
The UK government’s cyber assurance process, under which departments assess their most critical systems against the NCSC Cyber Assessment Framework.
GovAssure is the UK government’s cyber security assurance process. It requires departments and their arm’s-length bodies to assess their most critical systems against the NCSC Cyber Assessment Framework, with independent review rather than pure self-declaration.
It replaced the previous Departmental Security Health Check, moving government away from a light-touch annual return towards a structured, evidence-based assessment focused on the systems that matter most.
The intent is not to award a badge. It is to give departments, and the centre of government, a realistic picture of cyber resilience across critical services and a prioritised plan to improve it.
GovAssure runs as a defined sequence. Each stage builds on the last, and the independent review is what distinguishes it from a self-assessment exercise.
GovAssure applies the CAF through profiles that set the expected level for a given system. A baseline profile applies to most in-scope systems, with a more demanding profile used where a system is of greater criticality or carries higher consequence if it fails.
This means "good" is defined relative to the importance of the system, rather than applying one uniform standard to everything a department runs.
Suppliers are not assessed under GovAssure directly, but they are increasingly drawn into it. Where a supplier operates, hosts or supports an in-scope system, the department needs evidence about that supplier’s controls in order to complete its own assessment.
This is why GovAssure-driven questions now appear in supplier assurance questionnaires, and why suppliers to government are asked for evidence mapped to CAF outcomes rather than generic security statements.