The process
How it works
The engagement runs as a clear sequence: a scoping call, the scope and framework confirmed in writing, an internal gap analysis by our consultants, a prioritised remediation plan and roadmap, then the work to close the gaps and an internal audit to confirm they have. Any formal external assessment or audit comes after that and is yours to commission. The same sequence runs whether you need a CAF assessment, GovAssure support, MOD Secure by Design or IT Health Check readiness.
Six steps
From scoping call to assured outcome
Every engagement runs this sequence. What changes between a CAF assessment, GovAssure support, MOD Secure by Design and an ITHC is the framework in the middle, not the shape of the process.
Step 1
The scoping call
Free, 45 minutes, taken by a consultant rather than a salesperson. We establish which framework applies to you: the NCSC Cyber Assessment Framework, GovAssure, MOD Secure by Design or a CHECK IT Health Check, the profile, stage or tier you need to meet, and the systems in scope. You leave knowing the indicative fixed-scope figure already published on the pricing page.
Step 2
Scope and framework confirmed
We confirm in writing the framework, the CAF profile (baseline or enhanced), the GovAssure stage coverage, the Secure by Design tier or the IP ranges for an ITHC, and the systems and boundaries in scope. A fixed-scope statement of work is agreed before any assessment begins, so there are no moving goalposts once the work is under way.
Step 3
The internal gap analysis
Our consultants assess your systems, policies and evidence against the framework's outcomes at the profile that applies to you. This is an internal assessment, done properly and without the pressure of a formal audit, so the answer you get is where you genuinely stand rather than the version you would present to a regulator.
Step 4
Findings, remediation plan and roadmap
You receive a clear gap analysis: where you meet the framework, where you fall short, and a remediation plan ordered by risk and sequenced into a roadmap your team can actually work through. Alongside it comes a report you can put in front of your board, your regulator or your sponsoring department without editing it first.
Step 5
We help you close the gaps
This is the part most assessment suppliers hand back to you. We stay on it: defining the controls, working alongside your team to stand them up, writing the policies and procedures the framework expects, and evidencing each one as it lands. Sequenced by the roadmap, so the highest risk closes first.
Step 6
Internal audit, then your formal assessment
Once the gaps are closed we run an internal audit to confirm the controls hold and the evidence stands up. From there, any formal assessment is yours to commission: your external auditor, the independent reviewer appointed under GovAssure, or a CHECK-accredited tester for an ITHC. We prepare you for it and support you through it, and we stay available as the framework moves through its versions or your systems change.
The CAF process, explained
What a CAF assessment actually involves
People ask what the CAF process is, or search for a CAF gap analysis, a CAF audit or a CAF compliance review. In practice these are the same piece of work. A CAF assessment measures your organisation against the NCSC Cyber Assessment Framework, its four objectives and fourteen principles, and produces a gap analysis: a clear picture of the outcomes you already achieve and the ones you do not yet.
The process is a sequence, not a certificate. You scope the essential functions and the systems that support them, assess them against the CAF outcomes, gather the evidence, and receive a prioritised plan to close the gaps. GovAssure applies that same CAF-based method through its five stages for central government, and MOD suppliers meet a parallel standard through Secure by Design; the shape of the work is the one set out above.
The exchange
What the assessment needs from you, and what you get back
What it asks of you
- A named owner: someone who receives the findings and owns the remediation inside your organisation.
- The systems and services in scope: the essential functions and the systems that support them, defined before work starts.
- Access to the policies, documentation and technical evidence the assessment draws on.
- Written authorisation for any technical testing, such as an IT Health Check, agreed at scoping; we never test systems we have not been authorised on.
What it hands back
- A clear gap analysis against the framework: the CAF outcomes, the GovAssure stages, the Secure by Design activities or the ITHC findings, and exactly where you stand.
- A remediation plan ordered by risk and written for the people who will act on it, not a raw list of findings to decode.
- A report you can put in front of a regulator, a sponsoring department, the MOD or an auditor without reworking it.
- One team throughout, from the gap analysis to the internal audit, and a route back for continued assurance as the framework or your systems change.
Common questions
What teams ask before they book
What is the CAF process?
A CAF assessment measures your organisation against the NCSC Cyber Assessment Framework, its four objectives and fourteen principles. The process runs in a clear sequence: scope the essential functions and the systems that support them, assess them against the CAF outcomes, gather the evidence, then produce a prioritised gap analysis and remediation plan. It is an assessment and improvement cycle, not a pass-or-fail certificate, and it is the same work whether it is described as a CAF gap analysis, a CAF audit or a CAF compliance review.
Who does the work?
CyPro's own consultants, from the scoping call to the internal audit at the end. We are the delivery partner rather than a layer of management on top of one, and the people who run the gap analysis are the people who help you close it. What we do not do is assess ourselves: any formal external assessment or audit, an appointed GovAssure independent reviewer, a certification auditor or a CHECK-accredited ITHC tester, is out of scope and commissioned by you. We use the framework names, CAF, GovAssure and MOD Secure by Design, to describe what we work to, never as a CyPro accreditation.
Is this a gap analysis, an audit or a full assessment?
For most organisations these describe the same engagement: a measured comparison of where you are against where the framework says you should be, with a prioritised plan to close the difference. We scope it to your obligation, whether that is a first CAF gap analysis, a GovAssure submission or evidence for the MOD, so you get the depth the framework requires and no more.
What happens after we get the findings?
The remediation plan is yours to act on, and where you want support closing the gaps we scope that with you. Once the fixes are in, a re-test confirms they have landed, and for GovAssure it feeds the independent assurance stage. As the framework or your systems change, a re-assessment keeps your position current.
Step one costs nothing
Book the scoping call
Bring your framework obligation and a rough idea of the systems in scope. We bring the sequence above, the indicative fixed-scope figure, and a clear view of which assessment you actually need.