Cyber Security
Cyber Security Glossary

NCSC Cyber Assessment Framework (CAF)

The NCSC framework of 14 principles across four objectives, used to assess the cyber resilience of organisations operating essential functions.

What it is
An outcome-based cyber resilience framework
Published by
The National Cyber Security Centre (NCSC)
Structure
Four objectives containing fourteen principles
Used for
GovAssure, and regulation of essential services and CNI

The Cyber Assessment Framework (CAF) is published by the National Cyber Security Centre. It sets out what good cyber resilience looks like for organisations responsible for essential functions, expressed as outcomes to achieve rather than a list of controls to install.

It is applied across UK government through GovAssure, and used by regulators overseeing critical national infrastructure and operators of essential services.

Its outcome-based design is deliberate. Two organisations can reach the same outcome by very different means, so the framework asks whether a risk is genuinely being managed rather than whether a particular product has been purchased.

Four objectives, fourteen principles

The CAF is organised into four objectives, labelled A to D, which together contain fourteen principles.

  1. Objective A — Managing security riskCovers governance, risk management, asset management and supply chain (principles A1 to A4), establishing the foundations for managing cyber risk.
  2. Objective B — Protecting against cyber attackCovers service protection policies and processes, identity and access control, data security, system security, resilient networks and systems, and staff awareness and training (principles B1 to B6).
  3. Objective C — Detecting cyber security eventsCovers security monitoring and proactive security event discovery (principles C1 and C2), so that attacks are noticed rather than assumed absent.
  4. Objective D — Minimising the impact of incidentsCovers response and recovery planning, and learning lessons from incidents (principles D1 and D2), on the basis that some incidents will happen.

How assessment works

Each principle contains contributing outcomes, and each outcome is assessed against indicators of good practice. An outcome is typically judged as achieved, partially achieved or not achieved, supported by evidence rather than assertion.

Because the framework is outcome-based, an assessment considers whether the organisation is actually achieving the result described, taking account of its size, function and risk. This is also why assessments benefit from independent challenge — it is easy to over-rate your own position when marking against a descriptive standard.

How it differs from other standards

ISO 27001 certifies that an information security management system meets a defined standard. The CAF assesses whether specific security outcomes are being achieved for an essential function. The two can coexist: ISO 27001 evidence can support a CAF assessment, but it does not replace one.

Similarly, Cyber Essentials addresses a baseline of common technical controls. The CAF goes considerably further and is aimed at organisations whose failure would have wider consequences.

NCSC Cyber Assessment Framework (CAF), answered

Is the CAF mandatory?
It depends on the organisation. It is applied to in-scope UK government systems through GovAssure, and used by some regulators for operators of essential services. It is not a general obligation on every organisation.
How many principles does the CAF have?
Fourteen principles, grouped under four objectives — managing security risk, protecting against cyber attack, detecting cyber security events, and minimising the impact of incidents.
How is the CAF different from ISO 27001?
ISO 27001 certifies a management system against a standard, whereas the CAF assesses whether specific security outcomes are achieved for an essential function. ISO 27001 evidence can support a CAF assessment but does not substitute for one.
What do achieved, partially achieved and not achieved mean?
They describe how far a contributing outcome is being met, judged against the indicators of good practice and supported by evidence. They are an assessment of the outcome, not a score to be optimised.

Related terms

Authoritative sources

How we help

We run and independently challenge CAF assessments — turning indicators of good practice into an evidenced position and a plan that closes the gaps that matter.