NCSC Cyber Assessment Framework (CAF)
Strengthen cyber resilience. Protect essential services. Demonstrate that your controls work.
The National Cyber Security Centre Cyber Assessment Framework (NCSC CAF) provides organisations with a structured way to assess, evidence and improve their cyber security and operational resilience.
Developed by the NCSC, the UK's national technical authority for cyber security, the CAF is designed around the protection of essential functions: the systems, services, information, people and suppliers that an organisation depends upon to continue operating.
Rather than prescribing a fixed set of technologies or controls, the CAF asks a more important question:
Can your organisation demonstrate that cyber risk is being effectively managed and that its essential services can withstand, detect, respond to and recover from cyber attack?
For organisations operating in financial services, government, public services, Critical National Infrastructure or complex regulated environments, this provides a powerful framework for understanding cyber resilience at an organisational level.
Business benefits of adopting CAF
A well-implemented CAF programme should provide value beyond regulatory or customer assurance.
Prioritise cyber investment
CAF helps organisations focus investment on weaknesses that create genuine risk to essential functions rather than deploying security technology in isolation.
Improve board-level visibility
CAF provides executives and boards with a structured view of cyber risk, control effectiveness, resilience gaps and remediation priorities.
Strengthen third-party assurance
The framework helps identify and manage dependencies on cloud providers, SaaS platforms, technology suppliers, outsourced services and other critical third parties.
Improve resilience and recovery
CAF considers not only whether an attack can be prevented, but whether malicious activity can be detected and essential services maintained or recovered when preventative controls fail.
Support procurement and customer assurance
Organisations can use CAF assessments to demonstrate a structured approach to managing cyber security and resilience risk. This can be particularly relevant to organisations supplying government, public-sector bodies, Critical National Infrastructure or regulated industries.
Support alignment with existing frameworks
CAF can be used alongside established security frameworks and standards including ISO 27001, NIST Cybersecurity Framework and Cyber Essentials. The objective should be to reuse evidence and controls wherever appropriate rather than create separate compliance environments.
A practical CAF readiness roadmap
CAF should be approached as a resilience improvement programme rather than a documentation exercise.
- 01
Define the scope
Identify the essential functions, services and critical systems that need to be assessed.
- 02
Map critical dependencies
Understand the people, processes, information, applications, infrastructure, cloud services, suppliers and facilities required to deliver those functions.
- 03
Understand the target
Determine the relevant CAF Profile, threat environment and, where applicable, regulatory or Cyber Oversight Body expectations.
- 04
Assess the 41 contributing outcomes
Review each contributing outcome against the relevant Indicators of Good Practice and available evidence.
- 05
Identify gaps and risks
Determine where outcomes are Achieved, Partially Achieved or Not Achieved and understand the business and operational consequences of identified weaknesses.
- 06
Prioritise remediation
Develop a risk-based improvement programme focused on the weaknesses that could have the greatest impact on essential functions.
- 07
Validate improvements
Confirm that remediation has addressed the underlying risk and that controls operate as intended.
- 08
Maintain continuous assurance
CAF should not become a point-in-time assessment. Technology, suppliers, threats and business services continually change. Cyber assurance should therefore form part of an ongoing governance, risk and resilience programme.
How Intelligistica can help
Intelligistica helps organisations move from CAF awareness to evidence-based cyber resilience. Our services include:
- CAF readiness assessments
- Independent CAF gap assessments
- CAF v4.0 maturity reviews
- Governance and cyber-risk frameworks
- Essential-function mapping
- Important Business Service and CAF dependency mapping
- Enterprise and security architecture reviews
- Identity and access management assessments
- Vulnerability and technical-debt reviews
- Third-party and supply-chain assurance
- SOC and security-monitoring assessments
- Threat-hunting capability reviews
- Incident response and recovery planning
- Cyber and operational resilience exercises
- Executive and board reporting
- ISO 27001, NIST CSF and Cyber Essentials alignment
- Financial-services operational resilience alignment
- Prioritised remediation roadmaps
Our approach combines cyber security, enterprise architecture, technology risk, operational resilience and regulatory experience. The objective is not simply to identify whether documentation exists. It is to determine whether the controls supporting essential services are appropriate, operating effectively and supported by evidence.
Ready to assess your position against CAF?
Intelligistica can undertake an NCSC CAF v4.0 readiness and gap assessment, establish your current position against the 41 contributing outcomes and develop a practical, risk-based remediation roadmap.
Understand the risks. Identify the gaps. Prioritise remediation. Build the evidence. Strengthen resilience.
Talk to Intelligistica about your NCSC CAF assessment