What is the NCSC Cyber Assessment Framework?

Cyber resilience is not simply about having security controls in place. Organisations also need to understand whether those controls are working, whether risks are being managed effectively, and whether they can demonstrate this with evidence.

The NCSC Cyber Assessment Framework (CAF) provides a structured way of doing this.

Developed by the UK’s National Cyber Security Centre (NCSC), the CAF provides a systematic approach to assessing how effectively an organisation manages cyber risks to its essential functions. It can support self-assessment as well as independent assessment.

How does the CAF work?

Unlike a traditional compliance checklist, the CAF is outcome-focused.

Rather than simply asking whether a particular control exists, it considers whether an organisation is achieving defined cyber security and resilience outcomes.

CAF 4.0 is structured around four high-level objectives:

Objective A — Managing security risk
How effectively the organisation understands and manages cyber security risks.

Objective B — Protecting against cyber attack
Whether proportionate measures are in place to protect the systems supporting essential functions.

Objective C — Detecting cyber security events
Whether the organisation has capabilities to identify security events and potential incidents.

Objective D — Minimising the impact of cyber security incidents
Whether the organisation can respond, recover and reduce the impact of incidents on essential functions.

Beneath these objectives sit 14 principles and 41 contributing outcomes. Indicators of Good Practice (IGPs) support organisations and assessors in judging whether those outcomes are being achieved.

Where does evidence fit?

This is where CAF assessment becomes particularly interesting.

An organisation may already hold policies, risk registers, technical standards, governance records, supplier documentation, security reports and other evidence across multiple teams and systems.

The challenge is not necessarily whether that information exists.

The challenge is whether an organisation can connect its evidence to the cyber resilience outcomes it is trying to demonstrate.

A policy may describe an intended approach. A risk register may demonstrate how risks are being managed. Technical documentation may provide evidence of implemented controls. Governance records may show how decisions, responsibilities and oversight operate in practice.

Individually, these artefacts tell part of the story. Assurance requires understanding what the evidence demonstrates collectively — and where gaps remain.

Because the CAF is outcome-focused rather than a simple checklist, professional judgement remains essential. Evidence needs to be considered in context before determining whether it genuinely supports an outcome.

Who uses the CAF?

The CAF is particularly relevant to organisations playing an important role in UK society, including organisations operating Critical National Infrastructure and organisations subject to certain forms of cyber regulation.

It can also support cyber oversight bodies seeking to understand resilience across organisations or sectors.

The common core of the CAF is sector-agnostic, although it can be extended to meet the requirements of particular sectors.

The important question

Ultimately, the CAF encourages organisations to move beyond asking:

“Do we have cyber security controls?”

towards asking:

“Can we demonstrate that our cyber resilience measures are achieving the outcomes we expect?”

That distinction matters.

Modern cyber assurance is not simply about having policies, controls and documentation. It is about being able to understand and demonstrate what that evidence says about an organisation’s actual cyber resilience.

SIFTR INSIGHT

SIFTR is exploring how organisations can turn dispersed cyber evidence into clearer, traceable assurance findings — helping teams understand what their evidence supports, where potential gaps exist and where human review is required.

Professional judgement remains at the centre of the assurance process.

Explore SIFTR →

Leave a comment