HomeFrameworksNational Cyber & Cloud SchemesNCSC CAF

Framework  National Cyber & Cloud Schemes

NCSC CAF

The Cyber Assessment Framework (CAF) is the UK National Cyber Security Centre's outcome-based framework for assessing the cyber resilience of organizations that run essential functions.

It was created in 2018 to give competent authorities under the NIS Regulations a common assessment tool and is now used by nearly all UK cyber regulators, by the GovAssure scheme for central government departments, and increasingly by devolved administrations and public bodies.

The CAF has four objectives (managing security risk, protecting against cyber attack, detecting cyber security events, minimizing the impact of incidents), 14 principles, and a set of contributing outcomes, each with indicators of good practice used to rate the outcome as Achieved, Partially Achieved, or Not Achieved.

Version 3.1 (April 2022) introduced the Partially Achieved level widely; version 3.2 (April 2024) made targeted changes; version 4.0 (August 2025) added outcomes on secure software development, AI-related risk, and threat hunting and realigned wording for NIS2-style expectations (verify the current version on the NCSC collection page).

The CAF is not a certificate. Operators self-assess against the CAF profile their regulator sets (each competent authority publishes the outcomes it expects for its sector), regulators review and may inspect, and GovAssure uses independent assurance reviewers to verify departmental self-assessments.

In writing, an organization needs the CAF self-assessment with evidence per contributing outcome, its risk management framework and governance records, asset and dependency inventories, security policies and their implementation evidence, monitoring and detection capabilities, incident response and recovery plans with exercise records, and improvement plans agreed with the regulator.

AI-compiled
Share
Sponsored
NCSC
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with NCSC CAF
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Operators of essential services and relevant digital service providers designated under the UK NIS Regulations (energy, transport, health, water, digital infrastructure), central government departments under GovAssure, and other organizations whose regulators adopt CAF-based profiles. Others may use it voluntarily.

What the assessor asks to see

CAF self-assessment with ratings and evidence per contributing outcome; governance and risk management records; asset, service, and dependency inventories; security policies and standards; identity and access management; system security and patching evidence; data protection and resilience measures; staff awareness and training records; supply chain risk management; monitoring coverage and detection capability; incident response plans, incident records, and exercise reports; recovery plans and tests; lessons learned and improvement plans.

Versions

CAF v3.1 (April 2022) mostly refined wording and consistency and embedded the Partially Achieved rating; v3.2 (April 2024) made targeted updates; v4.0 (August 2025) added new contributing outcomes for secure software development and AI-related risk and strengthened threat hunting expectations. Regulators announce when their sector profiles move to a new version.

Assessors

Who assesses NCSC CAF

Sector competent authorities (for example Ofgem, DfT, DHSC, Ofcom, the Drinking Water Inspectorate) review operator self-assessments and may inspect; independent assurance reviewers verify GovAssure self-assessments; no certificate is issued. competent authorities act under statutory powers, and GovAssure reviewers are selected through Cabinet Office arrangements.

No firm has claimed a NCSC CAF assessor listing yet. Claim yours →

Consultants

Who helps with NCSC CAF

UK cyber consultancies, including NCSC Assured Consultancy scheme members, offer CAF gap assessments, evidence gathering, and remediation roadmaps; GovAssure independent assurance reviewers are drawn from an approved supplier pool. Engagements run from a few weeks for a self-assessment to many months for remediation programs.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

URM ConsultingUKNot yet verified
What they do
ISO 27001 consultancy
Who they help
URM Consulting is an ISO 27001 consultancy based in UK. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Software

Tools for NCSC CAF

Tools that name this framework in their own material.

No firm has claimed a NCSC CAF tool listing yet. Claim yours →

Related reading

  1. Understanding and implementing the Cyber Assessment FrameworkIndustry body's guide to using an outcomes-based framework where regulators, not a certificate, decide whether you have achieved an outcome.techUK
  2. NCSC Cyber Assessment FrameworkExplains the four objectives, fourteen principles and the achieved, partially achieved and not achieved scoring used in assessments.Bridewell

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for NCSC CAF

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with NCSC CAF

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.