
The NCSC framework of 14 principles across four objectives, used to assess the cyber resilience of organisations operating essential functions.
The Cyber Assessment Framework (CAF) is published by the National Cyber Security Centre. It sets out what good cyber resilience looks like for organisations responsible for essential functions, expressed as outcomes to achieve rather than a list of controls to install.
It is applied across UK government through GovAssure, and used by regulators overseeing critical national infrastructure and operators of essential services.
Its outcome-based design is deliberate. Two organisations can reach the same outcome by very different means, so the framework asks whether a risk is genuinely being managed rather than whether a particular product has been purchased.
The CAF is organised into four objectives, labelled A to D, which together contain fourteen principles.
Each principle contains contributing outcomes, and each outcome is assessed against indicators of good practice. An outcome is typically judged as achieved, partially achieved or not achieved, supported by evidence rather than assertion.
Because the framework is outcome-based, an assessment considers whether the organisation is actually achieving the result described, taking account of its size, function and risk. This is also why assessments benefit from independent challenge — it is easy to over-rate your own position when marking against a descriptive standard.
ISO 27001 certifies that an information security management system meets a defined standard. The CAF assesses whether specific security outcomes are being achieved for an essential function. The two can coexist: ISO 27001 evidence can support a CAF assessment, but it does not replace one.
Similarly, Cyber Essentials addresses a baseline of common technical controls. The CAF goes considerably further and is aimed at organisations whose failure would have wider consequences.