NCSC CAF v4.0

    Updated: 6 July 2026

    Resilience,
    assessed by outcome

    NCSC Cyber Assessment Framework (CAF) Guide

    The Cyber Assessment Framework is how the NCSC assesses whether organisations responsible for essential functions are managing cyber security risk - used across the NIS Regulations, Critical National Infrastructure and GovAssure. It is outcome-based: four objectives, fourteen principles, assessed against contributing outcomes.

    4

    Objectives (A–D)

    14

    Principles

    NIS · CNI

    GovAssure

    The Four Objectives and Fourteen Principles

    The CAF assesses cyber resilience by outcome, not by checklist. Each objective groups a set of principles; each principle is assessed against contributing outcomes rated Achieved, Partially achieved or Not achieved, guided by Indicators of Good Practice.

    Objective A: Managing security risk

    NCSC guidance

    Appropriate organisational structures, policies, processes and practices to understand, assess and systematically manage security risks to the networks and information systems supporting essential functions.

    Principles

    • A1 Governance - board-level ownership, clear roles and accountability for cyber resilience
    • A2 Risk management - a systematic, proportionate process to identify, assess and treat risks to essential functions
    • A3 Asset management - a complete, current understanding of the data, systems and people that support essential functions
    • A4 Supply chain - understanding and managing the security risks that arise from third parties and dependencies

    Objective B: Protecting against cyber attack

    NCSC guidance

    Proportionate security measures in place to protect essential functions and the networks and information systems supporting them from cyber attack.

    Principles

    • B1 Service protection policies, processes and procedures - defined, communicated and enforced
    • B2 Identity and access control - only authorised users and devices can access systems supporting essential functions
    • B3 Data security - protect stored and transmitted data from actions that could compromise essential functions
    • B4 System security - protect critical systems and technology from cyber attack
    • B5 Resilient networks and systems - design, build and operate for resilience against attack, failure and disruption, including backups
    • B6 Staff awareness and training - people supporting essential functions are appropriately aware and trained

    Objective C: Detecting cyber security events

    NCSC guidance

    Capabilities to ensure security defences remain effective and to detect cyber security events affecting, or with the potential to affect, essential functions.

    Principles

    • C1 Security monitoring - monitor to detect potential security problems and track the ongoing effectiveness of protective measures
    • C2 Proactive security event discovery - actively hunt for indicators of compromise that evade standard monitoring

    Objective D: Minimising the impact of cyber security incidents

    NCSC guidance

    Capabilities to minimise the impact of a cyber security incident on essential functions - including restoring those functions where necessary. This is where disaster-recovery testing and evidenced recovery live.

    Principles

    • D1 Response and recovery planning - well-defined, tested incident response and recovery plans
    • D1.a Response plan - a documented plan proportionate to the impact on essential functions
    • D1.b Response and recovery capability - the people, tooling and processes to enact the plan
    • D1.c Testing and exercising - regular exercising so plans work when they are needed
    • D2 Lessons learned - root-cause analysis and using incidents to drive continuous improvement