Central government and ALBs
GovAssure: Managed Support Through All Five Stages
GovAssure is the government's mandatory cyber assurance scheme, and it assesses your most critical systems against the NCSC Cyber Assessment Framework. We manage the whole engagement, from scoping to your Targeted Improvement Plan, with an accredited partner performing the independent assurance review.
Why now
A scheme that rewards preparation
GovAssure replaced the old departmental health check with a structured, CAF-based assessment that is independently reviewed. The departments that find it painful are the ones that treat it as a form-filling exercise. The ones that find it straightforward have their scope drawn cleanly, their evidence mapped to the CAF outcomes and their gaps identified before the formal assessment starts.
That preparation is what we manage. You get one engagement, one point of contact and a specialist partner performing the independent assurance work, rather than a scramble to assemble evidence against outcomes nobody in the team has read.
The partner-delivered model
- CyPro fronts and manages the whole engagement, from scoping to the improvement plan
- An accredited delivery partner performs the independent assurance work
- A single point of contact who speaks both CAF and plain English
- Evidence prepared and mapped to CAF outcomes before the formal assessment
- A prioritised, costed Targeted Improvement Plan you can take to your board
- Indicative fixed-scope pricing, from GBP 9,500, published rather than quote-only
The scheme, stage by stage
The five stages of GovAssure
GovAssure runs in five defined stages, from agreeing what is in scope to signing off an improvement plan. Here is what each stage asks of you, and where we carry the load.
Stage 1
Organisational context and services
Working with the Government Security Group, you define your organisation's context: the essential services you deliver, your mission and the functions that depend on technology. This framing decides everything that follows, so we help you articulate it clearly and evidence why each service matters.
Stage 2
In-scope systems and CAF profiles
You identify the in-scope systems, the ones whose compromise would stop the organisation delivering, and each is assigned a Government CAF profile: Baseline for most, Enhanced where the impact of failure is highest. We help you draw the boundary, justify what is in or out and prepare the evidence base before assessment begins.
Stage 3
Self-assessment in WebCAF
Each in-scope system is assessed against the four CAF objectives and their principles, outcome by outcome, at the assigned profile, with the results recorded in the government's WebCAF service. This is where readiness is proven with evidence rather than assertion. We run it as a structured, documented review so every judgement is defensible.
Stage 4
Independent Assurance Review
An independent reviewer examines your scoping, WebCAF responses and supporting evidence for rigour and accuracy. This is the check that gives the Government Security Group confidence in the result. The partner performs this review; we manage the engagement, prepare your team and make sure the evidence stands up.
Stage 5
Targeted Improvement Plan
The findings from the review report become a prioritised, costed Targeted Improvement Plan agreed with the Government Security Group. This is the output that matters: a clear route from where you are to the profile you must meet, sequenced so the highest-risk gaps close first.
Quick answers
GovAssure questions, answered
What is GovAssure?
GovAssure is the UK government's cyber security assurance scheme for central government. Run by the Government Security Group, it requires departments and their arm's length bodies to assess their most critical systems against the NCSC Cyber Assessment Framework and to have that assessment independently reviewed. It replaced the older departmental security health check with a more rigorous, CAF-based approach.
Who needs to complete a GovAssure assessment?
Central government departments and their arm's length bodies (ALBs) are in scope, with the schedule set by the Government Security Group. If you deliver a critical government service or hold a system the department depends on, you are likely to be drawn into a GovAssure assessment either directly or as part of a department's scope.
Is CyPro an appointed GovAssure reviewer?
The independent assurance review is performed by our accredited delivery partner, not by CyPro directly. CyPro fronts and manages the engagement: scoping, evidence preparation, CAF mapping and the improvement plan. We are clear about this split because the value is in a managed, single-contract engagement where the specialist work is done by the right accredited people.
How does GovAssure relate to the Cyber Assessment Framework?
GovAssure is the scheme; the NCSC Cyber Assessment Framework is the measuring stick it uses. Every GovAssure assessment is a CAF assessment of your in-scope systems at an assigned profile (baseline or enhanced). Understanding the CAF is the fastest way to understand what a GovAssure assessment will ask of you.
What does GovAssure support cost?
Indicative support starts from GBP 9,500, scaled to the size of the department or ALB and the number of systems and stages in scope. Pricing is fixed-scope and published rather than quote-only, and delivery is partner-led. The pricing page sets out the published prices for GovAssure alongside CAF, Secure by Design and ITHC work.
Get ahead of the assessment
Scope your GovAssure engagement
A free 45 minute call establishes which systems fall in scope, the profile they need to meet and the indicative fixed-scope cost of managed, partner-delivered GovAssure support.