Asked and answered
Frequently asked questions
The questions government, defence and CNI suppliers bring to us before an assessment, answered plainly. Anything the list leaves open, put to us on the scoping call and you will have a direct answer.
What is a CAF assessment?
A CAF assessment measures an organisation against the NCSC Cyber Assessment Framework: a structured review of how well you manage cyber risk, protect systems, detect events and limit the impact of incidents. The output is a profile showing where you meet the required outcomes and where the gaps are, with a prioritised plan to close them.
CyPro fronts and manages the engagement, and the assessment itself is performed by an accredited delivery partner. That keeps a single point of accountability for you while the framework work is done by specialists who assess against the CAF day in, day out.
What is the Cyber Assessment Framework?
The Cyber Assessment Framework (CAF) is the National Cyber Security Centre's framework for assessing the cyber resilience of organisations that run essential functions, such as operators of essential services under the NIS Regulations and public-sector bodies. It is outcome-based rather than a checklist: it describes what good cyber security looks like and lets the assessor judge how far you achieve it.
The CAF is organised into 4 top-level objectives, from managing security risk through to minimising the impact of incidents, each broken down into principles and contributing outcomes with indicators of good practice.
How many principles does the NCSC CAF use?
The NCSC Cyber Assessment Framework uses 14 principles, grouped under its 4 objectives: managing security risk, protecting against cyber attack, detecting cyber security events, and minimising the impact of cyber security incidents.
Each principle sets out a security outcome to achieve rather than a control to tick off, and every principle is supported by contributing outcomes and indicators of good practice that an assessment scores against.
What is GovAssure?
GovAssure is the UK government's cyber security assurance scheme for central government, run by the Government Security Group. It uses the NCSC Cyber Assessment Framework as its baseline and takes a department through a staged process: scoping the systems in scope, assessing them against the CAF, an independent assurance review of that assessment, and an agreed improvement plan.
We provide managed readiness and support through the stages. CyPro fronts and manages the work, and an accredited delivery partner performs the assessment. GovAssure is a government scheme we support against, not a CyPro accreditation or mark.
Who needs a GovAssure assessment?
GovAssure applies to central government departments and their arm's length bodies. Since it was rolled out in 2023 it is the route through which those organisations demonstrate the cyber resilience of their most important systems, assessed against the NCSC Cyber Assessment Framework.
Suppliers and delivery teams working on those systems are often drawn into the same evidence, so if you support a department's critical services it is worth understanding where you sit in its GovAssure scope. A scoping call is the quickest way to find out.
What is MOD Secure by Design?
MOD Secure by Design is the Ministry of Defence's approach to building cyber security into projects from the outset, rather than assessing it once at the end. It puts a continuous responsibility on delivery teams and their suppliers to identify risks, maintain a security case and evidence their decisions across the life of a project.
This is the MOD defence scheme, which is distinct from the police 'Secured by Design' initiative for physical security of buildings and products. We support defence suppliers and delivery teams against the MOD scheme; CyPro fronts and manages, and an accredited delivery partner performs the assessment.
What is an IT Health Check (ITHC)?
An IT Health Check (ITHC) is a security assessment of the systems and networks an organisation uses to connect to public-sector infrastructure, such as the Public Services Network, and other government-connected services. It combines vulnerability assessment and penetration testing to show whether the environment is safe to connect and where it needs remediation.
An ITHC has to be carried out by testers accredited under the NCSC CHECK scheme, or the equivalent CREST route. On our engagements the testing is performed by CHECK-accredited testers through our delivery partner, with CyPro fronting and managing the engagement end to end.
Is the DSPT mandatory?
The Data Security and Protection Toolkit (DSPT) is an annual online self-assessment published by NHS England. It is mandatory for organisations that have access to NHS patient data and systems, which includes NHS bodies and many of their suppliers and adult social care providers.
The DSPT and the Cyber Assessment Framework are aligned, so evidence gathered for a CAF-based review often supports a DSPT submission. We publish a plain explainer of the DSPT on our resources page for organisations weighing up where it fits; it is background information, not a service we sell.
How much does a CAF assessment cost?
Indicative fixed-scope pricing is published on our pricing page, starting from £4,500. The figure for your organisation depends on the scope drivers for the framework in question: organisation size, whether the CAF baseline or enhanced profile applies, and the number of systems or IP ranges in scope.
Assessment work in this sector is almost always priced on application. We break from that by publishing indicative 'from' prices for CAF assessment, GovAssure support, MOD Secure by Design and CHECK-accredited ITHC, then confirming the fixed fee in writing after a scoping call. Delivery is partner-led.
A question we missed?
Bring it to the scoping call
That is what the scoping call is for: 45 minutes, free, on which framework applies to you, the profile or stage you need to meet and the indicative cost, whether or not you go on to instruct the work.