Skip to content

Cyber Assessment Framework (CAF)

The NCSC Cyber Assessment Framework (CAF) is the UK's primary assurance framework for organisations responsible for Critical National Infrastructure (CNI) and other essential services. It is also widely used by public sector organisations, regulated industries, and any organisation seeking to assess its cyber security posture against a structured UK standard.

What the CAF is

The CAF provides a set of 14 security objectives grouped into four top-level goals. For each objective, the CAF defines indicators of good practice (IGP) — what a well-run organisation looks like — and indicators of poor practice (IPP) — warning signs that an objective is not being met.

The CAF is principle-based, not prescriptive: it describes outcomes, not specific technologies.

The four goals

Goal A: Managing security risk

ObjectiveDescription
A.1Governance — responsible individuals; clear accountability
A.2Risk management — proportionate, regularly reviewed
A.3Asset management — comprehensive, current inventory
A.4Supply chain — understanding and managing supply chain risk

Goal B: Protecting against cyber attack

ObjectiveDescription
B.1Service protection policies and processes
B.2Identity and access control
B.3Data security
B.4System security — secure design, configuration, patching
B.5Resilient networks and systems
B.6Staff awareness and training

Goal C: Detecting cyber security events

ObjectiveDescription
C.1Security monitoring — detecting security events
C.2Proactive security event discovery

Goal D: Minimising the impact of cyber security incidents

ObjectiveDescription
D.1Response and recovery planning
D.2Lessons learned

CAF and the NIS Regulations

The Network and Information Systems (NIS) Regulations 2018 (UK) require Operators of Essential Services (OES) to implement appropriate security measures. The CAF is the primary tool regulators use to assess compliance with NIS.

Sectors covered: Energy, Transport, Water, Health, Digital Infrastructure, and Finance.

Using the CAF for self-assessment

The CAF is freely available and can be used by any organisation for self-assessment:

  1. Work through each of the 14 objectives
  2. For each, assess current practice against the IGPs and IPPs
  3. Score each objective: Achieved / Partially achieved / Not achieved
  4. Produce a remediation plan for objectives that are not achieved

The CAF self-assessment produces a structured gap analysis that can prioritise security investment.

CAF vs Cyber Essentials

DimensionCyber EssentialsCAF
ScopeAll organisationsCNI / essential services / public sector
DepthFive basic controls14 objectives across the full security lifecycle
CertifiableYes (third-party assessment)Yes (regulator assessment for OES)
CostLowHigher (detailed assessment)
Primary useBaseline hygieneComprehensive organisational assurance

For most organisations, Cyber Essentials is the starting point and CAF is the comprehensive assurance framework once baseline hygiene is in place.

Further reading

Released under the MIT Licence.