RaptorGRC — Offline GRC

BLOG

The NCSC Cyber Assessment Framework A Practical Introduction

Published 10 August 2026 · By P Larner

Frameworks & Standards#GovAssure#critical national infrastructure#NIS Regulations#CAF#NCSC

The NCSC Cyber Assessment Framework: A Practical Introduction

Illustration for: The NCSC Cyber Assessment Framework: A Practical Introduction

Illustration for: The NCSC Cyber Assessment Framework: A Practical Introduction

The Cyber Assessment Framework (CAF) is the National Cyber Security Centre’s method for judging how well an organisation manages cyber risk to its essential functions. It sits behind NIS regulation in the UK and behind GovAssure for central government. If you run infrastructure the country depends on, or you supply someone who does, you will meet it sooner or later, so it is worth understanding how it actually works.

Why the CAF exists

The NIS Regulations 2018 require operators of essential services (energy, water, transport, health, digital infrastructure) to manage security risk, and they give sector regulators the job of checking. Those regulators, called competent authorities, include Ofgem for energy, the DfT for transport and the DHSC for health. The NCSC built the CAF so that every competent authority could assess against a common structure instead of inventing fourteen different questionnaires.

Three-layer flow diagram from the NIS Regulations 2018 down to competent authorities such as Ofgem, DfT and DHSC, and on down to operators of essential services, all assessed using the common CAF

Three-layer flow diagram from the NIS Regulations 2018 down to competent authorities such as Ofgem, DfT and DHSC, and on down to operators of essential services, all assessed using the common CAF

Every competent authority assesses its operators against the same common framework, which is the CAF.

The framework is deliberately outcome-based. The NCSC’s view, which I share after years of watching checklist compliance fail, is that prescriptive control lists go stale and invite box-ticking. The CAF instead describes what a well-defended essential function looks like and asks you to demonstrate that you achieve it, by whatever means fit your environment. The NCSC has revised it several times since 2018 (version 4.0 arrived in August 2025), so always pull the current edition from the NCSC website before starting work.

The four objectives and 14 principles

The CAF is organised into four objectives, lettered A to D, containing 14 principles between them.

  • Objective A, managing security risk, holds A1 Governance, A2 Risk management, A3 Asset management and A4 Supply chain. Board ownership, documented risk decisions, knowing what you run, and holding suppliers to account.
  • Objective B, protecting against cyber attack, holds B1 Service protection policies, processes and procedures, B2 Identity and access control, B3 Data security, B4 System security, B5 Resilient networks and systems, and B6 Staff awareness and training. This is the largest objective and covers most technical controls.
  • Objective C, detecting cyber security events, holds C1 Security monitoring and C2 Threat hunting. Not just having a SIEM, but demonstrating you would actually notice an attack on the essential function.
  • Objective D, minimising the impact of incidents, holds D1 Response and recovery planning and D2 Lessons learned. Tested plans, not shelf documents, and evidence that incidents change how you operate.

Each principle breaks into contributing outcomes, 41 in total, and those outcomes are what you actually assess.

Structure diagram of the four CAF objectives with their fourteen principles beneath them, all feeding a footer band reading 41 contributing outcomes

Structure diagram of the four CAF objectives with their fourteen principles beneath them, all feeding a footer band reading 41 contributing outcomes

The four objectives, the fourteen principles beneath them, and the 41 contributing outcomes they resolve into.

How assessment works, IGPs and the three verdicts

Every contributing outcome comes with indicators of good practice (IGPs), arranged in tables. There are typically three columns, holding indicators that the outcome is achieved, indicators that it is partially achieved, and indicators that it is not achieved. You read the tables, gather evidence, and record one of three verdicts per outcome, which are achieved, partially achieved, or not achieved.

Two points trip people up. First, the “not achieved” indicators act as vetoes, so if even one applies to you, you cannot claim achieved for that outcome regardless of how much of the good column you match. Second, the IGPs are indicators, not requirements. You can achieve an outcome through a route the tables never mention, provided you can argue it convincingly to an assessor. That flexibility is the point of an outcome-based framework, but it puts the burden of proof on you.

Flowchart of the CAF verdict logic for one contributing outcome, where any applicable not-achieved indicator vetoes the outcome, fully met achieved indicators give achieved and anything less gives partially achieved, with a faded mock indicator table for context

Flowchart of the CAF verdict logic for one contributing outcome, where any applicable not-achieved indicator vetoes the outcome, fully met achieved indicators give achieved and anything less gives partially achieved, with a faded mock indicator table for context

The verdict logic for a single outcome, where one applicable not-achieved indicator vetoes everything else.

Competent authorities set expectations using CAF profiles, which are statements of which outcomes must be achieved or partially achieved for a given operator. A water company and a rail operator will face different profiles even though they use the same framework.

Who it applies to

  • Operators of essential services regulated under NIS, across energy, transport, water, health and digital infrastructure.
  • Central government, through GovAssure, which since 2023 has required departments to assess their critical systems against the CAF.
  • Wider critical national infrastructure organisations, many of whom adopt it voluntarily or at their lead government department’s request.
  • Anyone else who wants it, because the CAF is free and public. I have seen mid-sized firms with no regulatory driver use Objective A alone as a governance health check, and it works well for that.

If you supply a regulated operator, expect CAF language to appear in security schedules and supplier questionnaires even though the regulation does not apply to you directly.

How it differs from ISO 27001

The two get conflated constantly, and they answer different questions. ISO 27001 certifies that you operate a management system for information security across a scope you choose. The CAF assesses whether specific essential functions are actually resilient against attack, judged against a bar a regulator chooses.

Aspect

NCSC CAF

ISO 27001

Origin

UK NCSC, regulatory

International standard, commercial

Style

Outcome-based, 41 contributing outcomes

Management system plus 93 Annex A controls

Assessment

Self-assessment, reviewed by regulator or assessor

Certification audit by accredited body

Scope

Defined by the essential function

Defined by the organisation

Result

Achieved, partially achieved or not achieved per outcome

Certificate, pass or fail

An ISO 27001 certificate does not get you through a CAF assessment, and I have watched organisations discover this late. A certified ISMS scoped around head office says little about whether the operational technology running a treatment works would survive a targeted intrusion. That said, a mature ISMS makes CAF evidence gathering far easier, because the risk assessments, asset registers and incident records already exist.

Tips for a first self-assessment

  • Define the essential function precisely before you score anything. The assessment is about the systems supporting that function, not your whole estate.
  • Start with Objective A. Weak governance and asset management undermine every claim you make in B, C and D.
  • Read the not-achieved indicators first for each outcome. They disqualify fastest and tell you immediately where you stand.
  • Record evidence, not opinions. “Partially achieved, because quarterly access reviews cover IT but not OT, see review log Q1” survives regulator scrutiny. “We think this is fine” does not.
  • Resist grade inflation. Regulators compare your self-assessment against inspection findings, and optimistic scoring destroys credibility for years.
  • Expect a first pass across 41 outcomes to take a small team four to six weeks alongside the day job.

Getting moving

Download the current CAF from the NCSC website, agree in writing what your essential function is, and run Objective A against it this month with the people who actually operate the systems in the room. The result will be humbling, which is normal, and it gives you a prioritised list grounded in the framework your regulator will eventually use. That beats guessing at what good looks like.

Run your GRC programme in your own network.

RaptorGRC Community Edition is free — every module, offline licence activation, nothing phones home.

Register / Download Contact us
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.