Intelligistica, Fractional Technology Leadership
Guide

A guide to the NCSC Cyber Assessment Framework (CAF)

The National Cyber Security Centre Cyber Assessment Framework (NCSC CAF) provides organisations with a structured way to assess, evidence and improve their cyber security and resilience.

The current framework, CAF v4.0, is organised around four objectives, 14 principles and 41 contributing outcomes. It is designed around an important question:

Can your organisation demonstrate that the cyber risks to its essential functions are being effectively managed?

For organisations operating in government, public services, Critical National Infrastructure, financial services or other regulated and complex environments, CAF provides a consistent framework for understanding cyber resilience, identifying weaknesses and demonstrating that appropriate controls are operating effectively.

The framework

What is the NCSC Cyber Assessment Framework?

CAF is an outcome-based cyber security and resilience framework developed by the National Cyber Security Centre. Rather than prescribing a fixed set of technologies or controls, CAF defines the security and resilience outcomes an organisation should achieve.

This enables organisations to select controls appropriate to their size, technology environment, threat profile and operational requirements, while maintaining a consistent approach to assurance.

The framework considers the governance, technology, processes, people, information and third parties supporting an organisation's essential functions. It is structured around four objectives.

Objective A

Managing Security Risk

Ensuring cyber security risks are understood, governed and systematically managed.

  • A1 Governance
  • A2 Risk Management
  • A3 Asset Management
  • A4 Supply Chain

This objective considers whether there is clear accountability for cyber risk, whether risks are understood and managed, whether critical assets and dependencies are known and whether supply-chain risks are appropriately controlled.

Objective B

Protecting Against Cyber Attack

Ensuring proportionate controls are in place to protect the networks, systems, information and services supporting essential functions.

  • B1 Service Protection Policies, Processes and Procedures
  • B2 Identity and Access Control
  • B3 Data Security
  • B4 System Security
  • B5 Resilient Networks and Systems
  • B6 Staff Awareness and Training

This objective examines whether preventative controls are appropriate to the organisation's risks and whether systems and services have been designed, configured and operated securely.

Objective C

Detecting Cyber Security Events

Ensuring organisations can identify potentially malicious activity and detect when preventative controls may have been bypassed.

  • C1 Security Monitoring
  • C2 Threat Hunting

Effective cyber resilience cannot rely on prevention alone. Organisations need the ability to identify abnormal activity, detect compromise and proactively seek evidence of malicious activity that may have evaded existing security controls.

Objective D

Minimising the Impact of Cyber Security Incidents

Ensuring organisations can respond effectively to incidents, recover essential functions and learn from disruption.

  • D1 Response and Recovery Planning
  • D2 Lessons Learned

This objective considers whether the organisation can contain incidents, restore services, communicate effectively during disruption and use lessons from incidents and exercises to strengthen future resilience.

CAF v4.0

What changed in CAF v4.0?

CAF v4.0 reflects the changing cyber threat environment and strengthens the framework in several important areas. The NCSC introduced greater emphasis on:

  • Understanding attacker methods, capabilities and motivations
  • Secure software development and maintenance
  • Security monitoring and proactive threat hunting
  • Cyber risks associated with artificial intelligence

Of particular significance is Principle C2 Threat Hunting. This considers whether an organisation proactively searches for malicious activity that may have evaded conventional preventative and detective controls. The principle reinforces an important aspect of modern cyber resilience:

Organisations should not assume preventative controls will always succeed.

They must also be capable of detecting compromise, understanding its potential impact and responding before essential functions are materially affected.

Why it matters

Why does NCSC CAF matter?

Cyber resilience is no longer simply an information security issue.

Organisations increasingly depend on interconnected technology environments including cloud services, SaaS platforms, digital supply chains, outsourced technology providers, third-party data services and artificial intelligence. A cyber incident affecting one critical dependency can therefore rapidly affect customers, employees, markets, public services and wider supply chains.

CAF provides organisations with a structured way to answer three fundamental questions:

What services and functions matter most?
What technology, people, information and third parties do we depend upon to deliver them?
Can we demonstrate that appropriate security, detection, response and recovery capabilities are actually operating?

