Audit methodology · Last verified
GovAssure
GovAssure is the UK government's scheme for assessing government critical systems against the NCSC Cyber Assessment Framework. It is run by the Government Cyber Unit and works through the WebCAF service in stages: self-assessment, review, and Targeted Improvement Plans, covering OFFICIAL government systems including critical national infrastructure.
- Class
- Audit methodology
- Owner
- Government Cyber Unit (GCU)
- Last verified
What it is
In its own words, "GovAssure is the cyber security scheme for assessing government critical systems against NCSC's Cyber Assessment Framework (CAF)." The process "provides government organisations with visibility of cyber security risks, and support to understand and manage them more effectively", and "is designed for OFFICIAL government systems, including government sector critical national infrastructure (CNI)". Organisations work through the scheme in stages: the WebCAF service holds "stage 3 self-assessments, stage 4 reviews and stage 5 Targeted Improvement Plans (TIPs)".
Who owns it
GovAssure is run by the Government Cyber Unit (GCU). The scheme's own page carries two statements about where the unit sits: it says the team "is part of the Government Cyber Unit (GCU) in the Department for Science, Innovation and Technology (DSIT)", and also that "the Government Cyber Unit (GCU) and the broader Digital functions of the Department for Science, Innovation and Technology (DSIT) have moved to the Department of Digital, Culture, Media and Sport (DCMS)". Both appear on the page as last updated on 29 July 2026; we reproduce both rather than choosing between them.
Who asks for it
"GovAssure supports the aims of the Government Cyber Action Plan."
Sources
- UK Government Security — GovAssure ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.