Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Explainer

The NCSC Cyber Assessment Framework, explained

An outcome-based framework rather than a control checklist. Why that distinction changes what you have to produce.

Updated August 2026 · 6 minute read

Outcomes, not controls

Most frameworks give you a control list. The CAF gives you objectives, principles beneath them, and indicators of good practice that describe what achieving each principle looks like.

The reason this matters: you cannot pass by procurement. A control you have bought but that does not produce the outcome does not count, and a different approach that does produce the outcome does. It is a more honest framework and a harder one to game.

The four objectives

A: Managing security risk. Governance, risk management, asset management and supply chain. Do you understand what you have and what threatens it.

B: Protecting against cyber attack. Policies, identity and access, data security, system security, resilient networks, staff awareness.

C: Detecting cyber security events. Security monitoring and proactive discovery. This is where organisations most often score lower than they expect.

D: Minimising the impact of incidents. Response and recovery planning, and lessons learned.

How assessment works

Each contributing outcome is judged achieved, partially achieved or not achieved against its indicators. The result is a profile rather than a score, and competent authorities set the profile expected of a given sector or organisation.

That profile is the target, not universal maximum achievement. Being assessed as partially achieved on something genuinely peripheral to your service is not a failure.

Where it is used

The CAF underpins GovAssure for UK central government and is used by competent authorities overseeing operators of essential services. Several sector regulators have built their own profiles on top of it.

What it demands of your evidence

Because it asks for outcomes, the evidence that satisfies it is operational rather than documentary. Objective C in particular is difficult to evidence with policies: you are being asked to show that you detect things, which means showing detection coverage, log source health and worked examples.

Organisations that generate that evidence as a by-product of running their security operation find CAF assessment much cheaper than those who prepare for it as an exercise.

FAQ

Questions, answered

Is the CAF mandatory?
It depends who your competent authority is and what regime you fall under. It is the assessment model behind GovAssure for UK central government and is widely adopted by regulators of essential services. Applicability is confirmed for your organisation during onboarding.
How does the CAF relate to ISO 27001?
They are complementary and structurally different. ISO 27001 certifies a management system; the CAF assesses whether security outcomes are being achieved. A mature ISMS produces a lot of the evidence a CAF assessment wants, particularly under objective A.

Want this applied to your estate?

Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.