This makes CAF particularly valuable where the consequences of technology failure or cyber attack extend beyond the compromise of an individual system.

Public sector

NCSC CAF and the public sector

CAF has become an important component of cyber assurance across UK government.

The Government Cyber Security Strategy adopted CAF as the assurance framework for government, with GovAssure using the framework to assess the cyber security and resilience of critical government systems. CAF provides a consistent approach to understanding:

  • Governance and accountability
  • Cyber and technology risk
  • Critical assets and dependencies
  • Identity and access management
  • Supply-chain risk
  • Security monitoring
  • Threat detection and threat hunting
  • Incident response
  • Service recovery
  • Continuous improvement

For organisations supplying technology or services into government and the wider public sector, understanding CAF can also be commercially important. Customers increasingly require assurance not simply that a supplier has security policies, but that the services they depend upon are resilient and that associated cyber risks are understood, controlled and evidenced.

CAF therefore provides a useful framework for supplier assurance, procurement, contract governance and demonstrating cyber security maturity.

Financial services

NCSC CAF and financial services

CAF is also highly relevant to banks, building societies, insurers, fintechs, payment providers and other financial services organisations, even where CAF itself is not the firm's direct regulatory assessment framework.

The Bank of England has specifically referenced the NCSC CAF as a framework that firms and Financial Market Infrastructures can consider using to achieve and demonstrate cyber resilience.

For firms within the scope of FCA and PRA operational resilience requirements, there is also a natural relationship between cyber resilience and the protection of Important Business Services. Firms need to understand the people, processes, technology, information, facilities and third parties supporting their Important Business Services and manage disruption within defined impact tolerances. Many CAF capabilities directly support that objective, including:

  • Governance and risk management
  • Asset and dependency management
  • Supply-chain security
  • Identity and access management
  • Data security
  • Infrastructure resilience
  • Security monitoring
  • Threat hunting
  • Incident management
  • Response and recovery
A CAF essential function should not automatically be treated as equivalent to an FCA or PRA Important Business Service.

The two frameworks have different purposes and definitions. Mapping between them can nevertheless provide valuable assurance over the technology and cyber dependencies supporting Important Business Services.

CAF can therefore provide a useful cyber resilience assurance framework that complements FCA and PRA operational resilience requirements and established financial-sector cyber assessment approaches including CBEST, STAR-FS, CQUEST and CORST.

The value is not in treating CAF as another compliance checklist. It is in demonstrating that the organisation understands its critical dependencies, has appropriate controls in place and can detect, respond to and recover from cyber incidents before unacceptable disruption occurs. See our operational resilience consulting.

Target profiles

Basic and Enhanced CAF Profiles

CAF Profiles define target levels of cyber security and resilience based on the level of attack capability an organisation may need to withstand. There are two types of profile.

Basic Profile

The Basic Profile establishes a target level of cyber security and resilience applicable across sectors when organisations face attackers with a basic level of attack capability. This typically includes common cyber attacks and widely available attack techniques.

The Basic Profile can provide organisations with a structured baseline against which gaps in cyber resilience can be identified.

Enhanced Profile

Enhanced Profiles are sector-specific and build upon the Basic Profile. They represent a higher target level of cyber security and resilience for environments where organisations may face attackers that are more capable, better resourced and able to undertake more sophisticated attacks.

Where CAF forms part of formal regulatory or cyber oversight, the relevant Cyber Oversight Body determines the applicable target profile and how CAF assessment results should be interpreted.

Organisations using CAF voluntarily can use the profiles to inform a proportionate target based on their risk environment, threat exposure and the criticality of their essential functions.

Assessment

What does a CAF assessment look like?

