Framework · Last verified

Cyber Assessment Framework

The Cyber Assessment Framework is the NCSC's outcome-based framework for assessing cyber resilience, structured around 4 objectives and 41 assessments. Assessments can be carried out by the organisation itself or by an independent external body, and the NCSC states it holds no regulatory power itself.

Class
Framework
Owner
National Cyber Security Centre (NCSC), a part of GCHQ
Last verified

What it is

The Cyber Assessment Framework is the NCSC's outcome-based framework for assessing cyber resilience. In the NCSC's words it "provides a systematic and comprehensive approach to assessing the extent to which cyber risks to essential function(s) are being managed by the organisation responsible." Its structure is fixed: "The 4 high-level objectives and the 14 principles are written in terms of outcomes, i.e. specification of what needs to be achieved rather than a checklist of what needs to be done," and "The result of applying the CAF is 41 individual assessments." The four objectives are Managing security risk, Protecting against cyber attack, Detecting Cyber Security Events, and Minimising the impact of cyber security incidents.

The 14 principles sit under those four objectives, and the NCSC names them: under Objective A — A1 Governance, A2 Risk Management, A3 Asset Management, A4 Supply Chain; under Objective B — B1 Service protection policies, processes and procedures, B2 Identity and Access Control, B3 Data security, B4 System security, B5 Resilient networks and systems, B6 Staff awareness and training; under Objective C — C1 Security monitoring, C2 Threat Hunting; under Objective D — D1 Response and recovery planning, D2 Lessons Learned.

Who it is written for, in the NCSC's own words: "The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions." The NCSC adds that it is "designed for organisations operating essential services, in sectors such as energy, healthcare, transport, digital infrastructure and government" and is "appropriate for situations where an organisation typically faces attackers that are more capable, better resourced and can undertake more sophisticated attacks."

The current edition is version 4.0; the NCSC's own collection page carries it as a download titled "Cyber Assessment Framework version 4.0", described there as the "Fourth iteration of the Framework used to assess the cyber security of UK CNI and related sectors."

Who owns it

The Cyber Assessment Framework is published by the National Cyber Security Centre (NCSC), a part of GCHQ.

Who assesses it

CAF-based assessments can be carried out either by the responsible organisation itself (self-assessment) or by an independent external entity, possibly a regulator / cyber oversight body or a suitably qualified organisation acting on behalf of a regulator, such as an NCSC assured commercial service provider.

Who asks for it

The NCSC is explicit that it is not the body that requires the CAF: "NCSC itself has no regulatory responsibilities, and organisations subject to cyber regulation should consult with their regulators to learn whether they should use the CAF in the context of meeting regulatory requirements." The demand is created elsewhere. In UK central government the Cabinet Office's Government Cyber Security Strategy states that "Government will adopt the Cyber Assessment Framework (CAF) as the assurance framework for government" and that "these assurance processes will be mandated for central government departments." Whether any individual regulator has made CAF use binding in its own sector was not verified in the sources reviewed as of 29 August 2026 — confirm against the relevant sector regulator.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Cyber Assessment Framework." Certifidex, FutureTechnologies. Last verified 29 August 2026. https://certifidex.com/frameworks/uk-caf

All frameworks & audits →