The NCSC Cyber Assessment Framework, explained
An outcome-based framework rather than a control checklist. Why that distinction changes what you have to produce.
Outcomes, not controls
Most frameworks give you a control list. The CAF gives you objectives, principles beneath them, and indicators of good practice that describe what achieving each principle looks like.
The reason this matters: you cannot pass by procurement. A control you have bought but that does not produce the outcome does not count, and a different approach that does produce the outcome does. It is a more honest framework and a harder one to game.
The four objectives
A: Managing security risk. Governance, risk management, asset management and supply chain. Do you understand what you have and what threatens it.
B: Protecting against cyber attack. Policies, identity and access, data security, system security, resilient networks, staff awareness.
C: Detecting cyber security events. Security monitoring and proactive discovery. This is where organisations most often score lower than they expect.
D: Minimising the impact of incidents. Response and recovery planning, and lessons learned.
How assessment works
Each contributing outcome is judged achieved, partially achieved or not achieved against its indicators. The result is a profile rather than a score, and competent authorities set the profile expected of a given sector or organisation.
That profile is the target, not universal maximum achievement. Being assessed as partially achieved on something genuinely peripheral to your service is not a failure.
Where it is used
The CAF underpins GovAssure for UK central government and is used by competent authorities overseeing operators of essential services. Several sector regulators have built their own profiles on top of it.
What it demands of your evidence
Because it asks for outcomes, the evidence that satisfies it is operational rather than documentary. Objective C in particular is difficult to evidence with policies: you are being asked to show that you detect things, which means showing detection coverage, log source health and worked examples.
Organisations that generate that evidence as a by-product of running their security operation find CAF assessment much cheaper than those who prepare for it as an exercise.
Questions, answered
Is the CAF mandatory?
How does the CAF relate to ISO 27001?
Where this goes next
Want this applied to your estate?
Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.