The process

How it works

A managed, partner-delivered assessment runs as a clear sequence: a scoping call, scope and framework confirmed in writing, an accredited partner performs the assessment, CyPro manages and quality-assures it throughout, and you receive findings, a prioritised remediation plan and a route back for re-test. The same sequence runs whether you need a CAF assessment, GovAssure support, MOD Secure by Design or a CHECK-accredited IT Health Check.

Six steps

From scoping call to assured outcome

Every engagement runs this sequence. What changes between a CAF assessment, GovAssure support, MOD Secure by Design and an ITHC is the framework in the middle, not the shape of the process.

measurable client outcomes for CAF and government assurance

Step 1

The scoping call

Free, 45 minutes, taken by a consultant rather than a salesperson. We establish which framework applies to you: the NCSC Cyber Assessment Framework, GovAssure, MOD Secure by Design or a CHECK IT Health Check, the profile, stage or tier you need to meet, and the systems in scope. You leave knowing the indicative fixed-scope figure already published on the pricing page.

secure technology for CAF and government assurance

Step 2

Scope and framework confirmed

We confirm in writing the framework, the CAF profile (baseline or enhanced), the GovAssure stage coverage, the Secure by Design tier or the IP ranges for an ITHC, and the systems and boundaries in scope. A fixed-scope statement of work is agreed before any assessment begins, so there are no moving goalposts once the work is under way.

recognised framework alignment for CAF and government assurance

Step 3

An accredited partner performs the assessment

The assessment itself is carried out by an accredited delivery partner, the specialists who hold the relevant accreditation, including CHECK-accredited testers for an IT Health Check. They assess your systems and evidence against the framework's outcomes and gather what is needed to show where you genuinely stand.

expert incident response for CAF and government assurance

Step 4

CyPro manages and quality-assures

CyPro fronts and runs the engagement end to end: coordinating the partner, holding the work to the agreed scope, and quality-assuring every finding before it reaches you. You deal with one managed relationship, not a handoff, and each finding is checked for accuracy and relevance rather than passed on raw.

meeting compliance obligations for CAF and government assurance

Step 5

Findings and prioritised remediation

You receive a clear gap analysis: where you meet the framework, where you fall short, and a remediation plan ordered by risk and written for the people who will act on it. Alongside it comes a report you can put in front of your board, your regulator or your sponsoring department without editing it first.

measurable client outcomes for CAF and government assurance

Step 6

Re-test and continued assurance

Once you have closed the gaps, a re-test confirms the remediation has landed and, for GovAssure, supports the independent assurance stage. As the framework changes, the CAF moves through its versions, or as your own systems change, a re-assessment keeps your position current rather than letting it drift.

The CAF process, explained

What a CAF assessment actually involves

People ask what the CAF process is, or search for a CAF gap analysis, a CAF audit or a CAF compliance review. In practice these are the same piece of work. A CAF assessment measures your organisation against the NCSC Cyber Assessment Framework, its four objectives and fourteen principles, and produces a gap analysis: a clear picture of the outcomes you already achieve and the ones you do not yet.

The process is a sequence, not a certificate. You scope the essential functions and the systems that support them, assess them against the CAF outcomes, gather the evidence, and receive a prioritised plan to close the gaps. GovAssure applies that same CAF-based method through its five stages for central government, and MOD suppliers meet a parallel standard through Secure by Design; the shape of the work is the one set out above.

The exchange

What the assessment needs from you, and what you get back

What it asks of you

  • A named owner: someone who receives the findings and owns the remediation inside your organisation.
  • The systems and services in scope: the essential functions and the systems that support them, defined before work starts.
  • Access to the policies, documentation and technical evidence the assessment draws on.
  • Written authorisation for any technical testing, such as an IT Health Check, agreed at scoping; we never test systems we have not been authorised on.

What it hands back

  • A clear gap analysis against the framework: the CAF outcomes, the GovAssure stages, the Secure by Design activities or the ITHC findings, and exactly where you stand.
  • A remediation plan ordered by risk and written for the people who will act on it, not a raw list of findings to decode.
  • A report you can put in front of a regulator, a sponsoring department, the MOD or an auditor without reworking it.
  • One managed relationship throughout, and a route back for re-test and continued assurance once the gaps are closed.

Common questions

What teams ask before they book

What is the CAF process?

A CAF assessment measures your organisation against the NCSC Cyber Assessment Framework, its four objectives and fourteen principles. The process runs in a clear sequence: scope the essential functions and the systems that support them, assess them against the CAF outcomes, gather the evidence, then produce a prioritised gap analysis and remediation plan. It is an assessment and improvement cycle, not a pass-or-fail certificate, and it is the same work whether it is described as a CAF gap analysis, a CAF audit or a CAF compliance review.

Who performs the assessment?

An accredited delivery partner carries out the assessment; CyPro fronts, manages and quality-assures the engagement from the scoping call to the final report. For an IT Health Check the testing is performed by CHECK-accredited testers. We use the framework names, CAF, GovAssure and MOD Secure by Design, to describe what we assess you against, never as a CyPro accreditation.

Is this a gap analysis, an audit or a full assessment?

For most organisations these describe the same engagement: a measured comparison of where you are against where the framework says you should be, with a prioritised plan to close the difference. We scope it to your obligation, whether that is a first CAF gap analysis, a GovAssure submission or evidence for the MOD, so you get the depth the framework requires and no more.

What happens after we get the findings?

The remediation plan is yours to act on, and where you want support closing the gaps we scope that with you. Once the fixes are in, a re-test confirms they have landed, and for GovAssure it feeds the independent assurance stage. As the framework or your systems change, a re-assessment keeps your position current.

See indicative pricing

Rocket above the CAF Assessment call to action

Step one costs nothing

Book the scoping call

Bring your framework obligation and a rough idea of the systems in scope. We bring the sequence above, the indicative fixed-scope figure, and a clear view of which assessment you actually need.