Guide
The NCSC Cyber Assessment Framework (CAF) explained.
Last reviewed 24 September 2026, against the NCSC's CAF guidance (version 4.0).
What is the NCSC CAF?
The Cyber Assessment Framework (CAF) is the National Cyber Security Centre's tool for helping organisations assess and improve their cyber security and resilience, and protect essential services from cyber threats. It is written for organisations that run important services: those subject to the Network and Information Systems (NIS) Regulations, UK critical national infrastructure, and public sector organisations that support core government functions.
The CAF is deliberately outcome-focused rather than a checklist. It describes what good cyber security and resilience should achieve, and the NCSC discourages treating an assessment as a tick-box exercise.
What changed in CAF v4.0?
The NCSC released version 4.0 on 6 August 2025 in response to a growing threat. It added:
- a deeper understanding of attacker methods and motivations, to inform cyber risk decisions
- guidance on making sure software used in essential services is developed and maintained securely
- stronger coverage of security monitoring and threat hunting
- wider treatment of cyber security risks from AI
The four CAF objectives and 14 principles.
The CAF is organised into four high-level objectives, broken down into 14 principles.
Objective A: Managing security risk
- A1 Governance
- A2 Risk management
- A3 Asset management
- A4 Supply chain
Objective B: Protecting against cyber attacks
- B1 Service protection policies, processes and procedures
- B2 Identity and access control
- B3 Data security
- B4 System security
- B5 Resilient networks and systems
- B6 Staff awareness and training
Objective C: Detecting cyber security events
- C1 Security monitoring
- C2 Threat hunting
Objective D: Minimising the impact of cyber security incidents
- D1 Response and recovery planning
- D2 Lessons learned
Each principle is broken down into contributing outcomes, and each contributing outcome has indicators of good practice (IGPs) that an assessor uses to judge whether the outcome is met. The IGPs are a guide, not a rigid set of requirements.
How a CAF assessment is scored.
Each contributing outcome is assessed as achieved, partially achieved or not achieved. Results are compared with a CAF profile: the level of achievement an organisation is expected to reach. The NCSC describes a basic profile, the target for all sectors against attackers with a basic level of capability, and enhanced profiles, which are sector specific.
The CAF in government: GovAssure.
GovAssure is the cyber security assurance scheme for government organisations, developed by the Cabinet Office's Government Security Group and the NCSC. It uses the CAF, with government-specific Baseline and Enhanced profiles, to assess critical government systems at OFFICIAL. It is not designed for systems processing SECRET information or above.
The process runs in five stages. An organisation's self-assessment is reviewed and verified through an independent assurance review, which must be carried out by a supplier registered as an Assured Service Provider on the NCSC's Cyber Resilience Audit scheme. The final report sets out observations and recommendations against the target CAF profile.
How to prepare for a CAF assessment.
- Scope the essential functions and systems the assessment covers, and confirm which CAF profile you are being measured against.
- Assemble evidence for each contributing outcome, not just policies: logs, configurations, test results and records of decisions.
- Assess honestly against the IGPs and record partially achieved outcomes as such. An inflated self-assessment is harder to defend at review.
- Prioritise the gaps by risk to the essential function, and plan remediation with owners and dates.
- Exercise your incident response before the review, so that D1 and D2 are evidenced by practice rather than paper.
How Mayfair IT Consultancy helps.
We work before and after the independent review, not as the reviewer. We carry out CAF-aligned cyber security posture assessments, which typically take two to four weeks and produce a risk-ranked set of recommendations. We then help close the gaps: network architecture review and hardening, network access control, security monitoring, and incident response planning with tabletop exercises. Where testing is needed we co-ordinate penetration testing with CREST-accredited partners.
Our network security engineers hold SC and DV clearances and have delivered on sensitive government infrastructure, including monitoring and network access control across prisons, courts and headquarters for the Ministry of Justice.
For a wider view of what the CAF means for departments, read our insight on cyber resilience in government and what the CAF demands.
Sources
- Cyber Assessment Framework (National Cyber Security Centre)
- Cyber Assessment Framework v4.0 released in response to growing threat (National Cyber Security Centre)
- GovAssure guidance (UK Government Security)
