Cyber Security
GovAssure

Preparing for GovAssure: a practical guide to the NCSC CAF

GovAssure applies the NCSC Cyber Assessment Framework to central government. Here is how to scope it, assess honestly and survive independent review.

13 September 2026 8 min read GovAssure

GovAssure is the UK government’s cyber assurance scheme for central government departments and their arm’s-length bodies. It replaces self-declared annual returns with a structured assessment against the NCSC Cyber Assessment Framework, reviewed independently. For teams used to filling in a spreadsheet once a year, that independent review is the part that changes everything.

The good news is that GovAssure is not trying to catch you out. It is trying to establish an honest, evidence-backed picture of how well the systems that matter are actually defended. The organisations that do well are the ones that treat it as a genuine assessment rather than a form to be argued past.

What GovAssure actually is

GovAssure sits on top of the NCSC Cyber Assessment Framework (CAF). The CAF is organised into four objectives - managing security risk, protecting against cyber attack, detecting cyber security events, and minimising the impact of incidents - which break down into fourteen principles and a set of contributing outcomes. Each outcome is judged as achieved, partially achieved or not achieved, with evidence.

GovAssure adds the government wrapper: a defined scope of critical systems, a profile of expected outcomes (Baseline or Enhanced depending on criticality), an independent review, and a route from the assessed position into an improvement plan. It aligns with the Government Cyber Security Strategy and the GovS 007 security functional standard.

Get the scope right first

Most of the pain in a first GovAssure cycle comes from scope, not controls. Teams either scope too widely and drown, or too narrowly and cannot defend the boundary. The way through is to argue criticality from business consequence rather than from who owns which server.

Start from the functions the organisation exists to deliver, then work down to the systems that genuinely support them. Document why a system is in scope, and just as importantly why others are out, so the boundary survives challenge during review. A scope you can explain is a scope you can defend.

Assess against the CAF honestly

An over-stated self-assessment is worse than an honest one, because the moment an independent reviewer finds one weak claim, they stop trusting the rest. Mark an outcome as partially achieved where that is the truth. A CAF full of green that cannot be evidenced is a liability, not an achievement.

Work through the contributing outcomes with the people who actually operate the systems, and capture evidence as you find it rather than reconstructing it afterwards. The reviewer will ask not just what your position is, but why - and the answer needs to be sitting next to the claim.

A useful test for every claimed outcome: if an independent reviewer asked you to show them, could you, today, without a scramble? If not, it is not achieved yet.

Rehearse the independent review

The single most valuable thing you can do before a formal review is to challenge your own draft position the way an external reviewer will. Weak evidence found internally is a task on a plan. Weak evidence found in the formal review is a finding on the record.

Turn gaps into a plan, not a list

The point of the assessment is not the grade. It is the improvement plan that follows. Convert assessed gaps into prioritised actions with named owners and dates, so the centre of government can see that you understand your own weaknesses and are closing them. A list of observations that nobody owns changes nothing.

Done this way, your CAF position becomes something you maintain rather than rebuild from scratch each cycle - which is the real return on getting the first one right.

Written by the E2E Security Consulting team. This article is general guidance, not formal advice on your specific circumstances - for that, the useful first step is a short conversation.

More insights

Need this on your programme?

If the topic above is live for you right now, we can help you work through it - practically, and aligned to NCSC guidance.