Essential services & resilience

NCSC Cyber Assessment Framework readiness support

The NCSC Cyber Assessment Framework is designed around the security and resilience of essential functions. For organisations using CAF directly—or responding to a regulator, government customer or supply-chain requirement—we help turn its outcomes into a defensible assessment and improvement programme.

How we can help

Practical support, properly explained

Assess and improve cyber resilience against the NCSC Cyber Assessment Framework with outcome mapping, evidence review and prioritised remediation support.

01

CAF applicability and profile review

02

Essential-function and dependency mapping

03

Outcome and indicator assessment

04

Governance and risk evidence review

05

Protection and identity control review

06

Detection and monitoring readiness

07

Incident response and recovery assessment

08

Remediation roadmap and evidence register

Designed for vital functions

CAF is not a generic badge for every small business

The framework is primarily intended for organisations operating essential services, critical national infrastructure, government functions and regulated environments. It may also appear through sector profiles, public-sector assurance or supply-chain expectations.

Before starting a CAF assessment, regulated organisations should confirm the applicable profile and expectations with their regulator or responsible authority.

  • Operators of essential services and critical infrastructure
  • Government and wider public-sector organisations
  • Organisations assessed through a sector-specific CAF profile
  • Suppliers supporting an in-scope essential function where assurance is required

Outcome focused

Assess whether the essential function is genuinely resilient

CAF organises cyber resilience across managing security risk, protecting against attack, detecting cyber events, and minimising the impact of incidents. The assessment should connect those outcomes to the systems, people, information and suppliers that the essential function depends upon.

We help collect and challenge evidence, identify unknowns and separate genuine control weakness from a documentation gap.

Map intelligently

Reuse existing assurance without assuming equivalence

ISO 27001, Cyber Essentials, sector standards and internal controls can contribute useful evidence, but they do not automatically demonstrate every CAF outcome. Mapping should show exactly what an existing control proves and where further resilience work is still needed.

This approach reduces duplication while keeping the CAF assessment honest and useful to decision-makers.

Simple process

From problem to practical plan

01

Confirm the context

We identify the essential functions, relevant regulator or authority, CAF profile and assessment expectations before scoring outcomes.

02

Assess the outcomes

Evidence is reviewed across governance, protection, detection and response, with dependencies and material gaps made visible.

03

Improve resilience

Actions are prioritised by risk and essential-service impact, then tracked through a practical evidence and assurance plan.

Independent decisions stay independent

Preparation you can stand behind.

CAF is an assessment framework rather than a general certification. The relevant regulator or authority determines the required profile, assurance approach and acceptance decision.

Read the current NCSC CAF guidance

Common questions

Before you get in touch

Still unsure? A quick message is enough—we will point you in the right direction.

Is the NCSC CAF a certification?

No. CAF is an outcome-focused assessment framework. How it is used, reviewed and accepted depends on the relevant regulator, government body or assurance programme.

Does every business need a CAF assessment?

No. CAF is principally aimed at essential services, critical infrastructure, government and regulated contexts. A named requirement from a regulator or customer is a strong reason to use it; most ordinary SMEs should begin with a more proportionate baseline.

Can ISO 27001 evidence be reused for CAF?

Often, yes, where the evidence genuinely supports a CAF outcome. ISO 27001 certification does not automatically satisfy CAF, so the mapping and any remaining resilience gaps still need to be assessed.

Can you decide our CAF profile?

We can help interpret and prepare against a confirmed profile, but regulated organisations should agree the applicable profile and assessment expectations with their regulator or responsible authority.

Ready when you are

Let’s turn CAF outcomes into a practical resilience plan.