NCSC Cyber Assessment Framework

A CAF assessment against every contributing outcome

We assess your essential functions against the NCSC CAF objectives and principles, rate each contributing outcome, and compare the results with the CAF profile you are expected to meet.

Book a NCSC CAF assessmentSee a sample report
VersionCAF v4.0
Maintained byUK National Cyber Security Centre
Structure4 objectives · 14 principles
Suited toUK operators of essential services and the public sector
01 · The framework

Objectives and principles

The CAF is outcome-based: it describes what good looks like rather than prescribing controls. Each principle breaks down into contributing outcomes with indicators of good practice.

AManaging security riskA1 Governance · A2 Risk management · A3 Asset management · A4 Supply chain
BProtecting against cyber attackB1 Policies and processes · B2 Identity and access · B3 Data security · B4 System security · B5 Resilient networks · B6 Staff awareness
CDetecting cyber security eventsC1 Security monitoring · C2 Proactive event discovery
DMinimising the impact of incidentsD1 Response and recovery planning · D2 Lessons learned
02 · Ratings

How outcomes are rated

Each contributing outcome is rated against its indicators of good practice.

AchievedOutcome metAll the indicators of good practice for the outcome are in place.
Partially achievedSome indicators metUsed where an outcome allows a partial rating. Gaps are recorded with remediation.
Not achievedOutcome not metOne or more indicators of poor practice apply.
03 · How we assess

Evidence first, interviews second

Every rating is backed by evidence from your environment, so the result reflects what is running, not what the policy says. A baseline typically takes two weeks.

  1. 01ScopeAgree the target, the systems in scope and who we need to speak to.
  2. 02CollectInterviews, document review and live data from Pulse and Trace.
  3. 03ScoreRate every requirement against your target, with evidence for each rating.
  4. 04ReportA prioritised roadmap and a short board briefing.
04 · What you receive

A result you can act on

Findings map across frameworks, so work done for NCSC CAF counts towards the others you hold.

✓Scored gap analysisStatus for every requirement against your target, backed by evidence.
✓Prioritised roadmapP1 to P3 work packages with owners, dates and exit criteria.
✓Board briefingA short summary of where you stand and the decisions needed.
✓Evidence kept currentResults live in Attest and update as your environment changes.
Often assessed together
NIS2 Directive NIST Cybersecurity Framework 2.0 ISO/IEC 27001:2022

Know where you stand against NCSC CAF in two weeks

A baseline assessment with a prioritised roadmap and a board-ready summary.

Book a NCSC CAF assessment