Confirm the context
We identify the essential functions, relevant regulator or authority, CAF profile and assessment expectations before scoring outcomes.
Essential services & resilience
The NCSC Cyber Assessment Framework is designed around the security and resilience of essential functions. For organisations using CAF directly—or responding to a regulator, government customer or supply-chain requirement—we help turn its outcomes into a defensible assessment and improvement programme.
How we can help
Assess and improve cyber resilience against the NCSC Cyber Assessment Framework with outcome mapping, evidence review and prioritised remediation support.
Designed for vital functions
The framework is primarily intended for organisations operating essential services, critical national infrastructure, government functions and regulated environments. It may also appear through sector profiles, public-sector assurance or supply-chain expectations.
Before starting a CAF assessment, regulated organisations should confirm the applicable profile and expectations with their regulator or responsible authority.
Outcome focused
CAF organises cyber resilience across managing security risk, protecting against attack, detecting cyber events, and minimising the impact of incidents. The assessment should connect those outcomes to the systems, people, information and suppliers that the essential function depends upon.
We help collect and challenge evidence, identify unknowns and separate genuine control weakness from a documentation gap.
Map intelligently
ISO 27001, Cyber Essentials, sector standards and internal controls can contribute useful evidence, but they do not automatically demonstrate every CAF outcome. Mapping should show exactly what an existing control proves and where further resilience work is still needed.
This approach reduces duplication while keeping the CAF assessment honest and useful to decision-makers.
Simple process
We identify the essential functions, relevant regulator or authority, CAF profile and assessment expectations before scoring outcomes.
Evidence is reviewed across governance, protection, detection and response, with dependencies and material gaps made visible.
Actions are prioritised by risk and essential-service impact, then tracked through a practical evidence and assurance plan.
Independent decisions stay independent
CAF is an assessment framework rather than a general certification. The relevant regulator or authority determines the required profile, assurance approach and acceptance decision.
Read the current NCSC CAF guidanceConnected assurance
Use the framework that fits the requirement, then reuse compatible controls and evidence without confusing one standard for another.
Practical readiness support for Cyber Essentials, ISO 27001, Defence Cyber Certification, DSPT, PCI DSS and the NCSC Cyber Assessment Framework.
View readiness support Information security managementBuild and prepare an ISO/IEC 27001 information security management system with practical gap analysis, risk treatment, documentation and audit readiness support.
View readiness support UK defence supply chainPrepare for Defence Cyber Certification and Cyber Security Model v4 requirements with scope, control, SAQ, improvement-plan and evidence support.
View readiness support Health & care data securityPrepare an accurate NHS Data Security and Protection Toolkit submission with practical evidence, policy, training, continuity and technical security support.
View readiness supportCommon questions
Still unsure? A quick message is enough—we will point you in the right direction.
No. CAF is an outcome-focused assessment framework. How it is used, reviewed and accepted depends on the relevant regulator, government body or assurance programme.
No. CAF is principally aimed at essential services, critical infrastructure, government and regulated contexts. A named requirement from a regulator or customer is a strong reason to use it; most ordinary SMEs should begin with a more proportionate baseline.
Often, yes, where the evidence genuinely supports a CAF outcome. ISO 27001 certification does not automatically satisfy CAF, so the mapping and any remaining resilience gaps still need to be assessed.
We can help interpret and prepare against a confirmed profile, but regulated organisations should agree the applicable profile and assessment expectations with their regulator or responsible authority.
Ready when you are