessment, GovAssure support, MOD Secure by Design and IT Health Check readiness, then confirming the fixed fee in writing after a scoping call.
A question we missed?
Bring it to the scoping call
That is what the scoping call is for: 45 minutes, free, on which framework applies to you, the profile or stage you need to meet and the indicative cost, whether or not you go on to instruct the work.