CAF assesses the evidence supporting each of the framework's 41 contributing outcomes. The NCSC provides Indicators of Good Practice (IGPs) to support assessment and determine whether each contributing outcome is:

AchievedPartially Achieved (where applicable)Not Achieved

An effective CAF assessment therefore goes significantly beyond reviewing policies. It considers whether controls and capabilities have been implemented, whether they operate effectively and whether the organisation can provide appropriate evidence. Evidence may include:

  • Governance records and board reporting
  • Risk assessments
  • Security strategies and policies
  • Architecture documentation
  • Asset and configuration inventories
  • Identity and access controls
  • Vulnerability and patch management
  • Technical-debt registers
  • Security monitoring and SOC evidence
  • Threat intelligence and threat-hunting activity
  • Supplier and third-party assurance
  • Penetration testing and security testing
  • Incident-management records
  • Cyber exercises
  • Business continuity arrangements
  • Disaster-recovery and technology-recovery testing
  • Remediation programmes
  • Technical security controls

The objective is to establish a clear line between:

Risk→Essential Function→Dependency→Control→Evidence→Assurance

This provides a much clearer picture of the organisation's actual cyber resilience than policy review alone.

Obligations

Is NCSC CAF mandatory?

There is no single answer for every organisation.

CAF is not universally mandatory for all UK businesses. Its applicability depends on the organisation, sector and regulatory or government assurance regime.

For UK central government, CAF underpins the GovAssure cyber assurance programme. CAF is also widely used within cyber regulation, Critical National Infrastructure and environments subject to the Network and Information Systems Regulations.

Where CAF forms part of regulatory or formal cyber oversight, organisations should understand the requirements established by their relevant regulator or Cyber Oversight Body.

For most commercial organisations and FCA-regulated financial services firms, there is no universal requirement stating that every organisation must be "CAF compliant". For this reason, terminology such as "assessed against the NCSC CAF" or "aligned to CAF outcomes" is generally more useful than treating CAF as a simple certification standard.

CAF nevertheless provides a powerful framework for achieving, evidencing and independently assessing cyber resilience.

FAQs

NCSC CAF questions

What is the NCSC Cyber Assessment Framework?

The NCSC Cyber Assessment Framework is an outcome-based cyber security and resilience framework designed to help organisations understand and manage cyber risks to essential functions. CAF v4.0 contains four objectives, 14 principles and 41 contributing outcomes.

Is NCSC CAF mandatory?

It depends on the organisation and regulatory context. CAF underpins GovAssure for UK central government and is used within a number of cyber regulatory and Critical National Infrastructure environments. For most commercial organisations and FCA-regulated firms, there is no universal requirement to be CAF compliant.

Is CAF relevant to financial services?

Yes. The Bank of England has specifically referenced CAF as a framework organisations can consider using to achieve and demonstrate cyber resilience. CAF can complement FCA and PRA operational resilience requirements and financial-sector cyber assessment approaches such as CBEST, STAR-FS, CQUEST and CORST.

What is the difference between the Basic and Enhanced CAF Profiles?

The Basic Profile defines a target level applicable across sectors for attackers using basic attack capabilities. Enhanced Profiles are sector-specific and build upon the Basic Profile for environments where organisations may face more capable, better-resourced and sophisticated attackers.

Is CAF the same as ISO 27001?

No. ISO 27001 is an international standard for establishing and operating an Information Security Management System and can be independently certified. CAF is an outcome-based framework for assessing cyber security and resilience in relation to essential functions. The two can complement each other and organisations can reuse relevant ISO 27001 controls and evidence as part of a CAF assessment.

Can CAF be used alongside Cyber Essentials?

Yes. Cyber Essentials establishes a baseline of technical controls intended to protect organisations against common cyber attacks. CAF considers a much broader range of cyber security and resilience capabilities including governance, risk management, supply chains, monitoring, threat hunting, incident response and recovery. Cyber Essentials can therefore form part of the evidence supporting a wider CAF assurance programme.

Ready to assess your position against CAF?

Intelligistica can undertake an NCSC CAF v4.0 readiness and gap assessment, establish your current position against the 41 contributing outcomes and develop a practical, risk-based remediation roadmap.

Understand the risks. Identify the gaps. Prioritise remediation. Build the evidence. Strengthen resilience.

Explore our CAF service